From e54c02fabbfc528b00c45d54e82cc1ce8313ace4 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Tue, 11 Aug 2026 11:54:12 +0100 Subject: [PATCH 1/4] reset Alembic to v0.1 schema baseline --- .../TEST_STRUCTURE_DEBT.json | 446 +- .../DECISIONS.md | 8 + .../WS-DB-001-v01-schema-baseline/PLAN.md | 13 +- .../WS-DB-001-v01-schema-baseline/STATUS.md | 9 +- .../chunks/WS-DB-001-01-v01-baseline-reset.md | 9 +- CONTRIBUTING.md | 4 + README.md | 5 + backend/alembic/MIGRATION_TEST_CUSTODY.md | 153 + backend/alembic/README | 5 + .../baseline/v01_approved_manifest_delta.json | 17 + .../baseline/v01_baseline_manifest.json | 26923 ++++++++++++++++ .../v01_pre_reset_source_manifest.json | 26923 ++++++++++++++++ .../alembic/baseline/v01_reference_data.sql | 183 + backend/alembic/baseline/v01_schema.sql | 5633 ++++ backend/alembic/env.py | 33 +- .../alembic/versions/0001_initial_baseline.py | 22 - backend/alembic/versions/0001_v01_baseline.py | 86 + .../versions/0002_project_guide_foundation.py | 169 - .../versions/0003_task_queue_assignment.py | 181 - .../0004_submission_packet_foundation.py | 149 - backend/alembic/versions/0005_checker_runs.py | 184 - ...6_submission_artifact_policy_foundation.py | 642 - .../0007_task_locked_submission_context.py | 316 - ...8_post_submit_checker_policy_provenance.py | 298 - .../0009_evaluation_pending_status.py | 21 - .../0010_project_guide_contract_marker.py | 21 - .../0011_task_artifact_contract_marker.py | 21 - .../0012_actor_identity_profile_registry.py | 125 - .../versions/0013_project_setup_runs.py | 166 - .../0014_post_submit_setup_continuation.py | 350 - ...015_post_submit_policy_correction_audit.py | 119 - .../0016_artifact_domain_local_adapter.py | 382 - backend/alembic/versions/0017_api_controls.py | 71 - .../versions/0018_authority_audit_evidence.py | 604 - .../versions/0019_authority_idempotency.py | 319 - .../versions/0020_canonical_actor_profile.py | 388 - .../0021_authorization_action_evidence.py | 297 - .../versions/0022_bootstrap_admin_grants.py | 630 - .../versions/0023_service_actor_identity.py | 366 - .../0024_service_link_verification.py | 57 - .../0025_artifact_store_v2_clean_cut.py | 422 - .../versions/0026_actor_profile_lifecycle.py | 394 - .../versions/0027_contributor_foundation.py | 281 - .../versions/0028_artifact_admission.py | 384 - .../0029_shared_transactional_outbox.py | 330 - .../0030_artifact_verification_fencing.py | 340 - .../versions/0031_project_role_grants.py | 461 - .../0032_artifact_recovery_attempts.py | 290 - .../0033_authorization_read_rate_control.py | 75 - .../0034_project_role_issue_evidence.py | 490 - .../0035_project_read_action_evidence.py | 139 - .../0036_art_auth_catalogue_reconciliation.py | 196 - ...artifact_authorization_context_evidence.py | 99 - .../0038_guide_source_artifact_ingests.py | 82 - .../versions/0039_guide_source_bindings.py | 215 - .../versions/0040_guide_materialization.py | 131 - .../0041_project_mutation_action_evidence.py | 129 - .../alembic/versions/0042_guide_extraction.py | 277 - .../versions/0043_project_setup_service.py | 62 - .../versions/0044_project_create_authority.py | 336 - .../0045_guide_source_metadata_authority.py | 515 - .../0046_guide_sufficiency_provenance.py | 196 - ...mmutable_review_revision_policy_lineage.py | 597 - .../0048_review_revision_policy_authority.py | 413 - .../versions/0049_rev_auth_readiness.py | 157 - .../versions/0050_guide_source_v2_cutover.py | 247 - .../versions/0051_review_queue_foundation.py | 410 - .../versions/0052_legacy_intake_removal.py | 343 - ...3_project_compensation_adapter_bindings.py | 140 - .../0054_guide_sufficiency_authority.py | 318 - .../versions/0055_contribution_policy.py | 627 - .../versions/0056_review_lease_preference.py | 361 - .../0057_submission_policy_authority.py | 821 - .../versions/0058_pre_submit_evidence.py | 398 - .../0059_submission_policy_execution_claim.py | 169 - .../0060_submission_bundle_durable_intent.py | 251 - .../0061_submission_bundle_admission.py | 328 - ...62_project_guide_compilation_foundation.py | 484 - .../0063_guide_compilation_authority.py | 198 - .../actors/service_identity_migration.py | 589 - backend/migration_contracts/__init__.py | 1 - .../service_identity_0023.py | 628 - backend/pyproject.toml | 2 +- backend/scripts/run_test_lanes.py | 1 - backend/scripts/schema_baseline_manifest.py | 272 + backend/scripts/schema_baseline_sql.py | 68 + .../scripts/service_actor_identity_mapping.py | 145 - .../test_migration_contract.py | 225 +- backend/tests/conftest.py | 2 +- .../test_migration_contract.py | 129 +- backend/tests/test_actor_migration_tools.py | 574 - backend/tests/test_alembic.py | 14256 +------- backend/tests/test_artifact_admission.py | 194 - backend/tests/test_authorization.py | 4 - backend/tests/test_compensation.py | 56 +- backend/tests/test_guide_bindings.py | 182 - .../tests/test_review_lease_persistence.py | 84 - .../tests/test_review_queue_persistence.py | 87 - backend/tests/test_tasks.py | 28 - docs/architecture_data_model.md | 31 +- docs/operations_artifact_storage.md | 24 +- docs/operations_authorization_service.md | 427 +- docs/operations_backend_testing.md | 4 +- docs/spec_artifact_storage_service.md | 54 +- docs/spec_authorization_service.md | 35 +- 105 files changed, 60831 insertions(+), 35725 deletions(-) create mode 100644 backend/alembic/MIGRATION_TEST_CUSTODY.md create mode 100644 backend/alembic/baseline/v01_approved_manifest_delta.json create mode 100644 backend/alembic/baseline/v01_baseline_manifest.json create mode 100644 backend/alembic/baseline/v01_pre_reset_source_manifest.json create mode 100644 backend/alembic/baseline/v01_reference_data.sql create mode 100644 backend/alembic/baseline/v01_schema.sql delete mode 100644 backend/alembic/versions/0001_initial_baseline.py create mode 100644 backend/alembic/versions/0001_v01_baseline.py delete mode 100644 backend/alembic/versions/0002_project_guide_foundation.py delete mode 100644 backend/alembic/versions/0003_task_queue_assignment.py delete mode 100644 backend/alembic/versions/0004_submission_packet_foundation.py delete mode 100644 backend/alembic/versions/0005_checker_runs.py delete mode 100644 backend/alembic/versions/0006_submission_artifact_policy_foundation.py delete mode 100644 backend/alembic/versions/0007_task_locked_submission_context.py delete mode 100644 backend/alembic/versions/0008_post_submit_checker_policy_provenance.py delete mode 100644 backend/alembic/versions/0009_evaluation_pending_status.py delete mode 100644 backend/alembic/versions/0010_project_guide_contract_marker.py delete mode 100644 backend/alembic/versions/0011_task_artifact_contract_marker.py delete mode 100644 backend/alembic/versions/0012_actor_identity_profile_registry.py delete mode 100644 backend/alembic/versions/0013_project_setup_runs.py delete mode 100644 backend/alembic/versions/0014_post_submit_setup_continuation.py delete mode 100644 backend/alembic/versions/0015_post_submit_policy_correction_audit.py delete mode 100644 backend/alembic/versions/0016_artifact_domain_local_adapter.py delete mode 100644 backend/alembic/versions/0017_api_controls.py delete mode 100644 backend/alembic/versions/0018_authority_audit_evidence.py delete mode 100644 backend/alembic/versions/0019_authority_idempotency.py delete mode 100644 backend/alembic/versions/0020_canonical_actor_profile.py delete mode 100644 backend/alembic/versions/0021_authorization_action_evidence.py delete mode 100644 backend/alembic/versions/0022_bootstrap_admin_grants.py delete mode 100644 backend/alembic/versions/0023_service_actor_identity.py delete mode 100644 backend/alembic/versions/0024_service_link_verification.py delete mode 100644 backend/alembic/versions/0025_artifact_store_v2_clean_cut.py delete mode 100644 backend/alembic/versions/0026_actor_profile_lifecycle.py delete mode 100644 backend/alembic/versions/0027_contributor_foundation.py delete mode 100644 backend/alembic/versions/0028_artifact_admission.py delete mode 100644 backend/alembic/versions/0029_shared_transactional_outbox.py delete mode 100644 backend/alembic/versions/0030_artifact_verification_fencing.py delete mode 100644 backend/alembic/versions/0031_project_role_grants.py delete mode 100644 backend/alembic/versions/0032_artifact_recovery_attempts.py delete mode 100644 backend/alembic/versions/0033_authorization_read_rate_control.py delete mode 100644 backend/alembic/versions/0034_project_role_issue_evidence.py delete mode 100644 backend/alembic/versions/0035_project_read_action_evidence.py delete mode 100644 backend/alembic/versions/0036_art_auth_catalogue_reconciliation.py delete mode 100644 backend/alembic/versions/0037_artifact_authorization_context_evidence.py delete mode 100644 backend/alembic/versions/0038_guide_source_artifact_ingests.py delete mode 100644 backend/alembic/versions/0039_guide_source_bindings.py delete mode 100644 backend/alembic/versions/0040_guide_materialization.py delete mode 100644 backend/alembic/versions/0041_project_mutation_action_evidence.py delete mode 100644 backend/alembic/versions/0042_guide_extraction.py delete mode 100644 backend/alembic/versions/0043_project_setup_service.py delete mode 100644 backend/alembic/versions/0044_project_create_authority.py delete mode 100644 backend/alembic/versions/0045_guide_source_metadata_authority.py delete mode 100644 backend/alembic/versions/0046_guide_sufficiency_provenance.py delete mode 100644 backend/alembic/versions/0047_immutable_review_revision_policy_lineage.py delete mode 100644 backend/alembic/versions/0048_review_revision_policy_authority.py delete mode 100644 backend/alembic/versions/0049_rev_auth_readiness.py delete mode 100644 backend/alembic/versions/0050_guide_source_v2_cutover.py delete mode 100644 backend/alembic/versions/0051_review_queue_foundation.py delete mode 100644 backend/alembic/versions/0052_legacy_intake_removal.py delete mode 100644 backend/alembic/versions/0053_project_compensation_adapter_bindings.py delete mode 100644 backend/alembic/versions/0054_guide_sufficiency_authority.py delete mode 100644 backend/alembic/versions/0055_contribution_policy.py delete mode 100644 backend/alembic/versions/0056_review_lease_preference.py delete mode 100644 backend/alembic/versions/0057_submission_policy_authority.py delete mode 100644 backend/alembic/versions/0058_pre_submit_evidence.py delete mode 100644 backend/alembic/versions/0059_submission_policy_execution_claim.py delete mode 100644 backend/alembic/versions/0060_submission_bundle_durable_intent.py delete mode 100644 backend/alembic/versions/0061_submission_bundle_admission.py delete mode 100644 backend/alembic/versions/0062_project_guide_compilation_foundation.py delete mode 100644 backend/alembic/versions/0063_guide_compilation_authority.py delete mode 100644 backend/app/modules/actors/service_identity_migration.py delete mode 100644 backend/migration_contracts/__init__.py delete mode 100644 backend/migration_contracts/service_identity_0023.py create mode 100644 backend/scripts/schema_baseline_manifest.py create mode 100644 backend/scripts/schema_baseline_sql.py delete mode 100644 backend/scripts/service_actor_identity_mapping.py delete mode 100644 backend/tests/test_actor_migration_tools.py diff --git a/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json b/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json index 956f267c0..cd050f10f 100644 --- a/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json +++ b/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json @@ -170,23 +170,11 @@ }, { "capability": "unassigned_legacy_auth", - "content_sha256": "82d11f09ce0a0684ec0eaa6dbb75266a8207060ee8cfdb406ac2a10b2a4913f6", - "end_line": 14088, + "content_sha256": "af8e6d93649b4715d9757f6ccf3aa6d24c260c494bfca076a3191d493cb514f9", + "end_line": 3293, "hard_limit": 1200, "kind": "test_file", - "observed_lines": 14088, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": null, - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 1 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "7e1f47f6b9c8fce4829c38d32a875870e1a0c53309b94479072d7fbea816327c", - "end_line": 3487, - "hard_limit": 1200, - "kind": "test_file", - "observed_lines": 3487, + "observed_lines": 3293, "path": "backend/tests/test_artifact_admission.py", "qualified_symbol": null, "removal_chunk": "WS-AUTH-003-CLOSE", @@ -230,11 +218,11 @@ }, { "capability": "unassigned_legacy_auth", - "content_sha256": "dccb6b375f33912a43ae12fed6d27c385720b517878c59b947758a65430dfca1", - "end_line": 13439, + "content_sha256": "5ef6aaa93c09a9625196c0d1fc8f6e9c6e22b13f68b4d95253fad97616e21871", + "end_line": 13435, "hard_limit": 1200, "kind": "test_file", - "observed_lines": 13439, + "observed_lines": 13435, "path": "backend/tests/test_authorization.py", "qualified_symbol": null, "removal_chunk": "WS-AUTH-003-CLOSE", @@ -254,11 +242,11 @@ }, { "capability": "unassigned_legacy_auth", - "content_sha256": "4cb3592eb506de0b0248b33f78626ef36ff83f9367b14e6396b230ff28fefc1c", - "end_line": 2708, + "content_sha256": "8182eec08bb881fe6eed443e628bcf17710af112060ad3937a80c13040ccc5c1", + "end_line": 2526, "hard_limit": 1200, "kind": "test_file", - "observed_lines": 2708, + "observed_lines": 2526, "path": "backend/tests/test_guide_bindings.py", "qualified_symbol": null, "removal_chunk": "WS-AUTH-003-CLOSE", @@ -288,221 +276,65 @@ "removal_chunk": "WS-AUTH-003-CLOSE", "start_line": 1473 }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "30c45ea5c1222fadde46fd67473a865878e129581b659418b6b95a3ee59c7fb9", - "end_line": 4808, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 138, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_0036_art_auth_catalogue_refuses_each_new_evidence_shape", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 4671 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "3db1c111493dfddb3f31b359d00a247b255e9e8786598eaf3ab616522a882fd4", - "end_line": 4668, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 162, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_0036_art_auth_catalogue_refuses_each_obsolete_evidence_shape", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 4507 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "1fd01aa50e08e9d030bf57a38488fe94f5e55d6682ec948087475e766609577a", - "end_line": 4305, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 141, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_0045_refuses_populated_guide_authority_downgrade", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 4165 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "e6de50a8dce959e0c7acda27c2a8a7d4242f1a7ac97d8f819a5f0b177b8489c1", - "end_line": 1318, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 204, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_0050_replay_is_append_only_and_blocks_populated_downgrade", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 1115 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "a2230b4ba19040c254ee6c079255bec019157bbdf1db8e61342732eb61a65b44", - "end_line": 6678, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 237, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_actor_profile_lifecycle_constraint_and_trigger_parity", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6442 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "2e0a21b0cabfd9848336b1ab916634e86b3ef444b0ed81a4b4bed3ac492a69cb", - "end_line": 7105, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 225, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_actor_profile_lifecycle_downgrade_refuses_forward_evidence", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6881 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "227911179d5c719984be3d8f6179fc494fcbab4d15e6cc3106aba4793d6a380f", - "end_line": 6857, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 177, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_actor_profile_lifecycle_upgrade_refuses_dirty_rows", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6681 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "a65f146c03ec7406de43435a4f91267c13dd7ae7b8f2bcf730081ba22e0fe1c7", - "end_line": 5709, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 145, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_authorization_action_evidence_constraints_and_guarded_downgrade", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 5565 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "09ff96e6a32fdd56c810fe4cb872b035ed92412520bfbd6ca321bb2ab56db041", - "end_line": 5939, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 131, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_fixed_service_identity_schema_mapping_and_guarded_downgrade", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 5809 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "529e092a08f60bbd7246c8e962f1e3aa3d12b277a8021b2288a6dc7a88f61ebb", - "end_line": 4992, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 123, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_project_role_upgrade_refuses_each_legacy_predicate_before_ddl", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 4870 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "45eebcdaffabc34e517bc3e91b4881528585fbb7d57cd661020d111e97cc8e5b", - "end_line": 6138, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 197, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_service_link_verification_timestamp_schema_and_guarded_downgrade", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 5942 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "1125efccf1833fd1acda25babcb51df87d18f9a320340c6901d7ceb7b3553291", - "end_line": 1031, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 425, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_submission_policy_authority_pending_replay_blocks_downgrade", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 607 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "c2b4bb79329cf2768b2d6722b7914b2c11dcf0f1ee2f801768a2577ee0ec000e", - "end_line": 3487, - "hard_limit": 120, - "kind": "test_function", - "observed_lines": 127, - "path": "backend/tests/test_artifact_admission.py", - "qualified_symbol": "test_artifact_admission_migration_refuses_populated_downgrade", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 3361 - }, { "capability": "unassigned_legacy_auth", "content_sha256": "0febc9420a1ee5b520e320ba511cda9f73c6469d1a63bf537a263ba5886f3ce3", - "end_line": 3252, + "end_line": 3251, "hard_limit": 120, "kind": "test_function", "observed_lines": 123, "path": "backend/tests/test_artifact_admission.py", "qualified_symbol": "test_checker_output_put_observation_terminal_outcomes", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 3130 + "start_line": 3129 }, { "capability": "unassigned_legacy_auth", "content_sha256": "fa7c9ad2acfa3b9810c43509966c61171d2234042ca32f7cb8e2d543f17cc252", - "end_line": 3029, + "end_line": 3028, "hard_limit": 120, "kind": "test_function", "observed_lines": 187, "path": "backend/tests/test_artifact_admission.py", "qualified_symbol": "test_checker_output_requires_exact_active_fixed_service_identity", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 2843 + "start_line": 2842 }, { "capability": "unassigned_legacy_auth", "content_sha256": "e9f4d7d65b3794e1642401465a6f2c5a4ae179865c1a4113f97b8494ae0e1241", - "end_line": 2709, + "end_line": 2708, "hard_limit": 120, "kind": "test_function", "observed_lines": 199, "path": "backend/tests/test_artifact_admission.py", "qualified_symbol": "test_guide_admission_consumes_real_project_manager_prep_atomically", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 2511 + "start_line": 2510 }, { "capability": "unassigned_legacy_auth", "content_sha256": "bf9f2a59d649d11892c2889665478cc06dc61f597692b403458c89a593538434", - "end_line": 2508, + "end_line": 2507, "hard_limit": 120, "kind": "test_function", "observed_lines": 167, "path": "backend/tests/test_artifact_admission.py", "qualified_symbol": "test_guide_admission_derives_three_scopes_without_provider_evidence", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 2342 + "start_line": 2341 }, { "capability": "unassigned_legacy_auth", "content_sha256": "944c0487e49ed46976106404e83bcb8ad72ebb427eba10a34610a8de9697fb61", - "end_line": 1660, + "end_line": 1659, "hard_limit": 120, "kind": "test_function", "observed_lines": 131, "path": "backend/tests/test_artifact_admission.py", "qualified_symbol": "test_verification_claim_takeover_and_scanner_due_order_are_fenced", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 1530 + "start_line": 1529 }, { "capability": "unassigned_legacy_auth", @@ -699,50 +531,50 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "951b44cc07e36002118fe93b7974e8d65851b0e2c3cec89a3031cbe42b014e2d", - "end_line": 8539, + "end_line": 8535, "hard_limit": 120, "kind": "test_function", "observed_lines": 140, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_actor_lifecycle_service_applies_success_and_guards_conflicts", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8400 + "start_line": 8396 }, { "capability": "unassigned_legacy_auth", "content_sha256": "569084d6de89ff9eae71d526fc6c157aea7638f55ca93ad128b721fbda339be6", - "end_line": 9029, + "end_line": 9025, "hard_limit": 120, "kind": "test_function", "observed_lines": 122, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_admin_resource_digest_alone_rejects_substituted_role_and_disposition", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8908 + "start_line": 8904 }, { "capability": "unassigned_legacy_auth", "content_sha256": "90b8b670b4d277209617cc1aa794188b4fb3cd9d894b69d5dc3d0adfc885f6ed", - "end_line": 9257, + "end_line": 9253, "hard_limit": 120, "kind": "test_function", "observed_lines": 132, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_admin_revoke_stages_complete_state_and_evidence", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 9126 + "start_line": 9122 }, { "capability": "unassigned_legacy_auth", "content_sha256": "78d9bf3df08e5633e9a75720b1e4bf5b7d7b24019bc392b4cb7496a9ac5e5e8e", - "end_line": 11091, + "end_line": 11087, "hard_limit": 120, "kind": "test_function", "observed_lines": 122, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_authorization_locks_refresh_cached_actor_lifecycle_state", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 10970 + "start_line": 10966 }, { "capability": "unassigned_legacy_auth", @@ -759,86 +591,86 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "df1df6ec2ba6aa55445e21cfcf4e4e3ad9664c9504313484a495b6a6df1e9047", - "end_line": 3486, + "end_line": 3482, "hard_limit": 120, "kind": "test_function", "observed_lines": 126, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_identity_link_lifecycle_route_preserves_outcome_transaction_contract", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 3361 + "start_line": 3357 }, { "capability": "unassigned_legacy_auth", "content_sha256": "05d1b020ecff0f9bc0a0567adc07f5b31a2f9dfb7828ae3ad34d4e1e7757797c", - "end_line": 8692, + "end_line": 8688, "hard_limit": 120, "kind": "test_function", "observed_lines": 151, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_identity_link_lifecycle_service_applies_success_and_guards_conflicts", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8542 + "start_line": 8538 }, { "capability": "unassigned_legacy_auth", "content_sha256": "a45270573154ce2f298221169a3d55530059598bc976263feafc349c77c6ea46", - "end_line": 6344, + "end_line": 6340, "hard_limit": 120, "kind": "test_function", "observed_lines": 121, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_pre_submit_materializer_adapter_binds_every_fact_and_service", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6224 + "start_line": 6220 }, { "capability": "unassigned_legacy_auth", "content_sha256": "c5d6d0d480ced964354915614f15202c0159bfbb281658da0d44186dffd17848", - "end_line": 7487, + "end_line": 7483, "hard_limit": 120, "kind": "test_function", "observed_lines": 142, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_prepared_actor_authority_crossed_mutations_complete_in_both_orders", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 7346 + "start_line": 7342 }, { "capability": "unassigned_legacy_auth", "content_sha256": "ebb76e63671195aa4d806ac602bfe58cb22bf82d00c8a70ab186785f3acd7f9b", - "end_line": 7828, + "end_line": 7824, "hard_limit": 120, "kind": "test_function", "observed_lines": 336, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_prepared_crosses_real_lifecycle_service_transactions", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 7493 + "start_line": 7489 }, { "capability": "unassigned_legacy_auth", "content_sha256": "9ea4fc0ddbab4c7262a43bc3f498ee1afea3318e9a0b6c93c87763f9f22aae9c", - "end_line": 7318, + "end_line": 7314, "hard_limit": 120, "kind": "test_function", "observed_lines": 518, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_prepared_postgresql_failure_and_cancellation_are_atomic", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6801 + "start_line": 6797 }, { "capability": "unassigned_legacy_auth", "content_sha256": "46e0b031394da6fee856e48615732a17ff8d2276d9cedfb0ecaa3a6879410adb", - "end_line": 4691, + "end_line": 4687, "hard_limit": 120, "kind": "test_function", "observed_lines": 157, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_11c2_reads_require_exact_admin_context_and_role_allowlist", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 4535 + "start_line": 4531 }, { "capability": "unassigned_legacy_auth", @@ -855,38 +687,38 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "105667302ed6e8f2fd16ea7e95d642e72e41514673e1152503536e0520f9c362", - "end_line": 10966, + "end_line": 10962, "hard_limit": 120, "kind": "test_function", "observed_lines": 204, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_read_permissions_have_postgresql_role_scope_matrix", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 10763 + "start_line": 10759 }, { "capability": "unassigned_legacy_auth", "content_sha256": "756b7f99f9a743284934b4d85ce263617710d9b8119792ccb4526a1de04070a1", - "end_line": 12468, + "end_line": 12464, "hard_limit": 120, "kind": "test_function", "observed_lines": 233, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_role_and_all_operation_mappings_commit_one_linked_pair", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 12236 + "start_line": 12232 }, { "capability": "unassigned_legacy_auth", "content_sha256": "2e1d7db74ddb955b90a0ee12e4fb72b651a0f85d2746c76e09079c05b0b85252", - "end_line": 13439, + "end_line": 13435, "hard_limit": 120, "kind": "test_function", "observed_lines": 681, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_role_issue_postgresql_prep_binds_target_role_and_scope", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 12759 + "start_line": 12755 }, { "capability": "unassigned_legacy_auth", @@ -915,14 +747,14 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "05621e885ed2f88d0ba1a072c1f263fc923939f7ce755a514e9872112aa830a1", - "end_line": 11985, + "end_line": 11981, "hard_limit": 120, "kind": "test_function", "observed_lines": 163, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_service_actor_replay_fails_closed_on_committed_state_drift", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 11823 + "start_line": 11819 }, { "capability": "unassigned_legacy_auth", @@ -939,38 +771,38 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "3ee40b000ff508e0418aeb28a6dcb640dff4854436770343088e096c3f91c79a", - "end_line": 1694, + "end_line": 1575, "hard_limit": 120, "kind": "test_function", "observed_lines": 135, "path": "backend/tests/test_guide_bindings.py", "qualified_symbol": "test_new_format_support_replaces_obsolete_policy_budget_without_replay", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 1560 + "start_line": 1441 }, { "capability": "unassigned_legacy_auth", "content_sha256": "9a0a149ec9d89468ec6a33e5b2bcaa825896a02f2aedf75f52aee3bb402ce5f7", - "end_line": 412, + "end_line": 312, "hard_limit": 120, "kind": "test_function", "observed_lines": 176, "path": "backend/tests/test_guide_bindings.py", "qualified_symbol": "test_sufficiency_material_uses_only_exact_current_extraction", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 237 + "start_line": 137 }, { "capability": "unassigned_legacy_auth", "content_sha256": "14a28aa2e24af745acbfa5f2052873b893a42f4c27ad98325f193a9eff92dd08", - "end_line": 592, + "end_line": 492, "hard_limit": 120, "kind": "test_function", "observed_lines": 177, "path": "backend/tests/test_guide_bindings.py", "qualified_symbol": "test_verified_sufficiency_report_commits_exact_usage_provenance", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 416 + "start_line": 316 }, { "capability": "unassigned_legacy_auth", @@ -1164,173 +996,17 @@ "removal_chunk": "WS-AUTH-003-CLOSE", "start_line": 273 }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "98e4cd04125ed747aee2d97cafa0b8a244e03e17d27ed782a8a953611bb09147", - "end_line": 8460, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 191, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_assert_actor_registry_unique_constraints", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8270 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "817d69bed103a2803dfd7fe5b304adcfef329553213887f092371870921e28c2", - "end_line": 9830, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 319, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_assert_artifact_fact_guards", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 9512 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "3e5ed6a3877dfefda909fe1c68c15a365bb620e783c69f4e87539ef920e47b46", - "end_line": 10225, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 108, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_authority_audit_schema", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 10118 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "ebc0d8774563966998b4db10a048b778765a9e23109ba703506b95b7334df569", - "end_line": 11658, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 318, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_exercise_admin_authority_guards", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 11341 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "3b6c08f3e3d1e37b51315c789a4e6ed27003869c56c40a557686359033fff1ff", - "end_line": 12457, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 191, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_exercise_contributor_lineage_guards", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 12267 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "0122149c2718c63593230b51b0e1ea27536e311c7429202ce2a0c8364d2843a0", - "end_line": 13028, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 315, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_exercise_project_role_migration", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 12714 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "f9aed527b2465cadec510678d86a3ab74100ac3b55c7a7a890a7542bab7ec1b5", - "end_line": 1672, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 112, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_legacy_intake_shape", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 1561 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "14a7f4c2f1dd2cf32b144e185550fdd6f14ab4b9d02781944aa808087daa9384", - "end_line": 9277, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 302, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_seed_artifact_prior_head_runtime_rows", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8976 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "3df48541781fbe3b968cd80daa10c88b297862e6d461adde8536a0930e3d0afb", - "end_line": 12146, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 160, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_seed_contributor_prior_head", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 11987 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "1ca131d55649be7f826117fa9202300857df7a1c6f183662e9ca53dd5cbd264b", - "end_line": 8818, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 187, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "_seed_pre_provenance_runtime_rows", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8632 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "e9c7867ea3d3a381ac3ad35df8e8cf6278f713c2759f85355eb3669c5d5109e9", - "end_line": 4284, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 114, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_0045_refuses_populated_guide_authority_downgrade.seed", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 4171 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "e1d84b95accf71abd4dada32db1e1786b9d0425920f60840098bdc446d03331c", - "end_line": 6670, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 221, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_actor_profile_lifecycle_constraint_and_trigger_parity.prove_guards", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6450 - }, - { - "capability": "unassigned_legacy_auth", - "content_sha256": "34b6d34b659cb23e6a2765252a53966ce26a3263d29b58259280a9c5b8289670", - "end_line": 1008, - "hard_limit": 100, - "kind": "test_helper", - "observed_lines": 388, - "path": "backend/tests/test_alembic.py", - "qualified_symbol": "test_submission_policy_authority_pending_replay_blocks_downgrade.seed_pending", - "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 621 - }, { "capability": "unassigned_legacy_auth", "content_sha256": "0c7b21c804df09df7687641af563ea9808f7ce68fa29548b7c1c6f8b194e7d1b", - "end_line": 692, + "end_line": 691, "hard_limit": 100, "kind": "test_helper", "observed_lines": 353, "path": "backend/tests/test_artifact_admission.py", "qualified_symbol": "_seed_checker_output_relationships", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 340 + "start_line": 339 }, { "capability": "unassigned_legacy_auth", @@ -1359,26 +1035,26 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "1a0a9f3e2be6965e29f76aa74272ccfa2fe4b99e4e0c3bde5ec8ba2c374b369b", - "end_line": 11299, + "end_line": 11295, "hard_limit": 100, "kind": "test_helper", "observed_lines": 169, "path": "backend/tests/test_authorization.py", "qualified_symbol": "_operation_success", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 11131 + "start_line": 11127 }, { "capability": "unassigned_legacy_auth", "content_sha256": "19100482ea5552739e4ce0561c771da27b5ec4e99f108d0e7cbd24aae94dbaae", - "end_line": 1059, + "end_line": 959, "hard_limit": 100, "kind": "test_helper", "observed_lines": 221, "path": "backend/tests/test_guide_bindings.py", "qualified_symbol": "_seed_binding_lineage", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 839 + "start_line": 739 }, { "capability": "unassigned_legacy_auth", diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/DECISIONS.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/DECISIONS.md index 07f17b299..e8a0af71a 100644 --- a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/DECISIONS.md +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/DECISIONS.md @@ -17,3 +17,11 @@ 8. The revision-0023 frozen Python contract, service-identity migration helper, and its CLI are obsolete after the clean cut and are deleted. The current runtime service-identity registry remains authoritative. +9. The two singleton seed sequences are advanced to their seeded maximum with + `is_called = true`. The old development chain left both at `(1, false)`, + which would make the first generated key collide with row `1`; preserving + that unsafe runtime state would contradict the approved collision guard. +10. The raw pre-reset source manifest is retained unchanged. A separate + installed-baseline manifest and machine-checked approved-delta record make + the two sequence repairs visible; parity proof must never mutate the source + evidence until it appears identical to the safer target. diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/PLAN.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/PLAN.md index c844b4a58..925e4f28d 100644 --- a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/PLAN.md +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/PLAN.md @@ -22,14 +22,16 @@ 3. Build one root Alembic revision, `0001_v01_baseline`, from reviewed deterministic schema and seed resources. 4. Commit deterministic resources under `backend/alembic/baseline/`: - `v01_schema.sql`, `v01_reference_data.sql`, and - `v01_source_manifest.json`. The SQL must contain no owner, database, + `v01_schema.sql`, `v01_reference_data.sql`, the raw + `v01_pre_reset_source_manifest.json`, the installed + `v01_baseline_manifest.json`, and `v01_approved_manifest_delta.json`. The SQL must contain no owner, database, credential, session authorization, or environment-specific statement. It emits grants against the allowlisted target-role mapping and applies deterministic `setval`/identity restart state after seeded inserts. 5. Provision a second empty database from only the new baseline. -6. Compare normalized old-head and new-baseline manifests byte-for-byte, then - run ORM, runtime catalogue, fixed-service, mutation-guard, and API proof. +6. Machine-check that normalized old-head and new-baseline manifests differ + only by the approved two-sequence collision repair, then run ORM, runtime + catalogue, fixed-service, mutation-guard, and API proof. 7. Delete the 63 old revisions and replace historical-transition tests with current-state baseline and enforcement tests. 8. Delete `backend/migration_contracts/**`, the revision-0023-only service @@ -63,7 +65,8 @@ change. - Alembic reports exactly one head/root revision. - Empty database upgrade succeeds twice on independent databases. -- Normalized old-head and new-baseline object/reference manifests match. +- Normalized old-head and new-baseline object/reference manifests differ only + by the committed, approved sequence-state repair. - Sequence runtime/identity restart state matches, and the first generated key after baseline installation cannot collide with a seeded row. - For every canonical ACL entry, effective privileges queried under each diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/STATUS.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/STATUS.md index c4bea2f9d..6b8a76846 100644 --- a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/STATUS.md +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/STATUS.md @@ -1,9 +1,10 @@ # Status - Initiative: `WS-DB-001-v01-schema-baseline` -- State: planning proposed -- Source head: `98eae13e` -- Current Alembic head: `0063_compilation_authority` -- Next action: approve `WS-DB-001-01` for implementation +- State: `WS-DB-001-01` local implementation and internal review complete; + hosted CI pending +- Source head: `1ad50f4f` +- Current Alembic head: `0001_v01_baseline` +- Next action: publish the single PR and complete hosted Backend and Agent Gates - Product work remains paused until the baseline reset is merged and a clean database passes the full hosted backend gate. diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/chunks/WS-DB-001-01-v01-baseline-reset.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/chunks/WS-DB-001-01-v01-baseline-reset.md index 68a19de6d..9b3792592 100644 --- a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/chunks/WS-DB-001-01-v01-baseline-reset.md +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/chunks/WS-DB-001-01-v01-baseline-reset.md @@ -35,7 +35,9 @@ schema baseline. No old database is upgradeable. `0001_v01_baseline`, with `down_revision = None`. 2. A fresh database reaches the single head and exposes exact current tables, columns, keys, checks, indexes, sequences, types, functions, and triggers. -3. Normalized source-head and baseline manifests match byte-for-byte. +3. The raw normalized source-head manifest and installed-baseline manifest + differ only by the committed, machine-checked correction that advances the + two singleton-row sequences past their seeded keys. 4. Canonical authorization catalogue and fixed-service reference rows match runtime definitions exactly. 5. Database immutability, append-only, evidence-linkage, and lifecycle guards @@ -57,7 +59,10 @@ schema baseline. No old database is upgradeable. rows remain unchanged. 12. The committed manifest extractor covers a closed list of PostgreSQL object classes and has sentinel tests for each class. Source and baseline manifests - are committed at `backend/alembic/baseline/v01_source_manifest.json` and + are committed at + `backend/alembic/baseline/v01_pre_reset_source_manifest.json` and + `backend/alembic/baseline/v01_baseline_manifest.json`, with the sole + approved difference recorded in `v01_approved_manifest_delta.json` and compared by the hosted suite. Sequence runtime state (`last_value`/`is_called` and equivalent identity restart state) is included; seed SQL restores it deterministically and a diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index f89dccd7a..a1dc3e627 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -50,6 +50,10 @@ progress. Calendar plans, early chunk specifications, imported files under are useful history unless a current document explicitly adopts them; they are not by themselves current sequencing or proof that behavior is live. +The active migration graph is the clean v0.1 baseline. A local database with a +removed pre-v0.1 revision must be recreated; do not add a compatibility stamp, +bridge migration, or second baseline. + Roadmaps and status documents must use capability milestones and evidence. Do not introduce delivery promises such as day plans, numbered weeks, or rolling time windows as repository authority. diff --git a/README.md b/README.md index 6747ae216..762537a0a 100644 --- a/README.md +++ b/README.md @@ -357,6 +357,11 @@ uv sync --locked --extra dev --python python3 .venv/bin/python -m uvicorn app.main:app --reload ``` +The v0.1 schema starts at the single `0001_v01_baseline` Alembic revision. +Development databases stamped with any earlier revision are intentionally not +upgradeable: delete and recreate the local database, then run `alembic upgrade +head`. Workstream never rewrites or compatibility-stamps an old database. + Verify the API from another terminal with: ```bash diff --git a/backend/alembic/MIGRATION_TEST_CUSTODY.md b/backend/alembic/MIGRATION_TEST_CUSTODY.md new file mode 100644 index 000000000..fb9c4524e --- /dev/null +++ b/backend/alembic/MIGRATION_TEST_CUSTODY.md @@ -0,0 +1,153 @@ +# Migration Test Custody + +This ledger accounts for every test removed by the v0.1 clean-cut baseline reset. +Historical revision traversal is intentionally obsolete; current product invariants remain +covered by the canonical manifest, focused baseline refusal tests, and subsystem behavior tests. + +Current-invariant replacement proof is intentionally owned by behavior suites, not by +revision traversal. The exact anchors are: actor and grant guards in +`tests/test_authorization.py::test_project_role_mutation_routes_conceal_denials_and_preserve_self_guards_atomically`, +catalogue parity in `tests/test_authorization.py::test_closed_permission_and_action_catalogue_is_exact_and_non_executable`, +artifact fencing in `tests/test_artifact_admission.py::test_committed_put_and_independent_verification_are_fenced`, +outbox immutability in `tests/test_outbox.py::test_outbox_immutable_columns_delete_and_truncate_are_guarded`, +review queue lineage in `tests/test_review_queue_persistence.py::test_database_enforces_routing_uniqueness_and_immutable_lineage`, +review lease guards in `tests/test_review_lease_persistence.py::test_terminal_attempt_is_immutable_and_cannot_reopen`, +and exact PostgreSQL shape in `tests/test_alembic.py::test_fresh_database_matches_committed_manifest`. +Rows whose only subject was a deleted revision, downgrade, backfill, private envelope, or +removed migration CLI are obsolete by the approved no-compatibility clean cut. + +| Removed test | Disposition | Current proof | +|---|---|---| +| `backend/tests/test_artifact_admission.py::test_artifact_admission_migration_preserves_prior_rows_and_round_trips_empty` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_artifact_admission.py` | +| `backend/tests/test_artifact_admission.py::test_artifact_admission_migration_refuses_populated_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_artifact_admission.py` | +| `backend/tests/test_review_queue_persistence.py::test_later_authority_preserves_populated_review_admission_on_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_review_queue_persistence.py` | +| `backend/tests/test_review_queue_persistence.py::test_later_authority_preserves_populated_review_queue_on_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_review_queue_persistence.py` | +| `backend/tests/test_alembic.py::test_0034_downgrade_refuses_five_key_revoke_evidence_without_mutation` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0034_five_key_revoke_invalidation_requires_exact_linkage` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0034_project_role_issue_evidence_exact_safe_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0034_project_role_issue_evidence_fact_shape_is_closed` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0034_project_role_issue_evidence_refuses_fact_constraint_drift` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0034_project_role_issue_evidence_refuses_frozen_definition_drift` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0034_project_role_issue_evidence_refuses_incompatible_pending_state` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0034_project_role_issue_evidence_rejects_false_invalidation_at_insert` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0035_project_read_action_evidence_refuses_nonempty_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0035_project_read_action_evidence_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0036_art_auth_catalogue_refuses_each_new_evidence_shape` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0036_art_auth_catalogue_refuses_each_obsolete_evidence_shape` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0036_art_auth_catalogue_refuses_new_evidence_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0036_art_auth_catalogue_refuses_obsolete_evidence` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0036_art_auth_catalogue_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0039_backfills_setup_generations_per_guide` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0041_project_mutation_action_evidence_refuses_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0041_project_mutation_action_evidence_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0043_project_setup_service_refuses_in_use_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0043_project_setup_service_round_trip_and_seeds_no_authority` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0044_project_create_authority_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0044_refuses_populated_project_create_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0044_rejects_new_unattributed_project` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0045_guide_source_metadata_authority_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0045_preserves_historical_guide_rows` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0045_refuses_populated_guide_authority_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0050_replay_is_append_only_and_blocks_populated_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0051_legacy_intake_refuses_each_populated_condition_atomically` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0051_legacy_intake_safe_empty_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0051_review_queue_foundation_empty_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0054_guide_sufficiency_authority_safe_empty_downgrade_and_reupgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0056_review_lease_preference_empty_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0058_pre_submit_evidence_empty_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0060_submission_bundle_intent_empty_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_0061_submission_bundle_admission_empty_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_actor_profile_lifecycle_constraint_and_trigger_parity` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_actor_profile_lifecycle_downgrade_refuses_forward_evidence` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_actor_profile_lifecycle_fresh_and_prior_head_upgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_actor_profile_lifecycle_safe_downgrade_and_reupgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_actor_profile_lifecycle_upgrade_refuses_dirty_rows` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_actor_profile_registry_unique_constraints_are_enforced` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_alembic_upgrade_and_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_api_rate_control_schema_preserves_domain_and_guards_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_artifact_foundation_enforces_immutable_facts_and_guarded_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_artifact_foundation_upgrade_preserves_prior_head_and_promotes_nothing` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_artifact_recovery_schema_and_empty_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_artifact_store_v2_empty_clean_cut_and_reversible_shape` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_artifact_store_v2_refuses_populated_v1_before_ddl` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_artifact_store_v2_refuses_populated_v2_downgrade_before_ddl` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_artifact_store_v2_waits_for_concurrent_v1_writer_and_refuses` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_authority_audit_schema_preserves_legacy_and_guards_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_authority_idempotency_schema_preserves_audit_and_guards_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_authorization_action_evidence_constraints_and_guarded_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_authorization_read_rate_scope_migration_refuses_constraint_drift` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_authorization_read_rate_scope_upgrade_and_downgrade_refusal` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_bootstrap_admin_grant_schema_is_immutable_and_guarded` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_canonical_actor_classified_upgrade_preserves_identity_and_attribution` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_canonical_actor_downgrade_refuses_nonactive_authority_state` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_canonical_actor_registry_separates_authority_from_legacy_workflow_metadata` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_canonical_actor_upgrade_redacts_invalid_legacy_row_values` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_canonical_actor_upgrade_rejects_unclassified_legacy_rows` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_contributor_foundation_preflight_refuses_all_unsafe_classes_atomically` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_contributor_foundation_upgrade_guards_and_reversible_preservation` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_current_schema_uses_project_policy_contract` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_fixed_service_identity_schema_mapping_and_guarded_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_frozen_mapping_path_custody_is_independent_of_install_location` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_guide_source_artifact_ingest_schema_and_replay` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_outbox_migration_schema_and_downgrade_writer_guard` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_post_submit_policy_upgrade_blocks_pre_provenance_runtime_rows` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_post_submit_policy_upgrade_leaves_pre_provenance_rows_fail_closed` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_project_role_downgrade_refuses_each_reserved_evidence_predicate` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_project_role_migration_constraints_and_immutable_history` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_project_role_upgrade_refuses_each_legacy_predicate_before_ddl` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_service_identity_migration_contract_is_frozen_from_application_modules` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_service_link_verification_timestamp_schema_and_guarded_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_submission_policy_authority_audit_evidence_blocks_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_submission_policy_authority_pending_replay_blocks_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_submission_policy_authority_safe_empty_roundtrip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_xint003_02a_policy_lineage_backfill_immutability_and_roundtrip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_xint003_02b_policy_authority_schema_and_roundtrip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_xint003_02c_rev_auth_readiness_guarded_action_evidence_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_xint003_02c_rev_auth_readiness_guarded_identity_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_alembic.py::test_xint003_02c_rev_auth_readiness_schema_and_roundtrip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_alembic.py` | +| `backend/tests/test_tasks.py::test_chunk4_migration_downgrade_removes_task_tables` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_tasks.py` | +| `backend/tests/test_compensation.py::test_0053_binding_migration_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_compensation.py` | +| `backend/tests/test_guide_bindings.py::test_0039_refuses_populated_binding_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_guide_bindings.py` | +| `backend/tests/test_guide_bindings.py::test_0040_refuses_incident_only_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_guide_bindings.py` | +| `backend/tests/test_guide_bindings.py::test_0040_refuses_populated_classification_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_guide_bindings.py` | +| `backend/tests/test_guide_bindings.py::test_guide_sufficiency_provenance_migration_round_trip` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_guide_bindings.py` | +| `backend/tests/test_guide_bindings.py::test_superseded_guide_migration_populated_guards_remain_enforced` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_guide_bindings.py` | +| `backend/tests/test_review_lease_persistence.py::test_newer_submission_policy_authority_precedes_preference_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_review_lease_persistence.py` | +| `backend/tests/test_review_lease_persistence.py::test_populated_lease_persistence_refuses_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/test_review_lease_persistence.py` | +| `backend/tests/authorization/guide_compilation/test_migration_contract.py::test_0063_compilation_permissions_require_exact_action_evidence` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/authorization/guide_compilation/test_migration_contract.py` | +| `backend/tests/authorization/guide_compilation/test_migration_contract.py::test_0063_downgrade_refuses_compilation_permission_registry_reference` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/authorization/guide_compilation/test_migration_contract.py` | +| `backend/tests/authorization/guide_compilation/test_migration_contract.py::test_0063_empty_round_trip_preserves_exact_request_registries` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/authorization/guide_compilation/test_migration_contract.py` | +| `backend/tests/authorization/guide_compilation/test_migration_contract.py::test_0063_refuses_downgrade_after_retained_compilation_authority` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/authorization/guide_compilation/test_migration_contract.py` | +| `backend/tests/authorization/guide_compilation/test_migration_contract.py::test_0063_refuses_historical_permission_only_execute_evidence` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/authorization/guide_compilation/test_migration_contract.py` | +| `backend/tests/projects/guide_compilation/test_migration_contract.py::test_0062_empty_round_trip_restores_exact_current_schema` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/projects/guide_compilation/test_migration_contract.py` | +| `backend/tests/projects/guide_compilation/test_migration_contract.py::test_0062_nonempty_attempt_blocks_downgrade` | Obsolete intermediate-revision or downgrade-path proof | `tests/test_alembic.py` manifest/refusal proof plus the surviving current-state tests in `backend/tests/projects/guide_compilation/test_migration_contract.py` | +| `backend/tests/test_actor_migration_tools.py::test_service_identity_migration_contract_registry_is_exact` | Obsolete deleted revision-0023 contract proof | Current fixed-service registry parity is proved by `tests/test_authorization.py::test_fixed_service_action_matrix_and_activation_are_exact_and_immutable` | +| `backend/tests/test_actor_migration_tools.py::test_mapping_rejects_noncanonical_or_unknown_values` | Obsolete removed private mapping workflow | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_mapping_rejects_ambiguous_issuer_bytes` | Obsolete removed private mapping workflow | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_draft_rejects_duplicate_profile_external_identity_and_fixed_identity` | Obsolete removed private mapping workflow | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_exact_mapping_accepts_zero_subset_and_all_seven_rows` | Obsolete removed private mapping workflow | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_exact_mapping_rejects_missing_extra_or_changed_private_source` | Obsolete removed private mapping workflow | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_exact_mapping_rejects_inventory_larger_than_closed_registry` | Obsolete removed private mapping workflow | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_envelope_has_stable_known_answer_and_detects_any_binding_drift` | Obsolete removed private envelope format | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_envelope_rejects_noncanonical_or_impossible_metadata` | Obsolete removed private envelope format | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_canonical_hashes_ignore_input_order` | Obsolete removed private envelope format | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_private_loader_rejects_ambiguous_json_without_echo` | Obsolete removed migration-only loader | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_private_loader_redacts_strict_schema_failures` | Obsolete removed migration-only loader | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_private_loader_rejects_coerced_schema_versions` | Obsolete removed migration-only loader | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_private_loader_accepts_only_exact_canonical_draft` | Obsolete removed migration-only loader | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_private_loader_requires_exact_canonical_bytes` | Obsolete removed migration-only loader | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_private_loader_rejects_open_permissions_and_symlink` | Obsolete removed migration-only loader | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_publish_envelope_is_owner_only_reloadable_and_never_overwrites` | Obsolete removed private envelope publisher | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_publish_envelope_removes_partial_output_after_write_failure` | Obsolete removed private envelope publisher | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_migration_environment_is_required_only_for_existing_services` | Obsolete removed revision-0023 environment path | Current baseline environment is proved by `tests/test_alembic.py::test_fresh_database_matches_committed_manifest` | +| `backend/tests/test_actor_migration_tools.py::test_mapping_paths_reject_relative_and_every_linked_repository_root` | Obsolete removed migration-only path guard | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_mapping_path_guard_supports_deployments_without_git_metadata` | Obsolete removed migration-only path guard | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_mapping_path_guard_handles_main_and_linked_git_layouts` | Obsolete removed migration-only path guard | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_mapping_path_guard_rejects_invalid_git_metadata` | Obsolete removed migration-only path guard | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_mapping_path_guard_rejects_missing_linked_worktree_metadata` | Obsolete removed migration-only path guard | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_mapping_path_guard_rejects_missing_input` | Obsolete removed migration-only path guard | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_envelope_loader_preserves_bounded_file_errors` | Obsolete removed private envelope loader | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_report_contains_only_counts_and_non_secret_digests` | Obsolete removed migration-only report | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_cli_executes_and_disposes_engine_on_one_event_loop` | Obsolete removed migration-only CLI | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_cli_preserves_workflow_error_when_cleanup_also_fails` | Obsolete removed migration-only CLI | No runtime replacement; pre-v0.1 databases must be recreated | +| `backend/tests/test_actor_migration_tools.py::test_cli_reports_cleanup_failure_only_after_success` | Obsolete removed migration-only CLI | No runtime replacement; pre-v0.1 databases must be recreated | diff --git a/backend/alembic/README b/backend/alembic/README index c36ba96b3..2b34dfc51 100644 --- a/backend/alembic/README +++ b/backend/alembic/README @@ -1,2 +1,7 @@ Alembic migration environment for the Workstream backend. +The active graph begins at the single 0001_v01_baseline root. Databases stamped +with a removed development revision must be recreated; they are never stamped +or upgraded across the v0.1 clean cut. New revisions begin at 0002. +Offline SQL generation is intentionally disabled because the clean-database +preflight requires a live PostgreSQL target. diff --git a/backend/alembic/baseline/v01_approved_manifest_delta.json b/backend/alembic/baseline/v01_approved_manifest_delta.json new file mode 100644 index 000000000..05c351f7d --- /dev/null +++ b/backend/alembic/baseline/v01_approved_manifest_delta.json @@ -0,0 +1,17 @@ +{ + "reason": "Prevent generated-key collisions after the two singleton reference rows are seeded.", + "sequence_state_changes": [ + { + "field": "is_called", + "from": false, + "name": "actor_profile_migration_state_id_seq", + "to": true + }, + { + "field": "is_called", + "from": false, + "name": "authority_control_id_seq", + "to": true + } + ] +} diff --git a/backend/alembic/baseline/v01_baseline_manifest.json b/backend/alembic/baseline/v01_baseline_manifest.json new file mode 100644 index 000000000..362ea8889 --- /dev/null +++ b/backend/alembic/baseline/v01_baseline_manifest.json @@ -0,0 +1,26923 @@ +{ + "acl": [ + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_event_facts_are_safe(event_name text, before_state js", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_event_facts_are_safe(event_name text, before_state js", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_facts_are_safe(facts json)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_facts_are_safe(facts json)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "enforce_compensation_binding_lifecycle()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "enforce_compensation_binding_lifecycle()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_identity_link_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_identity_link_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_profile_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_profile_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_admin_role_grant()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_admin_role_grant()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_artifact_receipt_producer_reference()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_artifact_receipt_producer_reference()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_control()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_control()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_idempotency_record()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_idempotency_record()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_children()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_children()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_version_content()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_version_content()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_lineage_and_lifecycle()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_lineage_and_lifecycle()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_mutation_idempotency()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_mutation_idempotency()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_iso_4217_currency_codes()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_iso_4217_currency_codes()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_outbox_event()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_outbox_event()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_policy_mutation_replay()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_policy_mutation_replay()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_result_membership()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_result_membership()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_results_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_results_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_set_creation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_set_creation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_sets_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_sets_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_compensation_units()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_compensation_units()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_create_idempotency()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_create_idempotency()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_attempt_update()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_attempt_update()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_insert()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_insert()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_policy_selection()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_policy_selection()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_grant_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_grant_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_snapshot_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_snapshot_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_admission_record()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_admission_record()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_lease()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_lease()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_policies_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_policies_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_queue_entry()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_queue_entry()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_revision_policies_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_revision_policies_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_service_identity_migration_evidence()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_service_identity_migration_evidence()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_delete()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_delete()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_lineage()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_lineage()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_verified_lineage()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_verified_lineage()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intent_put_attempt()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intent_put_attempt()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intents_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intents_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_availability_is_safe(value jsonb)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_availability_is_safe(value jsonb)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reason_is_safe(value text)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reason_is_safe(value text)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_token_is_safe(value text)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_token_is_safe(value text)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_approval_provenance()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_approval_provenance()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_creation_provenance()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_creation_provenance()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_output_provenance()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_output_provenance()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_admin_role_grant_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_admin_role_grant_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_artifact_fact_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_artifact_fact_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_audit_event_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_audit_event_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_control_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_control_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_idempotency_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_idempotency_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_contribution_policy_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_contribution_policy_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_mutation_idempotency_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_mutation_idempotency_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_source_snapshot_item_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_source_snapshot_item_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_pending_authority_idempotency()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_pending_authority_idempotency()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_policy_mutation_replay_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_policy_mutation_replay_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_create_idempotency_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_create_idempotency_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_guide_compilation_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_guide_compilation_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_role_history_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_role_history_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_lease_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_lease_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_queue_foundation_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_queue_foundation_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "require_human_actor_profile_reference()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "require_human_actor_profile_reference()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "set_authority_audit_database_time()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "set_authority_audit_database_time()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_binding_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_binding_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_recovery_attempt()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_recovery_attempt()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_verification_lineage()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_verification_lineage()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_bootstrap_authority_state()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_bootstrap_authority_state()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_canonical_actor_link()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_canonical_actor_link()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_contribution_policy_graph()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_contribution_policy_graph()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_mutation_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_mutation_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_source_snapshot_items()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_source_snapshot_items()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_linked_authority_event()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_linked_authority_event()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_policy_mutation_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_policy_mutation_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_project_create_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_project_create_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_review_active_lease()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_review_active_lease()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_authority_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_authority_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_creation_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_creation_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "sequence", + "name": "actor_profile_migration_state_id_seq", + "principal": "owner", + "privilege": "USAGE" + }, + { + "grantable": "false", + "kind": "sequence", + "name": "authority_control_id_seq", + "principal": "owner", + "privilege": "USAGE" + } + ], + "auxiliary_objects": [], + "columns": [ + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "issuer", + "not_null": true, + "ordinal": 3, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "subject", + "not_null": true, + "ordinal": 4, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "subject_kind", + "not_null": true, + "ordinal": 5, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "linked_by", + "not_null": true, + "ordinal": 7, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "linked_at", + "not_null": true, + "ordinal": 8, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_verified_at", + "not_null": false, + "ordinal": 9, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by", + "not_null": false, + "ordinal": 10, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_at", + "not_null": false, + "ordinal": 11, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_reason", + "not_null": false, + "ordinal": 12, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_by", + "not_null": false, + "ordinal": 13, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_at", + "not_null": false, + "ordinal": 14, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivation_reason", + "not_null": false, + "ordinal": 15, + "table_name": "actor_identity_links" + }, + { + "data_type": "integer", + "default_expression": "nextval('actor_profile_migration_state_id_seq'::regclass)", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "schema_version", + "not_null": true, + "ordinal": 2, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classified_count", + "not_null": true, + "ordinal": 3, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_row_set_sha256", + "not_null": true, + "ordinal": 4, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "manifest_sha256", + "not_null": false, + "ordinal": 5, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "envelope_sha256", + "not_null": false, + "ordinal": 6, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "migrated_at", + "not_null": true, + "ordinal": 7, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_mapped_count", + "not_null": true, + "ordinal": 8, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_source_row_set_sha256", + "not_null": true, + "ordinal": 9, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_manifest_sha256", + "not_null": false, + "ordinal": 10, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_envelope_sha256", + "not_null": false, + "ordinal": 11, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(76)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_database_binding", + "not_null": true, + "ordinal": 12, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_kind", + "not_null": true, + "ordinal": 2, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 3, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provisioning_method", + "not_null": true, + "ordinal": 4, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "display_name", + "not_null": false, + "ordinal": 5, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(320)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contact_email", + "not_null": false, + "ordinal": 6, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 7, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 8, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 9, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_seen_at", + "not_null": false, + "ordinal": 10, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_by", + "not_null": false, + "ordinal": 11, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_at", + "not_null": false, + "ordinal": 12, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspension_reason", + "not_null": false, + "ordinal": 13, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deactivated_by", + "not_null": false, + "ordinal": 14, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deactivated_at", + "not_null": false, + "ordinal": 15, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deactivation_reason", + "not_null": false, + "ordinal": 16, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity", + "not_null": false, + "ordinal": 17, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_by", + "not_null": false, + "ordinal": 18, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_at", + "not_null": false, + "ordinal": 19, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivation_reason", + "not_null": false, + "ordinal": 20, + "table_name": "actor_profiles" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "role", + "not_null": true, + "ordinal": 3, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 4, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_project_id", + "not_null": false, + "ordinal": 5, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "admin_role_grants" + }, + { + "data_type": "smallint", + "default_expression": "'1'::smallint", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 7, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_actor_profile_id", + "not_null": false, + "ordinal": 8, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_system_principal", + "not_null": false, + "ordinal": 9, + "table_name": "admin_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_admin_role_grant_id", + "not_null": false, + "ordinal": 10, + "table_name": "admin_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "grant_reason", + "not_null": true, + "ordinal": 11, + "table_name": "admin_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "clock_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_at", + "not_null": true, + "ordinal": 12, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_actor_profile_id", + "not_null": false, + "ordinal": 13, + "table_name": "admin_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_admin_role_grant_id", + "not_null": false, + "ordinal": 14, + "table_name": "admin_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_reason", + "not_null": false, + "ordinal": 15, + "table_name": "admin_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_at", + "not_null": false, + "ordinal": 16, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "control_scope", + "not_null": true, + "ordinal": 1, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "bytea", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "key_digest", + "not_null": true, + "ordinal": 2, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "window_started_at", + "not_null": true, + "ordinal": 3, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "window_expires_at", + "not_null": true, + "ordinal": 4, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_count", + "not_null": true, + "ordinal": 5, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 6, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_type", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_ref", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creating_operation_identity", + "not_null": true, + "ordinal": 8, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(20)", + "default_expression": "'provisional'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "state", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "reserved_at", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "completed_at", + "not_null": false, + "ordinal": 12, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "released_at", + "not_null": false, + "ordinal": 13, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 15, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "limit_bytes", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "counted_bytes", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_type", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_id", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_bindings" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_version", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 8, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attribution_type", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_binding_id", + "not_null": false, + "ordinal": 10, + "table_name": "artifact_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_contents" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": false, + "ordinal": 4, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "normalized_display_name", + "not_null": false, + "ordinal": 5, + "table_name": "artifact_contents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replica_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(1024)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_object_ref", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replayed", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome", + "not_null": true, + "ordinal": 8, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_number", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "details", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "contract_version", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_source_item_id", + "not_null": false, + "ordinal": 15, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_run_id", + "not_null": false, + "ordinal": 16, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": false, + "ordinal": 17, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_put_attempt_charges" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "charge_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_put_attempt_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_put_attempt_charges" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_request_type", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_type", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_ref", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": false, + "ordinal": 6, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_source_item_id", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_run_id", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": false, + "ordinal": 9, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(255)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "storage_namespace_id", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_fingerprint", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(1024)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_target", + "not_null": true, + "ordinal": 15, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_identity", + "not_null": true, + "ordinal": 16, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 17, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "'prepared'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 18, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "next_run_at", + "not_null": false, + "ordinal": 19, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "executor_id", + "not_null": false, + "ordinal": 20, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lease_expires_at", + "not_null": false, + "ordinal": 21, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 22, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_result_code", + "not_null": false, + "ordinal": 23, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replica_id", + "not_null": false, + "ordinal": 24, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "receipt_id", + "not_null": false, + "ordinal": 25, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 26, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "prepared_at", + "not_null": true, + "ordinal": 27, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 28, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 29, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 30, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_mode", + "not_null": false, + "ordinal": 31, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "observation_count", + "not_null": true, + "ordinal": 32, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'5'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "maximum_observations", + "not_null": true, + "ordinal": 33, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "expected_sha256", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "expected_byte_count", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_sha256", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_byte_count", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 9, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requester_actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requester_identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_request_id", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_correlation_id", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_verification_job_id", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retry_verification_job_id", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "parent_recovery_attempt_id", + "not_null": false, + "ordinal": 11, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "recovery_class", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(1000)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reason", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "client_idempotency_key", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 15, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(20)", + "default_expression": "'requested'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 16, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_result_code", + "not_null": false, + "ordinal": 17, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "initiation_audit_event_id", + "not_null": true, + "ordinal": 18, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_audit_event_id", + "not_null": false, + "ordinal": 19, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 20, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 21, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 22, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": false, + "ordinal": 23, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(1024)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_object_ref", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verification_state", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "availability_state", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "integrity_state", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_replicas" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_reconciled_at", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_replicas" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_replicas" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "storage_namespace_id", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_fingerprint", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_profile", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "backend", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_profile", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_descriptor", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_fingerprint", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "originating_put_attempt_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replica_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(40)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "integer", + "default_expression": "0", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_count", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "maximum_attempts", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "next_run_at", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "executor_id", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lease_expires_at", + "not_null": false, + "ordinal": 9, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_result_code", + "not_null": false, + "ordinal": 12, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 13, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 14, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": false, + "ordinal": 15, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "parent_verification_job_id", + "not_null": false, + "ordinal": 16, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verification_job_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_sha256", + "not_null": false, + "ordinal": 5, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_byte_count", + "not_null": false, + "ordinal": 6, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "audit_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "entity_type", + "not_null": true, + "ordinal": 2, + "table_name": "audit_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "entity_id", + "not_null": true, + "ordinal": 3, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_type", + "not_null": true, + "ordinal": 4, + "table_name": "audit_events" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "from_status", + "not_null": false, + "ordinal": 5, + "table_name": "audit_events" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "to_status", + "not_null": false, + "ordinal": 6, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 7, + "table_name": "audit_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_subject", + "not_null": false, + "ordinal": 8, + "table_name": "audit_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_issuer", + "not_null": false, + "ordinal": 9, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_roles", + "not_null": true, + "ordinal": 10, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_snapshot", + "not_null": true, + "ordinal": 11, + "table_name": "audit_events" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "auth_source", + "not_null": true, + "ordinal": 12, + "table_name": "audit_events" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "is_dev_auth", + "not_null": true, + "ordinal": 13, + "table_name": "audit_events" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reason", + "not_null": false, + "ordinal": 14, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_payload", + "not_null": true, + "ordinal": 15, + "table_name": "audit_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "audit_events" + }, + { + "data_type": "character varying(24)", + "default_expression": "'legacy_lifecycle'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_domain", + "not_null": true, + "ordinal": 17, + "table_name": "audit_events" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_version", + "not_null": false, + "ordinal": 18, + "table_name": "audit_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "occurred_at", + "not_null": false, + "ordinal": 19, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_ref_kind", + "not_null": false, + "ordinal": 20, + "table_name": "audit_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_id", + "not_null": false, + "ordinal": 21, + "table_name": "audit_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": false, + "ordinal": 22, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_actor_ref_kind", + "not_null": false, + "ordinal": 23, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_actor_ref", + "not_null": false, + "ordinal": 24, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "matched_grant_id", + "not_null": false, + "ordinal": 25, + "table_name": "audit_events" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "permission_id", + "not_null": false, + "ordinal": 26, + "table_name": "audit_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": false, + "ordinal": 27, + "table_name": "audit_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_type", + "not_null": false, + "ordinal": 28, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_id", + "not_null": false, + "ordinal": 29, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_ref_kind", + "not_null": false, + "ordinal": 30, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_ref_id", + "not_null": false, + "ordinal": 31, + "table_name": "audit_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "denial_code", + "not_null": false, + "ordinal": 32, + "table_name": "audit_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_reference", + "not_null": false, + "ordinal": 33, + "table_name": "audit_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "invalidation_cause_event_id", + "not_null": false, + "ordinal": 34, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "invalidation_target_kind", + "not_null": false, + "ordinal": 35, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "invalidation_target_ref", + "not_null": false, + "ordinal": 36, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "before_facts", + "not_null": false, + "ordinal": 37, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "after_facts", + "not_null": false, + "ordinal": 38, + "table_name": "audit_events" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": false, + "ordinal": 39, + "table_name": "audit_events" + }, + { + "data_type": "smallint", + "default_expression": "nextval('authority_control_id_seq'::regclass)", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "authority_control" + }, + { + "data_type": "boolean", + "default_expression": "false", + "generated_kind": "00", + "identity_kind": "00", + "name": "bootstrap_completed", + "not_null": true, + "ordinal": 2, + "table_name": "authority_control" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bootstrap_grant_id", + "not_null": false, + "ordinal": 3, + "table_name": "authority_control" + }, + { + "data_type": "smallint", + "default_expression": "'0'::smallint", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 4, + "table_name": "authority_control" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "clock_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 5, + "table_name": "authority_control" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "clock_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 6, + "table_name": "authority_control" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 2, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_ref_kind", + "not_null": true, + "ordinal": 3, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_ref", + "not_null": true, + "ordinal": 4, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(48)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation", + "not_null": true, + "ordinal": 5, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 7, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_resource_type", + "not_null": false, + "ordinal": 8, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_resource_id", + "not_null": false, + "ordinal": 9, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_resource_version", + "not_null": false, + "ordinal": 10, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "smallint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_http_status", + "not_null": false, + "ordinal": 11, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 12, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 13, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "required_checkers", + "not_null": true, + "ordinal": 4, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_checkers", + "not_null": true, + "ordinal": 5, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "blocking_severities", + "not_null": true, + "ordinal": 6, + "table_name": "checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": false, + "ordinal": 8, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_body", + "not_null": false, + "ordinal": 9, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 10, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 11, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 12, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_id", + "not_null": true, + "ordinal": 13, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_hash", + "not_null": true, + "ordinal": 14, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_checker_policy_id", + "not_null": true, + "ordinal": 15, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_checker_bundle_hash", + "not_null": true, + "ordinal": 16, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 17, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_role", + "not_null": false, + "ordinal": 18, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_actor", + "not_null": false, + "ordinal": 19, + "table_name": "checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_at", + "not_null": false, + "ordinal": 20, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 21, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 22, + "table_name": "checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 23, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_by_role", + "not_null": false, + "ordinal": 24, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_by_actor", + "not_null": false, + "ordinal": 25, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersession_kind", + "not_null": false, + "ordinal": 26, + "table_name": "checker_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersession_reason", + "not_null": false, + "ordinal": 27, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_run_id", + "not_null": true, + "ordinal": 2, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 3, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 4, + "table_name": "checker_results" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_name", + "not_null": true, + "ordinal": 5, + "table_name": "checker_results" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "checker_results" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "severity", + "not_null": true, + "ordinal": 7, + "table_name": "checker_results" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "blocks_review", + "not_null": true, + "ordinal": 8, + "table_name": "checker_results" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "message", + "not_null": true, + "ordinal": 9, + "table_name": "checker_results" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_message", + "not_null": false, + "ordinal": 10, + "table_name": "checker_results" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_suggested_fix", + "not_null": false, + "ordinal": 11, + "table_name": "checker_results" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_evidence_refs", + "not_null": true, + "ordinal": 12, + "table_name": "checker_results" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_visible", + "not_null": true, + "ordinal": 13, + "table_name": "checker_results" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "metadata", + "not_null": true, + "ordinal": 14, + "table_name": "checker_results" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 15, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 2, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 3, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 4, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "trigger_source", + "not_null": true, + "ordinal": 5, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_recommendation", + "not_null": true, + "ordinal": 7, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome_source", + "not_null": true, + "ordinal": 8, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "triggered_by", + "not_null": true, + "ordinal": 9, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "triggered_by_subject", + "not_null": true, + "ordinal": 10, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "triggered_by_issuer", + "not_null": true, + "ordinal": 11, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "trigger_auth_source", + "not_null": true, + "ordinal": 12, + "table_name": "checker_runs" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "trigger_reason", + "not_null": false, + "ordinal": 13, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "audit_event_id", + "not_null": false, + "ordinal": 14, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_number", + "not_null": true, + "ordinal": 15, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_checker_run_id", + "not_null": false, + "ordinal": 16, + "table_name": "checker_runs" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "is_current_for_submission", + "not_null": true, + "ordinal": 17, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_version", + "not_null": true, + "ordinal": 18, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_payment_policy_version", + "not_null": true, + "ordinal": 19, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "package_hash", + "not_null": true, + "ordinal": 20, + "table_name": "checker_runs" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_hash_manifest", + "not_null": true, + "ordinal": 21, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_manifest_hash", + "not_null": true, + "ordinal": 22, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "passed_count", + "not_null": true, + "ordinal": 23, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_count", + "not_null": true, + "ordinal": 24, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failed_count", + "not_null": true, + "ordinal": 25, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "blocking_count", + "not_null": true, + "ordinal": 26, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "queued_at", + "not_null": true, + "ordinal": 27, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "started_at", + "not_null": false, + "ordinal": 28, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "completed_at", + "not_null": false, + "ordinal": 29, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_code", + "not_null": false, + "ordinal": 30, + "table_name": "checker_runs" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_message", + "not_null": false, + "ordinal": 31, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 32, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 33, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_version", + "not_null": false, + "ordinal": 34, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_hash", + "not_null": false, + "ordinal": 35, + "table_name": "checker_runs" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_body", + "not_null": false, + "ordinal": 36, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_id", + "not_null": true, + "ordinal": 37, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_generation", + "not_null": true, + "ordinal": 38, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_hash", + "not_null": true, + "ordinal": 39, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_id", + "not_null": true, + "ordinal": 40, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_generation", + "not_null": true, + "ordinal": 41, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_hash", + "not_null": true, + "ordinal": 42, + "table_name": "checker_runs" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_rule_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_policy_version_id", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_type", + "not_null": true, + "ordinal": 5, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instrument_type", + "not_null": true, + "ordinal": 6, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "unit_code", + "not_null": true, + "ordinal": 7, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "numeric", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "quantity", + "not_null": true, + "ordinal": 8, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter_binding_id", + "not_null": true, + "ordinal": 9, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "name", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "'draft'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "current_published_version_id", + "not_null": false, + "ordinal": 5, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 6, + "table_name": "contribution_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 8, + "table_name": "contribution_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 9, + "table_name": "contribution_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_policy_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "version_number", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(16)", + "default_expression": "'draft'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 6, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "published_by", + "not_null": false, + "ordinal": 8, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "published_at", + "not_null": false, + "ordinal": 9, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 10, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 11, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_rules" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_policy_version_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_type", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compensation_mode", + "not_null": true, + "ordinal": 5, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_artifact_policy_id", + "not_null": true, + "ordinal": 7, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_artifact_policy_hash", + "not_null": true, + "ordinal": 8, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 9, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "merge_algorithm_version", + "not_null": true, + "ordinal": 10, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy", + "not_null": true, + "ordinal": 11, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_hash", + "not_null": true, + "ordinal": 12, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 13, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_effective_policy_id", + "not_null": false, + "ordinal": 15, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 16, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 17, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 18, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 19, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 20, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 21, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 22, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_decision_event_id", + "not_null": false, + "ordinal": 23, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 2, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "type", + "not_null": true, + "ordinal": 3, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "label", + "not_null": true, + "ordinal": 4, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(1000)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "uri", + "not_null": false, + "ordinal": 5, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "hash", + "not_null": false, + "ordinal": 6, + "table_name": "evidence_items" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "size_bytes", + "not_null": false, + "ordinal": 7, + "table_name": "evidence_items" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_at", + "not_null": false, + "ordinal": 8, + "table_name": "evidence_items" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "metadata", + "not_null": true, + "ordinal": 9, + "table_name": "evidence_items" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "evidence_items" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 7, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_id", + "not_null": true, + "ordinal": 10, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_generation", + "not_null": true, + "ordinal": 11, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 12, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 13, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": false, + "ordinal": 14, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 15, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 16, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_binding_id", + "not_null": false, + "ordinal": 11, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service", + "not_null": true, + "ordinal": 12, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "code", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_sha256", + "not_null": false, + "ordinal": 7, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_byte_count", + "not_null": false, + "ordinal": 8, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bounded_facts", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(255)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detected_format", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_name", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_version", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_sha256", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_byte_count", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_sha256", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_output", + "not_null": true, + "ordinal": 11, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "omission_facts", + "not_null": true, + "ordinal": 12, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detected_format", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_name", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_version", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_number", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 11, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_code", + "not_null": false, + "ordinal": 12, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bounded_facts", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claimed_slots", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extracted_content_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extraction_attempt_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_status", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(255)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detected_format", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detector_name", + "not_null": true, + "ordinal": 11, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detector_version", + "not_null": true, + "ordinal": 12, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification_facts", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "item_order", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_kind", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_label", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "ingestion_adapter", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": false, + "ordinal": 7, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "manifest_schema_version", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "manifest_json", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bundle_hash", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_by", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_at", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 10, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 11, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 12, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 13, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 14, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 15, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 16, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_generation", + "not_null": false, + "ordinal": 17, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 7, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 10, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 11, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "report_id", + "not_null": false, + "ordinal": 12, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": false, + "ordinal": 13, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 14, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 15, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 16, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 17, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 18, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "report_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "item_order", + "not_null": true, + "ordinal": 3, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 6, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extraction_usage_id", + "not_null": true, + "ordinal": 7, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extraction_attempt_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extracted_content_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": true, + "ordinal": 10, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 11, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_output_sha256", + "not_null": true, + "ordinal": 12, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 7, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "findings", + "not_null": true, + "ordinal": 8, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "summary", + "not_null": false, + "ordinal": 9, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_name", + "not_null": false, + "ordinal": 10, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_version", + "not_null": false, + "ordinal": 11, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 12, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 13, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_role", + "not_null": false, + "ordinal": 14, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_actor", + "not_null": false, + "ordinal": 15, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_at", + "not_null": false, + "ordinal": 16, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "acknowledgement_note", + "not_null": false, + "ordinal": 17, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": false, + "ordinal": 18, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": false, + "ordinal": 19, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_material_sha256", + "not_null": false, + "ordinal": 20, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_material_byte_count", + "not_null": false, + "ordinal": 21, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 22, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 23, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 24, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service_identity", + "not_null": false, + "ordinal": 25, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 26, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 27, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 28, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 29, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_actor_profile_id", + "not_null": false, + "ordinal": 30, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_via_identity_link_id", + "not_null": false, + "ordinal": 31, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_admin_role_grant_id", + "not_null": false, + "ordinal": 32, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_scope_type", + "not_null": false, + "ordinal": 33, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_scope_project_id", + "not_null": false, + "ordinal": 34, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_action_id", + "not_null": false, + "ordinal": 35, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_decision_event_id", + "not_null": false, + "ordinal": 36, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(3)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "code", + "not_null": true, + "ordinal": 1, + "table_name": "iso_4217_currency_codes" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 1, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_subject", + "not_null": true, + "ordinal": 2, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_issuer", + "not_null": true, + "ordinal": 3, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "display_name", + "not_null": false, + "ordinal": 4, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(320)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "email", + "not_null": false, + "ordinal": 5, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_seen_roles", + "not_null": true, + "ordinal": 6, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_claim_snapshot", + "not_null": true, + "ordinal": 7, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "auth_source", + "not_null": true, + "ordinal": 8, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "is_dev_auth", + "not_null": true, + "ordinal": 9, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "first_seen_at", + "not_null": true, + "ordinal": 10, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_seen_at", + "not_null": true, + "ordinal": 11, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 12, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 2, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "profile_type", + "not_null": true, + "ordinal": 3, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "skill_tags", + "not_null": true, + "ordinal": 5, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 6, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_id", + "not_null": true, + "ordinal": 7, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "profile_metadata", + "not_null": true, + "ordinal": 8, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 9, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 10, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_id", + "not_null": true, + "ordinal": 1, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_type", + "not_null": true, + "ordinal": 2, + "table_name": "outbox_events" + }, + { + "data_type": "smallint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_version", + "not_null": true, + "ordinal": 3, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "'workstream'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer", + "not_null": true, + "ordinal": 4, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "aggregate_type", + "not_null": true, + "ordinal": 5, + "table_name": "outbox_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "aggregate_id", + "not_null": true, + "ordinal": 6, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 7, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": true, + "ordinal": 8, + "table_name": "outbox_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "causation_event_id", + "not_null": false, + "ordinal": 9, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 10, + "table_name": "outbox_events" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payload", + "not_null": true, + "ordinal": 11, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payload_digest", + "not_null": true, + "ordinal": 12, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "occurred_at", + "not_null": true, + "ordinal": 13, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(16)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "delivery_state", + "not_null": true, + "ordinal": 14, + "table_name": "outbox_events" + }, + { + "data_type": "integer", + "default_expression": "0", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_count", + "not_null": true, + "ordinal": 15, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "next_attempt_at", + "not_null": false, + "ordinal": 16, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_owner", + "not_null": false, + "ordinal": 17, + "table_name": "outbox_events" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_generation", + "not_null": true, + "ordinal": 18, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claimed_at", + "not_null": false, + "ordinal": 19, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_expires_at", + "not_null": false, + "ordinal": 20, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_attempt_at", + "not_null": false, + "ordinal": 21, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_error_code", + "not_null": false, + "ordinal": 22, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "finalized_at", + "not_null": false, + "ordinal": 23, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archived_at", + "not_null": false, + "ordinal": 24, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "payment_policies" + }, + { + "data_type": "numeric(12,2)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "base_amount", + "not_null": false, + "ordinal": 4, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "currency", + "not_null": false, + "ordinal": 5, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payout_type", + "not_null": false, + "ordinal": 6, + "table_name": "payment_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revision_payment_rule", + "not_null": false, + "ordinal": 7, + "table_name": "payment_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "rejection_payment_rule", + "not_null": false, + "ordinal": 8, + "table_name": "payment_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "accepted_payment_rule", + "not_null": false, + "ordinal": 9, + "table_name": "payment_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "payment_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 7, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 8, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 9, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 10, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 11, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_id", + "not_null": true, + "ordinal": 12, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_generation", + "not_null": true, + "ordinal": 13, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 14, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 15, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 17, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_id", + "not_null": true, + "ordinal": 7, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_hash", + "not_null": true, + "ordinal": 8, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 9, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compiler_version", + "not_null": false, + "ordinal": 10, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compiled_bundle", + "not_null": false, + "ordinal": 11, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compiled_bundle_hash", + "not_null": false, + "ordinal": 12, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_names", + "not_null": true, + "ordinal": 13, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_configs", + "not_null": true, + "ordinal": 14, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 15, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_pre_submit_checker_policy_id", + "not_null": false, + "ordinal": 17, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 18, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 19, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 20, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 21, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 22, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 23, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 24, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_decision_event_id", + "not_null": false, + "ordinal": 25, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "evidence_set_id", + "not_null": true, + "ordinal": 2, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_order", + "not_null": true, + "ordinal": 3, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "schema_version", + "not_null": true, + "ordinal": 4, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "dispatch_authority", + "not_null": true, + "ordinal": 5, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "definition_id", + "not_null": true, + "ordinal": 6, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "definition_version", + "not_null": true, + "ordinal": 7, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "public_name", + "not_null": true, + "ordinal": 8, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source", + "not_null": true, + "ordinal": 9, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "phase", + "not_null": true, + "ordinal": 10, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification", + "not_null": true, + "ordinal": 11, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "severity", + "not_null": true, + "ordinal": 12, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 13, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_code", + "not_null": false, + "ordinal": 14, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "message_code", + "not_null": true, + "ordinal": 15, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_plan_sha256", + "not_null": true, + "ordinal": 16, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "rule_instance_id", + "not_null": false, + "ordinal": 17, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_policy_sha256", + "not_null": true, + "ordinal": 18, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 19, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_identity", + "not_null": true, + "ordinal": 2, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 4, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 5, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 6, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assignment_id", + "not_null": true, + "ordinal": 7, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_id", + "not_null": false, + "ordinal": 8, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_version", + "not_null": false, + "ordinal": 9, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "prepared_generation_id", + "not_null": true, + "ordinal": 10, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_sha256", + "not_null": true, + "ordinal": 11, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_byte_count", + "not_null": true, + "ordinal": 12, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_id", + "not_null": true, + "ordinal": 13, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_sha256", + "not_null": true, + "ordinal": 14, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 15, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 16, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 17, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_sha256", + "not_null": true, + "ordinal": 18, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_sha256", + "not_null": true, + "ordinal": 19, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_id", + "not_null": true, + "ordinal": 20, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_artifact_policy_sha256", + "not_null": true, + "ordinal": 21, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_policy_id", + "not_null": true, + "ordinal": 22, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_checker_policy_sha256", + "not_null": true, + "ordinal": 23, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_plan_sha256", + "not_null": true, + "ordinal": 24, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "catalogue_id", + "not_null": true, + "ordinal": 25, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "catalogue_version", + "not_null": true, + "ordinal": 26, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "catalogue_manifest_sha256", + "not_null": true, + "ordinal": 27, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "storage_scheme", + "not_null": true, + "ordinal": 28, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_status", + "not_null": true, + "ordinal": 29, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "eligible", + "not_null": true, + "ordinal": 30, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_count", + "not_null": true, + "ordinal": 31, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_manifest_sha256", + "not_null": true, + "ordinal": 32, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 33, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_policy_context_hash", + "not_null": true, + "ordinal": 34, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instrument_type", + "not_null": true, + "ordinal": 3, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter_actor_id", + "not_null": true, + "ordinal": 4, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "route_key", + "not_null": true, + "ordinal": 5, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_lifecycle_version", + "not_null": true, + "ordinal": 7, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 8, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 9, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_by", + "not_null": false, + "ordinal": 10, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_at", + "not_null": false, + "ordinal": 11, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 12, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 13, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 1, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instrument_type", + "not_null": true, + "ordinal": 2, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "unit_code", + "not_null": true, + "ordinal": 3, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(3)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "iso_currency_code", + "not_null": false, + "ordinal": 4, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 6, + "table_name": "project_compensation_units" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 8, + "table_name": "project_compensation_units" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 9, + "table_name": "project_compensation_units" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 7, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 8, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_generation", + "not_null": true, + "ordinal": 9, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 11, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 12, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": true, + "ordinal": 7, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 8, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_input_hash", + "not_null": true, + "ordinal": 9, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_material_hash", + "not_null": true, + "ordinal": 10, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_id", + "not_null": true, + "ordinal": 11, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_version", + "not_null": true, + "ordinal": 12, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_schema_version", + "not_null": true, + "ordinal": 13, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_manifest_hash", + "not_null": true, + "ordinal": 14, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_id", + "not_null": true, + "ordinal": 15, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_version", + "not_null": true, + "ordinal": 16, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_schema_version", + "not_null": true, + "ordinal": 17, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_manifest_hash", + "not_null": true, + "ordinal": 18, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_identity", + "not_null": true, + "ordinal": 19, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_version", + "not_null": true, + "ordinal": 20, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instruction_version", + "not_null": true, + "ordinal": 21, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_idempotency_key", + "not_null": true, + "ordinal": 22, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 23, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_result", + "not_null": false, + "ordinal": 24, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_hash", + "not_null": false, + "ordinal": 25, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "component_hashes", + "not_null": false, + "ordinal": 26, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_code", + "not_null": false, + "ordinal": 27, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "persisted_compilation_id", + "not_null": false, + "ordinal": 28, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "reserved_at", + "not_null": true, + "ordinal": 29, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_uncertain_at", + "not_null": false, + "ordinal": 30, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "accepted_at", + "not_null": false, + "ordinal": 31, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 32, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "persisted_at", + "not_null": false, + "ordinal": 33, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_guide_compilations" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 4, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 5, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 6, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 7, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": true, + "ordinal": 8, + "table_name": "project_guide_compilations" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 9, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_input_hash", + "not_null": true, + "ordinal": 10, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_material_hash", + "not_null": true, + "ordinal": 11, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_manifest_hash", + "not_null": true, + "ordinal": 12, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_manifest_hash", + "not_null": true, + "ordinal": 13, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_identity", + "not_null": true, + "ordinal": 14, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_version", + "not_null": true, + "ordinal": 15, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instruction_version", + "not_null": true, + "ordinal": 16, + "table_name": "project_guide_compilations" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_result", + "not_null": true, + "ordinal": 17, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_hash", + "not_null": true, + "ordinal": 18, + "table_name": "project_guide_compilations" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "component_hashes", + "not_null": true, + "ordinal": 19, + "table_name": "project_guide_compilations" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_compilation_id", + "not_null": false, + "ordinal": 20, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": true, + "ordinal": 21, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": true, + "ordinal": 22, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service_identity", + "not_null": true, + "ordinal": 23, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": true, + "ordinal": 24, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": true, + "ordinal": 25, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_resource_context_digest", + "not_null": true, + "ordinal": 26, + "table_name": "project_guide_compilations" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 27, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_guides" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 3, + "table_name": "project_guides" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "project_guides" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_markdown", + "not_null": true, + "ordinal": 5, + "table_name": "project_guides" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by", + "not_null": false, + "ordinal": 6, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_at", + "not_null": false, + "ordinal": 7, + "table_name": "project_guides" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "change_summary", + "not_null": false, + "ordinal": 8, + "table_name": "project_guides" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 9, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 11, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 12, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutated_by_actor_profile_id", + "not_null": false, + "ordinal": 13, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutated_via_identity_link_id", + "not_null": false, + "ordinal": 14, + "table_name": "project_guides" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutated_by_admin_role_grant_id", + "not_null": false, + "ordinal": 15, + "table_name": "project_guides" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutation_scope_type", + "not_null": false, + "ordinal": 16, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutation_scope_project_id", + "not_null": false, + "ordinal": 17, + "table_name": "project_guides" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutation_action_id", + "not_null": false, + "ordinal": 18, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_authorization_decision_event_id", + "not_null": false, + "ordinal": 19, + "table_name": "project_guides" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "mutation_generation", + "not_null": false, + "ordinal": 20, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_review_policy_id", + "not_null": false, + "ordinal": 21, + "table_name": "project_guides" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_review_policy_hash", + "not_null": false, + "ordinal": 22, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_revision_policy_id", + "not_null": false, + "ordinal": 23, + "table_name": "project_guides" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_revision_policy_hash", + "not_null": false, + "ordinal": 24, + "table_name": "project_guides" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_review_policy_generation", + "not_null": false, + "ordinal": 25, + "table_name": "project_guides" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_revision_policy_generation", + "not_null": false, + "ordinal": 26, + "table_name": "project_guides" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "role", + "not_null": true, + "ordinal": 4, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "project_role_grants" + }, + { + "data_type": "smallint", + "default_expression": "'1'::smallint", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 6, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "'manual'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "grant_method", + "not_null": true, + "ordinal": 7, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "qualification_snapshot_id", + "not_null": true, + "ordinal": 8, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_actor_profile_id", + "not_null": true, + "ordinal": 9, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_admin_role_grant_id", + "not_null": true, + "ordinal": 10, + "table_name": "project_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "grant_reason", + "not_null": true, + "ordinal": 11, + "table_name": "project_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_at", + "not_null": true, + "ordinal": 12, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_actor_profile_id", + "not_null": false, + "ordinal": 13, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_admin_role_grant_id", + "not_null": false, + "ordinal": 14, + "table_name": "project_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_reason", + "not_null": false, + "ordinal": 15, + "table_name": "project_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_at", + "not_null": false, + "ordinal": 16, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requested_role", + "not_null": true, + "ordinal": 4, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "skills_snapshot", + "not_null": true, + "ordinal": 5, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reputation_snapshot", + "not_null": true, + "ordinal": 6, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "prior_project_work_refs", + "not_null": true, + "ordinal": 7, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_expertise_refs", + "not_null": true, + "ordinal": 8, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_by_actor_profile_id", + "not_null": true, + "ordinal": 9, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_by_admin_role_grant_id", + "not_null": true, + "ordinal": 10, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_at", + "not_null": true, + "ordinal": 11, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(155)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "celery_task_id", + "not_null": false, + "ordinal": 7, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 8, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "current_step", + "not_null": true, + "ordinal": 9, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_sufficiency_report_id", + "not_null": false, + "ordinal": 10, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_submission_artifact_policy_id", + "not_null": false, + "ordinal": 11, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_code", + "not_null": false, + "ordinal": 12, + "table_name": "project_setup_runs" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_summary", + "not_null": false, + "ordinal": 13, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 14, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 15, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 16, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "started_at", + "not_null": false, + "ordinal": 17, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "finished_at", + "not_null": false, + "ordinal": 18, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 19, + "table_name": "project_setup_runs" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_submit_derivation_summary", + "not_null": false, + "ordinal": 20, + "table_name": "project_setup_runs" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 21, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorized_by_actor_profile_id", + "not_null": false, + "ordinal": 22, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorized_via_identity_link_id", + "not_null": false, + "ordinal": 23, + "table_name": "project_setup_runs" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorized_by_admin_role_grant_id", + "not_null": false, + "ordinal": 24, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_scope_type", + "not_null": false, + "ordinal": 25, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_scope_project_id", + "not_null": false, + "ordinal": 26, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_action_id", + "not_null": false, + "ordinal": 27, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 28, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_artifact_incident_id", + "not_null": false, + "ordinal": 29, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "continuation_verification_job_id", + "not_null": false, + "ordinal": 30, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "continuation_started_at", + "not_null": false, + "ordinal": 31, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "projects" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "name", + "not_null": true, + "ordinal": 2, + "table_name": "projects" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "slug", + "not_null": true, + "ordinal": 3, + "table_name": "projects" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "description", + "not_null": false, + "ordinal": 4, + "table_name": "projects" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "projects" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 6, + "table_name": "projects" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 7, + "table_name": "projects" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 8, + "table_name": "projects" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 9, + "table_name": "projects" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 10, + "table_name": "projects" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 11, + "table_name": "projects" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 12, + "table_name": "projects" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 13, + "table_name": "projects" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 2, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 3, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 4, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 5, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 6, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 7, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 8, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "admitting_checker_run_id", + "not_null": true, + "ordinal": 9, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_queue_entry_id", + "not_null": false, + "ordinal": 11, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 12, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 13, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_leases" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_queue_entry_id", + "not_null": true, + "ordinal": 2, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 4, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 5, + "table_name": "review_leases" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 6, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reviewer_id", + "not_null": true, + "ordinal": 7, + "table_name": "review_leases" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reviewer_contribution_policy_version_id", + "not_null": true, + "ordinal": 8, + "table_name": "review_leases" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_generation", + "not_null": true, + "ordinal": 9, + "table_name": "review_leases" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "review_leases" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "claimed_at", + "not_null": true, + "ordinal": 11, + "table_name": "review_leases" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "expires_at", + "not_null": true, + "ordinal": 12, + "table_name": "review_leases" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "closed_at", + "not_null": false, + "ordinal": 13, + "table_name": "review_leases" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "close_reason", + "not_null": false, + "ordinal": 14, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "review_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "review_policies" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requires_second_review", + "not_null": true, + "ordinal": 4, + "table_name": "review_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "allowed_decisions", + "not_null": true, + "ordinal": 5, + "table_name": "review_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "minimum_finding_fields", + "not_null": true, + "ordinal": 6, + "table_name": "review_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_generation", + "not_null": true, + "ordinal": 8, + "table_name": "review_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 9, + "table_name": "review_policies" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantics_status", + "not_null": true, + "ordinal": 10, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 11, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_preference_window_seconds", + "not_null": false, + "ordinal": 12, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_lease_duration_seconds", + "not_null": false, + "ordinal": 13, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "max_active_review_leases_per_reviewer", + "not_null": false, + "ordinal": 14, + "table_name": "review_policies" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "self_review_allowed", + "not_null": false, + "ordinal": 15, + "table_name": "review_policies" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reject_policy", + "not_null": false, + "ordinal": 16, + "table_name": "review_policies" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "finding_evidence_requirement", + "not_null": false, + "ordinal": 17, + "table_name": "review_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_policy_hash", + "not_null": false, + "ordinal": 18, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 19, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 20, + "table_name": "review_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 21, + "table_name": "review_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 22, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 23, + "table_name": "review_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 24, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 25, + "table_name": "review_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 3, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 4, + "table_name": "review_queue_entries" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 5, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "admitting_checker_run_id", + "not_null": true, + "ordinal": 6, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(16)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "queue_state", + "not_null": true, + "ordinal": 7, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_mode", + "not_null": true, + "ordinal": 8, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_reason", + "not_null": true, + "ordinal": 9, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "first_queued_at", + "not_null": true, + "ordinal": 10, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "available_since", + "not_null": true, + "ordinal": 11, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "preferred_reviewer_id", + "not_null": false, + "ordinal": 12, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "preference_expires_at", + "not_null": false, + "ordinal": 13, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "closed_at", + "not_null": false, + "ordinal": 14, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "closed_reason", + "not_null": false, + "ordinal": 15, + "table_name": "review_queue_entries" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_generation", + "not_null": true, + "ordinal": 16, + "table_name": "review_queue_entries" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_generation", + "not_null": true, + "ordinal": 17, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 18, + "table_name": "review_queue_entries" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "active_lease_id", + "not_null": false, + "ordinal": 19, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "revision_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "max_revision_rounds", + "not_null": true, + "ordinal": 4, + "table_name": "revision_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revision_deadline_hours", + "not_null": true, + "ordinal": 5, + "table_name": "revision_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "allowed_resubmission_states", + "not_null": true, + "ordinal": 6, + "table_name": "revision_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reviewer_reassignment_rule", + "not_null": false, + "ordinal": 7, + "table_name": "revision_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 8, + "table_name": "revision_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_generation", + "not_null": true, + "ordinal": 9, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 10, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantics_status", + "not_null": true, + "ordinal": 11, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 12, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_policy_hash", + "not_null": false, + "ordinal": 13, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 14, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 15, + "table_name": "revision_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 16, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 17, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 18, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 19, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 20, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 7, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 8, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_body", + "not_null": true, + "ordinal": 9, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 10, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "derivation_source", + "not_null": true, + "ordinal": 11, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_material_refs", + "not_null": true, + "ordinal": 12, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "derivation_agent_name", + "not_null": false, + "ordinal": 13, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "derivation_agent_version", + "not_null": false, + "ordinal": 14, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 15, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 17, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_role", + "not_null": false, + "ordinal": 18, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_actor", + "not_null": false, + "ordinal": 19, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_at", + "not_null": false, + "ordinal": 20, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 21, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 22, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "change_summary", + "not_null": false, + "ordinal": 23, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 24, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 25, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 26, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service_identity", + "not_null": false, + "ordinal": 27, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 28, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 29, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 30, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_decision_event_id", + "not_null": false, + "ordinal": 31, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_actor_profile_id", + "not_null": false, + "ordinal": 32, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_via_identity_link_id", + "not_null": false, + "ordinal": 33, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_admin_role_grant_id", + "not_null": false, + "ordinal": 34, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_scope_type", + "not_null": false, + "ordinal": 35, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_scope_project_id", + "not_null": false, + "ordinal": 36, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_action_id", + "not_null": false, + "ordinal": 37, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_decision_event_id", + "not_null": false, + "ordinal": 38, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "durable_intent_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_evidence_set_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 4, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_content_id", + "not_null": true, + "ordinal": 5, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 6, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verification_receipt_id", + "not_null": true, + "ordinal": 7, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_operation_receipt_id", + "not_null": false, + "ordinal": 8, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_observation_receipt_id", + "not_null": false, + "ordinal": 9, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 10, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 11, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 12, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 13, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assignment_id", + "not_null": true, + "ordinal": 14, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_id", + "not_null": false, + "ordinal": 15, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_version", + "not_null": false, + "ordinal": 16, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_policy_context_hash", + "not_null": true, + "ordinal": 17, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_id", + "not_null": true, + "ordinal": 18, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_sha256", + "not_null": true, + "ordinal": 19, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_sha256", + "not_null": true, + "ordinal": 20, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_byte_count", + "not_null": true, + "ordinal": 21, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(16)", + "default_expression": "'ready'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 22, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "ready_at", + "not_null": true, + "ordinal": 23, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "consumed_at", + "not_null": false, + "ordinal": 24, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "consumed_by_submission_id", + "not_null": false, + "ordinal": 25, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "stale_at", + "not_null": false, + "ordinal": 26, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "stale_reason", + "not_null": false, + "ordinal": 27, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 28, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_evidence_set_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 4, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity", + "not_null": false, + "ordinal": 4, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 5, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": false, + "ordinal": 6, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 7, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 8, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_json", + "not_null": true, + "ordinal": 9, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 10, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 11, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 12, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 13, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_id", + "not_null": true, + "ordinal": 14, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": false, + "ordinal": 15, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 16, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_task_id", + "not_null": false, + "ordinal": 17, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": false, + "ordinal": 18, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 19, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 20, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_policy_id", + "not_null": false, + "ordinal": 21, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_effective_policy_id", + "not_null": false, + "ordinal": 22, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_pre_submit_policy_id", + "not_null": false, + "ordinal": 23, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 24, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 25, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 2, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contributor_id", + "not_null": true, + "ordinal": 3, + "table_name": "submissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 4, + "table_name": "submissions" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "submissions" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "summary", + "not_null": true, + "ordinal": 6, + "table_name": "submissions" + }, + { + "data_type": "character varying(1000)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "package_uri", + "not_null": false, + "ordinal": 7, + "table_name": "submissions" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "package_hash", + "not_null": true, + "ordinal": 8, + "table_name": "submissions" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_hash_manifest", + "not_null": true, + "ordinal": 9, + "table_name": "submissions" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_attestation", + "not_null": true, + "ordinal": 10, + "table_name": "submissions" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_version", + "not_null": true, + "ordinal": 11, + "table_name": "submissions" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_payment_policy_version", + "not_null": true, + "ordinal": 12, + "table_name": "submissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "submitted_at", + "not_null": true, + "ordinal": 13, + "table_name": "submissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_at", + "not_null": false, + "ordinal": 14, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_submission_id", + "not_null": false, + "ordinal": 15, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_id", + "not_null": false, + "ordinal": 16, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_hash", + "not_null": false, + "ordinal": 17, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_id", + "not_null": false, + "ordinal": 18, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_hash", + "not_null": false, + "ordinal": 19, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_policy_id", + "not_null": false, + "ordinal": 20, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_bundle_hash", + "not_null": false, + "ordinal": 21, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 22, + "table_name": "submissions" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_version", + "not_null": false, + "ordinal": 23, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_hash", + "not_null": false, + "ordinal": 24, + "table_name": "submissions" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_body", + "not_null": false, + "ordinal": 25, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_id", + "not_null": true, + "ordinal": 26, + "table_name": "submissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_generation", + "not_null": true, + "ordinal": 27, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_hash", + "not_null": true, + "ordinal": 28, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_id", + "not_null": true, + "ordinal": 29, + "table_name": "submissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_generation", + "not_null": true, + "ordinal": 30, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_hash", + "not_null": true, + "ordinal": 31, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 2, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contributor_id", + "not_null": true, + "ordinal": 3, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assigned_by", + "not_null": true, + "ordinal": 4, + "table_name": "task_assignments" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "assigned_at", + "not_null": true, + "ordinal": 5, + "table_name": "task_assignments" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "accepted_at", + "not_null": false, + "ordinal": 6, + "table_name": "task_assignments" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "released_at", + "not_null": false, + "ordinal": 7, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 8, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_version", + "not_null": false, + "ordinal": 3, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_payment_policy_version", + "not_null": false, + "ordinal": 4, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_type", + "not_null": true, + "ordinal": 5, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_ref", + "not_null": false, + "ordinal": 6, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_payload_hash", + "not_null": false, + "ordinal": 7, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "import_batch_id", + "not_null": false, + "ordinal": 8, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_task_id", + "not_null": false, + "ordinal": 9, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(300)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "title", + "not_null": true, + "ordinal": 10, + "table_name": "workstream_tasks" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "description", + "not_null": true, + "ordinal": 11, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_type", + "not_null": false, + "ordinal": 12, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "difficulty", + "not_null": false, + "ordinal": 13, + "table_name": "workstream_tasks" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "skill_tags", + "not_null": true, + "ordinal": 14, + "table_name": "workstream_tasks" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "estimated_time_minutes", + "not_null": false, + "ordinal": 15, + "table_name": "workstream_tasks" + }, + { + "data_type": "numeric(12,2)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "base_amount", + "not_null": false, + "ordinal": 16, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "currency", + "not_null": false, + "ordinal": 17, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payout_type", + "not_null": false, + "ordinal": 18, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 19, + "table_name": "workstream_tasks" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "acceptance_criteria", + "not_null": false, + "ordinal": 20, + "table_name": "workstream_tasks" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "rejection_criteria", + "not_null": false, + "ordinal": 21, + "table_name": "workstream_tasks" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deadline_at", + "not_null": false, + "ordinal": 22, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 23, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assigned_to", + "not_null": false, + "ordinal": 24, + "table_name": "workstream_tasks" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 25, + "table_name": "workstream_tasks" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 26, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_id", + "not_null": false, + "ordinal": 27, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_hash", + "not_null": false, + "ordinal": 28, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_id", + "not_null": false, + "ordinal": 29, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_hash", + "not_null": false, + "ordinal": 30, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_policy_id", + "not_null": false, + "ordinal": 31, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_bundle_hash", + "not_null": false, + "ordinal": 32, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 33, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_version", + "not_null": false, + "ordinal": 34, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_hash", + "not_null": false, + "ordinal": 35, + "table_name": "workstream_tasks" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_body", + "not_null": false, + "ordinal": 36, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_id", + "not_null": false, + "ordinal": 37, + "table_name": "workstream_tasks" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_generation", + "not_null": false, + "ordinal": 38, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_hash", + "not_null": false, + "ordinal": 39, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_id", + "not_null": false, + "ordinal": 40, + "table_name": "workstream_tasks" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_generation", + "not_null": false, + "ordinal": 41, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_hash", + "not_null": false, + "ordinal": 42, + "table_name": "workstream_tasks" + } + ], + "constraints": [ + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "actor_identity_link_profile_guard", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (subject_kind::text = 'service'::text OR last_verified_at IS NOT NULL)", + "kind": "c", + "name": "ck_actor_identity_links_human_verified", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_actor_identity_links_id_uuid", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (length(btrim(issuer::text)) >= 1 AND length(btrim(issuer::text)) <= 200)", + "kind": "c", + "name": "ck_actor_identity_links_issuer", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK ((revoked_reason IS NULL OR revoked_reason::text = btrim(revoked_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(revoked_reason::text) >= 1 AND octet_length(revoked_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500))", + "kind": "c", + "name": "ck_actor_identity_links_lifecycle_reason_bounds", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_identity_links_reactivation_fields", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (status::text = 'active'::text AND revoked_by IS NULL AND revoked_at IS NULL AND revoked_reason IS NULL OR status::text = 'revoked'::text AND revoked_by IS NOT NULL AND revoked_at IS NOT NULL AND revoked_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_identity_links_revocation_fields", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'revoked']))", + "kind": "c", + "name": "ck_actor_identity_links_status", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (length(btrim(subject::text)) >= 1 AND length(btrim(subject::text)) <= 200)", + "kind": "c", + "name": "ck_actor_identity_links_subject", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (subject_kind::text = ANY (ARRAY['human', 'service']))", + "kind": "c", + "name": "ck_actor_identity_links_subject_kind", + "table_name": "actor_identity_links" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_actor_identity_links_actor_profile_id_actor_profiles", + "table_name": "actor_identity_links" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_actor_identity_links", + "table_name": "actor_identity_links" + }, + { + "definition": "UNIQUE (actor_profile_id)", + "kind": "u", + "name": "uq_actor_identity_links_actor_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "UNIQUE (issuer, subject)", + "kind": "u", + "name": "uq_actor_identity_links_external_identity", + "table_name": "actor_identity_links" + }, + { + "definition": "UNIQUE (id, actor_profile_id)", + "kind": "u", + "name": "uq_actor_identity_links_id_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (classified_count = 0 AND manifest_sha256 IS NULL AND envelope_sha256 IS NULL OR classified_count > 0 AND manifest_sha256 IS NOT NULL AND envelope_sha256 IS NOT NULL)", + "kind": "c", + "name": "ck_actor_profile_migration_state_evidence", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CHECK (service_identity_mapped_count >= 0 AND service_identity_mapped_count <= 7 AND service_identity_source_row_set_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_database_binding::text ~ '^postgres-v1:[0-9a-f]{64}$'::text AND (service_identity_mapped_count = 0 AND service_identity_manifest_sha256 IS NULL AND service_identity_envelope_sha256 IS NULL OR service_identity_mapped_count >= 1 AND service_identity_mapped_count <= 7 AND service_identity_manifest_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_envelope_sha256::text ~ '^[0-9a-f]{64}$'::text))", + "kind": "c", + "name": "ck_actor_profile_migration_state_service_identity_evidence", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CHECK (id = 1 AND schema_version = 1 AND classified_count >= 0)", + "kind": "c", + "name": "ck_actor_profile_migration_state_singleton", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_actor_profile_migration_state", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "actor_profile_link_guard", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (actor_kind::text = ANY (ARRAY['human', 'service']))", + "kind": "c", + "name": "ck_actor_profiles_actor_kind", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_actor_profiles_id_uuid", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (actor_kind::text = 'human'::text AND provisioning_method::text = 'automatic_first_access'::text OR actor_kind::text = 'service'::text AND provisioning_method::text = 'manual_service_provisioning'::text)", + "kind": "c", + "name": "ck_actor_profiles_kind_provisioning", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (actor_kind::text = 'human'::text AND service_identity IS NULL OR actor_kind::text = 'service'::text AND (service_identity::text = ANY (ARRAY['workstream.artifact.verifier', 'workstream.artifact.put_resolver', 'workstream.artifact.scheduler', 'workstream.artifact.binding', 'workstream.artifact.guide_reader', 'workstream.artifact.materializer', 'workstream.artifact.checker_output', 'workstream.project.setup', 'workstream.review.preference_expiry', 'workstream.review.lease_expiry', 'workstream.review.authority_invalidation_reconciliation', 'workstream.review.reconciliation', 'workstream.review.artifact_reference_reconciliation', 'workstream.review.projection'])))", + "kind": "c", + "name": "ck_actor_profiles_kind_service_identity", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (status::text = 'active'::text AND suspended_by IS NULL AND suspended_at IS NULL AND suspension_reason IS NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'suspended'::text AND suspended_by IS NOT NULL AND suspended_at IS NOT NULL AND suspension_reason IS NOT NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'deactivated'::text AND deactivated_by IS NOT NULL AND deactivated_at IS NOT NULL AND deactivation_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_profiles_lifecycle_fields", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK ((suspension_reason IS NULL OR suspension_reason::text = btrim(suspension_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(suspension_reason::text) >= 1 AND octet_length(suspension_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500) AND (deactivation_reason IS NULL OR deactivation_reason::text = btrim(deactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(deactivation_reason::text) >= 1 AND octet_length(deactivation_reason::text) <= 500))", + "kind": "c", + "name": "ck_actor_profiles_lifecycle_reason_bounds", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (provisioning_method::text = ANY (ARRAY['automatic_first_access', 'manual_service_provisioning']))", + "kind": "c", + "name": "ck_actor_profiles_provisioning_method", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_profiles_reactivation_fields", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'deactivated']))", + "kind": "c", + "name": "ck_actor_profiles_status", + "table_name": "actor_profiles" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_actor_profiles", + "table_name": "actor_profiles" + }, + { + "definition": "UNIQUE (service_identity)", + "kind": "u", + "name": "service_identity", + "table_name": "actor_profiles" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "admin_role_grants_bootstrap_invariant", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (granted_by_system_principal::text = 'workstream:system:bootstrap'::text AND granted_by_actor_profile_id IS NULL AND granted_by_admin_role_grant_id IS NULL OR granted_by_system_principal IS NULL AND granted_by_actor_profile_id IS NOT NULL AND granted_by_admin_role_grant_id IS NOT NULL)", + "kind": "c", + "name": "ck_admin_role_grants_grant_attribution", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (octet_length(grant_reason) >= 1 AND octet_length(grant_reason) <= 500)", + "kind": "c", + "name": "ck_admin_role_grants_grant_reason", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND octet_length(revoked_reason) >= 1 AND octet_length(revoked_reason) <= 500 AND revoked_at IS NOT NULL)", + "kind": "c", + "name": "ck_admin_role_grants_lifecycle", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (role::text = ANY (ARRAY['access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority']))", + "kind": "c", + "name": "ck_admin_role_grants_role", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (scope_type::text = 'system'::text AND scope_project_id IS NULL OR scope_type::text = 'project'::text AND scope_project_id IS NOT NULL AND (role::text <> ALL (ARRAY['access_administrator', 'operator'])))", + "kind": "c", + "name": "ck_admin_role_grants_role_scope", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (scope_type::text = ANY (ARRAY['system', 'project']))", + "kind": "c", + "name": "ck_admin_role_grants_scope_type", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_admin_role_grants_granted_by_admin_role_grant_id_adm_81e0", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_admin_role_grants_revoked_by_admin_role_grant_id_adm_78b5", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_admin_role_grants_scope_project_id_projects", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (target_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_admin_role_grants_target_actor_profile_id_actor_profiles", + "table_name": "admin_role_grants" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_admin_role_grants", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (octet_length(key_digest) = 32)", + "kind": "c", + "name": "ck_api_rate_control_counters_digest_length", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (request_count >= 1 AND request_count <= '9223372036854775807'::bigint)", + "kind": "c", + "name": "ck_api_rate_control_counters_request_count", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (control_scope::text = ANY (ARRAY['first_access', 'admin_mutation', 'authorization_read']))", + "kind": "c", + "name": "ck_api_rate_control_counters_scope_token", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (window_started_at < window_expires_at)", + "kind": "c", + "name": "ck_api_rate_control_counters_window_order", + "table_name": "api_rate_control_counters" + }, + { + "definition": "PRIMARY KEY (control_scope, key_digest)", + "kind": "p", + "name": "pk_api_rate_control_counters", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_admission_charges_byte_count_nonnegative", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_admission_charges_cas_nonnegative", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK ((state::text = 'completed'::text) = (completed_at IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_admission_charges_completed_timestamp", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (creating_operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_admission_charges_operation_identity_shape", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", + "kind": "c", + "name": "ck_artifact_admission_charges_producer_type", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK ((state::text = 'released'::text) = (released_at IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_admission_charges_released_timestamp", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_admission_charges_sha256_shape", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (state::text = ANY (ARRAY['provisional', 'completed', 'released']))", + "kind": "c", + "name": "ck_artifact_admission_charges_state", + "table_name": "artifact_admission_charges" + }, + { + "definition": "FOREIGN KEY (scope_type, scope_id) REFERENCES artifact_admission_scopes(scope_type, scope_id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_admission_charges_scope", + "table_name": "artifact_admission_charges" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_admission_charges", + "table_name": "artifact_admission_charges" + }, + { + "definition": "UNIQUE (scope_type, scope_id, sha256, byte_count)", + "kind": "u", + "name": "uq_artifact_admission_charge_scope_content", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_admission_scopes_cas_nonnegative", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (counted_bytes >= 0 AND counted_bytes <= limit_bytes)", + "kind": "c", + "name": "ck_artifact_admission_scopes_counted_bytes_within_limit", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (limit_bytes > 0)", + "kind": "c", + "name": "ck_artifact_admission_scopes_limit_positive", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (octet_length(scope_id::text) >= 1 AND octet_length(scope_id::text) <= 120)", + "kind": "c", + "name": "ck_artifact_admission_scopes_scope_id_bounds", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (scope_type::text = ANY (ARRAY['deployment', 'project', 'producer', 'task']))", + "kind": "c", + "name": "ck_artifact_admission_scopes_scope_type", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "PRIMARY KEY (scope_type, scope_id)", + "kind": "p", + "name": "pk_artifact_admission_scopes", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (scope_version > 0)", + "kind": "c", + "name": "ck_artifact_bindings_scope_version_positive", + "table_name": "artifact_bindings" + }, + { + "definition": "CHECK (scope_version = 1 AND supersedes_binding_id IS NULL OR scope_version > 1 AND supersedes_binding_id IS NOT NULL)", + "kind": "c", + "name": "ck_artifact_bindings_scope_version_predecessor", + "table_name": "artifact_bindings" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_bindings_content_id_artifact_contents", + "table_name": "artifact_bindings" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_bindings_project_id_projects", + "table_name": "artifact_bindings" + }, + { + "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES artifact_bindings(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_bindings_supersedes_binding_id_artifact_bindings", + "table_name": "artifact_bindings" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_bindings", + "table_name": "artifact_bindings" + }, + { + "definition": "TRIGGER DEFERRABLE", + "kind": "t", + "name": "trg_artifact_binding_history", + "table_name": "artifact_bindings" + }, + { + "definition": "UNIQUE (project_id, resource_type, resource_id, logical_role, scope_version)", + "kind": "u", + "name": "uq_artifact_binding_scope_version", + "table_name": "artifact_bindings" + }, + { + "definition": "UNIQUE (supersedes_binding_id)", + "kind": "u", + "name": "uq_artifact_binding_supersedes", + "table_name": "artifact_bindings" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_contents_byte_count_nonnegative", + "table_name": "artifact_contents" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_contents_sha256_shape", + "table_name": "artifact_contents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_contents", + "table_name": "artifact_contents" + }, + { + "definition": "UNIQUE (sha256, byte_count)", + "kind": "u", + "name": "uq_artifact_content_digest_size", + "table_name": "artifact_contents" + }, + { + "definition": "CHECK (attempt_number > 0)", + "kind": "c", + "name": "ck_artifact_operation_receipts_attempt_positive", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (contract_version = 2 AND put_attempt_id IS NOT NULL AND (guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND logical_role IS NULL OR guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR guide_source_item_id IS NULL AND checker_run_id IS NULL AND logical_role IS NULL))", + "kind": "c", + "name": "ck_artifact_operation_receipts_contract_producer_reference", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (operation::text = 'put'::text)", + "kind": "c", + "name": "ck_artifact_operation_receipts_operation", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (outcome::text = 'stored_pending_verification'::text)", + "kind": "c", + "name": "ck_artifact_operation_receipts_outcome", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_operation_receipts_request_digest_shape", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_operation_receipts_replica_id_artifact_replicas", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_receipt_checker_run", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_receipt_guide_item", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_receipt_put_attempt", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_operation_receipts", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "UNIQUE (put_attempt_id)", + "kind": "u", + "name": "uq_artifact_receipt_put_attempt", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempt_charges_attempt_id_artifact_put_b25d", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "FOREIGN KEY (charge_id) REFERENCES artifact_admission_charges(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempt_charges_charge_id_artifact_admi_85a9", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "PRIMARY KEY (attempt_id, charge_id)", + "kind": "p", + "name": "pk_artifact_put_attempt_charges", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_put_attempts_byte_count_nonnegative", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (canonical_target::text ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_canonical_target_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (execution_mode IS NULL OR (execution_mode::text = ANY (ARRAY['caller_put', 'observation'])))", + "kind": "c", + "name": "ck_artifact_put_attempts_execution_mode", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", + "kind": "c", + "name": "ck_artifact_put_attempts_executor_lease_pair", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK ((status::text = 'put_in_flight'::text) = (executor_id IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_put_attempts_inflight_fence", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (observation_count >= 0 AND maximum_observations > 0)", + "kind": "c", + "name": "ck_artifact_put_attempts_observation_counts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_operation_identity_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (status::text <> 'prepared'::text OR next_run_at IS NULL AND executor_id IS NULL AND lease_expires_at IS NULL AND execution_generation = 0 AND terminal_result_code IS NULL AND terminal_at IS NULL AND replica_id IS NULL AND receipt_id IS NULL)", + "kind": "c", + "name": "ck_artifact_put_attempts_prepared_execution_inactive", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_request_type::text = 'guide'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text OR producer_request_type::text = 'checker_output'::text AND producer_type::text = 'service_identity'::text AND producer_ref::text = 'workstream.artifact.checker_output'::text OR producer_request_type::text = 'submission_bundle'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_identity", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_request_type::text = 'guide'::text AND guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND task_id IS NULL AND logical_role IS NULL OR producer_request_type::text = 'checker_output'::text AND guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND task_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR producer_request_type::text = 'submission_bundle'::text AND guide_source_item_id IS NULL AND checker_run_id IS NULL AND task_id IS NOT NULL AND logical_role IS NULL)", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_reference", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_request_type::text = ANY (ARRAY['guide', 'checker_output', 'submission_bundle']))", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_request_type", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_type", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_request_digest_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_sha256_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['prepared', 'put_in_flight', 'acknowledgement_unknown', 'object_confirmed', 'absent_replay_required', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", + "kind": "c", + "name": "ck_artifact_put_attempts_status", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (status::text <> 'provider_unavailable'::text OR observation_count >= maximum_observations AND next_run_at IS NULL AND terminal_at IS NOT NULL)", + "kind": "c", + "name": "ck_artifact_put_attempts_unavailable_exhausted", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_put_attempts_versions_nonnegative", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_checker_run_id_checker_runs", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_guide_source_item_id_guide_sou_e48c", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (storage_namespace_id, namespace_fingerprint) REFERENCES artifact_storage_namespaces(id, namespace_fingerprint) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_namespace_fingerprint", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_project_id_projects", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_receipt_id_artifact_operation_receipts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_replica_id_artifact_replicas", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_task_id_workstream_tasks", + "table_name": "artifact_put_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_put_attempts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "UNIQUE (operation_identity)", + "kind": "u", + "name": "uq_artifact_put_attempt_operation", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (expected_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_expected_sha256", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (expected_byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_expected_size", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK ((outcome::text = ANY (ARRAY['observed_confirmed', 'observed_integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_observed_facts", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_observed_sha256", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_observed_size", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (outcome::text = ANY (ARRAY['observed_confirmed', 'observed_missing', 'observed_integrity_mismatch', 'conflict']))", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_outcome", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_observation_receipts_put_attempt_id_art_237d", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_put_observation_receipts", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "UNIQUE (put_attempt_id, execution_generation)", + "kind": "u", + "name": "uq_artifact_put_observation_fence", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_cas_nonnegative", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (source_verification_job_id::text <> retry_verification_job_id::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_distinct_jobs", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (recovery_class::text = 'provider_observation'::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_recovery_class", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_request_digest", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['requested', 'succeeded', 'failed']))", + "kind": "c", + "name": "ck_artifact_recovery_attempts_status", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (status::text = 'succeeded'::text AND terminal_result_code::text = 'verified'::text OR status::text = 'failed'::text AND (terminal_result_code::text = ANY (ARRAY['provider_unavailable', 'missing', 'integrity_mismatch', 'conflict'])) OR status::text = 'requested'::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_terminal_result", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (status::text = 'requested'::text AND terminal_result_code IS NULL AND terminal_at IS NULL AND terminal_audit_event_id IS NULL OR (status::text = ANY (ARRAY['succeeded', 'failed'])) AND terminal_result_code IS NOT NULL AND terminal_at IS NOT NULL AND terminal_audit_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_terminal_shape", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (initiation_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_initiation_audit_event_id_2af7", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (parent_recovery_attempt_id) REFERENCES artifact_recovery_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_parent_recovery_attempt_i_130d", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_project_id_projects", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (requester_actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_requester_actor_profile_i_77f5", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (requester_identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_requester_identity_link_i_3619", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (retry_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_retry_verification_job_id_b330", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (source_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_source_verification_job_i_5eac", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_submission_id_submissions", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_task_id_workstream_tasks", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (terminal_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_terminal_audit_event_id_a_47ab", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_recovery_attempts", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "UNIQUE (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", + "kind": "u", + "name": "uq_artifact_recovery_idempotency", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "UNIQUE (retry_verification_job_id)", + "kind": "u", + "name": "uq_artifact_recovery_retry_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "UNIQUE (source_verification_job_id)", + "kind": "u", + "name": "uq_artifact_recovery_source_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (availability_state::text = ANY (ARRAY['unknown', 'available', 'unavailable']))", + "kind": "c", + "name": "ck_artifact_replicas_availability_state", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_replicas_fingerprint_shape", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (integrity_state::text = ANY (ARRAY['unknown', 'valid', 'invalid']))", + "kind": "c", + "name": "ck_artifact_replicas_integrity_state", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (verification_state::text = ANY (ARRAY['pending', 'verified', 'missing', 'integrity_mismatch']))", + "kind": "c", + "name": "ck_artifact_replicas_verification_state", + "table_name": "artifact_replicas" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_replicas_content_id_artifact_contents", + "table_name": "artifact_replicas" + }, + { + "definition": "FOREIGN KEY (storage_namespace_id) REFERENCES artifact_storage_namespaces(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_replicas_storage_namespace_id_artifact_stor_d6cc", + "table_name": "artifact_replicas" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_replicas", + "table_name": "artifact_replicas" + }, + { + "definition": "UNIQUE (storage_namespace_id, provider_object_ref)", + "kind": "u", + "name": "uq_artifact_replica_provider_object", + "table_name": "artifact_replicas" + }, + { + "definition": "UNIQUE (id, content_id)", + "kind": "u", + "name": "uq_artifact_replicas_id_content", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_storage_namespaces_fingerprint_shape", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CHECK (id::text = 'primary'::text)", + "kind": "c", + "name": "ck_artifact_storage_namespaces_singleton_id", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_storage_namespaces", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "UNIQUE (namespace_fingerprint)", + "kind": "u", + "name": "uq_artifact_storage_namespace_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "UNIQUE (id, namespace_fingerprint)", + "kind": "u", + "name": "uq_artifact_storage_namespace_id_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CHECK (attempt_count >= 0 AND maximum_attempts > 0)", + "kind": "c", + "name": "ck_artifact_verification_jobs_attempts", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", + "kind": "c", + "name": "ck_artifact_verification_jobs_fence_pair", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK ((status::text = 'running'::text) = (executor_id IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_verification_jobs_running_fence", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'running', 'verified', 'missing', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", + "kind": "c", + "name": "ck_artifact_verification_jobs_status", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK (status::text <> 'provider_unavailable'::text OR next_run_at IS NOT NULL AND terminal_at IS NULL AND attempt_count < maximum_attempts OR next_run_at IS NULL AND terminal_at IS NOT NULL AND attempt_count >= maximum_attempts)", + "kind": "c", + "name": "ck_artifact_verification_jobs_unavailable_retryability", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_verification_jobs_versions", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "FOREIGN KEY (originating_put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_jobs_originating_put_attempt_i_3260", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_jobs_replica_id_artifact_replicas", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "FOREIGN KEY (parent_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_parent", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_verification_jobs", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "UNIQUE (parent_verification_job_id)", + "kind": "u", + "name": "uq_artifact_verification_parent", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK ((outcome::text = ANY (ARRAY['verified', 'integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_verification_receipts_observed_facts", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_verification_receipts_observed_sha256", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_verification_receipts_observed_size", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (outcome::text = ANY (ARRAY['verified', 'missing', 'integrity_mismatch', 'conflict']))", + "kind": "c", + "name": "ck_artifact_verification_receipts_outcome", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "FOREIGN KEY (verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_receipts_verification_job_id_a_dabf", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_verification_receipts", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "UNIQUE (verification_job_id, execution_generation)", + "kind": "u", + "name": "uq_artifact_verification_fence", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND (entity_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'authorization_decision', 'authority_invalidation'])) AND entity_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND ((actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile'])) AND actor_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR actor_ref_kind::text = 'system_principal'::text AND actor_id::text = 'workstream:system:bootstrap'::text) AND (target_actor_ref IS NULL OR target_actor_ref_kind::text = 'actor_profile'::text AND target_actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (matched_grant_id IS NULL OR matched_grant_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (project_id IS NULL OR project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (resource_type IS NULL OR (resource_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'project', 'qualification_snapshot', 'project_role_grant', 'task', 'submission', 'review', 'contribution', 'compensation_award', 'compensation_delivery', 'operations', 'audit_event', 'project_create_operation', 'project_submission_artifact_policy_mutation', 'project_guide_compilation_attempt', 'project_guide_compilation_request']))) AND (resource_id IS NULL OR resource_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (target_ref_kind IS NULL OR (target_ref_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'project'])) AND target_ref_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR target_ref_kind::text = 'permission_registry'::text AND (target_ref_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND (invalidation_target_kind IS NULL OR (invalidation_target_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant'])) AND invalidation_target_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR invalidation_target_kind::text = 'permission_registry'::text AND (invalidation_target_ref::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND ((entity_type::text <> ALL (ARRAY['authorization_decision', 'authority_invalidation'])) OR entity_id::text = id::text) AND (resource_type::text <> 'project'::text OR resource_id IS NULL OR project_id IS NOT NULL AND resource_id::text = project_id::text))", + "kind": "c", + "name": "ck_audit_events_authority_privacy_bounds", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR reason IS NOT NULL AND (event_type::text = 'ActorProfileProvisioned'::text AND reason = 'automatic_first_access'::text OR event_type::text = 'ServiceActorProvisioned'::text AND reason = 'manual_service_provisioning'::text OR event_type::text = 'ActorIdentityLinked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkRevoked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkReactivated'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorProfileSuspended'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'ActorProfileReactivated'::text AND reason = 'administrative_correction'::text OR event_type::text = 'ActorProfileDeactivated'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'InitialAccessAdministratorBootstrapped'::text AND reason = 'initial_access_bootstrap'::text OR event_type::text = 'AdminRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'AdminRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'AdminRoleGrantIssueDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'LastAccessAdministratorOperationDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'ProjectRoleQualificationSnapshotCaptured'::text AND reason = 'qualification_evidence_captured'::text OR event_type::text = 'ProjectRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'ProjectRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'SensitiveAuthorizationDenied'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'AuthorityInvalidationRequested'::text AND reason = 'authority_state_changed'::text) AND (permission_id IS NULL OR (permission_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.execute', 'project.guide_compilation.request']))) AND (denial_code IS NULL OR (denial_code::text = ANY (ARRAY['required_scope_missing', 'unsupported_subject_kind', 'service_actor_not_provisioned', 'identity_link_revoked', 'actor_suspended', 'actor_deactivated', 'permission_not_granted', 'scope_not_authorized', 'self_grant_forbidden', 'self_role_revoke_forbidden', 'resource_guard_denied', 'actor_not_found', 'grant_not_found', 'resource_not_found', 'actor_already_suspended', 'actor_not_suspended', 'actor_deactivated_terminal', 'last_access_administrator', 'admin_role_grant_exists', 'project_role_grant_exists', 'identity_link_conflict', 'project_role_grant_already_revoked', 'project_role_grant_replay_state_changed', 'identity_link_already_revoked', 'identity_link_not_revoked', 'resource_project_mismatch', 'idempotency_mismatch', 'invalid_role_scope', 'invalid_project_role', 'qualification_snapshot_invalid']))))", + "kind": "c", + "name": "ck_audit_events_authority_registries", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text = ANY (ARRAY['ActorProfileProvisioned', 'ServiceActorProvisioned', 'ActorIdentityLinked', 'ActorIdentityLinkRevoked', 'ActorIdentityLinkReactivated', 'ActorProfileSuspended', 'ActorProfileReactivated', 'ActorProfileDeactivated', 'InitialAccessAdministratorBootstrapped', 'AdminRoleGrantIssued', 'AdminRoleGrantRevoked', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied', 'ProjectRoleQualificationSnapshotCaptured', 'ProjectRoleGrantIssued', 'ProjectRoleGrantReplaced', 'ProjectRoleGrantRevoked', 'SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested'])))", + "kind": "c", + "name": "ck_audit_events_authority_tokens", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND action_id IS NULL OR event_domain::text = 'authority'::text AND (action_id IS NULL OR (event_type::text = ANY (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied'])) AND permission_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)) AND (permission_id IS NULL OR (permission_id::text <> ALL (ARRAY['operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'project.guide_compilation.request', 'project.guide_compilation.execute'])) OR action_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)))", + "kind": "c", + "name": "ck_audit_events_authorization_action_evidence", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND event_version IS NULL AND occurred_at IS NULL AND actor_ref_kind IS NULL AND request_id IS NULL AND correlation_id IS NULL AND target_actor_ref_kind IS NULL AND target_actor_ref IS NULL AND matched_grant_id IS NULL AND permission_id IS NULL AND project_id IS NULL AND resource_type IS NULL AND resource_id IS NULL AND target_ref_kind IS NULL AND target_ref_id IS NULL AND denial_code IS NULL AND idempotency_reference IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND invalidation_target_ref IS NULL AND before_facts IS NULL AND after_facts IS NULL AND external_subject IS NOT NULL AND external_issuer IS NOT NULL OR event_domain::text = 'authority'::text AND event_version = 1 AND occurred_at IS NOT NULL AND (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal'])) AND request_id IS NOT NULL AND correlation_id IS NOT NULL AND from_status IS NULL AND to_status IS NULL AND reason IS NOT NULL AND external_subject IS NULL AND external_issuer IS NULL AND actor_roles::jsonb = '[]'::jsonb AND claim_snapshot::jsonb = '{}'::jsonb AND auth_source::text = 'local_authority'::text AND is_dev_auth = false AND event_payload::jsonb = '{}'::jsonb)", + "kind": "c", + "name": "ck_audit_events_domain_shape", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR (before_facts IS NULL OR octet_length(before_facts::text) <= 4096) AND (after_facts IS NULL OR octet_length(after_facts::text) <= 4096) AND COALESCE(authority_event_facts_are_safe(event_type::text, before_facts, after_facts, project_id::text), false))", + "kind": "c", + "name": "ck_audit_events_fact_bounds", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text <> ALL (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) OR (event_type::text = ANY (ARRAY['AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) AND denial_code IS NOT NULL OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND permission_id IS NOT NULL AND denial_code IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL OR event_type::text = 'SensitiveAuthorizationDenied'::text AND permission_id IS NOT NULL AND denial_code IS NOT NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND idempotency_reference IS NULL OR event_type::text = 'AuthorityInvalidationRequested'::text AND invalidation_cause_event_id IS NOT NULL AND invalidation_target_kind IS NOT NULL AND denial_code IS NULL)", + "kind": "c", + "name": "ck_audit_events_foundation_shapes", + "table_name": "audit_events" + }, + { + "definition": "CHECK ((target_actor_ref_kind IS NULL) = (target_actor_ref IS NULL) AND (resource_type IS NOT NULL OR resource_id IS NULL) AND (target_ref_kind IS NULL) = (target_ref_id IS NULL) AND (invalidation_target_kind IS NULL) = (invalidation_target_ref IS NULL) AND (invalidation_cause_event_id IS NULL OR invalidation_cause_event_id::text <> id::text))", + "kind": "c", + "name": "ck_audit_events_reference_pairs", + "table_name": "audit_events" + }, + { + "definition": "FOREIGN KEY (idempotency_reference, actor_ref_kind, actor_id) REFERENCES authority_idempotency_records(id, actor_ref_kind, actor_ref) NOT VALID", + "kind": "f", + "name": "fk_audit_events_authority_idempotency", + "table_name": "audit_events" + }, + { + "definition": "FOREIGN KEY (invalidation_cause_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_audit_events_invalidation_cause", + "table_name": "audit_events" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_audit_events", + "table_name": "audit_events" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "authority_control_bootstrap_invariant", + "table_name": "authority_control" + }, + { + "definition": "CHECK (bootstrap_completed = false AND bootstrap_grant_id IS NULL AND version = 0 OR bootstrap_completed = true AND bootstrap_grant_id IS NOT NULL AND version = 1)", + "kind": "c", + "name": "ck_authority_control_bootstrap_state", + "table_name": "authority_control" + }, + { + "definition": "CHECK (id = 1)", + "kind": "c", + "name": "ck_authority_control_singleton", + "table_name": "authority_control" + }, + { + "definition": "FOREIGN KEY (bootstrap_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_authority_control_bootstrap_grant_id_admin_role_grants", + "table_name": "authority_control" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_authority_control", + "table_name": "authority_control" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "authority_idempotency_pending_guard", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal']))", + "kind": "c", + "name": "ck_authority_idempotency_records_actor_kind", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (actor_ref_kind::text = 'system_principal'::text AND actor_ref::text = 'workstream:system:bootstrap'::text OR actor_ref_kind::text <> 'system_principal'::text AND actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_authority_idempotency_records_actor_reference", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'admin_role_grant.revoke', 'project_role_grant.issue', 'project_role_grant.revoke', 'actor_profile.suspend', 'actor_profile.reactivate', 'actor_profile.deactivate', 'actor_identity_link.revoke', 'actor_identity_link.reactivate']))", + "kind": "c", + "name": "ck_authority_idempotency_records_operation", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_authority_idempotency_records_request_digest", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (response_http_status IS NULL OR (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 201 OR (operation::text <> ALL (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 200)", + "kind": "c", + "name": "ck_authority_idempotency_records_response_status", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (operation::text = 'service_actor.create'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'admin_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'admin_role_grant'::text) OR operation::text ~~ 'project_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'project_role_grant'::text) OR operation::text ~~ 'actor_profile.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'actor_identity_link.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_identity_link'::text))", + "kind": "c", + "name": "ck_authority_idempotency_records_response_type", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (response_resource_version IS NULL OR response_resource_version > 0)", + "kind": "c", + "name": "ck_authority_idempotency_records_response_version", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_resource_type IS NULL AND response_resource_id IS NULL AND response_resource_version IS NULL AND response_http_status IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_resource_type IS NOT NULL AND response_resource_id IS NOT NULL AND response_http_status IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_authority_idempotency_records_state_shape", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_authority_idempotency_records_status", + "table_name": "authority_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_authority_idempotency_records", + "table_name": "authority_idempotency_records" + }, + { + "definition": "UNIQUE (id, actor_ref_kind, actor_ref)", + "kind": "u", + "name": "uq_authority_idempotency_records_actor_reference", + "table_name": "authority_idempotency_records" + }, + { + "definition": "UNIQUE (actor_ref_kind, actor_ref, operation, idempotency_key)", + "kind": "u", + "name": "uq_authority_idempotency_records_replay_namespace", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", + "kind": "c", + "name": "ck_checker_policies_approval_provenance", + "table_name": "checker_policies" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'superseded'::text OR superseded_at IS NOT NULL AND (superseded_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND superseded_by_actor IS NOT NULL AND (supersession_kind::text = ANY (ARRAY['correction_requested', 'upstream_policy_changed'])) AND supersession_reason IS NOT NULL AND length(btrim(supersession_reason)) > 0)", + "kind": "c", + "name": "ck_checker_policies_correction_provenance", + "table_name": "checker_policies" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['compiled', 'approved', 'superseded']))", + "kind": "c", + "name": "ck_checker_policies_lifecycle_status", + "table_name": "checker_policies" + }, + { + "definition": "CHECK (policy_hash IS NULL OR policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_checker_policies_policy_hash_shape", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_checker_policies_effective_policy_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_checker_policies_guide_id_project_guides", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (pre_submit_checker_policy_id, pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", + "kind": "f", + "name": "fk_checker_policies_pre_submit_checker_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_checker_policies_project_guide", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_checker_policies_project_id_projects", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_checker_policies_source_snapshot_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES checker_policies(id)", + "kind": "f", + "name": "fk_checker_policies_supersedes_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_checker_policies", + "table_name": "checker_policies" + }, + { + "definition": "UNIQUE (id, guide_version, policy_hash)", + "kind": "u", + "name": "uq_checker_policies_id_version_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_checker_results_checker_run_id_checker_runs", + "table_name": "checker_results" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_checker_results_submission_id_submissions", + "table_name": "checker_results" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_checker_results_task_id_workstream_tasks", + "table_name": "checker_results" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_checker_results", + "table_name": "checker_results" + }, + { + "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", + "kind": "c", + "name": "ck_checker_runs_post_submit_policy_lock_complete", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (audit_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_checker_runs_audit_event_id_audit_events", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", + "kind": "f", + "name": "fk_checker_runs_locked_post_submit_policy_hash", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_checker_runs_submission_id_submissions", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (submission_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES submissions(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "f", + "name": "fk_checker_runs_submission_locked_post_submit_policy_hash", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_checker_runs_submission_version", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (supersedes_checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_checker_runs_supersedes_checker_run_id_checker_runs", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_checker_runs_task_id_workstream_tasks", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", + "kind": "f", + "name": "fk_checker_runs_task_locked_guide", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", + "kind": "f", + "name": "fk_checker_runs_task_locked_payment_policy", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "kind": "f", + "name": "fk_checker_runs_task_locked_review_policy", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "kind": "f", + "name": "fk_checker_runs_task_locked_revision_policy", + "table_name": "checker_runs" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_checker_runs", + "table_name": "checker_runs" + }, + { + "definition": "UNIQUE (submission_id, attempt_number)", + "kind": "u", + "name": "uq_checker_runs_submission_attempt", + "table_name": "checker_runs" + }, + { + "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", + "kind": "c", + "name": "ck_contribution_award_definitions_contribution_type", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", + "kind": "c", + "name": "ck_contribution_award_definitions_instrument_type", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (instrument_type::text <> 'project_points'::text OR scale(quantity) = 0)", + "kind": "c", + "name": "ck_contribution_award_definitions_project_points_whole", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (quantity > 0::numeric AND quantity < '100000000000000000000'::numeric AND scale(quantity) >= 0 AND scale(quantity) <= 18)", + "kind": "c", + "name": "ck_contribution_award_definitions_quantity_exact_bounds", + "table_name": "contribution_award_definitions" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_award_definitions_graph_guard", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (adapter_binding_id, project_id, instrument_type) REFERENCES project_compensation_adapter_bindings(id, project_id, instrument_type)", + "kind": "f", + "name": "fk_contribution_award_definition_binding", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_award_definition_project", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (contribution_rule_id, contribution_policy_version_id, project_id, contribution_type) REFERENCES contribution_rules(id, contribution_policy_version_id, project_id, contribution_type)", + "kind": "f", + "name": "fk_contribution_award_definition_rule", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (project_id, instrument_type, unit_code) REFERENCES project_compensation_units(project_id, instrument_type, unit_code)", + "kind": "f", + "name": "fk_contribution_award_definition_unit", + "table_name": "contribution_award_definitions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_award_definitions", + "table_name": "contribution_award_definitions" + }, + { + "definition": "UNIQUE (contribution_rule_id, instrument_type)", + "kind": "u", + "name": "uq_contribution_award_definition_instrument", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (status::text = 'draft'::text AND current_published_version_id IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'active'::text AND current_published_version_id IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND current_published_version_id IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", + "kind": "c", + "name": "ck_contribution_policies_lifecycle_shape", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (char_length(btrim(name::text)) >= 1 AND char_length(btrim(name::text)) <= 200)", + "kind": "c", + "name": "ck_contribution_policies_name", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", + "kind": "c", + "name": "ck_contribution_policies_retirement_timestamp", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['draft', 'active', 'retired']))", + "kind": "c", + "name": "ck_contribution_policies_status", + "table_name": "contribution_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_policies_graph_guard", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_created_by", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (current_published_version_id, id, project_id) REFERENCES contribution_policy_versions(id, contribution_policy_id, project_id) DEFERRABLE INITIALLY DEFERRED", + "kind": "f", + "name": "fk_contribution_policy_current_version", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_policy_project", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_retired_by", + "table_name": "contribution_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_policies", + "table_name": "contribution_policies" + }, + { + "definition": "UNIQUE (id, project_id)", + "kind": "u", + "name": "uq_contribution_policy_ownership", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (status::text = 'draft'::text AND published_by IS NULL AND published_at IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'published'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", + "kind": "c", + "name": "ck_contribution_policy_versions_lifecycle_shape", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK ((published_at IS NULL OR published_at >= created_at) AND (retired_at IS NULL OR retired_at >= published_at))", + "kind": "c", + "name": "ck_contribution_policy_versions_lifecycle_timestamps", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['draft', 'published', 'retired']))", + "kind": "c", + "name": "ck_contribution_policy_versions_status", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK (version_number > 0)", + "kind": "c", + "name": "ck_contribution_policy_versions_version_number_positive", + "table_name": "contribution_policy_versions" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_policy_versions_graph_guard", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_version_created_by", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (contribution_policy_id, project_id) REFERENCES contribution_policies(id, project_id)", + "kind": "f", + "name": "fk_contribution_policy_version_policy", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_policy_version_project", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (published_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_version_published_by", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_version_retired_by", + "table_name": "contribution_policy_versions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_policy_versions", + "table_name": "contribution_policy_versions" + }, + { + "definition": "UNIQUE (contribution_policy_id, version_number)", + "kind": "u", + "name": "uq_contribution_policy_version_number", + "table_name": "contribution_policy_versions" + }, + { + "definition": "UNIQUE (id, contribution_policy_id, project_id)", + "kind": "u", + "name": "uq_contribution_policy_version_ownership", + "table_name": "contribution_policy_versions" + }, + { + "definition": "UNIQUE (id, project_id)", + "kind": "u", + "name": "uq_contribution_policy_version_project", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK (compensation_mode::text = ANY (ARRAY['unpaid', 'compensated']))", + "kind": "c", + "name": "ck_contribution_rules_compensation_mode", + "table_name": "contribution_rules" + }, + { + "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", + "kind": "c", + "name": "ck_contribution_rules_contribution_type", + "table_name": "contribution_rules" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_rules_graph_guard", + "table_name": "contribution_rules" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_rule_project", + "table_name": "contribution_rules" + }, + { + "definition": "FOREIGN KEY (contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", + "kind": "f", + "name": "fk_contribution_rule_version", + "table_name": "contribution_rules" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_rules", + "table_name": "contribution_rules" + }, + { + "definition": "UNIQUE (id, contribution_policy_version_id, project_id, contribution_type)", + "kind": "u", + "name": "uq_contribution_rule_ownership", + "table_name": "contribution_rules" + }, + { + "definition": "UNIQUE (contribution_policy_version_id, contribution_type)", + "kind": "u", + "name": "uq_contribution_rule_type", + "table_name": "contribution_rules" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['approved', 'superseded']))", + "kind": "c", + "name": "ck_effective_project_submission_artifact_policies_ck_ef_7be7", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_effective_project_submission_artifact_policies_ck_ef_bd4e", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "effective_submission_policy_custody", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_effective_policy_creation_actor", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_effective_policy_creation_decision", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_effective_policy_creation_grant", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_effective_policy_creation_link", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_effective_policy_creation_project", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_effective_project_submission_artifact_policies_project_guide", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_effective_psap_guide", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_effective_psap_project", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_effective_psap_source_snapshot_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (submission_artifact_policy_id, submission_artifact_policy_hash) REFERENCES submission_artifact_policies(id, policy_hash)", + "kind": "f", + "name": "fk_effective_psap_submission_policy_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", + "kind": "f", + "name": "fk_effective_psap_supersedes", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_effective_project_submission_artifact_policies", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "UNIQUE (id, effective_policy_hash)", + "kind": "u", + "name": "uq_effective_project_submission_artifact_policies_id_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_evidence_items_submission_id_submissions", + "table_name": "evidence_items" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_evidence_items", + "table_name": "evidence_items" + }, + { + "definition": "CHECK (operation_generation > 0)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_6506", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL AND setup_run_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_9402", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create']))", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_action", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_b397", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_e32d", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_status", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_actor_profile_id__2ee3", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_identity_link_id__3ddf", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_project_id_projects", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_setup_run_id_proj_7dc3", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "guide_mutation_reservation_custody", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_mutation_idempotency_records", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_guide_mutation_operation_identity", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", + "kind": "u", + "name": "uq_guide_mutation_replay_namespace", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_gen_b5fe", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CHECK (logical_role::text = 'guide_source_original'::text)", + "kind": "c", + "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_role", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (source_item_id, source_snapshot_id) REFERENCES guide_source_snapshot_items(id, source_snapshot_id)", + "kind": "f", + "name": "fk_guide_bindings_exact_item", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (project_setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", + "kind": "f", + "name": "fk_guide_bindings_exact_setup_generation", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, project_id, guide_id) REFERENCES guide_source_snapshots(id, project_id, guide_id)", + "kind": "f", + "name": "fk_guide_bindings_exact_snapshot", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (verified_replica_id, content_id) REFERENCES artifact_replicas(id, content_id)", + "kind": "f", + "name": "fk_guide_bindings_verified_replica_content", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_guide_source_artifact_bindings_content_id_artifact_contents", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES guide_source_artifact_bindings(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_guide_source_artifact_bindings_supersedes_binding_id_bfa2", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_artifact_bindings", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (id, content_id, verified_replica_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_exact_read", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (id, content_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_extraction_attempt_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (id, content_id, source_item_id, project_setup_run_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_extraction_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (source_item_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_item_generation", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (supersedes_binding_id)", + "kind": "u", + "name": "uq_guide_bindings_supersedes", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CHECK (code::text = ANY (ARRAY['missing', 'changed', 'truncated', 'unavailable', 'stale', 'conflict']))", + "kind": "c", + "name": "ck_guide_source_artifact_incidents_ck_guide_incidents_code", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_621b", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_92fa", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", + "kind": "f", + "name": "fk_guide_incidents_exact_binding", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_artifact_incidents", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_2958", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_64cb", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_source_artifact_ingests_actor_profile_id_actor_22c1", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "FOREIGN KEY (source_item_id) REFERENCES guide_source_snapshot_items(id)", + "kind": "f", + "name": "fk_guide_source_artifact_ingests_source_item_id_guide_s_7ba9", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_artifact_ingests", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "UNIQUE (source_item_id)", + "kind": "u", + "name": "uq_guide_source_artifact_ingests_source_item_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CHECK (output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_1b91", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (octet_length(canonical_output) <= 4194304)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_54b5", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (source_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_988f", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (status::text = 'extracted'::text)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_a759", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (source_byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_fb79", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_guide_source_extracted_contents_content_id_artifact_contents", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_extracted_contents", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "UNIQUE (id, content_id)", + "kind": "u", + "name": "uq_guide_extracted_contents_exact_usage", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "UNIQUE (content_id, detected_format, extractor_name, extractor_version, policy_version)", + "kind": "u", + "name": "uq_guide_extracted_contents_identity", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (attempt_number > 0)", + "kind": "c", + "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_3927", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CHECK ((status::text = 'extracted'::text) = (error_code IS NULL))", + "kind": "c", + "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_940d", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['extracted', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded', 'parser_failure', 'cancelled', 'artifact_incident']))", + "kind": "c", + "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_ff6d", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_attempts_exact_binding", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_attempts_exact_classification", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "UNIQUE (binding_id, policy_version, attempt_number)", + "kind": "u", + "name": "uq_guide_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "UNIQUE (id, binding_id, content_id, setup_generation, status)", + "kind": "u", + "name": "uq_guide_extraction_attempts_exact_usage", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CHECK (claimed_slots >= 1 AND claimed_slots <= 2)", + "kind": "c", + "name": "ck_guide_source_extraction_retry_budgets_ck_guide_extra_99c3", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_retry_budgets_exact_binding", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_retry_budgets_exact_classification", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "PRIMARY KEY (binding_id)", + "kind": "p", + "name": "pk_guide_source_extraction_retry_budgets", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "CHECK (attempt_status::text = 'extracted'::text)", + "kind": "c", + "name": "ck_guide_source_extraction_usages_ck_guide_extraction_u_a2fd", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "FOREIGN KEY (extraction_attempt_id, binding_id, content_id, setup_generation, attempt_status) REFERENCES guide_source_extraction_attempts(id, binding_id, content_id, setup_generation, status)", + "kind": "f", + "name": "fk_guide_extraction_usages_exact_attempt", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, source_item_id, project_setup_run_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, source_item_id, project_setup_run_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_usages_exact_binding", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "FOREIGN KEY (extracted_content_id, content_id) REFERENCES guide_source_extracted_contents(id, content_id)", + "kind": "f", + "name": "fk_guide_extraction_usages_exact_content", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "UNIQUE (binding_id, extracted_content_id)", + "kind": "u", + "name": "uq_guide_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "UNIQUE (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", + "kind": "u", + "name": "uq_guide_extraction_usages_exact_provenance", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['classified', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded']))", + "kind": "c", + "name": "ck_guide_source_format_classifications_ck_guide_classif_8737", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_format_classifications_ck_guide_source__0dd2", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_format_classifications_ck_guide_source__7235", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", + "kind": "f", + "name": "fk_guide_classifications_exact_binding", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_format_classifications", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "UNIQUE (binding_id)", + "kind": "u", + "name": "uq_guide_classifications_binding", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "UNIQUE (id, binding_id, content_id, setup_generation)", + "kind": "u", + "name": "uq_guide_classifications_extraction_lineage", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_gssi_source_snapshot", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "guide_source_snapshot_items_custody", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_snapshot_items", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "UNIQUE (id, source_snapshot_id)", + "kind": "u", + "name": "uq_guide_source_snapshot_items_exact_lineage", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "UNIQUE (source_snapshot_id, item_order)", + "kind": "u", + "name": "uq_guide_source_snapshot_items_snapshot_order", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CHECK (creation_generation IS NULL AND created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR creation_generation > 0 AND created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (creation_scope_type::text = 'system'::text AND creation_scope_project_id IS NULL OR creation_scope_type::text = 'project'::text AND creation_scope_project_id::text = project_id::text) AND creation_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_guide_source_snapshots_source_snapshot_creation_auth_2f3e", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_actor", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_admin_grant", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_decision", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_identity_link", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_guide_id_project_guides", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_guide_source_snapshots_project_guide", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_project_id_projects", + "table_name": "guide_source_snapshots" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_snapshots", + "table_name": "guide_source_snapshots" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "source_snapshot_product_custody", + "table_name": "guide_source_snapshots" + }, + { + "definition": "UNIQUE (id, project_id, guide_id)", + "kind": "u", + "name": "uq_guide_source_snapshots_exact_lineage", + "table_name": "guide_source_snapshots" + }, + { + "definition": "UNIQUE (id, bundle_hash)", + "kind": "u", + "name": "uq_guide_source_snapshots_id_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "UNIQUE (project_id, guide_version, bundle_hash)", + "kind": "u", + "name": "uq_guide_source_snapshots_project_version_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_1033", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_177a", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run', 'project.guide_sufficiency.warnings.acknowledge']))", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_6651", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_87dd", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND (action_id::text = 'project.guide_sufficiency.run'::text AND (setup_run_id IS NOT NULL OR report_id IS NOT NULL) OR action_id::text <> 'project.guide_sufficiency.run'::text AND report_id IS NOT NULL))", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_e7f6", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_actor_16d8", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_guide_1d2b", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_ident_2378", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_proje_7f82", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_repor_48c3", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_setup_7059", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_sourc_9985", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_sufficiency_mutation_idempotency_records", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_sufficiency_mutation_operation_identity", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, idempotency_key)", + "kind": "u", + "name": "uq_sufficiency_mutation_replay_namespace", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_2983", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CHECK (canonical_output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_8148", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CHECK (item_order >= 0)", + "kind": "c", + "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_eb12", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id) ON DELETE CASCADE", + "kind": "f", + "name": "fk_guide_sufficiency_report_source_usages_report_id_gui_1d57", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "FOREIGN KEY (extraction_usage_id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation) REFERENCES guide_source_extraction_usages(id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", + "kind": "f", + "name": "fk_sufficiency_report_source_usage_exact_extraction", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_sufficiency_report_source_usages", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "UNIQUE (report_id, extraction_usage_id)", + "kind": "u", + "name": "uq_sufficiency_report_extraction_usage", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "UNIQUE (report_id, item_order)", + "kind": "u", + "name": "uq_sufficiency_report_item_order", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CHECK (warnings_acknowledged_by_actor_profile_id IS NULL AND warnings_acknowledged_via_identity_link_id IS NULL AND warnings_acknowledged_by_admin_role_grant_id IS NULL AND warning_acknowledgement_scope_type IS NULL AND warning_acknowledgement_scope_project_id IS NULL AND warning_acknowledgement_action_id IS NULL AND warning_acknowledgement_decision_event_id IS NULL OR warnings_acknowledged_by_actor_profile_id IS NOT NULL AND warnings_acknowledged_via_identity_link_id IS NOT NULL AND warnings_acknowledged_by_admin_role_grant_id IS NOT NULL AND (warning_acknowledgement_scope_type::text = ANY (ARRAY['system', 'project'])) AND warning_acknowledgement_scope_project_id IS NOT NULL AND warning_acknowledgement_action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND warning_acknowledgement_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_guide_sufficiency_ack_authority_shape", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run'])) AND authorization_decision_event_id IS NOT NULL AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.guide_sufficiency.run'::text AND project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL))", + "kind": "c", + "name": "ck_guide_sufficiency_creation_authority_shape", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (agent_material_byte_count IS NULL OR agent_material_byte_count >= 0)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_31bb", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (setup_generation IS NULL OR setup_generation > 0)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_3e43", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (project_setup_run_id IS NULL AND setup_generation IS NULL AND agent_material_sha256 IS NULL AND agent_material_byte_count IS NULL OR project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_4640", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['passed', 'blocked', 'passed_with_warnings']))", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_841c", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (agent_material_sha256 IS NULL OR agent_material_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_b3ec", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_guide_id_project_guides", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_project_guide", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_project_id_projects", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_source_snapshot_hash", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warnings_acknowledged_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_suff_ack_actor", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warning_acknowledgement_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_suff_ack_decision", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warnings_acknowledged_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_suff_ack_grant", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warnings_acknowledged_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_suff_ack_link", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warning_acknowledgement_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_suff_ack_project", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_suff_create_actor", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_suff_create_decision", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_suff_create_grant", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_suff_create_link", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_suff_create_project", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (project_setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_sufficiency_reports_setup_run", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_sufficiency_reports", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (code::text ~ '^[A-Z]{3}$'::text)", + "kind": "c", + "name": "ck_iso_4217_currency_codes_code", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "PRIMARY KEY (code)", + "kind": "p", + "name": "pk_iso_4217_currency_codes", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "PRIMARY KEY (actor_id)", + "kind": "p", + "name": "pk_legacy_actor_identities", + "table_name": "legacy_actor_identities" + }, + { + "definition": "UNIQUE (external_issuer, external_subject)", + "kind": "u", + "name": "uq_legacy_actor_identities_external_identity", + "table_name": "legacy_actor_identities" + }, + { + "definition": "CHECK (profile_type::text = ANY (ARRAY['worker', 'reviewer', 'admin', 'project_manager', 'project_owner']))", + "kind": "c", + "name": "ck_legacy_workflow_eligibility_profile_type", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['observed', 'active', 'disabled']))", + "kind": "c", + "name": "ck_legacy_workflow_eligibility_status", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "FOREIGN KEY (actor_id) REFERENCES legacy_actor_identities(actor_id)", + "kind": "f", + "name": "fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_legacy_workflow_eligibility", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "UNIQUE (actor_id, profile_type, scope_type, scope_id)", + "kind": "u", + "name": "uq_legacy_workflow_eligibility_actor_type_scope", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CHECK (aggregate_type::text ~ '^[a-z][a-z0-9_]{0,63}$'::text)", + "kind": "c", + "name": "ck_outbox_events_aggregate_type", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (claim_owner IS NULL OR claim_owner::text ~ '^[A-Za-z0-9._:-]{1,120}$'::text)", + "kind": "c", + "name": "ck_outbox_events_claim_owner", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (correlation_id::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", + "kind": "c", + "name": "ck_outbox_events_correlation_id", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (attempt_count >= 0 AND claim_generation >= 0 AND attempt_count = claim_generation)", + "kind": "c", + "name": "ck_outbox_events_delivery_counters", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (delivery_state::text = ANY (ARRAY['pending', 'claimed', 'retryable', 'acknowledged', 'dead_letter', 'cancelled']))", + "kind": "c", + "name": "ck_outbox_events_delivery_state", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (delivery_state::text = 'pending'::text AND attempt_count = 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NULL AND last_error_code IS NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'claimed'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NOT NULL AND claimed_at IS NOT NULL AND claim_expires_at IS NOT NULL AND last_attempt_at = claimed_at AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'retryable'::text AND attempt_count > 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'acknowledged'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'dead_letter'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'cancelled'::text AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND finalized_at IS NOT NULL AND (attempt_count = 0 AND last_attempt_at IS NULL AND last_error_code IS NULL OR attempt_count > 0 AND last_attempt_at IS NOT NULL))", + "kind": "c", + "name": "ck_outbox_events_delivery_state_shape", + "table_name": "outbox_events" + }, + { + "definition": "CHECK ((next_attempt_at IS NULL OR next_attempt_at >= occurred_at) AND (claimed_at IS NULL OR claimed_at >= occurred_at) AND (last_attempt_at IS NULL OR last_attempt_at >= occurred_at) AND (claim_expires_at IS NULL OR claim_expires_at > claimed_at) AND (finalized_at IS NULL OR finalized_at >= occurred_at) AND (finalized_at IS NULL OR last_attempt_at IS NULL OR finalized_at >= last_attempt_at) AND (archived_at IS NULL OR archived_at >= finalized_at))", + "kind": "c", + "name": "ck_outbox_events_delivery_timestamps", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (last_error_code IS NULL OR last_error_code::text ~ '^[A-Z][A-Z0-9_]{0,79}$'::text)", + "kind": "c", + "name": "ck_outbox_events_error_code", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (event_type::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'::text)", + "kind": "c", + "name": "ck_outbox_events_event_type", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (event_version >= 1 AND event_version <= 32767)", + "kind": "c", + "name": "ck_outbox_events_event_version", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (idempotency_key::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", + "kind": "c", + "name": "ck_outbox_events_idempotency_key", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (payload_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_outbox_events_payload_digest", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (jsonb_typeof(payload) = 'object'::text AND octet_length(payload::text) <= 262144)", + "kind": "c", + "name": "ck_outbox_events_payload_shape", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (producer::text = 'workstream'::text)", + "kind": "c", + "name": "ck_outbox_events_producer", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_outbox_events_project_id", + "table_name": "outbox_events" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_outbox_events_project_id_projects", + "table_name": "outbox_events" + }, + { + "definition": "PRIMARY KEY (event_id)", + "kind": "p", + "name": "pk_outbox_events", + "table_name": "outbox_events" + }, + { + "definition": "UNIQUE (idempotency_key)", + "kind": "u", + "name": "uq_outbox_events_idempotency_key", + "table_name": "outbox_events" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_payment_policies_project_guide", + "table_name": "payment_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_payment_policies_project_id_projects", + "table_name": "payment_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_payment_policies", + "table_name": "payment_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version)", + "kind": "u", + "name": "uq_payment_policies_project_version", + "table_name": "payment_policies" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_26aa", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_595e", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.review_policy.update', 'project.revision_policy.update']))", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_7f7f", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (policy_generation > 0)", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_8b22", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_dc05", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_actor_profile_id_41c2", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_guide_id_project_guides", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_identity_link_id_b806", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_project_id_projects", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_policy_mutation_idempotency_records", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "policy_mutation_replay_custody", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_policy_mutation_operation_identity", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", + "kind": "u", + "name": "uq_policy_mutation_replay_namespace", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'compiled'::text OR compiler_version IS NOT NULL AND compiled_bundle IS NOT NULL AND compiled_bundle_hash IS NOT NULL AND compiled_bundle_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_5010", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['pending_compilation', 'compiled', 'superseded']))", + "kind": "c", + "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_a935", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_pre_submit_checker_policies_ck_pre_submit_policy_aut_90fc", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_effective_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_guide", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_project", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_project_guide", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_source_snapshot_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_pre_submit_checker_policy_id) REFERENCES pre_submit_checker_policies(id)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_supersedes", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_actor", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_decision", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_grant", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_link", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_project", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_pre_submit_checker_policies", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "pre_submit_policy_custody", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "UNIQUE (id, compiled_bundle_hash)", + "kind": "u", + "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CHECK (classification::text = ANY (ARRAY['mandatory_security', 'mandatory_integrity', 'mandatory_accountability', 'advisory']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_b0de", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (classification::text = 'advisory'::text AND severity::text = 'warning'::text OR classification::text <> 'advisory'::text AND severity::text = 'blocking'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_f04e", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (result_order >= 0)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_order", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (phase::text = ANY (ARRAY['custody', 'identity', 'materialization', 'default_policy', 'project_policy']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_phase", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_plan_sha256", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (locked_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_pol_cef4", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (phase::text = 'project_policy'::text AND rule_instance_id IS NOT NULL AND rule_instance_id::text ~ '^sha256:[0-9a-f]{64}$'::text OR phase::text <> 'project_policy'::text AND rule_instance_id IS NULL)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_rul_321f", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (severity::text = ANY (ARRAY['blocking', 'warning']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_severity", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['passed', 'warning', 'advisory_disabled', 'dependency_not_run', 'failed']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_status", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (status::text = 'failed'::text AND failure_code IS NOT NULL OR status::text <> 'failed'::text AND failure_code IS NULL)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_result_failure_shape", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "FOREIGN KEY (evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_results_evidence_set_id_pre_subm_096e", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_pre_submit_evidence_results", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "UNIQUE (evidence_set_id, definition_id)", + "kind": "u", + "name": "uq_pre_submit_result_definition", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "UNIQUE (evidence_set_id, result_order)", + "kind": "u", + "name": "uq_pre_submit_result_order", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arch_8e95", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (archive_byte_count >= 0)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_archive_size", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_artifact_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arti_16f8", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (catalogue_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_cata_ffcb", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_checker_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_chec_765d", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_guide_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_guide_sha256", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_mani_7268", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_oper_f617", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_plan_sha256", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (predecessor_submission_id IS NULL AND predecessor_submission_version IS NULL OR predecessor_submission_id IS NOT NULL AND predecessor_submission_version IS NOT NULL)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_pred_bd87", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (result_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_resu_0b46", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (result_count > 0)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_result_count", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (source_snapshot_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_sour_982b", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (terminal_status::text = 'passed'::text AND eligible OR terminal_status::text = 'blocked'::text AND NOT eligible)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stat_1ae6", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (storage_scheme::text = ANY (ARRAY['local', 's3']))", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stor_022c", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (terminal_status::text = ANY (ARRAY['passed', 'blocked']))", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_term_a512", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_policy_context_sha256", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (assignment_id, task_id, actor_profile_id) REFERENCES task_assignments(id, task_id, contributor_id)", + "kind": "f", + "name": "fk_pre_submit_evidence_assignment", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (guide_id, project_id, guide_version) REFERENCES project_guides(id, project_id, version)", + "kind": "f", + "name": "fk_pre_submit_evidence_guide_lineage", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (identity_link_id, actor_profile_id) REFERENCES actor_identity_links(id, actor_profile_id)", + "kind": "f", + "name": "fk_pre_submit_evidence_identity_actor", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (predecessor_submission_id, task_id, predecessor_submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_pre_submit_evidence_predecessor", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_actor_profile_id_actor_profiles", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_assignment_id_task_assignments", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_effective_policy_id_effecti_6a99", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_guide_id_project_guides", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_identity_link_id_actor_iden_5cef", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_pre_submit_policy_id_pre_su_c77f", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_predecessor_submission_id_s_6ec2", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_project_id_projects", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_source_snapshot_id_guide_so_1667", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_task_id_workstream_tasks", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, effective_policy_id, locked_artifact_policy_sha256) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_artifact_policy", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, pre_submit_policy_id, locked_checker_policy_sha256) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_checker_policy", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_guide", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, project_id) REFERENCES workstream_tasks(id, project_id)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_project", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, source_snapshot_id, source_snapshot_sha256) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_source_snapshot", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_pre_submit_evidence_sets", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "UNIQUE (operation_identity)", + "kind": "u", + "name": "uq_pre_submit_evidence_operation", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (binding_lifecycle_version > 0)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_1870", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_3372", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (route_key::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'::text)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_6958", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (status::text = 'active'::text AND binding_lifecycle_version = 1 AND suspended_by IS NULL AND suspended_at IS NULL AND retired_by IS NULL AND retired_at IS NULL)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_95ba", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK ((suspended_at IS NULL OR suspended_at >= created_at) AND (retired_at IS NULL OR retired_at >= created_at) AND (retired_at IS NULL OR suspended_at IS NULL OR retired_at >= suspended_at))", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_ade1", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'retired']))", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_da73", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (route_key::text !~~ '%..%'::text)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_f32d", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (adapter_actor_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_adapter_actor", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_created_by", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_compensation_binding_project", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_retired_by", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (suspended_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_suspended_by", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_compensation_adapter_bindings", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "UNIQUE (id, project_id, instrument_type)", + "kind": "u", + "name": "uq_compensation_binding_ownership", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", + "kind": "c", + "name": "ck_project_compensation_units_instrument_type", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (status::text = 'active'::text AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", + "kind": "c", + "name": "ck_project_compensation_units_lifecycle_shape", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", + "kind": "c", + "name": "ck_project_compensation_units_retirement_time", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'retired']))", + "kind": "c", + "name": "ck_project_compensation_units_status", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (instrument_type::text = 'money'::text AND iso_currency_code IS NOT NULL AND unit_code::text = iso_currency_code::text OR instrument_type::text = 'project_points'::text AND iso_currency_code IS NULL AND unit_code::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$'::text)", + "kind": "c", + "name": "ck_project_compensation_units_unit_identity", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_compensation_unit_created_by", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (iso_currency_code) REFERENCES iso_4217_currency_codes(code)", + "kind": "f", + "name": "fk_project_compensation_unit_iso_currency", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_compensation_unit_project", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_compensation_unit_retired_by", + "table_name": "project_compensation_units" + }, + { + "definition": "PRIMARY KEY (project_id, instrument_type, unit_code)", + "kind": "p", + "name": "pk_project_compensation_units", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_0a41", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (operation_generation = 1)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_100d", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND committed_at IS NULL OR status::text = 'committed'::text AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_3aa0", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = 'project.create'::text)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_action", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_status", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_create_idempotency_records_actor_profile_id__ebb1", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_create_idempotency_records_identity_link_id__ddce", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_create_idempotency_records", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "project_create_reservation_custody", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_project_create_operation_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "UNIQUE (project_id)", + "kind": "u", + "name": "uq_project_create_project_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", + "kind": "u", + "name": "uq_project_create_replay_namespace", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_00d8", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (component_hashes IS NULL OR json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_31c4", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (status::text = 'compilation_reserved'::text AND provider_uncertain_at IS NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_provider_uncertain'::text AND provider_uncertain_at IS NOT NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'provider_result_accepted'::text AND accepted_at IS NOT NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_persisted'::text AND accepted_at IS NOT NULL AND persisted_at IS NOT NULL AND terminal_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NOT NULL OR status::text = 'compilation_invalid_terminal'::text AND terminal_at IS NOT NULL AND accepted_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND persisted_compilation_id IS NULL AND (failure_code::text = ANY (ARRAY['schema_invalid', 'unsafe_text', 'hash_mismatch', 'context_mismatch'])))", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_444c", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_513e", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (canonical_result IS NULL OR octet_length(canonical_result::text) <= 4194304)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6057", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (result_hash IS NULL OR result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6609", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['compilation_reserved', 'compilation_provider_uncertain', 'provider_result_accepted', 'compilation_invalid_terminal', 'compilation_persisted']))", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6c82", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (persisted_compilation_id, id) REFERENCES project_guide_compilations(id, attempt_id)", + "kind": "f", + "name": "fk_compilation_attempt_exact_persisted_compilation", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", + "kind": "f", + "name": "fk_compilation_attempt_exact_setup", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_compilation_attempt_snapshot_hash", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_project_guide_compilation_attempts_guide_id_project_guides", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_guide_compilation_attempts_project_id_projects", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_guide_compilation_attempts", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "UNIQUE (provider_idempotency_key)", + "kind": "u", + "name": "uq_compilation_attempt_provider_key", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "UNIQUE (setup_run_id, setup_generation)", + "kind": "u", + "name": "uq_compilation_attempt_setup_generation", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (setup_generation > 0 AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_action_id::text = 'project.guide_compilation.execute'::text)", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_8a51", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_9cd9", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK (authorization_resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_d554", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK (octet_length(canonical_result::text) <= 4194304 AND json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_dafe", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (supersedes_compilation_id, project_id, guide_id) REFERENCES project_guide_compilations(id, project_id, guide_id)", + "kind": "f", + "name": "fk_project_guide_compilation_predecessor", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (attempt_id) REFERENCES project_guide_compilation_attempts(id)", + "kind": "f", + "name": "fk_project_guide_compilations_attempt_id_project_guide__0e94", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_project_guide_compilations_authorization_decision_ev_42ad", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_guide_compilations_created_by_actor_profile__953f", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_guide_compilations_created_via_identity_link_b250", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_project_guide_compilations_guide_id_project_guides", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_guide_compilations_project_id_projects", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_project_guide_compilations_setup_run_id_project_setup_runs", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_project_guide_compilations_source_snapshot_id_guide__033a", + "table_name": "project_guide_compilations" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_guide_compilations", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (attempt_id)", + "kind": "u", + "name": "uq_project_guide_compilation_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (id, attempt_id)", + "kind": "u", + "name": "uq_project_guide_compilation_id_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (supersedes_compilation_id)", + "kind": "u", + "name": "uq_project_guide_compilation_predecessor", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (id, project_id, guide_id)", + "kind": "u", + "name": "uq_project_guide_compilation_scope", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK ((status::text <> ALL (ARRAY['active', 'superseded'])) OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL AND selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL)", + "kind": "c", + "name": "ck_project_guides_active_policy_selection_required", + "table_name": "project_guides" + }, + { + "definition": "CHECK (mutation_generation IS NULL AND last_mutated_by_actor_profile_id IS NULL AND last_mutated_via_identity_link_id IS NULL AND last_mutated_by_admin_role_grant_id IS NULL AND last_mutation_scope_type IS NULL AND last_mutation_scope_project_id IS NULL AND last_mutation_action_id IS NULL AND last_authorization_decision_event_id IS NULL OR mutation_generation > 0 AND last_mutated_by_actor_profile_id IS NOT NULL AND last_mutated_via_identity_link_id IS NOT NULL AND last_mutated_by_admin_role_grant_id IS NOT NULL AND (last_mutation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (last_mutation_scope_type::text = 'system'::text AND last_mutation_scope_project_id IS NULL OR last_mutation_scope_type::text = 'project'::text AND last_mutation_scope_project_id::text = project_id::text) AND (last_mutation_action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create'])) AND last_authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_project_guides_guide_mutation_authority_shape", + "table_name": "project_guides" + }, + { + "definition": "CHECK ((selected_review_policy_id IS NULL AND selected_review_policy_generation IS NULL AND selected_review_policy_hash IS NULL OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL) AND (selected_revision_policy_id IS NULL AND selected_revision_policy_generation IS NULL AND selected_revision_policy_hash IS NULL OR selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL))", + "kind": "c", + "name": "ck_project_guides_policy_selection_shape", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_mutated_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_actor", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_mutated_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_admin_grant", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_decision", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_mutated_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_identity_link", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_guides_project_id_projects", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (project_id, version, selected_review_policy_id, selected_review_policy_generation, selected_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_project_guides_selected_review_policy", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (project_id, version, selected_revision_policy_id, selected_revision_policy_generation, selected_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_project_guides_selected_revision_policy", + "table_name": "project_guides" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "guide_mutation_product_custody", + "table_name": "project_guides" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_guides", + "table_name": "project_guides" + }, + { + "definition": "UNIQUE (id, project_id, version)", + "kind": "u", + "name": "uq_project_guides_id_project_version", + "table_name": "project_guides" + }, + { + "definition": "UNIQUE (project_id, version)", + "kind": "u", + "name": "uq_project_guides_project_version", + "table_name": "project_guides" + }, + { + "definition": "CHECK (grant_method::text = 'manual'::text)", + "kind": "c", + "name": "ck_project_role_grants_grant_method", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND revoked_at IS NOT NULL)", + "kind": "c", + "name": "ck_project_role_grants_lifecycle", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (project_role_reason_is_safe(grant_reason) AND (revoked_reason IS NULL OR project_role_reason_is_safe(revoked_reason)))", + "kind": "c", + "name": "ck_project_role_grants_reason", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", + "kind": "c", + "name": "ck_project_role_grants_role", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_grants_actor_profile_id_actor_profiles", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_grants_granted_by_actor_profile_id_acto_c240", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_role_grants_granted_by_admin_role_grant_id_a_71d7", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_role_grants_project_id_projects", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_grants_revoked_by_actor_profile_id_acto_a5dd", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_role_grants_revoked_by_admin_role_grant_id_a_aa4d", + "table_name": "project_role_grants" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_role_grants", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (qualification_snapshot_id, actor_profile_id, project_id, role) REFERENCES project_role_qualification_snapshots(id, actor_profile_id, project_id, requested_role) ON DELETE RESTRICT", + "kind": "f", + "name": "qualification_ownership", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (project_role_availability_is_safe(skills_snapshot) AND project_role_availability_is_safe(reputation_snapshot))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_availability", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (project_role_reference_array_is_safe(external_expertise_refs, false))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_external_expertise_refs", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (project_role_reference_array_is_safe(prior_project_work_refs, true))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_prior_work_refs", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (requested_role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_role", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_actor_profile_i_aedc", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (captured_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_captured_by_act_ab57", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (captured_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_captured_by_adm_c8b8", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_project_id_projects", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "UNIQUE (id, actor_profile_id, project_id, requested_role)", + "kind": "u", + "name": "grant_reference", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_role_qualification_snapshots", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_project_setup_runs_ck_project_setup_runs_generation_positive", + "table_name": "project_setup_runs" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['queued', 'dispatch_pending', 'enqueue_failed', 'enqueue_identity_mismatch', 'running_sufficiency_agent', 'sufficiency_blocked', 'running_policy_derivation_agent', 'policy_draft_ready', 'running_post_submit_derivation_agent', 'post_submit_setup_blocked', 'post_submit_policy_compiled', 'setup_blocked', 'failed']))", + "kind": "c", + "name": "ck_project_setup_runs_ck_project_setup_runs_status", + "table_name": "project_setup_runs" + }, + { + "definition": "CHECK (authorized_by_actor_profile_id IS NULL AND authorized_via_identity_link_id IS NULL AND authorized_by_admin_role_grant_id IS NULL AND authorization_scope_type IS NULL AND authorization_scope_project_id IS NULL AND authorization_action_id IS NULL AND authorization_decision_event_id IS NULL OR authorized_by_actor_profile_id IS NOT NULL AND authorized_via_identity_link_id IS NOT NULL AND authorized_by_admin_role_grant_id IS NOT NULL AND (authorization_scope_type::text = ANY (ARRAY['system', 'project'])) AND (authorization_scope_type::text = 'system'::text AND authorization_scope_project_id IS NULL OR authorization_scope_type::text = 'project'::text AND authorization_scope_project_id::text = project_id::text) AND authorization_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_project_setup_runs_setup_run_authority_shape", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (error_artifact_incident_id) REFERENCES guide_source_artifact_incidents(id)", + "kind": "f", + "name": "fk_project_setup_runs_artifact_incident", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorized_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_actor", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorized_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_admin_grant", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_decision", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorized_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_identity_link", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (continuation_verification_job_id) REFERENCES artifact_verification_jobs(id)", + "kind": "f", + "name": "fk_project_setup_runs_continuation_verification_job", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_project_setup_runs_guide_id_project_guides", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (output_post_submit_checker_policy_id) REFERENCES checker_policies(id)", + "kind": "f", + "name": "fk_project_setup_runs_post_submit_checker_policy", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_project_setup_runs_project_guide", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_setup_runs_project_id_projects", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_project_setup_runs_source_snapshot_hash", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_project_setup_runs_source_snapshot_id_guide_source_snapshots", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (output_submission_artifact_policy_id) REFERENCES submission_artifact_policies(id)", + "kind": "f", + "name": "fk_project_setup_runs_submission_artifact_policy", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (output_sufficiency_report_id) REFERENCES guide_sufficiency_reports(id)", + "kind": "f", + "name": "fk_project_setup_runs_sufficiency_report", + "table_name": "project_setup_runs" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_setup_runs", + "table_name": "project_setup_runs" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "source_setup_run_custody", + "table_name": "project_setup_runs" + }, + { + "definition": "UNIQUE (id, project_id, guide_id, source_snapshot_id, setup_generation)", + "kind": "u", + "name": "uq_project_setup_runs_exact_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "UNIQUE (guide_id, setup_generation)", + "kind": "u", + "name": "uq_project_setup_runs_guide_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type::text = 'system'::text AND creation_action_id::text = 'project.create'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_projects_creation_authority_shape", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_projects_creation_actor", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_projects_creation_admin_grant", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_projects_creation_decision", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_projects_creation_identity_link", + "table_name": "projects" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_projects", + "table_name": "projects" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "project_creation_custody", + "table_name": "projects" + }, + { + "definition": "UNIQUE (slug)", + "kind": "u", + "name": "uq_projects_slug", + "table_name": "projects" + }, + { + "definition": "CHECK (submission_version > 0)", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_2b6d", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND review_queue_entry_id IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND review_queue_entry_id IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_4cd5", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_88bf", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_b8b8", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_review_admission_checker", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", + "kind": "f", + "name": "fk_review_admission_committed_queue", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_admission_project", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (review_queue_entry_id) REFERENCES review_queue_entries(id)", + "kind": "f", + "name": "fk_review_admission_queue", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_review_admission_submission", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_review_admission_submission_lineage", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_review_admission_task", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_admission_idempotency_records", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "UNIQUE (admitting_checker_run_id)", + "kind": "u", + "name": "uq_review_admission_checker_run", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_review_admission_operation", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "UNIQUE (idempotency_key)", + "kind": "u", + "name": "uq_review_admission_replay_key", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (attempt_generation > 0)", + "kind": "c", + "name": "ck_review_leases_attempt_generation_positive", + "table_name": "review_leases" + }, + { + "definition": "CHECK (closed_at IS NULL OR closed_at >= claimed_at)", + "kind": "c", + "name": "ck_review_leases_closure_after_claim", + "table_name": "review_leases" + }, + { + "definition": "CHECK (expires_at > claimed_at)", + "kind": "c", + "name": "ck_review_leases_expiry_after_claim", + "table_name": "review_leases" + }, + { + "definition": "CHECK (status::text = 'active'::text AND closed_at IS NULL AND close_reason IS NULL OR status::text = 'consumed'::text AND closed_at IS NOT NULL AND close_reason::text = 'review_recorded'::text OR status::text = 'released'::text AND closed_at IS NOT NULL AND close_reason::text = 'manual_release'::text OR status::text = 'expired'::text AND closed_at IS NOT NULL AND close_reason::text = 'lease_expired'::text OR status::text = 'revoked'::text AND closed_at IS NOT NULL AND (close_reason::text = ANY (ARRAY['grant_revoked', 'admin_override'])))", + "kind": "c", + "name": "ck_review_leases_lifecycle_shape", + "table_name": "review_leases" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'consumed', 'released', 'expired', 'revoked']))", + "kind": "c", + "name": "ck_review_leases_status", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (reviewer_contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", + "kind": "f", + "name": "fk_review_lease_policy_version", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_lease_project", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version)", + "kind": "f", + "name": "fk_review_lease_queue_lineage", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (reviewer_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_review_lease_reviewer", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_review_lease_submission", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_review_lease_task", + "table_name": "review_leases" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_leases", + "table_name": "review_leases" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "review_leases_active_lease_guard", + "table_name": "review_leases" + }, + { + "definition": "UNIQUE (review_queue_entry_id, attempt_generation)", + "kind": "u", + "name": "uq_review_lease_attempt", + "table_name": "review_leases" + }, + { + "definition": "UNIQUE (review_queue_entry_id, id)", + "kind": "u", + "name": "uq_review_lease_queue_identity", + "table_name": "review_leases" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.review_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_review_policies_review_policy_authority_shape", + "table_name": "review_policies" + }, + { + "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", + "kind": "c", + "name": "ck_review_policies_review_policy_identity_shape", + "table_name": "review_policies" + }, + { + "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", + "kind": "c", + "name": "ck_review_policies_review_policy_predecessor_shape", + "table_name": "review_policies" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR review_preference_window_seconds > 0 AND review_lease_duration_seconds > 0 AND max_active_review_leases_per_reviewer = 1 AND self_review_allowed = false AND reject_policy::text = 'close_task'::text AND (finding_evidence_requirement::text = ANY (ARRAY['optional', 'required_for_blocking', 'required_for_all'])))", + "kind": "c", + "name": "ck_review_policies_review_policy_semantics_shape", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_review_policies_actor_profile", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_review_policies_admin_grant", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_review_policies_decision_event", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_review_policies_identity_link", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_review_policies_project_guide", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_policies_project_id_projects", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES review_policies(id)", + "kind": "f", + "name": "fk_review_policies_supersedes", + "table_name": "review_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_policies", + "table_name": "review_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "review_policy_mutation_custody", + "table_name": "review_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, policy_generation)", + "kind": "u", + "name": "uq_review_policies_project_version_generation", + "table_name": "review_policies" + }, + { + "definition": "UNIQUE (id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_review_policy_lineage", + "table_name": "review_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_review_policy_scoped_lineage", + "table_name": "review_policies" + }, + { + "definition": "CHECK (available_since >= first_queued_at)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_availab_d484", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_generation > 0 AND lifecycle_generation > 0)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_generat_38b7", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (queue_state::text = 'pending'::text AND active_lease_id IS NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'leased'::text AND active_lease_id IS NOT NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'closed'::text AND active_lease_id IS NULL AND closed_at IS NOT NULL AND (closed_reason::text = ANY (ARRAY['review_recorded', 'task_closed', 'admin_cancelled'])) AND closed_at >= first_queued_at)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_lifecycle_shape", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (queue_state::text = ANY (ARRAY['pending', 'leased', 'closed']))", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_queue_state", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_mode::text = ANY (ARRAY['open', 'preferred']))", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_routing_mode", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_reason::text = ANY (ARRAY['first_submission', 'revision_return', 'admin_assignment']))", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_routing_reason", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_mode::text = 'open'::text AND preferred_reviewer_id IS NULL AND preference_expires_at IS NULL OR routing_mode::text = 'preferred'::text AND preferred_reviewer_id IS NOT NULL AND preference_expires_at IS NOT NULL AND preference_expires_at > first_queued_at)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_routing_shape", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (submission_version > 0)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_submiss_2f6b", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (active_lease_id, id) REFERENCES review_leases(id, review_queue_entry_id) DEFERRABLE INITIALLY DEFERRED", + "kind": "f", + "name": "fk_review_queue_active_lease", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_review_queue_checker", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (preferred_reviewer_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_review_queue_preferred_reviewer", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_queue_project", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_review_queue_submission", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_review_queue_submission_lineage", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_review_queue_task", + "table_name": "review_queue_entries" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_queue_entries", + "table_name": "review_queue_entries" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "review_queue_entries_active_lease_guard", + "table_name": "review_queue_entries" + }, + { + "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", + "kind": "u", + "name": "uq_review_queue_admission_identity", + "table_name": "review_queue_entries" + }, + { + "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version)", + "kind": "u", + "name": "uq_review_queue_lease_lineage", + "table_name": "review_queue_entries" + }, + { + "definition": "UNIQUE (submission_id)", + "kind": "u", + "name": "uq_review_queue_submission", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.revision_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_revision_policies_revision_policy_authority_shape", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", + "kind": "c", + "name": "ck_revision_policies_revision_policy_identity_shape", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", + "kind": "c", + "name": "ck_revision_policies_revision_policy_predecessor_shape", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR max_revision_rounds > 0 AND revision_deadline_hours > 0)", + "kind": "c", + "name": "ck_revision_policies_revision_policy_semantics_shape", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_revision_policies_actor_profile", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_revision_policies_admin_grant", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_revision_policies_decision_event", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_revision_policies_identity_link", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_revision_policies_project_guide", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_revision_policies_project_id_projects", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES revision_policies(id)", + "kind": "f", + "name": "fk_revision_policies_supersedes", + "table_name": "revision_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_revision_policies", + "table_name": "revision_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "revision_policy_mutation_custody", + "table_name": "revision_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, policy_generation)", + "kind": "u", + "name": "uq_revision_policies_project_version_generation", + "table_name": "revision_policies" + }, + { + "definition": "UNIQUE (id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_revision_policy_lineage", + "table_name": "revision_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_revision_policy_scoped_lineage", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['draft', 'approved', 'superseded']))", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_artifact__20ca", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_artifact__52ca", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (approved_by_actor_profile_id IS NULL AND approved_via_identity_link_id IS NULL AND approved_by_admin_role_grant_id IS NULL AND approval_scope_type IS NULL AND approval_scope_project_id IS NULL AND approval_action_id IS NULL AND approval_decision_event_id IS NULL OR approved_by_actor_profile_id IS NOT NULL AND approved_via_identity_link_id IS NOT NULL AND approved_by_admin_role_grant_id IS NOT NULL AND approval_scope_type IS NOT NULL AND approval_action_id IS NOT NULL AND (approval_scope_type::text = ANY (ARRAY['system', 'project'])) AND approval_scope_project_id IS NOT NULL AND approval_scope_project_id::text = project_id::text AND approval_action_id::text = 'project.submission_artifact_policy.approve'::text AND approval_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_policy_ap_0e4d", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_decision_event_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update'])) AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NOT NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.submission_artifact_policy.derive'::text))", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_policy_cr_0629", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES submission_artifact_policies(id)", + "kind": "f", + "name": "fk_sap_supersedes_policy", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_submission_artifact_policies_guide_id_project_guides", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_submission_artifact_policies_project_guide", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_artifact_policies_project_id_projects", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_submission_artifact_policies_source_snapshot_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approved_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submission_policy_approval_actor", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approval_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_submission_policy_approval_decision", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approved_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_submission_policy_approval_grant", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approved_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_submission_policy_approval_link", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approval_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_policy_approval_project", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submission_policy_creation_actor", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_submission_policy_creation_decision", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_submission_policy_creation_grant", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_submission_policy_creation_link", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_policy_creation_project", + "table_name": "submission_artifact_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_artifact_policies", + "table_name": "submission_artifact_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "submission_policy_creation_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "submission_policy_product_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "UNIQUE (id, policy_hash)", + "kind": "u", + "name": "uq_submission_artifact_policies_id_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, policy_version)", + "kind": "u", + "name": "uq_submission_artifact_policies_project_version_policy", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_bundle_admissions_archive_sha256", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (archive_byte_count >= 0)", + "kind": "c", + "name": "ck_submission_bundle_admissions_archive_size", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_bundle_admissions_manifest_sha256", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_bundle_admissions_policy_context_hash", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK ((predecessor_submission_id IS NULL) = (predecessor_submission_version IS NULL))", + "kind": "c", + "name": "ck_submission_bundle_admissions_predecessor_shape", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['ready', 'consumed', 'stale']))", + "kind": "c", + "name": "ck_submission_bundle_admissions_status", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (status::text = 'ready'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'consumed'::text AND consumed_at IS NOT NULL AND consumed_by_submission_id IS NOT NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'stale'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NOT NULL AND octet_length(stale_reason::text) >= 1 AND octet_length(stale_reason::text) <= 500)", + "kind": "c", + "name": "ck_submission_bundle_admissions_terminal_shape", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (((put_operation_receipt_id IS NOT NULL)::integer + (put_observation_receipt_id IS NOT NULL)::integer) = 1)", + "kind": "c", + "name": "ck_submission_bundle_admissions_write_receipt_shape", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_actor_profile_id_actor_profiles", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (artifact_content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_artifact_content_id_art_12c8", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_assignment_id_task_assignments", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (consumed_by_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_consumed_by_submission__2b23", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (durable_intent_id) REFERENCES submission_bundle_durable_intents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_durable_intent_id_submi_102c", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_identity_link_id_actor__d29d", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_pre_submit_evidence_set_a752", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_predecessor_submission__242d", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_project_id_projects", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_put_attempt_id_artifact_bbc3", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (put_observation_receipt_id) REFERENCES artifact_put_observation_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_put_observation_receipt_5136", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (put_operation_receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_put_operation_receipt_i_9602", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_task_id_workstream_tasks", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (verification_receipt_id) REFERENCES artifact_verification_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_verification_receipt_id_0ea1", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (verified_replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_verified_replica_id_art_3a4e", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_bundle_admissions", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "UNIQUE (pre_submit_evidence_set_id)", + "kind": "u", + "name": "uq_submission_bundle_admission_evidence", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "UNIQUE (durable_intent_id)", + "kind": "u", + "name": "uq_submission_bundle_admission_intent", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "UNIQUE (verification_receipt_id)", + "kind": "u", + "name": "uq_submission_bundle_admission_verification", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_durable_intents_pre_submit_evidenc_c406", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_durable_intents_put_attempt_id_art_b4e4", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_bundle_durable_intents", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "UNIQUE (pre_submit_evidence_set_id)", + "kind": "u", + "name": "uq_submission_bundle_intent_evidence", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "UNIQUE (put_attempt_id)", + "kind": "u", + "name": "uq_submission_bundle_intent_put_attempt", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0119", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update', 'project.submission_artifact_policy.approve']))", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0dbe", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_2b53", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK ((status::text = ANY (ARRAY['reserved', 'pending'])) AND response_json IS NULL AND committed_at IS NULL AND committed_policy_id IS NULL AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND committed_policy_id IS NOT NULL AND (action_id::text = 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NOT NULL AND committed_pre_submit_policy_id IS NOT NULL OR action_id::text <> 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL))", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_58d4", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['reserved', 'pending', 'committed']))", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_a824", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (service_identity IS NULL AND idempotency_key IS NOT NULL AND setup_run_id IS NULL AND setup_task_id IS NULL AND correlation_id IS NULL OR service_identity IS NOT NULL AND service_identity::text = 'workstream.project.setup'::text AND idempotency_key IS NULL AND action_id::text = 'project.submission_artifact_policy.derive'::text AND setup_run_id IS NOT NULL AND setup_task_id IS NOT NULL AND correlation_id IS NOT NULL)", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_b357", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_actor_f5bb", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (committed_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_commi_4fa6", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (committed_policy_id) REFERENCES submission_artifact_policies(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_commi_571a", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (committed_pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_commi_baa9", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_guide_ed8d", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_ident_2567", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_proje_442a", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_setup_a102", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_sourc_536e", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_policy_mutation_idempotency_records", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "submission_policy_replay_custody", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_submission_policy_operation_identity", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", + "kind": "c", + "name": "ck_submissions_post_submit_policy_lock_complete", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submissions_contributor_id_actor_profiles", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_submissions_locked_effective_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", + "kind": "f", + "name": "fk_submissions_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", + "kind": "f", + "name": "fk_submissions_locked_pre_submit_checker_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_submissions_locked_source_snapshot_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (supersedes_submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_submissions_supersedes_submission_id_submissions", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_submissions_task_id_workstream_tasks", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_effective_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", + "kind": "f", + "name": "fk_submissions_task_locked_guide", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", + "kind": "f", + "name": "fk_submissions_task_locked_payment_policy", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES workstream_tasks(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_pre_submit_checker_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_review_policy", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_revision_policy", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_source_snapshot_hash", + "table_name": "submissions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submissions", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "u", + "name": "uq_submissions_id_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (id, task_id, version)", + "kind": "u", + "name": "uq_submissions_id_task_version", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (id, version)", + "kind": "u", + "name": "uq_submissions_id_version", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (task_id, version)", + "kind": "u", + "name": "uq_submissions_task_version", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_task_assignments_contributor_id_actor_profiles", + "table_name": "task_assignments" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_task_assignments_task_id_workstream_tasks", + "table_name": "task_assignments" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_task_assignments", + "table_name": "task_assignments" + }, + { + "definition": "UNIQUE (id, task_id, contributor_id)", + "kind": "u", + "name": "uq_task_assignments_id_task_contributor", + "table_name": "task_assignments" + }, + { + "definition": "CHECK (status::text = 'draft'::text OR locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", + "kind": "c", + "name": "ck_workstream_tasks_post_submit_policy_lock_complete", + "table_name": "workstream_tasks" + }, + { + "definition": "CHECK (status::text = 'draft'::text OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", + "kind": "c", + "name": "ck_workstream_tasks_review_revision_policy_lock_required", + "table_name": "workstream_tasks" + }, + { + "definition": "CHECK (locked_review_policy_id IS NULL AND locked_review_policy_generation IS NULL AND locked_review_policy_hash IS NULL AND locked_revision_policy_id IS NULL AND locked_revision_policy_generation IS NULL AND locked_revision_policy_hash IS NULL OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", + "kind": "c", + "name": "ck_workstream_tasks_review_revision_policy_lock_shape", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_workstream_tasks_locked_guide", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_payment_policy_version) REFERENCES payment_policies(project_id, guide_version)", + "kind": "f", + "name": "fk_workstream_tasks_locked_payment_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_review_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_revision_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_source_snapshot_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_workstream_tasks_project_id_projects", + "table_name": "workstream_tasks" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_workstream_tasks", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_guide_version)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_guide", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_payment_policy_version)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_payment_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_review_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_revision_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, project_id)", + "kind": "u", + "name": "uq_workstream_tasks_id_project", + "table_name": "workstream_tasks" + } + ], + "format": "workstream-v01-schema-manifest-1", + "indexes": [ + { + "definition": "CREATE INDEX ix_actor_identity_links_issuer_subject_status ON public.actor_identity_links USING btree (issuer, subject, status)", + "name": "ix_actor_identity_links_issuer_subject_status", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX pk_actor_identity_links ON public.actor_identity_links USING btree (id)", + "name": "pk_actor_identity_links", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_actor_profile ON public.actor_identity_links USING btree (actor_profile_id)", + "name": "uq_actor_identity_links_actor_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_external_identity ON public.actor_identity_links USING btree (issuer, subject)", + "name": "uq_actor_identity_links_external_identity", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_id_profile ON public.actor_identity_links USING btree (id, actor_profile_id)", + "name": "uq_actor_identity_links_id_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX pk_actor_profile_migration_state ON public.actor_profile_migration_state USING btree (id)", + "name": "pk_actor_profile_migration_state", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CREATE INDEX ix_actor_profiles_last_seen_at ON public.actor_profiles USING btree (last_seen_at)", + "name": "ix_actor_profiles_last_seen_at", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE INDEX ix_actor_profiles_status_actor_kind ON public.actor_profiles USING btree (status, actor_kind)", + "name": "ix_actor_profiles_status_actor_kind", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE UNIQUE INDEX pk_actor_profiles ON public.actor_profiles USING btree (id)", + "name": "pk_actor_profiles", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE UNIQUE INDEX service_identity ON public.actor_profiles USING btree (service_identity)", + "name": "service_identity", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE INDEX ix_admin_role_grants_effective_candidate ON public.admin_role_grants USING btree (target_actor_profile_id, status, scope_type, scope_project_id)", + "name": "ix_admin_role_grants_effective_candidate", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE INDEX ix_admin_role_grants_final_access_admin ON public.admin_role_grants USING btree (role, status) WHERE (((role)::text = 'access_administrator'::text) AND ((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", + "name": "ix_admin_role_grants_final_access_admin", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE INDEX ix_admin_role_grants_history ON public.admin_role_grants USING btree (target_actor_profile_id, granted_at, id)", + "name": "ix_admin_role_grants_history", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX pk_admin_role_grants ON public.admin_role_grants USING btree (id)", + "name": "pk_admin_role_grants", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_project ON public.admin_role_grants USING btree (target_actor_profile_id, role, scope_project_id) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'project'::text))", + "name": "uq_admin_role_grants_active_project", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_system ON public.admin_role_grants USING btree (target_actor_profile_id, role) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", + "name": "uq_admin_role_grants_active_system", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE INDEX ix_api_rate_control_counters_window_expires_at ON public.api_rate_control_counters USING btree (window_expires_at)", + "name": "ix_api_rate_control_counters_window_expires_at", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CREATE UNIQUE INDEX pk_api_rate_control_counters ON public.api_rate_control_counters USING btree (control_scope, key_digest)", + "name": "pk_api_rate_control_counters", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_admission_charges ON public.artifact_admission_charges USING btree (id)", + "name": "pk_artifact_admission_charges", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_admission_charge_scope_content ON public.artifact_admission_charges USING btree (scope_type, scope_id, sha256, byte_count)", + "name": "uq_artifact_admission_charge_scope_content", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_admission_scopes ON public.artifact_admission_scopes USING btree (scope_type, scope_id)", + "name": "pk_artifact_admission_scopes", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_content_id ON public.artifact_bindings USING btree (content_id)", + "name": "ix_artifact_bindings_content_id", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_project_id ON public.artifact_bindings USING btree (project_id)", + "name": "ix_artifact_bindings_project_id", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_scope ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version DESC)", + "name": "ix_artifact_bindings_scope", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_supersedes_binding_id ON public.artifact_bindings USING btree (supersedes_binding_id)", + "name": "ix_artifact_bindings_supersedes_binding_id", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_bindings ON public.artifact_bindings USING btree (id)", + "name": "pk_artifact_bindings", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_binding_scope_version ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version)", + "name": "uq_artifact_binding_scope_version", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_binding_supersedes ON public.artifact_bindings USING btree (supersedes_binding_id)", + "name": "uq_artifact_binding_supersedes", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_contents_sha256 ON public.artifact_contents USING btree (sha256)", + "name": "ix_artifact_contents_sha256", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_contents ON public.artifact_contents USING btree (id)", + "name": "pk_artifact_contents", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_content_digest_size ON public.artifact_contents USING btree (sha256, byte_count)", + "name": "uq_artifact_content_digest_size", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE INDEX ix_artifact_operation_receipts_put_attempt_id ON public.artifact_operation_receipts USING btree (put_attempt_id)", + "name": "ix_artifact_operation_receipts_put_attempt_id", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE INDEX ix_artifact_operation_receipts_replica_id ON public.artifact_operation_receipts USING btree (replica_id)", + "name": "ix_artifact_operation_receipts_replica_id", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_operation_receipts ON public.artifact_operation_receipts USING btree (id)", + "name": "pk_artifact_operation_receipts", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_receipt_put_attempt ON public.artifact_operation_receipts USING btree (put_attempt_id)", + "name": "uq_artifact_receipt_put_attempt", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempt_charges ON public.artifact_put_attempt_charges USING btree (attempt_id, charge_id)", + "name": "pk_artifact_put_attempt_charges", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_checker_run_id ON public.artifact_put_attempts USING btree (checker_run_id)", + "name": "ix_artifact_put_attempts_checker_run_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_guide_source_item_id ON public.artifact_put_attempts USING btree (guide_source_item_id)", + "name": "ix_artifact_put_attempts_guide_source_item_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_next_run_at ON public.artifact_put_attempts USING btree (next_run_at)", + "name": "ix_artifact_put_attempts_next_run_at", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_project_id ON public.artifact_put_attempts USING btree (project_id)", + "name": "ix_artifact_put_attempts_project_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_receipt_id ON public.artifact_put_attempts USING btree (receipt_id)", + "name": "ix_artifact_put_attempts_receipt_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_replica_id ON public.artifact_put_attempts USING btree (replica_id)", + "name": "ix_artifact_put_attempts_replica_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_status ON public.artifact_put_attempts USING btree (status)", + "name": "ix_artifact_put_attempts_status", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_task_id ON public.artifact_put_attempts USING btree (task_id)", + "name": "ix_artifact_put_attempts_task_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempts ON public.artifact_put_attempts USING btree (id)", + "name": "pk_artifact_put_attempts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_put_attempt_operation ON public.artifact_put_attempts USING btree (operation_identity)", + "name": "uq_artifact_put_attempt_operation", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_observation_receipts_put_attempt_id ON public.artifact_put_observation_receipts USING btree (put_attempt_id)", + "name": "ix_artifact_put_observation_receipts_put_attempt_id", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_put_observation_receipts ON public.artifact_put_observation_receipts USING btree (id)", + "name": "pk_artifact_put_observation_receipts", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_put_observation_fence ON public.artifact_put_observation_receipts USING btree (put_attempt_id, execution_generation)", + "name": "uq_artifact_put_observation_fence", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_parent_recovery_attempt_id ON public.artifact_recovery_attempts USING btree (parent_recovery_attempt_id)", + "name": "ix_artifact_recovery_attempts_parent_recovery_attempt_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_project_id ON public.artifact_recovery_attempts USING btree (project_id)", + "name": "ix_artifact_recovery_attempts_project_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_requester_actor_profile_id ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id)", + "name": "ix_artifact_recovery_attempts_requester_actor_profile_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_submission_id ON public.artifact_recovery_attempts USING btree (submission_id)", + "name": "ix_artifact_recovery_attempts_submission_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_task_id ON public.artifact_recovery_attempts USING btree (task_id)", + "name": "ix_artifact_recovery_attempts_task_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_recovery_attempts ON public.artifact_recovery_attempts USING btree (id)", + "name": "pk_artifact_recovery_attempts", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_idempotency ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", + "name": "uq_artifact_recovery_idempotency", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_retry_job ON public.artifact_recovery_attempts USING btree (retry_verification_job_id)", + "name": "uq_artifact_recovery_retry_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_source_job ON public.artifact_recovery_attempts USING btree (source_verification_job_id)", + "name": "uq_artifact_recovery_source_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_replicas_content_id ON public.artifact_replicas USING btree (content_id)", + "name": "ix_artifact_replicas_content_id", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE INDEX ix_artifact_replicas_storage_namespace_id ON public.artifact_replicas USING btree (storage_namespace_id)", + "name": "ix_artifact_replicas_storage_namespace_id", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_replicas ON public.artifact_replicas USING btree (id)", + "name": "pk_artifact_replicas", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_replica_provider_object ON public.artifact_replicas USING btree (storage_namespace_id, provider_object_ref)", + "name": "uq_artifact_replica_provider_object", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_replicas_id_content ON public.artifact_replicas USING btree (id, content_id)", + "name": "uq_artifact_replicas_id_content", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_storage_namespaces ON public.artifact_storage_namespaces USING btree (id)", + "name": "pk_artifact_storage_namespaces", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_fingerprint ON public.artifact_storage_namespaces USING btree (namespace_fingerprint)", + "name": "uq_artifact_storage_namespace_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_id_fingerprint ON public.artifact_storage_namespaces USING btree (id, namespace_fingerprint)", + "name": "uq_artifact_storage_namespace_id_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_next_run_at ON public.artifact_verification_jobs USING btree (next_run_at)", + "name": "ix_artifact_verification_jobs_next_run_at", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_originating_put_attempt_id ON public.artifact_verification_jobs USING btree (originating_put_attempt_id)", + "name": "ix_artifact_verification_jobs_originating_put_attempt_id", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_parent_verification_job_id ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", + "name": "ix_artifact_verification_jobs_parent_verification_job_id", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_replica_id ON public.artifact_verification_jobs USING btree (replica_id)", + "name": "ix_artifact_verification_jobs_replica_id", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_status ON public.artifact_verification_jobs USING btree (status)", + "name": "ix_artifact_verification_jobs_status", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_verification_jobs ON public.artifact_verification_jobs USING btree (id)", + "name": "pk_artifact_verification_jobs", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_verification_initial_origin ON public.artifact_verification_jobs USING btree (originating_put_attempt_id) WHERE (parent_verification_job_id IS NULL)", + "name": "uq_artifact_verification_initial_origin", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_verification_parent ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", + "name": "uq_artifact_verification_parent", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_receipts_verification_job_id ON public.artifact_verification_receipts USING btree (verification_job_id)", + "name": "ix_artifact_verification_receipts_verification_job_id", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_verification_receipts ON public.artifact_verification_receipts USING btree (id)", + "name": "pk_artifact_verification_receipts", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_verification_fence ON public.artifact_verification_receipts USING btree (verification_job_id, execution_generation)", + "name": "uq_artifact_verification_fence", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE INDEX ix_audit_events_actor_id ON public.audit_events USING btree (actor_id)", + "name": "ix_audit_events_actor_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_actor_ref ON public.audit_events USING btree (actor_ref_kind, actor_id)", + "name": "ix_audit_events_actor_ref", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_correlation_id ON public.audit_events USING btree (correlation_id)", + "name": "ix_audit_events_correlation_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_entity_id ON public.audit_events USING btree (entity_id)", + "name": "ix_audit_events_entity_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_entity_type ON public.audit_events USING btree (entity_type)", + "name": "ix_audit_events_entity_type", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_event_type ON public.audit_events USING btree (event_type)", + "name": "ix_audit_events_event_type", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_occurred_at ON public.audit_events USING btree (occurred_at)", + "name": "ix_audit_events_occurred_at", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_project_id ON public.audit_events USING btree (project_id)", + "name": "ix_audit_events_project_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_request_id ON public.audit_events USING btree (request_id)", + "name": "ix_audit_events_request_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE UNIQUE INDEX pk_audit_events ON public.audit_events USING btree (id)", + "name": "pk_audit_events", + "table_name": "audit_events" + }, + { + "definition": "CREATE UNIQUE INDEX pk_authority_control ON public.authority_control USING btree (id)", + "name": "pk_authority_control", + "table_name": "authority_control" + }, + { + "definition": "CREATE UNIQUE INDEX pk_authority_idempotency_records ON public.authority_idempotency_records USING btree (id)", + "name": "pk_authority_idempotency_records", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_actor_reference ON public.authority_idempotency_records USING btree (id, actor_ref_kind, actor_ref)", + "name": "uq_authority_idempotency_records_actor_reference", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_replay_namespace ON public.authority_idempotency_records USING btree (actor_ref_kind, actor_ref, operation, idempotency_key)", + "name": "uq_authority_idempotency_records_replay_namespace", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_checker_policies_effective_policy_hash ON public.checker_policies USING btree (effective_policy_hash)", + "name": "ix_checker_policies_effective_policy_hash", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_effective_policy_id ON public.checker_policies USING btree (effective_policy_id)", + "name": "ix_checker_policies_effective_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_guide_id ON public.checker_policies USING btree (guide_id)", + "name": "ix_checker_policies_guide_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_bundle_hash ON public.checker_policies USING btree (pre_submit_checker_bundle_hash)", + "name": "ix_checker_policies_pre_submit_checker_bundle_hash", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_policy_id ON public.checker_policies USING btree (pre_submit_checker_policy_id)", + "name": "ix_checker_policies_pre_submit_checker_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_project_id ON public.checker_policies USING btree (project_id)", + "name": "ix_checker_policies_project_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_source_snapshot_id ON public.checker_policies USING btree (source_snapshot_id)", + "name": "ix_checker_policies_source_snapshot_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_supersedes_policy_id ON public.checker_policies USING btree (supersedes_policy_id)", + "name": "ix_checker_policies_supersedes_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_checker_policies ON public.checker_policies USING btree (id)", + "name": "pk_checker_policies", + "table_name": "checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_policies_current_project_version ON public.checker_policies USING btree (project_id, guide_version) WHERE ((lifecycle_status)::text = ANY (ARRAY['compiled', 'approved']))", + "name": "uq_checker_policies_current_project_version", + "table_name": "checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_policies_id_version_hash ON public.checker_policies USING btree (id, guide_version, policy_hash)", + "name": "uq_checker_policies_id_version_hash", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_results_checker_name ON public.checker_results USING btree (checker_name)", + "name": "ix_checker_results_checker_name", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_checker_run_id ON public.checker_results USING btree (checker_run_id)", + "name": "ix_checker_results_checker_run_id", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_submission_id ON public.checker_results USING btree (submission_id)", + "name": "ix_checker_results_submission_id", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_task_id ON public.checker_results USING btree (task_id)", + "name": "ix_checker_results_task_id", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_worker_visible ON public.checker_results USING btree (worker_visible)", + "name": "ix_checker_results_worker_visible", + "table_name": "checker_results" + }, + { + "definition": "CREATE UNIQUE INDEX pk_checker_results ON public.checker_results USING btree (id)", + "name": "pk_checker_results", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_runs_audit_event_id ON public.checker_runs USING btree (audit_event_id)", + "name": "ix_checker_runs_audit_event_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_locked_post_submit_policy_hash ON public.checker_runs USING btree (locked_post_submit_checker_policy_hash)", + "name": "ix_checker_runs_locked_post_submit_policy_hash", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_routing_recommendation ON public.checker_runs USING btree (routing_recommendation)", + "name": "ix_checker_runs_routing_recommendation", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_status ON public.checker_runs USING btree (status)", + "name": "ix_checker_runs_status", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_submission_id ON public.checker_runs USING btree (submission_id)", + "name": "ix_checker_runs_submission_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_supersedes_checker_run_id ON public.checker_runs USING btree (supersedes_checker_run_id)", + "name": "ix_checker_runs_supersedes_checker_run_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_task_id ON public.checker_runs USING btree (task_id)", + "name": "ix_checker_runs_task_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_checker_runs ON public.checker_runs USING btree (id)", + "name": "pk_checker_runs", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_runs_current_per_submission ON public.checker_runs USING btree (submission_id) WHERE (is_current_for_submission = true)", + "name": "uq_checker_runs_current_per_submission", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_runs_submission_attempt ON public.checker_runs USING btree (submission_id, attempt_number)", + "name": "uq_checker_runs_submission_attempt", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_award_definitions ON public.contribution_award_definitions USING btree (id)", + "name": "pk_contribution_award_definitions", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_award_definition_instrument ON public.contribution_award_definitions USING btree (contribution_rule_id, instrument_type)", + "name": "uq_contribution_award_definition_instrument", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_policies ON public.contribution_policies USING btree (id)", + "name": "pk_contribution_policies", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_active_project ON public.contribution_policies USING btree (project_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_contribution_policy_active_project", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_ownership ON public.contribution_policies USING btree (id, project_id)", + "name": "uq_contribution_policy_ownership", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_policy_versions ON public.contribution_policy_versions USING btree (id)", + "name": "pk_contribution_policy_versions", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_number ON public.contribution_policy_versions USING btree (contribution_policy_id, version_number)", + "name": "uq_contribution_policy_version_number", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_ownership ON public.contribution_policy_versions USING btree (id, contribution_policy_id, project_id)", + "name": "uq_contribution_policy_version_ownership", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_project ON public.contribution_policy_versions USING btree (id, project_id)", + "name": "uq_contribution_policy_version_project", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_rules ON public.contribution_rules USING btree (id)", + "name": "pk_contribution_rules", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_rule_ownership ON public.contribution_rules USING btree (id, contribution_policy_version_id, project_id, contribution_type)", + "name": "uq_contribution_rule_ownership", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_rule_type ON public.contribution_rules USING btree (contribution_policy_version_id, contribution_type)", + "name": "uq_contribution_rule_type", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE INDEX ix_effective_psap_effective_hash ON public.effective_project_submission_artifact_policies USING btree (effective_policy_hash)", + "name": "ix_effective_psap_effective_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_guide ON public.effective_project_submission_artifact_policies USING btree (guide_id)", + "name": "ix_effective_psap_guide", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_lifecycle ON public.effective_project_submission_artifact_policies USING btree (lifecycle_status)", + "name": "ix_effective_psap_lifecycle", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_project ON public.effective_project_submission_artifact_policies USING btree (project_id)", + "name": "ix_effective_psap_project", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_source_snapshot ON public.effective_project_submission_artifact_policies USING btree (source_snapshot_id)", + "name": "ix_effective_psap_source_snapshot", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_submission_policy ON public.effective_project_submission_artifact_policies USING btree (submission_artifact_policy_id)", + "name": "ix_effective_psap_submission_policy", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_effective_project_submission_artifact_policies ON public.effective_project_submission_artifact_policies USING btree (id)", + "name": "pk_effective_project_submission_artifact_policies", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_effective_project_submission_artifact_policies_id_hash ON public.effective_project_submission_artifact_policies USING btree (id, effective_policy_hash)", + "name": "uq_effective_project_submission_artifact_policies_id_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_evidence_items_submission_id ON public.evidence_items USING btree (submission_id)", + "name": "ix_evidence_items_submission_id", + "table_name": "evidence_items" + }, + { + "definition": "CREATE INDEX ix_evidence_items_type ON public.evidence_items USING btree (type)", + "name": "ix_evidence_items_type", + "table_name": "evidence_items" + }, + { + "definition": "CREATE UNIQUE INDEX pk_evidence_items ON public.evidence_items USING btree (id)", + "name": "pk_evidence_items", + "table_name": "evidence_items" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_mutation_idempotency_records ON public.guide_mutation_idempotency_records USING btree (id)", + "name": "pk_guide_mutation_idempotency_records", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_mutation_operation_identity ON public.guide_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_guide_mutation_operation_identity", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_mutation_replay_namespace ON public.guide_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", + "name": "uq_guide_mutation_replay_namespace", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_content_id ON public.guide_source_artifact_bindings USING btree (content_id)", + "name": "ix_guide_source_artifact_bindings_content_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_guide_id ON public.guide_source_artifact_bindings USING btree (guide_id)", + "name": "ix_guide_source_artifact_bindings_guide_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_id ON public.guide_source_artifact_bindings USING btree (project_id)", + "name": "ix_guide_source_artifact_bindings_project_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_setup_run_id ON public.guide_source_artifact_bindings USING btree (project_setup_run_id)", + "name": "ix_guide_source_artifact_bindings_project_setup_run_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_item_id ON public.guide_source_artifact_bindings USING btree (source_item_id)", + "name": "ix_guide_source_artifact_bindings_source_item_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_snapshot_id ON public.guide_source_artifact_bindings USING btree (source_snapshot_id)", + "name": "ix_guide_source_artifact_bindings_source_snapshot_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_supersedes_binding_id ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", + "name": "ix_guide_source_artifact_bindings_supersedes_binding_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_verified_replica_id ON public.guide_source_artifact_bindings USING btree (verified_replica_id)", + "name": "ix_guide_source_artifact_bindings_verified_replica_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_bindings ON public.guide_source_artifact_bindings USING btree (id)", + "name": "pk_guide_source_artifact_bindings", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_exact_read ON public.guide_source_artifact_bindings USING btree (id, content_id, verified_replica_id, setup_generation)", + "name": "uq_guide_bindings_exact_read", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_attempt_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, setup_generation)", + "name": "uq_guide_bindings_extraction_attempt_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, source_item_id, project_setup_run_id, setup_generation)", + "name": "uq_guide_bindings_extraction_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_item_generation ON public.guide_source_artifact_bindings USING btree (source_item_id, setup_generation)", + "name": "uq_guide_bindings_item_generation", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_supersedes ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", + "name": "uq_guide_bindings_supersedes", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_incidents_binding_id ON public.guide_source_artifact_incidents USING btree (binding_id)", + "name": "ix_guide_source_artifact_incidents_binding_id", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_incidents_content_id ON public.guide_source_artifact_incidents USING btree (content_id)", + "name": "ix_guide_source_artifact_incidents_content_id", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_incidents_verified_replica_id ON public.guide_source_artifact_incidents USING btree (verified_replica_id)", + "name": "ix_guide_source_artifact_incidents_verified_replica_id", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_incidents ON public.guide_source_artifact_incidents USING btree (id)", + "name": "pk_guide_source_artifact_incidents", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_ingests_actor_profile_id ON public.guide_source_artifact_ingests USING btree (actor_profile_id)", + "name": "ix_guide_source_artifact_ingests_actor_profile_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE UNIQUE INDEX ix_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", + "name": "ix_guide_source_artifact_ingests_source_item_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_ingests ON public.guide_source_artifact_ingests USING btree (id)", + "name": "pk_guide_source_artifact_ingests", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", + "name": "uq_guide_source_artifact_ingests_source_item_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE INDEX ix_guide_source_extracted_contents_content_id ON public.guide_source_extracted_contents USING btree (content_id)", + "name": "ix_guide_source_extracted_contents_content_id", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extracted_contents ON public.guide_source_extracted_contents USING btree (id)", + "name": "pk_guide_source_extracted_contents", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_exact_usage ON public.guide_source_extracted_contents USING btree (id, content_id)", + "name": "uq_guide_extracted_contents_exact_usage", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_identity ON public.guide_source_extracted_contents USING btree (content_id, detected_format, extractor_name, extractor_version, policy_version)", + "name": "uq_guide_extracted_contents_identity", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_attempts_binding_id ON public.guide_source_extraction_attempts USING btree (binding_id)", + "name": "ix_guide_source_extraction_attempts_binding_id", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_attempts_content_id ON public.guide_source_extraction_attempts USING btree (content_id)", + "name": "ix_guide_source_extraction_attempts_content_id", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_attempts ON public.guide_source_extraction_attempts USING btree (id)", + "name": "pk_guide_source_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts ON public.guide_source_extraction_attempts USING btree (binding_id, policy_version, attempt_number)", + "name": "uq_guide_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts_exact_usage ON public.guide_source_extraction_attempts USING btree (id, binding_id, content_id, setup_generation, status)", + "name": "uq_guide_extraction_attempts_exact_usage", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_retry_budgets ON public.guide_source_extraction_retry_budgets USING btree (binding_id)", + "name": "pk_guide_source_extraction_retry_budgets", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_binding_id ON public.guide_source_extraction_usages USING btree (binding_id)", + "name": "ix_guide_source_extraction_usages_binding_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_content_id ON public.guide_source_extraction_usages USING btree (content_id)", + "name": "ix_guide_source_extraction_usages_content_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_extracted_content_id ON public.guide_source_extraction_usages USING btree (extracted_content_id)", + "name": "ix_guide_source_extraction_usages_extracted_content_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_project_setup_run_id ON public.guide_source_extraction_usages USING btree (project_setup_run_id)", + "name": "ix_guide_source_extraction_usages_project_setup_run_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_source_item_id ON public.guide_source_extraction_usages USING btree (source_item_id)", + "name": "ix_guide_source_extraction_usages_source_item_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_usages ON public.guide_source_extraction_usages USING btree (id)", + "name": "pk_guide_source_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages ON public.guide_source_extraction_usages USING btree (binding_id, extracted_content_id)", + "name": "uq_guide_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages_exact_provenance ON public.guide_source_extraction_usages USING btree (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", + "name": "uq_guide_extraction_usages_exact_provenance", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_format_classifications_binding_id ON public.guide_source_format_classifications USING btree (binding_id)", + "name": "ix_guide_source_format_classifications_binding_id", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE INDEX ix_guide_source_format_classifications_content_id ON public.guide_source_format_classifications USING btree (content_id)", + "name": "ix_guide_source_format_classifications_content_id", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE INDEX ix_guide_source_format_classifications_verified_replica_id ON public.guide_source_format_classifications USING btree (verified_replica_id)", + "name": "ix_guide_source_format_classifications_verified_replica_id", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_format_classifications ON public.guide_source_format_classifications USING btree (id)", + "name": "pk_guide_source_format_classifications", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_classifications_binding ON public.guide_source_format_classifications USING btree (binding_id)", + "name": "uq_guide_classifications_binding", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_classifications_extraction_lineage ON public.guide_source_format_classifications USING btree (id, binding_id, content_id, setup_generation)", + "name": "uq_guide_classifications_extraction_lineage", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshot_items_source_snapshot_id ON public.guide_source_snapshot_items USING btree (source_snapshot_id)", + "name": "ix_guide_source_snapshot_items_source_snapshot_id", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshot_items ON public.guide_source_snapshot_items USING btree (id)", + "name": "pk_guide_source_snapshot_items", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_exact_lineage ON public.guide_source_snapshot_items USING btree (id, source_snapshot_id)", + "name": "uq_guide_source_snapshot_items_exact_lineage", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_snapshot_order ON public.guide_source_snapshot_items USING btree (source_snapshot_id, item_order)", + "name": "uq_guide_source_snapshot_items_snapshot_order", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshots_bundle_hash ON public.guide_source_snapshots USING btree (bundle_hash)", + "name": "ix_guide_source_snapshots_bundle_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshots_guide_id ON public.guide_source_snapshots USING btree (guide_id)", + "name": "ix_guide_source_snapshots_guide_id", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshots_project_id ON public.guide_source_snapshots USING btree (project_id)", + "name": "ix_guide_source_snapshots_project_id", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshots ON public.guide_source_snapshots USING btree (id)", + "name": "pk_guide_source_snapshots", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_exact_lineage ON public.guide_source_snapshots USING btree (id, project_id, guide_id)", + "name": "uq_guide_source_snapshots_exact_lineage", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_id_hash ON public.guide_source_snapshots USING btree (id, bundle_hash)", + "name": "uq_guide_source_snapshots_id_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_project_version_hash ON public.guide_source_snapshots USING btree (project_id, guide_version, bundle_hash)", + "name": "uq_guide_source_snapshots_project_version_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_mutation_idempotency_records ON public.guide_sufficiency_mutation_idempotency_records USING btree (id)", + "name": "pk_guide_sufficiency_mutation_idempotency_records", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_operation_identity ON public.guide_sufficiency_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_sufficiency_mutation_operation_identity", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_replay_namespace ON public.guide_sufficiency_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key)", + "name": "uq_sufficiency_mutation_replay_namespace", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_sufficiency_report_source_usage_report_id ON public.guide_sufficiency_report_source_usages USING btree (report_id)", + "name": "ix_sufficiency_report_source_usage_report_id", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_report_source_usages ON public.guide_sufficiency_report_source_usages USING btree (id)", + "name": "pk_guide_sufficiency_report_source_usages", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_extraction_usage ON public.guide_sufficiency_report_source_usages USING btree (report_id, extraction_usage_id)", + "name": "uq_sufficiency_report_extraction_usage", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_item_order ON public.guide_sufficiency_report_source_usages USING btree (report_id, item_order)", + "name": "uq_sufficiency_report_item_order", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_guide_id ON public.guide_sufficiency_reports USING btree (guide_id)", + "name": "ix_guide_sufficiency_reports_guide_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_id ON public.guide_sufficiency_reports USING btree (project_id)", + "name": "ix_guide_sufficiency_reports_project_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_setup_run_id ON public.guide_sufficiency_reports USING btree (project_setup_run_id)", + "name": "ix_guide_sufficiency_reports_project_setup_run_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_source_snapshot_id ON public.guide_sufficiency_reports USING btree (source_snapshot_id)", + "name": "ix_guide_sufficiency_reports_source_snapshot_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_status ON public.guide_sufficiency_reports USING btree (status)", + "name": "ix_guide_sufficiency_reports_status", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_reports ON public.guide_sufficiency_reports USING btree (id)", + "name": "pk_guide_sufficiency_reports", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_diagnostic_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NULL)", + "name": "uq_guide_sufficiency_reports_diagnostic_snapshot", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_verified_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NOT NULL)", + "name": "uq_guide_sufficiency_reports_verified_snapshot", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX pk_iso_4217_currency_codes ON public.iso_4217_currency_codes USING btree (code)", + "name": "pk_iso_4217_currency_codes", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "CREATE UNIQUE INDEX pk_legacy_actor_identities ON public.legacy_actor_identities USING btree (actor_id)", + "name": "pk_legacy_actor_identities", + "table_name": "legacy_actor_identities" + }, + { + "definition": "CREATE UNIQUE INDEX uq_legacy_actor_identities_external_identity ON public.legacy_actor_identities USING btree (external_issuer, external_subject)", + "name": "uq_legacy_actor_identities_external_identity", + "table_name": "legacy_actor_identities" + }, + { + "definition": "CREATE INDEX ix_legacy_workflow_eligibility_actor_id ON public.legacy_workflow_eligibility USING btree (actor_id)", + "name": "ix_legacy_workflow_eligibility_actor_id", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE INDEX ix_legacy_workflow_eligibility_profile_type ON public.legacy_workflow_eligibility USING btree (profile_type)", + "name": "ix_legacy_workflow_eligibility_profile_type", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE INDEX ix_legacy_workflow_eligibility_status ON public.legacy_workflow_eligibility USING btree (status)", + "name": "ix_legacy_workflow_eligibility_status", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE UNIQUE INDEX pk_legacy_workflow_eligibility ON public.legacy_workflow_eligibility USING btree (id)", + "name": "pk_legacy_workflow_eligibility", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE UNIQUE INDEX uq_legacy_workflow_eligibility_actor_type_scope ON public.legacy_workflow_eligibility USING btree (actor_id, profile_type, scope_type, scope_id)", + "name": "uq_legacy_workflow_eligibility_actor_type_scope", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE INDEX ix_outbox_events_aggregate ON public.outbox_events USING btree (aggregate_type, aggregate_id, occurred_at, event_id)", + "name": "ix_outbox_events_aggregate", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_eligible ON public.outbox_events USING btree (event_type, delivery_state, next_attempt_at, occurred_at, event_id) WHERE ((delivery_state)::text = ANY (ARRAY['pending', 'retryable']))", + "name": "ix_outbox_events_eligible", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_expired_claims ON public.outbox_events USING btree (claim_expires_at, event_id) WHERE ((delivery_state)::text = 'claimed'::text)", + "name": "ix_outbox_events_expired_claims", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_project_drain ON public.outbox_events USING btree (project_id, delivery_state, occurred_at, event_id)", + "name": "ix_outbox_events_project_drain", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_retention ON public.outbox_events USING btree (finalized_at, event_id) WHERE (((delivery_state)::text = ANY (ARRAY['acknowledged', 'dead_letter', 'cancelled'])) AND (archived_at IS NULL))", + "name": "ix_outbox_events_retention", + "table_name": "outbox_events" + }, + { + "definition": "CREATE UNIQUE INDEX pk_outbox_events ON public.outbox_events USING btree (event_id)", + "name": "pk_outbox_events", + "table_name": "outbox_events" + }, + { + "definition": "CREATE UNIQUE INDEX uq_outbox_events_idempotency_key ON public.outbox_events USING btree (idempotency_key)", + "name": "uq_outbox_events_idempotency_key", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_payment_policies_project_id ON public.payment_policies USING btree (project_id)", + "name": "ix_payment_policies_project_id", + "table_name": "payment_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_payment_policies ON public.payment_policies USING btree (id)", + "name": "pk_payment_policies", + "table_name": "payment_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_payment_policies_project_version ON public.payment_policies USING btree (project_id, guide_version)", + "name": "uq_payment_policies_project_version", + "table_name": "payment_policies" + }, + { + "definition": "CREATE INDEX ix_policy_mutation_custody_lookup ON public.policy_mutation_idempotency_records USING btree (policy_id, action_id, policy_generation, status)", + "name": "ix_policy_mutation_custody_lookup", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX pk_policy_mutation_idempotency_records ON public.policy_mutation_idempotency_records USING btree (id)", + "name": "pk_policy_mutation_idempotency_records", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_policy_mutation_operation_identity ON public.policy_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_policy_mutation_operation_identity", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_policy_mutation_replay_namespace ON public.policy_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", + "name": "uq_policy_mutation_replay_namespace", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_compiled_hash ON public.pre_submit_checker_policies USING btree (compiled_bundle_hash)", + "name": "ix_pre_submit_checker_compiled_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_effective ON public.pre_submit_checker_policies USING btree (effective_policy_id)", + "name": "ix_pre_submit_checker_effective", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_effective_hash ON public.pre_submit_checker_policies USING btree (effective_policy_hash)", + "name": "ix_pre_submit_checker_effective_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_guide ON public.pre_submit_checker_policies USING btree (guide_id)", + "name": "ix_pre_submit_checker_guide", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_lifecycle ON public.pre_submit_checker_policies USING btree (lifecycle_status)", + "name": "ix_pre_submit_checker_lifecycle", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_project ON public.pre_submit_checker_policies USING btree (project_id)", + "name": "ix_pre_submit_checker_project", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_source_snapshot ON public.pre_submit_checker_policies USING btree (source_snapshot_id)", + "name": "ix_pre_submit_checker_source_snapshot", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_pre_submit_checker_policies ON public.pre_submit_checker_policies USING btree (id)", + "name": "pk_pre_submit_checker_policies", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_checker_policies_id_compiled_bundle_hash ON public.pre_submit_checker_policies USING btree (id, compiled_bundle_hash)", + "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_results_evidence_set_id ON public.pre_submit_evidence_results USING btree (evidence_set_id)", + "name": "ix_pre_submit_evidence_results_evidence_set_id", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_results ON public.pre_submit_evidence_results USING btree (id)", + "name": "pk_pre_submit_evidence_results", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_definition ON public.pre_submit_evidence_results USING btree (evidence_set_id, definition_id)", + "name": "uq_pre_submit_result_definition", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_order ON public.pre_submit_evidence_results USING btree (evidence_set_id, result_order)", + "name": "uq_pre_submit_result_order", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_sets_actor_profile_id ON public.pre_submit_evidence_sets USING btree (actor_profile_id)", + "name": "ix_pre_submit_evidence_sets_actor_profile_id", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_sets_project_id ON public.pre_submit_evidence_sets USING btree (project_id)", + "name": "ix_pre_submit_evidence_sets_project_id", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_sets_task_id ON public.pre_submit_evidence_sets USING btree (task_id)", + "name": "ix_pre_submit_evidence_sets_task_id", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_sets ON public.pre_submit_evidence_sets USING btree (id)", + "name": "pk_pre_submit_evidence_sets", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_evidence_operation ON public.pre_submit_evidence_sets USING btree (operation_identity)", + "name": "uq_pre_submit_evidence_operation", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE INDEX ix_compensation_binding_adapter_actor ON public.project_compensation_adapter_bindings USING btree (adapter_actor_id, status, id)", + "name": "ix_compensation_binding_adapter_actor", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_compensation_adapter_bindings ON public.project_compensation_adapter_bindings USING btree (id)", + "name": "pk_project_compensation_adapter_bindings", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compensation_binding_active_project_instrument ON public.project_compensation_adapter_bindings USING btree (project_id, instrument_type) WHERE ((status)::text = 'active'::text)", + "name": "uq_compensation_binding_active_project_instrument", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compensation_binding_ownership ON public.project_compensation_adapter_bindings USING btree (id, project_id, instrument_type)", + "name": "uq_compensation_binding_ownership", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_compensation_units ON public.project_compensation_units USING btree (project_id, instrument_type, unit_code)", + "name": "pk_project_compensation_units", + "table_name": "project_compensation_units" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_create_idempotency_records ON public.project_create_idempotency_records USING btree (id)", + "name": "pk_project_create_idempotency_records", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_create_operation_identity ON public.project_create_idempotency_records USING btree (operation_id)", + "name": "uq_project_create_operation_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_create_project_identity ON public.project_create_idempotency_records USING btree (project_id)", + "name": "uq_project_create_project_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_create_replay_namespace ON public.project_create_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", + "name": "uq_project_create_replay_namespace", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_guide_id ON public.project_guide_compilation_attempts USING btree (guide_id)", + "name": "ix_project_guide_compilation_attempts_guide_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_project_id ON public.project_guide_compilation_attempts USING btree (project_id)", + "name": "ix_project_guide_compilation_attempts_project_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_setup_run_id ON public.project_guide_compilation_attempts USING btree (setup_run_id)", + "name": "ix_project_guide_compilation_attempts_setup_run_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_source_snapshot_id ON public.project_guide_compilation_attempts USING btree (source_snapshot_id)", + "name": "ix_project_guide_compilation_attempts_source_snapshot_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_guide_compilation_attempts ON public.project_guide_compilation_attempts USING btree (id)", + "name": "pk_project_guide_compilation_attempts", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_provider_key ON public.project_guide_compilation_attempts USING btree (provider_idempotency_key)", + "name": "uq_compilation_attempt_provider_key", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_setup_generation ON public.project_guide_compilation_attempts USING btree (setup_run_id, setup_generation)", + "name": "uq_compilation_attempt_setup_generation", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_guide_id ON public.project_guide_compilations USING btree (guide_id)", + "name": "ix_project_guide_compilations_guide_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_project_id ON public.project_guide_compilations USING btree (project_id)", + "name": "ix_project_guide_compilations_project_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_setup_run_id ON public.project_guide_compilations USING btree (setup_run_id)", + "name": "ix_project_guide_compilations_setup_run_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_source_snapshot_id ON public.project_guide_compilations USING btree (source_snapshot_id)", + "name": "ix_project_guide_compilations_source_snapshot_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_guide_compilations ON public.project_guide_compilations USING btree (id)", + "name": "pk_project_guide_compilations", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_attempt ON public.project_guide_compilations USING btree (attempt_id)", + "name": "uq_project_guide_compilation_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_id_attempt ON public.project_guide_compilations USING btree (id, attempt_id)", + "name": "uq_project_guide_compilation_id_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_predecessor ON public.project_guide_compilations USING btree (supersedes_compilation_id)", + "name": "uq_project_guide_compilation_predecessor", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_root ON public.project_guide_compilations USING btree (project_id, guide_id) WHERE (supersedes_compilation_id IS NULL)", + "name": "uq_project_guide_compilation_root", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_scope ON public.project_guide_compilations USING btree (id, project_id, guide_id)", + "name": "uq_project_guide_compilation_scope", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guides_project_id ON public.project_guides USING btree (project_id)", + "name": "ix_project_guides_project_id", + "table_name": "project_guides" + }, + { + "definition": "CREATE INDEX ix_project_guides_status ON public.project_guides USING btree (status)", + "name": "ix_project_guides_status", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_guides ON public.project_guides USING btree (id)", + "name": "pk_project_guides", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guides_id_project_version ON public.project_guides USING btree (id, project_id, version)", + "name": "uq_project_guides_id_project_version", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guides_one_active_per_project ON public.project_guides USING btree (project_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_project_guides_one_active_per_project", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guides_project_version ON public.project_guides USING btree (project_id, version)", + "name": "uq_project_guides_project_version", + "table_name": "project_guides" + }, + { + "definition": "CREATE INDEX ix_project_role_grants_actor_role_status ON public.project_role_grants USING btree (actor_profile_id, role, status)", + "name": "ix_project_role_grants_actor_role_status", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE INDEX ix_project_role_grants_project_actor_role_status ON public.project_role_grants USING btree (project_id, actor_profile_id, role, status)", + "name": "ix_project_role_grants_project_actor_role_status", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_role_grants ON public.project_role_grants USING btree (id)", + "name": "pk_project_role_grants", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_role_grants_active_exact_role ON public.project_role_grants USING btree (project_id, actor_profile_id, role) WHERE ((status)::text = 'active'::text)", + "name": "uq_project_role_grants_active_exact_role", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX grant_reference ON public.project_role_qualification_snapshots USING btree (id, actor_profile_id, project_id, requested_role)", + "name": "grant_reference", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE INDEX ix_project_role_qualification_snapshots_history ON public.project_role_qualification_snapshots USING btree (project_id, actor_profile_id, requested_role, captured_at)", + "name": "ix_project_role_qualification_snapshots_history", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_role_qualification_snapshots ON public.project_role_qualification_snapshots USING btree (id)", + "name": "pk_project_role_qualification_snapshots", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_celery_task_id ON public.project_setup_runs USING btree (celery_task_id)", + "name": "ix_project_setup_runs_celery_task_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_continuation_verification_job_id ON public.project_setup_runs USING btree (continuation_verification_job_id)", + "name": "ix_project_setup_runs_continuation_verification_job_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_error_artifact_incident_id ON public.project_setup_runs USING btree (error_artifact_incident_id)", + "name": "ix_project_setup_runs_error_artifact_incident_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_guide_id ON public.project_setup_runs USING btree (guide_id)", + "name": "ix_project_setup_runs_guide_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_output_post_submit_checker_policy_id ON public.project_setup_runs USING btree (output_post_submit_checker_policy_id)", + "name": "ix_project_setup_runs_output_post_submit_checker_policy_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_output_submission_artifact_policy_id ON public.project_setup_runs USING btree (output_submission_artifact_policy_id)", + "name": "ix_project_setup_runs_output_submission_artifact_policy_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_output_sufficiency_report_id ON public.project_setup_runs USING btree (output_sufficiency_report_id)", + "name": "ix_project_setup_runs_output_sufficiency_report_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_project_id ON public.project_setup_runs USING btree (project_id)", + "name": "ix_project_setup_runs_project_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_source_snapshot_id ON public.project_setup_runs USING btree (source_snapshot_id)", + "name": "ix_project_setup_runs_source_snapshot_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_status ON public.project_setup_runs USING btree (status)", + "name": "ix_project_setup_runs_status", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_setup_runs ON public.project_setup_runs USING btree (id)", + "name": "pk_project_setup_runs", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_exact_generation ON public.project_setup_runs USING btree (id, project_id, guide_id, source_snapshot_id, setup_generation)", + "name": "uq_project_setup_runs_exact_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_guide_generation ON public.project_setup_runs USING btree (guide_id, setup_generation)", + "name": "uq_project_setup_runs_guide_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_projects_slug ON public.projects USING btree (slug)", + "name": "ix_projects_slug", + "table_name": "projects" + }, + { + "definition": "CREATE INDEX ix_projects_status ON public.projects USING btree (status)", + "name": "ix_projects_status", + "table_name": "projects" + }, + { + "definition": "CREATE UNIQUE INDEX pk_projects ON public.projects USING btree (id)", + "name": "pk_projects", + "table_name": "projects" + }, + { + "definition": "CREATE UNIQUE INDEX uq_projects_slug ON public.projects USING btree (slug)", + "name": "uq_projects_slug", + "table_name": "projects" + }, + { + "definition": "CREATE INDEX ix_review_admission_submission ON public.review_admission_idempotency_records USING btree (submission_id, status, created_at, id)", + "name": "ix_review_admission_submission", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_admission_idempotency_records ON public.review_admission_idempotency_records USING btree (id)", + "name": "pk_review_admission_idempotency_records", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_admission_checker_run ON public.review_admission_idempotency_records USING btree (admitting_checker_run_id)", + "name": "uq_review_admission_checker_run", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_admission_operation ON public.review_admission_idempotency_records USING btree (operation_id)", + "name": "uq_review_admission_operation", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_admission_replay_key ON public.review_admission_idempotency_records USING btree (idempotency_key)", + "name": "uq_review_admission_replay_key", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_review_lease_expiry ON public.review_leases USING btree (status, expires_at, id)", + "name": "ix_review_lease_expiry", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_leases ON public.review_leases USING btree (id)", + "name": "pk_review_leases", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_active_queue ON public.review_leases USING btree (review_queue_entry_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_review_lease_active_queue", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_active_reviewer ON public.review_leases USING btree (reviewer_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_review_lease_active_reviewer", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_attempt ON public.review_leases USING btree (review_queue_entry_id, attempt_generation)", + "name": "uq_review_lease_attempt", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_queue_identity ON public.review_leases USING btree (review_queue_entry_id, id)", + "name": "uq_review_lease_queue_identity", + "table_name": "review_leases" + }, + { + "definition": "CREATE INDEX ix_review_policies_project_id ON public.review_policies USING btree (project_id)", + "name": "ix_review_policies_project_id", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_policies ON public.review_policies USING btree (id)", + "name": "pk_review_policies", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_policies_project_version_generation ON public.review_policies USING btree (project_id, guide_version, policy_generation)", + "name": "uq_review_policies_project_version_generation", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_policy_lineage ON public.review_policies USING btree (id, policy_generation, policy_hash)", + "name": "uq_review_policy_lineage", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_policy_scoped_lineage ON public.review_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", + "name": "uq_review_policy_scoped_lineage", + "table_name": "review_policies" + }, + { + "definition": "CREATE INDEX ix_review_queue_preference ON public.review_queue_entries USING btree (preferred_reviewer_id, queue_state, preference_expires_at, id)", + "name": "ix_review_queue_preference", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE INDEX ix_review_queue_selection ON public.review_queue_entries USING btree (project_id, queue_state, routing_mode, first_queued_at, id)", + "name": "ix_review_queue_selection", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_queue_entries ON public.review_queue_entries USING btree (id)", + "name": "pk_review_queue_entries", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_queue_admission_identity ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", + "name": "uq_review_queue_admission_identity", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_queue_lease_lineage ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version)", + "name": "uq_review_queue_lease_lineage", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_queue_submission ON public.review_queue_entries USING btree (submission_id)", + "name": "uq_review_queue_submission", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE INDEX ix_revision_policies_project_id ON public.revision_policies USING btree (project_id)", + "name": "ix_revision_policies_project_id", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_revision_policies ON public.revision_policies USING btree (id)", + "name": "pk_revision_policies", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_revision_policies_project_version_generation ON public.revision_policies USING btree (project_id, guide_version, policy_generation)", + "name": "uq_revision_policies_project_version_generation", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_revision_policy_lineage ON public.revision_policies USING btree (id, policy_generation, policy_hash)", + "name": "uq_revision_policy_lineage", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_revision_policy_scoped_lineage ON public.revision_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", + "name": "uq_revision_policy_scoped_lineage", + "table_name": "revision_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_guide_id ON public.submission_artifact_policies USING btree (guide_id)", + "name": "ix_submission_artifact_policies_guide_id", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_lifecycle_status ON public.submission_artifact_policies USING btree (lifecycle_status)", + "name": "ix_submission_artifact_policies_lifecycle_status", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_policy_hash ON public.submission_artifact_policies USING btree (policy_hash)", + "name": "ix_submission_artifact_policies_policy_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_project_id ON public.submission_artifact_policies USING btree (project_id)", + "name": "ix_submission_artifact_policies_project_id", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_source_snapshot_id ON public.submission_artifact_policies USING btree (source_snapshot_id)", + "name": "ix_submission_artifact_policies_source_snapshot_id", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_artifact_policies ON public.submission_artifact_policies USING btree (id)", + "name": "pk_submission_artifact_policies", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_id_hash ON public.submission_artifact_policies USING btree (id, policy_hash)", + "name": "uq_submission_artifact_policies_id_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_project_version_policy ON public.submission_artifact_policies USING btree (project_id, guide_version, policy_version)", + "name": "uq_submission_artifact_policies_project_version_policy", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_actor_profile_id ON public.submission_bundle_admissions USING btree (actor_profile_id)", + "name": "ix_submission_bundle_admissions_actor_profile_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_artifact_content_id ON public.submission_bundle_admissions USING btree (artifact_content_id)", + "name": "ix_submission_bundle_admissions_artifact_content_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_pre_submit_evidence_set_id ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", + "name": "ix_submission_bundle_admissions_pre_submit_evidence_set_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_project_id ON public.submission_bundle_admissions USING btree (project_id)", + "name": "ix_submission_bundle_admissions_project_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_status ON public.submission_bundle_admissions USING btree (status)", + "name": "ix_submission_bundle_admissions_status", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_task_id ON public.submission_bundle_admissions USING btree (task_id)", + "name": "ix_submission_bundle_admissions_task_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_bundle_admissions ON public.submission_bundle_admissions USING btree (id)", + "name": "pk_submission_bundle_admissions", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_consumer ON public.submission_bundle_admissions USING btree (consumed_by_submission_id) WHERE (consumed_by_submission_id IS NOT NULL)", + "name": "uq_submission_bundle_admission_consumer", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_evidence ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", + "name": "uq_submission_bundle_admission_evidence", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_intent ON public.submission_bundle_admissions USING btree (durable_intent_id)", + "name": "uq_submission_bundle_admission_intent", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_verification ON public.submission_bundle_admissions USING btree (verification_receipt_id)", + "name": "uq_submission_bundle_admission_verification", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_durable_intents_pre_submit_evidence_set_id ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", + "name": "ix_submission_bundle_durable_intents_pre_submit_evidence_set_id", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_durable_intents_put_attempt_id ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", + "name": "ix_submission_bundle_durable_intents_put_attempt_id", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_bundle_durable_intents ON public.submission_bundle_durable_intents USING btree (id)", + "name": "pk_submission_bundle_durable_intents", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_evidence ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", + "name": "uq_submission_bundle_intent_evidence", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_put_attempt ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", + "name": "uq_submission_bundle_intent_put_attempt", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_policy_mutation_idempotency_records ON public.submission_policy_mutation_idempotency_records USING btree (id)", + "name": "pk_submission_policy_mutation_idempotency_records", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_committed_policy_action ON public.submission_policy_mutation_idempotency_records USING btree (committed_policy_id, action_id) WHERE ((status)::text = 'committed'::text)", + "name": "uq_submission_policy_committed_policy_action", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_human_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key) WHERE (service_identity IS NULL)", + "name": "uq_submission_policy_human_replay_namespace", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_operation_identity ON public.submission_policy_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_submission_policy_operation_identity", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_service_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, setup_run_id, setup_generation, setup_task_id, correlation_id, action_id) WHERE (service_identity IS NOT NULL)", + "name": "uq_submission_policy_service_replay_namespace", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_submissions_contributor_id ON public.submissions USING btree (contributor_id)", + "name": "ix_submissions_contributor_id", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_effective_policy_hash ON public.submissions USING btree (locked_effective_project_submission_artifact_policy_hash)", + "name": "ix_submissions_locked_effective_policy_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_post_submit_policy_hash ON public.submissions USING btree (locked_post_submit_checker_policy_hash)", + "name": "ix_submissions_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_pre_submit_checker_hash ON public.submissions USING btree (locked_pre_submit_checker_bundle_hash)", + "name": "ix_submissions_locked_pre_submit_checker_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_source_snapshot ON public.submissions USING btree (locked_guide_source_snapshot_id)", + "name": "ix_submissions_locked_source_snapshot", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_status ON public.submissions USING btree (status)", + "name": "ix_submissions_status", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_supersedes_submission_id ON public.submissions USING btree (supersedes_submission_id)", + "name": "ix_submissions_supersedes_submission_id", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_task_id ON public.submissions USING btree (task_id)", + "name": "ix_submissions_task_id", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submissions ON public.submissions USING btree (id)", + "name": "pk_submissions", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_id_locked_post_submit_policy_hash ON public.submissions USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "name": "uq_submissions_id_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_id_task_version ON public.submissions USING btree (id, task_id, version)", + "name": "uq_submissions_id_task_version", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_id_version ON public.submissions USING btree (id, version)", + "name": "uq_submissions_id_version", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_task_version ON public.submissions USING btree (task_id, version)", + "name": "uq_submissions_task_version", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_task_assignments_contributor_id ON public.task_assignments USING btree (contributor_id)", + "name": "ix_task_assignments_contributor_id", + "table_name": "task_assignments" + }, + { + "definition": "CREATE INDEX ix_task_assignments_status ON public.task_assignments USING btree (status)", + "name": "ix_task_assignments_status", + "table_name": "task_assignments" + }, + { + "definition": "CREATE INDEX ix_task_assignments_task_id ON public.task_assignments USING btree (task_id)", + "name": "ix_task_assignments_task_id", + "table_name": "task_assignments" + }, + { + "definition": "CREATE UNIQUE INDEX pk_task_assignments ON public.task_assignments USING btree (id)", + "name": "pk_task_assignments", + "table_name": "task_assignments" + }, + { + "definition": "CREATE UNIQUE INDEX uq_task_assignments_id_task_contributor ON public.task_assignments USING btree (id, task_id, contributor_id)", + "name": "uq_task_assignments_id_task_contributor", + "table_name": "task_assignments" + }, + { + "definition": "CREATE UNIQUE INDEX uq_task_assignments_one_active_per_task ON public.task_assignments USING btree (task_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_task_assignments_one_active_per_task", + "table_name": "task_assignments" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_assigned_to ON public.workstream_tasks USING btree (assigned_to)", + "name": "ix_workstream_tasks_assigned_to", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_effective_policy_hash ON public.workstream_tasks USING btree (locked_effective_project_submission_artifact_policy_hash)", + "name": "ix_workstream_tasks_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (locked_post_submit_checker_policy_hash)", + "name": "ix_workstream_tasks_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (locked_pre_submit_checker_bundle_hash)", + "name": "ix_workstream_tasks_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_source_snapshot ON public.workstream_tasks USING btree (locked_guide_source_snapshot_id)", + "name": "ix_workstream_tasks_locked_source_snapshot", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_project_id ON public.workstream_tasks USING btree (project_id)", + "name": "ix_workstream_tasks_project_id", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_status ON public.workstream_tasks USING btree (status)", + "name": "ix_workstream_tasks_status", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX pk_workstream_tasks ON public.workstream_tasks USING btree (id)", + "name": "pk_workstream_tasks", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_effective_policy_hash ON public.workstream_tasks USING btree (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "name": "uq_workstream_tasks_id_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_guide ON public.workstream_tasks USING btree (id, locked_guide_version)", + "name": "uq_workstream_tasks_id_locked_guide", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_payment_policy ON public.workstream_tasks USING btree (id, locked_payment_policy_version)", + "name": "uq_workstream_tasks_id_locked_payment_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_review_policy ON public.workstream_tasks USING btree (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "name": "uq_workstream_tasks_id_locked_review_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_revision_policy ON public.workstream_tasks USING btree (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "name": "uq_workstream_tasks_id_locked_revision_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_source_snapshot_hash ON public.workstream_tasks USING btree (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_project ON public.workstream_tasks USING btree (id, project_id)", + "name": "uq_workstream_tasks_id_project", + "table_name": "workstream_tasks" + } + ], + "policies": [], + "reference_rows": { + "actor_profile_migration_state": [ + { + "classified_count": 0, + "envelope_sha256": null, + "id": 1, + "manifest_sha256": null, + "migrated_at": "2026-08-11T08:18:03.063940+00:00", + "schema_version": 1, + "service_identity_database_binding": "postgres-v1:aa1108b4a868ca4330673d1bbe499d99c330d196994696d89e56cf09bfc3c93e", + "service_identity_envelope_sha256": null, + "service_identity_manifest_sha256": null, + "service_identity_mapped_count": 0, + "service_identity_source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945", + "source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + } + ], + "authority_control": [ + { + "bootstrap_completed": false, + "bootstrap_grant_id": null, + "created_at": "2026-08-11T08:18:13.474128+00:00", + "id": 1, + "updated_at": "2026-08-11T08:18:13.474148+00:00", + "version": 0 + } + ], + "iso_4217_currency_codes": [ + { + "code": "AED" + }, + { + "code": "AFN" + }, + { + "code": "ALL" + }, + { + "code": "AMD" + }, + { + "code": "AOA" + }, + { + "code": "ARS" + }, + { + "code": "AUD" + }, + { + "code": "AWG" + }, + { + "code": "AZN" + }, + { + "code": "BAM" + }, + { + "code": "BBD" + }, + { + "code": "BDT" + }, + { + "code": "BHD" + }, + { + "code": "BIF" + }, + { + "code": "BMD" + }, + { + "code": "BND" + }, + { + "code": "BOB" + }, + { + "code": "BOV" + }, + { + "code": "BRL" + }, + { + "code": "BSD" + }, + { + "code": "BTN" + }, + { + "code": "BWP" + }, + { + "code": "BYN" + }, + { + "code": "BZD" + }, + { + "code": "CAD" + }, + { + "code": "CDF" + }, + { + "code": "CHE" + }, + { + "code": "CHF" + }, + { + "code": "CHW" + }, + { + "code": "CLF" + }, + { + "code": "CLP" + }, + { + "code": "CNY" + }, + { + "code": "COP" + }, + { + "code": "COU" + }, + { + "code": "CRC" + }, + { + "code": "CUP" + }, + { + "code": "CVE" + }, + { + "code": "CZK" + }, + { + "code": "DJF" + }, + { + "code": "DKK" + }, + { + "code": "DOP" + }, + { + "code": "DZD" + }, + { + "code": "EGP" + }, + { + "code": "ERN" + }, + { + "code": "ETB" + }, + { + "code": "EUR" + }, + { + "code": "FJD" + }, + { + "code": "FKP" + }, + { + "code": "GBP" + }, + { + "code": "GEL" + }, + { + "code": "GHS" + }, + { + "code": "GIP" + }, + { + "code": "GMD" + }, + { + "code": "GNF" + }, + { + "code": "GTQ" + }, + { + "code": "GYD" + }, + { + "code": "HKD" + }, + { + "code": "HNL" + }, + { + "code": "HTG" + }, + { + "code": "HUF" + }, + { + "code": "IDR" + }, + { + "code": "ILS" + }, + { + "code": "INR" + }, + { + "code": "IQD" + }, + { + "code": "IRR" + }, + { + "code": "ISK" + }, + { + "code": "JMD" + }, + { + "code": "JOD" + }, + { + "code": "JPY" + }, + { + "code": "KES" + }, + { + "code": "KGS" + }, + { + "code": "KHR" + }, + { + "code": "KMF" + }, + { + "code": "KPW" + }, + { + "code": "KRW" + }, + { + "code": "KWD" + }, + { + "code": "KYD" + }, + { + "code": "KZT" + }, + { + "code": "LAK" + }, + { + "code": "LBP" + }, + { + "code": "LKR" + }, + { + "code": "LRD" + }, + { + "code": "LSL" + }, + { + "code": "LYD" + }, + { + "code": "MAD" + }, + { + "code": "MDL" + }, + { + "code": "MGA" + }, + { + "code": "MKD" + }, + { + "code": "MMK" + }, + { + "code": "MNT" + }, + { + "code": "MOP" + }, + { + "code": "MRU" + }, + { + "code": "MUR" + }, + { + "code": "MVR" + }, + { + "code": "MWK" + }, + { + "code": "MXN" + }, + { + "code": "MXV" + }, + { + "code": "MYR" + }, + { + "code": "MZN" + }, + { + "code": "NAD" + }, + { + "code": "NGN" + }, + { + "code": "NIO" + }, + { + "code": "NOK" + }, + { + "code": "NPR" + }, + { + "code": "NZD" + }, + { + "code": "OMR" + }, + { + "code": "PAB" + }, + { + "code": "PEN" + }, + { + "code": "PGK" + }, + { + "code": "PHP" + }, + { + "code": "PKR" + }, + { + "code": "PLN" + }, + { + "code": "PYG" + }, + { + "code": "QAR" + }, + { + "code": "RON" + }, + { + "code": "RSD" + }, + { + "code": "RUB" + }, + { + "code": "RWF" + }, + { + "code": "SAR" + }, + { + "code": "SBD" + }, + { + "code": "SCR" + }, + { + "code": "SDG" + }, + { + "code": "SEK" + }, + { + "code": "SGD" + }, + { + "code": "SHP" + }, + { + "code": "SLE" + }, + { + "code": "SOS" + }, + { + "code": "SRD" + }, + { + "code": "SSP" + }, + { + "code": "STN" + }, + { + "code": "SVC" + }, + { + "code": "SYP" + }, + { + "code": "SZL" + }, + { + "code": "THB" + }, + { + "code": "TJS" + }, + { + "code": "TMT" + }, + { + "code": "TND" + }, + { + "code": "TOP" + }, + { + "code": "TRY" + }, + { + "code": "TTD" + }, + { + "code": "TWD" + }, + { + "code": "TZS" + }, + { + "code": "UAH" + }, + { + "code": "UGX" + }, + { + "code": "USD" + }, + { + "code": "USN" + }, + { + "code": "UYI" + }, + { + "code": "UYU" + }, + { + "code": "UYW" + }, + { + "code": "UZS" + }, + { + "code": "VED" + }, + { + "code": "VES" + }, + { + "code": "VND" + }, + { + "code": "VUV" + }, + { + "code": "WST" + }, + { + "code": "XAD" + }, + { + "code": "XAF" + }, + { + "code": "XAG" + }, + { + "code": "XAU" + }, + { + "code": "XBA" + }, + { + "code": "XBB" + }, + { + "code": "XBC" + }, + { + "code": "XBD" + }, + { + "code": "XCD" + }, + { + "code": "XCG" + }, + { + "code": "XDR" + }, + { + "code": "XOF" + }, + { + "code": "XPD" + }, + { + "code": "XPF" + }, + { + "code": "XPT" + }, + { + "code": "XSU" + }, + { + "code": "XTS" + }, + { + "code": "XUA" + }, + { + "code": "XXX" + }, + { + "code": "YER" + }, + { + "code": "ZAR" + }, + { + "code": "ZMW" + }, + { + "code": "ZWG" + } + ] + }, + "routines": [ + { + "arguments": "event_name text, before_state json, after_state json, envelope_project_id text", + "definition": "CREATE OR REPLACE FUNCTION public.authority_event_facts_are_safe(event_name text, before_state json, after_state json, envelope_project_id text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE AS $function$ begin if not (event_name='AuthorityInvalidationRequested' and before_state is not null and after_state is not null and coalesce(before_state::jsonb ? 'future_obligation', false) and coalesce(after_state::jsonb ? 'future_obligation', false)) and ((before_state is not null and not authority_facts_are_safe(before_state)) or (after_state is not null and not authority_facts_are_safe(after_state))) then return false; end if; case event_name when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"human\",\"provisioning_method\":\"automatic_first_access\"}'::jsonb; when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"service\",\"provisioning_method\":\"manual_service_provisioning\"}'::jsonb; when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( '{\"status\":\"active\",\"subject_kind\":\"human\"}'::jsonb, '{\"status\":\"active\",\"subject_kind\":\"service\"}'::jsonb); when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"revoked\"}'::jsonb; when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{\"status\":\"revoked\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileSuspended' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"suspended\"}'::jsonb; when 'ActorProfileReactivated' then return before_state::jsonb='{\"status\":\"suspended\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileDeactivated' then return before_state::jsonb in ('{\"status\":\"active\"}'::jsonb,'{\"status\":\"suspended\"}'::jsonb) and after_state::jsonb='{\"status\":\"deactivated\"}'::jsonb; when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','adjudicator'],'active',true,envelope_project_id); when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then return authority_grant_facts_are_safe(before_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'active',true,envelope_project_id) and authority_grant_facts_are_safe(after_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'revoked',false,envelope_project_id) and before_state->>'role'=after_state->>'role' and before_state->>'scope_type'=after_state->>'scope_type' and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{\"status\":\"captured\"}'::jsonb; when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; when 'SensitiveAuthorizationAllowed' then return before_state is null and ( after_state::jsonb = '{\"allowed\": true}'::jsonb or ( after_state::jsonb->'allowed' = 'true'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'SensitiveAuthorizationDenied' then return before_state is null and ( after_state::jsonb = '{\"allowed\": false}'::jsonb or ( after_state::jsonb->'allowed' = 'false'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'AuthorityInvalidationRequested' then return (before_state::jsonb = '{\"effective\": true}'::jsonb and after_state::jsonb = '{\"effective\": false}'::jsonb) or (before_state::jsonb = '{\"effective\": false}'::jsonb and after_state::jsonb = '{\"effective\": true}'::jsonb) or ( jsonb_typeof(before_state::jsonb)='object' and jsonb_typeof(after_state::jsonb)='object' and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and before_state::jsonb->'effective'='true'::jsonb and after_state::jsonb->'effective'='false'::jsonb and jsonb_typeof(before_state::jsonb->'role')='string' and jsonb_typeof(before_state::jsonb->'scope_type')='string' and jsonb_typeof(before_state::jsonb->'scope_id')='string' and jsonb_typeof(before_state::jsonb->'future_obligation')='string' and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') and before_state::jsonb->>'scope_type'='project' and before_state::jsonb->>'scope_id'=envelope_project_id and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) ); else return false; end case; end $function$", + "name": "authority_event_facts_are_safe" + }, + { + "arguments": "facts json", + "definition": "CREATE OR REPLACE FUNCTION public.authority_facts_are_safe(facts json) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select json_typeof(facts) = 'object' and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) and not exists ( select 1 from json_each(facts) item where item.key not in ( 'status', 'subject_kind', 'provisioning_method', 'role', 'scope_type', 'scope_id', 'effective', 'allowed', 'resource_context_digest' ) or case item.key when 'status' then item.value #>> '{}' not in ( 'active', 'suspended', 'deactivated', 'revoked', 'captured' ) when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') when 'provisioning_method' then item.value #>> '{}' not in ( 'automatic_first_access', 'manual_service_provisioning' ) when 'role' then item.value #>> '{}' not in ( 'access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' ) when 'scope_type' then item.value #>> '{}' not in ('system', 'project') when 'scope_id' then (item.value #>> '{}') !~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' when 'effective' then json_typeof(item.value) <> 'boolean' when 'allowed' then json_typeof(item.value) <> 'boolean' when 'resource_context_digest' then (item.value #>> '{}') !~ '^sha256:[0-9a-f]{64}$' else true end ) $function$", + "name": "authority_facts_are_safe" + }, + { + "arguments": "facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text", + "definition": "CREATE OR REPLACE FUNCTION public.authority_grant_facts_are_safe(facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text) RETURNS boolean LANGUAGE sql IMMUTABLE AS $function$ select authority_facts_are_safe(facts) and facts->>'role' = any(roles) and facts->>'status' = expected_status and (facts->>'effective')::boolean = expected_effective and ( ( facts->>'scope_type' = 'system' and envelope_project_id is null and not facts::jsonb ? 'scope_id' and facts->>'role' not in ('submitter', 'reviewer', 'both') and (select count(*) from json_each(facts)) = 4 ) or ( facts->>'scope_type' = 'project' and envelope_project_id is not null and facts->>'scope_id' = envelope_project_id and facts->>'role' not in ('access_administrator', 'operator') and (select count(*) from json_each(facts)) = 5 ) ) $function$", + "name": "authority_grant_facts_are_safe" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.enforce_compensation_binding_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compensation_binding_updates_deferred'; return new; end; $function$", + "name": "enforce_compensation_binding_lifecycle" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_identity_link_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then raise exception 'actor identity link anchor is immutable' using errcode='55000'; end if; if new.status=old.status and (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'identity link attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='revoked' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid identity link revocation attribution' using errcode='23514'; end if; if old.status='revoked' and new.status='active' and ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then raise exception 'invalid identity link reactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status='revoked') or (old.status='revoked' and new.status='active')) then raise exception 'invalid identity link lifecycle transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_actor_identity_link_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_profile_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then raise exception 'actor profile identity is immutable' using errcode='55000'; end if; if old.status='deactivated' and new.status <> 'deactivated' then raise exception 'deactivated actor is terminal' using errcode='23514'; end if; if new.status = old.status and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='suspended' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'invalid actor suspension attribution' using errcode='23514'; end if; if old.status='suspended' and new.status='active' and ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then raise exception 'invalid actor reactivation attribution' using errcode='23514'; end if; if new.status='deactivated' and old.status in ('active','suspended') and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid actor deactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status in ('suspended','deactivated')) or (old.status='suspended' and new.status in ('active','deactivated'))) then raise exception 'invalid actor lifecycle transition' using errcode='23514'; end if; new.updated_at = statement_timestamp(); return new; end $function$", + "name": "guard_actor_profile_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_admin_role_grant() RETURNS trigger LANGUAGE plpgsql AS $function$ declare target_kind text; authorizer admin_role_grants%rowtype; bootstrap_done boolean; begin if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; if tg_op='INSERT' then select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; new.granted_at := clock_timestamp(); if new.granted_by_system_principal is not null then if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; if bootstrap_done is distinct from false or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then raise exception 'bootstrap already completed' using errcode='23514'; end if; else select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; end if; return new; end if; if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, new.granted_by_actor_profile_id,new.granted_by_system_principal, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, old.granted_by_actor_profile_id,old.granted_by_system_principal, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then raise exception 'invalid admin role grant transition' using errcode='23514'; end if; select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", + "name": "guard_admin_role_grant" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_artifact_receipt_producer_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id; if request_type is null or (request_type = 'guide' and not ( new.guide_source_item_id is not null and new.checker_run_id is null and new.logical_role is null)) or (request_type = 'checker_output' and not ( new.guide_source_item_id is null and new.checker_run_id is not null and octet_length(new.logical_role) between 1 and 100)) or (request_type = 'submission_bundle' and not ( new.guide_source_item_id is null and new.checker_run_id is null and new.logical_role is null)) then raise exception 'artifact receipt producer reference mismatch' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_artifact_receipt_producer_reference" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_control() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; if old.id <> 1 or old.bootstrap_completed or old.version <> 0 or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then raise exception 'invalid authority control transition' using errcode='23514'; end if; new.updated_at := clock_timestamp(); return new; end $function$", + "name": "guard_authority_control" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_idempotency_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare success_count integer; invalidation_count integer; success_id text; qualification_row audit_events%rowtype; success_row audit_events%rowtype; grant_row project_role_grants%rowtype; snapshot_row project_role_qualification_snapshots%rowtype; begin if tg_op = 'INSERT' then if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; new.created_at := statement_timestamp(); new.committed_at := null; return new; elsif tg_op = 'DELETE' then raise exception 'authority idempotency records are immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, new.request_digest,new.created_at) is distinct from (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, old.request_digest,old.created_at) then raise exception 'invalid authority idempotency transition' using errcode='23514'; end if; select count(*), min(id) into success_count, success_id from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type <> 'AuthorityInvalidationRequested'; select count(*) into invalidation_count from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type='AuthorityInvalidationRequested'; if new.operation='project_role_grant.issue' then if success_count <> 2 or invalidation_count <> 0 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued') <> 1 then raise exception 'project role issue evidence pair required' using errcode='23514'; end if; select * into qualification_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured'; select * into success_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued'; select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; select * into snapshot_row from project_role_qualification_snapshots where id=qualification_row.resource_id::uuid; if not found or grant_row.id is null or snapshot_row.id is null or grant_row.qualification_snapshot_id <> snapshot_row.id or grant_row.project_id <> snapshot_row.project_id or grant_row.actor_profile_id <> snapshot_row.actor_profile_id or grant_row.role <> snapshot_row.requested_role or qualification_row.project_id is distinct from grant_row.project_id or success_row.project_id is distinct from grant_row.project_id or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id or success_row.target_actor_ref is distinct from grant_row.actor_profile_id or qualification_row.request_id is distinct from success_row.request_id or qualification_row.correlation_id is distinct from success_row.correlation_id or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind or qualification_row.actor_id is distinct from success_row.actor_id or qualification_row.permission_id is distinct from success_row.permission_id or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then raise exception 'project role issue evidence mismatch' using errcode='23514'; end if; else if success_count <> 1 or invalidation_count <> 1 then raise exception 'authority evidence pair required' using errcode='23514'; end if; select * into success_row from audit_events where id=success_id; end if; if success_row.resource_type <> new.response_resource_type or success_row.resource_id <> new.response_resource_id::text then raise exception 'authority response does not match evidence' using errcode='23514'; end if; new.committed_at := statement_timestamp(); return new; end $function$", + "name": "guard_authority_idempotency_record" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_children() RETURNS trigger LANGUAGE plpgsql AS $function$ declare old_parent_status text; declare new_parent_status text; begin if tg_op in ('UPDATE','DELETE') then select status into old_parent_status from contribution_policy_versions where id=old.contribution_policy_version_id for update; end if; if tg_op in ('INSERT','UPDATE') then select status into new_parent_status from contribution_policy_versions where id=new.contribution_policy_version_id for update; end if; if old_parent_status in ('published','retired') or new_parent_status in ('published','retired') then raise exception 'published contribution policy rules and definitions are immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", + "name": "guard_contribution_policy_children" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_version_content() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' and old.status in ('published','retired') then raise exception 'published contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='retired' then raise exception 'retired contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='published' and not ( new.status='retired' and new.id=old.id and new.contribution_policy_id=old.contribution_policy_id and new.project_id=old.project_id and new.version_number=old.version_number and new.created_by=old.created_by and new.created_at=old.created_at and new.published_by=old.published_by and new.published_at=old.published_at and new.retired_by is not null and new.retired_at is not null ) then raise exception 'published contribution policy version content is immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", + "name": "guard_contribution_policy_version_content" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_lineage_and_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if (new.id,new.project_id,new.version) is distinct from (old.id,old.project_id,old.version) then raise exception 'guide identity and lineage are immutable' using errcode='23514'; end if; if (new.status,new.approved_by,new.effective_at,new.superseded_at) is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then raise exception 'guide lifecycle mutation requires activation authority' using errcode='23514'; end if; return new; end $function$", + "name": "guard_guide_lineage_and_lifecycle" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_mutation_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'guide mutation custody is immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status<>'pending' or new.status<>'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, new.operation_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, old.operation_generation,old.created_at) then raise exception 'invalid guide mutation custody transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_guide_mutation_idempotency" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_iso_4217_currency_codes() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' using errcode='55000'; end; $function$", + "name": "guard_iso_4217_currency_codes" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_outbox_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare event_time timestamptz; begin if tg_op = 'TRUNCATE' then raise exception 'outbox events cannot be truncated' using errcode='55000'; elsif tg_op = 'DELETE' then raise exception 'outbox events cannot be deleted' using errcode='55000'; elsif tg_op = 'INSERT' then event_time := statement_timestamp(); new.producer := 'workstream'; new.occurred_at := event_time; new.delivery_state := 'pending'; new.attempt_count := 0; new.next_attempt_at := event_time; new.claim_owner := null; new.claim_generation := 0; new.claimed_at := null; new.claim_expires_at := null; new.last_attempt_at := null; new.last_error_code := null; new.finalized_at := null; new.archived_at := null; return new; end if; if (new.event_id, new.event_type, new.event_version, new.producer, new.aggregate_type, new.aggregate_id, new.project_id, new.correlation_id, new.causation_event_id, new.idempotency_key, new.payload, new.payload_digest, new.occurred_at) is distinct from (old.event_id, old.event_type, old.event_version, old.producer, old.aggregate_type, old.aggregate_id, old.project_id, old.correlation_id, old.causation_event_id, old.idempotency_key, old.payload, old.payload_digest, old.occurred_at) then raise exception 'outbox event envelope is immutable' using errcode='55000'; end if; if new.attempt_count < old.attempt_count or new.claim_generation < old.claim_generation or new.attempt_count <> new.claim_generation then raise exception 'outbox counters cannot regress' using errcode='23514'; end if; if old.archived_at is not null and (new.delivery_state, new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.delivery_state, old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'archived outbox event is closed' using errcode='55000'; end if; if old.delivery_state in ('pending', 'retryable') and new.delivery_state = 'claimed' then if new.attempt_count <> old.attempt_count + 1 or new.claim_generation <> old.claim_generation + 1 or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox claim generation must increment once' using errcode='23514'; end if; elsif old.delivery_state = 'claimed' and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at then raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state = 'dead_letter' and new.delivery_state = 'retryable' and old.archived_at is null then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = 'cancelled' then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.attempt_count, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; end if; elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at) is distinct from (old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at) or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) or (old.archived_at is null and new.archived_at is null) then raise exception 'terminal outbox event permits archival only' using errcode='23514'; end if; else raise exception 'illegal outbox delivery transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_outbox_event" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_policy_mutation_replay() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'policy mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'policy mutation replay is immutable' using errcode='55000'; elsif new is not distinct from old then return new; elsif old.status='pending' and new.status='committed' and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest,new.policy_hash, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.policy_id, new.policy_generation,new.created_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest,old.policy_hash, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.policy_id, old.policy_generation,old.created_at) then return new; end if; raise exception 'policy mutation replay is immutable' using errcode='23514'; end $function$", + "name": "guard_policy_mutation_replay" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_result_membership() RETURNS trigger LANGUAGE plpgsql AS $function$ declare parent_created_at timestamptz; expected_count integer; current_count integer; begin select created_at, result_count into parent_created_at, expected_count from pre_submit_evidence_sets where id=new.evidence_set_id for key share; select count(*) into current_count from pre_submit_evidence_results where evidence_set_id=new.evidence_set_id; if parent_created_at is null or parent_created_at <> transaction_timestamp() or current_count >= expected_count then raise exception 'pre-submit evidence result membership is closed' using errcode='55000'; end if; return new; end; $function$", + "name": "guard_pre_submit_evidence_result_membership" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_results_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_results rows are immutable' using errcode='55000'; end; $function$", + "name": "guard_pre_submit_evidence_results_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_set_creation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.created_at is distinct from transaction_timestamp() then raise exception 'pre-submit evidence creation timestamp is invalid' using errcode='55000'; end if; return new; end; $function$", + "name": "guard_pre_submit_evidence_set_creation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_sets_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_sets rows are immutable' using errcode='55000'; end; $function$", + "name": "guard_pre_submit_evidence_sets_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_compensation_units() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('UPDATE','DELETE') then raise exception 'project compensation-unit lifecycle behavior is deferred' using errcode='55000'; end if; if new.status <> 'active' then raise exception 'project compensation units must begin active' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_project_compensation_units" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_create_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'INSERT' then if new.status <> 'pending' or new.committed_at is not null then raise exception 'project create reservation must begin pending' using errcode='23514'; end if; return new; elsif tg_op = 'DELETE' then raise exception 'project create reservations are immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, new.idempotency_key, new.request_digest, new.operation_id, new.project_id, new.operation_generation, new.created_at) is distinct from (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, old.idempotency_key, old.request_digest, old.operation_id, old.project_id, old.operation_generation, old.created_at) then raise exception 'invalid project create reservation transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_project_create_idempotency" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_attempt_update() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, new.pre_catalogue_version,new.pre_catalogue_schema_version, new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.provider_idempotency_key) is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, old.source_snapshot_hash,old.setup_run_id,old.setup_generation, old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, old.pre_catalogue_version,old.pre_catalogue_schema_version, old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, old.agent_identity,old.agent_version,old.instruction_version, old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; if new.reserved_at is distinct from old.reserved_at then raise exception 'compilation reservation timestamp is immutable'; end if; if new.provider_uncertain_at is distinct from old.provider_uncertain_at and not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then raise exception 'provider uncertainty timestamp is immutable'; end if; if new.accepted_at is distinct from old.accepted_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then raise exception 'accepted timestamp is immutable'; end if; if new.terminal_at is distinct from old.terminal_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then raise exception 'terminal timestamp is immutable'; end if; if row(new.persisted_at,new.persisted_compilation_id) is distinct from row(old.persisted_at,old.persisted_compilation_id) and not (old.status='provider_result_accepted' and new.status='compilation_persisted') then raise exception 'persisted custody is immutable'; end if; if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then raise exception 'accepted compilation result is immutable'; end if; if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or (old.status='provider_result_accepted' and new.status='compilation_persisted')) then raise exception 'invalid compilation attempt transition'; end if; return new; end $function$", + "name": "guard_project_guide_compilation_attempt_update" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_insert() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor_generation bigint; declare source_attempt project_guide_compilation_attempts%rowtype; begin select * into source_attempt from project_guide_compilation_attempts where id=new.attempt_id for update; if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash, new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) is distinct from row(source_attempt.project_id,source_attempt.guide_id, source_attempt.guide_version,source_attempt.source_snapshot_id, source_attempt.source_snapshot_hash,source_attempt.setup_run_id, source_attempt.setup_generation,source_attempt.canonical_input_hash, source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, source_attempt.agent_version,source_attempt.instruction_version, source_attempt.canonical_result::jsonb,source_attempt.result_hash, source_attempt.component_hashes::jsonb) then raise exception 'compilation does not match its accepted attempt'; end if; if not exists( select 1 from audit_events event join actor_profiles profile on profile.id=new.created_by_actor_profile_id join actor_identity_links link on link.id=new.created_via_identity_link_id and link.actor_profile_id=profile.id where event.id=new.authorization_decision_event_id and event.event_domain='authority' and event.event_type='SensitiveAuthorizationAllowed' and event.denial_code is null and event.actor_id=new.created_by_actor_profile_id and event.permission_id='project.guide_compilation.execute' and event.action_id='project.guide_compilation.execute' and event.project_id=new.project_id and event.resource_type='project_guide_compilation_attempt' and event.resource_id=new.attempt_id::text and event.after_facts->>'allowed'='true' and event.after_facts->>'resource_context_digest'= new.authorization_resource_context_digest and profile.actor_kind='service' and profile.status='active' and profile.service_identity='workstream.project.setup' and link.subject_kind='service' and link.status='active' and link.issuer='workstream-internal' and link.subject='workstream.project.setup' ) then raise exception 'compilation authorization evidence is invalid'; end if; if new.supersedes_compilation_id is null then return new; end if; select setup_generation into predecessor_generation from project_guide_compilations where id=new.supersedes_compilation_id and project_id=new.project_id and guide_id=new.guide_id; if predecessor_generation is null or predecessor_generation >= new.setup_generation then raise exception 'compilation generation must strictly advance'; end if; return new; end $function$", + "name": "guard_project_guide_compilation_insert" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_policy_selection() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.status in ('active','superseded') and ( new.selected_review_policy_id is distinct from old.selected_review_policy_id or new.selected_review_policy_generation is distinct from old.selected_review_policy_generation or new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or new.selected_revision_policy_generation is distinct from old.selected_revision_policy_generation or new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash ) then raise exception 'active guide policy selection is immutable' using errcode='55000'; end if; return new; end $function$", + "name": "guard_project_guide_policy_selection" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_grant_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, new.qualification_snapshot_id,new.granted_by_actor_profile_id, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, old.qualification_snapshot_id,old.granted_by_actor_profile_id, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null or new.revoked_reason is null then raise exception 'invalid project-role grant history transition' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", + "name": "guard_project_role_grant_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_snapshot_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; end $function$", + "name": "guard_project_role_snapshot_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_admission_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review admission records cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' and new.status <> 'pending' then raise exception 'review admission must begin pending' using errcode='23514'; end if; if tg_op='INSERT' then new.created_at := statement_timestamp(); end if; if tg_op='UPDATE' then if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.created_at) is distinct from (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.created_at) then raise exception 'review admission identity is immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' then raise exception 'invalid review admission transition' using errcode='23514'; end if; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review admission task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review admission checker lineage mismatch' using errcode='23514'; end if; if new.status='committed' and ( checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true) then raise exception 'review admission checker is not admissible' using errcode='23514'; end if; return new; end $function$", + "name": "guard_review_admission_record" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare actor_type text; policy_status text; begin if tg_op='DELETE' then raise exception 'review leases cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.status <> 'active' then raise exception 'review lease must begin active' using errcode='23514'; end if; new.claimed_at := statement_timestamp(); new.closed_at := null; new.close_reason := null; else if old.status <> 'active' then raise exception 'terminal review leases are immutable' using errcode='55000'; end if; if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, new.submission_version,new.reviewer_id, new.reviewer_contribution_policy_version_id,new.attempt_generation, new.claimed_at,new.expires_at) is distinct from (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, old.submission_version,old.reviewer_id, old.reviewer_contribution_policy_version_id,old.attempt_generation, old.claimed_at,old.expires_at) then raise exception 'review lease identity is immutable' using errcode='55000'; end if; if new.status='active' then raise exception 'review lease update must close attempt' using errcode='23514'; end if; end if; select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; if actor_type is distinct from 'human' then raise exception 'review lease reviewer must be human' using errcode='23514'; end if; if tg_op='INSERT' then select status into policy_status from contribution_policy_versions where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; if policy_status is distinct from 'published' then raise exception 'review lease policy version must be published' using errcode='23514'; end if; end if; return new; end $function$", + "name": "guard_review_lease" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review_policies rows are immutable' using errcode='55000'; end $function$", + "name": "guard_review_policies_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_queue_entry() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review queue entries cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.queue_state <> 'pending' then raise exception 'review queue must begin pending' using errcode='23514'; end if; new.first_queued_at := statement_timestamp(); new.available_since := new.first_queued_at; new.routing_generation := 1; new.lifecycle_generation := 1; new.created_at := new.first_queued_at; end if; if tg_op='UPDATE' then if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.first_queued_at,new.created_at) is distinct from (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.first_queued_at,old.created_at) then raise exception 'review queue identity is immutable' using errcode='55000'; end if; if old.queue_state='closed' and new.queue_state <> 'closed' then raise exception 'closed review queue entries cannot reopen' using errcode='23514'; end if; if new.routing_generation < old.routing_generation or new.lifecycle_generation < old.lifecycle_generation then raise exception 'review queue generations cannot decrease' using errcode='23514'; end if; end if; if new.preferred_reviewer_id is not null and not exists( select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' ) then raise exception 'preferred reviewer must be human' using errcode='23514'; end if; if tg_op='UPDATE' then return new; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review queue task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review queue checker lineage mismatch' using errcode='23514'; end if; if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true then raise exception 'review queue checker is not admissible' using errcode='23514'; end if; return new; end $function$", + "name": "guard_review_queue_entry" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_revision_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'revision_policies rows are immutable' using errcode='55000'; end $function$", + "name": "guard_revision_policies_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_service_identity_migration_evidence() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'service identity migration evidence is immutable' using errcode='55000'; end $function$", + "name": "guard_service_identity_migration_evidence" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_delete() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $function$", + "name": "guard_submission_bundle_admission_delete" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, old.put_operation_receipt_id, old.put_observation_receipt_id, old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, old.assignment_id, old.predecessor_submission_id, old.predecessor_submission_version, old.locked_policy_context_hash, old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, old.archive_byte_count, old.ready_at, old.created_at) is distinct from row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, new.put_operation_receipt_id, new.put_observation_receipt_id, new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, new.assignment_id, new.predecessor_submission_id, new.predecessor_submission_version, new.locked_policy_context_hash, new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, new.archive_byte_count, new.ready_at, new.created_at) then raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; end if; if old.status <> 'ready' or new.status not in ('consumed','stale') then raise exception 'invalid submission bundle admission transition' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_submission_bundle_admission_lineage" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_verified_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ declare matches integer; begin select count(*) into matches from submission_bundle_durable_intents intent join pre_submit_evidence_sets evidence on evidence.id=intent.pre_submit_evidence_set_id join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id join artifact_replicas replica on replica.id=attempt.replica_id join artifact_contents content on content.id=replica.content_id join artifact_verification_jobs job on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id join artifact_verification_receipts verification on verification.verification_job_id=job.id where intent.id=new.durable_intent_id and evidence.id=new.pre_submit_evidence_set_id and attempt.id=new.put_attempt_id and content.id=new.artifact_content_id and replica.id=new.verified_replica_id and verification.id=new.verification_receipt_id and attempt.producer_request_type='submission_bundle' and attempt.producer_type='actor_profile' and attempt.producer_ref=evidence.actor_profile_id and attempt.project_id=evidence.project_id and attempt.task_id=evidence.task_id and attempt.media_type='application/zip' and content.media_type='application/zip' and attempt.status='object_confirmed' and evidence.terminal_status='passed' and evidence.eligible and replica.verification_state='verified' and replica.availability_state='available' and replica.integrity_state='valid' and verification.outcome='verified' and verification.execution_generation=job.execution_generation and verification.observed_sha256=attempt.sha256 and verification.observed_sha256=content.sha256 and verification.observed_sha256=evidence.archive_sha256 and verification.observed_byte_count=attempt.byte_count and verification.observed_byte_count=content.byte_count and verification.observed_byte_count=evidence.archive_byte_count and new.actor_profile_id=evidence.actor_profile_id and new.identity_link_id=evidence.identity_link_id and new.project_id=evidence.project_id and new.task_id=evidence.task_id and new.assignment_id=evidence.assignment_id and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version and new.locked_policy_context_hash=evidence.locked_policy_context_hash and new.semantic_manifest_id=evidence.semantic_manifest_id and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 and new.archive_sha256=evidence.archive_sha256 and new.archive_byte_count=evidence.archive_byte_count and ((new.put_operation_receipt_id is not null and exists ( select 1 from artifact_operation_receipts receipt where receipt.id=new.put_operation_receipt_id and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id and receipt.outcome='stored_pending_verification')) or (new.put_observation_receipt_id is not null and exists ( select 1 from artifact_put_observation_receipts observation where observation.id=new.put_observation_receipt_id and observation.put_attempt_id=attempt.id and observation.outcome='observed_confirmed' and observation.observed_sha256=attempt.sha256 and observation.observed_byte_count=attempt.byte_count))); if matches <> 1 then raise exception 'submission bundle admission verified lineage mismatch' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_submission_bundle_admission_verified_lineage" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id for share; if request_type is distinct from 'submission_bundle' then raise exception 'submission bundle durable intent requires submission_bundle put attempt' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_submission_bundle_durable_intent_put_attempt" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intents_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission_bundle_durable_intents rows are immutable' using errcode='55000'; end; $function$", + "name": "guard_submission_bundle_durable_intents_immutable" + }, + { + "arguments": "value jsonb", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_availability_is_safe(value jsonb) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='object' and (select count(*)=3 from jsonb_object_keys(value)) and value ?& array['availability','reference_ids','unavailable_reason'] and project_role_reference_array_is_safe(value->'reference_ids',false) and ( (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 and value->'unavailable_reason'='null'::jsonb) or (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) ) $function$", + "name": "project_role_availability_is_safe" + }, + { + "arguments": "value text", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_reason_is_safe(value text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE STRICT AS $function$ declare point integer; index integer; begin if octet_length(value) not between 1 and 500 or value <> btrim(value, (E' \\t\\n\\r\\f\\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)||chr(8239)||chr(8287)||chr(12288))) then return false; end if; for index in 1..char_length(value) loop point := ascii(substr(value,index,1)); if point between 0 and 31 or point between 127 and 159 or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then return false; end if; end loop; return true; end $function$", + "name": "project_role_reason_is_safe" + }, + { + "arguments": "value jsonb, uuid_only boolean", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_array_is_safe(value jsonb, uuid_only boolean) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 and not exists ( select 1 from jsonb_array_elements(value) item where jsonb_typeof(item)<>'string' or case when uuid_only then not (item #>> '{}') ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' else not project_role_reference_token_is_safe(item #>> '{}') end ) $function$", + "name": "project_role_reference_array_is_safe" + }, + { + "arguments": "value text", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_token_is_safe(value text) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 $function$", + "name": "project_role_reference_token_is_safe" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_approval_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.approval_action_id is not null and (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, new.approved_by_admin_role_grant_id,new.approval_scope_type, new.approval_scope_project_id,new.approval_action_id, new.approval_decision_event_id) is distinct from (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, old.approved_by_admin_role_grant_id,old.approval_scope_type, old.approval_scope_project_id,old.approval_action_id, old.approval_decision_event_id) then raise exception 'submission-policy approval provenance is immutable' using errcode='23514'; end if; return new; end $function$", + "name": "protect_submission_policy_approval_provenance" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_creation_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.created_by_service_identity, new.creation_scope_type,new.creation_scope_project_id, new.creation_action_id,new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.created_by_service_identity, old.creation_scope_type,old.creation_scope_project_id, old.creation_action_id,old.creation_decision_event_id) then raise exception 'submission-policy creation provenance is immutable' using errcode='23514'; end if; return new; end $function$", + "name": "protect_submission_policy_creation_provenance" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_output_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.creation_scope_type, new.creation_scope_project_id,new.creation_action_id, new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.creation_scope_type, old.creation_scope_project_id,old.creation_action_id, old.creation_decision_event_id) then raise exception 'submission-policy output provenance is immutable' using errcode='23514'; end if; return new; end $function$", + "name": "protect_submission_policy_output_provenance" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_admin_role_grant_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'admin role grants are immutable' using errcode='55000'; end $function$", + "name": "reject_admin_role_grant_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_artifact_fact_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception '% rows are immutable', tg_table_name; end; $function$", + "name": "reject_artifact_fact_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_audit_event_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'audit events are append-only' using errcode = '55000'; end $function$", + "name": "reject_audit_event_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_control_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority control is immutable' using errcode='55000'; end $function$", + "name": "reject_authority_control_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority idempotency records are immutable' using errcode='55000'; end $function$", + "name": "reject_authority_idempotency_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_contribution_policy_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'contribution policy persistence cannot be truncated' using errcode='55000'; end; $function$", + "name": "reject_contribution_policy_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_mutation_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide mutation custody is immutable' using errcode='55000'; end $function$", + "name": "reject_guide_mutation_idempotency_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_source_snapshot_item_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide source snapshot items are immutable' using errcode='23514'; end $function$", + "name": "reject_guide_source_snapshot_item_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_pending_authority_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then raise exception 'pending authority idempotency cannot commit' using errcode='23514'; end if; return null; end $function$", + "name": "reject_pending_authority_idempotency" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_policy_mutation_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'policy mutation replay is immutable' using errcode='55000'; end $function$", + "name": "reject_policy_mutation_replay_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_project_create_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project create reservations are immutable' using errcode='55000'; end $function$", + "name": "reject_project_create_idempotency_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_project_guide_compilation_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compilation custody is append-only'; end $function$", + "name": "reject_project_guide_compilation_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_project_role_history_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $function$", + "name": "reject_project_role_history_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_review_lease_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review leases cannot be truncated' using errcode='55000'; end $function$", + "name": "reject_review_lease_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_review_queue_foundation_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review queue foundation cannot be truncated' using errcode='55000'; end $function$", + "name": "reject_review_queue_foundation_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'submission-policy replay rows cannot be deleted'; end if; if old.status = 'reserved' and new.status = 'pending' and old.service_identity = 'workstream.project.setup' and old.action_id = 'project.submission_artifact_policy.derive' and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.operation_id,new.project_id, new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, new.committed_pre_submit_policy_id,new.committed_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.operation_id,old.project_id, old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, old.committed_pre_submit_policy_id,old.committed_at) then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.request_digest, new.resource_context_digest,new.resource_context_json::text,new.operation_id, new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, new.setup_run_id,new.setup_generation,new.setup_task_id, new.correlation_id,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.request_digest, old.resource_context_digest,old.resource_context_json::text,old.operation_id, old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, old.setup_run_id,old.setup_generation,old.setup_task_id, old.correlation_id,old.created_at) then raise exception 'invalid submission-policy replay mutation'; end if; return new; end $function$", + "name": "reject_submission_policy_replay_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission-policy replay rows cannot be truncated'; end $function$", + "name": "reject_submission_policy_replay_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'guide sufficiency replay rows are append-only'; end if; if old.status = 'committed' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, new.setup_run_id,new.setup_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, old.setup_run_id,old.setup_generation,old.created_at) then raise exception 'invalid guide sufficiency replay mutation'; end if; return new; end $function$", + "name": "reject_sufficiency_replay_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide sufficiency replay rows are append-only'; end $function$", + "name": "reject_sufficiency_replay_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.require_human_actor_profile_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare referenced_id text; referenced_kind text; begin if tg_nargs <> 1 or tg_argv[0] is null or not (to_jsonb(new) ? tg_argv[0]) then raise exception 'human actor reference trigger is misconfigured' using errcode='55000'; end if; referenced_id := to_jsonb(new) ->> tg_argv[0]; if referenced_id is null then return new; end if; select profile.actor_kind into referenced_kind from public.actor_profiles profile where profile.id=referenced_id; if not found then return new; end if; if referenced_kind <> 'human' then raise exception 'actor reference must identify a human profile' using errcode='23514', constraint='require_human_actor_profile_reference'; end if; return new; end $function$", + "name": "require_human_actor_profile_reference" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.set_authority_audit_database_time() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.event_domain = 'authority' then if new.invalidation_cause_event_id is not null and not exists ( select 1 from audit_events where id = new.invalidation_cause_event_id and event_domain = 'authority' ) then raise exception 'invalid authority invalidation cause' using errcode = '23503'; end if; new.occurred_at = statement_timestamp(); else new.occurred_at = null; end if; return new; end $function$", + "name": "set_authority_audit_database_time" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_binding_history() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor artifact_bindings%rowtype; begin if new.scope_version = 1 then return new; end if; select * into predecessor from artifact_bindings where id = new.supersedes_binding_id; if not found or predecessor.project_id != new.project_id or predecessor.resource_type != new.resource_type or predecessor.resource_id != new.resource_id or predecessor.logical_role != new.logical_role or predecessor.scope_version + 1 != new.scope_version then raise exception 'artifact binding predecessor is invalid'; end if; return new; end; $function$", + "name": "validate_artifact_binding_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_recovery_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare source_row artifact_verification_jobs%rowtype; retry_row artifact_verification_jobs%rowtype; expected_parent text; begin if tg_op = 'DELETE' then raise exception 'artifact recovery attempts are append-only' using errcode='55000'; end if; if tg_op = 'UPDATE' and ( to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] is distinct from to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] ) then raise exception 'artifact recovery identity is immutable' using errcode='55000'; end if; select * into source_row from artifact_verification_jobs where id=new.source_verification_job_id; select * into retry_row from artifact_verification_jobs where id=new.retry_verification_job_id; if source_row.id is null or retry_row.id is null or source_row.status <> 'provider_unavailable' or source_row.terminal_result_code <> 'provider_unavailable' or source_row.terminal_at is null or source_row.next_run_at is not null or source_row.executor_id is not null or source_row.attempt_count < source_row.maximum_attempts or retry_row.parent_verification_job_id <> source_row.id or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id or retry_row.replica_id <> source_row.replica_id then raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; end if; if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) or (tg_op = 'UPDATE' and ( retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null )) then raise exception 'invalid artifact recovery retry state' using errcode='23514'; end if; select id into expected_parent from artifact_recovery_attempts where retry_verification_job_id=source_row.id; if new.parent_recovery_attempt_id is distinct from expected_parent then raise exception 'invalid artifact recovery parent chain' using errcode='23514'; end if; if not exists ( select 1 from audit_events where id=new.initiation_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryInitiated' ) then raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; end if; if new.terminal_audit_event_id is not null and not exists ( select 1 from audit_events where id=new.terminal_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryCompleted' ) then raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; end if; return new; end $function$", + "name": "validate_artifact_recovery_attempt" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_verification_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if ( old.parent_verification_job_id is not null or exists( select 1 from artifact_recovery_attempts where source_verification_job_id = old.id or retry_verification_job_id = old.id ) ) and ( old.originating_put_attempt_id is distinct from new.originating_put_attempt_id or old.replica_id is distinct from new.replica_id or old.parent_verification_job_id is distinct from new.parent_verification_job_id ) then raise exception 'artifact verification lineage is immutable' using errcode='55000'; end if; return new; end $function$", + "name": "validate_artifact_verification_lineage" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_bootstrap_authority_state() RETURNS trigger LANGUAGE plpgsql AS $function$ declare control authority_control%rowtype; bootstrap_count bigint; referenced_bootstrap boolean; begin select * into control from authority_control where id=1; if not found then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; select count(*) into bootstrap_count from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap'; referenced_bootstrap := exists( select 1 from admin_role_grants where id=control.bootstrap_grant_id and granted_by_system_principal='workstream:system:bootstrap' ); if (not control.bootstrap_completed and (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) or (control.bootstrap_completed and (control.bootstrap_grant_id is null or control.version <> 1 or bootstrap_count <> 1 or not referenced_bootstrap)) then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; return null; end $function$", + "name": "validate_bootstrap_authority_state" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_canonical_actor_link() RETURNS trigger LANGUAGE plpgsql AS $function$ declare profile_row actor_profiles%rowtype; link_count integer; begin if tg_table_name='actor_profiles' then select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; else select * into profile_row from actor_profiles where id=new.actor_profile_id; if not found or profile_row.actor_kind <> new.subject_kind then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; end if; return new; end $function$", + "name": "validate_canonical_actor_link" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_contribution_policy_graph() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists ( select 1 from contribution_policy_versions v where v.status in ('published','retired') and ( (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='accepted_submission') <> 1 or (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='completed_review') <> 1 or exists ( select 1 from contribution_rules r where r.contribution_policy_version_id=v.id and ( (r.compensation_mode='unpaid' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) <> 0) or (r.compensation_mode='compensated' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) not between 1 and 2) ) ) ) ) then raise exception 'published contribution policy graph is incomplete' using errcode='23514'; end if; if exists ( select 1 from contribution_policies p left join contribution_policy_versions v on v.id=p.current_published_version_id and v.contribution_policy_id=p.id and v.project_id=p.project_id where p.status='active' and (v.id is null or v.status <> 'published') ) then raise exception 'active contribution policy selector is invalid' using errcode='23514'; end if; return null; end; $function$", + "name": "validate_contribution_policy_graph" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation guide_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_resource text; product_generation integer; begin if tg_table_name='guide_mutation_idempotency_records' then select * into reservation from guide_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id in ('project.guide.create','project.guide.update') then select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, last_mutated_by_admin_role_grant_id,last_mutation_action_id, last_mutation_scope_type,last_mutation_scope_project_id, last_authorization_decision_event_id,project_id,id,mutation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from project_guides where id=reservation.resource_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,project_id,id,creation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from guide_source_snapshots where id=reservation.resource_id; end if; elsif tg_table_name='project_guides' then if tg_op='UPDATE' and (new.content_markdown is distinct from old.content_markdown or new.change_summary is distinct from old.change_summary) and (new.mutation_generation is not distinct from old.mutation_generation or new.last_authorization_decision_event_id is not distinct from old.last_authorization_decision_event_id) then raise exception 'guide content mutation requires fresh custody' using errcode='23514'; end if; if new.mutation_generation is null then if tg_op='INSERT' then raise exception 'new guides require mutation authority' using errcode='23514'; end if; return null; end if; actor_id:=new.last_mutated_by_actor_profile_id; link_id:=new.last_mutated_via_identity_link_id; grant_id:=new.last_mutated_by_admin_role_grant_id; action_value:=new.last_mutation_action_id; scope_type:=new.last_mutation_scope_type; scope_project:=new.last_mutation_scope_project_id; decision_id:=new.last_authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.mutation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id=new.last_mutation_action_id and operation_generation=new.mutation_generation and status='committed'; elsif tg_table_name='guide_source_snapshots' then if tg_op='UPDATE' and (new.project_id,new.guide_id,new.guide_version, new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) is distinct from (old.project_id,old.guide_id,old.guide_version, old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then raise exception 'guide source snapshot content is immutable' using errcode='23514'; end if; if new.creation_generation is null then raise exception 'new source snapshots require creation authority' using errcode='23514'; end if; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.creation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id='project.guide_source_snapshot.create' and operation_generation=new.creation_generation and status='committed'; else if new.authorization_action_id is null then return null; end if; actor_id:=new.authorized_by_actor_profile_id; link_id:=new.authorized_via_identity_link_id; grant_id:=new.authorized_by_admin_role_grant_id; action_value:=new.authorization_action_id; scope_type:=new.authorization_scope_type; scope_project:=new.authorization_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.source_snapshot_id; select * into reservation from guide_mutation_idempotency_records where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' and status='committed'; product_generation:=reservation.operation_generation; end if; if reservation.id is null or product_resource is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.resource_id is distinct from product_resource or reservation.operation_generation is distinct from product_generation or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'guide mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.guide.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'guide mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_guide_mutation_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_source_snapshot_items() RETURNS trigger LANGUAGE plpgsql AS $function$ declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; begin select snapshot.manifest_json::jsonb->'items' into expected from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; if expected is null then raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; end if; select coalesce(jsonb_agg(jsonb_build_object( 'item_id',id,'item_order',item_order,'source_kind',source_kind, 'source_label',source_label,'ingestion_adapter',ingestion_adapter, 'media_type',media_type) order by item_order),'[]'::jsonb) into actual from guide_source_snapshot_items where source_snapshot_id=new.source_snapshot_id; if actual is distinct from expected then raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; end if; select r.* into reservation from guide_mutation_idempotency_records r join guide_source_snapshots s on s.id=r.resource_id where s.id=new.source_snapshot_id and r.action_id='project.guide_source_snapshot.create' and r.operation_generation=s.creation_generation and r.status='committed'; if reservation.id is null then raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_guide_source_snapshot_items" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_linked_authority_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare record_row authority_idempotency_records%rowtype; cause_row audit_events%rowtype; expected_permission text; expected_resource text; expected_invalidation_resource text; expected_invalidation_id text; valid_success boolean; begin if new.event_domain <> 'authority' then return new; end if; valid_success := new.event_type in ( 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', 'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued','ProjectRoleGrantRevoked', 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then if new.idempotency_reference is not null then raise exception 'invalid authority idempotency event' using errcode='23514'; end if; return new; end if; if new.idempotency_reference is null then raise exception 'authority event requires idempotency reference' using errcode='23514'; end if; select * into record_row from authority_idempotency_records where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; expected_permission := case record_row.operation when 'service_actor.create' then 'actor.service.provision' when 'admin_role_grant.issue' then 'admin_role.grant' when 'admin_role_grant.revoke' then 'admin_role.revoke' when 'project_role_grant.issue' then 'project.role_grant.manage' when 'project_role_grant.revoke' then 'project.role_grant.manage' when 'actor_profile.suspend' then 'actor.profile.suspend' when 'actor_profile.reactivate' then 'actor.profile.reactivate' when 'actor_profile.deactivate' then 'actor.profile.deactivate' when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; expected_resource := case when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' when record_row.operation like 'project_role_grant.%' then 'project_role_grant' else 'actor_identity_link' end; if new.permission_id <> expected_permission or new.resource_id is null then raise exception 'authority event does not match operation' using errcode='23514'; end if; if new.event_type='ProjectRoleQualificationSnapshotCaptured' then if record_row.operation <> 'project_role_grant.issue' or new.resource_type <> 'qualification_snapshot' or new.entity_type <> 'qualification_snapshot' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'qualification_snapshot' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or exists(select 1 from audit_events where idempotency_reference=record_row.id) then raise exception 'invalid project role qualification evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='ProjectRoleGrantIssued' then select * into cause_row from audit_events where idempotency_reference=record_row.id and event_type='ProjectRoleQualificationSnapshotCaptured'; if not found or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.matched_grant_id is distinct from new.matched_grant_id or new.resource_type <> 'project_role_grant' or new.entity_type <> 'project_role_grant' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null then raise exception 'invalid project role issue evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.revoke' and new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from 'actor_profile' or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.resource_type <> 'project_role_grant' or cause_row.target_ref_kind <> 'project_role_grant' or cause_row.target_ref_id is distinct from cause_row.resource_id or new.resource_type <> 'project_role_grant' or new.resource_id is distinct from cause_row.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from cause_row.resource_id or new.invalidation_target_kind <> 'project_role_grant' or new.invalidation_target_ref is distinct from cause_row.resource_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or new.before_facts::jsonb->>'effective' <> 'true' or new.after_facts::jsonb->>'effective' <> 'false' or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' or new.before_facts::jsonb->>'scope_type' <> 'project' or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then raise exception 'invalid project role revoke invalidation' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='AuthorityInvalidationRequested' then raise exception 'project role issue forbids invalidation' using errcode='23514'; elsif new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; expected_invalidation_resource := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then 'actor_profile' else expected_resource end; expected_invalidation_id := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then cause_row.target_actor_ref else cause_row.resource_id end; if not found or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.resource_type is distinct from expected_resource or new.resource_type is distinct from expected_invalidation_resource or new.resource_id is distinct from expected_invalidation_id or new.invalidation_target_kind is distinct from expected_invalidation_resource or new.invalidation_target_ref is distinct from expected_invalidation_id or cause_row.target_ref_kind is distinct from cause_row.resource_type or cause_row.target_ref_id is distinct from cause_row.resource_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": false}'::jsonb or new.after_facts::jsonb <> '{\"effective\": true}'::jsonb)) or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": true}'::jsonb or new.after_facts::jsonb <> '{\"effective\": false}'::jsonb)) or not ( (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then raise exception 'invalid linked authority cause' using errcode='23514'; end if; else if new.resource_type <> expected_resource or new.entity_type <> expected_resource or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or not ( (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then raise exception 'authority success event does not match operation' using errcode='23514'; end if; end if; return new; end $function$", + "name": "validate_linked_authority_event" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_policy_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_guide text; product_id text; product_generation integer; product_hash text; predecessor_id text; predecessor_hash text; selector_id text; selector_generation integer; selector_hash text; predecessor_valid boolean; begin if tg_table_name='policy_mutation_idempotency_records' then select * into reservation from policy_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id='project.review_policy.update' then select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_review_policy_id, g.selected_review_policy_generation,g.selected_review_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from review_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_revision_policy_id, g.selected_revision_policy_generation,g.selected_revision_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from revision_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; end if; else actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_id:=new.id; product_generation:=new.policy_generation; product_hash:=new.policy_hash; predecessor_id:=new.supersedes_policy_id; predecessor_hash:=new.predecessor_policy_hash; if tg_table_name='review_policies' then select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, g.selected_review_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; else select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, g.selected_revision_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; end if; select r.* into reservation from policy_mutation_idempotency_records r where r.policy_id=new.id and r.action_id=new.creation_action_id and r.policy_generation=new.policy_generation and r.status='committed'; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.guide_id is distinct from product_guide or reservation.policy_id is distinct from product_id or reservation.policy_generation is distinct from product_generation or reservation.policy_hash is distinct from product_hash or selector_id is distinct from product_id or selector_generation is distinct from product_generation or selector_hash is distinct from product_hash or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'policy mutation custody mismatch' using errcode='23514'; end if; if product_generation=1 then predecessor_valid:=predecessor_id is null and predecessor_hash is null; elsif reservation.action_id='project.review_policy.update' then select exists(select 1 from review_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; else select exists(select 1 from revision_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; end if; if predecessor_valid is not true then raise exception 'policy mutation lineage mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.review_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'policy mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_policy_mutation_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_project_create_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; evidence audit_events%rowtype; begin if tg_table_name = 'projects' then if tg_op = 'INSERT' and new.creation_action_id is null then raise exception 'new projects require creation authority' using errcode='23514'; end if; if new.creation_action_id is null then return null; end if; project_row := new; select * into reservation from project_create_idempotency_records where project_id=project_row.id and status='committed'; else select * into reservation from project_create_idempotency_records where id=new.id; if reservation.status <> 'committed' then raise exception 'pending project create reservation cannot commit' using errcode='23514'; end if; select * into project_row from projects where id=reservation.project_id; end if; if project_row.id is null or reservation.id is null or project_row.created_by_actor_profile_id is distinct from reservation.actor_profile_id or project_row.created_via_identity_link_id is distinct from reservation.identity_link_id or project_row.creation_action_id is distinct from reservation.action_id then raise exception 'project create custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=project_row.authorization_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from project_row.created_by_actor_profile_id or evidence.matched_grant_id is distinct from project_row.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.create' or evidence.action_id is distinct from 'project.create' or evidence.resource_type is distinct from 'project_create_operation' or evidence.resource_id is distinct from reservation.operation_id::text or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from project_row.id or evidence.after_facts->>'allowed' is distinct from 'true' or coalesce( evidence.after_facts->>'resource_context_digest' !~ '^sha256:[0-9a-f]{64}$', true ) then raise exception 'project create evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_project_create_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_review_active_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare queue_row review_queue_entries%rowtype; active_count integer; begin if tg_table_name='review_queue_entries' then queue_row := new; else select * into queue_row from review_queue_entries where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); end if; if not found and tg_table_name='review_leases' then raise exception 'review lease queue is missing' using errcode='23514'; end if; select count(*) into active_count from review_leases where review_queue_entry_id=queue_row.id and status='active'; if queue_row.queue_state='leased' then if queue_row.active_lease_id is null or active_count <> 1 or not exists( select 1 from review_leases where id=queue_row.active_lease_id and review_queue_entry_id=queue_row.id and status='active' ) then raise exception 'leased queue must identify its active lease' using errcode='23514'; end if; elsif queue_row.active_lease_id is not null or active_count <> 0 then raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; end if; return null; end $function$", + "name": "validate_review_active_lease" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_authority_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; action_value varchar; decision_id varchar; product_project varchar; product_id varchar; approval_outputs_valid boolean; begin if tg_table_name='submission_policy_mutation_idempotency_records' then if new.status='pending' then return null; end if; reservation:=new; select project_id,id, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_actor_profile_id else created_by_actor_profile_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_via_identity_link_id else created_via_identity_link_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_admin_role_grant_id else created_by_admin_role_grant_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then null else created_by_service_identity end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_action_id else creation_action_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_decision_event_id else creation_decision_event_id end into product_project,product_id,actor_id,link_id,grant_id,service_id, action_value,decision_id from submission_artifact_policies where id=reservation.committed_policy_id; if reservation.action_id='project.submission_artifact_policy.approve' then select exists( select 1 from submission_artifact_policies s join effective_project_submission_artifact_policies e on e.id=reservation.committed_effective_policy_id and e.submission_artifact_policy_id=s.id and e.submission_artifact_policy_hash=s.policy_hash join pre_submit_checker_policies p on p.id=reservation.committed_pre_submit_policy_id and p.project_id=e.project_id where s.id=reservation.committed_policy_id and s.id=reservation.policy_id and s.guide_id=reservation.guide_id and s.source_snapshot_id=reservation.source_snapshot_id and s.guide_version=reservation.resource_context_json->>'guide_version' and s.policy_hash=reservation.resource_context_json->>'policy_digest' and e.effective_policy_hash= reservation.resource_context_json->>'effective_output_digest' and p.compiled_bundle_hash= reservation.resource_context_json->>'compiled_pre_submit_output_digest' and e.project_id=reservation.project_id and e.guide_id=s.guide_id and p.guide_id=s.guide_id and e.guide_version=s.guide_version and p.guide_version=s.guide_version and e.source_snapshot_id=s.source_snapshot_id and p.source_snapshot_id=s.source_snapshot_id and e.source_snapshot_hash=s.source_snapshot_hash and p.source_snapshot_hash=s.source_snapshot_hash and e.submission_artifact_policy_id=reservation.committed_policy_id and p.effective_policy_id=e.id and p.effective_policy_hash=e.effective_policy_hash and e.created_by_actor_profile_id=reservation.actor_profile_id and p.created_by_actor_profile_id=reservation.actor_profile_id and e.created_via_identity_link_id=reservation.identity_link_id and p.created_via_identity_link_id=reservation.identity_link_id and e.created_by_admin_role_grant_id=grant_id and p.created_by_admin_role_grant_id=grant_id and e.creation_scope_project_id=reservation.project_id and p.creation_scope_project_id=reservation.project_id and e.creation_action_id=reservation.action_id and p.creation_action_id=reservation.action_id and e.creation_decision_event_id=decision_id and p.creation_decision_event_id=decision_id ) into approval_outputs_valid; if approval_outputs_valid is not true then raise exception 'submission-policy approval output custody mismatch' using errcode='23514'; end if; end if; elsif tg_table_name='submission_artifact_policies' then if new.creation_action_id is null and new.approval_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null or new.approved_by_actor_profile_id is not null or new.approved_via_identity_link_id is not null or new.approved_by_admin_role_grant_id is not null or new.approval_scope_type is not null or new.approval_scope_project_id is not null or new.approval_decision_event_id is not null then raise exception 'partial submission-policy provenance' using errcode='23514'; end if; return null; end if; if new.approval_action_id is not null then select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.approval_action_id and status='committed'; actor_id:=new.approved_by_actor_profile_id; link_id:=new.approved_via_identity_link_id; grant_id:=new.approved_by_admin_role_grant_id; service_id:=null; action_value:=new.approval_action_id; decision_id:=new.approval_decision_event_id; else select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=new.created_by_service_identity; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; end if; product_project:=new.project_id; product_id:=new.id; elsif tg_table_name='effective_project_submission_artifact_policies' then if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial effective-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_effective_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; else if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial pre-submit-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_pre_submit_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.committed_policy_id is distinct from product_id or reservation.service_identity is distinct from service_id then raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from product_id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy authorization evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_submission_policy_authority_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_creation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; begin if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial submission-policy creation provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; if reservation.id is null or reservation.actor_profile_id is distinct from new.created_by_actor_profile_id or reservation.identity_link_id is distinct from new.created_via_identity_link_id or reservation.service_identity is distinct from new.created_by_service_identity or reservation.project_id is distinct from new.project_id or reservation.policy_id is distinct from new.id or reservation.guide_id is distinct from new.guide_id or reservation.source_snapshot_id is distinct from new.source_snapshot_id or reservation.resource_context_json->>'guide_version' is distinct from new.guide_version then raise exception 'submission-policy creation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=new.creation_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from new.created_by_actor_profile_id or evidence.matched_grant_id is distinct from new.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from new.creation_action_id or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from new.id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy creation evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_submission_policy_creation_custody" + } + ], + "sequences": [ + { + "cache_size": 1, + "cycle": false, + "data_type": "integer", + "increment_by": 1, + "is_called": true, + "last_value": 1, + "max_value": 2147483647, + "min_value": 1, + "name": "actor_profile_migration_state_id_seq", + "start_value": 1 + }, + { + "cache_size": 1, + "cycle": false, + "data_type": "smallint", + "increment_by": 1, + "is_called": true, + "last_value": 1, + "max_value": 32767, + "min_value": 1, + "name": "authority_control_id_seq", + "start_value": 1 + } + ], + "tables": [ + { + "force_row_security": false, + "kind": "r", + "name": "actor_identity_links", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "actor_profile_migration_state", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "actor_profiles", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "admin_role_grants", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "api_rate_control_counters", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_admission_charges", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_admission_scopes", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_bindings", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_contents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_operation_receipts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_put_attempt_charges", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_put_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_put_observation_receipts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_recovery_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_replicas", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_storage_namespaces", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_verification_jobs", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_verification_receipts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "audit_events", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "authority_control", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "authority_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "checker_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "checker_results", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "checker_runs", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_award_definitions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_policy_versions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_rules", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "effective_project_submission_artifact_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "evidence_items", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_artifact_bindings", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_artifact_incidents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_artifact_ingests", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extracted_contents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extraction_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extraction_retry_budgets", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extraction_usages", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_format_classifications", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_snapshot_items", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_snapshots", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_sufficiency_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_sufficiency_report_source_usages", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_sufficiency_reports", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "iso_4217_currency_codes", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "legacy_actor_identities", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "legacy_workflow_eligibility", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "outbox_events", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "payment_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "policy_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "pre_submit_checker_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "pre_submit_evidence_results", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "pre_submit_evidence_sets", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_compensation_adapter_bindings", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_compensation_units", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_create_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_guide_compilation_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_guide_compilations", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_guides", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_role_grants", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_role_qualification_snapshots", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_setup_runs", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "projects", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_admission_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_leases", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_queue_entries", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "revision_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_artifact_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_bundle_admissions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_bundle_durable_intents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_policy_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submissions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "task_assignments", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "workstream_tasks", + "persistence": "p", + "row_security": false + } + ], + "triggers": [ + { + "definition": "CREATE TRIGGER actor_identity_link_history_guard BEFORE DELETE OR UPDATE ON actor_identity_links FOR EACH ROW EXECUTE FUNCTION guard_actor_identity_link_history()", + "enabled": "O", + "name": "actor_identity_link_history_guard", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER actor_identity_link_profile_guard AFTER INSERT OR UPDATE ON actor_identity_links DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", + "enabled": "O", + "name": "actor_identity_link_profile_guard", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE TRIGGER service_identity_migration_evidence_row_guard BEFORE DELETE OR UPDATE ON actor_profile_migration_state FOR EACH ROW EXECUTE FUNCTION guard_service_identity_migration_evidence()", + "enabled": "O", + "name": "service_identity_migration_evidence_row_guard", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CREATE TRIGGER service_identity_migration_evidence_truncate_guard BEFORE TRUNCATE ON actor_profile_migration_state FOR EACH STATEMENT EXECUTE FUNCTION guard_service_identity_migration_evidence()", + "enabled": "O", + "name": "service_identity_migration_evidence_truncate_guard", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CREATE TRIGGER actor_profile_history_guard BEFORE DELETE OR UPDATE ON actor_profiles FOR EACH ROW EXECUTE FUNCTION guard_actor_profile_history()", + "enabled": "O", + "name": "actor_profile_history_guard", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER actor_profile_link_guard AFTER INSERT OR UPDATE ON actor_profiles DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", + "enabled": "O", + "name": "actor_profile_link_guard", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER admin_role_grants_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON admin_role_grants DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", + "enabled": "O", + "name": "admin_role_grants_bootstrap_invariant", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE TRIGGER admin_role_grants_guard BEFORE INSERT OR DELETE OR UPDATE ON admin_role_grants FOR EACH ROW EXECUTE FUNCTION guard_admin_role_grant()", + "enabled": "O", + "name": "admin_role_grants_guard", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE TRIGGER admin_role_grants_reject_truncate BEFORE TRUNCATE ON admin_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_admin_role_grant_truncate()", + "enabled": "O", + "name": "admin_role_grants_reject_truncate", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER trg_artifact_binding_history AFTER INSERT ON artifact_bindings DEFERRABLE INITIALLY IMMEDIATE FOR EACH ROW EXECUTE FUNCTION validate_artifact_binding_history()", + "enabled": "O", + "name": "trg_artifact_binding_history", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE TRIGGER trg_artifact_bindings_immutable BEFORE DELETE OR UPDATE ON artifact_bindings FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_bindings_immutable", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE TRIGGER trg_artifact_contents_immutable BEFORE DELETE OR UPDATE ON artifact_contents FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_contents_immutable", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE TRIGGER artifact_receipt_producer_reference BEFORE INSERT OR UPDATE OF put_attempt_id, guide_source_item_id, checker_run_id, logical_role ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION guard_artifact_receipt_producer_reference()", + "enabled": "O", + "name": "artifact_receipt_producer_reference", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE TRIGGER trg_artifact_operation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_operation_receipts_immutable", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE TRIGGER trg_artifact_put_observation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_put_observation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_put_observation_receipts_immutable", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE TRIGGER artifact_recovery_attempt_custody BEFORE INSERT OR DELETE OR UPDATE ON artifact_recovery_attempts FOR EACH ROW EXECUTE FUNCTION validate_artifact_recovery_attempt()", + "enabled": "O", + "name": "artifact_recovery_attempt_custody", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE TRIGGER trg_artifact_storage_namespaces_immutable BEFORE DELETE OR UPDATE ON artifact_storage_namespaces FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_storage_namespaces_immutable", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE TRIGGER artifact_verification_lineage_custody BEFORE UPDATE ON artifact_verification_jobs FOR EACH ROW EXECUTE FUNCTION validate_artifact_verification_lineage()", + "enabled": "O", + "name": "artifact_verification_lineage_custody", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE TRIGGER trg_artifact_verification_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_verification_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_verification_receipts_immutable", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE TRIGGER audit_events_reject_truncate BEFORE TRUNCATE ON audit_events FOR EACH STATEMENT EXECUTE FUNCTION reject_audit_event_mutation()", + "enabled": "O", + "name": "audit_events_reject_truncate", + "table_name": "audit_events" + }, + { + "definition": "CREATE TRIGGER audit_events_reject_update_delete BEFORE DELETE OR UPDATE ON audit_events FOR EACH ROW EXECUTE FUNCTION reject_audit_event_mutation()", + "enabled": "O", + "name": "audit_events_reject_update_delete", + "table_name": "audit_events" + }, + { + "definition": "CREATE TRIGGER audit_events_set_authority_time BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION set_authority_audit_database_time()", + "enabled": "O", + "name": "audit_events_set_authority_time", + "table_name": "audit_events" + }, + { + "definition": "CREATE TRIGGER audit_events_validate_idempotency BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION validate_linked_authority_event()", + "enabled": "O", + "name": "audit_events_validate_idempotency", + "table_name": "audit_events" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER authority_control_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON authority_control DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", + "enabled": "O", + "name": "authority_control_bootstrap_invariant", + "table_name": "authority_control" + }, + { + "definition": "CREATE TRIGGER authority_control_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_control FOR EACH ROW EXECUTE FUNCTION guard_authority_control()", + "enabled": "O", + "name": "authority_control_guard", + "table_name": "authority_control" + }, + { + "definition": "CREATE TRIGGER authority_control_reject_truncate BEFORE TRUNCATE ON authority_control FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_control_truncate()", + "enabled": "O", + "name": "authority_control_reject_truncate", + "table_name": "authority_control" + }, + { + "definition": "CREATE TRIGGER authority_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_authority_idempotency_record()", + "enabled": "O", + "name": "authority_idempotency_guard", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER authority_idempotency_pending_guard AFTER INSERT OR UPDATE ON authority_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION reject_pending_authority_idempotency()", + "enabled": "O", + "name": "authority_idempotency_pending_guard", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE TRIGGER authority_idempotency_reject_truncate BEFORE TRUNCATE ON authority_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_idempotency_truncate()", + "enabled": "O", + "name": "authority_idempotency_reject_truncate", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE TRIGGER contribution_award_definitions_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_award_definitions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", + "enabled": "O", + "name": "contribution_award_definitions_content_guard", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_award_definitions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_award_definitions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_award_definitions_graph_guard", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE TRIGGER contribution_award_definitions_reject_truncate BEFORE TRUNCATE ON contribution_award_definitions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_award_definitions_reject_truncate", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_policies_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_policies_graph_guard", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE TRIGGER contribution_policies_reject_truncate BEFORE TRUNCATE ON contribution_policies FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_policies_reject_truncate", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE TRIGGER contribution_policy_versions_content_guard BEFORE DELETE OR UPDATE ON contribution_policy_versions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_version_content()", + "enabled": "O", + "name": "contribution_policy_versions_content_guard", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_policy_versions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policy_versions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_policy_versions_graph_guard", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE TRIGGER contribution_policy_versions_reject_truncate BEFORE TRUNCATE ON contribution_policy_versions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_policy_versions_reject_truncate", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE TRIGGER contribution_rules_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_rules FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", + "enabled": "O", + "name": "contribution_rules_content_guard", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_rules_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_rules DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_rules_graph_guard", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE TRIGGER contribution_rules_reject_truncate BEFORE TRUNCATE ON contribution_rules FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_rules_reject_truncate", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER effective_submission_policy_custody AFTER INSERT OR UPDATE ON effective_project_submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "effective_submission_policy_custody", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER effective_submission_policy_provenance_immutable BEFORE UPDATE ON effective_project_submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", + "enabled": "O", + "name": "effective_submission_policy_provenance_immutable", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER guide_mutation_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON guide_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_guide_mutation_idempotency()", + "enabled": "O", + "name": "guide_mutation_idempotency_guard", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER guide_mutation_idempotency_reject_truncate BEFORE TRUNCATE ON guide_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_mutation_idempotency_truncate()", + "enabled": "O", + "name": "guide_mutation_idempotency_reject_truncate", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_reservation_custody AFTER INSERT OR UPDATE ON guide_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "guide_mutation_reservation_custody", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER guide_source_snapshot_items_custody AFTER INSERT ON guide_source_snapshot_items DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_source_snapshot_items()", + "enabled": "O", + "name": "guide_source_snapshot_items_custody", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE TRIGGER guide_source_snapshot_items_immutable BEFORE DELETE OR UPDATE OR TRUNCATE ON guide_source_snapshot_items FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_source_snapshot_item_mutation()", + "enabled": "O", + "name": "guide_source_snapshot_items_immutable", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER source_snapshot_product_custody AFTER INSERT OR UPDATE ON guide_source_snapshots DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "source_snapshot_product_custody", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE TRIGGER trg_sufficiency_replay_immutable BEFORE DELETE OR UPDATE ON guide_sufficiency_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_sufficiency_replay_mutation()", + "enabled": "O", + "name": "trg_sufficiency_replay_immutable", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_sufficiency_replay_no_truncate BEFORE TRUNCATE ON guide_sufficiency_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_sufficiency_replay_truncate()", + "enabled": "O", + "name": "trg_sufficiency_replay_no_truncate", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER iso_4217_currency_codes_immutable BEFORE INSERT OR DELETE OR UPDATE ON iso_4217_currency_codes FOR EACH ROW EXECUTE FUNCTION guard_iso_4217_currency_codes()", + "enabled": "O", + "name": "iso_4217_currency_codes_immutable", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "CREATE TRIGGER iso_4217_currency_codes_reject_truncate BEFORE TRUNCATE ON iso_4217_currency_codes FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "iso_4217_currency_codes_reject_truncate", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "CREATE TRIGGER outbox_events_custody BEFORE INSERT OR DELETE OR UPDATE ON outbox_events FOR EACH ROW EXECUTE FUNCTION guard_outbox_event()", + "enabled": "O", + "name": "outbox_events_custody", + "table_name": "outbox_events" + }, + { + "definition": "CREATE TRIGGER outbox_events_reject_truncate BEFORE TRUNCATE ON outbox_events FOR EACH STATEMENT EXECUTE FUNCTION guard_outbox_event()", + "enabled": "O", + "name": "outbox_events_reject_truncate", + "table_name": "outbox_events" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER policy_mutation_replay_custody AFTER INSERT OR UPDATE ON policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", + "enabled": "O", + "name": "policy_mutation_replay_custody", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER policy_mutation_replay_immutable BEFORE INSERT OR DELETE OR UPDATE ON policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_policy_mutation_replay()", + "enabled": "O", + "name": "policy_mutation_replay_immutable", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER policy_mutation_replay_reject_truncate BEFORE TRUNCATE ON policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_policy_mutation_replay_truncate()", + "enabled": "O", + "name": "policy_mutation_replay_reject_truncate", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER pre_submit_policy_custody AFTER INSERT OR UPDATE ON pre_submit_checker_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "pre_submit_policy_custody", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE TRIGGER pre_submit_policy_provenance_immutable BEFORE UPDATE ON pre_submit_checker_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", + "enabled": "O", + "name": "pre_submit_policy_provenance_immutable", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_results_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_results_immutable", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_results_membership BEFORE INSERT ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_result_membership()", + "enabled": "O", + "name": "pre_submit_evidence_results_membership", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_results_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_results FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_results_no_truncate", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_sets_creation BEFORE INSERT ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_set_creation()", + "enabled": "O", + "name": "pre_submit_evidence_sets_creation", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_sets_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_sets_immutable", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_sets_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_sets FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_sets_no_truncate", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE TRIGGER project_compensation_binding_update_guard BEFORE UPDATE ON project_compensation_adapter_bindings FOR EACH ROW EXECUTE FUNCTION enforce_compensation_binding_lifecycle()", + "enabled": "O", + "name": "project_compensation_binding_update_guard", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE TRIGGER project_compensation_units_lifecycle_guard BEFORE INSERT OR DELETE OR UPDATE ON project_compensation_units FOR EACH ROW EXECUTE FUNCTION guard_project_compensation_units()", + "enabled": "O", + "name": "project_compensation_units_lifecycle_guard", + "table_name": "project_compensation_units" + }, + { + "definition": "CREATE TRIGGER project_compensation_units_reject_truncate BEFORE TRUNCATE ON project_compensation_units FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "project_compensation_units_reject_truncate", + "table_name": "project_compensation_units" + }, + { + "definition": "CREATE TRIGGER project_create_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON project_create_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_project_create_idempotency()", + "enabled": "O", + "name": "project_create_idempotency_guard", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE TRIGGER project_create_idempotency_reject_truncate BEFORE TRUNCATE ON project_create_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_project_create_idempotency_truncate()", + "enabled": "O", + "name": "project_create_idempotency_reject_truncate", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER project_create_reservation_custody AFTER INSERT OR UPDATE ON project_create_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", + "enabled": "O", + "name": "project_create_reservation_custody", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_compilation_attempt_delete BEFORE DELETE OR TRUNCATE ON project_guide_compilation_attempts FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", + "enabled": "O", + "name": "trg_compilation_attempt_delete", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE TRIGGER trg_compilation_attempt_update BEFORE UPDATE ON project_guide_compilation_attempts FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_attempt_update()", + "enabled": "O", + "name": "trg_compilation_attempt_update", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE TRIGGER trg_compilation_insert BEFORE INSERT ON project_guide_compilations FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_insert()", + "enabled": "O", + "name": "trg_compilation_insert", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE TRIGGER trg_compilation_mutation BEFORE DELETE OR UPDATE OR TRUNCATE ON project_guide_compilations FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", + "enabled": "O", + "name": "trg_compilation_mutation", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE TRIGGER guide_lineage_lifecycle_guard BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_guide_lineage_and_lifecycle()", + "enabled": "O", + "name": "guide_lineage_lifecycle_guard", + "table_name": "project_guides" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_product_custody AFTER INSERT OR UPDATE ON project_guides DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "guide_mutation_product_custody", + "table_name": "project_guides" + }, + { + "definition": "CREATE TRIGGER project_guides_policy_selection_immutable BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_project_guide_policy_selection()", + "enabled": "O", + "name": "project_guides_policy_selection_immutable", + "table_name": "project_guides" + }, + { + "definition": "CREATE TRIGGER trg_project_role_grants_history BEFORE INSERT OR DELETE OR UPDATE ON project_role_grants FOR EACH ROW EXECUTE FUNCTION guard_project_role_grant_history()", + "enabled": "O", + "name": "trg_project_role_grants_history", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE TRIGGER trg_project_role_grants_reject_truncate BEFORE TRUNCATE ON project_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", + "enabled": "O", + "name": "trg_project_role_grants_reject_truncate", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE TRIGGER trg_project_role_qualification_snapshots_immutable BEFORE INSERT OR DELETE OR UPDATE ON project_role_qualification_snapshots FOR EACH ROW EXECUTE FUNCTION guard_project_role_snapshot_history()", + "enabled": "O", + "name": "trg_project_role_qualification_snapshots_immutable", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE TRIGGER trg_project_role_snapshots_reject_truncate BEFORE TRUNCATE ON project_role_qualification_snapshots FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", + "enabled": "O", + "name": "trg_project_role_snapshots_reject_truncate", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER source_setup_run_custody AFTER INSERT OR UPDATE ON project_setup_runs DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "source_setup_run_custody", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER project_creation_custody AFTER INSERT OR UPDATE OF created_by_actor_profile_id, created_via_identity_link_id, created_by_admin_role_grant_id, creation_scope_type, creation_action_id, authorization_decision_event_id ON projects DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", + "enabled": "O", + "name": "project_creation_custody", + "table_name": "projects" + }, + { + "definition": "CREATE TRIGGER review_admission_idempotency_records_reject_truncate BEFORE TRUNCATE ON review_admission_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", + "enabled": "O", + "name": "review_admission_idempotency_records_reject_truncate", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE TRIGGER review_admission_records_guard BEFORE INSERT OR DELETE OR UPDATE ON review_admission_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_review_admission_record()", + "enabled": "O", + "name": "review_admission_records_guard", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER review_leases_active_lease_guard AFTER INSERT OR UPDATE ON review_leases DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", + "enabled": "O", + "name": "review_leases_active_lease_guard", + "table_name": "review_leases" + }, + { + "definition": "CREATE TRIGGER review_leases_guard BEFORE INSERT OR DELETE OR UPDATE ON review_leases FOR EACH ROW EXECUTE FUNCTION guard_review_lease()", + "enabled": "O", + "name": "review_leases_guard", + "table_name": "review_leases" + }, + { + "definition": "CREATE TRIGGER review_leases_reject_truncate BEFORE TRUNCATE ON review_leases FOR EACH STATEMENT EXECUTE FUNCTION reject_review_lease_truncate()", + "enabled": "O", + "name": "review_leases_reject_truncate", + "table_name": "review_leases" + }, + { + "definition": "CREATE TRIGGER review_policies_immutable BEFORE DELETE OR UPDATE ON review_policies FOR EACH ROW EXECUTE FUNCTION guard_review_policies_immutable()", + "enabled": "O", + "name": "review_policies_immutable", + "table_name": "review_policies" + }, + { + "definition": "CREATE TRIGGER review_policies_reject_truncate BEFORE TRUNCATE ON review_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_review_policies_immutable()", + "enabled": "O", + "name": "review_policies_reject_truncate", + "table_name": "review_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER review_policy_mutation_custody AFTER INSERT OR UPDATE ON review_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", + "enabled": "O", + "name": "review_policy_mutation_custody", + "table_name": "review_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER review_queue_entries_active_lease_guard AFTER INSERT OR UPDATE ON review_queue_entries DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", + "enabled": "O", + "name": "review_queue_entries_active_lease_guard", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE TRIGGER review_queue_entries_guard BEFORE INSERT OR DELETE OR UPDATE ON review_queue_entries FOR EACH ROW EXECUTE FUNCTION guard_review_queue_entry()", + "enabled": "O", + "name": "review_queue_entries_guard", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE TRIGGER review_queue_entries_reject_truncate BEFORE TRUNCATE ON review_queue_entries FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", + "enabled": "O", + "name": "review_queue_entries_reject_truncate", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE TRIGGER revision_policies_immutable BEFORE DELETE OR UPDATE ON revision_policies FOR EACH ROW EXECUTE FUNCTION guard_revision_policies_immutable()", + "enabled": "O", + "name": "revision_policies_immutable", + "table_name": "revision_policies" + }, + { + "definition": "CREATE TRIGGER revision_policies_reject_truncate BEFORE TRUNCATE ON revision_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_revision_policies_immutable()", + "enabled": "O", + "name": "revision_policies_reject_truncate", + "table_name": "revision_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER revision_policy_mutation_custody AFTER INSERT OR UPDATE ON revision_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", + "enabled": "O", + "name": "revision_policy_mutation_custody", + "table_name": "revision_policies" + }, + { + "definition": "CREATE TRIGGER submission_policy_approval_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_approval_provenance()", + "enabled": "O", + "name": "submission_policy_approval_provenance_immutable", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER submission_policy_creation_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_creation_custody()", + "enabled": "O", + "name": "submission_policy_creation_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER submission_policy_creation_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_creation_provenance()", + "enabled": "O", + "name": "submission_policy_creation_provenance_immutable", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER submission_policy_product_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "submission_policy_product_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER submission_bundle_admission_delete BEFORE DELETE OR TRUNCATE ON submission_bundle_admissions FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_admission_delete()", + "enabled": "O", + "name": "submission_bundle_admission_delete", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE TRIGGER submission_bundle_admission_lineage BEFORE UPDATE ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_lineage()", + "enabled": "O", + "name": "submission_bundle_admission_lineage", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE TRIGGER submission_bundle_admission_verified_lineage BEFORE INSERT ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_verified_lineage()", + "enabled": "O", + "name": "submission_bundle_admission_verified_lineage", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE TRIGGER submission_bundle_durable_intent_put_attempt BEFORE INSERT ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intent_put_attempt()", + "enabled": "O", + "name": "submission_bundle_durable_intent_put_attempt", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE TRIGGER submission_bundle_durable_intents_immutable BEFORE DELETE OR UPDATE ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", + "enabled": "O", + "name": "submission_bundle_durable_intents_immutable", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE TRIGGER submission_bundle_durable_intents_no_truncate BEFORE TRUNCATE ON submission_bundle_durable_intents FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", + "enabled": "O", + "name": "submission_bundle_durable_intents_no_truncate", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER submission_policy_replay_custody AFTER INSERT OR UPDATE ON submission_policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW WHEN (new.status::text = 'committed'::text) EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "submission_policy_replay_custody", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_submission_policy_replay_immutable BEFORE DELETE OR UPDATE ON submission_policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_submission_policy_replay_mutation()", + "enabled": "O", + "name": "trg_submission_policy_replay_immutable", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_submission_policy_replay_no_truncate BEFORE TRUNCATE ON submission_policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_submission_policy_replay_truncate()", + "enabled": "O", + "name": "trg_submission_policy_replay_no_truncate", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER submissions_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON submissions FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", + "enabled": "O", + "name": "submissions_contributor_human", + "table_name": "submissions" + }, + { + "definition": "CREATE TRIGGER task_assignments_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON task_assignments FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", + "enabled": "O", + "name": "task_assignments_contributor_human", + "table_name": "task_assignments" + } + ], + "types": [] +} diff --git a/backend/alembic/baseline/v01_pre_reset_source_manifest.json b/backend/alembic/baseline/v01_pre_reset_source_manifest.json new file mode 100644 index 000000000..782531c5d --- /dev/null +++ b/backend/alembic/baseline/v01_pre_reset_source_manifest.json @@ -0,0 +1,26923 @@ +{ + "acl": [ + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_identity_links", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profile_migration_state", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "actor_profiles", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "admin_role_grants", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "api_rate_control_counters", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_charges", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_admission_scopes", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_bindings", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_contents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_operation_receipts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempt_charges", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_put_observation_receipts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_recovery_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_replicas", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_storage_namespaces", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_jobs", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "artifact_verification_receipts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "audit_events", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_control", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "authority_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_results", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "checker_runs", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_award_definitions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_policy_versions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "contribution_rules", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "effective_project_submission_artifact_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "evidence_items", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_bindings", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_incidents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_artifact_ingests", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extracted_contents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_retry_budgets", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_extraction_usages", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_format_classifications", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshot_items", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_source_snapshots", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_report_source_usages", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "guide_sufficiency_reports", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "iso_4217_currency_codes", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_actor_identities", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "legacy_workflow_eligibility", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "outbox_events", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "payment_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_checker_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_results", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "pre_submit_evidence_sets", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_adapter_bindings", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_compensation_units", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_create_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilation_attempts", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guide_compilations", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_guides", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_grants", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_role_qualification_snapshots", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "project_setup_runs", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "projects", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_admission_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_leases", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "review_queue_entries", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "revision_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_artifact_policies", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_admissions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_bundle_durable_intents", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submission_policy_mutation_idempotency_records", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "submissions", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "task_assignments", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "DELETE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "INSERT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "REFERENCES" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "SELECT" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "TRIGGER" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "TRUNCATE" + }, + { + "grantable": "false", + "kind": "relation", + "name": "workstream_tasks", + "principal": "owner", + "privilege": "UPDATE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_event_facts_are_safe(event_name text, before_state js", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_event_facts_are_safe(event_name text, before_state js", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_facts_are_safe(facts json)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_facts_are_safe(facts json)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "enforce_compensation_binding_lifecycle()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "enforce_compensation_binding_lifecycle()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_identity_link_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_identity_link_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_profile_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_actor_profile_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_admin_role_grant()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_admin_role_grant()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_artifact_receipt_producer_reference()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_artifact_receipt_producer_reference()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_control()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_control()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_idempotency_record()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_authority_idempotency_record()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_children()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_children()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_version_content()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_contribution_policy_version_content()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_lineage_and_lifecycle()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_lineage_and_lifecycle()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_mutation_idempotency()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_guide_mutation_idempotency()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_iso_4217_currency_codes()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_iso_4217_currency_codes()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_outbox_event()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_outbox_event()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_policy_mutation_replay()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_policy_mutation_replay()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_result_membership()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_result_membership()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_results_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_results_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_set_creation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_set_creation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_sets_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_pre_submit_evidence_sets_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_compensation_units()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_compensation_units()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_create_idempotency()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_create_idempotency()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_attempt_update()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_attempt_update()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_insert()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_compilation_insert()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_policy_selection()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_guide_policy_selection()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_grant_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_grant_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_snapshot_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_project_role_snapshot_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_admission_record()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_admission_record()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_lease()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_lease()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_policies_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_policies_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_queue_entry()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_review_queue_entry()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_revision_policies_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_revision_policies_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_service_identity_migration_evidence()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_service_identity_migration_evidence()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_delete()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_delete()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_lineage()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_lineage()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_verified_lineage()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_admission_verified_lineage()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intent_put_attempt()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intent_put_attempt()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intents_immutable()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "guard_submission_bundle_durable_intents_immutable()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_availability_is_safe(value jsonb)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_availability_is_safe(value jsonb)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reason_is_safe(value text)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reason_is_safe(value text)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_token_is_safe(value text)", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "project_role_reference_token_is_safe(value text)", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_approval_provenance()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_approval_provenance()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_creation_provenance()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_creation_provenance()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_output_provenance()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "protect_submission_policy_output_provenance()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_admin_role_grant_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_admin_role_grant_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_artifact_fact_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_artifact_fact_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_audit_event_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_audit_event_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_control_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_control_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_idempotency_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_authority_idempotency_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_contribution_policy_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_contribution_policy_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_mutation_idempotency_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_mutation_idempotency_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_source_snapshot_item_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_guide_source_snapshot_item_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_pending_authority_idempotency()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_pending_authority_idempotency()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_policy_mutation_replay_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_policy_mutation_replay_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_create_idempotency_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_create_idempotency_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_guide_compilation_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_guide_compilation_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_role_history_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_project_role_history_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_lease_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_lease_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_queue_foundation_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_review_queue_foundation_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_submission_policy_replay_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_mutation()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_mutation()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_truncate()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "reject_sufficiency_replay_truncate()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "require_human_actor_profile_reference()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "require_human_actor_profile_reference()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "set_authority_audit_database_time()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "set_authority_audit_database_time()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_binding_history()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_binding_history()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_recovery_attempt()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_recovery_attempt()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_verification_lineage()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_artifact_verification_lineage()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_bootstrap_authority_state()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_bootstrap_authority_state()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_canonical_actor_link()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_canonical_actor_link()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_contribution_policy_graph()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_contribution_policy_graph()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_mutation_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_mutation_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_source_snapshot_items()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_guide_source_snapshot_items()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_linked_authority_event()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_linked_authority_event()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_policy_mutation_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_policy_mutation_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_project_create_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_project_create_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_review_active_lease()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_review_active_lease()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_authority_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_authority_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_creation_custody()", + "principal": "PUBLIC", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "routine", + "name": "validate_submission_policy_creation_custody()", + "principal": "owner", + "privilege": "EXECUTE" + }, + { + "grantable": "false", + "kind": "sequence", + "name": "actor_profile_migration_state_id_seq", + "principal": "owner", + "privilege": "USAGE" + }, + { + "grantable": "false", + "kind": "sequence", + "name": "authority_control_id_seq", + "principal": "owner", + "privilege": "USAGE" + } + ], + "auxiliary_objects": [], + "columns": [ + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "issuer", + "not_null": true, + "ordinal": 3, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "subject", + "not_null": true, + "ordinal": 4, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "subject_kind", + "not_null": true, + "ordinal": 5, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "linked_by", + "not_null": true, + "ordinal": 7, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "linked_at", + "not_null": true, + "ordinal": 8, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_verified_at", + "not_null": false, + "ordinal": 9, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by", + "not_null": false, + "ordinal": 10, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_at", + "not_null": false, + "ordinal": 11, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_reason", + "not_null": false, + "ordinal": 12, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_by", + "not_null": false, + "ordinal": 13, + "table_name": "actor_identity_links" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_at", + "not_null": false, + "ordinal": 14, + "table_name": "actor_identity_links" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivation_reason", + "not_null": false, + "ordinal": 15, + "table_name": "actor_identity_links" + }, + { + "data_type": "integer", + "default_expression": "nextval('actor_profile_migration_state_id_seq'::regclass)", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "schema_version", + "not_null": true, + "ordinal": 2, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classified_count", + "not_null": true, + "ordinal": 3, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_row_set_sha256", + "not_null": true, + "ordinal": 4, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "manifest_sha256", + "not_null": false, + "ordinal": 5, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "envelope_sha256", + "not_null": false, + "ordinal": 6, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "migrated_at", + "not_null": true, + "ordinal": 7, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_mapped_count", + "not_null": true, + "ordinal": 8, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_source_row_set_sha256", + "not_null": true, + "ordinal": 9, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_manifest_sha256", + "not_null": false, + "ordinal": 10, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_envelope_sha256", + "not_null": false, + "ordinal": 11, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(76)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity_database_binding", + "not_null": true, + "ordinal": 12, + "table_name": "actor_profile_migration_state" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_kind", + "not_null": true, + "ordinal": 2, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 3, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provisioning_method", + "not_null": true, + "ordinal": 4, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "display_name", + "not_null": false, + "ordinal": 5, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(320)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contact_email", + "not_null": false, + "ordinal": 6, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 7, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 8, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 9, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_seen_at", + "not_null": false, + "ordinal": 10, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_by", + "not_null": false, + "ordinal": 11, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_at", + "not_null": false, + "ordinal": 12, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspension_reason", + "not_null": false, + "ordinal": 13, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deactivated_by", + "not_null": false, + "ordinal": 14, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deactivated_at", + "not_null": false, + "ordinal": 15, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deactivation_reason", + "not_null": false, + "ordinal": 16, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity", + "not_null": false, + "ordinal": 17, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_by", + "not_null": false, + "ordinal": 18, + "table_name": "actor_profiles" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivated_at", + "not_null": false, + "ordinal": 19, + "table_name": "actor_profiles" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reactivation_reason", + "not_null": false, + "ordinal": 20, + "table_name": "actor_profiles" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "role", + "not_null": true, + "ordinal": 3, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 4, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_project_id", + "not_null": false, + "ordinal": 5, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "admin_role_grants" + }, + { + "data_type": "smallint", + "default_expression": "'1'::smallint", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 7, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_actor_profile_id", + "not_null": false, + "ordinal": 8, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_system_principal", + "not_null": false, + "ordinal": 9, + "table_name": "admin_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_admin_role_grant_id", + "not_null": false, + "ordinal": 10, + "table_name": "admin_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "grant_reason", + "not_null": true, + "ordinal": 11, + "table_name": "admin_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "clock_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_at", + "not_null": true, + "ordinal": 12, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_actor_profile_id", + "not_null": false, + "ordinal": 13, + "table_name": "admin_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_admin_role_grant_id", + "not_null": false, + "ordinal": 14, + "table_name": "admin_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_reason", + "not_null": false, + "ordinal": 15, + "table_name": "admin_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_at", + "not_null": false, + "ordinal": 16, + "table_name": "admin_role_grants" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "control_scope", + "not_null": true, + "ordinal": 1, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "bytea", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "key_digest", + "not_null": true, + "ordinal": 2, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "window_started_at", + "not_null": true, + "ordinal": 3, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "window_expires_at", + "not_null": true, + "ordinal": 4, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_count", + "not_null": true, + "ordinal": 5, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 6, + "table_name": "api_rate_control_counters" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_type", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_ref", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creating_operation_identity", + "not_null": true, + "ordinal": 8, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(20)", + "default_expression": "'provisional'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "state", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "reserved_at", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "completed_at", + "not_null": false, + "ordinal": 12, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "released_at", + "not_null": false, + "ordinal": 13, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 15, + "table_name": "artifact_admission_charges" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "limit_bytes", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "counted_bytes", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_admission_scopes" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_type", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_id", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_bindings" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_version", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 8, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attribution_type", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_binding_id", + "not_null": false, + "ordinal": 10, + "table_name": "artifact_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_contents" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": false, + "ordinal": 4, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "normalized_display_name", + "not_null": false, + "ordinal": 5, + "table_name": "artifact_contents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_contents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replica_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(1024)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_object_ref", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replayed", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome", + "not_null": true, + "ordinal": 8, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_number", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "details", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "contract_version", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_source_item_id", + "not_null": false, + "ordinal": 15, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_run_id", + "not_null": false, + "ordinal": 16, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": false, + "ordinal": 17, + "table_name": "artifact_operation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_put_attempt_charges" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "charge_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_put_attempt_charges" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_put_attempt_charges" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_request_type", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_type", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer_ref", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": false, + "ordinal": 6, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_source_item_id", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_run_id", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": false, + "ordinal": 9, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(255)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "storage_namespace_id", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_fingerprint", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(1024)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_target", + "not_null": true, + "ordinal": 15, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_identity", + "not_null": true, + "ordinal": 16, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 17, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "'prepared'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 18, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "next_run_at", + "not_null": false, + "ordinal": 19, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "executor_id", + "not_null": false, + "ordinal": 20, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lease_expires_at", + "not_null": false, + "ordinal": 21, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 22, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_result_code", + "not_null": false, + "ordinal": 23, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replica_id", + "not_null": false, + "ordinal": 24, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "receipt_id", + "not_null": false, + "ordinal": 25, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 26, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "prepared_at", + "not_null": true, + "ordinal": 27, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 28, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 29, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 30, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_mode", + "not_null": false, + "ordinal": 31, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "observation_count", + "not_null": true, + "ordinal": 32, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'5'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "maximum_observations", + "not_null": true, + "ordinal": 33, + "table_name": "artifact_put_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "expected_sha256", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "expected_byte_count", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_sha256", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_byte_count", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 9, + "table_name": "artifact_put_observation_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requester_actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requester_identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_request_id", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_correlation_id", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_verification_job_id", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retry_verification_job_id", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "parent_recovery_attempt_id", + "not_null": false, + "ordinal": 11, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "recovery_class", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(1000)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reason", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "client_idempotency_key", + "not_null": true, + "ordinal": 14, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 15, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(20)", + "default_expression": "'requested'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 16, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_result_code", + "not_null": false, + "ordinal": 17, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "initiation_audit_event_id", + "not_null": true, + "ordinal": 18, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_audit_event_id", + "not_null": false, + "ordinal": 19, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 20, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 21, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 22, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": false, + "ordinal": 23, + "table_name": "artifact_recovery_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(1024)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_object_ref", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verification_state", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "availability_state", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "integrity_state", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_replicas" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_reconciled_at", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_replicas" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 9, + "table_name": "artifact_replicas" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "storage_namespace_id", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_fingerprint", + "not_null": true, + "ordinal": 12, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_profile", + "not_null": true, + "ordinal": 13, + "table_name": "artifact_replicas" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "backend", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_profile", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_descriptor", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "namespace_fingerprint", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "artifact_storage_namespaces" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "originating_put_attempt_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "replica_id", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(40)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "integer", + "default_expression": "0", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_count", + "not_null": true, + "ordinal": 5, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "maximum_attempts", + "not_null": true, + "ordinal": 6, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "next_run_at", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "executor_id", + "not_null": false, + "ordinal": 8, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lease_expires_at", + "not_null": false, + "ordinal": 9, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 10, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "cas_version", + "not_null": true, + "ordinal": 11, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_result_code", + "not_null": false, + "ordinal": 12, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 13, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 14, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": false, + "ordinal": 15, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "parent_verification_job_id", + "not_null": false, + "ordinal": 16, + "table_name": "artifact_verification_jobs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verification_job_id", + "not_null": true, + "ordinal": 2, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "execution_generation", + "not_null": true, + "ordinal": 3, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome", + "not_null": true, + "ordinal": 4, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_sha256", + "not_null": false, + "ordinal": 5, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_byte_count", + "not_null": false, + "ordinal": 6, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": false, + "ordinal": 7, + "table_name": "artifact_verification_receipts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "audit_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "entity_type", + "not_null": true, + "ordinal": 2, + "table_name": "audit_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "entity_id", + "not_null": true, + "ordinal": 3, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_type", + "not_null": true, + "ordinal": 4, + "table_name": "audit_events" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "from_status", + "not_null": false, + "ordinal": 5, + "table_name": "audit_events" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "to_status", + "not_null": false, + "ordinal": 6, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 7, + "table_name": "audit_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_subject", + "not_null": false, + "ordinal": 8, + "table_name": "audit_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_issuer", + "not_null": false, + "ordinal": 9, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_roles", + "not_null": true, + "ordinal": 10, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_snapshot", + "not_null": true, + "ordinal": 11, + "table_name": "audit_events" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "auth_source", + "not_null": true, + "ordinal": 12, + "table_name": "audit_events" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "is_dev_auth", + "not_null": true, + "ordinal": 13, + "table_name": "audit_events" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reason", + "not_null": false, + "ordinal": 14, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_payload", + "not_null": true, + "ordinal": 15, + "table_name": "audit_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "audit_events" + }, + { + "data_type": "character varying(24)", + "default_expression": "'legacy_lifecycle'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_domain", + "not_null": true, + "ordinal": 17, + "table_name": "audit_events" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_version", + "not_null": false, + "ordinal": 18, + "table_name": "audit_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "occurred_at", + "not_null": false, + "ordinal": 19, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_ref_kind", + "not_null": false, + "ordinal": 20, + "table_name": "audit_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_id", + "not_null": false, + "ordinal": 21, + "table_name": "audit_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": false, + "ordinal": 22, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_actor_ref_kind", + "not_null": false, + "ordinal": 23, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_actor_ref", + "not_null": false, + "ordinal": 24, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "matched_grant_id", + "not_null": false, + "ordinal": 25, + "table_name": "audit_events" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "permission_id", + "not_null": false, + "ordinal": 26, + "table_name": "audit_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": false, + "ordinal": 27, + "table_name": "audit_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_type", + "not_null": false, + "ordinal": 28, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_id", + "not_null": false, + "ordinal": 29, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_ref_kind", + "not_null": false, + "ordinal": 30, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "target_ref_id", + "not_null": false, + "ordinal": 31, + "table_name": "audit_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "denial_code", + "not_null": false, + "ordinal": 32, + "table_name": "audit_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_reference", + "not_null": false, + "ordinal": 33, + "table_name": "audit_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "invalidation_cause_event_id", + "not_null": false, + "ordinal": 34, + "table_name": "audit_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "invalidation_target_kind", + "not_null": false, + "ordinal": 35, + "table_name": "audit_events" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "invalidation_target_ref", + "not_null": false, + "ordinal": 36, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "before_facts", + "not_null": false, + "ordinal": 37, + "table_name": "audit_events" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "after_facts", + "not_null": false, + "ordinal": 38, + "table_name": "audit_events" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": false, + "ordinal": 39, + "table_name": "audit_events" + }, + { + "data_type": "smallint", + "default_expression": "nextval('authority_control_id_seq'::regclass)", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "authority_control" + }, + { + "data_type": "boolean", + "default_expression": "false", + "generated_kind": "00", + "identity_kind": "00", + "name": "bootstrap_completed", + "not_null": true, + "ordinal": 2, + "table_name": "authority_control" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bootstrap_grant_id", + "not_null": false, + "ordinal": 3, + "table_name": "authority_control" + }, + { + "data_type": "smallint", + "default_expression": "'0'::smallint", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 4, + "table_name": "authority_control" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "clock_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 5, + "table_name": "authority_control" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "clock_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 6, + "table_name": "authority_control" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 2, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_ref_kind", + "not_null": true, + "ordinal": 3, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_ref", + "not_null": true, + "ordinal": 4, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(48)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation", + "not_null": true, + "ordinal": 5, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 7, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_resource_type", + "not_null": false, + "ordinal": 8, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_resource_id", + "not_null": false, + "ordinal": 9, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_resource_version", + "not_null": false, + "ordinal": 10, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "smallint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_http_status", + "not_null": false, + "ordinal": 11, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 12, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 13, + "table_name": "authority_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "required_checkers", + "not_null": true, + "ordinal": 4, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_checkers", + "not_null": true, + "ordinal": 5, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "blocking_severities", + "not_null": true, + "ordinal": 6, + "table_name": "checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": false, + "ordinal": 8, + "table_name": "checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_body", + "not_null": false, + "ordinal": 9, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 10, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 11, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 12, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_id", + "not_null": true, + "ordinal": 13, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_hash", + "not_null": true, + "ordinal": 14, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_checker_policy_id", + "not_null": true, + "ordinal": 15, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_checker_bundle_hash", + "not_null": true, + "ordinal": 16, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 17, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_role", + "not_null": false, + "ordinal": 18, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_actor", + "not_null": false, + "ordinal": 19, + "table_name": "checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_at", + "not_null": false, + "ordinal": 20, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 21, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 22, + "table_name": "checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 23, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_by_role", + "not_null": false, + "ordinal": 24, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_by_actor", + "not_null": false, + "ordinal": 25, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersession_kind", + "not_null": false, + "ordinal": 26, + "table_name": "checker_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersession_reason", + "not_null": false, + "ordinal": 27, + "table_name": "checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_run_id", + "not_null": true, + "ordinal": 2, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 3, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 4, + "table_name": "checker_results" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_name", + "not_null": true, + "ordinal": 5, + "table_name": "checker_results" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "checker_results" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "severity", + "not_null": true, + "ordinal": 7, + "table_name": "checker_results" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "blocks_review", + "not_null": true, + "ordinal": 8, + "table_name": "checker_results" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "message", + "not_null": true, + "ordinal": 9, + "table_name": "checker_results" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_message", + "not_null": false, + "ordinal": 10, + "table_name": "checker_results" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_suggested_fix", + "not_null": false, + "ordinal": 11, + "table_name": "checker_results" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_evidence_refs", + "not_null": true, + "ordinal": 12, + "table_name": "checker_results" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_visible", + "not_null": true, + "ordinal": 13, + "table_name": "checker_results" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "metadata", + "not_null": true, + "ordinal": 14, + "table_name": "checker_results" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 15, + "table_name": "checker_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 2, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 3, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 4, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "trigger_source", + "not_null": true, + "ordinal": 5, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_recommendation", + "not_null": true, + "ordinal": 7, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "outcome_source", + "not_null": true, + "ordinal": 8, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "triggered_by", + "not_null": true, + "ordinal": 9, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "triggered_by_subject", + "not_null": true, + "ordinal": 10, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "triggered_by_issuer", + "not_null": true, + "ordinal": 11, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "trigger_auth_source", + "not_null": true, + "ordinal": 12, + "table_name": "checker_runs" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "trigger_reason", + "not_null": false, + "ordinal": 13, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "audit_event_id", + "not_null": false, + "ordinal": 14, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_number", + "not_null": true, + "ordinal": 15, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_checker_run_id", + "not_null": false, + "ordinal": 16, + "table_name": "checker_runs" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "is_current_for_submission", + "not_null": true, + "ordinal": 17, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_version", + "not_null": true, + "ordinal": 18, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_payment_policy_version", + "not_null": true, + "ordinal": 19, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "package_hash", + "not_null": true, + "ordinal": 20, + "table_name": "checker_runs" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_hash_manifest", + "not_null": true, + "ordinal": 21, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_manifest_hash", + "not_null": true, + "ordinal": 22, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "passed_count", + "not_null": true, + "ordinal": 23, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_count", + "not_null": true, + "ordinal": 24, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failed_count", + "not_null": true, + "ordinal": 25, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "blocking_count", + "not_null": true, + "ordinal": 26, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "queued_at", + "not_null": true, + "ordinal": 27, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "started_at", + "not_null": false, + "ordinal": 28, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "completed_at", + "not_null": false, + "ordinal": 29, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_code", + "not_null": false, + "ordinal": 30, + "table_name": "checker_runs" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_message", + "not_null": false, + "ordinal": 31, + "table_name": "checker_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 32, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 33, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_version", + "not_null": false, + "ordinal": 34, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_hash", + "not_null": false, + "ordinal": 35, + "table_name": "checker_runs" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_body", + "not_null": false, + "ordinal": 36, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_id", + "not_null": true, + "ordinal": 37, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_generation", + "not_null": true, + "ordinal": 38, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_hash", + "not_null": true, + "ordinal": 39, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_id", + "not_null": true, + "ordinal": 40, + "table_name": "checker_runs" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_generation", + "not_null": true, + "ordinal": 41, + "table_name": "checker_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_hash", + "not_null": true, + "ordinal": 42, + "table_name": "checker_runs" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_rule_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_policy_version_id", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_type", + "not_null": true, + "ordinal": 5, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instrument_type", + "not_null": true, + "ordinal": 6, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "unit_code", + "not_null": true, + "ordinal": 7, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "numeric", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "quantity", + "not_null": true, + "ordinal": 8, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter_binding_id", + "not_null": true, + "ordinal": 9, + "table_name": "contribution_award_definitions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "name", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "'draft'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "current_published_version_id", + "not_null": false, + "ordinal": 5, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 6, + "table_name": "contribution_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "contribution_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 8, + "table_name": "contribution_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 9, + "table_name": "contribution_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_policy_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "version_number", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(16)", + "default_expression": "'draft'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 6, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "published_by", + "not_null": false, + "ordinal": 8, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "published_at", + "not_null": false, + "ordinal": 9, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 10, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 11, + "table_name": "contribution_policy_versions" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "contribution_rules" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_policy_version_id", + "not_null": true, + "ordinal": 2, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contribution_type", + "not_null": true, + "ordinal": 4, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compensation_mode", + "not_null": true, + "ordinal": 5, + "table_name": "contribution_rules" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_artifact_policy_id", + "not_null": true, + "ordinal": 7, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_artifact_policy_hash", + "not_null": true, + "ordinal": 8, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 9, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "merge_algorithm_version", + "not_null": true, + "ordinal": 10, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy", + "not_null": true, + "ordinal": 11, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_hash", + "not_null": true, + "ordinal": 12, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 13, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_effective_policy_id", + "not_null": false, + "ordinal": 15, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 16, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 17, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 18, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 19, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 20, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 21, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 22, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_decision_event_id", + "not_null": false, + "ordinal": 23, + "table_name": "effective_project_submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 2, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "type", + "not_null": true, + "ordinal": 3, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "label", + "not_null": true, + "ordinal": 4, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(1000)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "uri", + "not_null": false, + "ordinal": 5, + "table_name": "evidence_items" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "hash", + "not_null": false, + "ordinal": 6, + "table_name": "evidence_items" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "size_bytes", + "not_null": false, + "ordinal": 7, + "table_name": "evidence_items" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_at", + "not_null": false, + "ordinal": 8, + "table_name": "evidence_items" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "metadata", + "not_null": true, + "ordinal": 9, + "table_name": "evidence_items" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "evidence_items" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 7, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_id", + "not_null": true, + "ordinal": 10, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_generation", + "not_null": true, + "ordinal": 11, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 12, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 13, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": false, + "ordinal": 14, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 15, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 16, + "table_name": "guide_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "logical_role", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_binding_id", + "not_null": false, + "ordinal": 11, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service", + "not_null": true, + "ordinal": 12, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_artifact_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "code", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_sha256", + "not_null": false, + "ordinal": 7, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "observed_byte_count", + "not_null": false, + "ordinal": 8, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bounded_facts", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_artifact_incidents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(255)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_artifact_ingests" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detected_format", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_name", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_version", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_sha256", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_byte_count", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_sha256", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_output", + "not_null": true, + "ordinal": 11, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "omission_facts", + "not_null": true, + "ordinal": 12, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_extracted_contents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detected_format", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_name", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extractor_version", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_number", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 11, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_code", + "not_null": false, + "ordinal": 12, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bounded_facts", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "guide_source_extraction_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claimed_slots", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extracted_content_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extraction_attempt_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_status", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_extraction_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "sha256", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "byte_count", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(255)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detected_format", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detector_name", + "not_null": true, + "ordinal": 11, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "detector_version", + "not_null": true, + "ordinal": 12, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification_facts", + "not_null": true, + "ordinal": 13, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 14, + "table_name": "guide_source_format_classifications" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "item_order", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_kind", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_label", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "ingestion_adapter", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "media_type", + "not_null": false, + "ordinal": 7, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_snapshot_items" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "manifest_schema_version", + "not_null": true, + "ordinal": 5, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "manifest_json", + "not_null": true, + "ordinal": 6, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "bundle_hash", + "not_null": true, + "ordinal": 7, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_by", + "not_null": true, + "ordinal": 8, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_at", + "not_null": true, + "ordinal": 9, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 10, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 11, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 12, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 13, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 14, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 15, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 16, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_generation", + "not_null": false, + "ordinal": 17, + "table_name": "guide_source_snapshots" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 7, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 10, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 11, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "report_id", + "not_null": false, + "ordinal": 12, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": false, + "ordinal": 13, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 14, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 15, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 16, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 17, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 18, + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "report_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "item_order", + "not_null": true, + "ordinal": 3, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_item_id", + "not_null": true, + "ordinal": 4, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_id", + "not_null": true, + "ordinal": 6, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extraction_usage_id", + "not_null": true, + "ordinal": 7, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extraction_attempt_id", + "not_null": true, + "ordinal": 8, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "extracted_content_id", + "not_null": true, + "ordinal": 9, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": true, + "ordinal": 10, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 11, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_output_sha256", + "not_null": true, + "ordinal": 12, + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 7, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "findings", + "not_null": true, + "ordinal": 8, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "summary", + "not_null": false, + "ordinal": 9, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_name", + "not_null": false, + "ordinal": 10, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_version", + "not_null": false, + "ordinal": 11, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 12, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 13, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_role", + "not_null": false, + "ordinal": 14, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_actor", + "not_null": false, + "ordinal": 15, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_at", + "not_null": false, + "ordinal": 16, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "acknowledgement_note", + "not_null": false, + "ordinal": 17, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_setup_run_id", + "not_null": false, + "ordinal": 18, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": false, + "ordinal": 19, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_material_sha256", + "not_null": false, + "ordinal": 20, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_material_byte_count", + "not_null": false, + "ordinal": 21, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 22, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 23, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 24, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service_identity", + "not_null": false, + "ordinal": 25, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 26, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 27, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 28, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 29, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_actor_profile_id", + "not_null": false, + "ordinal": 30, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_via_identity_link_id", + "not_null": false, + "ordinal": 31, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warnings_acknowledged_by_admin_role_grant_id", + "not_null": false, + "ordinal": 32, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_scope_type", + "not_null": false, + "ordinal": 33, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_scope_project_id", + "not_null": false, + "ordinal": 34, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_action_id", + "not_null": false, + "ordinal": 35, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "warning_acknowledgement_decision_event_id", + "not_null": false, + "ordinal": 36, + "table_name": "guide_sufficiency_reports" + }, + { + "data_type": "character varying(3)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "code", + "not_null": true, + "ordinal": 1, + "table_name": "iso_4217_currency_codes" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 1, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_subject", + "not_null": true, + "ordinal": 2, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_issuer", + "not_null": true, + "ordinal": 3, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "display_name", + "not_null": false, + "ordinal": 4, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(320)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "email", + "not_null": false, + "ordinal": 5, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_seen_roles", + "not_null": true, + "ordinal": 6, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_claim_snapshot", + "not_null": true, + "ordinal": 7, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "auth_source", + "not_null": true, + "ordinal": 8, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "is_dev_auth", + "not_null": true, + "ordinal": 9, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "first_seen_at", + "not_null": true, + "ordinal": 10, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_seen_at", + "not_null": true, + "ordinal": 11, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 12, + "table_name": "legacy_actor_identities" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_id", + "not_null": true, + "ordinal": 2, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "profile_type", + "not_null": true, + "ordinal": 3, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "skill_tags", + "not_null": true, + "ordinal": 5, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_type", + "not_null": true, + "ordinal": 6, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "scope_id", + "not_null": true, + "ordinal": 7, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "profile_metadata", + "not_null": true, + "ordinal": 8, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 9, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 10, + "table_name": "legacy_workflow_eligibility" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_id", + "not_null": true, + "ordinal": 1, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_type", + "not_null": true, + "ordinal": 2, + "table_name": "outbox_events" + }, + { + "data_type": "smallint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "event_version", + "not_null": true, + "ordinal": 3, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(32)", + "default_expression": "'workstream'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "producer", + "not_null": true, + "ordinal": 4, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(64)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "aggregate_type", + "not_null": true, + "ordinal": 5, + "table_name": "outbox_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "aggregate_id", + "not_null": true, + "ordinal": 6, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 7, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": true, + "ordinal": 8, + "table_name": "outbox_events" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "causation_event_id", + "not_null": false, + "ordinal": 9, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 10, + "table_name": "outbox_events" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payload", + "not_null": true, + "ordinal": 11, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payload_digest", + "not_null": true, + "ordinal": 12, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "occurred_at", + "not_null": true, + "ordinal": 13, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(16)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "delivery_state", + "not_null": true, + "ordinal": 14, + "table_name": "outbox_events" + }, + { + "data_type": "integer", + "default_expression": "0", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_count", + "not_null": true, + "ordinal": 15, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "next_attempt_at", + "not_null": false, + "ordinal": 16, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_owner", + "not_null": false, + "ordinal": 17, + "table_name": "outbox_events" + }, + { + "data_type": "bigint", + "default_expression": "'0'::bigint", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_generation", + "not_null": true, + "ordinal": 18, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claimed_at", + "not_null": false, + "ordinal": 19, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "claim_expires_at", + "not_null": false, + "ordinal": 20, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_attempt_at", + "not_null": false, + "ordinal": 21, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_error_code", + "not_null": false, + "ordinal": 22, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "finalized_at", + "not_null": false, + "ordinal": 23, + "table_name": "outbox_events" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archived_at", + "not_null": false, + "ordinal": 24, + "table_name": "outbox_events" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "payment_policies" + }, + { + "data_type": "numeric(12,2)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "base_amount", + "not_null": false, + "ordinal": 4, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "currency", + "not_null": false, + "ordinal": 5, + "table_name": "payment_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payout_type", + "not_null": false, + "ordinal": 6, + "table_name": "payment_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revision_payment_rule", + "not_null": false, + "ordinal": 7, + "table_name": "payment_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "rejection_payment_rule", + "not_null": false, + "ordinal": 8, + "table_name": "payment_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "accepted_payment_rule", + "not_null": false, + "ordinal": 9, + "table_name": "payment_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "payment_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 7, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 8, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 9, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 10, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 11, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_id", + "not_null": true, + "ordinal": 12, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_generation", + "not_null": true, + "ordinal": 13, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 14, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 15, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 17, + "table_name": "policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_id", + "not_null": true, + "ordinal": 7, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_hash", + "not_null": true, + "ordinal": 8, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 9, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compiler_version", + "not_null": false, + "ordinal": 10, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compiled_bundle", + "not_null": false, + "ordinal": 11, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "compiled_bundle_hash", + "not_null": false, + "ordinal": 12, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_names", + "not_null": true, + "ordinal": 13, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "checker_configs", + "not_null": true, + "ordinal": 14, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 15, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_pre_submit_checker_policy_id", + "not_null": false, + "ordinal": 17, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 18, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 19, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 20, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 21, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 22, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 23, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 24, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_decision_event_id", + "not_null": false, + "ordinal": 25, + "table_name": "pre_submit_checker_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "evidence_set_id", + "not_null": true, + "ordinal": 2, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_order", + "not_null": true, + "ordinal": 3, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(80)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "schema_version", + "not_null": true, + "ordinal": 4, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "dispatch_authority", + "not_null": true, + "ordinal": 5, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "definition_id", + "not_null": true, + "ordinal": 6, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "definition_version", + "not_null": true, + "ordinal": 7, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "public_name", + "not_null": true, + "ordinal": 8, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source", + "not_null": true, + "ordinal": 9, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "phase", + "not_null": true, + "ordinal": 10, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "classification", + "not_null": true, + "ordinal": 11, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "severity", + "not_null": true, + "ordinal": 12, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 13, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_code", + "not_null": false, + "ordinal": 14, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "message_code", + "not_null": true, + "ordinal": 15, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_plan_sha256", + "not_null": true, + "ordinal": 16, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "rule_instance_id", + "not_null": false, + "ordinal": 17, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_policy_sha256", + "not_null": true, + "ordinal": 18, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 19, + "table_name": "pre_submit_evidence_results" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_identity", + "not_null": true, + "ordinal": 2, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 4, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 5, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 6, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assignment_id", + "not_null": true, + "ordinal": 7, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_id", + "not_null": false, + "ordinal": 8, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_version", + "not_null": false, + "ordinal": 9, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "prepared_generation_id", + "not_null": true, + "ordinal": 10, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_sha256", + "not_null": true, + "ordinal": 11, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_byte_count", + "not_null": true, + "ordinal": 12, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_id", + "not_null": true, + "ordinal": 13, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_sha256", + "not_null": true, + "ordinal": 14, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 15, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 16, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 17, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_sha256", + "not_null": true, + "ordinal": 18, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_sha256", + "not_null": true, + "ordinal": 19, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_policy_id", + "not_null": true, + "ordinal": 20, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_artifact_policy_sha256", + "not_null": true, + "ordinal": 21, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_policy_id", + "not_null": true, + "ordinal": 22, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_checker_policy_sha256", + "not_null": true, + "ordinal": 23, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_plan_sha256", + "not_null": true, + "ordinal": 24, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "catalogue_id", + "not_null": true, + "ordinal": 25, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(40)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "catalogue_version", + "not_null": true, + "ordinal": 26, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "catalogue_manifest_sha256", + "not_null": true, + "ordinal": 27, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "storage_scheme", + "not_null": true, + "ordinal": 28, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_status", + "not_null": true, + "ordinal": 29, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "eligible", + "not_null": true, + "ordinal": 30, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_count", + "not_null": true, + "ordinal": 31, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_manifest_sha256", + "not_null": true, + "ordinal": 32, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 33, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_policy_context_hash", + "not_null": true, + "ordinal": 34, + "table_name": "pre_submit_evidence_sets" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instrument_type", + "not_null": true, + "ordinal": 3, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "adapter_actor_id", + "not_null": true, + "ordinal": 4, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "route_key", + "not_null": true, + "ordinal": 5, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 6, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "binding_lifecycle_version", + "not_null": true, + "ordinal": 7, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 8, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 9, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_by", + "not_null": false, + "ordinal": 10, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "suspended_at", + "not_null": false, + "ordinal": 11, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 12, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 13, + "table_name": "project_compensation_adapter_bindings" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 1, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instrument_type", + "not_null": true, + "ordinal": 2, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "unit_code", + "not_null": true, + "ordinal": 3, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(3)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "iso_currency_code", + "not_null": false, + "ordinal": 4, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 6, + "table_name": "project_compensation_units" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "project_compensation_units" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_by", + "not_null": false, + "ordinal": 8, + "table_name": "project_compensation_units" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "retired_at", + "not_null": false, + "ordinal": 9, + "table_name": "project_compensation_units" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 4, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 5, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 6, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 7, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 8, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_generation", + "not_null": true, + "ordinal": 9, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 11, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 12, + "table_name": "project_create_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": true, + "ordinal": 7, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 8, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_input_hash", + "not_null": true, + "ordinal": 9, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_material_hash", + "not_null": true, + "ordinal": 10, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_id", + "not_null": true, + "ordinal": 11, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_version", + "not_null": true, + "ordinal": 12, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_schema_version", + "not_null": true, + "ordinal": 13, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_manifest_hash", + "not_null": true, + "ordinal": 14, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_id", + "not_null": true, + "ordinal": 15, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_version", + "not_null": true, + "ordinal": 16, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_schema_version", + "not_null": true, + "ordinal": 17, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_manifest_hash", + "not_null": true, + "ordinal": 18, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_identity", + "not_null": true, + "ordinal": 19, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_version", + "not_null": true, + "ordinal": 20, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instruction_version", + "not_null": true, + "ordinal": 21, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_idempotency_key", + "not_null": true, + "ordinal": 22, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 23, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_result", + "not_null": false, + "ordinal": 24, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_hash", + "not_null": false, + "ordinal": 25, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "component_hashes", + "not_null": false, + "ordinal": 26, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "failure_code", + "not_null": false, + "ordinal": 27, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "persisted_compilation_id", + "not_null": false, + "ordinal": 28, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "reserved_at", + "not_null": true, + "ordinal": 29, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "provider_uncertain_at", + "not_null": false, + "ordinal": 30, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "accepted_at", + "not_null": false, + "ordinal": 31, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "terminal_at", + "not_null": false, + "ordinal": 32, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "persisted_at", + "not_null": false, + "ordinal": 33, + "table_name": "project_guide_compilation_attempts" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_guide_compilations" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 4, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 5, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 6, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 7, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": true, + "ordinal": 8, + "table_name": "project_guide_compilations" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 9, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_input_hash", + "not_null": true, + "ordinal": 10, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_material_hash", + "not_null": true, + "ordinal": 11, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_catalogue_manifest_hash", + "not_null": true, + "ordinal": 12, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_catalogue_manifest_hash", + "not_null": true, + "ordinal": 13, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_identity", + "not_null": true, + "ordinal": 14, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "agent_version", + "not_null": true, + "ordinal": 15, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "instruction_version", + "not_null": true, + "ordinal": 16, + "table_name": "project_guide_compilations" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "canonical_result", + "not_null": true, + "ordinal": 17, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "result_hash", + "not_null": true, + "ordinal": 18, + "table_name": "project_guide_compilations" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "component_hashes", + "not_null": true, + "ordinal": 19, + "table_name": "project_guide_compilations" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_compilation_id", + "not_null": false, + "ordinal": 20, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": true, + "ordinal": 21, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": true, + "ordinal": 22, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service_identity", + "not_null": true, + "ordinal": 23, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": true, + "ordinal": 24, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": true, + "ordinal": 25, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_resource_context_digest", + "not_null": true, + "ordinal": 26, + "table_name": "project_guide_compilations" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 27, + "table_name": "project_guide_compilations" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_guides" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 3, + "table_name": "project_guides" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 4, + "table_name": "project_guides" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "content_markdown", + "not_null": true, + "ordinal": 5, + "table_name": "project_guides" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by", + "not_null": false, + "ordinal": 6, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "effective_at", + "not_null": false, + "ordinal": 7, + "table_name": "project_guides" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "change_summary", + "not_null": false, + "ordinal": 8, + "table_name": "project_guides" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 9, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 10, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 11, + "table_name": "project_guides" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 12, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutated_by_actor_profile_id", + "not_null": false, + "ordinal": 13, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutated_via_identity_link_id", + "not_null": false, + "ordinal": 14, + "table_name": "project_guides" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutated_by_admin_role_grant_id", + "not_null": false, + "ordinal": 15, + "table_name": "project_guides" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutation_scope_type", + "not_null": false, + "ordinal": 16, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutation_scope_project_id", + "not_null": false, + "ordinal": 17, + "table_name": "project_guides" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_mutation_action_id", + "not_null": false, + "ordinal": 18, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "last_authorization_decision_event_id", + "not_null": false, + "ordinal": 19, + "table_name": "project_guides" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "mutation_generation", + "not_null": false, + "ordinal": 20, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_review_policy_id", + "not_null": false, + "ordinal": 21, + "table_name": "project_guides" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_review_policy_hash", + "not_null": false, + "ordinal": 22, + "table_name": "project_guides" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_revision_policy_id", + "not_null": false, + "ordinal": 23, + "table_name": "project_guides" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_revision_policy_hash", + "not_null": false, + "ordinal": 24, + "table_name": "project_guides" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_review_policy_generation", + "not_null": false, + "ordinal": 25, + "table_name": "project_guides" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "selected_revision_policy_generation", + "not_null": false, + "ordinal": 26, + "table_name": "project_guides" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "role", + "not_null": true, + "ordinal": 4, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "project_role_grants" + }, + { + "data_type": "smallint", + "default_expression": "'1'::smallint", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 6, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(16)", + "default_expression": "'manual'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "grant_method", + "not_null": true, + "ordinal": 7, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "qualification_snapshot_id", + "not_null": true, + "ordinal": 8, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_actor_profile_id", + "not_null": true, + "ordinal": 9, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_by_admin_role_grant_id", + "not_null": true, + "ordinal": 10, + "table_name": "project_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "grant_reason", + "not_null": true, + "ordinal": 11, + "table_name": "project_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "granted_at", + "not_null": true, + "ordinal": 12, + "table_name": "project_role_grants" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_actor_profile_id", + "not_null": false, + "ordinal": 13, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_by_admin_role_grant_id", + "not_null": false, + "ordinal": 14, + "table_name": "project_role_grants" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_reason", + "not_null": false, + "ordinal": 15, + "table_name": "project_role_grants" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revoked_at", + "not_null": false, + "ordinal": 16, + "table_name": "project_role_grants" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requested_role", + "not_null": true, + "ordinal": 4, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "skills_snapshot", + "not_null": true, + "ordinal": 5, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reputation_snapshot", + "not_null": true, + "ordinal": 6, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "prior_project_work_refs", + "not_null": true, + "ordinal": 7, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "jsonb", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_expertise_refs", + "not_null": true, + "ordinal": 8, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_by_actor_profile_id", + "not_null": true, + "ordinal": 9, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_by_admin_role_grant_id", + "not_null": true, + "ordinal": 10, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "captured_at", + "not_null": true, + "ordinal": 11, + "table_name": "project_role_qualification_snapshots" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(155)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "celery_task_id", + "not_null": false, + "ordinal": 7, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 8, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "current_step", + "not_null": true, + "ordinal": 9, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_sufficiency_report_id", + "not_null": false, + "ordinal": 10, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_submission_artifact_policy_id", + "not_null": false, + "ordinal": 11, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_code", + "not_null": false, + "ordinal": 12, + "table_name": "project_setup_runs" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_summary", + "not_null": false, + "ordinal": 13, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 14, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 15, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 16, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "started_at", + "not_null": false, + "ordinal": 17, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "finished_at", + "not_null": false, + "ordinal": 18, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "output_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 19, + "table_name": "project_setup_runs" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "post_submit_derivation_summary", + "not_null": false, + "ordinal": 20, + "table_name": "project_setup_runs" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 21, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorized_by_actor_profile_id", + "not_null": false, + "ordinal": 22, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorized_via_identity_link_id", + "not_null": false, + "ordinal": 23, + "table_name": "project_setup_runs" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorized_by_admin_role_grant_id", + "not_null": false, + "ordinal": 24, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_scope_type", + "not_null": false, + "ordinal": 25, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_scope_project_id", + "not_null": false, + "ordinal": 26, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_action_id", + "not_null": false, + "ordinal": 27, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 28, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "error_artifact_incident_id", + "not_null": false, + "ordinal": 29, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "continuation_verification_job_id", + "not_null": false, + "ordinal": 30, + "table_name": "project_setup_runs" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "continuation_started_at", + "not_null": false, + "ordinal": 31, + "table_name": "project_setup_runs" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "projects" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "name", + "not_null": true, + "ordinal": 2, + "table_name": "projects" + }, + { + "data_type": "character varying(120)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "slug", + "not_null": true, + "ordinal": 3, + "table_name": "projects" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "description", + "not_null": false, + "ordinal": 4, + "table_name": "projects" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "projects" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 6, + "table_name": "projects" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 7, + "table_name": "projects" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 8, + "table_name": "projects" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 9, + "table_name": "projects" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 10, + "table_name": "projects" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 11, + "table_name": "projects" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 12, + "table_name": "projects" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 13, + "table_name": "projects" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": true, + "ordinal": 2, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 3, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 4, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 5, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 6, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 7, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 8, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "admitting_checker_run_id", + "not_null": true, + "ordinal": 9, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_queue_entry_id", + "not_null": false, + "ordinal": 11, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 12, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 13, + "table_name": "review_admission_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_leases" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_queue_entry_id", + "not_null": true, + "ordinal": 2, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 3, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 4, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 5, + "table_name": "review_leases" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 6, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reviewer_id", + "not_null": true, + "ordinal": 7, + "table_name": "review_leases" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reviewer_contribution_policy_version_id", + "not_null": true, + "ordinal": 8, + "table_name": "review_leases" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "attempt_generation", + "not_null": true, + "ordinal": 9, + "table_name": "review_leases" + }, + { + "data_type": "character varying(16)", + "default_expression": "'active'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 10, + "table_name": "review_leases" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "claimed_at", + "not_null": true, + "ordinal": 11, + "table_name": "review_leases" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "expires_at", + "not_null": true, + "ordinal": 12, + "table_name": "review_leases" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "closed_at", + "not_null": false, + "ordinal": 13, + "table_name": "review_leases" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "close_reason", + "not_null": false, + "ordinal": 14, + "table_name": "review_leases" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "review_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "review_policies" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "requires_second_review", + "not_null": true, + "ordinal": 4, + "table_name": "review_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "allowed_decisions", + "not_null": true, + "ordinal": 5, + "table_name": "review_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "minimum_finding_fields", + "not_null": true, + "ordinal": 6, + "table_name": "review_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 7, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_generation", + "not_null": true, + "ordinal": 8, + "table_name": "review_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 9, + "table_name": "review_policies" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantics_status", + "not_null": true, + "ordinal": 10, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 11, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_preference_window_seconds", + "not_null": false, + "ordinal": 12, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "review_lease_duration_seconds", + "not_null": false, + "ordinal": 13, + "table_name": "review_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "max_active_review_leases_per_reviewer", + "not_null": false, + "ordinal": 14, + "table_name": "review_policies" + }, + { + "data_type": "boolean", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "self_review_allowed", + "not_null": false, + "ordinal": 15, + "table_name": "review_policies" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reject_policy", + "not_null": false, + "ordinal": 16, + "table_name": "review_policies" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "finding_evidence_requirement", + "not_null": false, + "ordinal": 17, + "table_name": "review_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_policy_hash", + "not_null": false, + "ordinal": 18, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 19, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 20, + "table_name": "review_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 21, + "table_name": "review_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 22, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 23, + "table_name": "review_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 24, + "table_name": "review_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 25, + "table_name": "review_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 3, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_id", + "not_null": true, + "ordinal": 4, + "table_name": "review_queue_entries" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "submission_version", + "not_null": true, + "ordinal": 5, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "admitting_checker_run_id", + "not_null": true, + "ordinal": 6, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(16)", + "default_expression": "'pending'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "queue_state", + "not_null": true, + "ordinal": 7, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_mode", + "not_null": true, + "ordinal": 8, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_reason", + "not_null": true, + "ordinal": 9, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "first_queued_at", + "not_null": true, + "ordinal": 10, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "available_since", + "not_null": true, + "ordinal": 11, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "preferred_reviewer_id", + "not_null": false, + "ordinal": 12, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "preference_expires_at", + "not_null": false, + "ordinal": 13, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "closed_at", + "not_null": false, + "ordinal": 14, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(32)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "closed_reason", + "not_null": false, + "ordinal": 15, + "table_name": "review_queue_entries" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "routing_generation", + "not_null": true, + "ordinal": 16, + "table_name": "review_queue_entries" + }, + { + "data_type": "integer", + "default_expression": "1", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_generation", + "not_null": true, + "ordinal": 17, + "table_name": "review_queue_entries" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "statement_timestamp()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 18, + "table_name": "review_queue_entries" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "active_lease_id", + "not_null": false, + "ordinal": 19, + "table_name": "review_queue_entries" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 3, + "table_name": "revision_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "max_revision_rounds", + "not_null": true, + "ordinal": 4, + "table_name": "revision_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "revision_deadline_hours", + "not_null": true, + "ordinal": 5, + "table_name": "revision_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "allowed_resubmission_states", + "not_null": true, + "ordinal": 6, + "table_name": "revision_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "reviewer_reassignment_rule", + "not_null": false, + "ordinal": 7, + "table_name": "revision_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 8, + "table_name": "revision_policies" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_generation", + "not_null": true, + "ordinal": 9, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 10, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(24)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantics_status", + "not_null": true, + "ordinal": 11, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 12, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_policy_hash", + "not_null": false, + "ordinal": 13, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 14, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 15, + "table_name": "revision_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 16, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 17, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 18, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 19, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "authorization_decision_event_id", + "not_null": false, + "ordinal": 20, + "table_name": "revision_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_version", + "not_null": true, + "ordinal": 4, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 5, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_hash", + "not_null": true, + "ordinal": 6, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_version", + "not_null": true, + "ordinal": 7, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "lifecycle_status", + "not_null": true, + "ordinal": 8, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_body", + "not_null": true, + "ordinal": 9, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_hash", + "not_null": true, + "ordinal": 10, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "derivation_source", + "not_null": true, + "ordinal": 11, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_material_refs", + "not_null": true, + "ordinal": 12, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "derivation_agent_name", + "not_null": false, + "ordinal": 13, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "derivation_agent_version", + "not_null": false, + "ordinal": 14, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 15, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 16, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 17, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_role", + "not_null": false, + "ordinal": 18, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_actor", + "not_null": false, + "ordinal": 19, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_at", + "not_null": false, + "ordinal": 20, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_policy_id", + "not_null": false, + "ordinal": 21, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "superseded_at", + "not_null": false, + "ordinal": 22, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "change_summary", + "not_null": false, + "ordinal": 23, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_actor_profile_id", + "not_null": false, + "ordinal": 24, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_via_identity_link_id", + "not_null": false, + "ordinal": 25, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_admin_role_grant_id", + "not_null": false, + "ordinal": 26, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by_service_identity", + "not_null": false, + "ordinal": 27, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_type", + "not_null": false, + "ordinal": 28, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_scope_project_id", + "not_null": false, + "ordinal": 29, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_action_id", + "not_null": false, + "ordinal": 30, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "creation_decision_event_id", + "not_null": false, + "ordinal": 31, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_actor_profile_id", + "not_null": false, + "ordinal": 32, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_via_identity_link_id", + "not_null": false, + "ordinal": 33, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approved_by_admin_role_grant_id", + "not_null": false, + "ordinal": 34, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_scope_type", + "not_null": false, + "ordinal": 35, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_scope_project_id", + "not_null": false, + "ordinal": 36, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_action_id", + "not_null": false, + "ordinal": 37, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "approval_decision_event_id", + "not_null": false, + "ordinal": 38, + "table_name": "submission_artifact_policies" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "durable_intent_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_evidence_set_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 4, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_content_id", + "not_null": true, + "ordinal": 5, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verified_replica_id", + "not_null": true, + "ordinal": 6, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "verification_receipt_id", + "not_null": true, + "ordinal": 7, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_operation_receipt_id", + "not_null": false, + "ordinal": 8, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_observation_receipt_id", + "not_null": false, + "ordinal": 9, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 10, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 11, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 12, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 13, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assignment_id", + "not_null": true, + "ordinal": 14, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_id", + "not_null": false, + "ordinal": 15, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "predecessor_submission_version", + "not_null": false, + "ordinal": 16, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_policy_context_hash", + "not_null": true, + "ordinal": 17, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_id", + "not_null": true, + "ordinal": 18, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "semantic_manifest_sha256", + "not_null": true, + "ordinal": 19, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_sha256", + "not_null": true, + "ordinal": 20, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "archive_byte_count", + "not_null": true, + "ordinal": 21, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(16)", + "default_expression": "'ready'::character varying", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 22, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "ready_at", + "not_null": true, + "ordinal": 23, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "consumed_at", + "not_null": false, + "ordinal": 24, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "consumed_by_submission_id", + "not_null": false, + "ordinal": 25, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "stale_at", + "not_null": false, + "ordinal": 26, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "stale_reason", + "not_null": false, + "ordinal": 27, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 28, + "table_name": "submission_bundle_admissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "pre_submit_evidence_set_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "put_attempt_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 4, + "table_name": "submission_bundle_durable_intents" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "actor_profile_id", + "not_null": true, + "ordinal": 2, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "identity_link_id", + "not_null": true, + "ordinal": 3, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "service_identity", + "not_null": false, + "ordinal": 4, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(160)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "action_id", + "not_null": true, + "ordinal": 5, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "idempotency_key", + "not_null": false, + "ordinal": 6, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "request_digest", + "not_null": true, + "ordinal": 7, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_digest", + "not_null": true, + "ordinal": 8, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "resource_context_json", + "not_null": true, + "ordinal": 9, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "operation_id", + "not_null": true, + "ordinal": 10, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 11, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "guide_id", + "not_null": true, + "ordinal": 12, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_snapshot_id", + "not_null": true, + "ordinal": 13, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "policy_id", + "not_null": true, + "ordinal": 14, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_run_id", + "not_null": false, + "ordinal": 15, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "bigint", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_generation", + "not_null": true, + "ordinal": 16, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "setup_task_id", + "not_null": false, + "ordinal": 17, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "uuid", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "correlation_id", + "not_null": false, + "ordinal": 18, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(16)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 19, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "response_json", + "not_null": false, + "ordinal": 20, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_policy_id", + "not_null": false, + "ordinal": 21, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_effective_policy_id", + "not_null": false, + "ordinal": 22, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_pre_submit_policy_id", + "not_null": false, + "ordinal": 23, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 24, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "committed_at", + "not_null": false, + "ordinal": 25, + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 2, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contributor_id", + "not_null": true, + "ordinal": 3, + "table_name": "submissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "version", + "not_null": true, + "ordinal": 4, + "table_name": "submissions" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 5, + "table_name": "submissions" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "summary", + "not_null": true, + "ordinal": 6, + "table_name": "submissions" + }, + { + "data_type": "character varying(1000)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "package_uri", + "not_null": false, + "ordinal": 7, + "table_name": "submissions" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "package_hash", + "not_null": true, + "ordinal": 8, + "table_name": "submissions" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "artifact_hash_manifest", + "not_null": true, + "ordinal": 9, + "table_name": "submissions" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "worker_attestation", + "not_null": true, + "ordinal": 10, + "table_name": "submissions" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_version", + "not_null": true, + "ordinal": 11, + "table_name": "submissions" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_payment_policy_version", + "not_null": true, + "ordinal": 12, + "table_name": "submissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "submitted_at", + "not_null": true, + "ordinal": 13, + "table_name": "submissions" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_at", + "not_null": false, + "ordinal": 14, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "supersedes_submission_id", + "not_null": false, + "ordinal": 15, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_id", + "not_null": false, + "ordinal": 16, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_hash", + "not_null": false, + "ordinal": 17, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_id", + "not_null": false, + "ordinal": 18, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_hash", + "not_null": false, + "ordinal": 19, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_policy_id", + "not_null": false, + "ordinal": 20, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_bundle_hash", + "not_null": false, + "ordinal": 21, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 22, + "table_name": "submissions" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_version", + "not_null": false, + "ordinal": 23, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_hash", + "not_null": false, + "ordinal": 24, + "table_name": "submissions" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_body", + "not_null": false, + "ordinal": 25, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_id", + "not_null": true, + "ordinal": 26, + "table_name": "submissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_generation", + "not_null": true, + "ordinal": 27, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_hash", + "not_null": true, + "ordinal": 28, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_id", + "not_null": true, + "ordinal": 29, + "table_name": "submissions" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_generation", + "not_null": true, + "ordinal": 30, + "table_name": "submissions" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_hash", + "not_null": true, + "ordinal": 31, + "table_name": "submissions" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_id", + "not_null": true, + "ordinal": 2, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "contributor_id", + "not_null": true, + "ordinal": 3, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assigned_by", + "not_null": true, + "ordinal": 4, + "table_name": "task_assignments" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "assigned_at", + "not_null": true, + "ordinal": 5, + "table_name": "task_assignments" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "accepted_at", + "not_null": false, + "ordinal": 6, + "table_name": "task_assignments" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "released_at", + "not_null": false, + "ordinal": 7, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 8, + "table_name": "task_assignments" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "id", + "not_null": true, + "ordinal": 1, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "project_id", + "not_null": true, + "ordinal": 2, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_version", + "not_null": false, + "ordinal": 3, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_payment_policy_version", + "not_null": false, + "ordinal": 4, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_type", + "not_null": true, + "ordinal": 5, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(500)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_ref", + "not_null": false, + "ordinal": 6, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(128)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "source_payload_hash", + "not_null": false, + "ordinal": 7, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "import_batch_id", + "not_null": false, + "ordinal": 8, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(200)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "external_task_id", + "not_null": false, + "ordinal": 9, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(300)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "title", + "not_null": true, + "ordinal": 10, + "table_name": "workstream_tasks" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "description", + "not_null": true, + "ordinal": 11, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "task_type", + "not_null": false, + "ordinal": 12, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "difficulty", + "not_null": false, + "ordinal": 13, + "table_name": "workstream_tasks" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "skill_tags", + "not_null": true, + "ordinal": 14, + "table_name": "workstream_tasks" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "estimated_time_minutes", + "not_null": false, + "ordinal": 15, + "table_name": "workstream_tasks" + }, + { + "data_type": "numeric(12,2)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "base_amount", + "not_null": false, + "ordinal": 16, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(20)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "currency", + "not_null": false, + "ordinal": 17, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "payout_type", + "not_null": false, + "ordinal": 18, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(30)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "status", + "not_null": true, + "ordinal": 19, + "table_name": "workstream_tasks" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "acceptance_criteria", + "not_null": false, + "ordinal": 20, + "table_name": "workstream_tasks" + }, + { + "data_type": "text", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "rejection_criteria", + "not_null": false, + "ordinal": 21, + "table_name": "workstream_tasks" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "deadline_at", + "not_null": false, + "ordinal": 22, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_by", + "not_null": true, + "ordinal": 23, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(100)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "assigned_to", + "not_null": false, + "ordinal": 24, + "table_name": "workstream_tasks" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "created_at", + "not_null": true, + "ordinal": 25, + "table_name": "workstream_tasks" + }, + { + "data_type": "timestamp with time zone", + "default_expression": "now()", + "generated_kind": "00", + "identity_kind": "00", + "name": "updated_at", + "not_null": true, + "ordinal": 26, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_id", + "not_null": false, + "ordinal": 27, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_guide_source_snapshot_hash", + "not_null": false, + "ordinal": 28, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_id", + "not_null": false, + "ordinal": 29, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_effective_project_submission_artifact_policy_hash", + "not_null": false, + "ordinal": 30, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_policy_id", + "not_null": false, + "ordinal": 31, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_pre_submit_checker_bundle_hash", + "not_null": false, + "ordinal": 32, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_id", + "not_null": false, + "ordinal": 33, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(50)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_version", + "not_null": false, + "ordinal": 34, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_hash", + "not_null": false, + "ordinal": 35, + "table_name": "workstream_tasks" + }, + { + "data_type": "json", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_post_submit_checker_policy_body", + "not_null": false, + "ordinal": 36, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_id", + "not_null": false, + "ordinal": 37, + "table_name": "workstream_tasks" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_generation", + "not_null": false, + "ordinal": 38, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_review_policy_hash", + "not_null": false, + "ordinal": 39, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(36)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_id", + "not_null": false, + "ordinal": 40, + "table_name": "workstream_tasks" + }, + { + "data_type": "integer", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_generation", + "not_null": false, + "ordinal": 41, + "table_name": "workstream_tasks" + }, + { + "data_type": "character varying(71)", + "default_expression": "", + "generated_kind": "00", + "identity_kind": "00", + "name": "locked_revision_policy_hash", + "not_null": false, + "ordinal": 42, + "table_name": "workstream_tasks" + } + ], + "constraints": [ + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "actor_identity_link_profile_guard", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (subject_kind::text = 'service'::text OR last_verified_at IS NOT NULL)", + "kind": "c", + "name": "ck_actor_identity_links_human_verified", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_actor_identity_links_id_uuid", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (length(btrim(issuer::text)) >= 1 AND length(btrim(issuer::text)) <= 200)", + "kind": "c", + "name": "ck_actor_identity_links_issuer", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK ((revoked_reason IS NULL OR revoked_reason::text = btrim(revoked_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(revoked_reason::text) >= 1 AND octet_length(revoked_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500))", + "kind": "c", + "name": "ck_actor_identity_links_lifecycle_reason_bounds", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_identity_links_reactivation_fields", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (status::text = 'active'::text AND revoked_by IS NULL AND revoked_at IS NULL AND revoked_reason IS NULL OR status::text = 'revoked'::text AND revoked_by IS NOT NULL AND revoked_at IS NOT NULL AND revoked_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_identity_links_revocation_fields", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'revoked']))", + "kind": "c", + "name": "ck_actor_identity_links_status", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (length(btrim(subject::text)) >= 1 AND length(btrim(subject::text)) <= 200)", + "kind": "c", + "name": "ck_actor_identity_links_subject", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (subject_kind::text = ANY (ARRAY['human', 'service']))", + "kind": "c", + "name": "ck_actor_identity_links_subject_kind", + "table_name": "actor_identity_links" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_actor_identity_links_actor_profile_id_actor_profiles", + "table_name": "actor_identity_links" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_actor_identity_links", + "table_name": "actor_identity_links" + }, + { + "definition": "UNIQUE (actor_profile_id)", + "kind": "u", + "name": "uq_actor_identity_links_actor_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "UNIQUE (issuer, subject)", + "kind": "u", + "name": "uq_actor_identity_links_external_identity", + "table_name": "actor_identity_links" + }, + { + "definition": "UNIQUE (id, actor_profile_id)", + "kind": "u", + "name": "uq_actor_identity_links_id_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "CHECK (classified_count = 0 AND manifest_sha256 IS NULL AND envelope_sha256 IS NULL OR classified_count > 0 AND manifest_sha256 IS NOT NULL AND envelope_sha256 IS NOT NULL)", + "kind": "c", + "name": "ck_actor_profile_migration_state_evidence", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CHECK (service_identity_mapped_count >= 0 AND service_identity_mapped_count <= 7 AND service_identity_source_row_set_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_database_binding::text ~ '^postgres-v1:[0-9a-f]{64}$'::text AND (service_identity_mapped_count = 0 AND service_identity_manifest_sha256 IS NULL AND service_identity_envelope_sha256 IS NULL OR service_identity_mapped_count >= 1 AND service_identity_mapped_count <= 7 AND service_identity_manifest_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_envelope_sha256::text ~ '^[0-9a-f]{64}$'::text))", + "kind": "c", + "name": "ck_actor_profile_migration_state_service_identity_evidence", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CHECK (id = 1 AND schema_version = 1 AND classified_count >= 0)", + "kind": "c", + "name": "ck_actor_profile_migration_state_singleton", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_actor_profile_migration_state", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "actor_profile_link_guard", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (actor_kind::text = ANY (ARRAY['human', 'service']))", + "kind": "c", + "name": "ck_actor_profiles_actor_kind", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_actor_profiles_id_uuid", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (actor_kind::text = 'human'::text AND provisioning_method::text = 'automatic_first_access'::text OR actor_kind::text = 'service'::text AND provisioning_method::text = 'manual_service_provisioning'::text)", + "kind": "c", + "name": "ck_actor_profiles_kind_provisioning", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (actor_kind::text = 'human'::text AND service_identity IS NULL OR actor_kind::text = 'service'::text AND (service_identity::text = ANY (ARRAY['workstream.artifact.verifier', 'workstream.artifact.put_resolver', 'workstream.artifact.scheduler', 'workstream.artifact.binding', 'workstream.artifact.guide_reader', 'workstream.artifact.materializer', 'workstream.artifact.checker_output', 'workstream.project.setup', 'workstream.review.preference_expiry', 'workstream.review.lease_expiry', 'workstream.review.authority_invalidation_reconciliation', 'workstream.review.reconciliation', 'workstream.review.artifact_reference_reconciliation', 'workstream.review.projection'])))", + "kind": "c", + "name": "ck_actor_profiles_kind_service_identity", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (status::text = 'active'::text AND suspended_by IS NULL AND suspended_at IS NULL AND suspension_reason IS NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'suspended'::text AND suspended_by IS NOT NULL AND suspended_at IS NOT NULL AND suspension_reason IS NOT NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'deactivated'::text AND deactivated_by IS NOT NULL AND deactivated_at IS NOT NULL AND deactivation_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_profiles_lifecycle_fields", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK ((suspension_reason IS NULL OR suspension_reason::text = btrim(suspension_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(suspension_reason::text) >= 1 AND octet_length(suspension_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500) AND (deactivation_reason IS NULL OR deactivation_reason::text = btrim(deactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(deactivation_reason::text) >= 1 AND octet_length(deactivation_reason::text) <= 500))", + "kind": "c", + "name": "ck_actor_profiles_lifecycle_reason_bounds", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (provisioning_method::text = ANY (ARRAY['automatic_first_access', 'manual_service_provisioning']))", + "kind": "c", + "name": "ck_actor_profiles_provisioning_method", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", + "kind": "c", + "name": "ck_actor_profiles_reactivation_fields", + "table_name": "actor_profiles" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'deactivated']))", + "kind": "c", + "name": "ck_actor_profiles_status", + "table_name": "actor_profiles" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_actor_profiles", + "table_name": "actor_profiles" + }, + { + "definition": "UNIQUE (service_identity)", + "kind": "u", + "name": "service_identity", + "table_name": "actor_profiles" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "admin_role_grants_bootstrap_invariant", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (granted_by_system_principal::text = 'workstream:system:bootstrap'::text AND granted_by_actor_profile_id IS NULL AND granted_by_admin_role_grant_id IS NULL OR granted_by_system_principal IS NULL AND granted_by_actor_profile_id IS NOT NULL AND granted_by_admin_role_grant_id IS NOT NULL)", + "kind": "c", + "name": "ck_admin_role_grants_grant_attribution", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (octet_length(grant_reason) >= 1 AND octet_length(grant_reason) <= 500)", + "kind": "c", + "name": "ck_admin_role_grants_grant_reason", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND octet_length(revoked_reason) >= 1 AND octet_length(revoked_reason) <= 500 AND revoked_at IS NOT NULL)", + "kind": "c", + "name": "ck_admin_role_grants_lifecycle", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (role::text = ANY (ARRAY['access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority']))", + "kind": "c", + "name": "ck_admin_role_grants_role", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (scope_type::text = 'system'::text AND scope_project_id IS NULL OR scope_type::text = 'project'::text AND scope_project_id IS NOT NULL AND (role::text <> ALL (ARRAY['access_administrator', 'operator'])))", + "kind": "c", + "name": "ck_admin_role_grants_role_scope", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (scope_type::text = ANY (ARRAY['system', 'project']))", + "kind": "c", + "name": "ck_admin_role_grants_scope_type", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_admin_role_grants_granted_by_admin_role_grant_id_adm_81e0", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_admin_role_grants_revoked_by_admin_role_grant_id_adm_78b5", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_admin_role_grants_scope_project_id_projects", + "table_name": "admin_role_grants" + }, + { + "definition": "FOREIGN KEY (target_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_admin_role_grants_target_actor_profile_id_actor_profiles", + "table_name": "admin_role_grants" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_admin_role_grants", + "table_name": "admin_role_grants" + }, + { + "definition": "CHECK (octet_length(key_digest) = 32)", + "kind": "c", + "name": "ck_api_rate_control_counters_digest_length", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (request_count >= 1 AND request_count <= '9223372036854775807'::bigint)", + "kind": "c", + "name": "ck_api_rate_control_counters_request_count", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (control_scope::text = ANY (ARRAY['first_access', 'admin_mutation', 'authorization_read']))", + "kind": "c", + "name": "ck_api_rate_control_counters_scope_token", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (window_started_at < window_expires_at)", + "kind": "c", + "name": "ck_api_rate_control_counters_window_order", + "table_name": "api_rate_control_counters" + }, + { + "definition": "PRIMARY KEY (control_scope, key_digest)", + "kind": "p", + "name": "pk_api_rate_control_counters", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_admission_charges_byte_count_nonnegative", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_admission_charges_cas_nonnegative", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK ((state::text = 'completed'::text) = (completed_at IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_admission_charges_completed_timestamp", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (creating_operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_admission_charges_operation_identity_shape", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", + "kind": "c", + "name": "ck_artifact_admission_charges_producer_type", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK ((state::text = 'released'::text) = (released_at IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_admission_charges_released_timestamp", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_admission_charges_sha256_shape", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (state::text = ANY (ARRAY['provisional', 'completed', 'released']))", + "kind": "c", + "name": "ck_artifact_admission_charges_state", + "table_name": "artifact_admission_charges" + }, + { + "definition": "FOREIGN KEY (scope_type, scope_id) REFERENCES artifact_admission_scopes(scope_type, scope_id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_admission_charges_scope", + "table_name": "artifact_admission_charges" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_admission_charges", + "table_name": "artifact_admission_charges" + }, + { + "definition": "UNIQUE (scope_type, scope_id, sha256, byte_count)", + "kind": "u", + "name": "uq_artifact_admission_charge_scope_content", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CHECK (cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_admission_scopes_cas_nonnegative", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (counted_bytes >= 0 AND counted_bytes <= limit_bytes)", + "kind": "c", + "name": "ck_artifact_admission_scopes_counted_bytes_within_limit", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (limit_bytes > 0)", + "kind": "c", + "name": "ck_artifact_admission_scopes_limit_positive", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (octet_length(scope_id::text) >= 1 AND octet_length(scope_id::text) <= 120)", + "kind": "c", + "name": "ck_artifact_admission_scopes_scope_id_bounds", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (scope_type::text = ANY (ARRAY['deployment', 'project', 'producer', 'task']))", + "kind": "c", + "name": "ck_artifact_admission_scopes_scope_type", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "PRIMARY KEY (scope_type, scope_id)", + "kind": "p", + "name": "pk_artifact_admission_scopes", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CHECK (scope_version > 0)", + "kind": "c", + "name": "ck_artifact_bindings_scope_version_positive", + "table_name": "artifact_bindings" + }, + { + "definition": "CHECK (scope_version = 1 AND supersedes_binding_id IS NULL OR scope_version > 1 AND supersedes_binding_id IS NOT NULL)", + "kind": "c", + "name": "ck_artifact_bindings_scope_version_predecessor", + "table_name": "artifact_bindings" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_bindings_content_id_artifact_contents", + "table_name": "artifact_bindings" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_bindings_project_id_projects", + "table_name": "artifact_bindings" + }, + { + "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES artifact_bindings(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_bindings_supersedes_binding_id_artifact_bindings", + "table_name": "artifact_bindings" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_bindings", + "table_name": "artifact_bindings" + }, + { + "definition": "TRIGGER DEFERRABLE", + "kind": "t", + "name": "trg_artifact_binding_history", + "table_name": "artifact_bindings" + }, + { + "definition": "UNIQUE (project_id, resource_type, resource_id, logical_role, scope_version)", + "kind": "u", + "name": "uq_artifact_binding_scope_version", + "table_name": "artifact_bindings" + }, + { + "definition": "UNIQUE (supersedes_binding_id)", + "kind": "u", + "name": "uq_artifact_binding_supersedes", + "table_name": "artifact_bindings" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_contents_byte_count_nonnegative", + "table_name": "artifact_contents" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_contents_sha256_shape", + "table_name": "artifact_contents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_contents", + "table_name": "artifact_contents" + }, + { + "definition": "UNIQUE (sha256, byte_count)", + "kind": "u", + "name": "uq_artifact_content_digest_size", + "table_name": "artifact_contents" + }, + { + "definition": "CHECK (attempt_number > 0)", + "kind": "c", + "name": "ck_artifact_operation_receipts_attempt_positive", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (contract_version = 2 AND put_attempt_id IS NOT NULL AND (guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND logical_role IS NULL OR guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR guide_source_item_id IS NULL AND checker_run_id IS NULL AND logical_role IS NULL))", + "kind": "c", + "name": "ck_artifact_operation_receipts_contract_producer_reference", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (operation::text = 'put'::text)", + "kind": "c", + "name": "ck_artifact_operation_receipts_operation", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (outcome::text = 'stored_pending_verification'::text)", + "kind": "c", + "name": "ck_artifact_operation_receipts_outcome", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_operation_receipts_request_digest_shape", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_operation_receipts_replica_id_artifact_replicas", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_receipt_checker_run", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_receipt_guide_item", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_receipt_put_attempt", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_operation_receipts", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "UNIQUE (put_attempt_id)", + "kind": "u", + "name": "uq_artifact_receipt_put_attempt", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "FOREIGN KEY (attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempt_charges_attempt_id_artifact_put_b25d", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "FOREIGN KEY (charge_id) REFERENCES artifact_admission_charges(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempt_charges_charge_id_artifact_admi_85a9", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "PRIMARY KEY (attempt_id, charge_id)", + "kind": "p", + "name": "pk_artifact_put_attempt_charges", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_put_attempts_byte_count_nonnegative", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (canonical_target::text ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_canonical_target_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (execution_mode IS NULL OR (execution_mode::text = ANY (ARRAY['caller_put', 'observation'])))", + "kind": "c", + "name": "ck_artifact_put_attempts_execution_mode", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", + "kind": "c", + "name": "ck_artifact_put_attempts_executor_lease_pair", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK ((status::text = 'put_in_flight'::text) = (executor_id IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_put_attempts_inflight_fence", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (observation_count >= 0 AND maximum_observations > 0)", + "kind": "c", + "name": "ck_artifact_put_attempts_observation_counts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_operation_identity_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (status::text <> 'prepared'::text OR next_run_at IS NULL AND executor_id IS NULL AND lease_expires_at IS NULL AND execution_generation = 0 AND terminal_result_code IS NULL AND terminal_at IS NULL AND replica_id IS NULL AND receipt_id IS NULL)", + "kind": "c", + "name": "ck_artifact_put_attempts_prepared_execution_inactive", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_request_type::text = 'guide'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text OR producer_request_type::text = 'checker_output'::text AND producer_type::text = 'service_identity'::text AND producer_ref::text = 'workstream.artifact.checker_output'::text OR producer_request_type::text = 'submission_bundle'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_identity", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_request_type::text = 'guide'::text AND guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND task_id IS NULL AND logical_role IS NULL OR producer_request_type::text = 'checker_output'::text AND guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND task_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR producer_request_type::text = 'submission_bundle'::text AND guide_source_item_id IS NULL AND checker_run_id IS NULL AND task_id IS NOT NULL AND logical_role IS NULL)", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_reference", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_request_type::text = ANY (ARRAY['guide', 'checker_output', 'submission_bundle']))", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_request_type", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", + "kind": "c", + "name": "ck_artifact_put_attempts_producer_type", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_request_digest_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_attempts_sha256_shape", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['prepared', 'put_in_flight', 'acknowledgement_unknown', 'object_confirmed', 'absent_replay_required', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", + "kind": "c", + "name": "ck_artifact_put_attempts_status", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (status::text <> 'provider_unavailable'::text OR observation_count >= maximum_observations AND next_run_at IS NULL AND terminal_at IS NOT NULL)", + "kind": "c", + "name": "ck_artifact_put_attempts_unavailable_exhausted", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_put_attempts_versions_nonnegative", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_checker_run_id_checker_runs", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_guide_source_item_id_guide_sou_e48c", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (storage_namespace_id, namespace_fingerprint) REFERENCES artifact_storage_namespaces(id, namespace_fingerprint) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_namespace_fingerprint", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_project_id_projects", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_receipt_id_artifact_operation_receipts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_replica_id_artifact_replicas", + "table_name": "artifact_put_attempts" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_attempts_task_id_workstream_tasks", + "table_name": "artifact_put_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_put_attempts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "UNIQUE (operation_identity)", + "kind": "u", + "name": "uq_artifact_put_attempt_operation", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CHECK (expected_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_expected_sha256", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (expected_byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_expected_size", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK ((outcome::text = ANY (ARRAY['observed_confirmed', 'observed_integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_observed_facts", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_observed_sha256", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_observed_size", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (outcome::text = ANY (ARRAY['observed_confirmed', 'observed_missing', 'observed_integrity_mismatch', 'conflict']))", + "kind": "c", + "name": "ck_artifact_put_observation_receipts_outcome", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_put_observation_receipts_put_attempt_id_art_237d", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_put_observation_receipts", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "UNIQUE (put_attempt_id, execution_generation)", + "kind": "u", + "name": "uq_artifact_put_observation_fence", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CHECK (cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_cas_nonnegative", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (source_verification_job_id::text <> retry_verification_job_id::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_distinct_jobs", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (recovery_class::text = 'provider_observation'::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_recovery_class", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_request_digest", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['requested', 'succeeded', 'failed']))", + "kind": "c", + "name": "ck_artifact_recovery_attempts_status", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (status::text = 'succeeded'::text AND terminal_result_code::text = 'verified'::text OR status::text = 'failed'::text AND (terminal_result_code::text = ANY (ARRAY['provider_unavailable', 'missing', 'integrity_mismatch', 'conflict'])) OR status::text = 'requested'::text)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_terminal_result", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (status::text = 'requested'::text AND terminal_result_code IS NULL AND terminal_at IS NULL AND terminal_audit_event_id IS NULL OR (status::text = ANY (ARRAY['succeeded', 'failed'])) AND terminal_result_code IS NOT NULL AND terminal_at IS NOT NULL AND terminal_audit_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_artifact_recovery_attempts_terminal_shape", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (initiation_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_initiation_audit_event_id_2af7", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (parent_recovery_attempt_id) REFERENCES artifact_recovery_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_parent_recovery_attempt_i_130d", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_project_id_projects", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (requester_actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_requester_actor_profile_i_77f5", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (requester_identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_requester_identity_link_i_3619", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (retry_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_retry_verification_job_id_b330", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (source_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_source_verification_job_i_5eac", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_submission_id_submissions", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_task_id_workstream_tasks", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "FOREIGN KEY (terminal_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_recovery_attempts_terminal_audit_event_id_a_47ab", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_recovery_attempts", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "UNIQUE (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", + "kind": "u", + "name": "uq_artifact_recovery_idempotency", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "UNIQUE (retry_verification_job_id)", + "kind": "u", + "name": "uq_artifact_recovery_retry_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "UNIQUE (source_verification_job_id)", + "kind": "u", + "name": "uq_artifact_recovery_source_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CHECK (availability_state::text = ANY (ARRAY['unknown', 'available', 'unavailable']))", + "kind": "c", + "name": "ck_artifact_replicas_availability_state", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_replicas_fingerprint_shape", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (integrity_state::text = ANY (ARRAY['unknown', 'valid', 'invalid']))", + "kind": "c", + "name": "ck_artifact_replicas_integrity_state", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (verification_state::text = ANY (ARRAY['pending', 'verified', 'missing', 'integrity_mismatch']))", + "kind": "c", + "name": "ck_artifact_replicas_verification_state", + "table_name": "artifact_replicas" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_replicas_content_id_artifact_contents", + "table_name": "artifact_replicas" + }, + { + "definition": "FOREIGN KEY (storage_namespace_id) REFERENCES artifact_storage_namespaces(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_replicas_storage_namespace_id_artifact_stor_d6cc", + "table_name": "artifact_replicas" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_replicas", + "table_name": "artifact_replicas" + }, + { + "definition": "UNIQUE (storage_namespace_id, provider_object_ref)", + "kind": "u", + "name": "uq_artifact_replica_provider_object", + "table_name": "artifact_replicas" + }, + { + "definition": "UNIQUE (id, content_id)", + "kind": "u", + "name": "uq_artifact_replicas_id_content", + "table_name": "artifact_replicas" + }, + { + "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_storage_namespaces_fingerprint_shape", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CHECK (id::text = 'primary'::text)", + "kind": "c", + "name": "ck_artifact_storage_namespaces_singleton_id", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_storage_namespaces", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "UNIQUE (namespace_fingerprint)", + "kind": "u", + "name": "uq_artifact_storage_namespace_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "UNIQUE (id, namespace_fingerprint)", + "kind": "u", + "name": "uq_artifact_storage_namespace_id_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CHECK (attempt_count >= 0 AND maximum_attempts > 0)", + "kind": "c", + "name": "ck_artifact_verification_jobs_attempts", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", + "kind": "c", + "name": "ck_artifact_verification_jobs_fence_pair", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK ((status::text = 'running'::text) = (executor_id IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_verification_jobs_running_fence", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'running', 'verified', 'missing', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", + "kind": "c", + "name": "ck_artifact_verification_jobs_status", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK (status::text <> 'provider_unavailable'::text OR next_run_at IS NOT NULL AND terminal_at IS NULL AND attempt_count < maximum_attempts OR next_run_at IS NULL AND terminal_at IS NOT NULL AND attempt_count >= maximum_attempts)", + "kind": "c", + "name": "ck_artifact_verification_jobs_unavailable_retryability", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", + "kind": "c", + "name": "ck_artifact_verification_jobs_versions", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "FOREIGN KEY (originating_put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_jobs_originating_put_attempt_i_3260", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_jobs_replica_id_artifact_replicas", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "FOREIGN KEY (parent_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_parent", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_verification_jobs", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "UNIQUE (parent_verification_job_id)", + "kind": "u", + "name": "uq_artifact_verification_parent", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CHECK ((outcome::text = ANY (ARRAY['verified', 'integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", + "kind": "c", + "name": "ck_artifact_verification_receipts_observed_facts", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_artifact_verification_receipts_observed_sha256", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", + "kind": "c", + "name": "ck_artifact_verification_receipts_observed_size", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (outcome::text = ANY (ARRAY['verified', 'missing', 'integrity_mismatch', 'conflict']))", + "kind": "c", + "name": "ck_artifact_verification_receipts_outcome", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "FOREIGN KEY (verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_artifact_verification_receipts_verification_job_id_a_dabf", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_artifact_verification_receipts", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "UNIQUE (verification_job_id, execution_generation)", + "kind": "u", + "name": "uq_artifact_verification_fence", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND (entity_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'authorization_decision', 'authority_invalidation'])) AND entity_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND ((actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile'])) AND actor_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR actor_ref_kind::text = 'system_principal'::text AND actor_id::text = 'workstream:system:bootstrap'::text) AND (target_actor_ref IS NULL OR target_actor_ref_kind::text = 'actor_profile'::text AND target_actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (matched_grant_id IS NULL OR matched_grant_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (project_id IS NULL OR project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (resource_type IS NULL OR (resource_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'project', 'qualification_snapshot', 'project_role_grant', 'task', 'submission', 'review', 'contribution', 'compensation_award', 'compensation_delivery', 'operations', 'audit_event', 'project_create_operation', 'project_submission_artifact_policy_mutation', 'project_guide_compilation_attempt', 'project_guide_compilation_request']))) AND (resource_id IS NULL OR resource_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (target_ref_kind IS NULL OR (target_ref_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'project'])) AND target_ref_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR target_ref_kind::text = 'permission_registry'::text AND (target_ref_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND (invalidation_target_kind IS NULL OR (invalidation_target_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant'])) AND invalidation_target_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR invalidation_target_kind::text = 'permission_registry'::text AND (invalidation_target_ref::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND ((entity_type::text <> ALL (ARRAY['authorization_decision', 'authority_invalidation'])) OR entity_id::text = id::text) AND (resource_type::text <> 'project'::text OR resource_id IS NULL OR project_id IS NOT NULL AND resource_id::text = project_id::text))", + "kind": "c", + "name": "ck_audit_events_authority_privacy_bounds", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR reason IS NOT NULL AND (event_type::text = 'ActorProfileProvisioned'::text AND reason = 'automatic_first_access'::text OR event_type::text = 'ServiceActorProvisioned'::text AND reason = 'manual_service_provisioning'::text OR event_type::text = 'ActorIdentityLinked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkRevoked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkReactivated'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorProfileSuspended'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'ActorProfileReactivated'::text AND reason = 'administrative_correction'::text OR event_type::text = 'ActorProfileDeactivated'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'InitialAccessAdministratorBootstrapped'::text AND reason = 'initial_access_bootstrap'::text OR event_type::text = 'AdminRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'AdminRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'AdminRoleGrantIssueDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'LastAccessAdministratorOperationDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'ProjectRoleQualificationSnapshotCaptured'::text AND reason = 'qualification_evidence_captured'::text OR event_type::text = 'ProjectRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'ProjectRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'SensitiveAuthorizationDenied'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'AuthorityInvalidationRequested'::text AND reason = 'authority_state_changed'::text) AND (permission_id IS NULL OR (permission_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.execute', 'project.guide_compilation.request']))) AND (denial_code IS NULL OR (denial_code::text = ANY (ARRAY['required_scope_missing', 'unsupported_subject_kind', 'service_actor_not_provisioned', 'identity_link_revoked', 'actor_suspended', 'actor_deactivated', 'permission_not_granted', 'scope_not_authorized', 'self_grant_forbidden', 'self_role_revoke_forbidden', 'resource_guard_denied', 'actor_not_found', 'grant_not_found', 'resource_not_found', 'actor_already_suspended', 'actor_not_suspended', 'actor_deactivated_terminal', 'last_access_administrator', 'admin_role_grant_exists', 'project_role_grant_exists', 'identity_link_conflict', 'project_role_grant_already_revoked', 'project_role_grant_replay_state_changed', 'identity_link_already_revoked', 'identity_link_not_revoked', 'resource_project_mismatch', 'idempotency_mismatch', 'invalid_role_scope', 'invalid_project_role', 'qualification_snapshot_invalid']))))", + "kind": "c", + "name": "ck_audit_events_authority_registries", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text = ANY (ARRAY['ActorProfileProvisioned', 'ServiceActorProvisioned', 'ActorIdentityLinked', 'ActorIdentityLinkRevoked', 'ActorIdentityLinkReactivated', 'ActorProfileSuspended', 'ActorProfileReactivated', 'ActorProfileDeactivated', 'InitialAccessAdministratorBootstrapped', 'AdminRoleGrantIssued', 'AdminRoleGrantRevoked', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied', 'ProjectRoleQualificationSnapshotCaptured', 'ProjectRoleGrantIssued', 'ProjectRoleGrantReplaced', 'ProjectRoleGrantRevoked', 'SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested'])))", + "kind": "c", + "name": "ck_audit_events_authority_tokens", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND action_id IS NULL OR event_domain::text = 'authority'::text AND (action_id IS NULL OR (event_type::text = ANY (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied'])) AND permission_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)) AND (permission_id IS NULL OR (permission_id::text <> ALL (ARRAY['operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'project.guide_compilation.request', 'project.guide_compilation.execute'])) OR action_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)))", + "kind": "c", + "name": "ck_audit_events_authorization_action_evidence", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND event_version IS NULL AND occurred_at IS NULL AND actor_ref_kind IS NULL AND request_id IS NULL AND correlation_id IS NULL AND target_actor_ref_kind IS NULL AND target_actor_ref IS NULL AND matched_grant_id IS NULL AND permission_id IS NULL AND project_id IS NULL AND resource_type IS NULL AND resource_id IS NULL AND target_ref_kind IS NULL AND target_ref_id IS NULL AND denial_code IS NULL AND idempotency_reference IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND invalidation_target_ref IS NULL AND before_facts IS NULL AND after_facts IS NULL AND external_subject IS NOT NULL AND external_issuer IS NOT NULL OR event_domain::text = 'authority'::text AND event_version = 1 AND occurred_at IS NOT NULL AND (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal'])) AND request_id IS NOT NULL AND correlation_id IS NOT NULL AND from_status IS NULL AND to_status IS NULL AND reason IS NOT NULL AND external_subject IS NULL AND external_issuer IS NULL AND actor_roles::jsonb = '[]'::jsonb AND claim_snapshot::jsonb = '{}'::jsonb AND auth_source::text = 'local_authority'::text AND is_dev_auth = false AND event_payload::jsonb = '{}'::jsonb)", + "kind": "c", + "name": "ck_audit_events_domain_shape", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR (before_facts IS NULL OR octet_length(before_facts::text) <= 4096) AND (after_facts IS NULL OR octet_length(after_facts::text) <= 4096) AND COALESCE(authority_event_facts_are_safe(event_type::text, before_facts, after_facts, project_id::text), false))", + "kind": "c", + "name": "ck_audit_events_fact_bounds", + "table_name": "audit_events" + }, + { + "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text <> ALL (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) OR (event_type::text = ANY (ARRAY['AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) AND denial_code IS NOT NULL OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND permission_id IS NOT NULL AND denial_code IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL OR event_type::text = 'SensitiveAuthorizationDenied'::text AND permission_id IS NOT NULL AND denial_code IS NOT NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND idempotency_reference IS NULL OR event_type::text = 'AuthorityInvalidationRequested'::text AND invalidation_cause_event_id IS NOT NULL AND invalidation_target_kind IS NOT NULL AND denial_code IS NULL)", + "kind": "c", + "name": "ck_audit_events_foundation_shapes", + "table_name": "audit_events" + }, + { + "definition": "CHECK ((target_actor_ref_kind IS NULL) = (target_actor_ref IS NULL) AND (resource_type IS NOT NULL OR resource_id IS NULL) AND (target_ref_kind IS NULL) = (target_ref_id IS NULL) AND (invalidation_target_kind IS NULL) = (invalidation_target_ref IS NULL) AND (invalidation_cause_event_id IS NULL OR invalidation_cause_event_id::text <> id::text))", + "kind": "c", + "name": "ck_audit_events_reference_pairs", + "table_name": "audit_events" + }, + { + "definition": "FOREIGN KEY (idempotency_reference, actor_ref_kind, actor_id) REFERENCES authority_idempotency_records(id, actor_ref_kind, actor_ref) NOT VALID", + "kind": "f", + "name": "fk_audit_events_authority_idempotency", + "table_name": "audit_events" + }, + { + "definition": "FOREIGN KEY (invalidation_cause_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_audit_events_invalidation_cause", + "table_name": "audit_events" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_audit_events", + "table_name": "audit_events" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "authority_control_bootstrap_invariant", + "table_name": "authority_control" + }, + { + "definition": "CHECK (bootstrap_completed = false AND bootstrap_grant_id IS NULL AND version = 0 OR bootstrap_completed = true AND bootstrap_grant_id IS NOT NULL AND version = 1)", + "kind": "c", + "name": "ck_authority_control_bootstrap_state", + "table_name": "authority_control" + }, + { + "definition": "CHECK (id = 1)", + "kind": "c", + "name": "ck_authority_control_singleton", + "table_name": "authority_control" + }, + { + "definition": "FOREIGN KEY (bootstrap_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_authority_control_bootstrap_grant_id_admin_role_grants", + "table_name": "authority_control" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_authority_control", + "table_name": "authority_control" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "authority_idempotency_pending_guard", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal']))", + "kind": "c", + "name": "ck_authority_idempotency_records_actor_kind", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (actor_ref_kind::text = 'system_principal'::text AND actor_ref::text = 'workstream:system:bootstrap'::text OR actor_ref_kind::text <> 'system_principal'::text AND actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_authority_idempotency_records_actor_reference", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'admin_role_grant.revoke', 'project_role_grant.issue', 'project_role_grant.revoke', 'actor_profile.suspend', 'actor_profile.reactivate', 'actor_profile.deactivate', 'actor_identity_link.revoke', 'actor_identity_link.reactivate']))", + "kind": "c", + "name": "ck_authority_idempotency_records_operation", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_authority_idempotency_records_request_digest", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (response_http_status IS NULL OR (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 201 OR (operation::text <> ALL (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 200)", + "kind": "c", + "name": "ck_authority_idempotency_records_response_status", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (operation::text = 'service_actor.create'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'admin_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'admin_role_grant'::text) OR operation::text ~~ 'project_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'project_role_grant'::text) OR operation::text ~~ 'actor_profile.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'actor_identity_link.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_identity_link'::text))", + "kind": "c", + "name": "ck_authority_idempotency_records_response_type", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (response_resource_version IS NULL OR response_resource_version > 0)", + "kind": "c", + "name": "ck_authority_idempotency_records_response_version", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_resource_type IS NULL AND response_resource_id IS NULL AND response_resource_version IS NULL AND response_http_status IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_resource_type IS NOT NULL AND response_resource_id IS NOT NULL AND response_http_status IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_authority_idempotency_records_state_shape", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_authority_idempotency_records_status", + "table_name": "authority_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_authority_idempotency_records", + "table_name": "authority_idempotency_records" + }, + { + "definition": "UNIQUE (id, actor_ref_kind, actor_ref)", + "kind": "u", + "name": "uq_authority_idempotency_records_actor_reference", + "table_name": "authority_idempotency_records" + }, + { + "definition": "UNIQUE (actor_ref_kind, actor_ref, operation, idempotency_key)", + "kind": "u", + "name": "uq_authority_idempotency_records_replay_namespace", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", + "kind": "c", + "name": "ck_checker_policies_approval_provenance", + "table_name": "checker_policies" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'superseded'::text OR superseded_at IS NOT NULL AND (superseded_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND superseded_by_actor IS NOT NULL AND (supersession_kind::text = ANY (ARRAY['correction_requested', 'upstream_policy_changed'])) AND supersession_reason IS NOT NULL AND length(btrim(supersession_reason)) > 0)", + "kind": "c", + "name": "ck_checker_policies_correction_provenance", + "table_name": "checker_policies" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['compiled', 'approved', 'superseded']))", + "kind": "c", + "name": "ck_checker_policies_lifecycle_status", + "table_name": "checker_policies" + }, + { + "definition": "CHECK (policy_hash IS NULL OR policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_checker_policies_policy_hash_shape", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_checker_policies_effective_policy_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_checker_policies_guide_id_project_guides", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (pre_submit_checker_policy_id, pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", + "kind": "f", + "name": "fk_checker_policies_pre_submit_checker_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_checker_policies_project_guide", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_checker_policies_project_id_projects", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_checker_policies_source_snapshot_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES checker_policies(id)", + "kind": "f", + "name": "fk_checker_policies_supersedes_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_checker_policies", + "table_name": "checker_policies" + }, + { + "definition": "UNIQUE (id, guide_version, policy_hash)", + "kind": "u", + "name": "uq_checker_policies_id_version_hash", + "table_name": "checker_policies" + }, + { + "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_checker_results_checker_run_id_checker_runs", + "table_name": "checker_results" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_checker_results_submission_id_submissions", + "table_name": "checker_results" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_checker_results_task_id_workstream_tasks", + "table_name": "checker_results" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_checker_results", + "table_name": "checker_results" + }, + { + "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", + "kind": "c", + "name": "ck_checker_runs_post_submit_policy_lock_complete", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (audit_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_checker_runs_audit_event_id_audit_events", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", + "kind": "f", + "name": "fk_checker_runs_locked_post_submit_policy_hash", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_checker_runs_submission_id_submissions", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (submission_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES submissions(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "f", + "name": "fk_checker_runs_submission_locked_post_submit_policy_hash", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_checker_runs_submission_version", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (supersedes_checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_checker_runs_supersedes_checker_run_id_checker_runs", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_checker_runs_task_id_workstream_tasks", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", + "kind": "f", + "name": "fk_checker_runs_task_locked_guide", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", + "kind": "f", + "name": "fk_checker_runs_task_locked_payment_policy", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "kind": "f", + "name": "fk_checker_runs_task_locked_review_policy", + "table_name": "checker_runs" + }, + { + "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "kind": "f", + "name": "fk_checker_runs_task_locked_revision_policy", + "table_name": "checker_runs" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_checker_runs", + "table_name": "checker_runs" + }, + { + "definition": "UNIQUE (submission_id, attempt_number)", + "kind": "u", + "name": "uq_checker_runs_submission_attempt", + "table_name": "checker_runs" + }, + { + "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", + "kind": "c", + "name": "ck_contribution_award_definitions_contribution_type", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", + "kind": "c", + "name": "ck_contribution_award_definitions_instrument_type", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (instrument_type::text <> 'project_points'::text OR scale(quantity) = 0)", + "kind": "c", + "name": "ck_contribution_award_definitions_project_points_whole", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (quantity > 0::numeric AND quantity < '100000000000000000000'::numeric AND scale(quantity) >= 0 AND scale(quantity) <= 18)", + "kind": "c", + "name": "ck_contribution_award_definitions_quantity_exact_bounds", + "table_name": "contribution_award_definitions" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_award_definitions_graph_guard", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (adapter_binding_id, project_id, instrument_type) REFERENCES project_compensation_adapter_bindings(id, project_id, instrument_type)", + "kind": "f", + "name": "fk_contribution_award_definition_binding", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_award_definition_project", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (contribution_rule_id, contribution_policy_version_id, project_id, contribution_type) REFERENCES contribution_rules(id, contribution_policy_version_id, project_id, contribution_type)", + "kind": "f", + "name": "fk_contribution_award_definition_rule", + "table_name": "contribution_award_definitions" + }, + { + "definition": "FOREIGN KEY (project_id, instrument_type, unit_code) REFERENCES project_compensation_units(project_id, instrument_type, unit_code)", + "kind": "f", + "name": "fk_contribution_award_definition_unit", + "table_name": "contribution_award_definitions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_award_definitions", + "table_name": "contribution_award_definitions" + }, + { + "definition": "UNIQUE (contribution_rule_id, instrument_type)", + "kind": "u", + "name": "uq_contribution_award_definition_instrument", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CHECK (status::text = 'draft'::text AND current_published_version_id IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'active'::text AND current_published_version_id IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND current_published_version_id IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", + "kind": "c", + "name": "ck_contribution_policies_lifecycle_shape", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (char_length(btrim(name::text)) >= 1 AND char_length(btrim(name::text)) <= 200)", + "kind": "c", + "name": "ck_contribution_policies_name", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", + "kind": "c", + "name": "ck_contribution_policies_retirement_timestamp", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['draft', 'active', 'retired']))", + "kind": "c", + "name": "ck_contribution_policies_status", + "table_name": "contribution_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_policies_graph_guard", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_created_by", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (current_published_version_id, id, project_id) REFERENCES contribution_policy_versions(id, contribution_policy_id, project_id) DEFERRABLE INITIALLY DEFERRED", + "kind": "f", + "name": "fk_contribution_policy_current_version", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_policy_project", + "table_name": "contribution_policies" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_retired_by", + "table_name": "contribution_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_policies", + "table_name": "contribution_policies" + }, + { + "definition": "UNIQUE (id, project_id)", + "kind": "u", + "name": "uq_contribution_policy_ownership", + "table_name": "contribution_policies" + }, + { + "definition": "CHECK (status::text = 'draft'::text AND published_by IS NULL AND published_at IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'published'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", + "kind": "c", + "name": "ck_contribution_policy_versions_lifecycle_shape", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK ((published_at IS NULL OR published_at >= created_at) AND (retired_at IS NULL OR retired_at >= published_at))", + "kind": "c", + "name": "ck_contribution_policy_versions_lifecycle_timestamps", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['draft', 'published', 'retired']))", + "kind": "c", + "name": "ck_contribution_policy_versions_status", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK (version_number > 0)", + "kind": "c", + "name": "ck_contribution_policy_versions_version_number_positive", + "table_name": "contribution_policy_versions" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_policy_versions_graph_guard", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_version_created_by", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (contribution_policy_id, project_id) REFERENCES contribution_policies(id, project_id)", + "kind": "f", + "name": "fk_contribution_policy_version_policy", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_policy_version_project", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (published_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_version_published_by", + "table_name": "contribution_policy_versions" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_contribution_policy_version_retired_by", + "table_name": "contribution_policy_versions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_policy_versions", + "table_name": "contribution_policy_versions" + }, + { + "definition": "UNIQUE (contribution_policy_id, version_number)", + "kind": "u", + "name": "uq_contribution_policy_version_number", + "table_name": "contribution_policy_versions" + }, + { + "definition": "UNIQUE (id, contribution_policy_id, project_id)", + "kind": "u", + "name": "uq_contribution_policy_version_ownership", + "table_name": "contribution_policy_versions" + }, + { + "definition": "UNIQUE (id, project_id)", + "kind": "u", + "name": "uq_contribution_policy_version_project", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CHECK (compensation_mode::text = ANY (ARRAY['unpaid', 'compensated']))", + "kind": "c", + "name": "ck_contribution_rules_compensation_mode", + "table_name": "contribution_rules" + }, + { + "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", + "kind": "c", + "name": "ck_contribution_rules_contribution_type", + "table_name": "contribution_rules" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "contribution_rules_graph_guard", + "table_name": "contribution_rules" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_contribution_rule_project", + "table_name": "contribution_rules" + }, + { + "definition": "FOREIGN KEY (contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", + "kind": "f", + "name": "fk_contribution_rule_version", + "table_name": "contribution_rules" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_contribution_rules", + "table_name": "contribution_rules" + }, + { + "definition": "UNIQUE (id, contribution_policy_version_id, project_id, contribution_type)", + "kind": "u", + "name": "uq_contribution_rule_ownership", + "table_name": "contribution_rules" + }, + { + "definition": "UNIQUE (contribution_policy_version_id, contribution_type)", + "kind": "u", + "name": "uq_contribution_rule_type", + "table_name": "contribution_rules" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['approved', 'superseded']))", + "kind": "c", + "name": "ck_effective_project_submission_artifact_policies_ck_ef_7be7", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_effective_project_submission_artifact_policies_ck_ef_bd4e", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "effective_submission_policy_custody", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_effective_policy_creation_actor", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_effective_policy_creation_decision", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_effective_policy_creation_grant", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_effective_policy_creation_link", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_effective_policy_creation_project", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_effective_project_submission_artifact_policies_project_guide", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_effective_psap_guide", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_effective_psap_project", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_effective_psap_source_snapshot_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (submission_artifact_policy_id, submission_artifact_policy_hash) REFERENCES submission_artifact_policies(id, policy_hash)", + "kind": "f", + "name": "fk_effective_psap_submission_policy_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", + "kind": "f", + "name": "fk_effective_psap_supersedes", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_effective_project_submission_artifact_policies", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "UNIQUE (id, effective_policy_hash)", + "kind": "u", + "name": "uq_effective_project_submission_artifact_policies_id_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_evidence_items_submission_id_submissions", + "table_name": "evidence_items" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_evidence_items", + "table_name": "evidence_items" + }, + { + "definition": "CHECK (operation_generation > 0)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_6506", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL AND setup_run_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_9402", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create']))", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_action", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_b397", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_e32d", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_status", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_actor_profile_id__2ee3", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_identity_link_id__3ddf", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_project_id_projects", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_guide_mutation_idempotency_records_setup_run_id_proj_7dc3", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "guide_mutation_reservation_custody", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_mutation_idempotency_records", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_guide_mutation_operation_identity", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", + "kind": "u", + "name": "uq_guide_mutation_replay_namespace", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_gen_b5fe", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CHECK (logical_role::text = 'guide_source_original'::text)", + "kind": "c", + "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_role", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (source_item_id, source_snapshot_id) REFERENCES guide_source_snapshot_items(id, source_snapshot_id)", + "kind": "f", + "name": "fk_guide_bindings_exact_item", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (project_setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", + "kind": "f", + "name": "fk_guide_bindings_exact_setup_generation", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, project_id, guide_id) REFERENCES guide_source_snapshots(id, project_id, guide_id)", + "kind": "f", + "name": "fk_guide_bindings_exact_snapshot", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (verified_replica_id, content_id) REFERENCES artifact_replicas(id, content_id)", + "kind": "f", + "name": "fk_guide_bindings_verified_replica_content", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_guide_source_artifact_bindings_content_id_artifact_contents", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES guide_source_artifact_bindings(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_guide_source_artifact_bindings_supersedes_binding_id_bfa2", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_artifact_bindings", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (id, content_id, verified_replica_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_exact_read", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (id, content_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_extraction_attempt_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (id, content_id, source_item_id, project_setup_run_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_extraction_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (source_item_id, setup_generation)", + "kind": "u", + "name": "uq_guide_bindings_item_generation", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "UNIQUE (supersedes_binding_id)", + "kind": "u", + "name": "uq_guide_bindings_supersedes", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CHECK (code::text = ANY (ARRAY['missing', 'changed', 'truncated', 'unavailable', 'stale', 'conflict']))", + "kind": "c", + "name": "ck_guide_source_artifact_incidents_ck_guide_incidents_code", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_621b", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_92fa", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", + "kind": "f", + "name": "fk_guide_incidents_exact_binding", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_artifact_incidents", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_2958", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_64cb", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_source_artifact_ingests_actor_profile_id_actor_22c1", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "FOREIGN KEY (source_item_id) REFERENCES guide_source_snapshot_items(id)", + "kind": "f", + "name": "fk_guide_source_artifact_ingests_source_item_id_guide_s_7ba9", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_artifact_ingests", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "UNIQUE (source_item_id)", + "kind": "u", + "name": "uq_guide_source_artifact_ingests_source_item_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CHECK (output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_1b91", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (octet_length(canonical_output) <= 4194304)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_54b5", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (source_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_988f", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (status::text = 'extracted'::text)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_a759", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (source_byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_fb79", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_guide_source_extracted_contents_content_id_artifact_contents", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_extracted_contents", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "UNIQUE (id, content_id)", + "kind": "u", + "name": "uq_guide_extracted_contents_exact_usage", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "UNIQUE (content_id, detected_format, extractor_name, extractor_version, policy_version)", + "kind": "u", + "name": "uq_guide_extracted_contents_identity", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CHECK (attempt_number > 0)", + "kind": "c", + "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_3927", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CHECK ((status::text = 'extracted'::text) = (error_code IS NULL))", + "kind": "c", + "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_940d", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['extracted', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded', 'parser_failure', 'cancelled', 'artifact_incident']))", + "kind": "c", + "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_ff6d", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_attempts_exact_binding", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_attempts_exact_classification", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "UNIQUE (binding_id, policy_version, attempt_number)", + "kind": "u", + "name": "uq_guide_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "UNIQUE (id, binding_id, content_id, setup_generation, status)", + "kind": "u", + "name": "uq_guide_extraction_attempts_exact_usage", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CHECK (claimed_slots >= 1 AND claimed_slots <= 2)", + "kind": "c", + "name": "ck_guide_source_extraction_retry_budgets_ck_guide_extra_99c3", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_retry_budgets_exact_binding", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_retry_budgets_exact_classification", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "PRIMARY KEY (binding_id)", + "kind": "p", + "name": "pk_guide_source_extraction_retry_budgets", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "CHECK (attempt_status::text = 'extracted'::text)", + "kind": "c", + "name": "ck_guide_source_extraction_usages_ck_guide_extraction_u_a2fd", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "FOREIGN KEY (extraction_attempt_id, binding_id, content_id, setup_generation, attempt_status) REFERENCES guide_source_extraction_attempts(id, binding_id, content_id, setup_generation, status)", + "kind": "f", + "name": "fk_guide_extraction_usages_exact_attempt", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, source_item_id, project_setup_run_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, source_item_id, project_setup_run_id, setup_generation)", + "kind": "f", + "name": "fk_guide_extraction_usages_exact_binding", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "FOREIGN KEY (extracted_content_id, content_id) REFERENCES guide_source_extracted_contents(id, content_id)", + "kind": "f", + "name": "fk_guide_extraction_usages_exact_content", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "UNIQUE (binding_id, extracted_content_id)", + "kind": "u", + "name": "uq_guide_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "UNIQUE (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", + "kind": "u", + "name": "uq_guide_extraction_usages_exact_provenance", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['classified', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded']))", + "kind": "c", + "name": "ck_guide_source_format_classifications_ck_guide_classif_8737", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_source_format_classifications_ck_guide_source__0dd2", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CHECK (byte_count >= 0)", + "kind": "c", + "name": "ck_guide_source_format_classifications_ck_guide_source__7235", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", + "kind": "f", + "name": "fk_guide_classifications_exact_binding", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_format_classifications", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "UNIQUE (binding_id)", + "kind": "u", + "name": "uq_guide_classifications_binding", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "UNIQUE (id, binding_id, content_id, setup_generation)", + "kind": "u", + "name": "uq_guide_classifications_extraction_lineage", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_gssi_source_snapshot", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "guide_source_snapshot_items_custody", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_snapshot_items", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "UNIQUE (id, source_snapshot_id)", + "kind": "u", + "name": "uq_guide_source_snapshot_items_exact_lineage", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "UNIQUE (source_snapshot_id, item_order)", + "kind": "u", + "name": "uq_guide_source_snapshot_items_snapshot_order", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CHECK (creation_generation IS NULL AND created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR creation_generation > 0 AND created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (creation_scope_type::text = 'system'::text AND creation_scope_project_id IS NULL OR creation_scope_type::text = 'project'::text AND creation_scope_project_id::text = project_id::text) AND creation_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_guide_source_snapshots_source_snapshot_creation_auth_2f3e", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_actor", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_admin_grant", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_decision", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_created_identity_link", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_guide_id_project_guides", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_guide_source_snapshots_project_guide", + "table_name": "guide_source_snapshots" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_source_snapshots_project_id_projects", + "table_name": "guide_source_snapshots" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_source_snapshots", + "table_name": "guide_source_snapshots" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "source_snapshot_product_custody", + "table_name": "guide_source_snapshots" + }, + { + "definition": "UNIQUE (id, project_id, guide_id)", + "kind": "u", + "name": "uq_guide_source_snapshots_exact_lineage", + "table_name": "guide_source_snapshots" + }, + { + "definition": "UNIQUE (id, bundle_hash)", + "kind": "u", + "name": "uq_guide_source_snapshots_id_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "UNIQUE (project_id, guide_version, bundle_hash)", + "kind": "u", + "name": "uq_guide_source_snapshots_project_version_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_1033", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_177a", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run', 'project.guide_sufficiency.warnings.acknowledge']))", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_6651", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_87dd", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND (action_id::text = 'project.guide_sufficiency.run'::text AND (setup_run_id IS NOT NULL OR report_id IS NOT NULL) OR action_id::text <> 'project.guide_sufficiency.run'::text AND report_id IS NOT NULL))", + "kind": "c", + "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_e7f6", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_actor_16d8", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_guide_1d2b", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_ident_2378", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_proje_7f82", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_repor_48c3", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_setup_7059", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_guide_sufficiency_mutation_idempotency_records_sourc_9985", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_sufficiency_mutation_idempotency_records", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_sufficiency_mutation_operation_identity", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, idempotency_key)", + "kind": "u", + "name": "uq_sufficiency_mutation_replay_namespace", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_2983", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CHECK (canonical_output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_8148", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CHECK (item_order >= 0)", + "kind": "c", + "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_eb12", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id) ON DELETE CASCADE", + "kind": "f", + "name": "fk_guide_sufficiency_report_source_usages_report_id_gui_1d57", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "FOREIGN KEY (extraction_usage_id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation) REFERENCES guide_source_extraction_usages(id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", + "kind": "f", + "name": "fk_sufficiency_report_source_usage_exact_extraction", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_sufficiency_report_source_usages", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "UNIQUE (report_id, extraction_usage_id)", + "kind": "u", + "name": "uq_sufficiency_report_extraction_usage", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "UNIQUE (report_id, item_order)", + "kind": "u", + "name": "uq_sufficiency_report_item_order", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CHECK (warnings_acknowledged_by_actor_profile_id IS NULL AND warnings_acknowledged_via_identity_link_id IS NULL AND warnings_acknowledged_by_admin_role_grant_id IS NULL AND warning_acknowledgement_scope_type IS NULL AND warning_acknowledgement_scope_project_id IS NULL AND warning_acknowledgement_action_id IS NULL AND warning_acknowledgement_decision_event_id IS NULL OR warnings_acknowledged_by_actor_profile_id IS NOT NULL AND warnings_acknowledged_via_identity_link_id IS NOT NULL AND warnings_acknowledged_by_admin_role_grant_id IS NOT NULL AND (warning_acknowledgement_scope_type::text = ANY (ARRAY['system', 'project'])) AND warning_acknowledgement_scope_project_id IS NOT NULL AND warning_acknowledgement_action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND warning_acknowledgement_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_guide_sufficiency_ack_authority_shape", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run'])) AND authorization_decision_event_id IS NOT NULL AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.guide_sufficiency.run'::text AND project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL))", + "kind": "c", + "name": "ck_guide_sufficiency_creation_authority_shape", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (agent_material_byte_count IS NULL OR agent_material_byte_count >= 0)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_31bb", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (setup_generation IS NULL OR setup_generation > 0)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_3e43", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (project_setup_run_id IS NULL AND setup_generation IS NULL AND agent_material_sha256 IS NULL AND agent_material_byte_count IS NULL OR project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_4640", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['passed', 'blocked', 'passed_with_warnings']))", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_841c", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (agent_material_sha256 IS NULL OR agent_material_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_b3ec", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_guide_id_project_guides", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_project_guide", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_project_id_projects", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_guide_sufficiency_reports_source_snapshot_hash", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warnings_acknowledged_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_suff_ack_actor", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warning_acknowledgement_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_suff_ack_decision", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warnings_acknowledged_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_suff_ack_grant", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warnings_acknowledged_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_suff_ack_link", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (warning_acknowledgement_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_suff_ack_project", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_suff_create_actor", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_suff_create_decision", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_suff_create_grant", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_suff_create_link", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_suff_create_project", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "FOREIGN KEY (project_setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_sufficiency_reports_setup_run", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_guide_sufficiency_reports", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CHECK (code::text ~ '^[A-Z]{3}$'::text)", + "kind": "c", + "name": "ck_iso_4217_currency_codes_code", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "PRIMARY KEY (code)", + "kind": "p", + "name": "pk_iso_4217_currency_codes", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "PRIMARY KEY (actor_id)", + "kind": "p", + "name": "pk_legacy_actor_identities", + "table_name": "legacy_actor_identities" + }, + { + "definition": "UNIQUE (external_issuer, external_subject)", + "kind": "u", + "name": "uq_legacy_actor_identities_external_identity", + "table_name": "legacy_actor_identities" + }, + { + "definition": "CHECK (profile_type::text = ANY (ARRAY['worker', 'reviewer', 'admin', 'project_manager', 'project_owner']))", + "kind": "c", + "name": "ck_legacy_workflow_eligibility_profile_type", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['observed', 'active', 'disabled']))", + "kind": "c", + "name": "ck_legacy_workflow_eligibility_status", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "FOREIGN KEY (actor_id) REFERENCES legacy_actor_identities(actor_id)", + "kind": "f", + "name": "fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_legacy_workflow_eligibility", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "UNIQUE (actor_id, profile_type, scope_type, scope_id)", + "kind": "u", + "name": "uq_legacy_workflow_eligibility_actor_type_scope", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CHECK (aggregate_type::text ~ '^[a-z][a-z0-9_]{0,63}$'::text)", + "kind": "c", + "name": "ck_outbox_events_aggregate_type", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (claim_owner IS NULL OR claim_owner::text ~ '^[A-Za-z0-9._:-]{1,120}$'::text)", + "kind": "c", + "name": "ck_outbox_events_claim_owner", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (correlation_id::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", + "kind": "c", + "name": "ck_outbox_events_correlation_id", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (attempt_count >= 0 AND claim_generation >= 0 AND attempt_count = claim_generation)", + "kind": "c", + "name": "ck_outbox_events_delivery_counters", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (delivery_state::text = ANY (ARRAY['pending', 'claimed', 'retryable', 'acknowledged', 'dead_letter', 'cancelled']))", + "kind": "c", + "name": "ck_outbox_events_delivery_state", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (delivery_state::text = 'pending'::text AND attempt_count = 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NULL AND last_error_code IS NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'claimed'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NOT NULL AND claimed_at IS NOT NULL AND claim_expires_at IS NOT NULL AND last_attempt_at = claimed_at AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'retryable'::text AND attempt_count > 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'acknowledged'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'dead_letter'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'cancelled'::text AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND finalized_at IS NOT NULL AND (attempt_count = 0 AND last_attempt_at IS NULL AND last_error_code IS NULL OR attempt_count > 0 AND last_attempt_at IS NOT NULL))", + "kind": "c", + "name": "ck_outbox_events_delivery_state_shape", + "table_name": "outbox_events" + }, + { + "definition": "CHECK ((next_attempt_at IS NULL OR next_attempt_at >= occurred_at) AND (claimed_at IS NULL OR claimed_at >= occurred_at) AND (last_attempt_at IS NULL OR last_attempt_at >= occurred_at) AND (claim_expires_at IS NULL OR claim_expires_at > claimed_at) AND (finalized_at IS NULL OR finalized_at >= occurred_at) AND (finalized_at IS NULL OR last_attempt_at IS NULL OR finalized_at >= last_attempt_at) AND (archived_at IS NULL OR archived_at >= finalized_at))", + "kind": "c", + "name": "ck_outbox_events_delivery_timestamps", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (last_error_code IS NULL OR last_error_code::text ~ '^[A-Z][A-Z0-9_]{0,79}$'::text)", + "kind": "c", + "name": "ck_outbox_events_error_code", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (event_type::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'::text)", + "kind": "c", + "name": "ck_outbox_events_event_type", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (event_version >= 1 AND event_version <= 32767)", + "kind": "c", + "name": "ck_outbox_events_event_version", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (idempotency_key::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", + "kind": "c", + "name": "ck_outbox_events_idempotency_key", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (payload_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_outbox_events_payload_digest", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (jsonb_typeof(payload) = 'object'::text AND octet_length(payload::text) <= 262144)", + "kind": "c", + "name": "ck_outbox_events_payload_shape", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (producer::text = 'workstream'::text)", + "kind": "c", + "name": "ck_outbox_events_producer", + "table_name": "outbox_events" + }, + { + "definition": "CHECK (project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", + "kind": "c", + "name": "ck_outbox_events_project_id", + "table_name": "outbox_events" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_outbox_events_project_id_projects", + "table_name": "outbox_events" + }, + { + "definition": "PRIMARY KEY (event_id)", + "kind": "p", + "name": "pk_outbox_events", + "table_name": "outbox_events" + }, + { + "definition": "UNIQUE (idempotency_key)", + "kind": "u", + "name": "uq_outbox_events_idempotency_key", + "table_name": "outbox_events" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_payment_policies_project_guide", + "table_name": "payment_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_payment_policies_project_id_projects", + "table_name": "payment_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_payment_policies", + "table_name": "payment_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version)", + "kind": "u", + "name": "uq_payment_policies_project_version", + "table_name": "payment_policies" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_26aa", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_595e", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.review_policy.update', 'project.revision_policy.update']))", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_7f7f", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (policy_generation > 0)", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_8b22", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_dc05", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_actor_profile_id_41c2", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_guide_id_project_guides", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_identity_link_id_b806", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_policy_mutation_idempotency_records_project_id_projects", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_policy_mutation_idempotency_records", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "policy_mutation_replay_custody", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_policy_mutation_operation_identity", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", + "kind": "u", + "name": "uq_policy_mutation_replay_namespace", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'compiled'::text OR compiler_version IS NOT NULL AND compiled_bundle IS NOT NULL AND compiled_bundle_hash IS NOT NULL AND compiled_bundle_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_5010", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['pending_compilation', 'compiled', 'superseded']))", + "kind": "c", + "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_a935", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_pre_submit_checker_policies_ck_pre_submit_policy_aut_90fc", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_effective_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_guide", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_project", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_project_guide", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_source_snapshot_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_pre_submit_checker_policy_id) REFERENCES pre_submit_checker_policies(id)", + "kind": "f", + "name": "fk_pre_submit_checker_policies_supersedes", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_actor", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_decision", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_grant", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_link", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_pre_submit_policy_creation_project", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_pre_submit_checker_policies", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "pre_submit_policy_custody", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "UNIQUE (id, compiled_bundle_hash)", + "kind": "u", + "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CHECK (classification::text = ANY (ARRAY['mandatory_security', 'mandatory_integrity', 'mandatory_accountability', 'advisory']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_b0de", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (classification::text = 'advisory'::text AND severity::text = 'warning'::text OR classification::text <> 'advisory'::text AND severity::text = 'blocking'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_f04e", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (result_order >= 0)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_order", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (phase::text = ANY (ARRAY['custody', 'identity', 'materialization', 'default_policy', 'project_policy']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_phase", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_plan_sha256", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (locked_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_pol_cef4", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (phase::text = 'project_policy'::text AND rule_instance_id IS NOT NULL AND rule_instance_id::text ~ '^sha256:[0-9a-f]{64}$'::text OR phase::text <> 'project_policy'::text AND rule_instance_id IS NULL)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_rul_321f", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (severity::text = ANY (ARRAY['blocking', 'warning']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_severity", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['passed', 'warning', 'advisory_disabled', 'dependency_not_run', 'failed']))", + "kind": "c", + "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_status", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (status::text = 'failed'::text AND failure_code IS NOT NULL OR status::text <> 'failed'::text AND failure_code IS NULL)", + "kind": "c", + "name": "ck_pre_submit_evidence_results_result_failure_shape", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "FOREIGN KEY (evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_results_evidence_set_id_pre_subm_096e", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_pre_submit_evidence_results", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "UNIQUE (evidence_set_id, definition_id)", + "kind": "u", + "name": "uq_pre_submit_result_definition", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "UNIQUE (evidence_set_id, result_order)", + "kind": "u", + "name": "uq_pre_submit_result_order", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arch_8e95", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (archive_byte_count >= 0)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_archive_size", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_artifact_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arti_16f8", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (catalogue_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_cata_ffcb", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_checker_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_chec_765d", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_guide_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_guide_sha256", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_mani_7268", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_oper_f617", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_plan_sha256", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (predecessor_submission_id IS NULL AND predecessor_submission_version IS NULL OR predecessor_submission_id IS NOT NULL AND predecessor_submission_version IS NOT NULL)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_pred_bd87", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (result_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_resu_0b46", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (result_count > 0)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_result_count", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (source_snapshot_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_sour_982b", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (terminal_status::text = 'passed'::text AND eligible OR terminal_status::text = 'blocked'::text AND NOT eligible)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stat_1ae6", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (storage_scheme::text = ANY (ARRAY['local', 's3']))", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stor_022c", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (terminal_status::text = ANY (ARRAY['passed', 'blocked']))", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_term_a512", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_pre_submit_evidence_sets_policy_context_sha256", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (assignment_id, task_id, actor_profile_id) REFERENCES task_assignments(id, task_id, contributor_id)", + "kind": "f", + "name": "fk_pre_submit_evidence_assignment", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (guide_id, project_id, guide_version) REFERENCES project_guides(id, project_id, version)", + "kind": "f", + "name": "fk_pre_submit_evidence_guide_lineage", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (identity_link_id, actor_profile_id) REFERENCES actor_identity_links(id, actor_profile_id)", + "kind": "f", + "name": "fk_pre_submit_evidence_identity_actor", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (predecessor_submission_id, task_id, predecessor_submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_pre_submit_evidence_predecessor", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_actor_profile_id_actor_profiles", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_assignment_id_task_assignments", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_effective_policy_id_effecti_6a99", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_guide_id_project_guides", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_identity_link_id_actor_iden_5cef", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_pre_submit_policy_id_pre_su_c77f", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_predecessor_submission_id_s_6ec2", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_project_id_projects", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_source_snapshot_id_guide_so_1667", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_pre_submit_evidence_sets_task_id_workstream_tasks", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, effective_policy_id, locked_artifact_policy_sha256) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_artifact_policy", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, pre_submit_policy_id, locked_checker_policy_sha256) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_checker_policy", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_guide", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, project_id) REFERENCES workstream_tasks(id, project_id)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_project", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "FOREIGN KEY (task_id, source_snapshot_id, source_snapshot_sha256) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "kind": "f", + "name": "fk_pre_submit_evidence_task_source_snapshot", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_pre_submit_evidence_sets", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "UNIQUE (operation_identity)", + "kind": "u", + "name": "uq_pre_submit_evidence_operation", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CHECK (binding_lifecycle_version > 0)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_1870", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_3372", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (route_key::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'::text)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_6958", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (status::text = 'active'::text AND binding_lifecycle_version = 1 AND suspended_by IS NULL AND suspended_at IS NULL AND retired_by IS NULL AND retired_at IS NULL)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_95ba", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK ((suspended_at IS NULL OR suspended_at >= created_at) AND (retired_at IS NULL OR retired_at >= created_at) AND (retired_at IS NULL OR suspended_at IS NULL OR retired_at >= suspended_at))", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_ade1", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'retired']))", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_da73", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (route_key::text !~~ '%..%'::text)", + "kind": "c", + "name": "ck_project_compensation_adapter_bindings_ck_project_com_f32d", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (adapter_actor_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_adapter_actor", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_created_by", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_compensation_binding_project", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_retired_by", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "FOREIGN KEY (suspended_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_compensation_binding_suspended_by", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_compensation_adapter_bindings", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "UNIQUE (id, project_id, instrument_type)", + "kind": "u", + "name": "uq_compensation_binding_ownership", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", + "kind": "c", + "name": "ck_project_compensation_units_instrument_type", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (status::text = 'active'::text AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", + "kind": "c", + "name": "ck_project_compensation_units_lifecycle_shape", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", + "kind": "c", + "name": "ck_project_compensation_units_retirement_time", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'retired']))", + "kind": "c", + "name": "ck_project_compensation_units_status", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (instrument_type::text = 'money'::text AND iso_currency_code IS NOT NULL AND unit_code::text = iso_currency_code::text OR instrument_type::text = 'project_points'::text AND iso_currency_code IS NULL AND unit_code::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$'::text)", + "kind": "c", + "name": "ck_project_compensation_units_unit_identity", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_compensation_unit_created_by", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (iso_currency_code) REFERENCES iso_4217_currency_codes(code)", + "kind": "f", + "name": "fk_project_compensation_unit_iso_currency", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_compensation_unit_project", + "table_name": "project_compensation_units" + }, + { + "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_compensation_unit_retired_by", + "table_name": "project_compensation_units" + }, + { + "definition": "PRIMARY KEY (project_id, instrument_type, unit_code)", + "kind": "p", + "name": "pk_project_compensation_units", + "table_name": "project_compensation_units" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_0a41", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (operation_generation = 1)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_100d", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND committed_at IS NULL OR status::text = 'committed'::text AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_3aa0", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = 'project.create'::text)", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_action", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_project_create_idempotency_records_ck_project_create_status", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_create_idempotency_records_actor_profile_id__ebb1", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_create_idempotency_records_identity_link_id__ddce", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_create_idempotency_records", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "project_create_reservation_custody", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_project_create_operation_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "UNIQUE (project_id)", + "kind": "u", + "name": "uq_project_create_project_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", + "kind": "u", + "name": "uq_project_create_replay_namespace", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_00d8", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (component_hashes IS NULL OR json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_31c4", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (status::text = 'compilation_reserved'::text AND provider_uncertain_at IS NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_provider_uncertain'::text AND provider_uncertain_at IS NOT NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'provider_result_accepted'::text AND accepted_at IS NOT NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_persisted'::text AND accepted_at IS NOT NULL AND persisted_at IS NOT NULL AND terminal_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NOT NULL OR status::text = 'compilation_invalid_terminal'::text AND terminal_at IS NOT NULL AND accepted_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND persisted_compilation_id IS NULL AND (failure_code::text = ANY (ARRAY['schema_invalid', 'unsafe_text', 'hash_mismatch', 'context_mismatch'])))", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_444c", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_513e", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (canonical_result IS NULL OR octet_length(canonical_result::text) <= 4194304)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6057", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (result_hash IS NULL OR result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6609", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['compilation_reserved', 'compilation_provider_uncertain', 'provider_result_accepted', 'compilation_invalid_terminal', 'compilation_persisted']))", + "kind": "c", + "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6c82", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (persisted_compilation_id, id) REFERENCES project_guide_compilations(id, attempt_id)", + "kind": "f", + "name": "fk_compilation_attempt_exact_persisted_compilation", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", + "kind": "f", + "name": "fk_compilation_attempt_exact_setup", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_compilation_attempt_snapshot_hash", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_project_guide_compilation_attempts_guide_id_project_guides", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_guide_compilation_attempts_project_id_projects", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_guide_compilation_attempts", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "UNIQUE (provider_idempotency_key)", + "kind": "u", + "name": "uq_compilation_attempt_provider_key", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "UNIQUE (setup_run_id, setup_generation)", + "kind": "u", + "name": "uq_compilation_attempt_setup_generation", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CHECK (setup_generation > 0 AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_action_id::text = 'project.guide_compilation.execute'::text)", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_8a51", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_9cd9", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK (authorization_resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_d554", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK (octet_length(canonical_result::text) <= 4194304 AND json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", + "kind": "c", + "name": "ck_project_guide_compilations_ck_project_guide_compilat_dafe", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (supersedes_compilation_id, project_id, guide_id) REFERENCES project_guide_compilations(id, project_id, guide_id)", + "kind": "f", + "name": "fk_project_guide_compilation_predecessor", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (attempt_id) REFERENCES project_guide_compilation_attempts(id)", + "kind": "f", + "name": "fk_project_guide_compilations_attempt_id_project_guide__0e94", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_project_guide_compilations_authorization_decision_ev_42ad", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_guide_compilations_created_by_actor_profile__953f", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_guide_compilations_created_via_identity_link_b250", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_project_guide_compilations_guide_id_project_guides", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_guide_compilations_project_id_projects", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_project_guide_compilations_setup_run_id_project_setup_runs", + "table_name": "project_guide_compilations" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_project_guide_compilations_source_snapshot_id_guide__033a", + "table_name": "project_guide_compilations" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_guide_compilations", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (attempt_id)", + "kind": "u", + "name": "uq_project_guide_compilation_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (id, attempt_id)", + "kind": "u", + "name": "uq_project_guide_compilation_id_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (supersedes_compilation_id)", + "kind": "u", + "name": "uq_project_guide_compilation_predecessor", + "table_name": "project_guide_compilations" + }, + { + "definition": "UNIQUE (id, project_id, guide_id)", + "kind": "u", + "name": "uq_project_guide_compilation_scope", + "table_name": "project_guide_compilations" + }, + { + "definition": "CHECK ((status::text <> ALL (ARRAY['active', 'superseded'])) OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL AND selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL)", + "kind": "c", + "name": "ck_project_guides_active_policy_selection_required", + "table_name": "project_guides" + }, + { + "definition": "CHECK (mutation_generation IS NULL AND last_mutated_by_actor_profile_id IS NULL AND last_mutated_via_identity_link_id IS NULL AND last_mutated_by_admin_role_grant_id IS NULL AND last_mutation_scope_type IS NULL AND last_mutation_scope_project_id IS NULL AND last_mutation_action_id IS NULL AND last_authorization_decision_event_id IS NULL OR mutation_generation > 0 AND last_mutated_by_actor_profile_id IS NOT NULL AND last_mutated_via_identity_link_id IS NOT NULL AND last_mutated_by_admin_role_grant_id IS NOT NULL AND (last_mutation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (last_mutation_scope_type::text = 'system'::text AND last_mutation_scope_project_id IS NULL OR last_mutation_scope_type::text = 'project'::text AND last_mutation_scope_project_id::text = project_id::text) AND (last_mutation_action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create'])) AND last_authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_project_guides_guide_mutation_authority_shape", + "table_name": "project_guides" + }, + { + "definition": "CHECK ((selected_review_policy_id IS NULL AND selected_review_policy_generation IS NULL AND selected_review_policy_hash IS NULL OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL) AND (selected_revision_policy_id IS NULL AND selected_revision_policy_generation IS NULL AND selected_revision_policy_hash IS NULL OR selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL))", + "kind": "c", + "name": "ck_project_guides_policy_selection_shape", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_mutated_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_actor", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_mutated_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_admin_grant", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_decision", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (last_mutated_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_guides_last_mutated_identity_link", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_guides_project_id_projects", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (project_id, version, selected_review_policy_id, selected_review_policy_generation, selected_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_project_guides_selected_review_policy", + "table_name": "project_guides" + }, + { + "definition": "FOREIGN KEY (project_id, version, selected_revision_policy_id, selected_revision_policy_generation, selected_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_project_guides_selected_revision_policy", + "table_name": "project_guides" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "guide_mutation_product_custody", + "table_name": "project_guides" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_guides", + "table_name": "project_guides" + }, + { + "definition": "UNIQUE (id, project_id, version)", + "kind": "u", + "name": "uq_project_guides_id_project_version", + "table_name": "project_guides" + }, + { + "definition": "UNIQUE (project_id, version)", + "kind": "u", + "name": "uq_project_guides_project_version", + "table_name": "project_guides" + }, + { + "definition": "CHECK (grant_method::text = 'manual'::text)", + "kind": "c", + "name": "ck_project_role_grants_grant_method", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND revoked_at IS NOT NULL)", + "kind": "c", + "name": "ck_project_role_grants_lifecycle", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (project_role_reason_is_safe(grant_reason) AND (revoked_reason IS NULL OR project_role_reason_is_safe(revoked_reason)))", + "kind": "c", + "name": "ck_project_role_grants_reason", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", + "kind": "c", + "name": "ck_project_role_grants_role", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_grants_actor_profile_id_actor_profiles", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_grants_granted_by_actor_profile_id_acto_c240", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_role_grants_granted_by_admin_role_grant_id_a_71d7", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_role_grants_project_id_projects", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_grants_revoked_by_actor_profile_id_acto_a5dd", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_role_grants_revoked_by_admin_role_grant_id_a_aa4d", + "table_name": "project_role_grants" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_role_grants", + "table_name": "project_role_grants" + }, + { + "definition": "FOREIGN KEY (qualification_snapshot_id, actor_profile_id, project_id, role) REFERENCES project_role_qualification_snapshots(id, actor_profile_id, project_id, requested_role) ON DELETE RESTRICT", + "kind": "f", + "name": "qualification_ownership", + "table_name": "project_role_grants" + }, + { + "definition": "CHECK (project_role_availability_is_safe(skills_snapshot) AND project_role_availability_is_safe(reputation_snapshot))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_availability", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (project_role_reference_array_is_safe(external_expertise_refs, false))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_external_expertise_refs", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (project_role_reference_array_is_safe(prior_project_work_refs, true))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_prior_work_refs", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (requested_role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", + "kind": "c", + "name": "ck_project_role_qualification_snapshots_role", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_actor_profile_i_aedc", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (captured_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_captured_by_act_ab57", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (captured_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_captured_by_adm_c8b8", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_role_qualification_snapshots_project_id_projects", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "UNIQUE (id, actor_profile_id, project_id, requested_role)", + "kind": "u", + "name": "grant_reference", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_role_qualification_snapshots", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_project_setup_runs_ck_project_setup_runs_generation_positive", + "table_name": "project_setup_runs" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['queued', 'dispatch_pending', 'enqueue_failed', 'enqueue_identity_mismatch', 'running_sufficiency_agent', 'sufficiency_blocked', 'running_policy_derivation_agent', 'policy_draft_ready', 'running_post_submit_derivation_agent', 'post_submit_setup_blocked', 'post_submit_policy_compiled', 'setup_blocked', 'failed']))", + "kind": "c", + "name": "ck_project_setup_runs_ck_project_setup_runs_status", + "table_name": "project_setup_runs" + }, + { + "definition": "CHECK (authorized_by_actor_profile_id IS NULL AND authorized_via_identity_link_id IS NULL AND authorized_by_admin_role_grant_id IS NULL AND authorization_scope_type IS NULL AND authorization_scope_project_id IS NULL AND authorization_action_id IS NULL AND authorization_decision_event_id IS NULL OR authorized_by_actor_profile_id IS NOT NULL AND authorized_via_identity_link_id IS NOT NULL AND authorized_by_admin_role_grant_id IS NOT NULL AND (authorization_scope_type::text = ANY (ARRAY['system', 'project'])) AND (authorization_scope_type::text = 'system'::text AND authorization_scope_project_id IS NULL OR authorization_scope_type::text = 'project'::text AND authorization_scope_project_id::text = project_id::text) AND authorization_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_project_setup_runs_setup_run_authority_shape", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (error_artifact_incident_id) REFERENCES guide_source_artifact_incidents(id)", + "kind": "f", + "name": "fk_project_setup_runs_artifact_incident", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorized_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_actor", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorized_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_admin_grant", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_decision", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (authorized_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_project_setup_runs_authorized_identity_link", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (continuation_verification_job_id) REFERENCES artifact_verification_jobs(id)", + "kind": "f", + "name": "fk_project_setup_runs_continuation_verification_job", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_project_setup_runs_guide_id_project_guides", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (output_post_submit_checker_policy_id) REFERENCES checker_policies(id)", + "kind": "f", + "name": "fk_project_setup_runs_post_submit_checker_policy", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_project_setup_runs_project_guide", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_project_setup_runs_project_id_projects", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_project_setup_runs_source_snapshot_hash", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_project_setup_runs_source_snapshot_id_guide_source_snapshots", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (output_submission_artifact_policy_id) REFERENCES submission_artifact_policies(id)", + "kind": "f", + "name": "fk_project_setup_runs_submission_artifact_policy", + "table_name": "project_setup_runs" + }, + { + "definition": "FOREIGN KEY (output_sufficiency_report_id) REFERENCES guide_sufficiency_reports(id)", + "kind": "f", + "name": "fk_project_setup_runs_sufficiency_report", + "table_name": "project_setup_runs" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_project_setup_runs", + "table_name": "project_setup_runs" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "source_setup_run_custody", + "table_name": "project_setup_runs" + }, + { + "definition": "UNIQUE (id, project_id, guide_id, source_snapshot_id, setup_generation)", + "kind": "u", + "name": "uq_project_setup_runs_exact_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "UNIQUE (guide_id, setup_generation)", + "kind": "u", + "name": "uq_project_setup_runs_guide_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type::text = 'system'::text AND creation_action_id::text = 'project.create'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_projects_creation_authority_shape", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_projects_creation_actor", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_projects_creation_admin_grant", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_projects_creation_decision", + "table_name": "projects" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_projects_creation_identity_link", + "table_name": "projects" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_projects", + "table_name": "projects" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "project_creation_custody", + "table_name": "projects" + }, + { + "definition": "UNIQUE (slug)", + "kind": "u", + "name": "uq_projects_slug", + "table_name": "projects" + }, + { + "definition": "CHECK (submission_version > 0)", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_2b6d", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (status::text = 'pending'::text AND review_queue_entry_id IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND review_queue_entry_id IS NOT NULL AND committed_at IS NOT NULL)", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_4cd5", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_88bf", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", + "kind": "c", + "name": "ck_review_admission_idempotency_records_ck_review_admis_b8b8", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_review_admission_checker", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", + "kind": "f", + "name": "fk_review_admission_committed_queue", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_admission_project", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (review_queue_entry_id) REFERENCES review_queue_entries(id)", + "kind": "f", + "name": "fk_review_admission_queue", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_review_admission_submission", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_review_admission_submission_lineage", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_review_admission_task", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_admission_idempotency_records", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "UNIQUE (admitting_checker_run_id)", + "kind": "u", + "name": "uq_review_admission_checker_run", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_review_admission_operation", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "UNIQUE (idempotency_key)", + "kind": "u", + "name": "uq_review_admission_replay_key", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CHECK (attempt_generation > 0)", + "kind": "c", + "name": "ck_review_leases_attempt_generation_positive", + "table_name": "review_leases" + }, + { + "definition": "CHECK (closed_at IS NULL OR closed_at >= claimed_at)", + "kind": "c", + "name": "ck_review_leases_closure_after_claim", + "table_name": "review_leases" + }, + { + "definition": "CHECK (expires_at > claimed_at)", + "kind": "c", + "name": "ck_review_leases_expiry_after_claim", + "table_name": "review_leases" + }, + { + "definition": "CHECK (status::text = 'active'::text AND closed_at IS NULL AND close_reason IS NULL OR status::text = 'consumed'::text AND closed_at IS NOT NULL AND close_reason::text = 'review_recorded'::text OR status::text = 'released'::text AND closed_at IS NOT NULL AND close_reason::text = 'manual_release'::text OR status::text = 'expired'::text AND closed_at IS NOT NULL AND close_reason::text = 'lease_expired'::text OR status::text = 'revoked'::text AND closed_at IS NOT NULL AND (close_reason::text = ANY (ARRAY['grant_revoked', 'admin_override'])))", + "kind": "c", + "name": "ck_review_leases_lifecycle_shape", + "table_name": "review_leases" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['active', 'consumed', 'released', 'expired', 'revoked']))", + "kind": "c", + "name": "ck_review_leases_status", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (reviewer_contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", + "kind": "f", + "name": "fk_review_lease_policy_version", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_lease_project", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version)", + "kind": "f", + "name": "fk_review_lease_queue_lineage", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (reviewer_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_review_lease_reviewer", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_review_lease_submission", + "table_name": "review_leases" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_review_lease_task", + "table_name": "review_leases" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_leases", + "table_name": "review_leases" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "review_leases_active_lease_guard", + "table_name": "review_leases" + }, + { + "definition": "UNIQUE (review_queue_entry_id, attempt_generation)", + "kind": "u", + "name": "uq_review_lease_attempt", + "table_name": "review_leases" + }, + { + "definition": "UNIQUE (review_queue_entry_id, id)", + "kind": "u", + "name": "uq_review_lease_queue_identity", + "table_name": "review_leases" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.review_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_review_policies_review_policy_authority_shape", + "table_name": "review_policies" + }, + { + "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", + "kind": "c", + "name": "ck_review_policies_review_policy_identity_shape", + "table_name": "review_policies" + }, + { + "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", + "kind": "c", + "name": "ck_review_policies_review_policy_predecessor_shape", + "table_name": "review_policies" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR review_preference_window_seconds > 0 AND review_lease_duration_seconds > 0 AND max_active_review_leases_per_reviewer = 1 AND self_review_allowed = false AND reject_policy::text = 'close_task'::text AND (finding_evidence_requirement::text = ANY (ARRAY['optional', 'required_for_blocking', 'required_for_all'])))", + "kind": "c", + "name": "ck_review_policies_review_policy_semantics_shape", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_review_policies_actor_profile", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_review_policies_admin_grant", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_review_policies_decision_event", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_review_policies_identity_link", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_review_policies_project_guide", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_policies_project_id_projects", + "table_name": "review_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES review_policies(id)", + "kind": "f", + "name": "fk_review_policies_supersedes", + "table_name": "review_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_policies", + "table_name": "review_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "review_policy_mutation_custody", + "table_name": "review_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, policy_generation)", + "kind": "u", + "name": "uq_review_policies_project_version_generation", + "table_name": "review_policies" + }, + { + "definition": "UNIQUE (id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_review_policy_lineage", + "table_name": "review_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_review_policy_scoped_lineage", + "table_name": "review_policies" + }, + { + "definition": "CHECK (available_since >= first_queued_at)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_availab_d484", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_generation > 0 AND lifecycle_generation > 0)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_generat_38b7", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (queue_state::text = 'pending'::text AND active_lease_id IS NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'leased'::text AND active_lease_id IS NOT NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'closed'::text AND active_lease_id IS NULL AND closed_at IS NOT NULL AND (closed_reason::text = ANY (ARRAY['review_recorded', 'task_closed', 'admin_cancelled'])) AND closed_at >= first_queued_at)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_lifecycle_shape", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (queue_state::text = ANY (ARRAY['pending', 'leased', 'closed']))", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_queue_state", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_mode::text = ANY (ARRAY['open', 'preferred']))", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_routing_mode", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_reason::text = ANY (ARRAY['first_submission', 'revision_return', 'admin_assignment']))", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_routing_reason", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (routing_mode::text = 'open'::text AND preferred_reviewer_id IS NULL AND preference_expires_at IS NULL OR routing_mode::text = 'preferred'::text AND preferred_reviewer_id IS NOT NULL AND preference_expires_at IS NOT NULL AND preference_expires_at > first_queued_at)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_routing_shape", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (submission_version > 0)", + "kind": "c", + "name": "ck_review_queue_entries_ck_review_queue_entries_submiss_2f6b", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (active_lease_id, id) REFERENCES review_leases(id, review_queue_entry_id) DEFERRABLE INITIALLY DEFERRED", + "kind": "f", + "name": "fk_review_queue_active_lease", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", + "kind": "f", + "name": "fk_review_queue_checker", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (preferred_reviewer_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_review_queue_preferred_reviewer", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_review_queue_project", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_review_queue_submission", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", + "kind": "f", + "name": "fk_review_queue_submission_lineage", + "table_name": "review_queue_entries" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_review_queue_task", + "table_name": "review_queue_entries" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_review_queue_entries", + "table_name": "review_queue_entries" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "review_queue_entries_active_lease_guard", + "table_name": "review_queue_entries" + }, + { + "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", + "kind": "u", + "name": "uq_review_queue_admission_identity", + "table_name": "review_queue_entries" + }, + { + "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version)", + "kind": "u", + "name": "uq_review_queue_lease_lineage", + "table_name": "review_queue_entries" + }, + { + "definition": "UNIQUE (submission_id)", + "kind": "u", + "name": "uq_review_queue_submission", + "table_name": "review_queue_entries" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.revision_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_revision_policies_revision_policy_authority_shape", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", + "kind": "c", + "name": "ck_revision_policies_revision_policy_identity_shape", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", + "kind": "c", + "name": "ck_revision_policies_revision_policy_predecessor_shape", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR max_revision_rounds > 0 AND revision_deadline_hours > 0)", + "kind": "c", + "name": "ck_revision_policies_revision_policy_semantics_shape", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_revision_policies_actor_profile", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_revision_policies_admin_grant", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_revision_policies_decision_event", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_revision_policies_identity_link", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_revision_policies_project_guide", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_revision_policies_project_id_projects", + "table_name": "revision_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES revision_policies(id)", + "kind": "f", + "name": "fk_revision_policies_supersedes", + "table_name": "revision_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_revision_policies", + "table_name": "revision_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "revision_policy_mutation_custody", + "table_name": "revision_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, policy_generation)", + "kind": "u", + "name": "uq_revision_policies_project_version_generation", + "table_name": "revision_policies" + }, + { + "definition": "UNIQUE (id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_revision_policy_lineage", + "table_name": "revision_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "u", + "name": "uq_revision_policy_scoped_lineage", + "table_name": "revision_policies" + }, + { + "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['draft', 'approved', 'superseded']))", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_artifact__20ca", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_artifact__52ca", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (approved_by_actor_profile_id IS NULL AND approved_via_identity_link_id IS NULL AND approved_by_admin_role_grant_id IS NULL AND approval_scope_type IS NULL AND approval_scope_project_id IS NULL AND approval_action_id IS NULL AND approval_decision_event_id IS NULL OR approved_by_actor_profile_id IS NOT NULL AND approved_via_identity_link_id IS NOT NULL AND approved_by_admin_role_grant_id IS NOT NULL AND approval_scope_type IS NOT NULL AND approval_action_id IS NOT NULL AND (approval_scope_type::text = ANY (ARRAY['system', 'project'])) AND approval_scope_project_id IS NOT NULL AND approval_scope_project_id::text = project_id::text AND approval_action_id::text = 'project.submission_artifact_policy.approve'::text AND approval_decision_event_id IS NOT NULL)", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_policy_ap_0e4d", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_decision_event_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update'])) AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NOT NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.submission_artifact_policy.derive'::text))", + "kind": "c", + "name": "ck_submission_artifact_policies_ck_submission_policy_cr_0629", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES submission_artifact_policies(id)", + "kind": "f", + "name": "fk_sap_supersedes_policy", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_submission_artifact_policies_guide_id_project_guides", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_submission_artifact_policies_project_guide", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_artifact_policies_project_id_projects", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_submission_artifact_policies_source_snapshot_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approved_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submission_policy_approval_actor", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approval_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_submission_policy_approval_decision", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approved_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_submission_policy_approval_grant", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approved_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_submission_policy_approval_link", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (approval_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_policy_approval_project", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submission_policy_creation_actor", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", + "kind": "f", + "name": "fk_submission_policy_creation_decision", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", + "kind": "f", + "name": "fk_submission_policy_creation_grant", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_submission_policy_creation_link", + "table_name": "submission_artifact_policies" + }, + { + "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_policy_creation_project", + "table_name": "submission_artifact_policies" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_artifact_policies", + "table_name": "submission_artifact_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "submission_policy_creation_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "submission_policy_product_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "UNIQUE (id, policy_hash)", + "kind": "u", + "name": "uq_submission_artifact_policies_id_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "UNIQUE (project_id, guide_version, policy_version)", + "kind": "u", + "name": "uq_submission_artifact_policies_project_version_policy", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_bundle_admissions_archive_sha256", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (archive_byte_count >= 0)", + "kind": "c", + "name": "ck_submission_bundle_admissions_archive_size", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_bundle_admissions_manifest_sha256", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_bundle_admissions_policy_context_hash", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK ((predecessor_submission_id IS NULL) = (predecessor_submission_version IS NULL))", + "kind": "c", + "name": "ck_submission_bundle_admissions_predecessor_shape", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['ready', 'consumed', 'stale']))", + "kind": "c", + "name": "ck_submission_bundle_admissions_status", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (status::text = 'ready'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'consumed'::text AND consumed_at IS NOT NULL AND consumed_by_submission_id IS NOT NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'stale'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NOT NULL AND octet_length(stale_reason::text) >= 1 AND octet_length(stale_reason::text) <= 500)", + "kind": "c", + "name": "ck_submission_bundle_admissions_terminal_shape", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CHECK (((put_operation_receipt_id IS NOT NULL)::integer + (put_observation_receipt_id IS NOT NULL)::integer) = 1)", + "kind": "c", + "name": "ck_submission_bundle_admissions_write_receipt_shape", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_actor_profile_id_actor_profiles", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (artifact_content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_artifact_content_id_art_12c8", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_assignment_id_task_assignments", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (consumed_by_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_consumed_by_submission__2b23", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (durable_intent_id) REFERENCES submission_bundle_durable_intents(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_durable_intent_id_submi_102c", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_identity_link_id_actor__d29d", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_pre_submit_evidence_set_a752", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_predecessor_submission__242d", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_project_id_projects", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_put_attempt_id_artifact_bbc3", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (put_observation_receipt_id) REFERENCES artifact_put_observation_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_put_observation_receipt_5136", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (put_operation_receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_put_operation_receipt_i_9602", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_task_id_workstream_tasks", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (verification_receipt_id) REFERENCES artifact_verification_receipts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_verification_receipt_id_0ea1", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (verified_replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_admissions_verified_replica_id_art_3a4e", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_bundle_admissions", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "UNIQUE (pre_submit_evidence_set_id)", + "kind": "u", + "name": "uq_submission_bundle_admission_evidence", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "UNIQUE (durable_intent_id)", + "kind": "u", + "name": "uq_submission_bundle_admission_intent", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "UNIQUE (verification_receipt_id)", + "kind": "u", + "name": "uq_submission_bundle_admission_verification", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_durable_intents_pre_submit_evidenc_c406", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", + "kind": "f", + "name": "fk_submission_bundle_durable_intents_put_attempt_id_art_b4e4", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_bundle_durable_intents", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "UNIQUE (pre_submit_evidence_set_id)", + "kind": "u", + "name": "uq_submission_bundle_intent_evidence", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "UNIQUE (put_attempt_id)", + "kind": "u", + "name": "uq_submission_bundle_intent_put_attempt", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0119", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update', 'project.submission_artifact_policy.approve']))", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0dbe", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (setup_generation > 0)", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_2b53", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK ((status::text = ANY (ARRAY['reserved', 'pending'])) AND response_json IS NULL AND committed_at IS NULL AND committed_policy_id IS NULL AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND committed_policy_id IS NOT NULL AND (action_id::text = 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NOT NULL AND committed_pre_submit_policy_id IS NOT NULL OR action_id::text <> 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL))", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_58d4", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (status::text = ANY (ARRAY['reserved', 'pending', 'committed']))", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_a824", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (service_identity IS NULL AND idempotency_key IS NOT NULL AND setup_run_id IS NULL AND setup_task_id IS NULL AND correlation_id IS NULL OR service_identity IS NOT NULL AND service_identity::text = 'workstream.project.setup'::text AND idempotency_key IS NULL AND action_id::text = 'project.submission_artifact_policy.derive'::text AND setup_run_id IS NOT NULL AND setup_task_id IS NOT NULL AND correlation_id IS NOT NULL)", + "kind": "c", + "name": "ck_submission_policy_mutation_idempotency_records_ck_su_b357", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_actor_f5bb", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (committed_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_commi_4fa6", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (committed_policy_id) REFERENCES submission_artifact_policies(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_commi_571a", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (committed_pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_commi_baa9", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_guide_ed8d", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_ident_2567", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_proje_442a", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_setup_a102", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", + "kind": "f", + "name": "fk_submission_policy_mutation_idempotency_records_sourc_536e", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submission_policy_mutation_idempotency_records", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", + "kind": "t", + "name": "submission_policy_replay_custody", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "UNIQUE (operation_id)", + "kind": "u", + "name": "uq_submission_policy_operation_identity", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", + "kind": "c", + "name": "ck_submissions_post_submit_policy_lock_complete", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_submissions_contributor_id_actor_profiles", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_submissions_locked_effective_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", + "kind": "f", + "name": "fk_submissions_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", + "kind": "f", + "name": "fk_submissions_locked_pre_submit_checker_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_submissions_locked_source_snapshot_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (supersedes_submission_id) REFERENCES submissions(id)", + "kind": "f", + "name": "fk_submissions_supersedes_submission_id_submissions", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_submissions_task_id_workstream_tasks", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_effective_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", + "kind": "f", + "name": "fk_submissions_task_locked_guide", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", + "kind": "f", + "name": "fk_submissions_task_locked_payment_policy", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES workstream_tasks(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_pre_submit_checker_hash", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_review_policy", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_revision_policy", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (task_id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "kind": "f", + "name": "fk_submissions_task_locked_source_snapshot_hash", + "table_name": "submissions" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_submissions", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "u", + "name": "uq_submissions_id_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (id, task_id, version)", + "kind": "u", + "name": "uq_submissions_id_task_version", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (id, version)", + "kind": "u", + "name": "uq_submissions_id_version", + "table_name": "submissions" + }, + { + "definition": "UNIQUE (task_id, version)", + "kind": "u", + "name": "uq_submissions_task_version", + "table_name": "submissions" + }, + { + "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", + "kind": "f", + "name": "fk_task_assignments_contributor_id_actor_profiles", + "table_name": "task_assignments" + }, + { + "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", + "kind": "f", + "name": "fk_task_assignments_task_id_workstream_tasks", + "table_name": "task_assignments" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_task_assignments", + "table_name": "task_assignments" + }, + { + "definition": "UNIQUE (id, task_id, contributor_id)", + "kind": "u", + "name": "uq_task_assignments_id_task_contributor", + "table_name": "task_assignments" + }, + { + "definition": "CHECK (status::text = 'draft'::text OR locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", + "kind": "c", + "name": "ck_workstream_tasks_post_submit_policy_lock_complete", + "table_name": "workstream_tasks" + }, + { + "definition": "CHECK (status::text = 'draft'::text OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", + "kind": "c", + "name": "ck_workstream_tasks_review_revision_policy_lock_required", + "table_name": "workstream_tasks" + }, + { + "definition": "CHECK (locked_review_policy_id IS NULL AND locked_review_policy_generation IS NULL AND locked_review_policy_hash IS NULL AND locked_revision_policy_id IS NULL AND locked_revision_policy_generation IS NULL AND locked_revision_policy_hash IS NULL OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", + "kind": "c", + "name": "ck_workstream_tasks_review_revision_policy_lock_shape", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_guide_version) REFERENCES project_guides(project_id, version)", + "kind": "f", + "name": "fk_workstream_tasks_locked_guide", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_payment_policy_version) REFERENCES payment_policies(project_id, guide_version)", + "kind": "f", + "name": "fk_workstream_tasks_locked_payment_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_review_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_revision_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", + "kind": "f", + "name": "fk_workstream_tasks_locked_source_snapshot_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", + "kind": "f", + "name": "fk_workstream_tasks_project_id_projects", + "table_name": "workstream_tasks" + }, + { + "definition": "PRIMARY KEY (id)", + "kind": "p", + "name": "pk_workstream_tasks", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_guide_version)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_guide", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_payment_policy_version)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_payment_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_review_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_revision_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "kind": "u", + "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "UNIQUE (id, project_id)", + "kind": "u", + "name": "uq_workstream_tasks_id_project", + "table_name": "workstream_tasks" + } + ], + "format": "workstream-v01-schema-manifest-1", + "indexes": [ + { + "definition": "CREATE INDEX ix_actor_identity_links_issuer_subject_status ON public.actor_identity_links USING btree (issuer, subject, status)", + "name": "ix_actor_identity_links_issuer_subject_status", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX pk_actor_identity_links ON public.actor_identity_links USING btree (id)", + "name": "pk_actor_identity_links", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_actor_profile ON public.actor_identity_links USING btree (actor_profile_id)", + "name": "uq_actor_identity_links_actor_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_external_identity ON public.actor_identity_links USING btree (issuer, subject)", + "name": "uq_actor_identity_links_external_identity", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_id_profile ON public.actor_identity_links USING btree (id, actor_profile_id)", + "name": "uq_actor_identity_links_id_profile", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE UNIQUE INDEX pk_actor_profile_migration_state ON public.actor_profile_migration_state USING btree (id)", + "name": "pk_actor_profile_migration_state", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CREATE INDEX ix_actor_profiles_last_seen_at ON public.actor_profiles USING btree (last_seen_at)", + "name": "ix_actor_profiles_last_seen_at", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE INDEX ix_actor_profiles_status_actor_kind ON public.actor_profiles USING btree (status, actor_kind)", + "name": "ix_actor_profiles_status_actor_kind", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE UNIQUE INDEX pk_actor_profiles ON public.actor_profiles USING btree (id)", + "name": "pk_actor_profiles", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE UNIQUE INDEX service_identity ON public.actor_profiles USING btree (service_identity)", + "name": "service_identity", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE INDEX ix_admin_role_grants_effective_candidate ON public.admin_role_grants USING btree (target_actor_profile_id, status, scope_type, scope_project_id)", + "name": "ix_admin_role_grants_effective_candidate", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE INDEX ix_admin_role_grants_final_access_admin ON public.admin_role_grants USING btree (role, status) WHERE (((role)::text = 'access_administrator'::text) AND ((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", + "name": "ix_admin_role_grants_final_access_admin", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE INDEX ix_admin_role_grants_history ON public.admin_role_grants USING btree (target_actor_profile_id, granted_at, id)", + "name": "ix_admin_role_grants_history", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX pk_admin_role_grants ON public.admin_role_grants USING btree (id)", + "name": "pk_admin_role_grants", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_project ON public.admin_role_grants USING btree (target_actor_profile_id, role, scope_project_id) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'project'::text))", + "name": "uq_admin_role_grants_active_project", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_system ON public.admin_role_grants USING btree (target_actor_profile_id, role) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", + "name": "uq_admin_role_grants_active_system", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE INDEX ix_api_rate_control_counters_window_expires_at ON public.api_rate_control_counters USING btree (window_expires_at)", + "name": "ix_api_rate_control_counters_window_expires_at", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CREATE UNIQUE INDEX pk_api_rate_control_counters ON public.api_rate_control_counters USING btree (control_scope, key_digest)", + "name": "pk_api_rate_control_counters", + "table_name": "api_rate_control_counters" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_admission_charges ON public.artifact_admission_charges USING btree (id)", + "name": "pk_artifact_admission_charges", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_admission_charge_scope_content ON public.artifact_admission_charges USING btree (scope_type, scope_id, sha256, byte_count)", + "name": "uq_artifact_admission_charge_scope_content", + "table_name": "artifact_admission_charges" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_admission_scopes ON public.artifact_admission_scopes USING btree (scope_type, scope_id)", + "name": "pk_artifact_admission_scopes", + "table_name": "artifact_admission_scopes" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_content_id ON public.artifact_bindings USING btree (content_id)", + "name": "ix_artifact_bindings_content_id", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_project_id ON public.artifact_bindings USING btree (project_id)", + "name": "ix_artifact_bindings_project_id", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_scope ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version DESC)", + "name": "ix_artifact_bindings_scope", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_bindings_supersedes_binding_id ON public.artifact_bindings USING btree (supersedes_binding_id)", + "name": "ix_artifact_bindings_supersedes_binding_id", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_bindings ON public.artifact_bindings USING btree (id)", + "name": "pk_artifact_bindings", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_binding_scope_version ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version)", + "name": "uq_artifact_binding_scope_version", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_binding_supersedes ON public.artifact_bindings USING btree (supersedes_binding_id)", + "name": "uq_artifact_binding_supersedes", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_artifact_contents_sha256 ON public.artifact_contents USING btree (sha256)", + "name": "ix_artifact_contents_sha256", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_contents ON public.artifact_contents USING btree (id)", + "name": "pk_artifact_contents", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_content_digest_size ON public.artifact_contents USING btree (sha256, byte_count)", + "name": "uq_artifact_content_digest_size", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE INDEX ix_artifact_operation_receipts_put_attempt_id ON public.artifact_operation_receipts USING btree (put_attempt_id)", + "name": "ix_artifact_operation_receipts_put_attempt_id", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE INDEX ix_artifact_operation_receipts_replica_id ON public.artifact_operation_receipts USING btree (replica_id)", + "name": "ix_artifact_operation_receipts_replica_id", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_operation_receipts ON public.artifact_operation_receipts USING btree (id)", + "name": "pk_artifact_operation_receipts", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_receipt_put_attempt ON public.artifact_operation_receipts USING btree (put_attempt_id)", + "name": "uq_artifact_receipt_put_attempt", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempt_charges ON public.artifact_put_attempt_charges USING btree (attempt_id, charge_id)", + "name": "pk_artifact_put_attempt_charges", + "table_name": "artifact_put_attempt_charges" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_checker_run_id ON public.artifact_put_attempts USING btree (checker_run_id)", + "name": "ix_artifact_put_attempts_checker_run_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_guide_source_item_id ON public.artifact_put_attempts USING btree (guide_source_item_id)", + "name": "ix_artifact_put_attempts_guide_source_item_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_next_run_at ON public.artifact_put_attempts USING btree (next_run_at)", + "name": "ix_artifact_put_attempts_next_run_at", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_project_id ON public.artifact_put_attempts USING btree (project_id)", + "name": "ix_artifact_put_attempts_project_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_receipt_id ON public.artifact_put_attempts USING btree (receipt_id)", + "name": "ix_artifact_put_attempts_receipt_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_replica_id ON public.artifact_put_attempts USING btree (replica_id)", + "name": "ix_artifact_put_attempts_replica_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_status ON public.artifact_put_attempts USING btree (status)", + "name": "ix_artifact_put_attempts_status", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_attempts_task_id ON public.artifact_put_attempts USING btree (task_id)", + "name": "ix_artifact_put_attempts_task_id", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempts ON public.artifact_put_attempts USING btree (id)", + "name": "pk_artifact_put_attempts", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_put_attempt_operation ON public.artifact_put_attempts USING btree (operation_identity)", + "name": "uq_artifact_put_attempt_operation", + "table_name": "artifact_put_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_put_observation_receipts_put_attempt_id ON public.artifact_put_observation_receipts USING btree (put_attempt_id)", + "name": "ix_artifact_put_observation_receipts_put_attempt_id", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_put_observation_receipts ON public.artifact_put_observation_receipts USING btree (id)", + "name": "pk_artifact_put_observation_receipts", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_put_observation_fence ON public.artifact_put_observation_receipts USING btree (put_attempt_id, execution_generation)", + "name": "uq_artifact_put_observation_fence", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_parent_recovery_attempt_id ON public.artifact_recovery_attempts USING btree (parent_recovery_attempt_id)", + "name": "ix_artifact_recovery_attempts_parent_recovery_attempt_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_project_id ON public.artifact_recovery_attempts USING btree (project_id)", + "name": "ix_artifact_recovery_attempts_project_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_requester_actor_profile_id ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id)", + "name": "ix_artifact_recovery_attempts_requester_actor_profile_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_submission_id ON public.artifact_recovery_attempts USING btree (submission_id)", + "name": "ix_artifact_recovery_attempts_submission_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_recovery_attempts_task_id ON public.artifact_recovery_attempts USING btree (task_id)", + "name": "ix_artifact_recovery_attempts_task_id", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_recovery_attempts ON public.artifact_recovery_attempts USING btree (id)", + "name": "pk_artifact_recovery_attempts", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_idempotency ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", + "name": "uq_artifact_recovery_idempotency", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_retry_job ON public.artifact_recovery_attempts USING btree (retry_verification_job_id)", + "name": "uq_artifact_recovery_retry_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_source_job ON public.artifact_recovery_attempts USING btree (source_verification_job_id)", + "name": "uq_artifact_recovery_source_job", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE INDEX ix_artifact_replicas_content_id ON public.artifact_replicas USING btree (content_id)", + "name": "ix_artifact_replicas_content_id", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE INDEX ix_artifact_replicas_storage_namespace_id ON public.artifact_replicas USING btree (storage_namespace_id)", + "name": "ix_artifact_replicas_storage_namespace_id", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_replicas ON public.artifact_replicas USING btree (id)", + "name": "pk_artifact_replicas", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_replica_provider_object ON public.artifact_replicas USING btree (storage_namespace_id, provider_object_ref)", + "name": "uq_artifact_replica_provider_object", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_replicas_id_content ON public.artifact_replicas USING btree (id, content_id)", + "name": "uq_artifact_replicas_id_content", + "table_name": "artifact_replicas" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_storage_namespaces ON public.artifact_storage_namespaces USING btree (id)", + "name": "pk_artifact_storage_namespaces", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_fingerprint ON public.artifact_storage_namespaces USING btree (namespace_fingerprint)", + "name": "uq_artifact_storage_namespace_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_id_fingerprint ON public.artifact_storage_namespaces USING btree (id, namespace_fingerprint)", + "name": "uq_artifact_storage_namespace_id_fingerprint", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_next_run_at ON public.artifact_verification_jobs USING btree (next_run_at)", + "name": "ix_artifact_verification_jobs_next_run_at", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_originating_put_attempt_id ON public.artifact_verification_jobs USING btree (originating_put_attempt_id)", + "name": "ix_artifact_verification_jobs_originating_put_attempt_id", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_parent_verification_job_id ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", + "name": "ix_artifact_verification_jobs_parent_verification_job_id", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_replica_id ON public.artifact_verification_jobs USING btree (replica_id)", + "name": "ix_artifact_verification_jobs_replica_id", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_jobs_status ON public.artifact_verification_jobs USING btree (status)", + "name": "ix_artifact_verification_jobs_status", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_verification_jobs ON public.artifact_verification_jobs USING btree (id)", + "name": "pk_artifact_verification_jobs", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_verification_initial_origin ON public.artifact_verification_jobs USING btree (originating_put_attempt_id) WHERE (parent_verification_job_id IS NULL)", + "name": "uq_artifact_verification_initial_origin", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_verification_parent ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", + "name": "uq_artifact_verification_parent", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE INDEX ix_artifact_verification_receipts_verification_job_id ON public.artifact_verification_receipts USING btree (verification_job_id)", + "name": "ix_artifact_verification_receipts_verification_job_id", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_artifact_verification_receipts ON public.artifact_verification_receipts USING btree (id)", + "name": "pk_artifact_verification_receipts", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_artifact_verification_fence ON public.artifact_verification_receipts USING btree (verification_job_id, execution_generation)", + "name": "uq_artifact_verification_fence", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE INDEX ix_audit_events_actor_id ON public.audit_events USING btree (actor_id)", + "name": "ix_audit_events_actor_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_actor_ref ON public.audit_events USING btree (actor_ref_kind, actor_id)", + "name": "ix_audit_events_actor_ref", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_correlation_id ON public.audit_events USING btree (correlation_id)", + "name": "ix_audit_events_correlation_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_entity_id ON public.audit_events USING btree (entity_id)", + "name": "ix_audit_events_entity_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_entity_type ON public.audit_events USING btree (entity_type)", + "name": "ix_audit_events_entity_type", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_event_type ON public.audit_events USING btree (event_type)", + "name": "ix_audit_events_event_type", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_occurred_at ON public.audit_events USING btree (occurred_at)", + "name": "ix_audit_events_occurred_at", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_project_id ON public.audit_events USING btree (project_id)", + "name": "ix_audit_events_project_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE INDEX ix_audit_events_request_id ON public.audit_events USING btree (request_id)", + "name": "ix_audit_events_request_id", + "table_name": "audit_events" + }, + { + "definition": "CREATE UNIQUE INDEX pk_audit_events ON public.audit_events USING btree (id)", + "name": "pk_audit_events", + "table_name": "audit_events" + }, + { + "definition": "CREATE UNIQUE INDEX pk_authority_control ON public.authority_control USING btree (id)", + "name": "pk_authority_control", + "table_name": "authority_control" + }, + { + "definition": "CREATE UNIQUE INDEX pk_authority_idempotency_records ON public.authority_idempotency_records USING btree (id)", + "name": "pk_authority_idempotency_records", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_actor_reference ON public.authority_idempotency_records USING btree (id, actor_ref_kind, actor_ref)", + "name": "uq_authority_idempotency_records_actor_reference", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_replay_namespace ON public.authority_idempotency_records USING btree (actor_ref_kind, actor_ref, operation, idempotency_key)", + "name": "uq_authority_idempotency_records_replay_namespace", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_checker_policies_effective_policy_hash ON public.checker_policies USING btree (effective_policy_hash)", + "name": "ix_checker_policies_effective_policy_hash", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_effective_policy_id ON public.checker_policies USING btree (effective_policy_id)", + "name": "ix_checker_policies_effective_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_guide_id ON public.checker_policies USING btree (guide_id)", + "name": "ix_checker_policies_guide_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_bundle_hash ON public.checker_policies USING btree (pre_submit_checker_bundle_hash)", + "name": "ix_checker_policies_pre_submit_checker_bundle_hash", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_policy_id ON public.checker_policies USING btree (pre_submit_checker_policy_id)", + "name": "ix_checker_policies_pre_submit_checker_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_project_id ON public.checker_policies USING btree (project_id)", + "name": "ix_checker_policies_project_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_source_snapshot_id ON public.checker_policies USING btree (source_snapshot_id)", + "name": "ix_checker_policies_source_snapshot_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_policies_supersedes_policy_id ON public.checker_policies USING btree (supersedes_policy_id)", + "name": "ix_checker_policies_supersedes_policy_id", + "table_name": "checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_checker_policies ON public.checker_policies USING btree (id)", + "name": "pk_checker_policies", + "table_name": "checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_policies_current_project_version ON public.checker_policies USING btree (project_id, guide_version) WHERE ((lifecycle_status)::text = ANY (ARRAY['compiled', 'approved']))", + "name": "uq_checker_policies_current_project_version", + "table_name": "checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_policies_id_version_hash ON public.checker_policies USING btree (id, guide_version, policy_hash)", + "name": "uq_checker_policies_id_version_hash", + "table_name": "checker_policies" + }, + { + "definition": "CREATE INDEX ix_checker_results_checker_name ON public.checker_results USING btree (checker_name)", + "name": "ix_checker_results_checker_name", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_checker_run_id ON public.checker_results USING btree (checker_run_id)", + "name": "ix_checker_results_checker_run_id", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_submission_id ON public.checker_results USING btree (submission_id)", + "name": "ix_checker_results_submission_id", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_task_id ON public.checker_results USING btree (task_id)", + "name": "ix_checker_results_task_id", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_results_worker_visible ON public.checker_results USING btree (worker_visible)", + "name": "ix_checker_results_worker_visible", + "table_name": "checker_results" + }, + { + "definition": "CREATE UNIQUE INDEX pk_checker_results ON public.checker_results USING btree (id)", + "name": "pk_checker_results", + "table_name": "checker_results" + }, + { + "definition": "CREATE INDEX ix_checker_runs_audit_event_id ON public.checker_runs USING btree (audit_event_id)", + "name": "ix_checker_runs_audit_event_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_locked_post_submit_policy_hash ON public.checker_runs USING btree (locked_post_submit_checker_policy_hash)", + "name": "ix_checker_runs_locked_post_submit_policy_hash", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_routing_recommendation ON public.checker_runs USING btree (routing_recommendation)", + "name": "ix_checker_runs_routing_recommendation", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_status ON public.checker_runs USING btree (status)", + "name": "ix_checker_runs_status", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_submission_id ON public.checker_runs USING btree (submission_id)", + "name": "ix_checker_runs_submission_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_supersedes_checker_run_id ON public.checker_runs USING btree (supersedes_checker_run_id)", + "name": "ix_checker_runs_supersedes_checker_run_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE INDEX ix_checker_runs_task_id ON public.checker_runs USING btree (task_id)", + "name": "ix_checker_runs_task_id", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_checker_runs ON public.checker_runs USING btree (id)", + "name": "pk_checker_runs", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_runs_current_per_submission ON public.checker_runs USING btree (submission_id) WHERE (is_current_for_submission = true)", + "name": "uq_checker_runs_current_per_submission", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_checker_runs_submission_attempt ON public.checker_runs USING btree (submission_id, attempt_number)", + "name": "uq_checker_runs_submission_attempt", + "table_name": "checker_runs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_award_definitions ON public.contribution_award_definitions USING btree (id)", + "name": "pk_contribution_award_definitions", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_award_definition_instrument ON public.contribution_award_definitions USING btree (contribution_rule_id, instrument_type)", + "name": "uq_contribution_award_definition_instrument", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_policies ON public.contribution_policies USING btree (id)", + "name": "pk_contribution_policies", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_active_project ON public.contribution_policies USING btree (project_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_contribution_policy_active_project", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_ownership ON public.contribution_policies USING btree (id, project_id)", + "name": "uq_contribution_policy_ownership", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_policy_versions ON public.contribution_policy_versions USING btree (id)", + "name": "pk_contribution_policy_versions", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_number ON public.contribution_policy_versions USING btree (contribution_policy_id, version_number)", + "name": "uq_contribution_policy_version_number", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_ownership ON public.contribution_policy_versions USING btree (id, contribution_policy_id, project_id)", + "name": "uq_contribution_policy_version_ownership", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_project ON public.contribution_policy_versions USING btree (id, project_id)", + "name": "uq_contribution_policy_version_project", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_contribution_rules ON public.contribution_rules USING btree (id)", + "name": "pk_contribution_rules", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_rule_ownership ON public.contribution_rules USING btree (id, contribution_policy_version_id, project_id, contribution_type)", + "name": "uq_contribution_rule_ownership", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE UNIQUE INDEX uq_contribution_rule_type ON public.contribution_rules USING btree (contribution_policy_version_id, contribution_type)", + "name": "uq_contribution_rule_type", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE INDEX ix_effective_psap_effective_hash ON public.effective_project_submission_artifact_policies USING btree (effective_policy_hash)", + "name": "ix_effective_psap_effective_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_guide ON public.effective_project_submission_artifact_policies USING btree (guide_id)", + "name": "ix_effective_psap_guide", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_lifecycle ON public.effective_project_submission_artifact_policies USING btree (lifecycle_status)", + "name": "ix_effective_psap_lifecycle", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_project ON public.effective_project_submission_artifact_policies USING btree (project_id)", + "name": "ix_effective_psap_project", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_source_snapshot ON public.effective_project_submission_artifact_policies USING btree (source_snapshot_id)", + "name": "ix_effective_psap_source_snapshot", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_effective_psap_submission_policy ON public.effective_project_submission_artifact_policies USING btree (submission_artifact_policy_id)", + "name": "ix_effective_psap_submission_policy", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_effective_project_submission_artifact_policies ON public.effective_project_submission_artifact_policies USING btree (id)", + "name": "pk_effective_project_submission_artifact_policies", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_effective_project_submission_artifact_policies_id_hash ON public.effective_project_submission_artifact_policies USING btree (id, effective_policy_hash)", + "name": "uq_effective_project_submission_artifact_policies_id_hash", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_evidence_items_submission_id ON public.evidence_items USING btree (submission_id)", + "name": "ix_evidence_items_submission_id", + "table_name": "evidence_items" + }, + { + "definition": "CREATE INDEX ix_evidence_items_type ON public.evidence_items USING btree (type)", + "name": "ix_evidence_items_type", + "table_name": "evidence_items" + }, + { + "definition": "CREATE UNIQUE INDEX pk_evidence_items ON public.evidence_items USING btree (id)", + "name": "pk_evidence_items", + "table_name": "evidence_items" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_mutation_idempotency_records ON public.guide_mutation_idempotency_records USING btree (id)", + "name": "pk_guide_mutation_idempotency_records", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_mutation_operation_identity ON public.guide_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_guide_mutation_operation_identity", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_mutation_replay_namespace ON public.guide_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", + "name": "uq_guide_mutation_replay_namespace", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_content_id ON public.guide_source_artifact_bindings USING btree (content_id)", + "name": "ix_guide_source_artifact_bindings_content_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_guide_id ON public.guide_source_artifact_bindings USING btree (guide_id)", + "name": "ix_guide_source_artifact_bindings_guide_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_id ON public.guide_source_artifact_bindings USING btree (project_id)", + "name": "ix_guide_source_artifact_bindings_project_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_setup_run_id ON public.guide_source_artifact_bindings USING btree (project_setup_run_id)", + "name": "ix_guide_source_artifact_bindings_project_setup_run_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_item_id ON public.guide_source_artifact_bindings USING btree (source_item_id)", + "name": "ix_guide_source_artifact_bindings_source_item_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_snapshot_id ON public.guide_source_artifact_bindings USING btree (source_snapshot_id)", + "name": "ix_guide_source_artifact_bindings_source_snapshot_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_supersedes_binding_id ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", + "name": "ix_guide_source_artifact_bindings_supersedes_binding_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_bindings_verified_replica_id ON public.guide_source_artifact_bindings USING btree (verified_replica_id)", + "name": "ix_guide_source_artifact_bindings_verified_replica_id", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_bindings ON public.guide_source_artifact_bindings USING btree (id)", + "name": "pk_guide_source_artifact_bindings", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_exact_read ON public.guide_source_artifact_bindings USING btree (id, content_id, verified_replica_id, setup_generation)", + "name": "uq_guide_bindings_exact_read", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_attempt_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, setup_generation)", + "name": "uq_guide_bindings_extraction_attempt_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, source_item_id, project_setup_run_id, setup_generation)", + "name": "uq_guide_bindings_extraction_lineage", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_item_generation ON public.guide_source_artifact_bindings USING btree (source_item_id, setup_generation)", + "name": "uq_guide_bindings_item_generation", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_bindings_supersedes ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", + "name": "uq_guide_bindings_supersedes", + "table_name": "guide_source_artifact_bindings" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_incidents_binding_id ON public.guide_source_artifact_incidents USING btree (binding_id)", + "name": "ix_guide_source_artifact_incidents_binding_id", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_incidents_content_id ON public.guide_source_artifact_incidents USING btree (content_id)", + "name": "ix_guide_source_artifact_incidents_content_id", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_incidents_verified_replica_id ON public.guide_source_artifact_incidents USING btree (verified_replica_id)", + "name": "ix_guide_source_artifact_incidents_verified_replica_id", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_incidents ON public.guide_source_artifact_incidents USING btree (id)", + "name": "pk_guide_source_artifact_incidents", + "table_name": "guide_source_artifact_incidents" + }, + { + "definition": "CREATE INDEX ix_guide_source_artifact_ingests_actor_profile_id ON public.guide_source_artifact_ingests USING btree (actor_profile_id)", + "name": "ix_guide_source_artifact_ingests_actor_profile_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE UNIQUE INDEX ix_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", + "name": "ix_guide_source_artifact_ingests_source_item_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_ingests ON public.guide_source_artifact_ingests USING btree (id)", + "name": "pk_guide_source_artifact_ingests", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", + "name": "uq_guide_source_artifact_ingests_source_item_id", + "table_name": "guide_source_artifact_ingests" + }, + { + "definition": "CREATE INDEX ix_guide_source_extracted_contents_content_id ON public.guide_source_extracted_contents USING btree (content_id)", + "name": "ix_guide_source_extracted_contents_content_id", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extracted_contents ON public.guide_source_extracted_contents USING btree (id)", + "name": "pk_guide_source_extracted_contents", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_exact_usage ON public.guide_source_extracted_contents USING btree (id, content_id)", + "name": "uq_guide_extracted_contents_exact_usage", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_identity ON public.guide_source_extracted_contents USING btree (content_id, detected_format, extractor_name, extractor_version, policy_version)", + "name": "uq_guide_extracted_contents_identity", + "table_name": "guide_source_extracted_contents" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_attempts_binding_id ON public.guide_source_extraction_attempts USING btree (binding_id)", + "name": "ix_guide_source_extraction_attempts_binding_id", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_attempts_content_id ON public.guide_source_extraction_attempts USING btree (content_id)", + "name": "ix_guide_source_extraction_attempts_content_id", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_attempts ON public.guide_source_extraction_attempts USING btree (id)", + "name": "pk_guide_source_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts ON public.guide_source_extraction_attempts USING btree (binding_id, policy_version, attempt_number)", + "name": "uq_guide_extraction_attempts", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts_exact_usage ON public.guide_source_extraction_attempts USING btree (id, binding_id, content_id, setup_generation, status)", + "name": "uq_guide_extraction_attempts_exact_usage", + "table_name": "guide_source_extraction_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_retry_budgets ON public.guide_source_extraction_retry_budgets USING btree (binding_id)", + "name": "pk_guide_source_extraction_retry_budgets", + "table_name": "guide_source_extraction_retry_budgets" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_binding_id ON public.guide_source_extraction_usages USING btree (binding_id)", + "name": "ix_guide_source_extraction_usages_binding_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_content_id ON public.guide_source_extraction_usages USING btree (content_id)", + "name": "ix_guide_source_extraction_usages_content_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_extracted_content_id ON public.guide_source_extraction_usages USING btree (extracted_content_id)", + "name": "ix_guide_source_extraction_usages_extracted_content_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_project_setup_run_id ON public.guide_source_extraction_usages USING btree (project_setup_run_id)", + "name": "ix_guide_source_extraction_usages_project_setup_run_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_extraction_usages_source_item_id ON public.guide_source_extraction_usages USING btree (source_item_id)", + "name": "ix_guide_source_extraction_usages_source_item_id", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_usages ON public.guide_source_extraction_usages USING btree (id)", + "name": "pk_guide_source_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages ON public.guide_source_extraction_usages USING btree (binding_id, extracted_content_id)", + "name": "uq_guide_extraction_usages", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages_exact_provenance ON public.guide_source_extraction_usages USING btree (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", + "name": "uq_guide_extraction_usages_exact_provenance", + "table_name": "guide_source_extraction_usages" + }, + { + "definition": "CREATE INDEX ix_guide_source_format_classifications_binding_id ON public.guide_source_format_classifications USING btree (binding_id)", + "name": "ix_guide_source_format_classifications_binding_id", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE INDEX ix_guide_source_format_classifications_content_id ON public.guide_source_format_classifications USING btree (content_id)", + "name": "ix_guide_source_format_classifications_content_id", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE INDEX ix_guide_source_format_classifications_verified_replica_id ON public.guide_source_format_classifications USING btree (verified_replica_id)", + "name": "ix_guide_source_format_classifications_verified_replica_id", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_format_classifications ON public.guide_source_format_classifications USING btree (id)", + "name": "pk_guide_source_format_classifications", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_classifications_binding ON public.guide_source_format_classifications USING btree (binding_id)", + "name": "uq_guide_classifications_binding", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_classifications_extraction_lineage ON public.guide_source_format_classifications USING btree (id, binding_id, content_id, setup_generation)", + "name": "uq_guide_classifications_extraction_lineage", + "table_name": "guide_source_format_classifications" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshot_items_source_snapshot_id ON public.guide_source_snapshot_items USING btree (source_snapshot_id)", + "name": "ix_guide_source_snapshot_items_source_snapshot_id", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshot_items ON public.guide_source_snapshot_items USING btree (id)", + "name": "pk_guide_source_snapshot_items", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_exact_lineage ON public.guide_source_snapshot_items USING btree (id, source_snapshot_id)", + "name": "uq_guide_source_snapshot_items_exact_lineage", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_snapshot_order ON public.guide_source_snapshot_items USING btree (source_snapshot_id, item_order)", + "name": "uq_guide_source_snapshot_items_snapshot_order", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshots_bundle_hash ON public.guide_source_snapshots USING btree (bundle_hash)", + "name": "ix_guide_source_snapshots_bundle_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshots_guide_id ON public.guide_source_snapshots USING btree (guide_id)", + "name": "ix_guide_source_snapshots_guide_id", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE INDEX ix_guide_source_snapshots_project_id ON public.guide_source_snapshots USING btree (project_id)", + "name": "ix_guide_source_snapshots_project_id", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshots ON public.guide_source_snapshots USING btree (id)", + "name": "pk_guide_source_snapshots", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_exact_lineage ON public.guide_source_snapshots USING btree (id, project_id, guide_id)", + "name": "uq_guide_source_snapshots_exact_lineage", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_id_hash ON public.guide_source_snapshots USING btree (id, bundle_hash)", + "name": "uq_guide_source_snapshots_id_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_project_version_hash ON public.guide_source_snapshots USING btree (project_id, guide_version, bundle_hash)", + "name": "uq_guide_source_snapshots_project_version_hash", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_mutation_idempotency_records ON public.guide_sufficiency_mutation_idempotency_records USING btree (id)", + "name": "pk_guide_sufficiency_mutation_idempotency_records", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_operation_identity ON public.guide_sufficiency_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_sufficiency_mutation_operation_identity", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_replay_namespace ON public.guide_sufficiency_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key)", + "name": "uq_sufficiency_mutation_replay_namespace", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_sufficiency_report_source_usage_report_id ON public.guide_sufficiency_report_source_usages USING btree (report_id)", + "name": "ix_sufficiency_report_source_usage_report_id", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_report_source_usages ON public.guide_sufficiency_report_source_usages USING btree (id)", + "name": "pk_guide_sufficiency_report_source_usages", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_extraction_usage ON public.guide_sufficiency_report_source_usages USING btree (report_id, extraction_usage_id)", + "name": "uq_sufficiency_report_extraction_usage", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_item_order ON public.guide_sufficiency_report_source_usages USING btree (report_id, item_order)", + "name": "uq_sufficiency_report_item_order", + "table_name": "guide_sufficiency_report_source_usages" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_guide_id ON public.guide_sufficiency_reports USING btree (guide_id)", + "name": "ix_guide_sufficiency_reports_guide_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_id ON public.guide_sufficiency_reports USING btree (project_id)", + "name": "ix_guide_sufficiency_reports_project_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_setup_run_id ON public.guide_sufficiency_reports USING btree (project_setup_run_id)", + "name": "ix_guide_sufficiency_reports_project_setup_run_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_source_snapshot_id ON public.guide_sufficiency_reports USING btree (source_snapshot_id)", + "name": "ix_guide_sufficiency_reports_source_snapshot_id", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE INDEX ix_guide_sufficiency_reports_status ON public.guide_sufficiency_reports USING btree (status)", + "name": "ix_guide_sufficiency_reports_status", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_reports ON public.guide_sufficiency_reports USING btree (id)", + "name": "pk_guide_sufficiency_reports", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_diagnostic_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NULL)", + "name": "uq_guide_sufficiency_reports_diagnostic_snapshot", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_verified_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NOT NULL)", + "name": "uq_guide_sufficiency_reports_verified_snapshot", + "table_name": "guide_sufficiency_reports" + }, + { + "definition": "CREATE UNIQUE INDEX pk_iso_4217_currency_codes ON public.iso_4217_currency_codes USING btree (code)", + "name": "pk_iso_4217_currency_codes", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "CREATE UNIQUE INDEX pk_legacy_actor_identities ON public.legacy_actor_identities USING btree (actor_id)", + "name": "pk_legacy_actor_identities", + "table_name": "legacy_actor_identities" + }, + { + "definition": "CREATE UNIQUE INDEX uq_legacy_actor_identities_external_identity ON public.legacy_actor_identities USING btree (external_issuer, external_subject)", + "name": "uq_legacy_actor_identities_external_identity", + "table_name": "legacy_actor_identities" + }, + { + "definition": "CREATE INDEX ix_legacy_workflow_eligibility_actor_id ON public.legacy_workflow_eligibility USING btree (actor_id)", + "name": "ix_legacy_workflow_eligibility_actor_id", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE INDEX ix_legacy_workflow_eligibility_profile_type ON public.legacy_workflow_eligibility USING btree (profile_type)", + "name": "ix_legacy_workflow_eligibility_profile_type", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE INDEX ix_legacy_workflow_eligibility_status ON public.legacy_workflow_eligibility USING btree (status)", + "name": "ix_legacy_workflow_eligibility_status", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE UNIQUE INDEX pk_legacy_workflow_eligibility ON public.legacy_workflow_eligibility USING btree (id)", + "name": "pk_legacy_workflow_eligibility", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE UNIQUE INDEX uq_legacy_workflow_eligibility_actor_type_scope ON public.legacy_workflow_eligibility USING btree (actor_id, profile_type, scope_type, scope_id)", + "name": "uq_legacy_workflow_eligibility_actor_type_scope", + "table_name": "legacy_workflow_eligibility" + }, + { + "definition": "CREATE INDEX ix_outbox_events_aggregate ON public.outbox_events USING btree (aggregate_type, aggregate_id, occurred_at, event_id)", + "name": "ix_outbox_events_aggregate", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_eligible ON public.outbox_events USING btree (event_type, delivery_state, next_attempt_at, occurred_at, event_id) WHERE ((delivery_state)::text = ANY (ARRAY['pending', 'retryable']))", + "name": "ix_outbox_events_eligible", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_expired_claims ON public.outbox_events USING btree (claim_expires_at, event_id) WHERE ((delivery_state)::text = 'claimed'::text)", + "name": "ix_outbox_events_expired_claims", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_project_drain ON public.outbox_events USING btree (project_id, delivery_state, occurred_at, event_id)", + "name": "ix_outbox_events_project_drain", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_outbox_events_retention ON public.outbox_events USING btree (finalized_at, event_id) WHERE (((delivery_state)::text = ANY (ARRAY['acknowledged', 'dead_letter', 'cancelled'])) AND (archived_at IS NULL))", + "name": "ix_outbox_events_retention", + "table_name": "outbox_events" + }, + { + "definition": "CREATE UNIQUE INDEX pk_outbox_events ON public.outbox_events USING btree (event_id)", + "name": "pk_outbox_events", + "table_name": "outbox_events" + }, + { + "definition": "CREATE UNIQUE INDEX uq_outbox_events_idempotency_key ON public.outbox_events USING btree (idempotency_key)", + "name": "uq_outbox_events_idempotency_key", + "table_name": "outbox_events" + }, + { + "definition": "CREATE INDEX ix_payment_policies_project_id ON public.payment_policies USING btree (project_id)", + "name": "ix_payment_policies_project_id", + "table_name": "payment_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_payment_policies ON public.payment_policies USING btree (id)", + "name": "pk_payment_policies", + "table_name": "payment_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_payment_policies_project_version ON public.payment_policies USING btree (project_id, guide_version)", + "name": "uq_payment_policies_project_version", + "table_name": "payment_policies" + }, + { + "definition": "CREATE INDEX ix_policy_mutation_custody_lookup ON public.policy_mutation_idempotency_records USING btree (policy_id, action_id, policy_generation, status)", + "name": "ix_policy_mutation_custody_lookup", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX pk_policy_mutation_idempotency_records ON public.policy_mutation_idempotency_records USING btree (id)", + "name": "pk_policy_mutation_idempotency_records", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_policy_mutation_operation_identity ON public.policy_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_policy_mutation_operation_identity", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_policy_mutation_replay_namespace ON public.policy_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", + "name": "uq_policy_mutation_replay_namespace", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_compiled_hash ON public.pre_submit_checker_policies USING btree (compiled_bundle_hash)", + "name": "ix_pre_submit_checker_compiled_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_effective ON public.pre_submit_checker_policies USING btree (effective_policy_id)", + "name": "ix_pre_submit_checker_effective", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_effective_hash ON public.pre_submit_checker_policies USING btree (effective_policy_hash)", + "name": "ix_pre_submit_checker_effective_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_guide ON public.pre_submit_checker_policies USING btree (guide_id)", + "name": "ix_pre_submit_checker_guide", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_lifecycle ON public.pre_submit_checker_policies USING btree (lifecycle_status)", + "name": "ix_pre_submit_checker_lifecycle", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_project ON public.pre_submit_checker_policies USING btree (project_id)", + "name": "ix_pre_submit_checker_project", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_checker_source_snapshot ON public.pre_submit_checker_policies USING btree (source_snapshot_id)", + "name": "ix_pre_submit_checker_source_snapshot", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_pre_submit_checker_policies ON public.pre_submit_checker_policies USING btree (id)", + "name": "pk_pre_submit_checker_policies", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_checker_policies_id_compiled_bundle_hash ON public.pre_submit_checker_policies USING btree (id, compiled_bundle_hash)", + "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_results_evidence_set_id ON public.pre_submit_evidence_results USING btree (evidence_set_id)", + "name": "ix_pre_submit_evidence_results_evidence_set_id", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_results ON public.pre_submit_evidence_results USING btree (id)", + "name": "pk_pre_submit_evidence_results", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_definition ON public.pre_submit_evidence_results USING btree (evidence_set_id, definition_id)", + "name": "uq_pre_submit_result_definition", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_order ON public.pre_submit_evidence_results USING btree (evidence_set_id, result_order)", + "name": "uq_pre_submit_result_order", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_sets_actor_profile_id ON public.pre_submit_evidence_sets USING btree (actor_profile_id)", + "name": "ix_pre_submit_evidence_sets_actor_profile_id", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_sets_project_id ON public.pre_submit_evidence_sets USING btree (project_id)", + "name": "ix_pre_submit_evidence_sets_project_id", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE INDEX ix_pre_submit_evidence_sets_task_id ON public.pre_submit_evidence_sets USING btree (task_id)", + "name": "ix_pre_submit_evidence_sets_task_id", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_sets ON public.pre_submit_evidence_sets USING btree (id)", + "name": "pk_pre_submit_evidence_sets", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE UNIQUE INDEX uq_pre_submit_evidence_operation ON public.pre_submit_evidence_sets USING btree (operation_identity)", + "name": "uq_pre_submit_evidence_operation", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE INDEX ix_compensation_binding_adapter_actor ON public.project_compensation_adapter_bindings USING btree (adapter_actor_id, status, id)", + "name": "ix_compensation_binding_adapter_actor", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_compensation_adapter_bindings ON public.project_compensation_adapter_bindings USING btree (id)", + "name": "pk_project_compensation_adapter_bindings", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compensation_binding_active_project_instrument ON public.project_compensation_adapter_bindings USING btree (project_id, instrument_type) WHERE ((status)::text = 'active'::text)", + "name": "uq_compensation_binding_active_project_instrument", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compensation_binding_ownership ON public.project_compensation_adapter_bindings USING btree (id, project_id, instrument_type)", + "name": "uq_compensation_binding_ownership", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_compensation_units ON public.project_compensation_units USING btree (project_id, instrument_type, unit_code)", + "name": "pk_project_compensation_units", + "table_name": "project_compensation_units" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_create_idempotency_records ON public.project_create_idempotency_records USING btree (id)", + "name": "pk_project_create_idempotency_records", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_create_operation_identity ON public.project_create_idempotency_records USING btree (operation_id)", + "name": "uq_project_create_operation_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_create_project_identity ON public.project_create_idempotency_records USING btree (project_id)", + "name": "uq_project_create_project_identity", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_create_replay_namespace ON public.project_create_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", + "name": "uq_project_create_replay_namespace", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_guide_id ON public.project_guide_compilation_attempts USING btree (guide_id)", + "name": "ix_project_guide_compilation_attempts_guide_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_project_id ON public.project_guide_compilation_attempts USING btree (project_id)", + "name": "ix_project_guide_compilation_attempts_project_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_setup_run_id ON public.project_guide_compilation_attempts USING btree (setup_run_id)", + "name": "ix_project_guide_compilation_attempts_setup_run_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilation_attempts_source_snapshot_id ON public.project_guide_compilation_attempts USING btree (source_snapshot_id)", + "name": "ix_project_guide_compilation_attempts_source_snapshot_id", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_guide_compilation_attempts ON public.project_guide_compilation_attempts USING btree (id)", + "name": "pk_project_guide_compilation_attempts", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_provider_key ON public.project_guide_compilation_attempts USING btree (provider_idempotency_key)", + "name": "uq_compilation_attempt_provider_key", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_setup_generation ON public.project_guide_compilation_attempts USING btree (setup_run_id, setup_generation)", + "name": "uq_compilation_attempt_setup_generation", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_guide_id ON public.project_guide_compilations USING btree (guide_id)", + "name": "ix_project_guide_compilations_guide_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_project_id ON public.project_guide_compilations USING btree (project_id)", + "name": "ix_project_guide_compilations_project_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_setup_run_id ON public.project_guide_compilations USING btree (setup_run_id)", + "name": "ix_project_guide_compilations_setup_run_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guide_compilations_source_snapshot_id ON public.project_guide_compilations USING btree (source_snapshot_id)", + "name": "ix_project_guide_compilations_source_snapshot_id", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_guide_compilations ON public.project_guide_compilations USING btree (id)", + "name": "pk_project_guide_compilations", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_attempt ON public.project_guide_compilations USING btree (attempt_id)", + "name": "uq_project_guide_compilation_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_id_attempt ON public.project_guide_compilations USING btree (id, attempt_id)", + "name": "uq_project_guide_compilation_id_attempt", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_predecessor ON public.project_guide_compilations USING btree (supersedes_compilation_id)", + "name": "uq_project_guide_compilation_predecessor", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_root ON public.project_guide_compilations USING btree (project_id, guide_id) WHERE (supersedes_compilation_id IS NULL)", + "name": "uq_project_guide_compilation_root", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_scope ON public.project_guide_compilations USING btree (id, project_id, guide_id)", + "name": "uq_project_guide_compilation_scope", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE INDEX ix_project_guides_project_id ON public.project_guides USING btree (project_id)", + "name": "ix_project_guides_project_id", + "table_name": "project_guides" + }, + { + "definition": "CREATE INDEX ix_project_guides_status ON public.project_guides USING btree (status)", + "name": "ix_project_guides_status", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_guides ON public.project_guides USING btree (id)", + "name": "pk_project_guides", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guides_id_project_version ON public.project_guides USING btree (id, project_id, version)", + "name": "uq_project_guides_id_project_version", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guides_one_active_per_project ON public.project_guides USING btree (project_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_project_guides_one_active_per_project", + "table_name": "project_guides" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_guides_project_version ON public.project_guides USING btree (project_id, version)", + "name": "uq_project_guides_project_version", + "table_name": "project_guides" + }, + { + "definition": "CREATE INDEX ix_project_role_grants_actor_role_status ON public.project_role_grants USING btree (actor_profile_id, role, status)", + "name": "ix_project_role_grants_actor_role_status", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE INDEX ix_project_role_grants_project_actor_role_status ON public.project_role_grants USING btree (project_id, actor_profile_id, role, status)", + "name": "ix_project_role_grants_project_actor_role_status", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_role_grants ON public.project_role_grants USING btree (id)", + "name": "pk_project_role_grants", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_role_grants_active_exact_role ON public.project_role_grants USING btree (project_id, actor_profile_id, role) WHERE ((status)::text = 'active'::text)", + "name": "uq_project_role_grants_active_exact_role", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE UNIQUE INDEX grant_reference ON public.project_role_qualification_snapshots USING btree (id, actor_profile_id, project_id, requested_role)", + "name": "grant_reference", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE INDEX ix_project_role_qualification_snapshots_history ON public.project_role_qualification_snapshots USING btree (project_id, actor_profile_id, requested_role, captured_at)", + "name": "ix_project_role_qualification_snapshots_history", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_role_qualification_snapshots ON public.project_role_qualification_snapshots USING btree (id)", + "name": "pk_project_role_qualification_snapshots", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_celery_task_id ON public.project_setup_runs USING btree (celery_task_id)", + "name": "ix_project_setup_runs_celery_task_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_continuation_verification_job_id ON public.project_setup_runs USING btree (continuation_verification_job_id)", + "name": "ix_project_setup_runs_continuation_verification_job_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_error_artifact_incident_id ON public.project_setup_runs USING btree (error_artifact_incident_id)", + "name": "ix_project_setup_runs_error_artifact_incident_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_guide_id ON public.project_setup_runs USING btree (guide_id)", + "name": "ix_project_setup_runs_guide_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_output_post_submit_checker_policy_id ON public.project_setup_runs USING btree (output_post_submit_checker_policy_id)", + "name": "ix_project_setup_runs_output_post_submit_checker_policy_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_output_submission_artifact_policy_id ON public.project_setup_runs USING btree (output_submission_artifact_policy_id)", + "name": "ix_project_setup_runs_output_submission_artifact_policy_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_output_sufficiency_report_id ON public.project_setup_runs USING btree (output_sufficiency_report_id)", + "name": "ix_project_setup_runs_output_sufficiency_report_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_project_id ON public.project_setup_runs USING btree (project_id)", + "name": "ix_project_setup_runs_project_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_source_snapshot_id ON public.project_setup_runs USING btree (source_snapshot_id)", + "name": "ix_project_setup_runs_source_snapshot_id", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_project_setup_runs_status ON public.project_setup_runs USING btree (status)", + "name": "ix_project_setup_runs_status", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE UNIQUE INDEX pk_project_setup_runs ON public.project_setup_runs USING btree (id)", + "name": "pk_project_setup_runs", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_exact_generation ON public.project_setup_runs USING btree (id, project_id, guide_id, source_snapshot_id, setup_generation)", + "name": "uq_project_setup_runs_exact_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_guide_generation ON public.project_setup_runs USING btree (guide_id, setup_generation)", + "name": "uq_project_setup_runs_guide_generation", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE INDEX ix_projects_slug ON public.projects USING btree (slug)", + "name": "ix_projects_slug", + "table_name": "projects" + }, + { + "definition": "CREATE INDEX ix_projects_status ON public.projects USING btree (status)", + "name": "ix_projects_status", + "table_name": "projects" + }, + { + "definition": "CREATE UNIQUE INDEX pk_projects ON public.projects USING btree (id)", + "name": "pk_projects", + "table_name": "projects" + }, + { + "definition": "CREATE UNIQUE INDEX uq_projects_slug ON public.projects USING btree (slug)", + "name": "uq_projects_slug", + "table_name": "projects" + }, + { + "definition": "CREATE INDEX ix_review_admission_submission ON public.review_admission_idempotency_records USING btree (submission_id, status, created_at, id)", + "name": "ix_review_admission_submission", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_admission_idempotency_records ON public.review_admission_idempotency_records USING btree (id)", + "name": "pk_review_admission_idempotency_records", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_admission_checker_run ON public.review_admission_idempotency_records USING btree (admitting_checker_run_id)", + "name": "uq_review_admission_checker_run", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_admission_operation ON public.review_admission_idempotency_records USING btree (operation_id)", + "name": "uq_review_admission_operation", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_admission_replay_key ON public.review_admission_idempotency_records USING btree (idempotency_key)", + "name": "uq_review_admission_replay_key", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_review_lease_expiry ON public.review_leases USING btree (status, expires_at, id)", + "name": "ix_review_lease_expiry", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_leases ON public.review_leases USING btree (id)", + "name": "pk_review_leases", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_active_queue ON public.review_leases USING btree (review_queue_entry_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_review_lease_active_queue", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_active_reviewer ON public.review_leases USING btree (reviewer_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_review_lease_active_reviewer", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_attempt ON public.review_leases USING btree (review_queue_entry_id, attempt_generation)", + "name": "uq_review_lease_attempt", + "table_name": "review_leases" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_lease_queue_identity ON public.review_leases USING btree (review_queue_entry_id, id)", + "name": "uq_review_lease_queue_identity", + "table_name": "review_leases" + }, + { + "definition": "CREATE INDEX ix_review_policies_project_id ON public.review_policies USING btree (project_id)", + "name": "ix_review_policies_project_id", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_policies ON public.review_policies USING btree (id)", + "name": "pk_review_policies", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_policies_project_version_generation ON public.review_policies USING btree (project_id, guide_version, policy_generation)", + "name": "uq_review_policies_project_version_generation", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_policy_lineage ON public.review_policies USING btree (id, policy_generation, policy_hash)", + "name": "uq_review_policy_lineage", + "table_name": "review_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_policy_scoped_lineage ON public.review_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", + "name": "uq_review_policy_scoped_lineage", + "table_name": "review_policies" + }, + { + "definition": "CREATE INDEX ix_review_queue_preference ON public.review_queue_entries USING btree (preferred_reviewer_id, queue_state, preference_expires_at, id)", + "name": "ix_review_queue_preference", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE INDEX ix_review_queue_selection ON public.review_queue_entries USING btree (project_id, queue_state, routing_mode, first_queued_at, id)", + "name": "ix_review_queue_selection", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX pk_review_queue_entries ON public.review_queue_entries USING btree (id)", + "name": "pk_review_queue_entries", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_queue_admission_identity ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", + "name": "uq_review_queue_admission_identity", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_queue_lease_lineage ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version)", + "name": "uq_review_queue_lease_lineage", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE UNIQUE INDEX uq_review_queue_submission ON public.review_queue_entries USING btree (submission_id)", + "name": "uq_review_queue_submission", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE INDEX ix_revision_policies_project_id ON public.revision_policies USING btree (project_id)", + "name": "ix_revision_policies_project_id", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_revision_policies ON public.revision_policies USING btree (id)", + "name": "pk_revision_policies", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_revision_policies_project_version_generation ON public.revision_policies USING btree (project_id, guide_version, policy_generation)", + "name": "uq_revision_policies_project_version_generation", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_revision_policy_lineage ON public.revision_policies USING btree (id, policy_generation, policy_hash)", + "name": "uq_revision_policy_lineage", + "table_name": "revision_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_revision_policy_scoped_lineage ON public.revision_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", + "name": "uq_revision_policy_scoped_lineage", + "table_name": "revision_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_guide_id ON public.submission_artifact_policies USING btree (guide_id)", + "name": "ix_submission_artifact_policies_guide_id", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_lifecycle_status ON public.submission_artifact_policies USING btree (lifecycle_status)", + "name": "ix_submission_artifact_policies_lifecycle_status", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_policy_hash ON public.submission_artifact_policies USING btree (policy_hash)", + "name": "ix_submission_artifact_policies_policy_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_project_id ON public.submission_artifact_policies USING btree (project_id)", + "name": "ix_submission_artifact_policies_project_id", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_artifact_policies_source_snapshot_id ON public.submission_artifact_policies USING btree (source_snapshot_id)", + "name": "ix_submission_artifact_policies_source_snapshot_id", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_artifact_policies ON public.submission_artifact_policies USING btree (id)", + "name": "pk_submission_artifact_policies", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_id_hash ON public.submission_artifact_policies USING btree (id, policy_hash)", + "name": "uq_submission_artifact_policies_id_hash", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_project_version_policy ON public.submission_artifact_policies USING btree (project_id, guide_version, policy_version)", + "name": "uq_submission_artifact_policies_project_version_policy", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_actor_profile_id ON public.submission_bundle_admissions USING btree (actor_profile_id)", + "name": "ix_submission_bundle_admissions_actor_profile_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_artifact_content_id ON public.submission_bundle_admissions USING btree (artifact_content_id)", + "name": "ix_submission_bundle_admissions_artifact_content_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_pre_submit_evidence_set_id ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", + "name": "ix_submission_bundle_admissions_pre_submit_evidence_set_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_project_id ON public.submission_bundle_admissions USING btree (project_id)", + "name": "ix_submission_bundle_admissions_project_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_status ON public.submission_bundle_admissions USING btree (status)", + "name": "ix_submission_bundle_admissions_status", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_admissions_task_id ON public.submission_bundle_admissions USING btree (task_id)", + "name": "ix_submission_bundle_admissions_task_id", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_bundle_admissions ON public.submission_bundle_admissions USING btree (id)", + "name": "pk_submission_bundle_admissions", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_consumer ON public.submission_bundle_admissions USING btree (consumed_by_submission_id) WHERE (consumed_by_submission_id IS NOT NULL)", + "name": "uq_submission_bundle_admission_consumer", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_evidence ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", + "name": "uq_submission_bundle_admission_evidence", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_intent ON public.submission_bundle_admissions USING btree (durable_intent_id)", + "name": "uq_submission_bundle_admission_intent", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_verification ON public.submission_bundle_admissions USING btree (verification_receipt_id)", + "name": "uq_submission_bundle_admission_verification", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_durable_intents_pre_submit_evidence_set_id ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", + "name": "ix_submission_bundle_durable_intents_pre_submit_evidence_set_id", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE INDEX ix_submission_bundle_durable_intents_put_attempt_id ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", + "name": "ix_submission_bundle_durable_intents_put_attempt_id", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_bundle_durable_intents ON public.submission_bundle_durable_intents USING btree (id)", + "name": "pk_submission_bundle_durable_intents", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_evidence ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", + "name": "uq_submission_bundle_intent_evidence", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_put_attempt ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", + "name": "uq_submission_bundle_intent_put_attempt", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submission_policy_mutation_idempotency_records ON public.submission_policy_mutation_idempotency_records USING btree (id)", + "name": "pk_submission_policy_mutation_idempotency_records", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_committed_policy_action ON public.submission_policy_mutation_idempotency_records USING btree (committed_policy_id, action_id) WHERE ((status)::text = 'committed'::text)", + "name": "uq_submission_policy_committed_policy_action", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_human_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key) WHERE (service_identity IS NULL)", + "name": "uq_submission_policy_human_replay_namespace", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_operation_identity ON public.submission_policy_mutation_idempotency_records USING btree (operation_id)", + "name": "uq_submission_policy_operation_identity", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submission_policy_service_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, setup_run_id, setup_generation, setup_task_id, correlation_id, action_id) WHERE (service_identity IS NOT NULL)", + "name": "uq_submission_policy_service_replay_namespace", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE INDEX ix_submissions_contributor_id ON public.submissions USING btree (contributor_id)", + "name": "ix_submissions_contributor_id", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_effective_policy_hash ON public.submissions USING btree (locked_effective_project_submission_artifact_policy_hash)", + "name": "ix_submissions_locked_effective_policy_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_post_submit_policy_hash ON public.submissions USING btree (locked_post_submit_checker_policy_hash)", + "name": "ix_submissions_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_pre_submit_checker_hash ON public.submissions USING btree (locked_pre_submit_checker_bundle_hash)", + "name": "ix_submissions_locked_pre_submit_checker_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_locked_source_snapshot ON public.submissions USING btree (locked_guide_source_snapshot_id)", + "name": "ix_submissions_locked_source_snapshot", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_status ON public.submissions USING btree (status)", + "name": "ix_submissions_status", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_supersedes_submission_id ON public.submissions USING btree (supersedes_submission_id)", + "name": "ix_submissions_supersedes_submission_id", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_submissions_task_id ON public.submissions USING btree (task_id)", + "name": "ix_submissions_task_id", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX pk_submissions ON public.submissions USING btree (id)", + "name": "pk_submissions", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_id_locked_post_submit_policy_hash ON public.submissions USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "name": "uq_submissions_id_locked_post_submit_policy_hash", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_id_task_version ON public.submissions USING btree (id, task_id, version)", + "name": "uq_submissions_id_task_version", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_id_version ON public.submissions USING btree (id, version)", + "name": "uq_submissions_id_version", + "table_name": "submissions" + }, + { + "definition": "CREATE UNIQUE INDEX uq_submissions_task_version ON public.submissions USING btree (task_id, version)", + "name": "uq_submissions_task_version", + "table_name": "submissions" + }, + { + "definition": "CREATE INDEX ix_task_assignments_contributor_id ON public.task_assignments USING btree (contributor_id)", + "name": "ix_task_assignments_contributor_id", + "table_name": "task_assignments" + }, + { + "definition": "CREATE INDEX ix_task_assignments_status ON public.task_assignments USING btree (status)", + "name": "ix_task_assignments_status", + "table_name": "task_assignments" + }, + { + "definition": "CREATE INDEX ix_task_assignments_task_id ON public.task_assignments USING btree (task_id)", + "name": "ix_task_assignments_task_id", + "table_name": "task_assignments" + }, + { + "definition": "CREATE UNIQUE INDEX pk_task_assignments ON public.task_assignments USING btree (id)", + "name": "pk_task_assignments", + "table_name": "task_assignments" + }, + { + "definition": "CREATE UNIQUE INDEX uq_task_assignments_id_task_contributor ON public.task_assignments USING btree (id, task_id, contributor_id)", + "name": "uq_task_assignments_id_task_contributor", + "table_name": "task_assignments" + }, + { + "definition": "CREATE UNIQUE INDEX uq_task_assignments_one_active_per_task ON public.task_assignments USING btree (task_id) WHERE ((status)::text = 'active'::text)", + "name": "uq_task_assignments_one_active_per_task", + "table_name": "task_assignments" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_assigned_to ON public.workstream_tasks USING btree (assigned_to)", + "name": "ix_workstream_tasks_assigned_to", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_effective_policy_hash ON public.workstream_tasks USING btree (locked_effective_project_submission_artifact_policy_hash)", + "name": "ix_workstream_tasks_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (locked_post_submit_checker_policy_hash)", + "name": "ix_workstream_tasks_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (locked_pre_submit_checker_bundle_hash)", + "name": "ix_workstream_tasks_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_locked_source_snapshot ON public.workstream_tasks USING btree (locked_guide_source_snapshot_id)", + "name": "ix_workstream_tasks_locked_source_snapshot", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_project_id ON public.workstream_tasks USING btree (project_id)", + "name": "ix_workstream_tasks_project_id", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE INDEX ix_workstream_tasks_status ON public.workstream_tasks USING btree (status)", + "name": "ix_workstream_tasks_status", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX pk_workstream_tasks ON public.workstream_tasks USING btree (id)", + "name": "pk_workstream_tasks", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_effective_policy_hash ON public.workstream_tasks USING btree (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", + "name": "uq_workstream_tasks_id_locked_effective_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_guide ON public.workstream_tasks USING btree (id, locked_guide_version)", + "name": "uq_workstream_tasks_id_locked_guide", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_payment_policy ON public.workstream_tasks USING btree (id, locked_payment_policy_version)", + "name": "uq_workstream_tasks_id_locked_payment_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", + "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", + "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_review_policy ON public.workstream_tasks USING btree (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", + "name": "uq_workstream_tasks_id_locked_review_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_revision_policy ON public.workstream_tasks USING btree (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", + "name": "uq_workstream_tasks_id_locked_revision_policy", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_source_snapshot_hash ON public.workstream_tasks USING btree (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", + "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", + "table_name": "workstream_tasks" + }, + { + "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_project ON public.workstream_tasks USING btree (id, project_id)", + "name": "uq_workstream_tasks_id_project", + "table_name": "workstream_tasks" + } + ], + "policies": [], + "reference_rows": { + "actor_profile_migration_state": [ + { + "classified_count": 0, + "envelope_sha256": null, + "id": 1, + "manifest_sha256": null, + "migrated_at": "2026-08-11T08:18:03.063940+00:00", + "schema_version": 1, + "service_identity_database_binding": "postgres-v1:aa1108b4a868ca4330673d1bbe499d99c330d196994696d89e56cf09bfc3c93e", + "service_identity_envelope_sha256": null, + "service_identity_manifest_sha256": null, + "service_identity_mapped_count": 0, + "service_identity_source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945", + "source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" + } + ], + "authority_control": [ + { + "bootstrap_completed": false, + "bootstrap_grant_id": null, + "created_at": "2026-08-11T08:18:13.474128+00:00", + "id": 1, + "updated_at": "2026-08-11T08:18:13.474148+00:00", + "version": 0 + } + ], + "iso_4217_currency_codes": [ + { + "code": "AED" + }, + { + "code": "AFN" + }, + { + "code": "ALL" + }, + { + "code": "AMD" + }, + { + "code": "AOA" + }, + { + "code": "ARS" + }, + { + "code": "AUD" + }, + { + "code": "AWG" + }, + { + "code": "AZN" + }, + { + "code": "BAM" + }, + { + "code": "BBD" + }, + { + "code": "BDT" + }, + { + "code": "BHD" + }, + { + "code": "BIF" + }, + { + "code": "BMD" + }, + { + "code": "BND" + }, + { + "code": "BOB" + }, + { + "code": "BOV" + }, + { + "code": "BRL" + }, + { + "code": "BSD" + }, + { + "code": "BTN" + }, + { + "code": "BWP" + }, + { + "code": "BYN" + }, + { + "code": "BZD" + }, + { + "code": "CAD" + }, + { + "code": "CDF" + }, + { + "code": "CHE" + }, + { + "code": "CHF" + }, + { + "code": "CHW" + }, + { + "code": "CLF" + }, + { + "code": "CLP" + }, + { + "code": "CNY" + }, + { + "code": "COP" + }, + { + "code": "COU" + }, + { + "code": "CRC" + }, + { + "code": "CUP" + }, + { + "code": "CVE" + }, + { + "code": "CZK" + }, + { + "code": "DJF" + }, + { + "code": "DKK" + }, + { + "code": "DOP" + }, + { + "code": "DZD" + }, + { + "code": "EGP" + }, + { + "code": "ERN" + }, + { + "code": "ETB" + }, + { + "code": "EUR" + }, + { + "code": "FJD" + }, + { + "code": "FKP" + }, + { + "code": "GBP" + }, + { + "code": "GEL" + }, + { + "code": "GHS" + }, + { + "code": "GIP" + }, + { + "code": "GMD" + }, + { + "code": "GNF" + }, + { + "code": "GTQ" + }, + { + "code": "GYD" + }, + { + "code": "HKD" + }, + { + "code": "HNL" + }, + { + "code": "HTG" + }, + { + "code": "HUF" + }, + { + "code": "IDR" + }, + { + "code": "ILS" + }, + { + "code": "INR" + }, + { + "code": "IQD" + }, + { + "code": "IRR" + }, + { + "code": "ISK" + }, + { + "code": "JMD" + }, + { + "code": "JOD" + }, + { + "code": "JPY" + }, + { + "code": "KES" + }, + { + "code": "KGS" + }, + { + "code": "KHR" + }, + { + "code": "KMF" + }, + { + "code": "KPW" + }, + { + "code": "KRW" + }, + { + "code": "KWD" + }, + { + "code": "KYD" + }, + { + "code": "KZT" + }, + { + "code": "LAK" + }, + { + "code": "LBP" + }, + { + "code": "LKR" + }, + { + "code": "LRD" + }, + { + "code": "LSL" + }, + { + "code": "LYD" + }, + { + "code": "MAD" + }, + { + "code": "MDL" + }, + { + "code": "MGA" + }, + { + "code": "MKD" + }, + { + "code": "MMK" + }, + { + "code": "MNT" + }, + { + "code": "MOP" + }, + { + "code": "MRU" + }, + { + "code": "MUR" + }, + { + "code": "MVR" + }, + { + "code": "MWK" + }, + { + "code": "MXN" + }, + { + "code": "MXV" + }, + { + "code": "MYR" + }, + { + "code": "MZN" + }, + { + "code": "NAD" + }, + { + "code": "NGN" + }, + { + "code": "NIO" + }, + { + "code": "NOK" + }, + { + "code": "NPR" + }, + { + "code": "NZD" + }, + { + "code": "OMR" + }, + { + "code": "PAB" + }, + { + "code": "PEN" + }, + { + "code": "PGK" + }, + { + "code": "PHP" + }, + { + "code": "PKR" + }, + { + "code": "PLN" + }, + { + "code": "PYG" + }, + { + "code": "QAR" + }, + { + "code": "RON" + }, + { + "code": "RSD" + }, + { + "code": "RUB" + }, + { + "code": "RWF" + }, + { + "code": "SAR" + }, + { + "code": "SBD" + }, + { + "code": "SCR" + }, + { + "code": "SDG" + }, + { + "code": "SEK" + }, + { + "code": "SGD" + }, + { + "code": "SHP" + }, + { + "code": "SLE" + }, + { + "code": "SOS" + }, + { + "code": "SRD" + }, + { + "code": "SSP" + }, + { + "code": "STN" + }, + { + "code": "SVC" + }, + { + "code": "SYP" + }, + { + "code": "SZL" + }, + { + "code": "THB" + }, + { + "code": "TJS" + }, + { + "code": "TMT" + }, + { + "code": "TND" + }, + { + "code": "TOP" + }, + { + "code": "TRY" + }, + { + "code": "TTD" + }, + { + "code": "TWD" + }, + { + "code": "TZS" + }, + { + "code": "UAH" + }, + { + "code": "UGX" + }, + { + "code": "USD" + }, + { + "code": "USN" + }, + { + "code": "UYI" + }, + { + "code": "UYU" + }, + { + "code": "UYW" + }, + { + "code": "UZS" + }, + { + "code": "VED" + }, + { + "code": "VES" + }, + { + "code": "VND" + }, + { + "code": "VUV" + }, + { + "code": "WST" + }, + { + "code": "XAD" + }, + { + "code": "XAF" + }, + { + "code": "XAG" + }, + { + "code": "XAU" + }, + { + "code": "XBA" + }, + { + "code": "XBB" + }, + { + "code": "XBC" + }, + { + "code": "XBD" + }, + { + "code": "XCD" + }, + { + "code": "XCG" + }, + { + "code": "XDR" + }, + { + "code": "XOF" + }, + { + "code": "XPD" + }, + { + "code": "XPF" + }, + { + "code": "XPT" + }, + { + "code": "XSU" + }, + { + "code": "XTS" + }, + { + "code": "XUA" + }, + { + "code": "XXX" + }, + { + "code": "YER" + }, + { + "code": "ZAR" + }, + { + "code": "ZMW" + }, + { + "code": "ZWG" + } + ] + }, + "routines": [ + { + "arguments": "event_name text, before_state json, after_state json, envelope_project_id text", + "definition": "CREATE OR REPLACE FUNCTION public.authority_event_facts_are_safe(event_name text, before_state json, after_state json, envelope_project_id text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE AS $function$ begin if not (event_name='AuthorityInvalidationRequested' and before_state is not null and after_state is not null and coalesce(before_state::jsonb ? 'future_obligation', false) and coalesce(after_state::jsonb ? 'future_obligation', false)) and ((before_state is not null and not authority_facts_are_safe(before_state)) or (after_state is not null and not authority_facts_are_safe(after_state))) then return false; end if; case event_name when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"human\",\"provisioning_method\":\"automatic_first_access\"}'::jsonb; when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"service\",\"provisioning_method\":\"manual_service_provisioning\"}'::jsonb; when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( '{\"status\":\"active\",\"subject_kind\":\"human\"}'::jsonb, '{\"status\":\"active\",\"subject_kind\":\"service\"}'::jsonb); when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"revoked\"}'::jsonb; when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{\"status\":\"revoked\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileSuspended' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"suspended\"}'::jsonb; when 'ActorProfileReactivated' then return before_state::jsonb='{\"status\":\"suspended\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileDeactivated' then return before_state::jsonb in ('{\"status\":\"active\"}'::jsonb,'{\"status\":\"suspended\"}'::jsonb) and after_state::jsonb='{\"status\":\"deactivated\"}'::jsonb; when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','adjudicator'],'active',true,envelope_project_id); when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then return authority_grant_facts_are_safe(before_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'active',true,envelope_project_id) and authority_grant_facts_are_safe(after_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'revoked',false,envelope_project_id) and before_state->>'role'=after_state->>'role' and before_state->>'scope_type'=after_state->>'scope_type' and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{\"status\":\"captured\"}'::jsonb; when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; when 'SensitiveAuthorizationAllowed' then return before_state is null and ( after_state::jsonb = '{\"allowed\": true}'::jsonb or ( after_state::jsonb->'allowed' = 'true'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'SensitiveAuthorizationDenied' then return before_state is null and ( after_state::jsonb = '{\"allowed\": false}'::jsonb or ( after_state::jsonb->'allowed' = 'false'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'AuthorityInvalidationRequested' then return (before_state::jsonb = '{\"effective\": true}'::jsonb and after_state::jsonb = '{\"effective\": false}'::jsonb) or (before_state::jsonb = '{\"effective\": false}'::jsonb and after_state::jsonb = '{\"effective\": true}'::jsonb) or ( jsonb_typeof(before_state::jsonb)='object' and jsonb_typeof(after_state::jsonb)='object' and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and before_state::jsonb->'effective'='true'::jsonb and after_state::jsonb->'effective'='false'::jsonb and jsonb_typeof(before_state::jsonb->'role')='string' and jsonb_typeof(before_state::jsonb->'scope_type')='string' and jsonb_typeof(before_state::jsonb->'scope_id')='string' and jsonb_typeof(before_state::jsonb->'future_obligation')='string' and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') and before_state::jsonb->>'scope_type'='project' and before_state::jsonb->>'scope_id'=envelope_project_id and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) ); else return false; end case; end $function$", + "name": "authority_event_facts_are_safe" + }, + { + "arguments": "facts json", + "definition": "CREATE OR REPLACE FUNCTION public.authority_facts_are_safe(facts json) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select json_typeof(facts) = 'object' and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) and not exists ( select 1 from json_each(facts) item where item.key not in ( 'status', 'subject_kind', 'provisioning_method', 'role', 'scope_type', 'scope_id', 'effective', 'allowed', 'resource_context_digest' ) or case item.key when 'status' then item.value #>> '{}' not in ( 'active', 'suspended', 'deactivated', 'revoked', 'captured' ) when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') when 'provisioning_method' then item.value #>> '{}' not in ( 'automatic_first_access', 'manual_service_provisioning' ) when 'role' then item.value #>> '{}' not in ( 'access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' ) when 'scope_type' then item.value #>> '{}' not in ('system', 'project') when 'scope_id' then (item.value #>> '{}') !~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' when 'effective' then json_typeof(item.value) <> 'boolean' when 'allowed' then json_typeof(item.value) <> 'boolean' when 'resource_context_digest' then (item.value #>> '{}') !~ '^sha256:[0-9a-f]{64}$' else true end ) $function$", + "name": "authority_facts_are_safe" + }, + { + "arguments": "facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text", + "definition": "CREATE OR REPLACE FUNCTION public.authority_grant_facts_are_safe(facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text) RETURNS boolean LANGUAGE sql IMMUTABLE AS $function$ select authority_facts_are_safe(facts) and facts->>'role' = any(roles) and facts->>'status' = expected_status and (facts->>'effective')::boolean = expected_effective and ( ( facts->>'scope_type' = 'system' and envelope_project_id is null and not facts::jsonb ? 'scope_id' and facts->>'role' not in ('submitter', 'reviewer', 'both') and (select count(*) from json_each(facts)) = 4 ) or ( facts->>'scope_type' = 'project' and envelope_project_id is not null and facts->>'scope_id' = envelope_project_id and facts->>'role' not in ('access_administrator', 'operator') and (select count(*) from json_each(facts)) = 5 ) ) $function$", + "name": "authority_grant_facts_are_safe" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.enforce_compensation_binding_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compensation_binding_updates_deferred'; return new; end; $function$", + "name": "enforce_compensation_binding_lifecycle" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_identity_link_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then raise exception 'actor identity link anchor is immutable' using errcode='55000'; end if; if new.status=old.status and (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'identity link attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='revoked' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid identity link revocation attribution' using errcode='23514'; end if; if old.status='revoked' and new.status='active' and ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then raise exception 'invalid identity link reactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status='revoked') or (old.status='revoked' and new.status='active')) then raise exception 'invalid identity link lifecycle transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_actor_identity_link_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_profile_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then raise exception 'actor profile identity is immutable' using errcode='55000'; end if; if old.status='deactivated' and new.status <> 'deactivated' then raise exception 'deactivated actor is terminal' using errcode='23514'; end if; if new.status = old.status and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='suspended' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'invalid actor suspension attribution' using errcode='23514'; end if; if old.status='suspended' and new.status='active' and ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then raise exception 'invalid actor reactivation attribution' using errcode='23514'; end if; if new.status='deactivated' and old.status in ('active','suspended') and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid actor deactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status in ('suspended','deactivated')) or (old.status='suspended' and new.status in ('active','deactivated'))) then raise exception 'invalid actor lifecycle transition' using errcode='23514'; end if; new.updated_at = statement_timestamp(); return new; end $function$", + "name": "guard_actor_profile_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_admin_role_grant() RETURNS trigger LANGUAGE plpgsql AS $function$ declare target_kind text; authorizer admin_role_grants%rowtype; bootstrap_done boolean; begin if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; if tg_op='INSERT' then select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; new.granted_at := clock_timestamp(); if new.granted_by_system_principal is not null then if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; if bootstrap_done is distinct from false or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then raise exception 'bootstrap already completed' using errcode='23514'; end if; else select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; end if; return new; end if; if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, new.granted_by_actor_profile_id,new.granted_by_system_principal, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, old.granted_by_actor_profile_id,old.granted_by_system_principal, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then raise exception 'invalid admin role grant transition' using errcode='23514'; end if; select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", + "name": "guard_admin_role_grant" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_artifact_receipt_producer_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id; if request_type is null or (request_type = 'guide' and not ( new.guide_source_item_id is not null and new.checker_run_id is null and new.logical_role is null)) or (request_type = 'checker_output' and not ( new.guide_source_item_id is null and new.checker_run_id is not null and octet_length(new.logical_role) between 1 and 100)) or (request_type = 'submission_bundle' and not ( new.guide_source_item_id is null and new.checker_run_id is null and new.logical_role is null)) then raise exception 'artifact receipt producer reference mismatch' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_artifact_receipt_producer_reference" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_control() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; if old.id <> 1 or old.bootstrap_completed or old.version <> 0 or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then raise exception 'invalid authority control transition' using errcode='23514'; end if; new.updated_at := clock_timestamp(); return new; end $function$", + "name": "guard_authority_control" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_idempotency_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare success_count integer; invalidation_count integer; success_id text; qualification_row audit_events%rowtype; success_row audit_events%rowtype; grant_row project_role_grants%rowtype; snapshot_row project_role_qualification_snapshots%rowtype; begin if tg_op = 'INSERT' then if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; new.created_at := statement_timestamp(); new.committed_at := null; return new; elsif tg_op = 'DELETE' then raise exception 'authority idempotency records are immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, new.request_digest,new.created_at) is distinct from (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, old.request_digest,old.created_at) then raise exception 'invalid authority idempotency transition' using errcode='23514'; end if; select count(*), min(id) into success_count, success_id from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type <> 'AuthorityInvalidationRequested'; select count(*) into invalidation_count from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type='AuthorityInvalidationRequested'; if new.operation='project_role_grant.issue' then if success_count <> 2 or invalidation_count <> 0 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued') <> 1 then raise exception 'project role issue evidence pair required' using errcode='23514'; end if; select * into qualification_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured'; select * into success_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued'; select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; select * into snapshot_row from project_role_qualification_snapshots where id=qualification_row.resource_id::uuid; if not found or grant_row.id is null or snapshot_row.id is null or grant_row.qualification_snapshot_id <> snapshot_row.id or grant_row.project_id <> snapshot_row.project_id or grant_row.actor_profile_id <> snapshot_row.actor_profile_id or grant_row.role <> snapshot_row.requested_role or qualification_row.project_id is distinct from grant_row.project_id or success_row.project_id is distinct from grant_row.project_id or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id or success_row.target_actor_ref is distinct from grant_row.actor_profile_id or qualification_row.request_id is distinct from success_row.request_id or qualification_row.correlation_id is distinct from success_row.correlation_id or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind or qualification_row.actor_id is distinct from success_row.actor_id or qualification_row.permission_id is distinct from success_row.permission_id or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then raise exception 'project role issue evidence mismatch' using errcode='23514'; end if; else if success_count <> 1 or invalidation_count <> 1 then raise exception 'authority evidence pair required' using errcode='23514'; end if; select * into success_row from audit_events where id=success_id; end if; if success_row.resource_type <> new.response_resource_type or success_row.resource_id <> new.response_resource_id::text then raise exception 'authority response does not match evidence' using errcode='23514'; end if; new.committed_at := statement_timestamp(); return new; end $function$", + "name": "guard_authority_idempotency_record" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_children() RETURNS trigger LANGUAGE plpgsql AS $function$ declare old_parent_status text; declare new_parent_status text; begin if tg_op in ('UPDATE','DELETE') then select status into old_parent_status from contribution_policy_versions where id=old.contribution_policy_version_id for update; end if; if tg_op in ('INSERT','UPDATE') then select status into new_parent_status from contribution_policy_versions where id=new.contribution_policy_version_id for update; end if; if old_parent_status in ('published','retired') or new_parent_status in ('published','retired') then raise exception 'published contribution policy rules and definitions are immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", + "name": "guard_contribution_policy_children" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_version_content() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' and old.status in ('published','retired') then raise exception 'published contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='retired' then raise exception 'retired contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='published' and not ( new.status='retired' and new.id=old.id and new.contribution_policy_id=old.contribution_policy_id and new.project_id=old.project_id and new.version_number=old.version_number and new.created_by=old.created_by and new.created_at=old.created_at and new.published_by=old.published_by and new.published_at=old.published_at and new.retired_by is not null and new.retired_at is not null ) then raise exception 'published contribution policy version content is immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", + "name": "guard_contribution_policy_version_content" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_lineage_and_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if (new.id,new.project_id,new.version) is distinct from (old.id,old.project_id,old.version) then raise exception 'guide identity and lineage are immutable' using errcode='23514'; end if; if (new.status,new.approved_by,new.effective_at,new.superseded_at) is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then raise exception 'guide lifecycle mutation requires activation authority' using errcode='23514'; end if; return new; end $function$", + "name": "guard_guide_lineage_and_lifecycle" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_mutation_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'guide mutation custody is immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status<>'pending' or new.status<>'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, new.operation_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, old.operation_generation,old.created_at) then raise exception 'invalid guide mutation custody transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_guide_mutation_idempotency" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_iso_4217_currency_codes() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' using errcode='55000'; end; $function$", + "name": "guard_iso_4217_currency_codes" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_outbox_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare event_time timestamptz; begin if tg_op = 'TRUNCATE' then raise exception 'outbox events cannot be truncated' using errcode='55000'; elsif tg_op = 'DELETE' then raise exception 'outbox events cannot be deleted' using errcode='55000'; elsif tg_op = 'INSERT' then event_time := statement_timestamp(); new.producer := 'workstream'; new.occurred_at := event_time; new.delivery_state := 'pending'; new.attempt_count := 0; new.next_attempt_at := event_time; new.claim_owner := null; new.claim_generation := 0; new.claimed_at := null; new.claim_expires_at := null; new.last_attempt_at := null; new.last_error_code := null; new.finalized_at := null; new.archived_at := null; return new; end if; if (new.event_id, new.event_type, new.event_version, new.producer, new.aggregate_type, new.aggregate_id, new.project_id, new.correlation_id, new.causation_event_id, new.idempotency_key, new.payload, new.payload_digest, new.occurred_at) is distinct from (old.event_id, old.event_type, old.event_version, old.producer, old.aggregate_type, old.aggregate_id, old.project_id, old.correlation_id, old.causation_event_id, old.idempotency_key, old.payload, old.payload_digest, old.occurred_at) then raise exception 'outbox event envelope is immutable' using errcode='55000'; end if; if new.attempt_count < old.attempt_count or new.claim_generation < old.claim_generation or new.attempt_count <> new.claim_generation then raise exception 'outbox counters cannot regress' using errcode='23514'; end if; if old.archived_at is not null and (new.delivery_state, new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.delivery_state, old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'archived outbox event is closed' using errcode='55000'; end if; if old.delivery_state in ('pending', 'retryable') and new.delivery_state = 'claimed' then if new.attempt_count <> old.attempt_count + 1 or new.claim_generation <> old.claim_generation + 1 or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox claim generation must increment once' using errcode='23514'; end if; elsif old.delivery_state = 'claimed' and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at then raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state = 'dead_letter' and new.delivery_state = 'retryable' and old.archived_at is null then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = 'cancelled' then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.attempt_count, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; end if; elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at) is distinct from (old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at) or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) or (old.archived_at is null and new.archived_at is null) then raise exception 'terminal outbox event permits archival only' using errcode='23514'; end if; else raise exception 'illegal outbox delivery transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_outbox_event" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_policy_mutation_replay() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'policy mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'policy mutation replay is immutable' using errcode='55000'; elsif new is not distinct from old then return new; elsif old.status='pending' and new.status='committed' and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest,new.policy_hash, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.policy_id, new.policy_generation,new.created_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest,old.policy_hash, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.policy_id, old.policy_generation,old.created_at) then return new; end if; raise exception 'policy mutation replay is immutable' using errcode='23514'; end $function$", + "name": "guard_policy_mutation_replay" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_result_membership() RETURNS trigger LANGUAGE plpgsql AS $function$ declare parent_created_at timestamptz; expected_count integer; current_count integer; begin select created_at, result_count into parent_created_at, expected_count from pre_submit_evidence_sets where id=new.evidence_set_id for key share; select count(*) into current_count from pre_submit_evidence_results where evidence_set_id=new.evidence_set_id; if parent_created_at is null or parent_created_at <> transaction_timestamp() or current_count >= expected_count then raise exception 'pre-submit evidence result membership is closed' using errcode='55000'; end if; return new; end; $function$", + "name": "guard_pre_submit_evidence_result_membership" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_results_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_results rows are immutable' using errcode='55000'; end; $function$", + "name": "guard_pre_submit_evidence_results_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_set_creation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.created_at is distinct from transaction_timestamp() then raise exception 'pre-submit evidence creation timestamp is invalid' using errcode='55000'; end if; return new; end; $function$", + "name": "guard_pre_submit_evidence_set_creation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_sets_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_sets rows are immutable' using errcode='55000'; end; $function$", + "name": "guard_pre_submit_evidence_sets_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_compensation_units() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('UPDATE','DELETE') then raise exception 'project compensation-unit lifecycle behavior is deferred' using errcode='55000'; end if; if new.status <> 'active' then raise exception 'project compensation units must begin active' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_project_compensation_units" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_create_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'INSERT' then if new.status <> 'pending' or new.committed_at is not null then raise exception 'project create reservation must begin pending' using errcode='23514'; end if; return new; elsif tg_op = 'DELETE' then raise exception 'project create reservations are immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, new.idempotency_key, new.request_digest, new.operation_id, new.project_id, new.operation_generation, new.created_at) is distinct from (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, old.idempotency_key, old.request_digest, old.operation_id, old.project_id, old.operation_generation, old.created_at) then raise exception 'invalid project create reservation transition' using errcode='23514'; end if; return new; end $function$", + "name": "guard_project_create_idempotency" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_attempt_update() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, new.pre_catalogue_version,new.pre_catalogue_schema_version, new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.provider_idempotency_key) is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, old.source_snapshot_hash,old.setup_run_id,old.setup_generation, old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, old.pre_catalogue_version,old.pre_catalogue_schema_version, old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, old.agent_identity,old.agent_version,old.instruction_version, old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; if new.reserved_at is distinct from old.reserved_at then raise exception 'compilation reservation timestamp is immutable'; end if; if new.provider_uncertain_at is distinct from old.provider_uncertain_at and not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then raise exception 'provider uncertainty timestamp is immutable'; end if; if new.accepted_at is distinct from old.accepted_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then raise exception 'accepted timestamp is immutable'; end if; if new.terminal_at is distinct from old.terminal_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then raise exception 'terminal timestamp is immutable'; end if; if row(new.persisted_at,new.persisted_compilation_id) is distinct from row(old.persisted_at,old.persisted_compilation_id) and not (old.status='provider_result_accepted' and new.status='compilation_persisted') then raise exception 'persisted custody is immutable'; end if; if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then raise exception 'accepted compilation result is immutable'; end if; if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or (old.status='provider_result_accepted' and new.status='compilation_persisted')) then raise exception 'invalid compilation attempt transition'; end if; return new; end $function$", + "name": "guard_project_guide_compilation_attempt_update" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_insert() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor_generation bigint; declare source_attempt project_guide_compilation_attempts%rowtype; begin select * into source_attempt from project_guide_compilation_attempts where id=new.attempt_id for update; if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash, new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) is distinct from row(source_attempt.project_id,source_attempt.guide_id, source_attempt.guide_version,source_attempt.source_snapshot_id, source_attempt.source_snapshot_hash,source_attempt.setup_run_id, source_attempt.setup_generation,source_attempt.canonical_input_hash, source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, source_attempt.agent_version,source_attempt.instruction_version, source_attempt.canonical_result::jsonb,source_attempt.result_hash, source_attempt.component_hashes::jsonb) then raise exception 'compilation does not match its accepted attempt'; end if; if not exists( select 1 from audit_events event join actor_profiles profile on profile.id=new.created_by_actor_profile_id join actor_identity_links link on link.id=new.created_via_identity_link_id and link.actor_profile_id=profile.id where event.id=new.authorization_decision_event_id and event.event_domain='authority' and event.event_type='SensitiveAuthorizationAllowed' and event.denial_code is null and event.actor_id=new.created_by_actor_profile_id and event.permission_id='project.guide_compilation.execute' and event.action_id='project.guide_compilation.execute' and event.project_id=new.project_id and event.resource_type='project_guide_compilation_attempt' and event.resource_id=new.attempt_id::text and event.after_facts->>'allowed'='true' and event.after_facts->>'resource_context_digest'= new.authorization_resource_context_digest and profile.actor_kind='service' and profile.status='active' and profile.service_identity='workstream.project.setup' and link.subject_kind='service' and link.status='active' and link.issuer='workstream-internal' and link.subject='workstream.project.setup' ) then raise exception 'compilation authorization evidence is invalid'; end if; if new.supersedes_compilation_id is null then return new; end if; select setup_generation into predecessor_generation from project_guide_compilations where id=new.supersedes_compilation_id and project_id=new.project_id and guide_id=new.guide_id; if predecessor_generation is null or predecessor_generation >= new.setup_generation then raise exception 'compilation generation must strictly advance'; end if; return new; end $function$", + "name": "guard_project_guide_compilation_insert" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_policy_selection() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.status in ('active','superseded') and ( new.selected_review_policy_id is distinct from old.selected_review_policy_id or new.selected_review_policy_generation is distinct from old.selected_review_policy_generation or new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or new.selected_revision_policy_generation is distinct from old.selected_revision_policy_generation or new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash ) then raise exception 'active guide policy selection is immutable' using errcode='55000'; end if; return new; end $function$", + "name": "guard_project_guide_policy_selection" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_grant_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, new.qualification_snapshot_id,new.granted_by_actor_profile_id, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, old.qualification_snapshot_id,old.granted_by_actor_profile_id, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null or new.revoked_reason is null then raise exception 'invalid project-role grant history transition' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", + "name": "guard_project_role_grant_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_snapshot_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; end $function$", + "name": "guard_project_role_snapshot_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_admission_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review admission records cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' and new.status <> 'pending' then raise exception 'review admission must begin pending' using errcode='23514'; end if; if tg_op='INSERT' then new.created_at := statement_timestamp(); end if; if tg_op='UPDATE' then if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.created_at) is distinct from (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.created_at) then raise exception 'review admission identity is immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' then raise exception 'invalid review admission transition' using errcode='23514'; end if; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review admission task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review admission checker lineage mismatch' using errcode='23514'; end if; if new.status='committed' and ( checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true) then raise exception 'review admission checker is not admissible' using errcode='23514'; end if; return new; end $function$", + "name": "guard_review_admission_record" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare actor_type text; policy_status text; begin if tg_op='DELETE' then raise exception 'review leases cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.status <> 'active' then raise exception 'review lease must begin active' using errcode='23514'; end if; new.claimed_at := statement_timestamp(); new.closed_at := null; new.close_reason := null; else if old.status <> 'active' then raise exception 'terminal review leases are immutable' using errcode='55000'; end if; if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, new.submission_version,new.reviewer_id, new.reviewer_contribution_policy_version_id,new.attempt_generation, new.claimed_at,new.expires_at) is distinct from (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, old.submission_version,old.reviewer_id, old.reviewer_contribution_policy_version_id,old.attempt_generation, old.claimed_at,old.expires_at) then raise exception 'review lease identity is immutable' using errcode='55000'; end if; if new.status='active' then raise exception 'review lease update must close attempt' using errcode='23514'; end if; end if; select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; if actor_type is distinct from 'human' then raise exception 'review lease reviewer must be human' using errcode='23514'; end if; if tg_op='INSERT' then select status into policy_status from contribution_policy_versions where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; if policy_status is distinct from 'published' then raise exception 'review lease policy version must be published' using errcode='23514'; end if; end if; return new; end $function$", + "name": "guard_review_lease" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review_policies rows are immutable' using errcode='55000'; end $function$", + "name": "guard_review_policies_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_review_queue_entry() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review queue entries cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.queue_state <> 'pending' then raise exception 'review queue must begin pending' using errcode='23514'; end if; new.first_queued_at := statement_timestamp(); new.available_since := new.first_queued_at; new.routing_generation := 1; new.lifecycle_generation := 1; new.created_at := new.first_queued_at; end if; if tg_op='UPDATE' then if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.first_queued_at,new.created_at) is distinct from (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.first_queued_at,old.created_at) then raise exception 'review queue identity is immutable' using errcode='55000'; end if; if old.queue_state='closed' and new.queue_state <> 'closed' then raise exception 'closed review queue entries cannot reopen' using errcode='23514'; end if; if new.routing_generation < old.routing_generation or new.lifecycle_generation < old.lifecycle_generation then raise exception 'review queue generations cannot decrease' using errcode='23514'; end if; end if; if new.preferred_reviewer_id is not null and not exists( select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' ) then raise exception 'preferred reviewer must be human' using errcode='23514'; end if; if tg_op='UPDATE' then return new; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review queue task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review queue checker lineage mismatch' using errcode='23514'; end if; if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true then raise exception 'review queue checker is not admissible' using errcode='23514'; end if; return new; end $function$", + "name": "guard_review_queue_entry" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_revision_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'revision_policies rows are immutable' using errcode='55000'; end $function$", + "name": "guard_revision_policies_immutable" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_service_identity_migration_evidence() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'service identity migration evidence is immutable' using errcode='55000'; end $function$", + "name": "guard_service_identity_migration_evidence" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_delete() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $function$", + "name": "guard_submission_bundle_admission_delete" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, old.put_operation_receipt_id, old.put_observation_receipt_id, old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, old.assignment_id, old.predecessor_submission_id, old.predecessor_submission_version, old.locked_policy_context_hash, old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, old.archive_byte_count, old.ready_at, old.created_at) is distinct from row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, new.put_operation_receipt_id, new.put_observation_receipt_id, new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, new.assignment_id, new.predecessor_submission_id, new.predecessor_submission_version, new.locked_policy_context_hash, new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, new.archive_byte_count, new.ready_at, new.created_at) then raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; end if; if old.status <> 'ready' or new.status not in ('consumed','stale') then raise exception 'invalid submission bundle admission transition' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_submission_bundle_admission_lineage" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_verified_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ declare matches integer; begin select count(*) into matches from submission_bundle_durable_intents intent join pre_submit_evidence_sets evidence on evidence.id=intent.pre_submit_evidence_set_id join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id join artifact_replicas replica on replica.id=attempt.replica_id join artifact_contents content on content.id=replica.content_id join artifact_verification_jobs job on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id join artifact_verification_receipts verification on verification.verification_job_id=job.id where intent.id=new.durable_intent_id and evidence.id=new.pre_submit_evidence_set_id and attempt.id=new.put_attempt_id and content.id=new.artifact_content_id and replica.id=new.verified_replica_id and verification.id=new.verification_receipt_id and attempt.producer_request_type='submission_bundle' and attempt.producer_type='actor_profile' and attempt.producer_ref=evidence.actor_profile_id and attempt.project_id=evidence.project_id and attempt.task_id=evidence.task_id and attempt.media_type='application/zip' and content.media_type='application/zip' and attempt.status='object_confirmed' and evidence.terminal_status='passed' and evidence.eligible and replica.verification_state='verified' and replica.availability_state='available' and replica.integrity_state='valid' and verification.outcome='verified' and verification.execution_generation=job.execution_generation and verification.observed_sha256=attempt.sha256 and verification.observed_sha256=content.sha256 and verification.observed_sha256=evidence.archive_sha256 and verification.observed_byte_count=attempt.byte_count and verification.observed_byte_count=content.byte_count and verification.observed_byte_count=evidence.archive_byte_count and new.actor_profile_id=evidence.actor_profile_id and new.identity_link_id=evidence.identity_link_id and new.project_id=evidence.project_id and new.task_id=evidence.task_id and new.assignment_id=evidence.assignment_id and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version and new.locked_policy_context_hash=evidence.locked_policy_context_hash and new.semantic_manifest_id=evidence.semantic_manifest_id and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 and new.archive_sha256=evidence.archive_sha256 and new.archive_byte_count=evidence.archive_byte_count and ((new.put_operation_receipt_id is not null and exists ( select 1 from artifact_operation_receipts receipt where receipt.id=new.put_operation_receipt_id and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id and receipt.outcome='stored_pending_verification')) or (new.put_observation_receipt_id is not null and exists ( select 1 from artifact_put_observation_receipts observation where observation.id=new.put_observation_receipt_id and observation.put_attempt_id=attempt.id and observation.outcome='observed_confirmed' and observation.observed_sha256=attempt.sha256 and observation.observed_byte_count=attempt.byte_count))); if matches <> 1 then raise exception 'submission bundle admission verified lineage mismatch' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_submission_bundle_admission_verified_lineage" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id for share; if request_type is distinct from 'submission_bundle' then raise exception 'submission bundle durable intent requires submission_bundle put attempt' using errcode='23514'; end if; return new; end; $function$", + "name": "guard_submission_bundle_durable_intent_put_attempt" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intents_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission_bundle_durable_intents rows are immutable' using errcode='55000'; end; $function$", + "name": "guard_submission_bundle_durable_intents_immutable" + }, + { + "arguments": "value jsonb", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_availability_is_safe(value jsonb) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='object' and (select count(*)=3 from jsonb_object_keys(value)) and value ?& array['availability','reference_ids','unavailable_reason'] and project_role_reference_array_is_safe(value->'reference_ids',false) and ( (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 and value->'unavailable_reason'='null'::jsonb) or (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) ) $function$", + "name": "project_role_availability_is_safe" + }, + { + "arguments": "value text", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_reason_is_safe(value text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE STRICT AS $function$ declare point integer; index integer; begin if octet_length(value) not between 1 and 500 or value <> btrim(value, (E' \\t\\n\\r\\f\\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)||chr(8239)||chr(8287)||chr(12288))) then return false; end if; for index in 1..char_length(value) loop point := ascii(substr(value,index,1)); if point between 0 and 31 or point between 127 and 159 or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then return false; end if; end loop; return true; end $function$", + "name": "project_role_reason_is_safe" + }, + { + "arguments": "value jsonb, uuid_only boolean", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_array_is_safe(value jsonb, uuid_only boolean) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 and not exists ( select 1 from jsonb_array_elements(value) item where jsonb_typeof(item)<>'string' or case when uuid_only then not (item #>> '{}') ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' else not project_role_reference_token_is_safe(item #>> '{}') end ) $function$", + "name": "project_role_reference_array_is_safe" + }, + { + "arguments": "value text", + "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_token_is_safe(value text) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 $function$", + "name": "project_role_reference_token_is_safe" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_approval_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.approval_action_id is not null and (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, new.approved_by_admin_role_grant_id,new.approval_scope_type, new.approval_scope_project_id,new.approval_action_id, new.approval_decision_event_id) is distinct from (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, old.approved_by_admin_role_grant_id,old.approval_scope_type, old.approval_scope_project_id,old.approval_action_id, old.approval_decision_event_id) then raise exception 'submission-policy approval provenance is immutable' using errcode='23514'; end if; return new; end $function$", + "name": "protect_submission_policy_approval_provenance" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_creation_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.created_by_service_identity, new.creation_scope_type,new.creation_scope_project_id, new.creation_action_id,new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.created_by_service_identity, old.creation_scope_type,old.creation_scope_project_id, old.creation_action_id,old.creation_decision_event_id) then raise exception 'submission-policy creation provenance is immutable' using errcode='23514'; end if; return new; end $function$", + "name": "protect_submission_policy_creation_provenance" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_output_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.creation_scope_type, new.creation_scope_project_id,new.creation_action_id, new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.creation_scope_type, old.creation_scope_project_id,old.creation_action_id, old.creation_decision_event_id) then raise exception 'submission-policy output provenance is immutable' using errcode='23514'; end if; return new; end $function$", + "name": "protect_submission_policy_output_provenance" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_admin_role_grant_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'admin role grants are immutable' using errcode='55000'; end $function$", + "name": "reject_admin_role_grant_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_artifact_fact_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception '% rows are immutable', tg_table_name; end; $function$", + "name": "reject_artifact_fact_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_audit_event_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'audit events are append-only' using errcode = '55000'; end $function$", + "name": "reject_audit_event_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_control_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority control is immutable' using errcode='55000'; end $function$", + "name": "reject_authority_control_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority idempotency records are immutable' using errcode='55000'; end $function$", + "name": "reject_authority_idempotency_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_contribution_policy_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'contribution policy persistence cannot be truncated' using errcode='55000'; end; $function$", + "name": "reject_contribution_policy_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_mutation_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide mutation custody is immutable' using errcode='55000'; end $function$", + "name": "reject_guide_mutation_idempotency_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_source_snapshot_item_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide source snapshot items are immutable' using errcode='23514'; end $function$", + "name": "reject_guide_source_snapshot_item_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_pending_authority_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then raise exception 'pending authority idempotency cannot commit' using errcode='23514'; end if; return null; end $function$", + "name": "reject_pending_authority_idempotency" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_policy_mutation_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'policy mutation replay is immutable' using errcode='55000'; end $function$", + "name": "reject_policy_mutation_replay_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_project_create_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project create reservations are immutable' using errcode='55000'; end $function$", + "name": "reject_project_create_idempotency_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_project_guide_compilation_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compilation custody is append-only'; end $function$", + "name": "reject_project_guide_compilation_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_project_role_history_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $function$", + "name": "reject_project_role_history_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_review_lease_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review leases cannot be truncated' using errcode='55000'; end $function$", + "name": "reject_review_lease_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_review_queue_foundation_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review queue foundation cannot be truncated' using errcode='55000'; end $function$", + "name": "reject_review_queue_foundation_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'submission-policy replay rows cannot be deleted'; end if; if old.status = 'reserved' and new.status = 'pending' and old.service_identity = 'workstream.project.setup' and old.action_id = 'project.submission_artifact_policy.derive' and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.operation_id,new.project_id, new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, new.committed_pre_submit_policy_id,new.committed_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.operation_id,old.project_id, old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, old.committed_pre_submit_policy_id,old.committed_at) then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.request_digest, new.resource_context_digest,new.resource_context_json::text,new.operation_id, new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, new.setup_run_id,new.setup_generation,new.setup_task_id, new.correlation_id,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.request_digest, old.resource_context_digest,old.resource_context_json::text,old.operation_id, old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, old.setup_run_id,old.setup_generation,old.setup_task_id, old.correlation_id,old.created_at) then raise exception 'invalid submission-policy replay mutation'; end if; return new; end $function$", + "name": "reject_submission_policy_replay_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission-policy replay rows cannot be truncated'; end $function$", + "name": "reject_submission_policy_replay_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'guide sufficiency replay rows are append-only'; end if; if old.status = 'committed' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, new.setup_run_id,new.setup_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, old.setup_run_id,old.setup_generation,old.created_at) then raise exception 'invalid guide sufficiency replay mutation'; end if; return new; end $function$", + "name": "reject_sufficiency_replay_mutation" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide sufficiency replay rows are append-only'; end $function$", + "name": "reject_sufficiency_replay_truncate" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.require_human_actor_profile_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare referenced_id text; referenced_kind text; begin if tg_nargs <> 1 or tg_argv[0] is null or not (to_jsonb(new) ? tg_argv[0]) then raise exception 'human actor reference trigger is misconfigured' using errcode='55000'; end if; referenced_id := to_jsonb(new) ->> tg_argv[0]; if referenced_id is null then return new; end if; select profile.actor_kind into referenced_kind from public.actor_profiles profile where profile.id=referenced_id; if not found then return new; end if; if referenced_kind <> 'human' then raise exception 'actor reference must identify a human profile' using errcode='23514', constraint='require_human_actor_profile_reference'; end if; return new; end $function$", + "name": "require_human_actor_profile_reference" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.set_authority_audit_database_time() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.event_domain = 'authority' then if new.invalidation_cause_event_id is not null and not exists ( select 1 from audit_events where id = new.invalidation_cause_event_id and event_domain = 'authority' ) then raise exception 'invalid authority invalidation cause' using errcode = '23503'; end if; new.occurred_at = statement_timestamp(); else new.occurred_at = null; end if; return new; end $function$", + "name": "set_authority_audit_database_time" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_binding_history() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor artifact_bindings%rowtype; begin if new.scope_version = 1 then return new; end if; select * into predecessor from artifact_bindings where id = new.supersedes_binding_id; if not found or predecessor.project_id != new.project_id or predecessor.resource_type != new.resource_type or predecessor.resource_id != new.resource_id or predecessor.logical_role != new.logical_role or predecessor.scope_version + 1 != new.scope_version then raise exception 'artifact binding predecessor is invalid'; end if; return new; end; $function$", + "name": "validate_artifact_binding_history" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_recovery_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare source_row artifact_verification_jobs%rowtype; retry_row artifact_verification_jobs%rowtype; expected_parent text; begin if tg_op = 'DELETE' then raise exception 'artifact recovery attempts are append-only' using errcode='55000'; end if; if tg_op = 'UPDATE' and ( to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] is distinct from to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] ) then raise exception 'artifact recovery identity is immutable' using errcode='55000'; end if; select * into source_row from artifact_verification_jobs where id=new.source_verification_job_id; select * into retry_row from artifact_verification_jobs where id=new.retry_verification_job_id; if source_row.id is null or retry_row.id is null or source_row.status <> 'provider_unavailable' or source_row.terminal_result_code <> 'provider_unavailable' or source_row.terminal_at is null or source_row.next_run_at is not null or source_row.executor_id is not null or source_row.attempt_count < source_row.maximum_attempts or retry_row.parent_verification_job_id <> source_row.id or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id or retry_row.replica_id <> source_row.replica_id then raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; end if; if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) or (tg_op = 'UPDATE' and ( retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null )) then raise exception 'invalid artifact recovery retry state' using errcode='23514'; end if; select id into expected_parent from artifact_recovery_attempts where retry_verification_job_id=source_row.id; if new.parent_recovery_attempt_id is distinct from expected_parent then raise exception 'invalid artifact recovery parent chain' using errcode='23514'; end if; if not exists ( select 1 from audit_events where id=new.initiation_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryInitiated' ) then raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; end if; if new.terminal_audit_event_id is not null and not exists ( select 1 from audit_events where id=new.terminal_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryCompleted' ) then raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; end if; return new; end $function$", + "name": "validate_artifact_recovery_attempt" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_verification_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if ( old.parent_verification_job_id is not null or exists( select 1 from artifact_recovery_attempts where source_verification_job_id = old.id or retry_verification_job_id = old.id ) ) and ( old.originating_put_attempt_id is distinct from new.originating_put_attempt_id or old.replica_id is distinct from new.replica_id or old.parent_verification_job_id is distinct from new.parent_verification_job_id ) then raise exception 'artifact verification lineage is immutable' using errcode='55000'; end if; return new; end $function$", + "name": "validate_artifact_verification_lineage" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_bootstrap_authority_state() RETURNS trigger LANGUAGE plpgsql AS $function$ declare control authority_control%rowtype; bootstrap_count bigint; referenced_bootstrap boolean; begin select * into control from authority_control where id=1; if not found then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; select count(*) into bootstrap_count from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap'; referenced_bootstrap := exists( select 1 from admin_role_grants where id=control.bootstrap_grant_id and granted_by_system_principal='workstream:system:bootstrap' ); if (not control.bootstrap_completed and (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) or (control.bootstrap_completed and (control.bootstrap_grant_id is null or control.version <> 1 or bootstrap_count <> 1 or not referenced_bootstrap)) then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; return null; end $function$", + "name": "validate_bootstrap_authority_state" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_canonical_actor_link() RETURNS trigger LANGUAGE plpgsql AS $function$ declare profile_row actor_profiles%rowtype; link_count integer; begin if tg_table_name='actor_profiles' then select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; else select * into profile_row from actor_profiles where id=new.actor_profile_id; if not found or profile_row.actor_kind <> new.subject_kind then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; end if; return new; end $function$", + "name": "validate_canonical_actor_link" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_contribution_policy_graph() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists ( select 1 from contribution_policy_versions v where v.status in ('published','retired') and ( (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='accepted_submission') <> 1 or (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='completed_review') <> 1 or exists ( select 1 from contribution_rules r where r.contribution_policy_version_id=v.id and ( (r.compensation_mode='unpaid' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) <> 0) or (r.compensation_mode='compensated' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) not between 1 and 2) ) ) ) ) then raise exception 'published contribution policy graph is incomplete' using errcode='23514'; end if; if exists ( select 1 from contribution_policies p left join contribution_policy_versions v on v.id=p.current_published_version_id and v.contribution_policy_id=p.id and v.project_id=p.project_id where p.status='active' and (v.id is null or v.status <> 'published') ) then raise exception 'active contribution policy selector is invalid' using errcode='23514'; end if; return null; end; $function$", + "name": "validate_contribution_policy_graph" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation guide_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_resource text; product_generation integer; begin if tg_table_name='guide_mutation_idempotency_records' then select * into reservation from guide_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id in ('project.guide.create','project.guide.update') then select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, last_mutated_by_admin_role_grant_id,last_mutation_action_id, last_mutation_scope_type,last_mutation_scope_project_id, last_authorization_decision_event_id,project_id,id,mutation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from project_guides where id=reservation.resource_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,project_id,id,creation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from guide_source_snapshots where id=reservation.resource_id; end if; elsif tg_table_name='project_guides' then if tg_op='UPDATE' and (new.content_markdown is distinct from old.content_markdown or new.change_summary is distinct from old.change_summary) and (new.mutation_generation is not distinct from old.mutation_generation or new.last_authorization_decision_event_id is not distinct from old.last_authorization_decision_event_id) then raise exception 'guide content mutation requires fresh custody' using errcode='23514'; end if; if new.mutation_generation is null then if tg_op='INSERT' then raise exception 'new guides require mutation authority' using errcode='23514'; end if; return null; end if; actor_id:=new.last_mutated_by_actor_profile_id; link_id:=new.last_mutated_via_identity_link_id; grant_id:=new.last_mutated_by_admin_role_grant_id; action_value:=new.last_mutation_action_id; scope_type:=new.last_mutation_scope_type; scope_project:=new.last_mutation_scope_project_id; decision_id:=new.last_authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.mutation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id=new.last_mutation_action_id and operation_generation=new.mutation_generation and status='committed'; elsif tg_table_name='guide_source_snapshots' then if tg_op='UPDATE' and (new.project_id,new.guide_id,new.guide_version, new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) is distinct from (old.project_id,old.guide_id,old.guide_version, old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then raise exception 'guide source snapshot content is immutable' using errcode='23514'; end if; if new.creation_generation is null then raise exception 'new source snapshots require creation authority' using errcode='23514'; end if; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.creation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id='project.guide_source_snapshot.create' and operation_generation=new.creation_generation and status='committed'; else if new.authorization_action_id is null then return null; end if; actor_id:=new.authorized_by_actor_profile_id; link_id:=new.authorized_via_identity_link_id; grant_id:=new.authorized_by_admin_role_grant_id; action_value:=new.authorization_action_id; scope_type:=new.authorization_scope_type; scope_project:=new.authorization_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.source_snapshot_id; select * into reservation from guide_mutation_idempotency_records where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' and status='committed'; product_generation:=reservation.operation_generation; end if; if reservation.id is null or product_resource is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.resource_id is distinct from product_resource or reservation.operation_generation is distinct from product_generation or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'guide mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.guide.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'guide mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_guide_mutation_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_source_snapshot_items() RETURNS trigger LANGUAGE plpgsql AS $function$ declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; begin select snapshot.manifest_json::jsonb->'items' into expected from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; if expected is null then raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; end if; select coalesce(jsonb_agg(jsonb_build_object( 'item_id',id,'item_order',item_order,'source_kind',source_kind, 'source_label',source_label,'ingestion_adapter',ingestion_adapter, 'media_type',media_type) order by item_order),'[]'::jsonb) into actual from guide_source_snapshot_items where source_snapshot_id=new.source_snapshot_id; if actual is distinct from expected then raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; end if; select r.* into reservation from guide_mutation_idempotency_records r join guide_source_snapshots s on s.id=r.resource_id where s.id=new.source_snapshot_id and r.action_id='project.guide_source_snapshot.create' and r.operation_generation=s.creation_generation and r.status='committed'; if reservation.id is null then raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_guide_source_snapshot_items" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_linked_authority_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare record_row authority_idempotency_records%rowtype; cause_row audit_events%rowtype; expected_permission text; expected_resource text; expected_invalidation_resource text; expected_invalidation_id text; valid_success boolean; begin if new.event_domain <> 'authority' then return new; end if; valid_success := new.event_type in ( 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', 'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued','ProjectRoleGrantRevoked', 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then if new.idempotency_reference is not null then raise exception 'invalid authority idempotency event' using errcode='23514'; end if; return new; end if; if new.idempotency_reference is null then raise exception 'authority event requires idempotency reference' using errcode='23514'; end if; select * into record_row from authority_idempotency_records where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; expected_permission := case record_row.operation when 'service_actor.create' then 'actor.service.provision' when 'admin_role_grant.issue' then 'admin_role.grant' when 'admin_role_grant.revoke' then 'admin_role.revoke' when 'project_role_grant.issue' then 'project.role_grant.manage' when 'project_role_grant.revoke' then 'project.role_grant.manage' when 'actor_profile.suspend' then 'actor.profile.suspend' when 'actor_profile.reactivate' then 'actor.profile.reactivate' when 'actor_profile.deactivate' then 'actor.profile.deactivate' when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; expected_resource := case when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' when record_row.operation like 'project_role_grant.%' then 'project_role_grant' else 'actor_identity_link' end; if new.permission_id <> expected_permission or new.resource_id is null then raise exception 'authority event does not match operation' using errcode='23514'; end if; if new.event_type='ProjectRoleQualificationSnapshotCaptured' then if record_row.operation <> 'project_role_grant.issue' or new.resource_type <> 'qualification_snapshot' or new.entity_type <> 'qualification_snapshot' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'qualification_snapshot' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or exists(select 1 from audit_events where idempotency_reference=record_row.id) then raise exception 'invalid project role qualification evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='ProjectRoleGrantIssued' then select * into cause_row from audit_events where idempotency_reference=record_row.id and event_type='ProjectRoleQualificationSnapshotCaptured'; if not found or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.matched_grant_id is distinct from new.matched_grant_id or new.resource_type <> 'project_role_grant' or new.entity_type <> 'project_role_grant' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null then raise exception 'invalid project role issue evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.revoke' and new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from 'actor_profile' or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.resource_type <> 'project_role_grant' or cause_row.target_ref_kind <> 'project_role_grant' or cause_row.target_ref_id is distinct from cause_row.resource_id or new.resource_type <> 'project_role_grant' or new.resource_id is distinct from cause_row.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from cause_row.resource_id or new.invalidation_target_kind <> 'project_role_grant' or new.invalidation_target_ref is distinct from cause_row.resource_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or new.before_facts::jsonb->>'effective' <> 'true' or new.after_facts::jsonb->>'effective' <> 'false' or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' or new.before_facts::jsonb->>'scope_type' <> 'project' or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then raise exception 'invalid project role revoke invalidation' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='AuthorityInvalidationRequested' then raise exception 'project role issue forbids invalidation' using errcode='23514'; elsif new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; expected_invalidation_resource := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then 'actor_profile' else expected_resource end; expected_invalidation_id := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then cause_row.target_actor_ref else cause_row.resource_id end; if not found or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.resource_type is distinct from expected_resource or new.resource_type is distinct from expected_invalidation_resource or new.resource_id is distinct from expected_invalidation_id or new.invalidation_target_kind is distinct from expected_invalidation_resource or new.invalidation_target_ref is distinct from expected_invalidation_id or cause_row.target_ref_kind is distinct from cause_row.resource_type or cause_row.target_ref_id is distinct from cause_row.resource_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": false}'::jsonb or new.after_facts::jsonb <> '{\"effective\": true}'::jsonb)) or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": true}'::jsonb or new.after_facts::jsonb <> '{\"effective\": false}'::jsonb)) or not ( (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then raise exception 'invalid linked authority cause' using errcode='23514'; end if; else if new.resource_type <> expected_resource or new.entity_type <> expected_resource or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or not ( (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then raise exception 'authority success event does not match operation' using errcode='23514'; end if; end if; return new; end $function$", + "name": "validate_linked_authority_event" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_policy_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_guide text; product_id text; product_generation integer; product_hash text; predecessor_id text; predecessor_hash text; selector_id text; selector_generation integer; selector_hash text; predecessor_valid boolean; begin if tg_table_name='policy_mutation_idempotency_records' then select * into reservation from policy_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id='project.review_policy.update' then select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_review_policy_id, g.selected_review_policy_generation,g.selected_review_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from review_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_revision_policy_id, g.selected_revision_policy_generation,g.selected_revision_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from revision_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; end if; else actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_id:=new.id; product_generation:=new.policy_generation; product_hash:=new.policy_hash; predecessor_id:=new.supersedes_policy_id; predecessor_hash:=new.predecessor_policy_hash; if tg_table_name='review_policies' then select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, g.selected_review_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; else select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, g.selected_revision_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; end if; select r.* into reservation from policy_mutation_idempotency_records r where r.policy_id=new.id and r.action_id=new.creation_action_id and r.policy_generation=new.policy_generation and r.status='committed'; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.guide_id is distinct from product_guide or reservation.policy_id is distinct from product_id or reservation.policy_generation is distinct from product_generation or reservation.policy_hash is distinct from product_hash or selector_id is distinct from product_id or selector_generation is distinct from product_generation or selector_hash is distinct from product_hash or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'policy mutation custody mismatch' using errcode='23514'; end if; if product_generation=1 then predecessor_valid:=predecessor_id is null and predecessor_hash is null; elsif reservation.action_id='project.review_policy.update' then select exists(select 1 from review_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; else select exists(select 1 from revision_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; end if; if predecessor_valid is not true then raise exception 'policy mutation lineage mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.review_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'policy mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_policy_mutation_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_project_create_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; evidence audit_events%rowtype; begin if tg_table_name = 'projects' then if tg_op = 'INSERT' and new.creation_action_id is null then raise exception 'new projects require creation authority' using errcode='23514'; end if; if new.creation_action_id is null then return null; end if; project_row := new; select * into reservation from project_create_idempotency_records where project_id=project_row.id and status='committed'; else select * into reservation from project_create_idempotency_records where id=new.id; if reservation.status <> 'committed' then raise exception 'pending project create reservation cannot commit' using errcode='23514'; end if; select * into project_row from projects where id=reservation.project_id; end if; if project_row.id is null or reservation.id is null or project_row.created_by_actor_profile_id is distinct from reservation.actor_profile_id or project_row.created_via_identity_link_id is distinct from reservation.identity_link_id or project_row.creation_action_id is distinct from reservation.action_id then raise exception 'project create custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=project_row.authorization_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from project_row.created_by_actor_profile_id or evidence.matched_grant_id is distinct from project_row.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.create' or evidence.action_id is distinct from 'project.create' or evidence.resource_type is distinct from 'project_create_operation' or evidence.resource_id is distinct from reservation.operation_id::text or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from project_row.id or evidence.after_facts->>'allowed' is distinct from 'true' or coalesce( evidence.after_facts->>'resource_context_digest' !~ '^sha256:[0-9a-f]{64}$', true ) then raise exception 'project create evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_project_create_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_review_active_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare queue_row review_queue_entries%rowtype; active_count integer; begin if tg_table_name='review_queue_entries' then queue_row := new; else select * into queue_row from review_queue_entries where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); end if; if not found and tg_table_name='review_leases' then raise exception 'review lease queue is missing' using errcode='23514'; end if; select count(*) into active_count from review_leases where review_queue_entry_id=queue_row.id and status='active'; if queue_row.queue_state='leased' then if queue_row.active_lease_id is null or active_count <> 1 or not exists( select 1 from review_leases where id=queue_row.active_lease_id and review_queue_entry_id=queue_row.id and status='active' ) then raise exception 'leased queue must identify its active lease' using errcode='23514'; end if; elsif queue_row.active_lease_id is not null or active_count <> 0 then raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; end if; return null; end $function$", + "name": "validate_review_active_lease" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_authority_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; action_value varchar; decision_id varchar; product_project varchar; product_id varchar; approval_outputs_valid boolean; begin if tg_table_name='submission_policy_mutation_idempotency_records' then if new.status='pending' then return null; end if; reservation:=new; select project_id,id, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_actor_profile_id else created_by_actor_profile_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_via_identity_link_id else created_via_identity_link_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_admin_role_grant_id else created_by_admin_role_grant_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then null else created_by_service_identity end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_action_id else creation_action_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_decision_event_id else creation_decision_event_id end into product_project,product_id,actor_id,link_id,grant_id,service_id, action_value,decision_id from submission_artifact_policies where id=reservation.committed_policy_id; if reservation.action_id='project.submission_artifact_policy.approve' then select exists( select 1 from submission_artifact_policies s join effective_project_submission_artifact_policies e on e.id=reservation.committed_effective_policy_id and e.submission_artifact_policy_id=s.id and e.submission_artifact_policy_hash=s.policy_hash join pre_submit_checker_policies p on p.id=reservation.committed_pre_submit_policy_id and p.project_id=e.project_id where s.id=reservation.committed_policy_id and s.id=reservation.policy_id and s.guide_id=reservation.guide_id and s.source_snapshot_id=reservation.source_snapshot_id and s.guide_version=reservation.resource_context_json->>'guide_version' and s.policy_hash=reservation.resource_context_json->>'policy_digest' and e.effective_policy_hash= reservation.resource_context_json->>'effective_output_digest' and p.compiled_bundle_hash= reservation.resource_context_json->>'compiled_pre_submit_output_digest' and e.project_id=reservation.project_id and e.guide_id=s.guide_id and p.guide_id=s.guide_id and e.guide_version=s.guide_version and p.guide_version=s.guide_version and e.source_snapshot_id=s.source_snapshot_id and p.source_snapshot_id=s.source_snapshot_id and e.source_snapshot_hash=s.source_snapshot_hash and p.source_snapshot_hash=s.source_snapshot_hash and e.submission_artifact_policy_id=reservation.committed_policy_id and p.effective_policy_id=e.id and p.effective_policy_hash=e.effective_policy_hash and e.created_by_actor_profile_id=reservation.actor_profile_id and p.created_by_actor_profile_id=reservation.actor_profile_id and e.created_via_identity_link_id=reservation.identity_link_id and p.created_via_identity_link_id=reservation.identity_link_id and e.created_by_admin_role_grant_id=grant_id and p.created_by_admin_role_grant_id=grant_id and e.creation_scope_project_id=reservation.project_id and p.creation_scope_project_id=reservation.project_id and e.creation_action_id=reservation.action_id and p.creation_action_id=reservation.action_id and e.creation_decision_event_id=decision_id and p.creation_decision_event_id=decision_id ) into approval_outputs_valid; if approval_outputs_valid is not true then raise exception 'submission-policy approval output custody mismatch' using errcode='23514'; end if; end if; elsif tg_table_name='submission_artifact_policies' then if new.creation_action_id is null and new.approval_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null or new.approved_by_actor_profile_id is not null or new.approved_via_identity_link_id is not null or new.approved_by_admin_role_grant_id is not null or new.approval_scope_type is not null or new.approval_scope_project_id is not null or new.approval_decision_event_id is not null then raise exception 'partial submission-policy provenance' using errcode='23514'; end if; return null; end if; if new.approval_action_id is not null then select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.approval_action_id and status='committed'; actor_id:=new.approved_by_actor_profile_id; link_id:=new.approved_via_identity_link_id; grant_id:=new.approved_by_admin_role_grant_id; service_id:=null; action_value:=new.approval_action_id; decision_id:=new.approval_decision_event_id; else select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=new.created_by_service_identity; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; end if; product_project:=new.project_id; product_id:=new.id; elsif tg_table_name='effective_project_submission_artifact_policies' then if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial effective-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_effective_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; else if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial pre-submit-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_pre_submit_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.committed_policy_id is distinct from product_id or reservation.service_identity is distinct from service_id then raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from product_id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy authorization evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_submission_policy_authority_custody" + }, + { + "arguments": "", + "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_creation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; begin if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial submission-policy creation provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; if reservation.id is null or reservation.actor_profile_id is distinct from new.created_by_actor_profile_id or reservation.identity_link_id is distinct from new.created_via_identity_link_id or reservation.service_identity is distinct from new.created_by_service_identity or reservation.project_id is distinct from new.project_id or reservation.policy_id is distinct from new.id or reservation.guide_id is distinct from new.guide_id or reservation.source_snapshot_id is distinct from new.source_snapshot_id or reservation.resource_context_json->>'guide_version' is distinct from new.guide_version then raise exception 'submission-policy creation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=new.creation_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from new.created_by_actor_profile_id or evidence.matched_grant_id is distinct from new.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from new.creation_action_id or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from new.id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy creation evidence mismatch' using errcode='23514'; end if; return null; end $function$", + "name": "validate_submission_policy_creation_custody" + } + ], + "sequences": [ + { + "cache_size": 1, + "cycle": false, + "data_type": "integer", + "increment_by": 1, + "is_called": false, + "last_value": 1, + "max_value": 2147483647, + "min_value": 1, + "name": "actor_profile_migration_state_id_seq", + "start_value": 1 + }, + { + "cache_size": 1, + "cycle": false, + "data_type": "smallint", + "increment_by": 1, + "is_called": false, + "last_value": 1, + "max_value": 32767, + "min_value": 1, + "name": "authority_control_id_seq", + "start_value": 1 + } + ], + "tables": [ + { + "force_row_security": false, + "kind": "r", + "name": "actor_identity_links", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "actor_profile_migration_state", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "actor_profiles", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "admin_role_grants", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "api_rate_control_counters", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_admission_charges", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_admission_scopes", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_bindings", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_contents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_operation_receipts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_put_attempt_charges", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_put_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_put_observation_receipts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_recovery_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_replicas", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_storage_namespaces", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_verification_jobs", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "artifact_verification_receipts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "audit_events", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "authority_control", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "authority_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "checker_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "checker_results", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "checker_runs", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_award_definitions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_policy_versions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "contribution_rules", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "effective_project_submission_artifact_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "evidence_items", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_artifact_bindings", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_artifact_incidents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_artifact_ingests", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extracted_contents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extraction_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extraction_retry_budgets", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_extraction_usages", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_format_classifications", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_snapshot_items", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_source_snapshots", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_sufficiency_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_sufficiency_report_source_usages", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "guide_sufficiency_reports", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "iso_4217_currency_codes", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "legacy_actor_identities", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "legacy_workflow_eligibility", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "outbox_events", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "payment_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "policy_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "pre_submit_checker_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "pre_submit_evidence_results", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "pre_submit_evidence_sets", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_compensation_adapter_bindings", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_compensation_units", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_create_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_guide_compilation_attempts", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_guide_compilations", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_guides", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_role_grants", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_role_qualification_snapshots", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "project_setup_runs", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "projects", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_admission_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_leases", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "review_queue_entries", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "revision_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_artifact_policies", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_bundle_admissions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_bundle_durable_intents", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submission_policy_mutation_idempotency_records", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "submissions", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "task_assignments", + "persistence": "p", + "row_security": false + }, + { + "force_row_security": false, + "kind": "r", + "name": "workstream_tasks", + "persistence": "p", + "row_security": false + } + ], + "triggers": [ + { + "definition": "CREATE TRIGGER actor_identity_link_history_guard BEFORE DELETE OR UPDATE ON actor_identity_links FOR EACH ROW EXECUTE FUNCTION guard_actor_identity_link_history()", + "enabled": "O", + "name": "actor_identity_link_history_guard", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER actor_identity_link_profile_guard AFTER INSERT OR UPDATE ON actor_identity_links DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", + "enabled": "O", + "name": "actor_identity_link_profile_guard", + "table_name": "actor_identity_links" + }, + { + "definition": "CREATE TRIGGER service_identity_migration_evidence_row_guard BEFORE DELETE OR UPDATE ON actor_profile_migration_state FOR EACH ROW EXECUTE FUNCTION guard_service_identity_migration_evidence()", + "enabled": "O", + "name": "service_identity_migration_evidence_row_guard", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CREATE TRIGGER service_identity_migration_evidence_truncate_guard BEFORE TRUNCATE ON actor_profile_migration_state FOR EACH STATEMENT EXECUTE FUNCTION guard_service_identity_migration_evidence()", + "enabled": "O", + "name": "service_identity_migration_evidence_truncate_guard", + "table_name": "actor_profile_migration_state" + }, + { + "definition": "CREATE TRIGGER actor_profile_history_guard BEFORE DELETE OR UPDATE ON actor_profiles FOR EACH ROW EXECUTE FUNCTION guard_actor_profile_history()", + "enabled": "O", + "name": "actor_profile_history_guard", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER actor_profile_link_guard AFTER INSERT OR UPDATE ON actor_profiles DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", + "enabled": "O", + "name": "actor_profile_link_guard", + "table_name": "actor_profiles" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER admin_role_grants_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON admin_role_grants DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", + "enabled": "O", + "name": "admin_role_grants_bootstrap_invariant", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE TRIGGER admin_role_grants_guard BEFORE INSERT OR DELETE OR UPDATE ON admin_role_grants FOR EACH ROW EXECUTE FUNCTION guard_admin_role_grant()", + "enabled": "O", + "name": "admin_role_grants_guard", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE TRIGGER admin_role_grants_reject_truncate BEFORE TRUNCATE ON admin_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_admin_role_grant_truncate()", + "enabled": "O", + "name": "admin_role_grants_reject_truncate", + "table_name": "admin_role_grants" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER trg_artifact_binding_history AFTER INSERT ON artifact_bindings DEFERRABLE INITIALLY IMMEDIATE FOR EACH ROW EXECUTE FUNCTION validate_artifact_binding_history()", + "enabled": "O", + "name": "trg_artifact_binding_history", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE TRIGGER trg_artifact_bindings_immutable BEFORE DELETE OR UPDATE ON artifact_bindings FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_bindings_immutable", + "table_name": "artifact_bindings" + }, + { + "definition": "CREATE TRIGGER trg_artifact_contents_immutable BEFORE DELETE OR UPDATE ON artifact_contents FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_contents_immutable", + "table_name": "artifact_contents" + }, + { + "definition": "CREATE TRIGGER artifact_receipt_producer_reference BEFORE INSERT OR UPDATE OF put_attempt_id, guide_source_item_id, checker_run_id, logical_role ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION guard_artifact_receipt_producer_reference()", + "enabled": "O", + "name": "artifact_receipt_producer_reference", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE TRIGGER trg_artifact_operation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_operation_receipts_immutable", + "table_name": "artifact_operation_receipts" + }, + { + "definition": "CREATE TRIGGER trg_artifact_put_observation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_put_observation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_put_observation_receipts_immutable", + "table_name": "artifact_put_observation_receipts" + }, + { + "definition": "CREATE TRIGGER artifact_recovery_attempt_custody BEFORE INSERT OR DELETE OR UPDATE ON artifact_recovery_attempts FOR EACH ROW EXECUTE FUNCTION validate_artifact_recovery_attempt()", + "enabled": "O", + "name": "artifact_recovery_attempt_custody", + "table_name": "artifact_recovery_attempts" + }, + { + "definition": "CREATE TRIGGER trg_artifact_storage_namespaces_immutable BEFORE DELETE OR UPDATE ON artifact_storage_namespaces FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_storage_namespaces_immutable", + "table_name": "artifact_storage_namespaces" + }, + { + "definition": "CREATE TRIGGER artifact_verification_lineage_custody BEFORE UPDATE ON artifact_verification_jobs FOR EACH ROW EXECUTE FUNCTION validate_artifact_verification_lineage()", + "enabled": "O", + "name": "artifact_verification_lineage_custody", + "table_name": "artifact_verification_jobs" + }, + { + "definition": "CREATE TRIGGER trg_artifact_verification_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_verification_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", + "enabled": "O", + "name": "trg_artifact_verification_receipts_immutable", + "table_name": "artifact_verification_receipts" + }, + { + "definition": "CREATE TRIGGER audit_events_reject_truncate BEFORE TRUNCATE ON audit_events FOR EACH STATEMENT EXECUTE FUNCTION reject_audit_event_mutation()", + "enabled": "O", + "name": "audit_events_reject_truncate", + "table_name": "audit_events" + }, + { + "definition": "CREATE TRIGGER audit_events_reject_update_delete BEFORE DELETE OR UPDATE ON audit_events FOR EACH ROW EXECUTE FUNCTION reject_audit_event_mutation()", + "enabled": "O", + "name": "audit_events_reject_update_delete", + "table_name": "audit_events" + }, + { + "definition": "CREATE TRIGGER audit_events_set_authority_time BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION set_authority_audit_database_time()", + "enabled": "O", + "name": "audit_events_set_authority_time", + "table_name": "audit_events" + }, + { + "definition": "CREATE TRIGGER audit_events_validate_idempotency BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION validate_linked_authority_event()", + "enabled": "O", + "name": "audit_events_validate_idempotency", + "table_name": "audit_events" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER authority_control_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON authority_control DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", + "enabled": "O", + "name": "authority_control_bootstrap_invariant", + "table_name": "authority_control" + }, + { + "definition": "CREATE TRIGGER authority_control_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_control FOR EACH ROW EXECUTE FUNCTION guard_authority_control()", + "enabled": "O", + "name": "authority_control_guard", + "table_name": "authority_control" + }, + { + "definition": "CREATE TRIGGER authority_control_reject_truncate BEFORE TRUNCATE ON authority_control FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_control_truncate()", + "enabled": "O", + "name": "authority_control_reject_truncate", + "table_name": "authority_control" + }, + { + "definition": "CREATE TRIGGER authority_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_authority_idempotency_record()", + "enabled": "O", + "name": "authority_idempotency_guard", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER authority_idempotency_pending_guard AFTER INSERT OR UPDATE ON authority_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION reject_pending_authority_idempotency()", + "enabled": "O", + "name": "authority_idempotency_pending_guard", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE TRIGGER authority_idempotency_reject_truncate BEFORE TRUNCATE ON authority_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_idempotency_truncate()", + "enabled": "O", + "name": "authority_idempotency_reject_truncate", + "table_name": "authority_idempotency_records" + }, + { + "definition": "CREATE TRIGGER contribution_award_definitions_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_award_definitions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", + "enabled": "O", + "name": "contribution_award_definitions_content_guard", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_award_definitions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_award_definitions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_award_definitions_graph_guard", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE TRIGGER contribution_award_definitions_reject_truncate BEFORE TRUNCATE ON contribution_award_definitions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_award_definitions_reject_truncate", + "table_name": "contribution_award_definitions" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_policies_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_policies_graph_guard", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE TRIGGER contribution_policies_reject_truncate BEFORE TRUNCATE ON contribution_policies FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_policies_reject_truncate", + "table_name": "contribution_policies" + }, + { + "definition": "CREATE TRIGGER contribution_policy_versions_content_guard BEFORE DELETE OR UPDATE ON contribution_policy_versions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_version_content()", + "enabled": "O", + "name": "contribution_policy_versions_content_guard", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_policy_versions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policy_versions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_policy_versions_graph_guard", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE TRIGGER contribution_policy_versions_reject_truncate BEFORE TRUNCATE ON contribution_policy_versions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_policy_versions_reject_truncate", + "table_name": "contribution_policy_versions" + }, + { + "definition": "CREATE TRIGGER contribution_rules_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_rules FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", + "enabled": "O", + "name": "contribution_rules_content_guard", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER contribution_rules_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_rules DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", + "enabled": "O", + "name": "contribution_rules_graph_guard", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE TRIGGER contribution_rules_reject_truncate BEFORE TRUNCATE ON contribution_rules FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "contribution_rules_reject_truncate", + "table_name": "contribution_rules" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER effective_submission_policy_custody AFTER INSERT OR UPDATE ON effective_project_submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "effective_submission_policy_custody", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER effective_submission_policy_provenance_immutable BEFORE UPDATE ON effective_project_submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", + "enabled": "O", + "name": "effective_submission_policy_provenance_immutable", + "table_name": "effective_project_submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER guide_mutation_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON guide_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_guide_mutation_idempotency()", + "enabled": "O", + "name": "guide_mutation_idempotency_guard", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER guide_mutation_idempotency_reject_truncate BEFORE TRUNCATE ON guide_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_mutation_idempotency_truncate()", + "enabled": "O", + "name": "guide_mutation_idempotency_reject_truncate", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_reservation_custody AFTER INSERT OR UPDATE ON guide_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "guide_mutation_reservation_custody", + "table_name": "guide_mutation_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER guide_source_snapshot_items_custody AFTER INSERT ON guide_source_snapshot_items DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_source_snapshot_items()", + "enabled": "O", + "name": "guide_source_snapshot_items_custody", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE TRIGGER guide_source_snapshot_items_immutable BEFORE DELETE OR UPDATE OR TRUNCATE ON guide_source_snapshot_items FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_source_snapshot_item_mutation()", + "enabled": "O", + "name": "guide_source_snapshot_items_immutable", + "table_name": "guide_source_snapshot_items" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER source_snapshot_product_custody AFTER INSERT OR UPDATE ON guide_source_snapshots DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "source_snapshot_product_custody", + "table_name": "guide_source_snapshots" + }, + { + "definition": "CREATE TRIGGER trg_sufficiency_replay_immutable BEFORE DELETE OR UPDATE ON guide_sufficiency_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_sufficiency_replay_mutation()", + "enabled": "O", + "name": "trg_sufficiency_replay_immutable", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_sufficiency_replay_no_truncate BEFORE TRUNCATE ON guide_sufficiency_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_sufficiency_replay_truncate()", + "enabled": "O", + "name": "trg_sufficiency_replay_no_truncate", + "table_name": "guide_sufficiency_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER iso_4217_currency_codes_immutable BEFORE INSERT OR DELETE OR UPDATE ON iso_4217_currency_codes FOR EACH ROW EXECUTE FUNCTION guard_iso_4217_currency_codes()", + "enabled": "O", + "name": "iso_4217_currency_codes_immutable", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "CREATE TRIGGER iso_4217_currency_codes_reject_truncate BEFORE TRUNCATE ON iso_4217_currency_codes FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "iso_4217_currency_codes_reject_truncate", + "table_name": "iso_4217_currency_codes" + }, + { + "definition": "CREATE TRIGGER outbox_events_custody BEFORE INSERT OR DELETE OR UPDATE ON outbox_events FOR EACH ROW EXECUTE FUNCTION guard_outbox_event()", + "enabled": "O", + "name": "outbox_events_custody", + "table_name": "outbox_events" + }, + { + "definition": "CREATE TRIGGER outbox_events_reject_truncate BEFORE TRUNCATE ON outbox_events FOR EACH STATEMENT EXECUTE FUNCTION guard_outbox_event()", + "enabled": "O", + "name": "outbox_events_reject_truncate", + "table_name": "outbox_events" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER policy_mutation_replay_custody AFTER INSERT OR UPDATE ON policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", + "enabled": "O", + "name": "policy_mutation_replay_custody", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER policy_mutation_replay_immutable BEFORE INSERT OR DELETE OR UPDATE ON policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_policy_mutation_replay()", + "enabled": "O", + "name": "policy_mutation_replay_immutable", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER policy_mutation_replay_reject_truncate BEFORE TRUNCATE ON policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_policy_mutation_replay_truncate()", + "enabled": "O", + "name": "policy_mutation_replay_reject_truncate", + "table_name": "policy_mutation_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER pre_submit_policy_custody AFTER INSERT OR UPDATE ON pre_submit_checker_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "pre_submit_policy_custody", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE TRIGGER pre_submit_policy_provenance_immutable BEFORE UPDATE ON pre_submit_checker_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", + "enabled": "O", + "name": "pre_submit_policy_provenance_immutable", + "table_name": "pre_submit_checker_policies" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_results_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_results_immutable", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_results_membership BEFORE INSERT ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_result_membership()", + "enabled": "O", + "name": "pre_submit_evidence_results_membership", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_results_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_results FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_results_no_truncate", + "table_name": "pre_submit_evidence_results" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_sets_creation BEFORE INSERT ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_set_creation()", + "enabled": "O", + "name": "pre_submit_evidence_sets_creation", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_sets_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_sets_immutable", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE TRIGGER pre_submit_evidence_sets_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_sets FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", + "enabled": "O", + "name": "pre_submit_evidence_sets_no_truncate", + "table_name": "pre_submit_evidence_sets" + }, + { + "definition": "CREATE TRIGGER project_compensation_binding_update_guard BEFORE UPDATE ON project_compensation_adapter_bindings FOR EACH ROW EXECUTE FUNCTION enforce_compensation_binding_lifecycle()", + "enabled": "O", + "name": "project_compensation_binding_update_guard", + "table_name": "project_compensation_adapter_bindings" + }, + { + "definition": "CREATE TRIGGER project_compensation_units_lifecycle_guard BEFORE INSERT OR DELETE OR UPDATE ON project_compensation_units FOR EACH ROW EXECUTE FUNCTION guard_project_compensation_units()", + "enabled": "O", + "name": "project_compensation_units_lifecycle_guard", + "table_name": "project_compensation_units" + }, + { + "definition": "CREATE TRIGGER project_compensation_units_reject_truncate BEFORE TRUNCATE ON project_compensation_units FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", + "enabled": "O", + "name": "project_compensation_units_reject_truncate", + "table_name": "project_compensation_units" + }, + { + "definition": "CREATE TRIGGER project_create_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON project_create_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_project_create_idempotency()", + "enabled": "O", + "name": "project_create_idempotency_guard", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE TRIGGER project_create_idempotency_reject_truncate BEFORE TRUNCATE ON project_create_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_project_create_idempotency_truncate()", + "enabled": "O", + "name": "project_create_idempotency_reject_truncate", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER project_create_reservation_custody AFTER INSERT OR UPDATE ON project_create_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", + "enabled": "O", + "name": "project_create_reservation_custody", + "table_name": "project_create_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_compilation_attempt_delete BEFORE DELETE OR TRUNCATE ON project_guide_compilation_attempts FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", + "enabled": "O", + "name": "trg_compilation_attempt_delete", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE TRIGGER trg_compilation_attempt_update BEFORE UPDATE ON project_guide_compilation_attempts FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_attempt_update()", + "enabled": "O", + "name": "trg_compilation_attempt_update", + "table_name": "project_guide_compilation_attempts" + }, + { + "definition": "CREATE TRIGGER trg_compilation_insert BEFORE INSERT ON project_guide_compilations FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_insert()", + "enabled": "O", + "name": "trg_compilation_insert", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE TRIGGER trg_compilation_mutation BEFORE DELETE OR UPDATE OR TRUNCATE ON project_guide_compilations FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", + "enabled": "O", + "name": "trg_compilation_mutation", + "table_name": "project_guide_compilations" + }, + { + "definition": "CREATE TRIGGER guide_lineage_lifecycle_guard BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_guide_lineage_and_lifecycle()", + "enabled": "O", + "name": "guide_lineage_lifecycle_guard", + "table_name": "project_guides" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_product_custody AFTER INSERT OR UPDATE ON project_guides DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "guide_mutation_product_custody", + "table_name": "project_guides" + }, + { + "definition": "CREATE TRIGGER project_guides_policy_selection_immutable BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_project_guide_policy_selection()", + "enabled": "O", + "name": "project_guides_policy_selection_immutable", + "table_name": "project_guides" + }, + { + "definition": "CREATE TRIGGER trg_project_role_grants_history BEFORE INSERT OR DELETE OR UPDATE ON project_role_grants FOR EACH ROW EXECUTE FUNCTION guard_project_role_grant_history()", + "enabled": "O", + "name": "trg_project_role_grants_history", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE TRIGGER trg_project_role_grants_reject_truncate BEFORE TRUNCATE ON project_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", + "enabled": "O", + "name": "trg_project_role_grants_reject_truncate", + "table_name": "project_role_grants" + }, + { + "definition": "CREATE TRIGGER trg_project_role_qualification_snapshots_immutable BEFORE INSERT OR DELETE OR UPDATE ON project_role_qualification_snapshots FOR EACH ROW EXECUTE FUNCTION guard_project_role_snapshot_history()", + "enabled": "O", + "name": "trg_project_role_qualification_snapshots_immutable", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE TRIGGER trg_project_role_snapshots_reject_truncate BEFORE TRUNCATE ON project_role_qualification_snapshots FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", + "enabled": "O", + "name": "trg_project_role_snapshots_reject_truncate", + "table_name": "project_role_qualification_snapshots" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER source_setup_run_custody AFTER INSERT OR UPDATE ON project_setup_runs DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", + "enabled": "O", + "name": "source_setup_run_custody", + "table_name": "project_setup_runs" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER project_creation_custody AFTER INSERT OR UPDATE OF created_by_actor_profile_id, created_via_identity_link_id, created_by_admin_role_grant_id, creation_scope_type, creation_action_id, authorization_decision_event_id ON projects DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", + "enabled": "O", + "name": "project_creation_custody", + "table_name": "projects" + }, + { + "definition": "CREATE TRIGGER review_admission_idempotency_records_reject_truncate BEFORE TRUNCATE ON review_admission_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", + "enabled": "O", + "name": "review_admission_idempotency_records_reject_truncate", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE TRIGGER review_admission_records_guard BEFORE INSERT OR DELETE OR UPDATE ON review_admission_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_review_admission_record()", + "enabled": "O", + "name": "review_admission_records_guard", + "table_name": "review_admission_idempotency_records" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER review_leases_active_lease_guard AFTER INSERT OR UPDATE ON review_leases DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", + "enabled": "O", + "name": "review_leases_active_lease_guard", + "table_name": "review_leases" + }, + { + "definition": "CREATE TRIGGER review_leases_guard BEFORE INSERT OR DELETE OR UPDATE ON review_leases FOR EACH ROW EXECUTE FUNCTION guard_review_lease()", + "enabled": "O", + "name": "review_leases_guard", + "table_name": "review_leases" + }, + { + "definition": "CREATE TRIGGER review_leases_reject_truncate BEFORE TRUNCATE ON review_leases FOR EACH STATEMENT EXECUTE FUNCTION reject_review_lease_truncate()", + "enabled": "O", + "name": "review_leases_reject_truncate", + "table_name": "review_leases" + }, + { + "definition": "CREATE TRIGGER review_policies_immutable BEFORE DELETE OR UPDATE ON review_policies FOR EACH ROW EXECUTE FUNCTION guard_review_policies_immutable()", + "enabled": "O", + "name": "review_policies_immutable", + "table_name": "review_policies" + }, + { + "definition": "CREATE TRIGGER review_policies_reject_truncate BEFORE TRUNCATE ON review_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_review_policies_immutable()", + "enabled": "O", + "name": "review_policies_reject_truncate", + "table_name": "review_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER review_policy_mutation_custody AFTER INSERT OR UPDATE ON review_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", + "enabled": "O", + "name": "review_policy_mutation_custody", + "table_name": "review_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER review_queue_entries_active_lease_guard AFTER INSERT OR UPDATE ON review_queue_entries DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", + "enabled": "O", + "name": "review_queue_entries_active_lease_guard", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE TRIGGER review_queue_entries_guard BEFORE INSERT OR DELETE OR UPDATE ON review_queue_entries FOR EACH ROW EXECUTE FUNCTION guard_review_queue_entry()", + "enabled": "O", + "name": "review_queue_entries_guard", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE TRIGGER review_queue_entries_reject_truncate BEFORE TRUNCATE ON review_queue_entries FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", + "enabled": "O", + "name": "review_queue_entries_reject_truncate", + "table_name": "review_queue_entries" + }, + { + "definition": "CREATE TRIGGER revision_policies_immutable BEFORE DELETE OR UPDATE ON revision_policies FOR EACH ROW EXECUTE FUNCTION guard_revision_policies_immutable()", + "enabled": "O", + "name": "revision_policies_immutable", + "table_name": "revision_policies" + }, + { + "definition": "CREATE TRIGGER revision_policies_reject_truncate BEFORE TRUNCATE ON revision_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_revision_policies_immutable()", + "enabled": "O", + "name": "revision_policies_reject_truncate", + "table_name": "revision_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER revision_policy_mutation_custody AFTER INSERT OR UPDATE ON revision_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", + "enabled": "O", + "name": "revision_policy_mutation_custody", + "table_name": "revision_policies" + }, + { + "definition": "CREATE TRIGGER submission_policy_approval_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_approval_provenance()", + "enabled": "O", + "name": "submission_policy_approval_provenance_immutable", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER submission_policy_creation_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_creation_custody()", + "enabled": "O", + "name": "submission_policy_creation_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER submission_policy_creation_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_creation_provenance()", + "enabled": "O", + "name": "submission_policy_creation_provenance_immutable", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER submission_policy_product_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "submission_policy_product_custody", + "table_name": "submission_artifact_policies" + }, + { + "definition": "CREATE TRIGGER submission_bundle_admission_delete BEFORE DELETE OR TRUNCATE ON submission_bundle_admissions FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_admission_delete()", + "enabled": "O", + "name": "submission_bundle_admission_delete", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE TRIGGER submission_bundle_admission_lineage BEFORE UPDATE ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_lineage()", + "enabled": "O", + "name": "submission_bundle_admission_lineage", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE TRIGGER submission_bundle_admission_verified_lineage BEFORE INSERT ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_verified_lineage()", + "enabled": "O", + "name": "submission_bundle_admission_verified_lineage", + "table_name": "submission_bundle_admissions" + }, + { + "definition": "CREATE TRIGGER submission_bundle_durable_intent_put_attempt BEFORE INSERT ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intent_put_attempt()", + "enabled": "O", + "name": "submission_bundle_durable_intent_put_attempt", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE TRIGGER submission_bundle_durable_intents_immutable BEFORE DELETE OR UPDATE ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", + "enabled": "O", + "name": "submission_bundle_durable_intents_immutable", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE TRIGGER submission_bundle_durable_intents_no_truncate BEFORE TRUNCATE ON submission_bundle_durable_intents FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", + "enabled": "O", + "name": "submission_bundle_durable_intents_no_truncate", + "table_name": "submission_bundle_durable_intents" + }, + { + "definition": "CREATE CONSTRAINT TRIGGER submission_policy_replay_custody AFTER INSERT OR UPDATE ON submission_policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW WHEN (new.status::text = 'committed'::text) EXECUTE FUNCTION validate_submission_policy_authority_custody()", + "enabled": "O", + "name": "submission_policy_replay_custody", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_submission_policy_replay_immutable BEFORE DELETE OR UPDATE ON submission_policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_submission_policy_replay_mutation()", + "enabled": "O", + "name": "trg_submission_policy_replay_immutable", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER trg_submission_policy_replay_no_truncate BEFORE TRUNCATE ON submission_policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_submission_policy_replay_truncate()", + "enabled": "O", + "name": "trg_submission_policy_replay_no_truncate", + "table_name": "submission_policy_mutation_idempotency_records" + }, + { + "definition": "CREATE TRIGGER submissions_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON submissions FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", + "enabled": "O", + "name": "submissions_contributor_human", + "table_name": "submissions" + }, + { + "definition": "CREATE TRIGGER task_assignments_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON task_assignments FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", + "enabled": "O", + "name": "task_assignments_contributor_human", + "table_name": "task_assignments" + } + ], + "types": [] +} diff --git a/backend/alembic/baseline/v01_reference_data.sql b/backend/alembic/baseline/v01_reference_data.sql new file mode 100644 index 000000000..367d4acdc --- /dev/null +++ b/backend/alembic/baseline/v01_reference_data.sql @@ -0,0 +1,183 @@ + +INSERT INTO public.actor_profile_migration_state (id, schema_version, classified_count, source_row_set_sha256, manifest_sha256, envelope_sha256, migrated_at, service_identity_mapped_count, service_identity_source_row_set_sha256, service_identity_manifest_sha256, service_identity_envelope_sha256, service_identity_database_binding) VALUES (1, 1, 0, '4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945', NULL, NULL, '2026-08-11 08:18:03.06394+00', 0, '4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945', NULL, NULL, 'postgres-v1:aa1108b4a868ca4330673d1bbe499d99c330d196994696d89e56cf09bfc3c93e'); +INSERT INTO public.authority_control (id, bootstrap_completed, bootstrap_grant_id, version, created_at, updated_at) VALUES (1, false, NULL, 0, '2026-08-11 08:18:13.474128+00', '2026-08-11 08:18:13.474148+00'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('AED'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('AFN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ALL'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('AMD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('AOA'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ARS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('AUD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('AWG'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('AZN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BAM'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BBD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BDT'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BHD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BIF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BMD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BND'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BOB'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BOV'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BRL'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BSD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BTN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BWP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BYN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('BZD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CAD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CDF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CHE'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CHF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CHW'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CLF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CLP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CNY'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('COP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('COU'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CRC'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CUP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CVE'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('CZK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('DJF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('DKK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('DOP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('DZD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('EGP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ERN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ETB'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('EUR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('FJD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('FKP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GBP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GEL'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GHS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GIP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GMD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GNF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GTQ'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('GYD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('HKD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('HNL'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('HTG'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('HUF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('IDR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ILS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('INR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('IQD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('IRR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ISK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('JMD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('JOD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('JPY'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KES'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KGS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KHR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KMF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KPW'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KRW'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KWD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KYD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('KZT'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('LAK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('LBP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('LKR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('LRD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('LSL'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('LYD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MAD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MDL'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MGA'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MKD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MMK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MNT'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MOP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MRU'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MUR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MVR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MWK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MXN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MXV'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MYR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('MZN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('NAD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('NGN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('NIO'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('NOK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('NPR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('NZD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('OMR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('PAB'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('PEN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('PGK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('PHP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('PKR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('PLN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('PYG'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('QAR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('RON'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('RSD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('RUB'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('RWF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SAR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SBD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SCR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SDG'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SEK'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SGD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SHP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SLE'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SOS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SRD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SSP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('STN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SVC'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SYP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('SZL'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('THB'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TJS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TMT'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TND'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TOP'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TRY'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TTD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TWD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('TZS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('UAH'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('UGX'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('USD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('USN'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('UYI'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('UYU'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('UYW'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('UZS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('VED'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('VES'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('VND'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('VUV'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('WST'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XAD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XAF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XAG'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XAU'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XBA'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XBB'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XBC'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XBD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XCD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XCG'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XDR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XOF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XPD'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XPF'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XPT'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XSU'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XTS'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XUA'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('XXX'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('YER'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ZAR'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ZMW'); +INSERT INTO public.iso_4217_currency_codes (code) VALUES ('ZWG'); +SELECT pg_catalog.setval('public.actor_profile_migration_state_id_seq', 1, true); +SELECT pg_catalog.setval('public.authority_control_id_seq', 1, true); diff --git a/backend/alembic/baseline/v01_schema.sql b/backend/alembic/baseline/v01_schema.sql new file mode 100644 index 000000000..af9d71b44 --- /dev/null +++ b/backend/alembic/baseline/v01_schema.sql @@ -0,0 +1,5633 @@ + +CREATE FUNCTION public.authority_event_facts_are_safe(event_name text, before_state json, after_state json, envelope_project_id text) RETURNS boolean + LANGUAGE plpgsql IMMUTABLE + AS $$ + begin + if not (event_name='AuthorityInvalidationRequested' + and before_state is not null + and after_state is not null + and coalesce(before_state::jsonb ? 'future_obligation', false) + and coalesce(after_state::jsonb ? 'future_obligation', false)) + and ((before_state is not null and not authority_facts_are_safe(before_state)) + or (after_state is not null and not authority_facts_are_safe(after_state))) then + return false; + end if; + case event_name + when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = + '{"status":"active","subject_kind":"human","provisioning_method":"automatic_first_access"}'::jsonb; + when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = + '{"status":"active","subject_kind":"service","provisioning_method":"manual_service_provisioning"}'::jsonb; + when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( + '{"status":"active","subject_kind":"human"}'::jsonb, + '{"status":"active","subject_kind":"service"}'::jsonb); + when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{"status":"active"}'::jsonb and after_state::jsonb='{"status":"revoked"}'::jsonb; + when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{"status":"revoked"}'::jsonb and after_state::jsonb='{"status":"active"}'::jsonb; + when 'ActorProfileSuspended' then return before_state::jsonb='{"status":"active"}'::jsonb and after_state::jsonb='{"status":"suspended"}'::jsonb; + when 'ActorProfileReactivated' then return before_state::jsonb='{"status":"suspended"}'::jsonb and after_state::jsonb='{"status":"active"}'::jsonb; + when 'ActorProfileDeactivated' then return before_state::jsonb in ('{"status":"active"}'::jsonb,'{"status":"suspended"}'::jsonb) and after_state::jsonb='{"status":"deactivated"}'::jsonb; + when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); + when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); + when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','adjudicator'],'active',true,envelope_project_id); + when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then + return authority_grant_facts_are_safe(before_state, + case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, + 'active',true,envelope_project_id) + and authority_grant_facts_are_safe(after_state, + case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, + 'revoked',false,envelope_project_id) + and before_state->>'role'=after_state->>'role' + and before_state->>'scope_type'=after_state->>'scope_type' + and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); + when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{"status":"captured"}'::jsonb; + when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; + when 'SensitiveAuthorizationAllowed' then + return before_state is null and ( + after_state::jsonb = '{"allowed": true}'::jsonb or ( + after_state::jsonb->'allowed' = 'true'::jsonb + and after_state::jsonb ? 'resource_context_digest' + and (select count(*) from json_each(after_state)) = 2 + ) + ); + when 'SensitiveAuthorizationDenied' then + return before_state is null and ( + after_state::jsonb = '{"allowed": false}'::jsonb or ( + after_state::jsonb->'allowed' = 'false'::jsonb + and after_state::jsonb ? 'resource_context_digest' + and (select count(*) from json_each(after_state)) = 2 + ) + ); + when 'AuthorityInvalidationRequested' then return + (before_state::jsonb = '{"effective": true}'::jsonb + and after_state::jsonb = '{"effective": false}'::jsonb) + or (before_state::jsonb = '{"effective": false}'::jsonb + and after_state::jsonb = '{"effective": true}'::jsonb) + or ( + jsonb_typeof(before_state::jsonb)='object' + and jsonb_typeof(after_state::jsonb)='object' + and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 + and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 + and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] + and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] + and before_state::jsonb->'effective'='true'::jsonb + and after_state::jsonb->'effective'='false'::jsonb + and jsonb_typeof(before_state::jsonb->'role')='string' + and jsonb_typeof(before_state::jsonb->'scope_type')='string' + and jsonb_typeof(before_state::jsonb->'scope_id')='string' + and jsonb_typeof(before_state::jsonb->'future_obligation')='string' + and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') + and before_state::jsonb->>'scope_type'='project' + and before_state::jsonb->>'scope_id'=envelope_project_id + and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') + or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') + or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) + ); + else return false; + end case; + end $$; +CREATE FUNCTION public.authority_facts_are_safe(facts json) RETURNS boolean + LANGUAGE sql IMMUTABLE STRICT + AS $_$ + select json_typeof(facts) = 'object' + and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) + and not exists ( + select 1 from json_each(facts) item + where item.key not in ( + 'status', 'subject_kind', 'provisioning_method', 'role', + 'scope_type', 'scope_id', 'effective', 'allowed', + 'resource_context_digest' + ) + or case item.key + when 'status' then item.value #>> '{}' not in ( + 'active', 'suspended', 'deactivated', 'revoked', 'captured' + ) + when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') + when 'provisioning_method' then item.value #>> '{}' not in ( + 'automatic_first_access', 'manual_service_provisioning' + ) + when 'role' then item.value #>> '{}' not in ( + 'access_administrator', 'operator', 'project_manager', + 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' + ) + when 'scope_type' then item.value #>> '{}' not in ('system', 'project') + when 'scope_id' then (item.value #>> '{}') !~ + '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' + when 'effective' then json_typeof(item.value) <> 'boolean' + when 'allowed' then json_typeof(item.value) <> 'boolean' + when 'resource_context_digest' then (item.value #>> '{}') !~ + '^sha256:[0-9a-f]{64}$' + else true + end + ) + $_$; +CREATE FUNCTION public.authority_grant_facts_are_safe(facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text) RETURNS boolean + LANGUAGE sql IMMUTABLE + AS $$ + select authority_facts_are_safe(facts) + and facts->>'role' = any(roles) + and facts->>'status' = expected_status + and (facts->>'effective')::boolean = expected_effective + and ( + ( + facts->>'scope_type' = 'system' + and envelope_project_id is null + and not facts::jsonb ? 'scope_id' + and facts->>'role' not in ('submitter', 'reviewer', 'both') + and (select count(*) from json_each(facts)) = 4 + ) or ( + facts->>'scope_type' = 'project' + and envelope_project_id is not null + and facts->>'scope_id' = envelope_project_id + and facts->>'role' not in ('access_administrator', 'operator') + and (select count(*) from json_each(facts)) = 5 + ) + ) + $$; +CREATE FUNCTION public.enforce_compensation_binding_lifecycle() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'compensation_binding_updates_deferred'; + return new; + end; + $$; +CREATE FUNCTION public.guard_actor_identity_link_history() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; + if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) + is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then + raise exception 'actor identity link anchor is immutable' using errcode='55000'; + end if; + if new.status=old.status and + (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) + is distinct from + (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then + raise exception 'identity link attribution requires a transition' using errcode='23514'; + end if; + if old.status='active' and new.status='revoked' and + (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from + (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then + raise exception 'invalid identity link revocation attribution' using errcode='23514'; + end if; + if old.status='revoked' and new.status='active' and + ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) + or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) + or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from + (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then + raise exception 'invalid identity link reactivation attribution' using errcode='23514'; + end if; + if new.status <> old.status and not ( + (old.status='active' and new.status='revoked') or + (old.status='revoked' and new.status='active')) then + raise exception 'invalid identity link lifecycle transition' using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_actor_profile_history() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; + if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) + is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then + raise exception 'actor profile identity is immutable' using errcode='55000'; + end if; + if old.status='deactivated' and new.status <> 'deactivated' then + raise exception 'deactivated actor is terminal' using errcode='23514'; + end if; + if new.status = old.status and + (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, + new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from + (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, + old.deactivated_by,old.deactivated_at,old.deactivation_reason) then + raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; + end if; + if old.status='active' and new.status='suspended' and + (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) + is distinct from + (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then + raise exception 'invalid actor suspension attribution' using errcode='23514'; + end if; + if old.status='suspended' and new.status='active' and + ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) + or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) + or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from + (old.reactivated_by,old.reactivated_at,old.reactivation_reason) + or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from + (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then + raise exception 'invalid actor reactivation attribution' using errcode='23514'; + end if; + if new.status='deactivated' and old.status in ('active','suspended') and + (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) + is distinct from + (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then + raise exception 'invalid actor deactivation attribution' using errcode='23514'; + end if; + if new.status <> old.status and not ( + (old.status='active' and new.status in ('suspended','deactivated')) or + (old.status='suspended' and new.status in ('active','deactivated'))) then + raise exception 'invalid actor lifecycle transition' using errcode='23514'; + end if; + new.updated_at = statement_timestamp(); return new; + end $$; +CREATE FUNCTION public.guard_admin_role_grant() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare target_kind text; authorizer admin_role_grants%rowtype; + bootstrap_done boolean; + begin + if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; + if tg_op='INSERT' then + select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; + if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; + new.granted_at := clock_timestamp(); + if new.granted_by_system_principal is not null then + if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; + select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; + if bootstrap_done is distinct from false + or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then + raise exception 'bootstrap already completed' using errcode='23514'; + end if; + else + select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; + if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id + or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' + or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; + end if; + return new; + end if; + if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 + or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, + new.granted_by_actor_profile_id,new.granted_by_system_principal, + new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) + is distinct from + (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, + old.granted_by_actor_profile_id,old.granted_by_system_principal, + old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then + raise exception 'invalid admin role grant transition' using errcode='23514'; + end if; + select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; + if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id + or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' + or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; + new.revoked_at := clock_timestamp(); return new; + end $$; +CREATE FUNCTION public.guard_artifact_receipt_producer_reference() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare request_type text; + begin + select producer_request_type into request_type + from artifact_put_attempts where id = new.put_attempt_id; + if request_type is null + or (request_type = 'guide' and not ( + new.guide_source_item_id is not null and new.checker_run_id is null + and new.logical_role is null)) + or (request_type = 'checker_output' and not ( + new.guide_source_item_id is null and new.checker_run_id is not null + and octet_length(new.logical_role) between 1 and 100)) + or (request_type = 'submission_bundle' and not ( + new.guide_source_item_id is null and new.checker_run_id is null + and new.logical_role is null)) + then + raise exception 'artifact receipt producer reference mismatch' + using errcode='23514'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.guard_authority_control() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; + if old.id <> 1 or old.bootstrap_completed or old.version <> 0 + or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 + or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then + raise exception 'invalid authority control transition' using errcode='23514'; + end if; + new.updated_at := clock_timestamp(); return new; + end $$; +CREATE FUNCTION public.guard_authority_idempotency_record() RETURNS trigger + LANGUAGE plpgsql + AS $$ +declare success_count integer; invalidation_count integer; success_id text; + qualification_row audit_events%rowtype; success_row audit_events%rowtype; + grant_row project_role_grants%rowtype; + snapshot_row project_role_qualification_snapshots%rowtype; +begin + if tg_op = 'INSERT' then + if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; + new.created_at := statement_timestamp(); new.committed_at := null; return new; + elsif tg_op = 'DELETE' then + raise exception 'authority idempotency records are immutable' using errcode='55000'; + end if; + if old.status <> 'pending' or new.status <> 'committed' + or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, + new.request_digest,new.created_at) is distinct from + (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, + old.request_digest,old.created_at) then + raise exception 'invalid authority idempotency transition' using errcode='23514'; + end if; + select count(*), min(id) into success_count, success_id from audit_events + where event_domain='authority' and idempotency_reference=new.id + and event_type <> 'AuthorityInvalidationRequested'; + select count(*) into invalidation_count from audit_events + where event_domain='authority' and idempotency_reference=new.id + and event_type='AuthorityInvalidationRequested'; + if new.operation='project_role_grant.issue' then + if success_count <> 2 or invalidation_count <> 0 + or (select count(*) from audit_events where idempotency_reference=new.id + and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 + or (select count(*) from audit_events where idempotency_reference=new.id + and event_type='ProjectRoleGrantIssued') <> 1 then + raise exception 'project role issue evidence pair required' using errcode='23514'; + end if; + select * into qualification_row from audit_events where idempotency_reference=new.id + and event_type='ProjectRoleQualificationSnapshotCaptured'; + select * into success_row from audit_events where idempotency_reference=new.id + and event_type='ProjectRoleGrantIssued'; + select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; + select * into snapshot_row from project_role_qualification_snapshots + where id=qualification_row.resource_id::uuid; + if not found or grant_row.id is null or snapshot_row.id is null + or grant_row.qualification_snapshot_id <> snapshot_row.id + or grant_row.project_id <> snapshot_row.project_id + or grant_row.actor_profile_id <> snapshot_row.actor_profile_id + or grant_row.role <> snapshot_row.requested_role + or qualification_row.project_id is distinct from grant_row.project_id + or success_row.project_id is distinct from grant_row.project_id + or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id + or success_row.target_actor_ref is distinct from grant_row.actor_profile_id + or qualification_row.request_id is distinct from success_row.request_id + or qualification_row.correlation_id is distinct from success_row.correlation_id + or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind + or qualification_row.actor_id is distinct from success_row.actor_id + or qualification_row.permission_id is distinct from success_row.permission_id + or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then + raise exception 'project role issue evidence mismatch' using errcode='23514'; + end if; + else + if success_count <> 1 or invalidation_count <> 1 then + raise exception 'authority evidence pair required' using errcode='23514'; + end if; + select * into success_row from audit_events where id=success_id; + end if; + if success_row.resource_type <> new.response_resource_type + or success_row.resource_id <> new.response_resource_id::text then + raise exception 'authority response does not match evidence' using errcode='23514'; + end if; + new.committed_at := statement_timestamp(); return new; +end $$; +CREATE FUNCTION public.guard_contribution_policy_children() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare old_parent_status text; + declare new_parent_status text; + begin + if tg_op in ('UPDATE','DELETE') then + select status into old_parent_status from contribution_policy_versions + where id=old.contribution_policy_version_id for update; + end if; + if tg_op in ('INSERT','UPDATE') then + select status into new_parent_status from contribution_policy_versions + where id=new.contribution_policy_version_id for update; + end if; + if old_parent_status in ('published','retired') + or new_parent_status in ('published','retired') then + raise exception 'published contribution policy rules and definitions are immutable' + using errcode='55000'; + end if; + return case when tg_op='DELETE' then old else new end; + end; + $$; +CREATE FUNCTION public.guard_contribution_policy_version_content() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op='DELETE' and old.status in ('published','retired') then + raise exception 'published contribution policy versions are immutable' + using errcode='55000'; + end if; + if tg_op='UPDATE' and old.status='retired' then + raise exception 'retired contribution policy versions are immutable' + using errcode='55000'; + end if; + if tg_op='UPDATE' and old.status='published' and not ( + new.status='retired' + and new.id=old.id + and new.contribution_policy_id=old.contribution_policy_id + and new.project_id=old.project_id + and new.version_number=old.version_number + and new.created_by=old.created_by + and new.created_at=old.created_at + and new.published_by=old.published_by + and new.published_at=old.published_at + and new.retired_by is not null + and new.retired_at is not null + ) then + raise exception 'published contribution policy version content is immutable' + using errcode='55000'; + end if; + return case when tg_op='DELETE' then old else new end; + end; + $$; +CREATE FUNCTION public.guard_guide_lineage_and_lifecycle() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + if (new.id,new.project_id,new.version) + is distinct from (old.id,old.project_id,old.version) then + raise exception 'guide identity and lineage are immutable' using errcode='23514'; + end if; + if (new.status,new.approved_by,new.effective_at,new.superseded_at) + is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then + raise exception 'guide lifecycle mutation requires activation authority' + using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_guide_mutation_idempotency() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + if tg_op='INSERT' then + if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; + return new; + elsif tg_op='DELETE' then + raise exception 'guide mutation custody is immutable' using errcode='55000'; + end if; + if new is not distinct from old then return new; end if; + if old.status<>'pending' or new.status<>'committed' + or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, + new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, + new.operation_generation,new.created_at) + is distinct from + (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, + old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, + old.operation_generation,old.created_at) then + raise exception 'invalid guide mutation custody transition' using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_iso_4217_currency_codes() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' + using errcode='55000'; + end; + $$; +CREATE FUNCTION public.guard_outbox_event() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare event_time timestamptz; + begin + if tg_op = 'TRUNCATE' then + raise exception 'outbox events cannot be truncated' using errcode='55000'; + elsif tg_op = 'DELETE' then + raise exception 'outbox events cannot be deleted' using errcode='55000'; + elsif tg_op = 'INSERT' then + event_time := statement_timestamp(); + new.producer := 'workstream'; + new.occurred_at := event_time; + new.delivery_state := 'pending'; + new.attempt_count := 0; + new.next_attempt_at := event_time; + new.claim_owner := null; + new.claim_generation := 0; + new.claimed_at := null; + new.claim_expires_at := null; + new.last_attempt_at := null; + new.last_error_code := null; + new.finalized_at := null; + new.archived_at := null; + return new; + end if; + if (new.event_id, new.event_type, new.event_version, new.producer, + new.aggregate_type, new.aggregate_id, new.project_id, + new.correlation_id, new.causation_event_id, new.idempotency_key, + new.payload, new.payload_digest, new.occurred_at) + is distinct from + (old.event_id, old.event_type, old.event_version, old.producer, + old.aggregate_type, old.aggregate_id, old.project_id, + old.correlation_id, old.causation_event_id, old.idempotency_key, + old.payload, old.payload_digest, old.occurred_at) then + raise exception 'outbox event envelope is immutable' using errcode='55000'; + end if; + if new.attempt_count < old.attempt_count + or new.claim_generation < old.claim_generation + or new.attempt_count <> new.claim_generation then + raise exception 'outbox counters cannot regress' using errcode='23514'; + end if; + if old.archived_at is not null and + (new.delivery_state, new.attempt_count, new.next_attempt_at, + new.claim_owner, new.claim_generation, new.claimed_at, + new.claim_expires_at, new.last_attempt_at, new.last_error_code, + new.finalized_at, new.archived_at) + is distinct from + (old.delivery_state, old.attempt_count, old.next_attempt_at, + old.claim_owner, old.claim_generation, old.claimed_at, + old.claim_expires_at, old.last_attempt_at, old.last_error_code, + old.finalized_at, old.archived_at) then + raise exception 'archived outbox event is closed' using errcode='55000'; + end if; + if old.delivery_state in ('pending', 'retryable') + and new.delivery_state = 'claimed' then + if new.attempt_count <> old.attempt_count + 1 + or new.claim_generation <> old.claim_generation + 1 + or new.last_error_code is distinct from old.last_error_code then + raise exception 'outbox claim generation must increment once' using errcode='23514'; + end if; + elsif old.delivery_state = 'claimed' + and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then + if new.attempt_count <> old.attempt_count + or new.claim_generation <> old.claim_generation + or new.last_attempt_at is distinct from old.last_attempt_at then + raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; + end if; + elsif old.delivery_state = 'dead_letter' + and new.delivery_state = 'retryable' and old.archived_at is null then + if new.attempt_count <> old.attempt_count + or new.claim_generation <> old.claim_generation + or new.last_attempt_at is distinct from old.last_attempt_at + or new.last_error_code is distinct from old.last_error_code then + raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; + end if; + elsif old.delivery_state in ('pending','retryable') + and new.delivery_state = 'cancelled' then + if new.attempt_count <> old.attempt_count + or new.claim_generation <> old.claim_generation + or new.last_attempt_at is distinct from old.last_attempt_at + or new.last_error_code is distinct from old.last_error_code then + raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; + end if; + elsif old.delivery_state in ('pending','retryable') + and new.delivery_state = old.delivery_state then + if (new.attempt_count, new.claim_owner, new.claim_generation, + new.claimed_at, new.claim_expires_at, new.last_attempt_at, + new.last_error_code, new.finalized_at, new.archived_at) + is distinct from + (old.attempt_count, old.claim_owner, old.claim_generation, + old.claimed_at, old.claim_expires_at, old.last_attempt_at, + old.last_error_code, old.finalized_at, old.archived_at) then + raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; + end if; + elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') + and new.delivery_state = old.delivery_state then + if (new.attempt_count, new.next_attempt_at, new.claim_owner, + new.claim_generation, new.claimed_at, new.claim_expires_at, + new.last_attempt_at, new.last_error_code, new.finalized_at) + is distinct from + (old.attempt_count, old.next_attempt_at, old.claim_owner, + old.claim_generation, old.claimed_at, old.claim_expires_at, + old.last_attempt_at, old.last_error_code, old.finalized_at) + or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) + or (old.archived_at is null and new.archived_at is null) then + raise exception 'terminal outbox event permits archival only' using errcode='23514'; + end if; + else + raise exception 'illegal outbox delivery transition' using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_policy_mutation_replay() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op='INSERT' then + if new.status<>'pending' then + raise exception 'policy mutation must begin pending' using errcode='23514'; + end if; + return new; + elsif tg_op='DELETE' then + raise exception 'policy mutation replay is immutable' using errcode='55000'; + elsif new is not distinct from old then + return new; + elsif old.status='pending' and new.status='committed' + and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, + new.idempotency_key,new.request_digest,new.policy_hash, + new.resource_context_digest, + new.operation_id,new.project_id,new.guide_id,new.policy_id, + new.policy_generation,new.created_at) + is not distinct from + (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, + old.idempotency_key,old.request_digest,old.policy_hash, + old.resource_context_digest, + old.operation_id,old.project_id,old.guide_id,old.policy_id, + old.policy_generation,old.created_at) then + return new; + end if; + raise exception 'policy mutation replay is immutable' using errcode='23514'; + end $$; +CREATE FUNCTION public.guard_pre_submit_evidence_result_membership() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare parent_created_at timestamptz; expected_count integer; current_count integer; + begin + select created_at, result_count into parent_created_at, expected_count + from pre_submit_evidence_sets where id=new.evidence_set_id for key share; + select count(*) into current_count from pre_submit_evidence_results + where evidence_set_id=new.evidence_set_id; + if parent_created_at is null + or parent_created_at <> transaction_timestamp() + or current_count >= expected_count then + raise exception 'pre-submit evidence result membership is closed' + using errcode='55000'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.guard_pre_submit_evidence_results_immutable() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'pre_submit_evidence_results rows are immutable' using errcode='55000'; + end; + $$; +CREATE FUNCTION public.guard_pre_submit_evidence_set_creation() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if new.created_at is distinct from transaction_timestamp() then + raise exception 'pre-submit evidence creation timestamp is invalid' + using errcode='55000'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.guard_pre_submit_evidence_sets_immutable() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'pre_submit_evidence_sets rows are immutable' using errcode='55000'; + end; + $$; +CREATE FUNCTION public.guard_project_compensation_units() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op in ('UPDATE','DELETE') then + raise exception 'project compensation-unit lifecycle behavior is deferred' + using errcode='55000'; + end if; + if new.status <> 'active' then + raise exception 'project compensation units must begin active' + using errcode='23514'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.guard_project_create_idempotency() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op = 'INSERT' then + if new.status <> 'pending' or new.committed_at is not null then + raise exception 'project create reservation must begin pending' using errcode='23514'; + end if; + return new; + elsif tg_op = 'DELETE' then + raise exception 'project create reservations are immutable' using errcode='55000'; + end if; + if new is not distinct from old then + return new; + end if; + if old.status <> 'pending' or new.status <> 'committed' + or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, + new.idempotency_key, new.request_digest, new.operation_id, + new.project_id, new.operation_generation, new.created_at) + is distinct from + (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, + old.idempotency_key, old.request_digest, old.operation_id, + old.project_id, old.operation_generation, old.created_at) then + raise exception 'invalid project create reservation transition' using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_project_guide_compilation_attempt_update() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, + new.source_snapshot_hash,new.setup_run_id,new.setup_generation, + new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, + new.pre_catalogue_version,new.pre_catalogue_schema_version, + new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, + new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, + new.agent_identity,new.agent_version,new.instruction_version, + new.provider_idempotency_key) + is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, + old.source_snapshot_hash,old.setup_run_id,old.setup_generation, + old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, + old.pre_catalogue_version,old.pre_catalogue_schema_version, + old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, + old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, + old.agent_identity,old.agent_version,old.instruction_version, + old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; + if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; + if new.reserved_at is distinct from old.reserved_at then + raise exception 'compilation reservation timestamp is immutable'; + end if; + if new.provider_uncertain_at is distinct from old.provider_uncertain_at and + not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then + raise exception 'provider uncertainty timestamp is immutable'; + end if; + if new.accepted_at is distinct from old.accepted_at and + not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then + raise exception 'accepted timestamp is immutable'; + end if; + if new.terminal_at is distinct from old.terminal_at and + not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then + raise exception 'terminal timestamp is immutable'; + end if; + if row(new.persisted_at,new.persisted_compilation_id) is distinct from + row(old.persisted_at,old.persisted_compilation_id) and + not (old.status='provider_result_accepted' and new.status='compilation_persisted') then + raise exception 'persisted custody is immutable'; + end if; + if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) + is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then + raise exception 'accepted compilation result is immutable'; + end if; + if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or + (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or + (old.status='provider_result_accepted' and new.status='compilation_persisted')) then + raise exception 'invalid compilation attempt transition'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_project_guide_compilation_insert() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare predecessor_generation bigint; + declare source_attempt project_guide_compilation_attempts%rowtype; + begin + select * into source_attempt from project_guide_compilation_attempts + where id=new.attempt_id for update; + if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or + row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, + new.source_snapshot_hash,new.setup_run_id,new.setup_generation, + new.canonical_input_hash,new.guide_material_hash, + new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, + new.agent_identity,new.agent_version,new.instruction_version, + new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) + is distinct from + row(source_attempt.project_id,source_attempt.guide_id, + source_attempt.guide_version,source_attempt.source_snapshot_id, + source_attempt.source_snapshot_hash,source_attempt.setup_run_id, + source_attempt.setup_generation,source_attempt.canonical_input_hash, + source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, + source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, + source_attempt.agent_version,source_attempt.instruction_version, + source_attempt.canonical_result::jsonb,source_attempt.result_hash, + source_attempt.component_hashes::jsonb) then + raise exception 'compilation does not match its accepted attempt'; + end if; + if not exists( + select 1 from audit_events event + join actor_profiles profile on profile.id=new.created_by_actor_profile_id + join actor_identity_links link on link.id=new.created_via_identity_link_id + and link.actor_profile_id=profile.id + where event.id=new.authorization_decision_event_id + and event.event_domain='authority' + and event.event_type='SensitiveAuthorizationAllowed' + and event.denial_code is null + and event.actor_id=new.created_by_actor_profile_id + and event.permission_id='project.guide_compilation.execute' + and event.action_id='project.guide_compilation.execute' + and event.project_id=new.project_id + and event.resource_type='project_guide_compilation_attempt' + and event.resource_id=new.attempt_id::text + and event.after_facts->>'allowed'='true' + and event.after_facts->>'resource_context_digest'= + new.authorization_resource_context_digest + and profile.actor_kind='service' and profile.status='active' + and profile.service_identity='workstream.project.setup' + and link.subject_kind='service' and link.status='active' + and link.issuer='workstream-internal' + and link.subject='workstream.project.setup' + ) then + raise exception 'compilation authorization evidence is invalid'; + end if; + if new.supersedes_compilation_id is null then return new; end if; + select setup_generation into predecessor_generation + from project_guide_compilations + where id=new.supersedes_compilation_id + and project_id=new.project_id and guide_id=new.guide_id; + if predecessor_generation is null or predecessor_generation >= new.setup_generation then + raise exception 'compilation generation must strictly advance'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_project_guide_policy_selection() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + if old.status in ('active','superseded') and ( + new.selected_review_policy_id is distinct from old.selected_review_policy_id or + new.selected_review_policy_generation is distinct from + old.selected_review_policy_generation or + new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or + new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or + new.selected_revision_policy_generation is distinct from + old.selected_revision_policy_generation or + new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash + ) then + raise exception 'active guide policy selection is immutable' using errcode='55000'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_project_role_grant_history() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; + if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; + if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, + new.qualification_snapshot_id,new.granted_by_actor_profile_id, + new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) + is distinct from + (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, + old.qualification_snapshot_id,old.granted_by_actor_profile_id, + old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) + or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 + or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null + or new.revoked_reason is null then + raise exception 'invalid project-role grant history transition' using errcode='23514'; + end if; + new.revoked_at := clock_timestamp(); + return new; + end $$; +CREATE FUNCTION public.guard_project_role_snapshot_history() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; + raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.guard_review_admission_record() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare + task_project text; + checker_row checker_runs%rowtype; + begin + if tg_op='DELETE' then + raise exception 'review admission records cannot be deleted' using errcode='55000'; + end if; + if tg_op='INSERT' and new.status <> 'pending' then + raise exception 'review admission must begin pending' using errcode='23514'; + end if; + if tg_op='INSERT' then + new.created_at := statement_timestamp(); + end if; + if tg_op='UPDATE' then + if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, + new.task_id,new.submission_id,new.submission_version, + new.admitting_checker_run_id,new.created_at) + is distinct from + (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, + old.task_id,old.submission_id,old.submission_version, + old.admitting_checker_run_id,old.created_at) then + raise exception 'review admission identity is immutable' using errcode='55000'; + end if; + if old.status <> 'pending' or new.status <> 'committed' then + raise exception 'invalid review admission transition' using errcode='23514'; + end if; + end if; + select project_id into task_project from workstream_tasks where id=new.task_id; + if task_project is null or task_project <> new.project_id then + raise exception 'review admission task project mismatch' using errcode='23514'; + end if; + select * into checker_row from checker_runs where id=new.admitting_checker_run_id; + if not found or checker_row.task_id <> new.task_id + or checker_row.submission_id <> new.submission_id + or checker_row.submission_version <> new.submission_version then + raise exception 'review admission checker lineage mismatch' using errcode='23514'; + end if; + if new.status='committed' and ( + checker_row.status <> 'completed' + or checker_row.routing_recommendation <> 'allow_review' + or checker_row.is_current_for_submission is not true) then + raise exception 'review admission checker is not admissible' using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_review_lease() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare + actor_type text; + policy_status text; + begin + if tg_op='DELETE' then + raise exception 'review leases cannot be deleted' using errcode='55000'; + end if; + if tg_op='INSERT' then + if new.status <> 'active' then + raise exception 'review lease must begin active' using errcode='23514'; + end if; + new.claimed_at := statement_timestamp(); + new.closed_at := null; + new.close_reason := null; + else + if old.status <> 'active' then + raise exception 'terminal review leases are immutable' using errcode='55000'; + end if; + if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, + new.submission_version,new.reviewer_id, + new.reviewer_contribution_policy_version_id,new.attempt_generation, + new.claimed_at,new.expires_at) + is distinct from + (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, + old.submission_version,old.reviewer_id, + old.reviewer_contribution_policy_version_id,old.attempt_generation, + old.claimed_at,old.expires_at) then + raise exception 'review lease identity is immutable' using errcode='55000'; + end if; + if new.status='active' then + raise exception 'review lease update must close attempt' using errcode='23514'; + end if; + end if; + select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; + if actor_type is distinct from 'human' then + raise exception 'review lease reviewer must be human' using errcode='23514'; + end if; + if tg_op='INSERT' then + select status into policy_status from contribution_policy_versions + where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; + if policy_status is distinct from 'published' then + raise exception 'review lease policy version must be published' using errcode='23514'; + end if; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_review_policies_immutable() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'review_policies rows are immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.guard_review_queue_entry() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare + task_project text; + checker_row checker_runs%rowtype; + begin + if tg_op='DELETE' then + raise exception 'review queue entries cannot be deleted' using errcode='55000'; + end if; + if tg_op='INSERT' then + if new.queue_state <> 'pending' then + raise exception 'review queue must begin pending' using errcode='23514'; + end if; + new.first_queued_at := statement_timestamp(); + new.available_since := new.first_queued_at; + new.routing_generation := 1; + new.lifecycle_generation := 1; + new.created_at := new.first_queued_at; + end if; + if tg_op='UPDATE' then + if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, + new.admitting_checker_run_id,new.first_queued_at,new.created_at) + is distinct from + (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, + old.admitting_checker_run_id,old.first_queued_at,old.created_at) then + raise exception 'review queue identity is immutable' using errcode='55000'; + end if; + if old.queue_state='closed' and new.queue_state <> 'closed' then + raise exception 'closed review queue entries cannot reopen' using errcode='23514'; + end if; + if new.routing_generation < old.routing_generation + or new.lifecycle_generation < old.lifecycle_generation then + raise exception 'review queue generations cannot decrease' using errcode='23514'; + end if; + end if; + if new.preferred_reviewer_id is not null and not exists( + select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' + ) then + raise exception 'preferred reviewer must be human' using errcode='23514'; + end if; + if tg_op='UPDATE' then return new; end if; + select project_id into task_project from workstream_tasks where id=new.task_id; + if task_project is null or task_project <> new.project_id then + raise exception 'review queue task project mismatch' using errcode='23514'; + end if; + select * into checker_row from checker_runs where id=new.admitting_checker_run_id; + if not found or checker_row.task_id <> new.task_id + or checker_row.submission_id <> new.submission_id + or checker_row.submission_version <> new.submission_version then + raise exception 'review queue checker lineage mismatch' using errcode='23514'; + end if; + if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' + or checker_row.is_current_for_submission is not true then + raise exception 'review queue checker is not admissible' using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.guard_revision_policies_immutable() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'revision_policies rows are immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.guard_service_identity_migration_evidence() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + raise exception 'service identity migration evidence is immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.guard_submission_bundle_admission_delete() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $$; +CREATE FUNCTION public.guard_submission_bundle_admission_lineage() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, + old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, + old.put_operation_receipt_id, old.put_observation_receipt_id, + old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, + old.assignment_id, old.predecessor_submission_id, + old.predecessor_submission_version, + old.locked_policy_context_hash, + old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, + old.archive_byte_count, old.ready_at, old.created_at) + is distinct from + row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, + new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, + new.put_operation_receipt_id, new.put_observation_receipt_id, + new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, + new.assignment_id, new.predecessor_submission_id, + new.predecessor_submission_version, + new.locked_policy_context_hash, + new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, + new.archive_byte_count, new.ready_at, new.created_at) + then + raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; + end if; + if old.status <> 'ready' or new.status not in ('consumed','stale') then + raise exception 'invalid submission bundle admission transition' using errcode='23514'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.guard_submission_bundle_admission_verified_lineage() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare matches integer; + begin + select count(*) into matches + from submission_bundle_durable_intents intent + join pre_submit_evidence_sets evidence + on evidence.id=intent.pre_submit_evidence_set_id + join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id + join artifact_replicas replica on replica.id=attempt.replica_id + join artifact_contents content on content.id=replica.content_id + join artifact_verification_jobs job + on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id + join artifact_verification_receipts verification + on verification.verification_job_id=job.id + where intent.id=new.durable_intent_id + and evidence.id=new.pre_submit_evidence_set_id + and attempt.id=new.put_attempt_id + and content.id=new.artifact_content_id + and replica.id=new.verified_replica_id + and verification.id=new.verification_receipt_id + and attempt.producer_request_type='submission_bundle' + and attempt.producer_type='actor_profile' + and attempt.producer_ref=evidence.actor_profile_id + and attempt.project_id=evidence.project_id + and attempt.task_id=evidence.task_id + and attempt.media_type='application/zip' + and content.media_type='application/zip' + and attempt.status='object_confirmed' + and evidence.terminal_status='passed' and evidence.eligible + and replica.verification_state='verified' + and replica.availability_state='available' + and replica.integrity_state='valid' + and verification.outcome='verified' + and verification.execution_generation=job.execution_generation + and verification.observed_sha256=attempt.sha256 + and verification.observed_sha256=content.sha256 + and verification.observed_sha256=evidence.archive_sha256 + and verification.observed_byte_count=attempt.byte_count + and verification.observed_byte_count=content.byte_count + and verification.observed_byte_count=evidence.archive_byte_count + and new.actor_profile_id=evidence.actor_profile_id + and new.identity_link_id=evidence.identity_link_id + and new.project_id=evidence.project_id and new.task_id=evidence.task_id + and new.assignment_id=evidence.assignment_id + and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id + and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version + and new.locked_policy_context_hash=evidence.locked_policy_context_hash + and new.semantic_manifest_id=evidence.semantic_manifest_id + and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 + and new.archive_sha256=evidence.archive_sha256 + and new.archive_byte_count=evidence.archive_byte_count + and ((new.put_operation_receipt_id is not null and exists ( + select 1 from artifact_operation_receipts receipt + where receipt.id=new.put_operation_receipt_id + and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id + and receipt.outcome='stored_pending_verification')) + or (new.put_observation_receipt_id is not null and exists ( + select 1 from artifact_put_observation_receipts observation + where observation.id=new.put_observation_receipt_id + and observation.put_attempt_id=attempt.id + and observation.outcome='observed_confirmed' + and observation.observed_sha256=attempt.sha256 + and observation.observed_byte_count=attempt.byte_count))); + if matches <> 1 then + raise exception 'submission bundle admission verified lineage mismatch' + using errcode='23514'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare request_type text; + begin + select producer_request_type into request_type + from artifact_put_attempts + where id = new.put_attempt_id + for share; + if request_type is distinct from 'submission_bundle' then + raise exception 'submission bundle durable intent requires submission_bundle put attempt' + using errcode='23514'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.guard_submission_bundle_durable_intents_immutable() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'submission_bundle_durable_intents rows are immutable' + using errcode='55000'; + end; + $$; +CREATE FUNCTION public.project_role_availability_is_safe(value jsonb) RETURNS boolean + LANGUAGE sql IMMUTABLE STRICT + AS $$ + select jsonb_typeof(value)='object' and + (select count(*)=3 from jsonb_object_keys(value)) and + value ?& array['availability','reference_ids','unavailable_reason'] and + project_role_reference_array_is_safe(value->'reference_ids',false) and ( + (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 + and value->'unavailable_reason'='null'::jsonb) or + (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 + and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) + ) + $$; +CREATE FUNCTION public.project_role_reason_is_safe(value text) RETURNS boolean + LANGUAGE plpgsql IMMUTABLE STRICT + AS $$ + declare point integer; index integer; + begin + if octet_length(value) not between 1 and 500 or value <> btrim(value, (E' \t\n\r\f\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)||chr(8239)||chr(8287)||chr(12288))) then return false; end if; + for index in 1..char_length(value) loop + point := ascii(substr(value,index,1)); + if point between 0 and 31 or point between 127 and 159 + or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then + return false; + end if; + end loop; + return true; + end $$; +CREATE FUNCTION public.project_role_reference_array_is_safe(value jsonb, uuid_only boolean) RETURNS boolean + LANGUAGE sql IMMUTABLE STRICT + AS $_$ + select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 + and not exists ( + select 1 from jsonb_array_elements(value) item + where jsonb_typeof(item)<>'string' or + case when uuid_only then not (item #>> '{}') ~ + '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' + else not project_role_reference_token_is_safe(item #>> '{}') end + ) + $_$; +CREATE FUNCTION public.project_role_reference_token_is_safe(value text) RETURNS boolean + LANGUAGE sql IMMUTABLE STRICT + AS $_$ + select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 + $_$; +CREATE FUNCTION public.protect_submission_policy_approval_provenance() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if old.approval_action_id is not null and + (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, + new.approved_by_admin_role_grant_id,new.approval_scope_type, + new.approval_scope_project_id,new.approval_action_id, + new.approval_decision_event_id) + is distinct from + (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, + old.approved_by_admin_role_grant_id,old.approval_scope_type, + old.approval_scope_project_id,old.approval_action_id, + old.approval_decision_event_id) then + raise exception 'submission-policy approval provenance is immutable' + using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.protect_submission_policy_creation_provenance() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if old.creation_action_id is not null and + (new.created_by_actor_profile_id,new.created_via_identity_link_id, + new.created_by_admin_role_grant_id,new.created_by_service_identity, + new.creation_scope_type,new.creation_scope_project_id, + new.creation_action_id,new.creation_decision_event_id) + is distinct from + (old.created_by_actor_profile_id,old.created_via_identity_link_id, + old.created_by_admin_role_grant_id,old.created_by_service_identity, + old.creation_scope_type,old.creation_scope_project_id, + old.creation_action_id,old.creation_decision_event_id) then + raise exception 'submission-policy creation provenance is immutable' + using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.protect_submission_policy_output_provenance() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if old.creation_action_id is not null and + (new.created_by_actor_profile_id,new.created_via_identity_link_id, + new.created_by_admin_role_grant_id,new.creation_scope_type, + new.creation_scope_project_id,new.creation_action_id, + new.creation_decision_event_id) + is distinct from + (old.created_by_actor_profile_id,old.created_via_identity_link_id, + old.created_by_admin_role_grant_id,old.creation_scope_type, + old.creation_scope_project_id,old.creation_action_id, + old.creation_decision_event_id) then + raise exception 'submission-policy output provenance is immutable' + using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.reject_admin_role_grant_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin raise exception 'admin role grants are immutable' using errcode='55000'; end $$; +CREATE FUNCTION public.reject_artifact_fact_mutation() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception '% rows are immutable', tg_table_name; + end; + $$; +CREATE FUNCTION public.reject_audit_event_mutation() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'audit events are append-only' using errcode = '55000'; + end + $$; +CREATE FUNCTION public.reject_authority_control_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin raise exception 'authority control is immutable' using errcode='55000'; end $$; +CREATE FUNCTION public.reject_authority_idempotency_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + raise exception 'authority idempotency records are immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.reject_contribution_policy_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'contribution policy persistence cannot be truncated' + using errcode='55000'; + end; + $$; +CREATE FUNCTION public.reject_guide_mutation_idempotency_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + raise exception 'guide mutation custody is immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.reject_guide_source_snapshot_item_mutation() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + raise exception 'guide source snapshot items are immutable' using errcode='23514'; + end $$; +CREATE FUNCTION public.reject_pending_authority_idempotency() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then + raise exception 'pending authority idempotency cannot commit' using errcode='23514'; + end if; return null; + end $$; +CREATE FUNCTION public.reject_policy_mutation_replay_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + raise exception 'policy mutation replay is immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.reject_project_create_idempotency_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + raise exception 'project create reservations are immutable' using errcode='55000'; + end $$; +CREATE FUNCTION public.reject_project_guide_compilation_mutation() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin raise exception 'compilation custody is append-only'; end $$; +CREATE FUNCTION public.reject_project_role_history_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $$; +CREATE FUNCTION public.reject_review_lease_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'review leases cannot be truncated' using errcode='55000'; + end $$; +CREATE FUNCTION public.reject_review_queue_foundation_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'review queue foundation cannot be truncated' using errcode='55000'; + end $$; +CREATE FUNCTION public.reject_submission_policy_replay_mutation() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op = 'DELETE' then + raise exception 'submission-policy replay rows cannot be deleted'; + end if; + if old.status = 'reserved' and new.status = 'pending' + and old.service_identity = 'workstream.project.setup' + and old.action_id = 'project.submission_artifact_policy.derive' + and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, + new.action_id,new.idempotency_key,new.operation_id,new.project_id, + new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, + new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, + new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, + new.committed_pre_submit_policy_id,new.committed_at) + is not distinct from + (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, + old.action_id,old.idempotency_key,old.operation_id,old.project_id, + old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, + old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, + old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, + old.committed_pre_submit_policy_id,old.committed_at) + then + return new; + end if; + if old.status <> 'pending' or new.status <> 'committed' + or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, + new.action_id,new.idempotency_key,new.request_digest, + new.resource_context_digest,new.resource_context_json::text,new.operation_id, + new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, + new.setup_run_id,new.setup_generation,new.setup_task_id, + new.correlation_id,new.created_at) + is distinct from + (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, + old.action_id,old.idempotency_key,old.request_digest, + old.resource_context_digest,old.resource_context_json::text,old.operation_id, + old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, + old.setup_run_id,old.setup_generation,old.setup_task_id, + old.correlation_id,old.created_at) + then + raise exception 'invalid submission-policy replay mutation'; + end if; + return new; + end $$; +CREATE FUNCTION public.reject_submission_policy_replay_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ begin + raise exception 'submission-policy replay rows cannot be truncated'; + end $$; +CREATE FUNCTION public.reject_sufficiency_replay_mutation() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if tg_op = 'DELETE' then + raise exception 'guide sufficiency replay rows are append-only'; + end if; + if old.status = 'committed' or new.status <> 'committed' + or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, + new.idempotency_key,new.request_digest, + new.resource_context_digest, + new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, + new.setup_run_id,new.setup_generation,new.created_at) + is distinct from + (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, + old.idempotency_key,old.request_digest, + old.resource_context_digest, + old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, + old.setup_run_id,old.setup_generation,old.created_at) + then + raise exception 'invalid guide sufficiency replay mutation'; + end if; + return new; + end $$; +CREATE FUNCTION public.reject_sufficiency_replay_truncate() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + raise exception 'guide sufficiency replay rows are append-only'; + end $$; +CREATE FUNCTION public.require_human_actor_profile_reference() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare referenced_id text; referenced_kind text; + begin + if tg_nargs <> 1 or tg_argv[0] is null + or not (to_jsonb(new) ? tg_argv[0]) then + raise exception 'human actor reference trigger is misconfigured' + using errcode='55000'; + end if; + referenced_id := to_jsonb(new) ->> tg_argv[0]; + if referenced_id is null then return new; end if; + select profile.actor_kind into referenced_kind + from public.actor_profiles profile where profile.id=referenced_id; + if not found then return new; end if; + if referenced_kind <> 'human' then + raise exception 'actor reference must identify a human profile' + using errcode='23514', constraint='require_human_actor_profile_reference'; + end if; + return new; + end $$; +CREATE FUNCTION public.set_authority_audit_database_time() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if new.event_domain = 'authority' then + if new.invalidation_cause_event_id is not null and not exists ( + select 1 from audit_events + where id = new.invalidation_cause_event_id and event_domain = 'authority' + ) then + raise exception 'invalid authority invalidation cause' using errcode = '23503'; + end if; + new.occurred_at = statement_timestamp(); + else + new.occurred_at = null; + end if; + return new; + end + $$; +CREATE FUNCTION public.validate_artifact_binding_history() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare predecessor artifact_bindings%rowtype; + begin + if new.scope_version = 1 then + return new; + end if; + select * into predecessor + from artifact_bindings where id = new.supersedes_binding_id; + if not found + or predecessor.project_id != new.project_id + or predecessor.resource_type != new.resource_type + or predecessor.resource_id != new.resource_id + or predecessor.logical_role != new.logical_role + or predecessor.scope_version + 1 != new.scope_version then + raise exception 'artifact binding predecessor is invalid'; + end if; + return new; + end; + $$; +CREATE FUNCTION public.validate_artifact_recovery_attempt() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare + source_row artifact_verification_jobs%rowtype; + retry_row artifact_verification_jobs%rowtype; + expected_parent text; + begin + if tg_op = 'DELETE' then + raise exception 'artifact recovery attempts are append-only' using errcode='55000'; + end if; + if tg_op = 'UPDATE' and ( + to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', + 'terminal_at','cas_version','updated_at'] + is distinct from + to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', + 'terminal_at','cas_version','updated_at'] + ) then + raise exception 'artifact recovery identity is immutable' using errcode='55000'; + end if; + select * into source_row from artifact_verification_jobs + where id=new.source_verification_job_id; + select * into retry_row from artifact_verification_jobs + where id=new.retry_verification_job_id; + if source_row.id is null or retry_row.id is null + or source_row.status <> 'provider_unavailable' + or source_row.terminal_result_code <> 'provider_unavailable' + or source_row.terminal_at is null or source_row.next_run_at is not null + or source_row.executor_id is not null + or source_row.attempt_count < source_row.maximum_attempts + or retry_row.parent_verification_job_id <> source_row.id + or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id + or retry_row.replica_id <> source_row.replica_id then + raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; + end if; + if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) + or (tg_op = 'UPDATE' and ( + retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null + )) then + raise exception 'invalid artifact recovery retry state' using errcode='23514'; + end if; + select id into expected_parent from artifact_recovery_attempts + where retry_verification_job_id=source_row.id; + if new.parent_recovery_attempt_id is distinct from expected_parent then + raise exception 'invalid artifact recovery parent chain' using errcode='23514'; + end if; + if not exists ( + select 1 from audit_events where id=new.initiation_audit_event_id + and entity_type='artifact_recovery_attempt' and entity_id=new.id + and event_type='ArtifactRecoveryInitiated' + ) then + raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; + end if; + if new.terminal_audit_event_id is not null and not exists ( + select 1 from audit_events where id=new.terminal_audit_event_id + and entity_type='artifact_recovery_attempt' and entity_id=new.id + and event_type='ArtifactRecoveryCompleted' + ) then + raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; + end if; + return new; + end $$; +CREATE FUNCTION public.validate_artifact_verification_lineage() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if ( + old.parent_verification_job_id is not null + or exists( + select 1 from artifact_recovery_attempts + where source_verification_job_id = old.id + or retry_verification_job_id = old.id + ) + ) and ( + old.originating_put_attempt_id is distinct from new.originating_put_attempt_id + or old.replica_id is distinct from new.replica_id + or old.parent_verification_job_id is distinct from new.parent_verification_job_id + ) then + raise exception 'artifact verification lineage is immutable' using errcode='55000'; + end if; + return new; + end $$; +CREATE FUNCTION public.validate_bootstrap_authority_state() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare control authority_control%rowtype; + bootstrap_count bigint; + referenced_bootstrap boolean; + begin + select * into control from authority_control where id=1; + if not found then + raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; + end if; + select count(*) into bootstrap_count from admin_role_grants + where granted_by_system_principal='workstream:system:bootstrap'; + referenced_bootstrap := exists( + select 1 from admin_role_grants + where id=control.bootstrap_grant_id + and granted_by_system_principal='workstream:system:bootstrap' + ); + if (not control.bootstrap_completed and + (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) + or (control.bootstrap_completed and + (control.bootstrap_grant_id is null or control.version <> 1 + or bootstrap_count <> 1 or not referenced_bootstrap)) then + raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; + end if; + return null; + end $$; +CREATE FUNCTION public.validate_canonical_actor_link() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare profile_row actor_profiles%rowtype; link_count integer; + begin + if tg_table_name='actor_profiles' then + select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; + if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; + if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then + raise exception 'actor and identity kind mismatch' using errcode='23514'; + end if; + else + select * into profile_row from actor_profiles where id=new.actor_profile_id; + if not found or profile_row.actor_kind <> new.subject_kind then + raise exception 'actor and identity kind mismatch' using errcode='23514'; + end if; + end if; return new; + end $$; +CREATE FUNCTION public.validate_contribution_policy_graph() RETURNS trigger + LANGUAGE plpgsql + AS $$ + begin + if exists ( + select 1 from contribution_policy_versions v + where v.status in ('published','retired') and ( + (select count(*) from contribution_rules r + where r.contribution_policy_version_id=v.id + and r.contribution_type='accepted_submission') <> 1 + or + (select count(*) from contribution_rules r + where r.contribution_policy_version_id=v.id + and r.contribution_type='completed_review') <> 1 + or exists ( + select 1 from contribution_rules r + where r.contribution_policy_version_id=v.id and ( + (r.compensation_mode='unpaid' and + (select count(*) from contribution_award_definitions d + where d.contribution_rule_id=r.id) <> 0) + or + (r.compensation_mode='compensated' and + (select count(*) from contribution_award_definitions d + where d.contribution_rule_id=r.id) not between 1 and 2) + ) + ) + ) + ) then + raise exception 'published contribution policy graph is incomplete' + using errcode='23514'; + end if; + if exists ( + select 1 from contribution_policies p + left join contribution_policy_versions v + on v.id=p.current_published_version_id + and v.contribution_policy_id=p.id + and v.project_id=p.project_id + where p.status='active' and (v.id is null or v.status <> 'published') + ) then + raise exception 'active contribution policy selector is invalid' + using errcode='23514'; + end if; + return null; + end; + $$; +CREATE FUNCTION public.validate_guide_mutation_custody() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare reservation guide_mutation_idempotency_records%rowtype; + evidence audit_events%rowtype; + actor_id text; link_id text; grant_id uuid; action_value text; + scope_type text; scope_project text; decision_id text; + product_project text; product_resource text; product_generation integer; + begin + if tg_table_name='guide_mutation_idempotency_records' then + select * into reservation from guide_mutation_idempotency_records where id=new.id; + if reservation.status<>'committed' then + raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; + end if; + if reservation.action_id in ('project.guide.create','project.guide.update') then + select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, + last_mutated_by_admin_role_grant_id,last_mutation_action_id, + last_mutation_scope_type,last_mutation_scope_project_id, + last_authorization_decision_event_id,project_id,id,mutation_generation + into actor_id,link_id,grant_id,action_value,scope_type,scope_project, + decision_id,product_project,product_resource,product_generation + from project_guides where id=reservation.resource_id; + else + select created_by_actor_profile_id,created_via_identity_link_id, + created_by_admin_role_grant_id,creation_action_id, + creation_scope_type,creation_scope_project_id, + authorization_decision_event_id,project_id,id,creation_generation + into actor_id,link_id,grant_id,action_value,scope_type,scope_project, + decision_id,product_project,product_resource,product_generation + from guide_source_snapshots where id=reservation.resource_id; + end if; + elsif tg_table_name='project_guides' then + if tg_op='UPDATE' + and (new.content_markdown is distinct from old.content_markdown + or new.change_summary is distinct from old.change_summary) + and (new.mutation_generation is not distinct from old.mutation_generation + or new.last_authorization_decision_event_id + is not distinct from old.last_authorization_decision_event_id) then + raise exception 'guide content mutation requires fresh custody' using errcode='23514'; + end if; + if new.mutation_generation is null then + if tg_op='INSERT' then + raise exception 'new guides require mutation authority' using errcode='23514'; + end if; + return null; + end if; + actor_id:=new.last_mutated_by_actor_profile_id; + link_id:=new.last_mutated_via_identity_link_id; + grant_id:=new.last_mutated_by_admin_role_grant_id; + action_value:=new.last_mutation_action_id; + scope_type:=new.last_mutation_scope_type; + scope_project:=new.last_mutation_scope_project_id; + decision_id:=new.last_authorization_decision_event_id; + product_project:=new.project_id; product_resource:=new.id; + product_generation:=new.mutation_generation; + select * into reservation from guide_mutation_idempotency_records + where resource_id=new.id and action_id=new.last_mutation_action_id + and operation_generation=new.mutation_generation and status='committed'; + elsif tg_table_name='guide_source_snapshots' then + if tg_op='UPDATE' + and (new.project_id,new.guide_id,new.guide_version, + new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) + is distinct from + (old.project_id,old.guide_id,old.guide_version, + old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then + raise exception 'guide source snapshot content is immutable' using errcode='23514'; + end if; + if new.creation_generation is null then + raise exception 'new source snapshots require creation authority' using errcode='23514'; + end if; + actor_id:=new.created_by_actor_profile_id; + link_id:=new.created_via_identity_link_id; + grant_id:=new.created_by_admin_role_grant_id; + action_value:=new.creation_action_id; + scope_type:=new.creation_scope_type; + scope_project:=new.creation_scope_project_id; + decision_id:=new.authorization_decision_event_id; + product_project:=new.project_id; product_resource:=new.id; + product_generation:=new.creation_generation; + select * into reservation from guide_mutation_idempotency_records + where resource_id=new.id and action_id='project.guide_source_snapshot.create' + and operation_generation=new.creation_generation and status='committed'; + else + if new.authorization_action_id is null then return null; end if; + actor_id:=new.authorized_by_actor_profile_id; + link_id:=new.authorized_via_identity_link_id; + grant_id:=new.authorized_by_admin_role_grant_id; + action_value:=new.authorization_action_id; + scope_type:=new.authorization_scope_type; + scope_project:=new.authorization_scope_project_id; + decision_id:=new.authorization_decision_event_id; + product_project:=new.project_id; product_resource:=new.source_snapshot_id; + select * into reservation from guide_mutation_idempotency_records + where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' + and status='committed'; + product_generation:=reservation.operation_generation; + end if; + if reservation.id is null or product_resource is null + or reservation.actor_profile_id is distinct from actor_id + or reservation.identity_link_id is distinct from link_id + or reservation.action_id is distinct from action_value + or reservation.project_id is distinct from product_project + or reservation.resource_id is distinct from product_resource + or reservation.operation_generation is distinct from product_generation + or scope_type not in ('system','project') + or (scope_type='project' and scope_project is distinct from product_project) + or (scope_type='system' and scope_project is not null) then + raise exception 'guide mutation custody mismatch' using errcode='23514'; + end if; + select * into evidence from audit_events where id=decision_id; + if evidence.id is null + or evidence.event_domain is distinct from 'authority' + or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' + or evidence.denial_code is not null + or evidence.actor_ref_kind is distinct from 'actor_profile' + or evidence.actor_id is distinct from actor_id + or evidence.matched_grant_id is distinct from grant_id::text + or evidence.permission_id is distinct from 'project.guide.manage' + or evidence.action_id is distinct from action_value + or evidence.resource_type is distinct from 'project' + or evidence.resource_id is distinct from product_project + or evidence.target_ref_kind is distinct from 'project' + or evidence.target_ref_id is distinct from product_project + or evidence.after_facts->>'allowed' is distinct from 'true' + or evidence.after_facts->>'resource_context_digest' + is distinct from reservation.resource_context_digest then + raise exception 'guide mutation evidence mismatch' using errcode='23514'; + end if; + return null; + end $$; +CREATE FUNCTION public.validate_guide_source_snapshot_items() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; + begin + select snapshot.manifest_json::jsonb->'items' into expected + from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; + if expected is null then + raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; + end if; + select coalesce(jsonb_agg(jsonb_build_object( + 'item_id',id,'item_order',item_order,'source_kind',source_kind, + 'source_label',source_label,'ingestion_adapter',ingestion_adapter, + 'media_type',media_type) order by item_order),'[]'::jsonb) + into actual from guide_source_snapshot_items + where source_snapshot_id=new.source_snapshot_id; + if actual is distinct from expected then + raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; + end if; + select r.* into reservation from guide_mutation_idempotency_records r + join guide_source_snapshots s on s.id=r.resource_id + where s.id=new.source_snapshot_id + and r.action_id='project.guide_source_snapshot.create' + and r.operation_generation=s.creation_generation and r.status='committed'; + if reservation.id is null then + raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; + end if; + return null; + end $$; +CREATE FUNCTION public.validate_linked_authority_event() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare record_row authority_idempotency_records%rowtype; + cause_row audit_events%rowtype; expected_permission text; + expected_resource text; expected_invalidation_resource text; + expected_invalidation_id text; valid_success boolean; + begin + if new.event_domain <> 'authority' then return new; end if; + valid_success := new.event_type in ( + 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', + 'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued','ProjectRoleGrantRevoked', + 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', + 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); + if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then + if new.idempotency_reference is not null then + raise exception 'invalid authority idempotency event' using errcode='23514'; + end if; return new; + end if; + if new.idempotency_reference is null then + raise exception 'authority event requires idempotency reference' using errcode='23514'; + end if; + select * into record_row from authority_idempotency_records + where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; + if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; + if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; + expected_permission := case record_row.operation + when 'service_actor.create' then 'actor.service.provision' + when 'admin_role_grant.issue' then 'admin_role.grant' + when 'admin_role_grant.revoke' then 'admin_role.revoke' + when 'project_role_grant.issue' then 'project.role_grant.manage' + when 'project_role_grant.revoke' then 'project.role_grant.manage' + when 'actor_profile.suspend' then 'actor.profile.suspend' + when 'actor_profile.reactivate' then 'actor.profile.reactivate' + when 'actor_profile.deactivate' then 'actor.profile.deactivate' + when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' + when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; + expected_resource := case + when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' + when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' + when record_row.operation like 'project_role_grant.%' then 'project_role_grant' + else 'actor_identity_link' end; + if new.permission_id <> expected_permission or new.resource_id is null then + raise exception 'authority event does not match operation' using errcode='23514'; + end if; + if new.event_type='ProjectRoleQualificationSnapshotCaptured' then + if record_row.operation <> 'project_role_grant.issue' + or new.resource_type <> 'qualification_snapshot' + or new.entity_type <> 'qualification_snapshot' + or new.entity_id <> new.resource_id + or new.target_ref_kind is distinct from 'qualification_snapshot' + or new.target_ref_id is distinct from new.resource_id + or new.invalidation_cause_event_id is not null + or new.invalidation_target_kind is not null + or new.invalidation_target_ref is not null + or exists(select 1 from audit_events where idempotency_reference=record_row.id) then + raise exception 'invalid project role qualification evidence' using errcode='23514'; + end if; + elsif record_row.operation='project_role_grant.issue' + and new.event_type='ProjectRoleGrantIssued' then + select * into cause_row from audit_events + where idempotency_reference=record_row.id + and event_type='ProjectRoleQualificationSnapshotCaptured'; + if not found + or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 + or cause_row.request_id is distinct from new.request_id + or cause_row.correlation_id is distinct from new.correlation_id + or cause_row.actor_ref_kind is distinct from new.actor_ref_kind + or cause_row.actor_id is distinct from new.actor_id + or cause_row.permission_id is distinct from new.permission_id + or cause_row.project_id is distinct from new.project_id + or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind + or cause_row.target_actor_ref is distinct from new.target_actor_ref + or cause_row.matched_grant_id is distinct from new.matched_grant_id + or new.resource_type <> 'project_role_grant' + or new.entity_type <> 'project_role_grant' + or new.entity_id <> new.resource_id + or new.target_ref_kind is distinct from 'project_role_grant' + or new.target_ref_id is distinct from new.resource_id + or new.invalidation_cause_event_id is not null + or new.invalidation_target_kind is not null + or new.invalidation_target_ref is not null then + raise exception 'invalid project role issue evidence' using errcode='23514'; + end if; + elsif record_row.operation='project_role_grant.revoke' + and new.event_type='AuthorityInvalidationRequested' then + select * into cause_row from audit_events where id=new.invalidation_cause_event_id; + if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' + or cause_row.idempotency_reference is distinct from record_row.id + or cause_row.actor_ref_kind is distinct from new.actor_ref_kind + or cause_row.actor_id is distinct from new.actor_id + or cause_row.permission_id is distinct from new.permission_id + or cause_row.request_id is distinct from new.request_id + or cause_row.correlation_id is distinct from new.correlation_id + or cause_row.project_id is distinct from new.project_id + or cause_row.target_actor_ref_kind is distinct from 'actor_profile' + or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind + or cause_row.target_actor_ref is distinct from new.target_actor_ref + or cause_row.resource_type <> 'project_role_grant' + or cause_row.target_ref_kind <> 'project_role_grant' + or cause_row.target_ref_id is distinct from cause_row.resource_id + or new.resource_type <> 'project_role_grant' + or new.resource_id is distinct from cause_row.resource_id + or new.target_ref_kind is distinct from 'project_role_grant' + or new.target_ref_id is distinct from cause_row.resource_id + or new.invalidation_target_kind <> 'project_role_grant' + or new.invalidation_target_ref is distinct from cause_row.resource_id + or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id + or new.before_facts::jsonb->>'effective' <> 'true' + or new.after_facts::jsonb->>'effective' <> 'false' + or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') + or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' + or new.before_facts::jsonb->>'scope_type' <> 'project' + or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id + or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' + or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' + or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') + or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') + or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then + raise exception 'invalid project role revoke invalidation' using errcode='23514'; + end if; + elsif record_row.operation='project_role_grant.issue' + and new.event_type='AuthorityInvalidationRequested' then + raise exception 'project role issue forbids invalidation' using errcode='23514'; + elsif new.event_type='AuthorityInvalidationRequested' then + select * into cause_row from audit_events where id=new.invalidation_cause_event_id; + expected_invalidation_resource := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then 'actor_profile' else expected_resource end; + expected_invalidation_id := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then cause_row.target_actor_ref else cause_row.resource_id end; + if not found or cause_row.idempotency_reference is distinct from record_row.id + or cause_row.actor_ref_kind is distinct from new.actor_ref_kind + or cause_row.actor_id is distinct from new.actor_id + or cause_row.permission_id is distinct from new.permission_id + or cause_row.resource_type is distinct from expected_resource + or new.resource_type is distinct from expected_invalidation_resource + or new.resource_id is distinct from expected_invalidation_id + or new.invalidation_target_kind is distinct from expected_invalidation_resource + or new.invalidation_target_ref is distinct from expected_invalidation_id + or cause_row.target_ref_kind is distinct from cause_row.resource_type + or cause_row.target_ref_id is distinct from cause_row.resource_id + or cause_row.request_id is distinct from new.request_id + or cause_row.correlation_id is distinct from new.correlation_id + or cause_row.project_id is distinct from new.project_id + or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id + or (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) + or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and + (new.before_facts::jsonb <> '{"effective": false}'::jsonb or new.after_facts::jsonb <> '{"effective": true}'::jsonb)) + or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and + (new.before_facts::jsonb <> '{"effective": true}'::jsonb or new.after_facts::jsonb <> '{"effective": false}'::jsonb)) + or not ( + (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or + (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or + (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or + (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued')) or + (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or + (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or + (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or + (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or + (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or + (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then + raise exception 'invalid linked authority cause' using errcode='23514'; + end if; + else + if new.resource_type <> expected_resource or new.entity_type <> expected_resource + or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource + or new.target_ref_id is distinct from new.resource_id + or new.invalidation_cause_event_id is not null + or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null + or not ( + (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or + (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or + (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or + (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued')) or + (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or + (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or + (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or + (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or + (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or + (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then + raise exception 'authority success event does not match operation' using errcode='23514'; + end if; + end if; return new; + end $$; +CREATE FUNCTION public.validate_policy_mutation_custody() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare reservation policy_mutation_idempotency_records%rowtype; + evidence audit_events%rowtype; + actor_id text; link_id text; grant_id uuid; action_value text; + scope_type text; scope_project text; decision_id text; + product_project text; product_guide text; product_id text; + product_generation integer; + product_hash text; predecessor_id text; predecessor_hash text; + selector_id text; selector_generation integer; selector_hash text; + predecessor_valid boolean; + begin + if tg_table_name='policy_mutation_idempotency_records' then + select * into reservation from policy_mutation_idempotency_records where id=new.id; + if reservation.status<>'committed' then + raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; + end if; + if reservation.action_id='project.review_policy.update' then + select created_by_actor_profile_id,created_via_identity_link_id, + created_by_admin_role_grant_id,creation_action_id, + creation_scope_type,creation_scope_project_id, + authorization_decision_event_id,p.project_id,g.id,p.id, + p.policy_generation,p.policy_hash,p.supersedes_policy_id, + p.predecessor_policy_hash,g.selected_review_policy_id, + g.selected_review_policy_generation,g.selected_review_policy_hash + into actor_id,link_id,grant_id,action_value,scope_type,scope_project, + decision_id,product_project,product_guide,product_id,product_generation, + product_hash,predecessor_id,predecessor_hash,selector_id, + selector_generation,selector_hash + from review_policies p join project_guides g + on g.project_id=p.project_id and g.version=p.guide_version + where p.id=reservation.policy_id and g.id=reservation.guide_id; + else + select created_by_actor_profile_id,created_via_identity_link_id, + created_by_admin_role_grant_id,creation_action_id, + creation_scope_type,creation_scope_project_id, + authorization_decision_event_id,p.project_id,g.id,p.id, + p.policy_generation,p.policy_hash,p.supersedes_policy_id, + p.predecessor_policy_hash,g.selected_revision_policy_id, + g.selected_revision_policy_generation,g.selected_revision_policy_hash + into actor_id,link_id,grant_id,action_value,scope_type,scope_project, + decision_id,product_project,product_guide,product_id,product_generation, + product_hash,predecessor_id,predecessor_hash,selector_id, + selector_generation,selector_hash + from revision_policies p join project_guides g + on g.project_id=p.project_id and g.version=p.guide_version + where p.id=reservation.policy_id and g.id=reservation.guide_id; + end if; + else + actor_id:=new.created_by_actor_profile_id; + link_id:=new.created_via_identity_link_id; + grant_id:=new.created_by_admin_role_grant_id; + action_value:=new.creation_action_id; + scope_type:=new.creation_scope_type; + scope_project:=new.creation_scope_project_id; + decision_id:=new.authorization_decision_event_id; + product_project:=new.project_id; product_id:=new.id; + product_generation:=new.policy_generation; product_hash:=new.policy_hash; + predecessor_id:=new.supersedes_policy_id; + predecessor_hash:=new.predecessor_policy_hash; + if tg_table_name='review_policies' then + select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, + g.selected_review_policy_hash + into product_guide,selector_id,selector_generation,selector_hash + from project_guides g + where g.project_id=new.project_id and g.version=new.guide_version; + else + select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, + g.selected_revision_policy_hash + into product_guide,selector_id,selector_generation,selector_hash + from project_guides g + where g.project_id=new.project_id and g.version=new.guide_version; + end if; + select r.* into reservation from policy_mutation_idempotency_records r + where r.policy_id=new.id and r.action_id=new.creation_action_id + and r.policy_generation=new.policy_generation and r.status='committed'; + end if; + if reservation.id is null or product_id is null + or reservation.actor_profile_id is distinct from actor_id + or reservation.identity_link_id is distinct from link_id + or reservation.action_id is distinct from action_value + or reservation.project_id is distinct from product_project + or reservation.guide_id is distinct from product_guide + or reservation.policy_id is distinct from product_id + or reservation.policy_generation is distinct from product_generation + or reservation.policy_hash is distinct from product_hash + or selector_id is distinct from product_id + or selector_generation is distinct from product_generation + or selector_hash is distinct from product_hash + or scope_type not in ('system','project') + or (scope_type='project' and scope_project is distinct from product_project) + or (scope_type='system' and scope_project is not null) then + raise exception 'policy mutation custody mismatch' using errcode='23514'; + end if; + if product_generation=1 then + predecessor_valid:=predecessor_id is null and predecessor_hash is null; + elsif reservation.action_id='project.review_policy.update' then + select exists(select 1 from review_policies prior + where prior.id=predecessor_id and prior.project_id=product_project + and prior.guide_version=(select version from project_guides where id=product_guide) + and prior.policy_generation=product_generation-1 + and prior.policy_hash=predecessor_hash) into predecessor_valid; + else + select exists(select 1 from revision_policies prior + where prior.id=predecessor_id and prior.project_id=product_project + and prior.guide_version=(select version from project_guides where id=product_guide) + and prior.policy_generation=product_generation-1 + and prior.policy_hash=predecessor_hash) into predecessor_valid; + end if; + if predecessor_valid is not true then + raise exception 'policy mutation lineage mismatch' using errcode='23514'; + end if; + select * into evidence from audit_events where id=decision_id; + if evidence.id is null or evidence.event_domain is distinct from 'authority' + or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' + or evidence.denial_code is not null + or evidence.actor_ref_kind is distinct from 'actor_profile' + or evidence.actor_id is distinct from actor_id + or evidence.matched_grant_id is distinct from grant_id::text + or evidence.permission_id is distinct from 'project.review_policy.manage' + or evidence.action_id is distinct from action_value + or evidence.resource_type is distinct from 'project' + or evidence.resource_id is distinct from product_project + or evidence.target_ref_kind is distinct from 'project' + or evidence.target_ref_id is distinct from product_project + or evidence.after_facts->>'allowed' is distinct from 'true' + or evidence.after_facts->>'resource_context_digest' + is distinct from reservation.resource_context_digest then + raise exception 'policy mutation evidence mismatch' using errcode='23514'; + end if; + return null; + end $$; +CREATE FUNCTION public.validate_project_create_custody() RETURNS trigger + LANGUAGE plpgsql + AS $_$ + declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; + evidence audit_events%rowtype; + begin + if tg_table_name = 'projects' then + if tg_op = 'INSERT' and new.creation_action_id is null then + raise exception 'new projects require creation authority' using errcode='23514'; + end if; + if new.creation_action_id is null then return null; end if; + project_row := new; + select * into reservation from project_create_idempotency_records + where project_id=project_row.id and status='committed'; + else + select * into reservation from project_create_idempotency_records + where id=new.id; + if reservation.status <> 'committed' then + raise exception 'pending project create reservation cannot commit' using errcode='23514'; + end if; + select * into project_row from projects where id=reservation.project_id; + end if; + if project_row.id is null or reservation.id is null + or project_row.created_by_actor_profile_id + is distinct from reservation.actor_profile_id + or project_row.created_via_identity_link_id + is distinct from reservation.identity_link_id + or project_row.creation_action_id is distinct from reservation.action_id then + raise exception 'project create custody mismatch' using errcode='23514'; + end if; + select * into evidence from audit_events + where id=project_row.authorization_decision_event_id; + if evidence.id is null + or evidence.event_domain is distinct from 'authority' + or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' + or evidence.denial_code is not null + or evidence.actor_ref_kind is distinct from 'actor_profile' + or evidence.actor_id is distinct from project_row.created_by_actor_profile_id + or evidence.matched_grant_id + is distinct from project_row.created_by_admin_role_grant_id::text + or evidence.permission_id is distinct from 'project.create' + or evidence.action_id is distinct from 'project.create' + or evidence.resource_type is distinct from 'project_create_operation' + or evidence.resource_id is distinct from reservation.operation_id::text + or evidence.target_ref_kind is distinct from 'project' + or evidence.target_ref_id is distinct from project_row.id + or evidence.after_facts->>'allowed' is distinct from 'true' + or coalesce( + evidence.after_facts->>'resource_context_digest' + !~ '^sha256:[0-9a-f]{64}$', + true + ) then + raise exception 'project create evidence mismatch' using errcode='23514'; + end if; + return null; + end $_$; +CREATE FUNCTION public.validate_review_active_lease() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare + queue_row review_queue_entries%rowtype; + active_count integer; + begin + if tg_table_name='review_queue_entries' then + queue_row := new; + else + select * into queue_row from review_queue_entries + where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); + end if; + if not found and tg_table_name='review_leases' then + raise exception 'review lease queue is missing' using errcode='23514'; + end if; + select count(*) into active_count from review_leases + where review_queue_entry_id=queue_row.id and status='active'; + if queue_row.queue_state='leased' then + if queue_row.active_lease_id is null or active_count <> 1 or not exists( + select 1 from review_leases where id=queue_row.active_lease_id + and review_queue_entry_id=queue_row.id and status='active' + ) then + raise exception 'leased queue must identify its active lease' using errcode='23514'; + end if; + elsif queue_row.active_lease_id is not null or active_count <> 0 then + raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; + end if; + return null; + end $$; +CREATE FUNCTION public.validate_submission_policy_authority_custody() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare reservation submission_policy_mutation_idempotency_records%rowtype; + evidence audit_events%rowtype; + actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; + action_value varchar; decision_id varchar; product_project varchar; + product_id varchar; approval_outputs_valid boolean; + begin + if tg_table_name='submission_policy_mutation_idempotency_records' then + if new.status='pending' then return null; end if; + reservation:=new; + select project_id,id, + case when reservation.action_id='project.submission_artifact_policy.approve' + then approved_by_actor_profile_id else created_by_actor_profile_id end, + case when reservation.action_id='project.submission_artifact_policy.approve' + then approved_via_identity_link_id else created_via_identity_link_id end, + case when reservation.action_id='project.submission_artifact_policy.approve' + then approved_by_admin_role_grant_id + else created_by_admin_role_grant_id end, + case when reservation.action_id='project.submission_artifact_policy.approve' + then null else created_by_service_identity end, + case when reservation.action_id='project.submission_artifact_policy.approve' + then approval_action_id else creation_action_id end, + case when reservation.action_id='project.submission_artifact_policy.approve' + then approval_decision_event_id else creation_decision_event_id end + into product_project,product_id,actor_id,link_id,grant_id,service_id, + action_value,decision_id + from submission_artifact_policies where id=reservation.committed_policy_id; + if reservation.action_id='project.submission_artifact_policy.approve' then + select exists( + select 1 + from submission_artifact_policies s + join effective_project_submission_artifact_policies e + on e.id=reservation.committed_effective_policy_id + and e.submission_artifact_policy_id=s.id + and e.submission_artifact_policy_hash=s.policy_hash + join pre_submit_checker_policies p + on p.id=reservation.committed_pre_submit_policy_id + and p.project_id=e.project_id + where s.id=reservation.committed_policy_id + and s.id=reservation.policy_id + and s.guide_id=reservation.guide_id + and s.source_snapshot_id=reservation.source_snapshot_id + and s.guide_version=reservation.resource_context_json->>'guide_version' + and s.policy_hash=reservation.resource_context_json->>'policy_digest' + and e.effective_policy_hash= + reservation.resource_context_json->>'effective_output_digest' + and p.compiled_bundle_hash= + reservation.resource_context_json->>'compiled_pre_submit_output_digest' + and e.project_id=reservation.project_id + and e.guide_id=s.guide_id and p.guide_id=s.guide_id + and e.guide_version=s.guide_version + and p.guide_version=s.guide_version + and e.source_snapshot_id=s.source_snapshot_id + and p.source_snapshot_id=s.source_snapshot_id + and e.source_snapshot_hash=s.source_snapshot_hash + and p.source_snapshot_hash=s.source_snapshot_hash + and e.submission_artifact_policy_id=reservation.committed_policy_id + and p.effective_policy_id=e.id + and p.effective_policy_hash=e.effective_policy_hash + and e.created_by_actor_profile_id=reservation.actor_profile_id + and p.created_by_actor_profile_id=reservation.actor_profile_id + and e.created_via_identity_link_id=reservation.identity_link_id + and p.created_via_identity_link_id=reservation.identity_link_id + and e.created_by_admin_role_grant_id=grant_id + and p.created_by_admin_role_grant_id=grant_id + and e.creation_scope_project_id=reservation.project_id + and p.creation_scope_project_id=reservation.project_id + and e.creation_action_id=reservation.action_id + and p.creation_action_id=reservation.action_id + and e.creation_decision_event_id=decision_id + and p.creation_decision_event_id=decision_id + ) into approval_outputs_valid; + if approval_outputs_valid is not true then + raise exception 'submission-policy approval output custody mismatch' + using errcode='23514'; + end if; + end if; + elsif tg_table_name='submission_artifact_policies' then + if new.creation_action_id is null and new.approval_action_id is null then + if new.created_by_actor_profile_id is not null + or new.created_via_identity_link_id is not null + or new.created_by_admin_role_grant_id is not null + or new.created_by_service_identity is not null + or new.creation_scope_type is not null + or new.creation_scope_project_id is not null + or new.creation_decision_event_id is not null + or new.approved_by_actor_profile_id is not null + or new.approved_via_identity_link_id is not null + or new.approved_by_admin_role_grant_id is not null + or new.approval_scope_type is not null + or new.approval_scope_project_id is not null + or new.approval_decision_event_id is not null then + raise exception 'partial submission-policy provenance' + using errcode='23514'; + end if; + return null; + end if; + if new.approval_action_id is not null then + select * into reservation from submission_policy_mutation_idempotency_records + where committed_policy_id=new.id and action_id=new.approval_action_id + and status='committed'; + actor_id:=new.approved_by_actor_profile_id; + link_id:=new.approved_via_identity_link_id; + grant_id:=new.approved_by_admin_role_grant_id; + service_id:=null; action_value:=new.approval_action_id; + decision_id:=new.approval_decision_event_id; + else + select * into reservation from submission_policy_mutation_idempotency_records + where committed_policy_id=new.id and action_id=new.creation_action_id + and status='committed'; + actor_id:=new.created_by_actor_profile_id; + link_id:=new.created_via_identity_link_id; + grant_id:=new.created_by_admin_role_grant_id; + service_id:=new.created_by_service_identity; + action_value:=new.creation_action_id; + decision_id:=new.creation_decision_event_id; + end if; + product_project:=new.project_id; product_id:=new.id; + elsif tg_table_name='effective_project_submission_artifact_policies' then + if new.creation_action_id is null then + if new.created_by_actor_profile_id is not null + or new.created_via_identity_link_id is not null + or new.created_by_admin_role_grant_id is not null + or new.creation_scope_type is not null + or new.creation_scope_project_id is not null + or new.creation_decision_event_id is not null then + raise exception 'partial effective-policy provenance' + using errcode='23514'; + end if; + return null; + end if; + select * into reservation from submission_policy_mutation_idempotency_records + where committed_effective_policy_id=new.id and status='committed'; + actor_id:=new.created_by_actor_profile_id; + link_id:=new.created_via_identity_link_id; + grant_id:=new.created_by_admin_role_grant_id; + service_id:=null; action_value:=new.creation_action_id; + decision_id:=new.creation_decision_event_id; + product_project:=new.project_id; product_id:=reservation.committed_policy_id; + else + if new.creation_action_id is null then + if new.created_by_actor_profile_id is not null + or new.created_via_identity_link_id is not null + or new.created_by_admin_role_grant_id is not null + or new.creation_scope_type is not null + or new.creation_scope_project_id is not null + or new.creation_decision_event_id is not null then + raise exception 'partial pre-submit-policy provenance' + using errcode='23514'; + end if; + return null; + end if; + select * into reservation from submission_policy_mutation_idempotency_records + where committed_pre_submit_policy_id=new.id and status='committed'; + actor_id:=new.created_by_actor_profile_id; + link_id:=new.created_via_identity_link_id; + grant_id:=new.created_by_admin_role_grant_id; + service_id:=null; action_value:=new.creation_action_id; + decision_id:=new.creation_decision_event_id; + product_project:=new.project_id; product_id:=reservation.committed_policy_id; + end if; + if reservation.id is null or product_id is null + or reservation.actor_profile_id is distinct from actor_id + or reservation.identity_link_id is distinct from link_id + or reservation.action_id is distinct from action_value + or reservation.project_id is distinct from product_project + or reservation.committed_policy_id is distinct from product_id + or reservation.service_identity is distinct from service_id then + raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; + end if; + select * into evidence from audit_events where id=decision_id; + if evidence.id is null or evidence.event_domain is distinct from 'authority' + or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' + or evidence.denial_code is not null + or evidence.actor_ref_kind is distinct from 'actor_profile' + or evidence.actor_id is distinct from actor_id + or evidence.matched_grant_id is distinct from grant_id::text + or evidence.permission_id is distinct from 'project.effective_policy.manage' + or evidence.action_id is distinct from action_value + or evidence.resource_type + is distinct from 'project_submission_artifact_policy_mutation' + or evidence.resource_id is distinct from product_id + or evidence.project_id is distinct from reservation.project_id + or evidence.target_ref_kind is distinct from 'project' + or evidence.target_ref_id is distinct from reservation.project_id + or evidence.after_facts->>'allowed' is distinct from 'true' + or evidence.after_facts->>'resource_context_digest' + is distinct from reservation.resource_context_digest then + raise exception 'submission-policy authorization evidence mismatch' + using errcode='23514'; + end if; + return null; + end $$; +CREATE FUNCTION public.validate_submission_policy_creation_custody() RETURNS trigger + LANGUAGE plpgsql + AS $$ + declare reservation submission_policy_mutation_idempotency_records%rowtype; + evidence audit_events%rowtype; + begin + if new.creation_action_id is null then + if new.created_by_actor_profile_id is not null + or new.created_via_identity_link_id is not null + or new.created_by_admin_role_grant_id is not null + or new.created_by_service_identity is not null + or new.creation_scope_type is not null + or new.creation_scope_project_id is not null + or new.creation_decision_event_id is not null then + raise exception 'partial submission-policy creation provenance' + using errcode='23514'; + end if; + return null; + end if; + select * into reservation from submission_policy_mutation_idempotency_records + where committed_policy_id=new.id and action_id=new.creation_action_id + and status='committed'; + if reservation.id is null + or reservation.actor_profile_id + is distinct from new.created_by_actor_profile_id + or reservation.identity_link_id + is distinct from new.created_via_identity_link_id + or reservation.service_identity + is distinct from new.created_by_service_identity + or reservation.project_id is distinct from new.project_id + or reservation.policy_id is distinct from new.id + or reservation.guide_id is distinct from new.guide_id + or reservation.source_snapshot_id is distinct from new.source_snapshot_id + or reservation.resource_context_json->>'guide_version' + is distinct from new.guide_version then + raise exception 'submission-policy creation custody mismatch' using errcode='23514'; + end if; + select * into evidence from audit_events where id=new.creation_decision_event_id; + if evidence.id is null or evidence.event_domain is distinct from 'authority' + or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' + or evidence.denial_code is not null + or evidence.actor_ref_kind is distinct from 'actor_profile' + or evidence.actor_id is distinct from new.created_by_actor_profile_id + or evidence.matched_grant_id + is distinct from new.created_by_admin_role_grant_id::text + or evidence.permission_id is distinct from 'project.effective_policy.manage' + or evidence.action_id is distinct from new.creation_action_id + or evidence.resource_type + is distinct from 'project_submission_artifact_policy_mutation' + or evidence.resource_id is distinct from new.id + or evidence.project_id is distinct from reservation.project_id + or evidence.target_ref_kind is distinct from 'project' + or evidence.target_ref_id is distinct from reservation.project_id + or evidence.after_facts->>'allowed' is distinct from 'true' + or evidence.after_facts->>'resource_context_digest' + is distinct from reservation.resource_context_digest then + raise exception 'submission-policy creation evidence mismatch' + using errcode='23514'; + end if; + return null; + end $$; +CREATE TABLE public.actor_identity_links ( + id character varying(36) NOT NULL, + actor_profile_id character varying(36) NOT NULL, + issuer character varying(200) NOT NULL, + subject character varying(200) NOT NULL, + subject_kind character varying(16) NOT NULL, + status character varying(16) NOT NULL, + linked_by character varying(120) NOT NULL, + linked_at timestamp with time zone DEFAULT now() NOT NULL, + last_verified_at timestamp with time zone, + revoked_by character varying(120), + revoked_at timestamp with time zone, + revoked_reason character varying(500), + reactivated_by character varying(120), + reactivated_at timestamp with time zone, + reactivation_reason character varying(500), + CONSTRAINT ck_actor_identity_links_human_verified CHECK ((((subject_kind)::text = 'service'::text) OR (last_verified_at IS NOT NULL))), + CONSTRAINT ck_actor_identity_links_id_uuid CHECK (((id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)), + CONSTRAINT ck_actor_identity_links_issuer CHECK (((length(btrim((issuer)::text)) >= 1) AND (length(btrim((issuer)::text)) <= 200))), + CONSTRAINT ck_actor_identity_links_lifecycle_reason_bounds CHECK ((((revoked_reason IS NULL) OR (((revoked_reason)::text = btrim((revoked_reason)::text, (((((((((((((((((((((((' + '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)))) AND ((octet_length((revoked_reason)::text) >= 1) AND (octet_length((revoked_reason)::text) <= 500)))) AND ((reactivation_reason IS NULL) OR (((reactivation_reason)::text = btrim((reactivation_reason)::text, (((((((((((((((((((((((' + '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)))) AND ((octet_length((reactivation_reason)::text) >= 1) AND (octet_length((reactivation_reason)::text) <= 500)))))), + CONSTRAINT ck_actor_identity_links_reactivation_fields CHECK ((((reactivated_by IS NULL) AND (reactivated_at IS NULL) AND (reactivation_reason IS NULL)) OR ((reactivated_by IS NOT NULL) AND (reactivated_at IS NOT NULL) AND (reactivation_reason IS NOT NULL)))), + CONSTRAINT ck_actor_identity_links_revocation_fields CHECK (((((status)::text = 'active'::text) AND (revoked_by IS NULL) AND (revoked_at IS NULL) AND (revoked_reason IS NULL)) OR (((status)::text = 'revoked'::text) AND (revoked_by IS NOT NULL) AND (revoked_at IS NOT NULL) AND (revoked_reason IS NOT NULL)))), + CONSTRAINT ck_actor_identity_links_status CHECK (((status)::text = ANY ((ARRAY['active'::character varying, 'revoked'::character varying])::text[]))), + CONSTRAINT ck_actor_identity_links_subject CHECK (((length(btrim((subject)::text)) >= 1) AND (length(btrim((subject)::text)) <= 200))), + CONSTRAINT ck_actor_identity_links_subject_kind CHECK (((subject_kind)::text = ANY ((ARRAY['human'::character varying, 'service'::character varying])::text[]))) +); +CREATE TABLE public.actor_profile_migration_state ( + id integer NOT NULL, + schema_version integer NOT NULL, + classified_count integer NOT NULL, + source_row_set_sha256 character varying(64) NOT NULL, + manifest_sha256 character varying(64), + envelope_sha256 character varying(64), + migrated_at timestamp with time zone DEFAULT now() NOT NULL, + service_identity_mapped_count integer NOT NULL, + service_identity_source_row_set_sha256 character varying(64) NOT NULL, + service_identity_manifest_sha256 character varying(64), + service_identity_envelope_sha256 character varying(64), + service_identity_database_binding character varying(76) NOT NULL, + CONSTRAINT ck_actor_profile_migration_state_evidence CHECK ((((classified_count = 0) AND (manifest_sha256 IS NULL) AND (envelope_sha256 IS NULL)) OR ((classified_count > 0) AND (manifest_sha256 IS NOT NULL) AND (envelope_sha256 IS NOT NULL)))), + CONSTRAINT ck_actor_profile_migration_state_service_identity_evidence CHECK ((((service_identity_mapped_count >= 0) AND (service_identity_mapped_count <= 7)) AND ((service_identity_source_row_set_sha256)::text ~ '^[0-9a-f]{64}$'::text) AND ((service_identity_database_binding)::text ~ '^postgres-v1:[0-9a-f]{64}$'::text) AND (((service_identity_mapped_count = 0) AND (service_identity_manifest_sha256 IS NULL) AND (service_identity_envelope_sha256 IS NULL)) OR (((service_identity_mapped_count >= 1) AND (service_identity_mapped_count <= 7)) AND ((service_identity_manifest_sha256)::text ~ '^[0-9a-f]{64}$'::text) AND ((service_identity_envelope_sha256)::text ~ '^[0-9a-f]{64}$'::text))))), + CONSTRAINT ck_actor_profile_migration_state_singleton CHECK (((id = 1) AND (schema_version = 1) AND (classified_count >= 0))) +); +CREATE SEQUENCE public.actor_profile_migration_state_id_seq + AS integer + START WITH 1 + INCREMENT BY 1 + NO MINVALUE + NO MAXVALUE + CACHE 1; +ALTER SEQUENCE public.actor_profile_migration_state_id_seq OWNED BY public.actor_profile_migration_state.id; +CREATE TABLE public.actor_profiles ( + id character varying(36) NOT NULL, + actor_kind character varying(16) NOT NULL, + status character varying(16) NOT NULL, + provisioning_method character varying(32) NOT NULL, + display_name character varying(200), + contact_email character varying(320), + created_by character varying(120) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + last_seen_at timestamp with time zone, + suspended_by character varying(120), + suspended_at timestamp with time zone, + suspension_reason character varying(500), + deactivated_by character varying(120), + deactivated_at timestamp with time zone, + deactivation_reason character varying(500), + service_identity character varying(80), + reactivated_by character varying(120), + reactivated_at timestamp with time zone, + reactivation_reason character varying(500), + CONSTRAINT ck_actor_profiles_actor_kind CHECK (((actor_kind)::text = ANY ((ARRAY['human'::character varying, 'service'::character varying])::text[]))), + CONSTRAINT ck_actor_profiles_id_uuid CHECK (((id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)), + CONSTRAINT ck_actor_profiles_kind_provisioning CHECK (((((actor_kind)::text = 'human'::text) AND ((provisioning_method)::text = 'automatic_first_access'::text)) OR (((actor_kind)::text = 'service'::text) AND ((provisioning_method)::text = 'manual_service_provisioning'::text)))), + CONSTRAINT ck_actor_profiles_kind_service_identity CHECK (((((actor_kind)::text = 'human'::text) AND (service_identity IS NULL)) OR (((actor_kind)::text = 'service'::text) AND ((service_identity)::text = ANY ((ARRAY['workstream.artifact.verifier'::character varying, 'workstream.artifact.put_resolver'::character varying, 'workstream.artifact.scheduler'::character varying, 'workstream.artifact.binding'::character varying, 'workstream.artifact.guide_reader'::character varying, 'workstream.artifact.materializer'::character varying, 'workstream.artifact.checker_output'::character varying, 'workstream.project.setup'::character varying, 'workstream.review.preference_expiry'::character varying, 'workstream.review.lease_expiry'::character varying, 'workstream.review.authority_invalidation_reconciliation'::character varying, 'workstream.review.reconciliation'::character varying, 'workstream.review.artifact_reference_reconciliation'::character varying, 'workstream.review.projection'::character varying])::text[]))))), + CONSTRAINT ck_actor_profiles_lifecycle_fields CHECK (((((status)::text = 'active'::text) AND (suspended_by IS NULL) AND (suspended_at IS NULL) AND (suspension_reason IS NULL) AND (deactivated_by IS NULL) AND (deactivated_at IS NULL) AND (deactivation_reason IS NULL)) OR (((status)::text = 'suspended'::text) AND (suspended_by IS NOT NULL) AND (suspended_at IS NOT NULL) AND (suspension_reason IS NOT NULL) AND (deactivated_by IS NULL) AND (deactivated_at IS NULL) AND (deactivation_reason IS NULL)) OR (((status)::text = 'deactivated'::text) AND (deactivated_by IS NOT NULL) AND (deactivated_at IS NOT NULL) AND (deactivation_reason IS NOT NULL)))), + CONSTRAINT ck_actor_profiles_lifecycle_reason_bounds CHECK ((((suspension_reason IS NULL) OR (((suspension_reason)::text = btrim((suspension_reason)::text, (((((((((((((((((((((((' + '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)))) AND ((octet_length((suspension_reason)::text) >= 1) AND (octet_length((suspension_reason)::text) <= 500)))) AND ((reactivation_reason IS NULL) OR (((reactivation_reason)::text = btrim((reactivation_reason)::text, (((((((((((((((((((((((' + '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)))) AND ((octet_length((reactivation_reason)::text) >= 1) AND (octet_length((reactivation_reason)::text) <= 500)))) AND ((deactivation_reason IS NULL) OR (((deactivation_reason)::text = btrim((deactivation_reason)::text, (((((((((((((((((((((((' + '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)))) AND ((octet_length((deactivation_reason)::text) >= 1) AND (octet_length((deactivation_reason)::text) <= 500)))))), + CONSTRAINT ck_actor_profiles_provisioning_method CHECK (((provisioning_method)::text = ANY ((ARRAY['automatic_first_access'::character varying, 'manual_service_provisioning'::character varying])::text[]))), + CONSTRAINT ck_actor_profiles_reactivation_fields CHECK ((((reactivated_by IS NULL) AND (reactivated_at IS NULL) AND (reactivation_reason IS NULL)) OR ((reactivated_by IS NOT NULL) AND (reactivated_at IS NOT NULL) AND (reactivation_reason IS NOT NULL)))), + CONSTRAINT ck_actor_profiles_status CHECK (((status)::text = ANY ((ARRAY['active'::character varying, 'suspended'::character varying, 'deactivated'::character varying])::text[]))) +); +CREATE TABLE public.admin_role_grants ( + id uuid NOT NULL, + target_actor_profile_id character varying(36) NOT NULL, + role character varying(40) NOT NULL, + scope_type character varying(16) NOT NULL, + scope_project_id character varying(36), + status character varying(16) DEFAULT 'active'::character varying NOT NULL, + version smallint DEFAULT '1'::smallint NOT NULL, + granted_by_actor_profile_id character varying(36), + granted_by_system_principal character varying(100), + granted_by_admin_role_grant_id uuid, + grant_reason text NOT NULL, + granted_at timestamp with time zone DEFAULT clock_timestamp() NOT NULL, + revoked_by_actor_profile_id character varying(36), + revoked_by_admin_role_grant_id uuid, + revoked_reason text, + revoked_at timestamp with time zone, + CONSTRAINT ck_admin_role_grants_grant_attribution CHECK (((((granted_by_system_principal)::text = 'workstream:system:bootstrap'::text) AND (granted_by_actor_profile_id IS NULL) AND (granted_by_admin_role_grant_id IS NULL)) OR ((granted_by_system_principal IS NULL) AND (granted_by_actor_profile_id IS NOT NULL) AND (granted_by_admin_role_grant_id IS NOT NULL)))), + CONSTRAINT ck_admin_role_grants_grant_reason CHECK (((octet_length(grant_reason) >= 1) AND (octet_length(grant_reason) <= 500))), + CONSTRAINT ck_admin_role_grants_lifecycle CHECK (((((status)::text = 'active'::text) AND (version = 1) AND (revoked_by_actor_profile_id IS NULL) AND (revoked_by_admin_role_grant_id IS NULL) AND (revoked_reason IS NULL) AND (revoked_at IS NULL)) OR (((status)::text = 'revoked'::text) AND (version = 2) AND (revoked_by_actor_profile_id IS NOT NULL) AND (revoked_by_admin_role_grant_id IS NOT NULL) AND (revoked_reason IS NOT NULL) AND ((octet_length(revoked_reason) >= 1) AND (octet_length(revoked_reason) <= 500)) AND (revoked_at IS NOT NULL)))), + CONSTRAINT ck_admin_role_grants_role CHECK (((role)::text = ANY ((ARRAY['access_administrator'::character varying, 'operator'::character varying, 'project_manager'::character varying, 'finance_authority'::character varying, 'audit_authority'::character varying])::text[]))), + CONSTRAINT ck_admin_role_grants_role_scope CHECK (((((scope_type)::text = 'system'::text) AND (scope_project_id IS NULL)) OR (((scope_type)::text = 'project'::text) AND (scope_project_id IS NOT NULL) AND ((role)::text <> ALL ((ARRAY['access_administrator'::character varying, 'operator'::character varying])::text[]))))), + CONSTRAINT ck_admin_role_grants_scope_type CHECK (((scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[]))) +); +CREATE TABLE public.api_rate_control_counters ( + control_scope character varying(32) NOT NULL, + key_digest bytea NOT NULL, + window_started_at timestamp with time zone NOT NULL, + window_expires_at timestamp with time zone NOT NULL, + request_count bigint NOT NULL, + updated_at timestamp with time zone NOT NULL, + CONSTRAINT ck_api_rate_control_counters_digest_length CHECK ((octet_length(key_digest) = 32)), + CONSTRAINT ck_api_rate_control_counters_request_count CHECK (((request_count >= 1) AND (request_count <= '9223372036854775807'::bigint))), + CONSTRAINT ck_api_rate_control_counters_scope_token CHECK (((control_scope)::text = ANY ((ARRAY['first_access'::character varying, 'admin_mutation'::character varying, 'authorization_read'::character varying])::text[]))), + CONSTRAINT ck_api_rate_control_counters_window_order CHECK ((window_started_at < window_expires_at)) +); +CREATE TABLE public.artifact_admission_charges ( + id character varying(36) NOT NULL, + scope_type character varying(20) NOT NULL, + scope_id character varying(120) NOT NULL, + sha256 character varying(71) NOT NULL, + byte_count bigint NOT NULL, + producer_type character varying(30) NOT NULL, + producer_ref character varying(120) NOT NULL, + creating_operation_identity character varying(71) NOT NULL, + state character varying(20) DEFAULT 'provisional'::character varying NOT NULL, + cas_version bigint DEFAULT '0'::bigint NOT NULL, + reserved_at timestamp with time zone DEFAULT now() NOT NULL, + completed_at timestamp with time zone, + released_at timestamp with time zone, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_artifact_admission_charges_byte_count_nonnegative CHECK ((byte_count >= 0)), + CONSTRAINT ck_artifact_admission_charges_cas_nonnegative CHECK ((cas_version >= 0)), + CONSTRAINT ck_artifact_admission_charges_completed_timestamp CHECK ((((state)::text = 'completed'::text) = (completed_at IS NOT NULL))), + CONSTRAINT ck_artifact_admission_charges_operation_identity_shape CHECK (((creating_operation_identity)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_admission_charges_producer_type CHECK (((producer_type)::text = ANY ((ARRAY['actor_profile'::character varying, 'service_identity'::character varying])::text[]))), + CONSTRAINT ck_artifact_admission_charges_released_timestamp CHECK ((((state)::text = 'released'::text) = (released_at IS NOT NULL))), + CONSTRAINT ck_artifact_admission_charges_sha256_shape CHECK (((sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_admission_charges_state CHECK (((state)::text = ANY ((ARRAY['provisional'::character varying, 'completed'::character varying, 'released'::character varying])::text[]))) +); +CREATE TABLE public.artifact_admission_scopes ( + scope_type character varying(20) NOT NULL, + scope_id character varying(120) NOT NULL, + limit_bytes bigint NOT NULL, + counted_bytes bigint DEFAULT '0'::bigint NOT NULL, + cas_version bigint DEFAULT '0'::bigint NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_artifact_admission_scopes_cas_nonnegative CHECK ((cas_version >= 0)), + CONSTRAINT ck_artifact_admission_scopes_counted_bytes_within_limit CHECK (((counted_bytes >= 0) AND (counted_bytes <= limit_bytes))), + CONSTRAINT ck_artifact_admission_scopes_limit_positive CHECK ((limit_bytes > 0)), + CONSTRAINT ck_artifact_admission_scopes_scope_id_bounds CHECK (((octet_length((scope_id)::text) >= 1) AND (octet_length((scope_id)::text) <= 120))), + CONSTRAINT ck_artifact_admission_scopes_scope_type CHECK (((scope_type)::text = ANY ((ARRAY['deployment'::character varying, 'project'::character varying, 'producer'::character varying, 'task'::character varying])::text[]))) +); +CREATE TABLE public.artifact_bindings ( + id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + resource_type character varying(80) NOT NULL, + resource_id character varying(100) NOT NULL, + logical_role character varying(100) NOT NULL, + scope_version integer NOT NULL, + actor_id character varying(100) NOT NULL, + attribution_type character varying(30) NOT NULL, + supersedes_binding_id character varying(36), + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_artifact_bindings_scope_version_positive CHECK ((scope_version > 0)), + CONSTRAINT ck_artifact_bindings_scope_version_predecessor CHECK ((((scope_version = 1) AND (supersedes_binding_id IS NULL)) OR ((scope_version > 1) AND (supersedes_binding_id IS NOT NULL)))) +); +CREATE TABLE public.artifact_contents ( + id character varying(36) NOT NULL, + sha256 character varying(71) NOT NULL, + byte_count integer NOT NULL, + media_type character varying(200), + normalized_display_name character varying(500), + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_artifact_contents_byte_count_nonnegative CHECK ((byte_count >= 0)), + CONSTRAINT ck_artifact_contents_sha256_shape CHECK (((sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)) +); +CREATE TABLE public.artifact_operation_receipts ( + id character varying(36) NOT NULL, + replica_id character varying(36) NOT NULL, + operation character varying(30) NOT NULL, + idempotency_key character varying(200) NOT NULL, + request_digest character varying(71) NOT NULL, + provider_object_ref character varying(1024) NOT NULL, + replayed boolean NOT NULL, + outcome character varying(30) NOT NULL, + attempt_number integer NOT NULL, + correlation_id character varying(100) NOT NULL, + details json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + contract_version integer DEFAULT 1 NOT NULL, + put_attempt_id character varying(36) NOT NULL, + guide_source_item_id character varying(36), + checker_run_id character varying(36), + logical_role character varying(100), + CONSTRAINT ck_artifact_operation_receipts_attempt_positive CHECK ((attempt_number > 0)), + CONSTRAINT ck_artifact_operation_receipts_contract_producer_reference CHECK (((contract_version = 2) AND (put_attempt_id IS NOT NULL) AND (((guide_source_item_id IS NOT NULL) AND (checker_run_id IS NULL) AND (logical_role IS NULL)) OR ((guide_source_item_id IS NULL) AND (checker_run_id IS NOT NULL) AND ((octet_length((logical_role)::text) >= 1) AND (octet_length((logical_role)::text) <= 100))) OR ((guide_source_item_id IS NULL) AND (checker_run_id IS NULL) AND (logical_role IS NULL))))), + CONSTRAINT ck_artifact_operation_receipts_operation CHECK (((operation)::text = 'put'::text)), + CONSTRAINT ck_artifact_operation_receipts_outcome CHECK (((outcome)::text = 'stored_pending_verification'::text)), + CONSTRAINT ck_artifact_operation_receipts_request_digest_shape CHECK (((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)) +); +CREATE TABLE public.artifact_put_attempt_charges ( + attempt_id character varying(36) NOT NULL, + charge_id character varying(36) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL +); +CREATE TABLE public.artifact_put_attempts ( + id character varying(36) NOT NULL, + producer_request_type character varying(30) NOT NULL, + producer_type character varying(30) NOT NULL, + producer_ref character varying(120) NOT NULL, + project_id character varying(36) NOT NULL, + task_id character varying(36), + guide_source_item_id character varying(36), + checker_run_id character varying(36), + logical_role character varying(100), + sha256 character varying(71) NOT NULL, + byte_count bigint NOT NULL, + media_type character varying(255) NOT NULL, + storage_namespace_id character varying(20) NOT NULL, + namespace_fingerprint character varying(71) NOT NULL, + canonical_target character varying(1024) NOT NULL, + operation_identity character varying(71) NOT NULL, + request_digest character varying(71) NOT NULL, + status character varying(40) DEFAULT 'prepared'::character varying NOT NULL, + next_run_at timestamp with time zone, + executor_id character varying(36), + lease_expires_at timestamp with time zone, + execution_generation bigint DEFAULT '0'::bigint NOT NULL, + terminal_result_code character varying(100), + replica_id character varying(36), + receipt_id character varying(36), + cas_version bigint DEFAULT '0'::bigint NOT NULL, + prepared_at timestamp with time zone DEFAULT now() NOT NULL, + terminal_at timestamp with time zone, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + execution_mode character varying(20), + observation_count bigint DEFAULT '0'::bigint NOT NULL, + maximum_observations bigint DEFAULT '5'::bigint NOT NULL, + CONSTRAINT ck_artifact_put_attempts_byte_count_nonnegative CHECK ((byte_count >= 0)), + CONSTRAINT ck_artifact_put_attempts_canonical_target_shape CHECK (((canonical_target)::text ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'::text)), + CONSTRAINT ck_artifact_put_attempts_execution_mode CHECK (((execution_mode IS NULL) OR ((execution_mode)::text = ANY ((ARRAY['caller_put'::character varying, 'observation'::character varying])::text[])))), + CONSTRAINT ck_artifact_put_attempts_executor_lease_pair CHECK (((executor_id IS NULL) = (lease_expires_at IS NULL))), + CONSTRAINT ck_artifact_put_attempts_inflight_fence CHECK ((((status)::text = 'put_in_flight'::text) = (executor_id IS NOT NULL))), + CONSTRAINT ck_artifact_put_attempts_observation_counts CHECK (((observation_count >= 0) AND (maximum_observations > 0))), + CONSTRAINT ck_artifact_put_attempts_operation_identity_shape CHECK (((operation_identity)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_put_attempts_prepared_execution_inactive CHECK ((((status)::text <> 'prepared'::text) OR ((next_run_at IS NULL) AND (executor_id IS NULL) AND (lease_expires_at IS NULL) AND (execution_generation = 0) AND (terminal_result_code IS NULL) AND (terminal_at IS NULL) AND (replica_id IS NULL) AND (receipt_id IS NULL)))), + CONSTRAINT ck_artifact_put_attempts_producer_identity CHECK (((((producer_request_type)::text = 'guide'::text) AND ((producer_type)::text = 'actor_profile'::text) AND ((producer_ref)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)) OR (((producer_request_type)::text = 'checker_output'::text) AND ((producer_type)::text = 'service_identity'::text) AND ((producer_ref)::text = 'workstream.artifact.checker_output'::text)) OR (((producer_request_type)::text = 'submission_bundle'::text) AND ((producer_type)::text = 'actor_profile'::text) AND ((producer_ref)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)))), + CONSTRAINT ck_artifact_put_attempts_producer_reference CHECK (((((producer_request_type)::text = 'guide'::text) AND (guide_source_item_id IS NOT NULL) AND (checker_run_id IS NULL) AND (task_id IS NULL) AND (logical_role IS NULL)) OR (((producer_request_type)::text = 'checker_output'::text) AND (guide_source_item_id IS NULL) AND (checker_run_id IS NOT NULL) AND (task_id IS NOT NULL) AND ((octet_length((logical_role)::text) >= 1) AND (octet_length((logical_role)::text) <= 100))) OR (((producer_request_type)::text = 'submission_bundle'::text) AND (guide_source_item_id IS NULL) AND (checker_run_id IS NULL) AND (task_id IS NOT NULL) AND (logical_role IS NULL)))), + CONSTRAINT ck_artifact_put_attempts_producer_request_type CHECK (((producer_request_type)::text = ANY ((ARRAY['guide'::character varying, 'checker_output'::character varying, 'submission_bundle'::character varying])::text[]))), + CONSTRAINT ck_artifact_put_attempts_producer_type CHECK (((producer_type)::text = ANY ((ARRAY['actor_profile'::character varying, 'service_identity'::character varying])::text[]))), + CONSTRAINT ck_artifact_put_attempts_request_digest_shape CHECK (((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_put_attempts_sha256_shape CHECK (((sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_put_attempts_status CHECK (((status)::text = ANY ((ARRAY['prepared'::character varying, 'put_in_flight'::character varying, 'acknowledgement_unknown'::character varying, 'object_confirmed'::character varying, 'absent_replay_required'::character varying, 'integrity_mismatch'::character varying, 'provider_unavailable'::character varying, 'conflict'::character varying])::text[]))), + CONSTRAINT ck_artifact_put_attempts_unavailable_exhausted CHECK ((((status)::text <> 'provider_unavailable'::text) OR ((observation_count >= maximum_observations) AND (next_run_at IS NULL) AND (terminal_at IS NOT NULL)))), + CONSTRAINT ck_artifact_put_attempts_versions_nonnegative CHECK (((execution_generation >= 0) AND (cas_version >= 0))) +); +CREATE TABLE public.artifact_put_observation_receipts ( + id character varying(36) NOT NULL, + put_attempt_id character varying(36) NOT NULL, + execution_generation bigint NOT NULL, + outcome character varying(40) NOT NULL, + expected_sha256 character varying(71) NOT NULL, + expected_byte_count bigint NOT NULL, + observed_sha256 character varying(71), + observed_byte_count bigint, + created_at timestamp with time zone DEFAULT now(), + CONSTRAINT ck_artifact_put_observation_receipts_expected_sha256 CHECK (((expected_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_put_observation_receipts_expected_size CHECK ((expected_byte_count >= 0)), + CONSTRAINT ck_artifact_put_observation_receipts_observed_facts CHECK ((((outcome)::text = ANY ((ARRAY['observed_confirmed'::character varying, 'observed_integrity_mismatch'::character varying])::text[])) = ((observed_sha256 IS NOT NULL) AND (observed_byte_count IS NOT NULL)))), + CONSTRAINT ck_artifact_put_observation_receipts_observed_sha256 CHECK (((observed_sha256 IS NULL) OR ((observed_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_artifact_put_observation_receipts_observed_size CHECK (((observed_byte_count IS NULL) OR (observed_byte_count >= 0))), + CONSTRAINT ck_artifact_put_observation_receipts_outcome CHECK (((outcome)::text = ANY ((ARRAY['observed_confirmed'::character varying, 'observed_missing'::character varying, 'observed_integrity_mismatch'::character varying, 'conflict'::character varying])::text[]))) +); +CREATE TABLE public.artifact_recovery_attempts ( + id character varying(36) NOT NULL, + requester_actor_profile_id character varying(36) NOT NULL, + requester_identity_link_id character varying(36) NOT NULL, + authorization_request_id character varying(36) NOT NULL, + authorization_correlation_id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + task_id character varying(36), + submission_id character varying(36), + source_verification_job_id character varying(36) NOT NULL, + retry_verification_job_id character varying(36) NOT NULL, + parent_recovery_attempt_id character varying(36), + recovery_class character varying(40) NOT NULL, + reason character varying(1000) NOT NULL, + client_idempotency_key character varying(200) NOT NULL, + request_digest character varying(71) NOT NULL, + status character varying(20) DEFAULT 'requested'::character varying NOT NULL, + terminal_result_code character varying(40), + initiation_audit_event_id character varying(36) NOT NULL, + terminal_audit_event_id character varying(36), + cas_version bigint DEFAULT '0'::bigint NOT NULL, + created_at timestamp with time zone DEFAULT now(), + terminal_at timestamp with time zone, + updated_at timestamp with time zone DEFAULT now(), + CONSTRAINT ck_artifact_recovery_attempts_cas_nonnegative CHECK ((cas_version >= 0)), + CONSTRAINT ck_artifact_recovery_attempts_distinct_jobs CHECK (((source_verification_job_id)::text <> (retry_verification_job_id)::text)), + CONSTRAINT ck_artifact_recovery_attempts_recovery_class CHECK (((recovery_class)::text = 'provider_observation'::text)), + CONSTRAINT ck_artifact_recovery_attempts_request_digest CHECK (((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_recovery_attempts_status CHECK (((status)::text = ANY ((ARRAY['requested'::character varying, 'succeeded'::character varying, 'failed'::character varying])::text[]))), + CONSTRAINT ck_artifact_recovery_attempts_terminal_result CHECK (((((status)::text = 'succeeded'::text) AND ((terminal_result_code)::text = 'verified'::text)) OR (((status)::text = 'failed'::text) AND ((terminal_result_code)::text = ANY ((ARRAY['provider_unavailable'::character varying, 'missing'::character varying, 'integrity_mismatch'::character varying, 'conflict'::character varying])::text[]))) OR ((status)::text = 'requested'::text))), + CONSTRAINT ck_artifact_recovery_attempts_terminal_shape CHECK (((((status)::text = 'requested'::text) AND (terminal_result_code IS NULL) AND (terminal_at IS NULL) AND (terminal_audit_event_id IS NULL)) OR (((status)::text = ANY ((ARRAY['succeeded'::character varying, 'failed'::character varying])::text[])) AND (terminal_result_code IS NOT NULL) AND (terminal_at IS NOT NULL) AND (terminal_audit_event_id IS NOT NULL)))) +); +CREATE TABLE public.artifact_replicas ( + id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + adapter character varying(50) NOT NULL, + provider_object_ref character varying(1024) NOT NULL, + verification_state character varying(30) NOT NULL, + availability_state character varying(30) NOT NULL, + integrity_state character varying(30) NOT NULL, + last_reconciled_at timestamp with time zone, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + storage_namespace_id character varying(20) NOT NULL, + namespace_fingerprint character varying(71) NOT NULL, + provider_profile character varying(100) NOT NULL, + CONSTRAINT ck_artifact_replicas_availability_state CHECK (((availability_state)::text = ANY ((ARRAY['unknown'::character varying, 'available'::character varying, 'unavailable'::character varying])::text[]))), + CONSTRAINT ck_artifact_replicas_fingerprint_shape CHECK (((namespace_fingerprint)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_replicas_integrity_state CHECK (((integrity_state)::text = ANY ((ARRAY['unknown'::character varying, 'valid'::character varying, 'invalid'::character varying])::text[]))), + CONSTRAINT ck_artifact_replicas_verification_state CHECK (((verification_state)::text = ANY ((ARRAY['pending'::character varying, 'verified'::character varying, 'missing'::character varying, 'integrity_mismatch'::character varying])::text[]))) +); +CREATE TABLE public.artifact_storage_namespaces ( + id character varying(20) NOT NULL, + backend character varying(50) NOT NULL, + adapter character varying(50) NOT NULL, + provider_profile character varying(100) NOT NULL, + namespace_descriptor json NOT NULL, + namespace_fingerprint character varying(71) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_artifact_storage_namespaces_fingerprint_shape CHECK (((namespace_fingerprint)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_artifact_storage_namespaces_singleton_id CHECK (((id)::text = 'primary'::text)) +); +CREATE TABLE public.artifact_verification_jobs ( + id character varying(36) NOT NULL, + originating_put_attempt_id character varying(36) NOT NULL, + replica_id character varying(36) NOT NULL, + status character varying(40) DEFAULT 'pending'::character varying NOT NULL, + attempt_count integer DEFAULT 0 NOT NULL, + maximum_attempts integer NOT NULL, + next_run_at timestamp with time zone, + executor_id character varying(36), + lease_expires_at timestamp with time zone, + execution_generation bigint DEFAULT '0'::bigint NOT NULL, + cas_version bigint DEFAULT '0'::bigint NOT NULL, + terminal_result_code character varying(100), + terminal_at timestamp with time zone, + created_at timestamp with time zone DEFAULT now(), + updated_at timestamp with time zone DEFAULT now(), + parent_verification_job_id character varying(36), + CONSTRAINT ck_artifact_verification_jobs_attempts CHECK (((attempt_count >= 0) AND (maximum_attempts > 0))), + CONSTRAINT ck_artifact_verification_jobs_fence_pair CHECK (((executor_id IS NULL) = (lease_expires_at IS NULL))), + CONSTRAINT ck_artifact_verification_jobs_running_fence CHECK ((((status)::text = 'running'::text) = (executor_id IS NOT NULL))), + CONSTRAINT ck_artifact_verification_jobs_status CHECK (((status)::text = ANY ((ARRAY['pending'::character varying, 'running'::character varying, 'verified'::character varying, 'missing'::character varying, 'integrity_mismatch'::character varying, 'provider_unavailable'::character varying, 'conflict'::character varying])::text[]))), + CONSTRAINT ck_artifact_verification_jobs_unavailable_retryability CHECK ((((status)::text <> 'provider_unavailable'::text) OR (((next_run_at IS NOT NULL) AND (terminal_at IS NULL) AND (attempt_count < maximum_attempts)) OR ((next_run_at IS NULL) AND (terminal_at IS NOT NULL) AND (attempt_count >= maximum_attempts))))), + CONSTRAINT ck_artifact_verification_jobs_versions CHECK (((execution_generation >= 0) AND (cas_version >= 0))) +); +CREATE TABLE public.artifact_verification_receipts ( + id character varying(36) NOT NULL, + verification_job_id character varying(36) NOT NULL, + execution_generation bigint NOT NULL, + outcome character varying(40) NOT NULL, + observed_sha256 character varying(71), + observed_byte_count bigint, + created_at timestamp with time zone DEFAULT now(), + CONSTRAINT ck_artifact_verification_receipts_observed_facts CHECK ((((outcome)::text = ANY ((ARRAY['verified'::character varying, 'integrity_mismatch'::character varying])::text[])) = ((observed_sha256 IS NOT NULL) AND (observed_byte_count IS NOT NULL)))), + CONSTRAINT ck_artifact_verification_receipts_observed_sha256 CHECK (((observed_sha256 IS NULL) OR ((observed_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_artifact_verification_receipts_observed_size CHECK (((observed_byte_count IS NULL) OR (observed_byte_count >= 0))), + CONSTRAINT ck_artifact_verification_receipts_outcome CHECK (((outcome)::text = ANY ((ARRAY['verified'::character varying, 'missing'::character varying, 'integrity_mismatch'::character varying, 'conflict'::character varying])::text[]))) +); +CREATE TABLE public.audit_events ( + id character varying(36) NOT NULL, + entity_type character varying(80) NOT NULL, + entity_id character varying(36) NOT NULL, + event_type character varying(100) NOT NULL, + from_status character varying(30), + to_status character varying(30), + actor_id character varying(100) NOT NULL, + external_subject character varying(200), + external_issuer character varying(200), + actor_roles json NOT NULL, + claim_snapshot json NOT NULL, + auth_source character varying(30) NOT NULL, + is_dev_auth boolean NOT NULL, + reason text, + event_payload json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + event_domain character varying(24) DEFAULT 'legacy_lifecycle'::character varying NOT NULL, + event_version integer, + occurred_at timestamp with time zone, + actor_ref_kind character varying(32), + request_id uuid, + correlation_id uuid, + target_actor_ref_kind character varying(32), + target_actor_ref character varying(100), + matched_grant_id character varying(100), + permission_id character varying(120), + project_id character varying(36), + resource_type character varying(80), + resource_id character varying(100), + target_ref_kind character varying(32), + target_ref_id character varying(100), + denial_code character varying(80), + idempotency_reference uuid, + invalidation_cause_event_id character varying(36), + invalidation_target_kind character varying(32), + invalidation_target_ref character varying(100), + before_facts json, + after_facts json, + action_id character varying(160), + CONSTRAINT ck_audit_events_authority_privacy_bounds CHECK ((((event_domain)::text <> 'authority'::text) OR (((id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND ((entity_type)::text = ANY (ARRAY[('actor_profile'::character varying)::text, ('actor_identity_link'::character varying)::text, ('admin_role_grant'::character varying)::text, ('qualification_snapshot'::character varying)::text, ('project_role_grant'::character varying)::text, ('authorization_decision'::character varying)::text, ('authority_invalidation'::character varying)::text])) AND ((entity_id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND ((((actor_ref_kind)::text = ANY (ARRAY[('legacy_actor'::character varying)::text, ('actor_profile'::character varying)::text])) AND ((actor_id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)) OR (((actor_ref_kind)::text = 'system_principal'::text) AND ((actor_id)::text = 'workstream:system:bootstrap'::text))) AND ((target_actor_ref IS NULL) OR (((target_actor_ref_kind)::text = 'actor_profile'::text) AND ((target_actor_ref)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text))) AND ((matched_grant_id IS NULL) OR ((matched_grant_id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)) AND ((project_id IS NULL) OR ((project_id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)) AND ((resource_type IS NULL) OR ((resource_type)::text = ANY (ARRAY[('actor_profile'::character varying)::text, ('actor_identity_link'::character varying)::text, ('admin_role_grant'::character varying)::text, ('project'::character varying)::text, ('qualification_snapshot'::character varying)::text, ('project_role_grant'::character varying)::text, ('task'::character varying)::text, ('submission'::character varying)::text, ('review'::character varying)::text, ('contribution'::character varying)::text, ('compensation_award'::character varying)::text, ('compensation_delivery'::character varying)::text, ('operations'::character varying)::text, ('audit_event'::character varying)::text, ('project_create_operation'::character varying)::text, ('project_submission_artifact_policy_mutation'::character varying)::text, ('project_guide_compilation_attempt'::character varying)::text, ('project_guide_compilation_request'::character varying)::text]))) AND ((resource_id IS NULL) OR ((resource_id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)) AND ((target_ref_kind IS NULL) OR (((target_ref_kind)::text = ANY (ARRAY[('actor_profile'::character varying)::text, ('actor_identity_link'::character varying)::text, ('admin_role_grant'::character varying)::text, ('qualification_snapshot'::character varying)::text, ('project_role_grant'::character varying)::text, ('project'::character varying)::text])) AND ((target_ref_id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)) OR (((target_ref_kind)::text = 'permission_registry'::text) AND ((target_ref_id)::text = ANY (ARRAY[('actor.profile.read_self'::character varying)::text, ('actor.profile.update_self'::character varying)::text, ('actor.profile.read_any'::character varying)::text, ('actor.profile.suspend'::character varying)::text, ('actor.profile.reactivate'::character varying)::text, ('actor.profile.deactivate'::character varying)::text, ('actor.identity_link.read'::character varying)::text, ('actor.identity_link.revoke'::character varying)::text, ('actor.identity_link.reactivate'::character varying)::text, ('actor.service.provision'::character varying)::text, ('admin_role.read'::character varying)::text, ('admin_role.grant'::character varying)::text, ('admin_role.revoke'::character varying)::text, ('project.create'::character varying)::text, ('project.read'::character varying)::text, ('project.update'::character varying)::text, ('project.archive'::character varying)::text, ('project.guide.manage'::character varying)::text, ('project.effective_policy.manage'::character varying)::text, ('project.task.manage'::character varying)::text, ('project.review_policy.manage'::character varying)::text, ('project.role_grant.read'::character varying)::text, ('project.role_grant.manage'::character varying)::text, ('project.setup_diagnostic.read'::character varying)::text, ('project.effective_policy.read'::character varying)::text, ('task.queue.read'::character varying)::text, ('task.claim'::character varying)::text, ('submission.create'::character varying)::text, ('submission.read_own'::character varying)::text, ('submission.read_for_review'::character varying)::text, ('review.queue.read'::character varying)::text, ('review.queue.inspect'::character varying)::text, ('review.claim'::character varying)::text, ('review.release'::character varying)::text, ('review.decline_preference'::character varying)::text, ('review.decision'::character varying)::text, ('review.lease.force_release'::character varying)::text, ('review.chain.read'::character varying)::text, ('contribution.read_self'::character varying)::text, ('contribution.read_project'::character varying)::text, ('compensation.policy.manage'::character varying)::text, ('compensation.adapter_binding.manage'::character varying)::text, ('compensation.award.read'::character varying)::text, ('compensation.delivery.reconcile'::character varying)::text, ('operations.status.read'::character varying)::text, ('operations.timer.run'::character varying)::text, ('operations.reconcile.run'::character varying)::text, ('operations.outbox.retry'::character varying)::text, ('operations.projection.rebuild'::character varying)::text, ('audit.read'::character varying)::text, ('audit.export'::character varying)::text, ('operations.task.start_override'::character varying)::text, ('operations.submission_gate.repair'::character varying)::text, ('operations.checker.retry'::character varying)::text, ('artifact.binding.read'::character varying)::text, ('artifact.replica.read'::character varying)::text, ('artifact.receipt.read'::character varying)::text, ('artifact.verification_job.read'::character varying)::text, ('artifact.verification_job.retry'::character varying)::text, ('artifact.recovery_attempt.read'::character varying)::text, ('artifact.audit.read'::character varying)::text, ('artifact.guide_source.ingest'::character varying)::text, ('artifact.binding.create'::character varying)::text, ('artifact.review_packet.materialize'::character varying)::text, ('artifact.verification.execute'::character varying)::text, ('artifact.pending_work.scan'::character varying)::text, ('artifact.put_attempt.resolve'::character varying)::text, ('artifact.guide_source.read'::character varying)::text, ('artifact.checker_input.materialize'::character varying)::text, ('artifact.checker_output.write'::character varying)::text, ('review.queue.override'::character varying)::text, ('project.guide_compilation.request'::character varying)::text, ('project.guide_compilation.execute'::character varying)::text])))) AND ((invalidation_target_kind IS NULL) OR (((invalidation_target_kind)::text = ANY (ARRAY[('actor_profile'::character varying)::text, ('actor_identity_link'::character varying)::text, ('admin_role_grant'::character varying)::text, ('qualification_snapshot'::character varying)::text, ('project_role_grant'::character varying)::text])) AND ((invalidation_target_ref)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)) OR (((invalidation_target_kind)::text = 'permission_registry'::text) AND ((invalidation_target_ref)::text = ANY (ARRAY[('actor.profile.read_self'::character varying)::text, ('actor.profile.update_self'::character varying)::text, ('actor.profile.read_any'::character varying)::text, ('actor.profile.suspend'::character varying)::text, ('actor.profile.reactivate'::character varying)::text, ('actor.profile.deactivate'::character varying)::text, ('actor.identity_link.read'::character varying)::text, ('actor.identity_link.revoke'::character varying)::text, ('actor.identity_link.reactivate'::character varying)::text, ('actor.service.provision'::character varying)::text, ('admin_role.read'::character varying)::text, ('admin_role.grant'::character varying)::text, ('admin_role.revoke'::character varying)::text, ('project.create'::character varying)::text, ('project.read'::character varying)::text, ('project.update'::character varying)::text, ('project.archive'::character varying)::text, ('project.guide.manage'::character varying)::text, ('project.effective_policy.manage'::character varying)::text, ('project.task.manage'::character varying)::text, ('project.review_policy.manage'::character varying)::text, ('project.role_grant.read'::character varying)::text, ('project.role_grant.manage'::character varying)::text, ('project.setup_diagnostic.read'::character varying)::text, ('project.effective_policy.read'::character varying)::text, ('task.queue.read'::character varying)::text, ('task.claim'::character varying)::text, ('submission.create'::character varying)::text, ('submission.read_own'::character varying)::text, ('submission.read_for_review'::character varying)::text, ('review.queue.read'::character varying)::text, ('review.queue.inspect'::character varying)::text, ('review.claim'::character varying)::text, ('review.release'::character varying)::text, ('review.decline_preference'::character varying)::text, ('review.decision'::character varying)::text, ('review.lease.force_release'::character varying)::text, ('review.chain.read'::character varying)::text, ('contribution.read_self'::character varying)::text, ('contribution.read_project'::character varying)::text, ('compensation.policy.manage'::character varying)::text, ('compensation.adapter_binding.manage'::character varying)::text, ('compensation.award.read'::character varying)::text, ('compensation.delivery.reconcile'::character varying)::text, ('operations.status.read'::character varying)::text, ('operations.timer.run'::character varying)::text, ('operations.reconcile.run'::character varying)::text, ('operations.outbox.retry'::character varying)::text, ('operations.projection.rebuild'::character varying)::text, ('audit.read'::character varying)::text, ('audit.export'::character varying)::text, ('operations.task.start_override'::character varying)::text, ('operations.submission_gate.repair'::character varying)::text, ('operations.checker.retry'::character varying)::text, ('artifact.binding.read'::character varying)::text, ('artifact.replica.read'::character varying)::text, ('artifact.receipt.read'::character varying)::text, ('artifact.verification_job.read'::character varying)::text, ('artifact.verification_job.retry'::character varying)::text, ('artifact.recovery_attempt.read'::character varying)::text, ('artifact.audit.read'::character varying)::text, ('artifact.guide_source.ingest'::character varying)::text, ('artifact.binding.create'::character varying)::text, ('artifact.review_packet.materialize'::character varying)::text, ('artifact.verification.execute'::character varying)::text, ('artifact.pending_work.scan'::character varying)::text, ('artifact.put_attempt.resolve'::character varying)::text, ('artifact.guide_source.read'::character varying)::text, ('artifact.checker_input.materialize'::character varying)::text, ('artifact.checker_output.write'::character varying)::text, ('review.queue.override'::character varying)::text, ('project.guide_compilation.request'::character varying)::text, ('project.guide_compilation.execute'::character varying)::text])))) AND (((entity_type)::text <> ALL (ARRAY[('authorization_decision'::character varying)::text, ('authority_invalidation'::character varying)::text])) OR ((entity_id)::text = (id)::text)) AND (((resource_type)::text <> 'project'::text) OR (resource_id IS NULL) OR ((project_id IS NOT NULL) AND ((resource_id)::text = (project_id)::text)))))), + CONSTRAINT ck_audit_events_authority_registries CHECK ((((event_domain)::text <> 'authority'::text) OR ((reason IS NOT NULL) AND ((((event_type)::text = 'ActorProfileProvisioned'::text) AND (reason = 'automatic_first_access'::text)) OR (((event_type)::text = 'ServiceActorProvisioned'::text) AND (reason = 'manual_service_provisioning'::text)) OR (((event_type)::text = 'ActorIdentityLinked'::text) AND (reason = 'identity_lifecycle_change'::text)) OR (((event_type)::text = 'ActorIdentityLinkRevoked'::text) AND (reason = 'identity_lifecycle_change'::text)) OR (((event_type)::text = 'ActorIdentityLinkReactivated'::text) AND (reason = 'identity_lifecycle_change'::text)) OR (((event_type)::text = 'ActorProfileSuspended'::text) AND (reason = ANY (ARRAY['security_response'::text, 'administrative_correction'::text]))) OR (((event_type)::text = 'ActorProfileReactivated'::text) AND (reason = 'administrative_correction'::text)) OR (((event_type)::text = 'ActorProfileDeactivated'::text) AND (reason = ANY (ARRAY['security_response'::text, 'administrative_correction'::text]))) OR (((event_type)::text = 'InitialAccessAdministratorBootstrapped'::text) AND (reason = 'initial_access_bootstrap'::text)) OR (((event_type)::text = 'AdminRoleGrantIssued'::text) AND (reason = 'authority_assignment'::text)) OR (((event_type)::text = 'AdminRoleGrantRevoked'::text) AND (reason = 'authority_revocation'::text)) OR (((event_type)::text = 'AdminRoleGrantIssueDenied'::text) AND (reason = 'authorization_policy_denial'::text)) OR (((event_type)::text = 'LastAccessAdministratorOperationDenied'::text) AND (reason = 'authorization_policy_denial'::text)) OR (((event_type)::text = 'ProjectRoleQualificationSnapshotCaptured'::text) AND (reason = 'qualification_evidence_captured'::text)) OR (((event_type)::text = 'ProjectRoleGrantIssued'::text) AND (reason = 'authority_assignment'::text)) OR (((event_type)::text = 'ProjectRoleGrantRevoked'::text) AND (reason = 'authority_revocation'::text)) OR (((event_type)::text = 'SensitiveAuthorizationAllowed'::text) AND (reason = 'authorization_evaluation'::text)) OR (((event_type)::text = 'SensitiveAuthorizationDenied'::text) AND (reason = 'authorization_evaluation'::text)) OR (((event_type)::text = 'AuthorityInvalidationRequested'::text) AND (reason = 'authority_state_changed'::text))) AND ((permission_id IS NULL) OR ((permission_id)::text = ANY (ARRAY[('actor.profile.read_self'::character varying)::text, ('actor.profile.update_self'::character varying)::text, ('actor.profile.read_any'::character varying)::text, ('actor.profile.suspend'::character varying)::text, ('actor.profile.reactivate'::character varying)::text, ('actor.profile.deactivate'::character varying)::text, ('actor.identity_link.read'::character varying)::text, ('actor.identity_link.revoke'::character varying)::text, ('actor.identity_link.reactivate'::character varying)::text, ('actor.service.provision'::character varying)::text, ('admin_role.read'::character varying)::text, ('admin_role.grant'::character varying)::text, ('admin_role.revoke'::character varying)::text, ('project.create'::character varying)::text, ('project.read'::character varying)::text, ('project.update'::character varying)::text, ('project.archive'::character varying)::text, ('project.guide.manage'::character varying)::text, ('project.effective_policy.manage'::character varying)::text, ('project.task.manage'::character varying)::text, ('project.review_policy.manage'::character varying)::text, ('project.role_grant.read'::character varying)::text, ('project.role_grant.manage'::character varying)::text, ('project.setup_diagnostic.read'::character varying)::text, ('project.effective_policy.read'::character varying)::text, ('task.queue.read'::character varying)::text, ('task.claim'::character varying)::text, ('submission.create'::character varying)::text, ('submission.read_own'::character varying)::text, ('submission.read_for_review'::character varying)::text, ('review.queue.read'::character varying)::text, ('review.queue.inspect'::character varying)::text, ('review.claim'::character varying)::text, ('review.release'::character varying)::text, ('review.decline_preference'::character varying)::text, ('review.decision'::character varying)::text, ('review.lease.force_release'::character varying)::text, ('review.chain.read'::character varying)::text, ('contribution.read_self'::character varying)::text, ('contribution.read_project'::character varying)::text, ('compensation.policy.manage'::character varying)::text, ('compensation.adapter_binding.manage'::character varying)::text, ('compensation.award.read'::character varying)::text, ('compensation.delivery.reconcile'::character varying)::text, ('operations.status.read'::character varying)::text, ('operations.timer.run'::character varying)::text, ('operations.reconcile.run'::character varying)::text, ('operations.outbox.retry'::character varying)::text, ('operations.projection.rebuild'::character varying)::text, ('audit.read'::character varying)::text, ('audit.export'::character varying)::text, ('operations.task.start_override'::character varying)::text, ('operations.submission_gate.repair'::character varying)::text, ('operations.checker.retry'::character varying)::text, ('artifact.binding.read'::character varying)::text, ('artifact.replica.read'::character varying)::text, ('artifact.receipt.read'::character varying)::text, ('artifact.verification_job.read'::character varying)::text, ('artifact.verification_job.retry'::character varying)::text, ('artifact.recovery_attempt.read'::character varying)::text, ('artifact.audit.read'::character varying)::text, ('artifact.guide_source.ingest'::character varying)::text, ('artifact.binding.create'::character varying)::text, ('artifact.review_packet.materialize'::character varying)::text, ('artifact.verification.execute'::character varying)::text, ('artifact.pending_work.scan'::character varying)::text, ('artifact.put_attempt.resolve'::character varying)::text, ('artifact.guide_source.read'::character varying)::text, ('artifact.checker_input.materialize'::character varying)::text, ('artifact.checker_output.write'::character varying)::text, ('review.queue.override'::character varying)::text, ('project.guide_compilation.execute'::character varying)::text, ('project.guide_compilation.request'::character varying)::text]))) AND ((denial_code IS NULL) OR ((denial_code)::text = ANY (ARRAY[('required_scope_missing'::character varying)::text, ('unsupported_subject_kind'::character varying)::text, ('service_actor_not_provisioned'::character varying)::text, ('identity_link_revoked'::character varying)::text, ('actor_suspended'::character varying)::text, ('actor_deactivated'::character varying)::text, ('permission_not_granted'::character varying)::text, ('scope_not_authorized'::character varying)::text, ('self_grant_forbidden'::character varying)::text, ('self_role_revoke_forbidden'::character varying)::text, ('resource_guard_denied'::character varying)::text, ('actor_not_found'::character varying)::text, ('grant_not_found'::character varying)::text, ('resource_not_found'::character varying)::text, ('actor_already_suspended'::character varying)::text, ('actor_not_suspended'::character varying)::text, ('actor_deactivated_terminal'::character varying)::text, ('last_access_administrator'::character varying)::text, ('admin_role_grant_exists'::character varying)::text, ('project_role_grant_exists'::character varying)::text, ('identity_link_conflict'::character varying)::text, ('project_role_grant_already_revoked'::character varying)::text, ('project_role_grant_replay_state_changed'::character varying)::text, ('identity_link_already_revoked'::character varying)::text, ('identity_link_not_revoked'::character varying)::text, ('resource_project_mismatch'::character varying)::text, ('idempotency_mismatch'::character varying)::text, ('invalid_role_scope'::character varying)::text, ('invalid_project_role'::character varying)::text, ('qualification_snapshot_invalid'::character varying)::text])))))), + CONSTRAINT ck_audit_events_authority_tokens CHECK ((((event_domain)::text <> 'authority'::text) OR ((event_type)::text = ANY ((ARRAY['ActorProfileProvisioned'::character varying, 'ServiceActorProvisioned'::character varying, 'ActorIdentityLinked'::character varying, 'ActorIdentityLinkRevoked'::character varying, 'ActorIdentityLinkReactivated'::character varying, 'ActorProfileSuspended'::character varying, 'ActorProfileReactivated'::character varying, 'ActorProfileDeactivated'::character varying, 'InitialAccessAdministratorBootstrapped'::character varying, 'AdminRoleGrantIssued'::character varying, 'AdminRoleGrantRevoked'::character varying, 'AdminRoleGrantIssueDenied'::character varying, 'LastAccessAdministratorOperationDenied'::character varying, 'ProjectRoleQualificationSnapshotCaptured'::character varying, 'ProjectRoleGrantIssued'::character varying, 'ProjectRoleGrantReplaced'::character varying, 'ProjectRoleGrantRevoked'::character varying, 'SensitiveAuthorizationAllowed'::character varying, 'SensitiveAuthorizationDenied'::character varying, 'AuthorityInvalidationRequested'::character varying])::text[])))), + CONSTRAINT ck_audit_events_authorization_action_evidence CHECK (((((event_domain)::text = 'legacy_lifecycle'::text) AND (action_id IS NULL)) OR (((event_domain)::text = 'authority'::text) AND ((action_id IS NULL) OR (((event_type)::text = ANY (ARRAY[('SensitiveAuthorizationAllowed'::character varying)::text, ('SensitiveAuthorizationDenied'::character varying)::text])) AND (permission_id IS NOT NULL) AND ((((action_id)::text = 'actor.profile.read_self'::text) AND ((permission_id)::text = 'actor.profile.read_self'::text)) OR (((action_id)::text = 'actor.profile.update_self'::text) AND ((permission_id)::text = 'actor.profile.update_self'::text)) OR (((action_id)::text = 'operations.task.start_override'::text) AND ((permission_id)::text = 'operations.task.start_override'::text)) OR (((action_id)::text = 'operations.submission_gate.repair'::text) AND ((permission_id)::text = 'operations.submission_gate.repair'::text)) OR (((action_id)::text = 'operations.checker.retry'::text) AND ((permission_id)::text = 'operations.checker.retry'::text)) OR (((action_id)::text = 'submission.create'::text) AND ((permission_id)::text = 'submission.create'::text)) OR (((action_id)::text = 'review.queue.read'::text) AND ((permission_id)::text = 'review.queue.read'::text)) OR (((action_id)::text = 'review.queue.inspect'::text) AND ((permission_id)::text = 'review.queue.inspect'::text)) OR (((action_id)::text = 'review.claim'::text) AND ((permission_id)::text = 'review.claim'::text)) OR (((action_id)::text = 'review.release'::text) AND ((permission_id)::text = 'review.release'::text)) OR (((action_id)::text = 'review.decline_preference'::text) AND ((permission_id)::text = 'review.decline_preference'::text)) OR (((action_id)::text = 'review.preference_expiry.run'::text) AND ((permission_id)::text = 'operations.timer.run'::text)) OR (((action_id)::text = 'review.lease_expiry.run'::text) AND ((permission_id)::text = 'operations.timer.run'::text)) OR (((action_id)::text = 'review.context.read'::text) AND ((permission_id)::text = 'submission.read_for_review'::text)) OR (((action_id)::text = 'review.chain.read'::text) AND ((permission_id)::text = 'review.chain.read'::text)) OR (((action_id)::text = 'review.finding_evidence.ingest'::text) AND ((permission_id)::text = 'review.decision'::text)) OR (((action_id)::text = 'review.decision'::text) AND ((permission_id)::text = 'review.decision'::text)) OR (((action_id)::text = 'review.finding_response_evidence.ingest'::text) AND ((permission_id)::text = 'submission.create'::text)) OR (((action_id)::text = 'review.lease.force_release'::text) AND ((permission_id)::text = 'review.lease.force_release'::text)) OR (((action_id)::text = 'review.queue.routing.override'::text) AND ((permission_id)::text = 'review.queue.override'::text)) OR (((action_id)::text = 'review.queue.routing.correct'::text) AND ((permission_id)::text = 'review.queue.override'::text)) OR (((action_id)::text = 'review.queue.close'::text) AND ((permission_id)::text = 'review.queue.override'::text)) OR (((action_id)::text = 'review.reconcile.run'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'review.artifact_reference.reconcile'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'review.projection.rebuild'::text) AND ((permission_id)::text = 'operations.projection.rebuild'::text)) OR (((action_id)::text = 'review.revision_context.repair'::text) AND ((permission_id)::text = 'project.task.manage'::text)) OR (((action_id)::text = 'review.revision_obligation.close'::text) AND ((permission_id)::text = 'project.task.manage'::text)) OR (((action_id)::text = 'review.revision_context.legacy_close'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'review.lifecycle.activation.manage'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'artifact.binding.read'::text) AND ((permission_id)::text = 'artifact.binding.read'::text)) OR (((action_id)::text = 'artifact.replica.read'::text) AND ((permission_id)::text = 'artifact.replica.read'::text)) OR (((action_id)::text = 'artifact.receipt.read'::text) AND ((permission_id)::text = 'artifact.receipt.read'::text)) OR (((action_id)::text = 'artifact.verification_job.read'::text) AND ((permission_id)::text = 'artifact.verification_job.read'::text)) OR (((action_id)::text = 'artifact.verification_job.retry'::text) AND ((permission_id)::text = 'artifact.verification_job.retry'::text)) OR (((action_id)::text = 'artifact.recovery_attempt.read'::text) AND ((permission_id)::text = 'artifact.recovery_attempt.read'::text)) OR (((action_id)::text = 'artifact.audit.read'::text) AND ((permission_id)::text = 'artifact.audit.read'::text)) OR (((action_id)::text = 'operations.artifact_storage_admission.read'::text) AND ((permission_id)::text = 'operations.status.read'::text)) OR (((action_id)::text = 'artifact.guide_source.ingest'::text) AND ((permission_id)::text = 'artifact.guide_source.ingest'::text)) OR (((action_id)::text = 'artifact.submission_bundle.prepare'::text) AND ((permission_id)::text = 'submission.create'::text)) OR (((action_id)::text = 'artifact.review_packet.materialize'::text) AND ((permission_id)::text = 'artifact.review_packet.materialize'::text)) OR (((action_id)::text = 'artifact.review_evidence.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.guide_source.read'::text) AND ((permission_id)::text = 'artifact.guide_source.read'::text)) OR (((action_id)::text = 'artifact.guide_source.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.submission.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.checker_output.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.verification.execute'::text) AND ((permission_id)::text = 'artifact.verification.execute'::text)) OR (((action_id)::text = 'artifact.pending_work.scan'::text) AND ((permission_id)::text = 'artifact.pending_work.scan'::text)) OR (((action_id)::text = 'artifact.put_attempt.resolve'::text) AND ((permission_id)::text = 'artifact.put_attempt.resolve'::text)) OR (((action_id)::text = 'artifact.pre_submit.checker_input.materialize'::text) AND ((permission_id)::text = 'artifact.checker_input.materialize'::text)) OR (((action_id)::text = 'artifact.post_submit.checker_input.materialize'::text) AND ((permission_id)::text = 'artifact.checker_input.materialize'::text)) OR (((action_id)::text = 'artifact.checker_output.write'::text) AND ((permission_id)::text = 'artifact.checker_output.write'::text)) OR (((action_id)::text = 'authorization.permission_catalogue.read'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'authorization.admin_role_definitions.read'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'admin_role_grant.list'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'actor.admin_role_grant_history.read'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'admin_role_grant.issue'::text) AND ((permission_id)::text = 'admin_role.grant'::text)) OR (((action_id)::text = 'admin_role_grant.revoke'::text) AND ((permission_id)::text = 'admin_role.revoke'::text)) OR (((action_id)::text = 'admin_role_grant.bootstrap'::text) AND ((permission_id)::text = 'admin_role.grant'::text)) OR (((action_id)::text = 'actor.profile.read'::text) AND ((permission_id)::text = 'actor.profile.read_any'::text)) OR (((action_id)::text = 'actor.profile.suspend'::text) AND ((permission_id)::text = 'actor.profile.suspend'::text)) OR (((action_id)::text = 'actor.profile.reactivate'::text) AND ((permission_id)::text = 'actor.profile.reactivate'::text)) OR (((action_id)::text = 'actor.profile.deactivate'::text) AND ((permission_id)::text = 'actor.profile.deactivate'::text)) OR (((action_id)::text = 'actor.identity_link.read'::text) AND ((permission_id)::text = 'actor.identity_link.read'::text)) OR (((action_id)::text = 'actor.identity_link.revoke'::text) AND ((permission_id)::text = 'actor.identity_link.revoke'::text)) OR (((action_id)::text = 'actor.identity_link.reactivate'::text) AND ((permission_id)::text = 'actor.identity_link.reactivate'::text)) OR (((action_id)::text = 'actor.service.provision'::text) AND ((permission_id)::text = 'actor.service.provision'::text)) OR (((action_id)::text = 'project.contributor_candidate.list'::text) AND ((permission_id)::text = 'project.role_grant.manage'::text)) OR (((action_id)::text = 'project_role_grant.list'::text) AND ((permission_id)::text = 'project.role_grant.read'::text)) OR (((action_id)::text = 'project_role_grant.read'::text) AND ((permission_id)::text = 'project.role_grant.read'::text)) OR (((action_id)::text = 'project_role_grant.issue'::text) AND ((permission_id)::text = 'project.role_grant.manage'::text)) OR (((action_id)::text = 'project_role_grant.revoke'::text) AND ((permission_id)::text = 'project.role_grant.manage'::text)) OR (((action_id)::text = 'project.read'::text) AND ((permission_id)::text = 'project.read'::text)) OR (((action_id)::text = 'actor.authorization_context.read'::text) AND ((permission_id)::text = 'actor.profile.read_self'::text)) OR (((action_id)::text = 'project.setup_run.read'::text) AND ((permission_id)::text = 'project.setup_diagnostic.read'::text)) OR (((action_id)::text = 'project.guide_sufficiency_report.list'::text) AND ((permission_id)::text = 'project.setup_diagnostic.read'::text)) OR (((action_id)::text = 'project.guide_sufficiency_report.read'::text) AND ((permission_id)::text = 'project.setup_diagnostic.read'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.list'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy_setup.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.effective_submission_artifact_policy.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.pre_submit_checker_policy.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.active_guide.read'::text) AND ((permission_id)::text = 'project.read'::text)) OR (((action_id)::text = 'project.create'::text) AND ((permission_id)::text = 'project.create'::text)) OR (((action_id)::text = 'project.guide.create'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide.update'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide_source_snapshot.create'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.review_policy.update'::text) AND ((permission_id)::text = 'project.review_policy.manage'::text)) OR (((action_id)::text = 'project.revision_policy.update'::text) AND ((permission_id)::text = 'project.review_policy.manage'::text)) OR (((action_id)::text = 'project.guide_sufficiency_report.create'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide_sufficiency.run'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide_compilation.execute'::text) AND ((permission_id)::text = 'project.guide_compilation.execute'::text)) OR (((action_id)::text = 'project.guide_compilation.request'::text) AND ((permission_id)::text = 'project.guide_compilation.request'::text)) OR (((action_id)::text = 'project.guide_sufficiency.warnings.acknowledge'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.create'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.derive'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.update'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.approve'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy.approve'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy.correction.request'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy.derive'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.setup_run.update'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide.activate'::text) AND ((permission_id)::text = 'project.guide.manage'::text))))) AND ((permission_id IS NULL) OR ((permission_id)::text <> ALL (ARRAY[('operations.task.start_override'::character varying)::text, ('operations.submission_gate.repair'::character varying)::text, ('operations.checker.retry'::character varying)::text, ('artifact.binding.read'::character varying)::text, ('artifact.replica.read'::character varying)::text, ('artifact.receipt.read'::character varying)::text, ('artifact.verification_job.read'::character varying)::text, ('artifact.verification_job.retry'::character varying)::text, ('artifact.recovery_attempt.read'::character varying)::text, ('artifact.audit.read'::character varying)::text, ('artifact.guide_source.ingest'::character varying)::text, ('artifact.binding.create'::character varying)::text, ('artifact.review_packet.materialize'::character varying)::text, ('artifact.verification.execute'::character varying)::text, ('artifact.pending_work.scan'::character varying)::text, ('artifact.put_attempt.resolve'::character varying)::text, ('artifact.guide_source.read'::character varying)::text, ('artifact.checker_input.materialize'::character varying)::text, ('artifact.checker_output.write'::character varying)::text, ('review.queue.override'::character varying)::text, ('project.setup_diagnostic.read'::character varying)::text, ('project.effective_policy.read'::character varying)::text, ('project.guide_compilation.request'::character varying)::text, ('project.guide_compilation.execute'::character varying)::text])) OR ((action_id IS NOT NULL) AND ((((action_id)::text = 'actor.profile.read_self'::text) AND ((permission_id)::text = 'actor.profile.read_self'::text)) OR (((action_id)::text = 'actor.profile.update_self'::text) AND ((permission_id)::text = 'actor.profile.update_self'::text)) OR (((action_id)::text = 'operations.task.start_override'::text) AND ((permission_id)::text = 'operations.task.start_override'::text)) OR (((action_id)::text = 'operations.submission_gate.repair'::text) AND ((permission_id)::text = 'operations.submission_gate.repair'::text)) OR (((action_id)::text = 'operations.checker.retry'::text) AND ((permission_id)::text = 'operations.checker.retry'::text)) OR (((action_id)::text = 'submission.create'::text) AND ((permission_id)::text = 'submission.create'::text)) OR (((action_id)::text = 'review.queue.read'::text) AND ((permission_id)::text = 'review.queue.read'::text)) OR (((action_id)::text = 'review.queue.inspect'::text) AND ((permission_id)::text = 'review.queue.inspect'::text)) OR (((action_id)::text = 'review.claim'::text) AND ((permission_id)::text = 'review.claim'::text)) OR (((action_id)::text = 'review.release'::text) AND ((permission_id)::text = 'review.release'::text)) OR (((action_id)::text = 'review.decline_preference'::text) AND ((permission_id)::text = 'review.decline_preference'::text)) OR (((action_id)::text = 'review.preference_expiry.run'::text) AND ((permission_id)::text = 'operations.timer.run'::text)) OR (((action_id)::text = 'review.lease_expiry.run'::text) AND ((permission_id)::text = 'operations.timer.run'::text)) OR (((action_id)::text = 'review.context.read'::text) AND ((permission_id)::text = 'submission.read_for_review'::text)) OR (((action_id)::text = 'review.chain.read'::text) AND ((permission_id)::text = 'review.chain.read'::text)) OR (((action_id)::text = 'review.finding_evidence.ingest'::text) AND ((permission_id)::text = 'review.decision'::text)) OR (((action_id)::text = 'review.decision'::text) AND ((permission_id)::text = 'review.decision'::text)) OR (((action_id)::text = 'review.finding_response_evidence.ingest'::text) AND ((permission_id)::text = 'submission.create'::text)) OR (((action_id)::text = 'review.lease.force_release'::text) AND ((permission_id)::text = 'review.lease.force_release'::text)) OR (((action_id)::text = 'review.queue.routing.override'::text) AND ((permission_id)::text = 'review.queue.override'::text)) OR (((action_id)::text = 'review.queue.routing.correct'::text) AND ((permission_id)::text = 'review.queue.override'::text)) OR (((action_id)::text = 'review.queue.close'::text) AND ((permission_id)::text = 'review.queue.override'::text)) OR (((action_id)::text = 'review.reconcile.run'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'review.artifact_reference.reconcile'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'review.projection.rebuild'::text) AND ((permission_id)::text = 'operations.projection.rebuild'::text)) OR (((action_id)::text = 'review.revision_context.repair'::text) AND ((permission_id)::text = 'project.task.manage'::text)) OR (((action_id)::text = 'review.revision_obligation.close'::text) AND ((permission_id)::text = 'project.task.manage'::text)) OR (((action_id)::text = 'review.revision_context.legacy_close'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'review.lifecycle.activation.manage'::text) AND ((permission_id)::text = 'operations.reconcile.run'::text)) OR (((action_id)::text = 'artifact.binding.read'::text) AND ((permission_id)::text = 'artifact.binding.read'::text)) OR (((action_id)::text = 'artifact.replica.read'::text) AND ((permission_id)::text = 'artifact.replica.read'::text)) OR (((action_id)::text = 'artifact.receipt.read'::text) AND ((permission_id)::text = 'artifact.receipt.read'::text)) OR (((action_id)::text = 'artifact.verification_job.read'::text) AND ((permission_id)::text = 'artifact.verification_job.read'::text)) OR (((action_id)::text = 'artifact.verification_job.retry'::text) AND ((permission_id)::text = 'artifact.verification_job.retry'::text)) OR (((action_id)::text = 'artifact.recovery_attempt.read'::text) AND ((permission_id)::text = 'artifact.recovery_attempt.read'::text)) OR (((action_id)::text = 'artifact.audit.read'::text) AND ((permission_id)::text = 'artifact.audit.read'::text)) OR (((action_id)::text = 'operations.artifact_storage_admission.read'::text) AND ((permission_id)::text = 'operations.status.read'::text)) OR (((action_id)::text = 'artifact.guide_source.ingest'::text) AND ((permission_id)::text = 'artifact.guide_source.ingest'::text)) OR (((action_id)::text = 'artifact.submission_bundle.prepare'::text) AND ((permission_id)::text = 'submission.create'::text)) OR (((action_id)::text = 'artifact.review_packet.materialize'::text) AND ((permission_id)::text = 'artifact.review_packet.materialize'::text)) OR (((action_id)::text = 'artifact.review_evidence.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.guide_source.read'::text) AND ((permission_id)::text = 'artifact.guide_source.read'::text)) OR (((action_id)::text = 'artifact.guide_source.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.submission.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.checker_output.binding.create'::text) AND ((permission_id)::text = 'artifact.binding.create'::text)) OR (((action_id)::text = 'artifact.verification.execute'::text) AND ((permission_id)::text = 'artifact.verification.execute'::text)) OR (((action_id)::text = 'artifact.pending_work.scan'::text) AND ((permission_id)::text = 'artifact.pending_work.scan'::text)) OR (((action_id)::text = 'artifact.put_attempt.resolve'::text) AND ((permission_id)::text = 'artifact.put_attempt.resolve'::text)) OR (((action_id)::text = 'artifact.pre_submit.checker_input.materialize'::text) AND ((permission_id)::text = 'artifact.checker_input.materialize'::text)) OR (((action_id)::text = 'artifact.post_submit.checker_input.materialize'::text) AND ((permission_id)::text = 'artifact.checker_input.materialize'::text)) OR (((action_id)::text = 'artifact.checker_output.write'::text) AND ((permission_id)::text = 'artifact.checker_output.write'::text)) OR (((action_id)::text = 'authorization.permission_catalogue.read'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'authorization.admin_role_definitions.read'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'admin_role_grant.list'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'actor.admin_role_grant_history.read'::text) AND ((permission_id)::text = 'admin_role.read'::text)) OR (((action_id)::text = 'admin_role_grant.issue'::text) AND ((permission_id)::text = 'admin_role.grant'::text)) OR (((action_id)::text = 'admin_role_grant.revoke'::text) AND ((permission_id)::text = 'admin_role.revoke'::text)) OR (((action_id)::text = 'admin_role_grant.bootstrap'::text) AND ((permission_id)::text = 'admin_role.grant'::text)) OR (((action_id)::text = 'actor.profile.read'::text) AND ((permission_id)::text = 'actor.profile.read_any'::text)) OR (((action_id)::text = 'actor.profile.suspend'::text) AND ((permission_id)::text = 'actor.profile.suspend'::text)) OR (((action_id)::text = 'actor.profile.reactivate'::text) AND ((permission_id)::text = 'actor.profile.reactivate'::text)) OR (((action_id)::text = 'actor.profile.deactivate'::text) AND ((permission_id)::text = 'actor.profile.deactivate'::text)) OR (((action_id)::text = 'actor.identity_link.read'::text) AND ((permission_id)::text = 'actor.identity_link.read'::text)) OR (((action_id)::text = 'actor.identity_link.revoke'::text) AND ((permission_id)::text = 'actor.identity_link.revoke'::text)) OR (((action_id)::text = 'actor.identity_link.reactivate'::text) AND ((permission_id)::text = 'actor.identity_link.reactivate'::text)) OR (((action_id)::text = 'actor.service.provision'::text) AND ((permission_id)::text = 'actor.service.provision'::text)) OR (((action_id)::text = 'project.contributor_candidate.list'::text) AND ((permission_id)::text = 'project.role_grant.manage'::text)) OR (((action_id)::text = 'project_role_grant.list'::text) AND ((permission_id)::text = 'project.role_grant.read'::text)) OR (((action_id)::text = 'project_role_grant.read'::text) AND ((permission_id)::text = 'project.role_grant.read'::text)) OR (((action_id)::text = 'project_role_grant.issue'::text) AND ((permission_id)::text = 'project.role_grant.manage'::text)) OR (((action_id)::text = 'project_role_grant.revoke'::text) AND ((permission_id)::text = 'project.role_grant.manage'::text)) OR (((action_id)::text = 'project.read'::text) AND ((permission_id)::text = 'project.read'::text)) OR (((action_id)::text = 'actor.authorization_context.read'::text) AND ((permission_id)::text = 'actor.profile.read_self'::text)) OR (((action_id)::text = 'project.setup_run.read'::text) AND ((permission_id)::text = 'project.setup_diagnostic.read'::text)) OR (((action_id)::text = 'project.guide_sufficiency_report.list'::text) AND ((permission_id)::text = 'project.setup_diagnostic.read'::text)) OR (((action_id)::text = 'project.guide_sufficiency_report.read'::text) AND ((permission_id)::text = 'project.setup_diagnostic.read'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.list'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy_setup.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.effective_submission_artifact_policy.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.pre_submit_checker_policy.read'::text) AND ((permission_id)::text = 'project.effective_policy.read'::text)) OR (((action_id)::text = 'project.active_guide.read'::text) AND ((permission_id)::text = 'project.read'::text)) OR (((action_id)::text = 'project.create'::text) AND ((permission_id)::text = 'project.create'::text)) OR (((action_id)::text = 'project.guide.create'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide.update'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide_source_snapshot.create'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.review_policy.update'::text) AND ((permission_id)::text = 'project.review_policy.manage'::text)) OR (((action_id)::text = 'project.revision_policy.update'::text) AND ((permission_id)::text = 'project.review_policy.manage'::text)) OR (((action_id)::text = 'project.guide_sufficiency_report.create'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide_sufficiency.run'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide_compilation.execute'::text) AND ((permission_id)::text = 'project.guide_compilation.execute'::text)) OR (((action_id)::text = 'project.guide_compilation.request'::text) AND ((permission_id)::text = 'project.guide_compilation.request'::text)) OR (((action_id)::text = 'project.guide_sufficiency.warnings.acknowledge'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.create'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.derive'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.update'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.submission_artifact_policy.approve'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy.approve'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy.correction.request'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.post_submit_checker_policy.derive'::text) AND ((permission_id)::text = 'project.effective_policy.manage'::text)) OR (((action_id)::text = 'project.setup_run.update'::text) AND ((permission_id)::text = 'project.guide.manage'::text)) OR (((action_id)::text = 'project.guide.activate'::text) AND ((permission_id)::text = 'project.guide.manage'::text)))))))), + CONSTRAINT ck_audit_events_domain_shape CHECK (((((event_domain)::text = 'legacy_lifecycle'::text) AND (event_version IS NULL) AND (occurred_at IS NULL) AND (actor_ref_kind IS NULL) AND (request_id IS NULL) AND (correlation_id IS NULL) AND (target_actor_ref_kind IS NULL) AND (target_actor_ref IS NULL) AND (matched_grant_id IS NULL) AND (permission_id IS NULL) AND (project_id IS NULL) AND (resource_type IS NULL) AND (resource_id IS NULL) AND (target_ref_kind IS NULL) AND (target_ref_id IS NULL) AND (denial_code IS NULL) AND (idempotency_reference IS NULL) AND (invalidation_cause_event_id IS NULL) AND (invalidation_target_kind IS NULL) AND (invalidation_target_ref IS NULL) AND (before_facts IS NULL) AND (after_facts IS NULL) AND (external_subject IS NOT NULL) AND (external_issuer IS NOT NULL)) OR (((event_domain)::text = 'authority'::text) AND (event_version = 1) AND (occurred_at IS NOT NULL) AND ((actor_ref_kind)::text = ANY ((ARRAY['legacy_actor'::character varying, 'actor_profile'::character varying, 'system_principal'::character varying])::text[])) AND (request_id IS NOT NULL) AND (correlation_id IS NOT NULL) AND (from_status IS NULL) AND (to_status IS NULL) AND (reason IS NOT NULL) AND (external_subject IS NULL) AND (external_issuer IS NULL) AND ((actor_roles)::jsonb = '[]'::jsonb) AND ((claim_snapshot)::jsonb = '{}'::jsonb) AND ((auth_source)::text = 'local_authority'::text) AND (is_dev_auth = false) AND ((event_payload)::jsonb = '{}'::jsonb)))), + CONSTRAINT ck_audit_events_fact_bounds CHECK ((((event_domain)::text <> 'authority'::text) OR (((before_facts IS NULL) OR (octet_length((before_facts)::text) <= 4096)) AND ((after_facts IS NULL) OR (octet_length((after_facts)::text) <= 4096)) AND COALESCE(public.authority_event_facts_are_safe((event_type)::text, before_facts, after_facts, (project_id)::text), false)))), + CONSTRAINT ck_audit_events_foundation_shapes CHECK ((((event_domain)::text <> 'authority'::text) OR ((event_type)::text <> ALL ((ARRAY['SensitiveAuthorizationAllowed'::character varying, 'SensitiveAuthorizationDenied'::character varying, 'AuthorityInvalidationRequested'::character varying, 'AdminRoleGrantIssueDenied'::character varying, 'LastAccessAdministratorOperationDenied'::character varying])::text[])) OR (((event_type)::text = ANY ((ARRAY['AdminRoleGrantIssueDenied'::character varying, 'LastAccessAdministratorOperationDenied'::character varying])::text[])) AND (denial_code IS NOT NULL)) OR (((event_type)::text = 'SensitiveAuthorizationAllowed'::text) AND (permission_id IS NOT NULL) AND (denial_code IS NULL) AND (invalidation_cause_event_id IS NULL) AND (invalidation_target_kind IS NULL)) OR (((event_type)::text = 'SensitiveAuthorizationDenied'::text) AND (permission_id IS NOT NULL) AND (denial_code IS NOT NULL) AND (invalidation_cause_event_id IS NULL) AND (invalidation_target_kind IS NULL) AND (idempotency_reference IS NULL)) OR (((event_type)::text = 'AuthorityInvalidationRequested'::text) AND (invalidation_cause_event_id IS NOT NULL) AND (invalidation_target_kind IS NOT NULL) AND (denial_code IS NULL)))), + CONSTRAINT ck_audit_events_reference_pairs CHECK ((((target_actor_ref_kind IS NULL) = (target_actor_ref IS NULL)) AND ((resource_type IS NOT NULL) OR (resource_id IS NULL)) AND ((target_ref_kind IS NULL) = (target_ref_id IS NULL)) AND ((invalidation_target_kind IS NULL) = (invalidation_target_ref IS NULL)) AND ((invalidation_cause_event_id IS NULL) OR ((invalidation_cause_event_id)::text <> (id)::text)))) +); +CREATE TABLE public.authority_control ( + id smallint NOT NULL, + bootstrap_completed boolean DEFAULT false NOT NULL, + bootstrap_grant_id uuid, + version smallint DEFAULT '0'::smallint NOT NULL, + created_at timestamp with time zone DEFAULT clock_timestamp() NOT NULL, + updated_at timestamp with time zone DEFAULT clock_timestamp() NOT NULL, + CONSTRAINT ck_authority_control_bootstrap_state CHECK ((((bootstrap_completed = false) AND (bootstrap_grant_id IS NULL) AND (version = 0)) OR ((bootstrap_completed = true) AND (bootstrap_grant_id IS NOT NULL) AND (version = 1)))), + CONSTRAINT ck_authority_control_singleton CHECK ((id = 1)) +); +CREATE SEQUENCE public.authority_control_id_seq + AS smallint + START WITH 1 + INCREMENT BY 1 + NO MINVALUE + NO MAXVALUE + CACHE 1; +ALTER SEQUENCE public.authority_control_id_seq OWNED BY public.authority_control.id; +CREATE TABLE public.authority_idempotency_records ( + id uuid NOT NULL, + idempotency_key uuid NOT NULL, + actor_ref_kind character varying(32) NOT NULL, + actor_ref character varying(100) NOT NULL, + operation character varying(48) NOT NULL, + request_digest character varying(71) NOT NULL, + status character varying(16) NOT NULL, + response_resource_type character varying(32), + response_resource_id uuid, + response_resource_version bigint, + response_http_status smallint, + created_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + committed_at timestamp with time zone, + CONSTRAINT ck_authority_idempotency_records_actor_kind CHECK (((actor_ref_kind)::text = ANY ((ARRAY['legacy_actor'::character varying, 'actor_profile'::character varying, 'system_principal'::character varying])::text[]))), + CONSTRAINT ck_authority_idempotency_records_actor_reference CHECK (((((actor_ref_kind)::text = 'system_principal'::text) AND ((actor_ref)::text = 'workstream:system:bootstrap'::text)) OR (((actor_ref_kind)::text <> 'system_principal'::text) AND ((actor_ref)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)))), + CONSTRAINT ck_authority_idempotency_records_operation CHECK (((operation)::text = ANY ((ARRAY['service_actor.create'::character varying, 'admin_role_grant.issue'::character varying, 'admin_role_grant.revoke'::character varying, 'project_role_grant.issue'::character varying, 'project_role_grant.revoke'::character varying, 'actor_profile.suspend'::character varying, 'actor_profile.reactivate'::character varying, 'actor_profile.deactivate'::character varying, 'actor_identity_link.revoke'::character varying, 'actor_identity_link.reactivate'::character varying])::text[]))), + CONSTRAINT ck_authority_idempotency_records_request_digest CHECK (((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_authority_idempotency_records_response_status CHECK (((response_http_status IS NULL) OR ((((operation)::text = ANY ((ARRAY['service_actor.create'::character varying, 'admin_role_grant.issue'::character varying, 'project_role_grant.issue'::character varying])::text[])) AND (response_http_status = 201)) OR (((operation)::text <> ALL ((ARRAY['service_actor.create'::character varying, 'admin_role_grant.issue'::character varying, 'project_role_grant.issue'::character varying])::text[])) AND (response_http_status = 200))))), + CONSTRAINT ck_authority_idempotency_records_response_type CHECK (((((operation)::text = 'service_actor.create'::text) AND ((response_resource_type IS NULL) OR ((response_resource_type)::text = 'actor_profile'::text))) OR (((operation)::text ~~ 'admin_role_grant.%'::text) AND ((response_resource_type IS NULL) OR ((response_resource_type)::text = 'admin_role_grant'::text))) OR (((operation)::text ~~ 'project_role_grant.%'::text) AND ((response_resource_type IS NULL) OR ((response_resource_type)::text = 'project_role_grant'::text))) OR (((operation)::text ~~ 'actor_profile.%'::text) AND ((response_resource_type IS NULL) OR ((response_resource_type)::text = 'actor_profile'::text))) OR (((operation)::text ~~ 'actor_identity_link.%'::text) AND ((response_resource_type IS NULL) OR ((response_resource_type)::text = 'actor_identity_link'::text))))), + CONSTRAINT ck_authority_idempotency_records_response_version CHECK (((response_resource_version IS NULL) OR (response_resource_version > 0))), + CONSTRAINT ck_authority_idempotency_records_state_shape CHECK (((((status)::text = 'pending'::text) AND (response_resource_type IS NULL) AND (response_resource_id IS NULL) AND (response_resource_version IS NULL) AND (response_http_status IS NULL) AND (committed_at IS NULL)) OR (((status)::text = 'committed'::text) AND (response_resource_type IS NOT NULL) AND (response_resource_id IS NOT NULL) AND (response_http_status IS NOT NULL) AND (committed_at IS NOT NULL)))), + CONSTRAINT ck_authority_idempotency_records_status CHECK (((status)::text = ANY ((ARRAY['pending'::character varying, 'committed'::character varying])::text[]))) +); +CREATE TABLE public.checker_policies ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + required_checkers json NOT NULL, + warning_checkers json NOT NULL, + blocking_severities json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + policy_hash character varying(71), + policy_body json, + guide_id character varying(36) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + effective_policy_id character varying(36) NOT NULL, + effective_policy_hash character varying(71) NOT NULL, + pre_submit_checker_policy_id character varying(36) NOT NULL, + pre_submit_checker_bundle_hash character varying(71) NOT NULL, + lifecycle_status character varying(30) NOT NULL, + approved_by_role character varying(50), + approved_by_actor character varying(100), + approved_at timestamp with time zone, + created_by character varying(100) NOT NULL, + supersedes_policy_id character varying(36), + superseded_at timestamp with time zone, + superseded_by_role character varying(50), + superseded_by_actor character varying(100), + supersession_kind character varying(50), + supersession_reason text, + CONSTRAINT ck_checker_policies_approval_provenance CHECK ((((lifecycle_status)::text <> 'approved'::text) OR (((approved_by_role)::text = ANY ((ARRAY['admin'::character varying, 'project_manager'::character varying])::text[])) AND (approved_by_actor IS NOT NULL) AND (approved_at IS NOT NULL)))), + CONSTRAINT ck_checker_policies_correction_provenance CHECK ((((lifecycle_status)::text <> 'superseded'::text) OR ((superseded_at IS NOT NULL) AND ((superseded_by_role)::text = ANY ((ARRAY['admin'::character varying, 'project_manager'::character varying])::text[])) AND (superseded_by_actor IS NOT NULL) AND ((supersession_kind)::text = ANY ((ARRAY['correction_requested'::character varying, 'upstream_policy_changed'::character varying])::text[])) AND (supersession_reason IS NOT NULL) AND (length(btrim(supersession_reason)) > 0)))), + CONSTRAINT ck_checker_policies_lifecycle_status CHECK (((lifecycle_status)::text = ANY ((ARRAY['compiled'::character varying, 'approved'::character varying, 'superseded'::character varying])::text[]))), + CONSTRAINT ck_checker_policies_policy_hash_shape CHECK (((policy_hash IS NULL) OR ((policy_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text))) +); +CREATE TABLE public.checker_results ( + id character varying(36) NOT NULL, + checker_run_id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + submission_id character varying(36) NOT NULL, + checker_name character varying(100) NOT NULL, + status character varying(30) NOT NULL, + severity character varying(30) NOT NULL, + blocks_review boolean NOT NULL, + message text NOT NULL, + worker_message text, + worker_suggested_fix text, + worker_evidence_refs json NOT NULL, + worker_visible boolean NOT NULL, + metadata json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL +); +CREATE TABLE public.checker_runs ( + id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + submission_id character varying(36) NOT NULL, + submission_version integer NOT NULL, + trigger_source character varying(50) NOT NULL, + status character varying(30) NOT NULL, + routing_recommendation character varying(50) NOT NULL, + outcome_source character varying(50) NOT NULL, + triggered_by character varying(100) NOT NULL, + triggered_by_subject character varying(200) NOT NULL, + triggered_by_issuer character varying(200) NOT NULL, + trigger_auth_source character varying(30) NOT NULL, + trigger_reason text, + audit_event_id character varying(36), + attempt_number integer NOT NULL, + supersedes_checker_run_id character varying(36), + is_current_for_submission boolean NOT NULL, + locked_guide_version character varying(50) NOT NULL, + locked_payment_policy_version character varying(50) NOT NULL, + package_hash character varying(128) NOT NULL, + artifact_hash_manifest json NOT NULL, + artifact_manifest_hash character varying(128) NOT NULL, + passed_count integer NOT NULL, + warning_count integer NOT NULL, + failed_count integer NOT NULL, + blocking_count integer NOT NULL, + queued_at timestamp with time zone DEFAULT now() NOT NULL, + started_at timestamp with time zone, + completed_at timestamp with time zone, + failure_code character varying(100), + failure_message text, + created_at timestamp with time zone DEFAULT now() NOT NULL, + locked_post_submit_checker_policy_id character varying(36), + locked_post_submit_checker_policy_version character varying(50), + locked_post_submit_checker_policy_hash character varying(71), + locked_post_submit_checker_policy_body json, + locked_review_policy_id character varying(36) NOT NULL, + locked_review_policy_generation integer NOT NULL, + locked_review_policy_hash character varying(71) NOT NULL, + locked_revision_policy_id character varying(36) NOT NULL, + locked_revision_policy_generation integer NOT NULL, + locked_revision_policy_hash character varying(71) NOT NULL, + CONSTRAINT ck_checker_runs_post_submit_policy_lock_complete CHECK (((locked_post_submit_checker_policy_id IS NOT NULL) AND (locked_post_submit_checker_policy_version IS NOT NULL) AND (locked_post_submit_checker_policy_hash IS NOT NULL) AND (locked_post_submit_checker_policy_body IS NOT NULL))) +); +CREATE TABLE public.contribution_award_definitions ( + id uuid NOT NULL, + contribution_rule_id uuid NOT NULL, + contribution_policy_version_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + contribution_type character varying(32) NOT NULL, + instrument_type character varying(32) NOT NULL, + unit_code character varying(32) NOT NULL, + quantity numeric NOT NULL, + adapter_binding_id uuid NOT NULL, + CONSTRAINT ck_contribution_award_definitions_contribution_type CHECK (((contribution_type)::text = ANY ((ARRAY['accepted_submission'::character varying, 'completed_review'::character varying])::text[]))), + CONSTRAINT ck_contribution_award_definitions_instrument_type CHECK (((instrument_type)::text = ANY ((ARRAY['money'::character varying, 'project_points'::character varying])::text[]))), + CONSTRAINT ck_contribution_award_definitions_project_points_whole CHECK ((((instrument_type)::text <> 'project_points'::text) OR (scale(quantity) = 0))), + CONSTRAINT ck_contribution_award_definitions_quantity_exact_bounds CHECK (((quantity > (0)::numeric) AND (quantity < '100000000000000000000'::numeric) AND ((scale(quantity) >= 0) AND (scale(quantity) <= 18)))) +); +CREATE TABLE public.contribution_policies ( + id uuid NOT NULL, + project_id character varying(36) NOT NULL, + name character varying(200) NOT NULL, + status character varying(16) DEFAULT 'draft'::character varying NOT NULL, + current_published_version_id uuid, + created_by character varying(36) NOT NULL, + created_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + retired_by character varying(36), + retired_at timestamp with time zone, + CONSTRAINT ck_contribution_policies_lifecycle_shape CHECK (((((status)::text = 'draft'::text) AND (current_published_version_id IS NULL) AND (retired_by IS NULL) AND (retired_at IS NULL)) OR (((status)::text = 'active'::text) AND (current_published_version_id IS NOT NULL) AND (retired_by IS NULL) AND (retired_at IS NULL)) OR (((status)::text = 'retired'::text) AND (current_published_version_id IS NOT NULL) AND (retired_by IS NOT NULL) AND (retired_at IS NOT NULL)))), + CONSTRAINT ck_contribution_policies_name CHECK (((char_length(btrim((name)::text)) >= 1) AND (char_length(btrim((name)::text)) <= 200))), + CONSTRAINT ck_contribution_policies_retirement_timestamp CHECK (((retired_at IS NULL) OR (retired_at >= created_at))), + CONSTRAINT ck_contribution_policies_status CHECK (((status)::text = ANY ((ARRAY['draft'::character varying, 'active'::character varying, 'retired'::character varying])::text[]))) +); +CREATE TABLE public.contribution_policy_versions ( + id uuid NOT NULL, + contribution_policy_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + version_number integer NOT NULL, + status character varying(16) DEFAULT 'draft'::character varying NOT NULL, + created_by character varying(36) NOT NULL, + created_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + published_by character varying(36), + published_at timestamp with time zone, + retired_by character varying(36), + retired_at timestamp with time zone, + CONSTRAINT ck_contribution_policy_versions_lifecycle_shape CHECK (((((status)::text = 'draft'::text) AND (published_by IS NULL) AND (published_at IS NULL) AND (retired_by IS NULL) AND (retired_at IS NULL)) OR (((status)::text = 'published'::text) AND (published_by IS NOT NULL) AND (published_at IS NOT NULL) AND (retired_by IS NULL) AND (retired_at IS NULL)) OR (((status)::text = 'retired'::text) AND (published_by IS NOT NULL) AND (published_at IS NOT NULL) AND (retired_by IS NOT NULL) AND (retired_at IS NOT NULL)))), + CONSTRAINT ck_contribution_policy_versions_lifecycle_timestamps CHECK ((((published_at IS NULL) OR (published_at >= created_at)) AND ((retired_at IS NULL) OR (retired_at >= published_at)))), + CONSTRAINT ck_contribution_policy_versions_status CHECK (((status)::text = ANY ((ARRAY['draft'::character varying, 'published'::character varying, 'retired'::character varying])::text[]))), + CONSTRAINT ck_contribution_policy_versions_version_number_positive CHECK ((version_number > 0)) +); +CREATE TABLE public.contribution_rules ( + id uuid NOT NULL, + contribution_policy_version_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + contribution_type character varying(32) NOT NULL, + compensation_mode character varying(16) NOT NULL, + CONSTRAINT ck_contribution_rules_compensation_mode CHECK (((compensation_mode)::text = ANY ((ARRAY['unpaid'::character varying, 'compensated'::character varying])::text[]))), + CONSTRAINT ck_contribution_rules_contribution_type CHECK (((contribution_type)::text = ANY ((ARRAY['accepted_submission'::character varying, 'completed_review'::character varying])::text[]))) +); +CREATE TABLE public.effective_project_submission_artifact_policies ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + submission_artifact_policy_id character varying(36) NOT NULL, + submission_artifact_policy_hash character varying(71) NOT NULL, + lifecycle_status character varying(30) NOT NULL, + merge_algorithm_version character varying(50) NOT NULL, + effective_policy json NOT NULL, + effective_policy_hash character varying(71) NOT NULL, + created_by character varying(100) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + supersedes_effective_policy_id character varying(36), + superseded_at timestamp with time zone, + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + creation_scope_type character varying(16), + creation_scope_project_id character varying(36), + creation_action_id character varying(160), + creation_decision_event_id character varying(36), + CONSTRAINT ck_effective_project_submission_artifact_policies_ck_ef_7be7 CHECK (((lifecycle_status)::text = ANY ((ARRAY['approved'::character varying, 'superseded'::character varying])::text[]))), + CONSTRAINT ck_effective_project_submission_artifact_policies_ck_ef_bd4e CHECK ((((created_by_actor_profile_id IS NULL) AND (created_via_identity_link_id IS NULL) AND (created_by_admin_role_grant_id IS NULL) AND (creation_scope_type IS NULL) AND (creation_scope_project_id IS NULL) AND (creation_action_id IS NULL) AND (creation_decision_event_id IS NULL)) OR ((created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (created_by_admin_role_grant_id IS NOT NULL) AND (creation_scope_type IS NOT NULL) AND (creation_action_id IS NOT NULL) AND ((creation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND (creation_scope_project_id IS NOT NULL) AND ((creation_scope_project_id)::text = (project_id)::text) AND ((creation_action_id)::text = 'project.submission_artifact_policy.approve'::text) AND (creation_decision_event_id IS NOT NULL)))) +); +CREATE TABLE public.evidence_items ( + id character varying(36) NOT NULL, + submission_id character varying(36) NOT NULL, + type character varying(50) NOT NULL, + label character varying(200) NOT NULL, + uri character varying(1000), + hash character varying(128), + size_bytes integer, + locked_at timestamp with time zone, + metadata json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL +); +CREATE TABLE public.guide_mutation_idempotency_records ( + id uuid NOT NULL, + actor_profile_id character varying(36) NOT NULL, + identity_link_id character varying(36) NOT NULL, + action_id character varying(160) NOT NULL, + idempotency_key uuid NOT NULL, + request_digest character varying(71) NOT NULL, + resource_context_digest character varying(71) NOT NULL, + operation_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + resource_id character varying(36) NOT NULL, + operation_generation integer NOT NULL, + status character varying(16) NOT NULL, + response_json json, + setup_run_id character varying(36), + created_at timestamp with time zone DEFAULT now() NOT NULL, + committed_at timestamp with time zone, + CONSTRAINT ck_guide_mutation_idempotency_records_ck_guide_mutation_6506 CHECK ((operation_generation > 0)), + CONSTRAINT ck_guide_mutation_idempotency_records_ck_guide_mutation_9402 CHECK (((((status)::text = 'pending'::text) AND (response_json IS NULL) AND (committed_at IS NULL) AND (setup_run_id IS NULL)) OR (((status)::text = 'committed'::text) AND (response_json IS NOT NULL) AND (committed_at IS NOT NULL)))), + CONSTRAINT ck_guide_mutation_idempotency_records_ck_guide_mutation_action CHECK (((action_id)::text = ANY ((ARRAY['project.guide.create'::character varying, 'project.guide.update'::character varying, 'project.guide_source_snapshot.create'::character varying])::text[]))), + CONSTRAINT ck_guide_mutation_idempotency_records_ck_guide_mutation_b397 CHECK (((resource_context_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_guide_mutation_idempotency_records_ck_guide_mutation_e32d CHECK (((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_guide_mutation_idempotency_records_ck_guide_mutation_status CHECK (((status)::text = ANY ((ARRAY['pending'::character varying, 'committed'::character varying])::text[]))) +); +CREATE TABLE public.guide_source_artifact_bindings ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_item_id character varying(36) NOT NULL, + project_setup_run_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + content_id character varying(36) NOT NULL, + verified_replica_id character varying(36) NOT NULL, + logical_role character varying(100) NOT NULL, + supersedes_binding_id character varying(36), + created_by_service character varying(100) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_artifact_bindings_ck_guide_bindings_gen_b5fe CHECK ((setup_generation > 0)), + CONSTRAINT ck_guide_source_artifact_bindings_ck_guide_bindings_role CHECK (((logical_role)::text = 'guide_source_original'::text)) +); +CREATE TABLE public.guide_source_artifact_incidents ( + id character varying(36) NOT NULL, + binding_id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + verified_replica_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + code character varying(40) NOT NULL, + observed_sha256 character varying(71), + observed_byte_count bigint, + bounded_facts json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_artifact_incidents_ck_guide_incidents_code CHECK (((code)::text = ANY ((ARRAY['missing'::character varying, 'changed'::character varying, 'truncated'::character varying, 'unavailable'::character varying, 'stale'::character varying, 'conflict'::character varying])::text[]))), + CONSTRAINT ck_guide_source_artifact_incidents_ck_guide_source_arti_621b CHECK (((observed_sha256 IS NULL) OR ((observed_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_guide_source_artifact_incidents_ck_guide_source_arti_92fa CHECK (((observed_byte_count IS NULL) OR (observed_byte_count >= 0))) +); +CREATE TABLE public.guide_source_artifact_ingests ( + id character varying(36) NOT NULL, + source_item_id character varying(36) NOT NULL, + actor_profile_id character varying(36) NOT NULL, + sha256 character varying(71) NOT NULL, + byte_count bigint NOT NULL, + media_type character varying(255) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_artifact_ingests_ck_guide_source_artifa_2958 CHECK ((byte_count >= 0)), + CONSTRAINT ck_guide_source_artifact_ingests_ck_guide_source_artifa_64cb CHECK (((sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)) +); +CREATE TABLE public.guide_source_extracted_contents ( + id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + detected_format character varying(40) NOT NULL, + extractor_name character varying(100) NOT NULL, + extractor_version character varying(40) NOT NULL, + policy_version character varying(80) NOT NULL, + source_sha256 character varying(71) NOT NULL, + source_byte_count bigint NOT NULL, + status character varying(40) NOT NULL, + output_sha256 character varying(71) NOT NULL, + canonical_output text NOT NULL, + omission_facts json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_extracted_contents_ck_guide_extracted_c_1b91 CHECK (((output_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_guide_source_extracted_contents_ck_guide_extracted_c_54b5 CHECK ((octet_length(canonical_output) <= 4194304)), + CONSTRAINT ck_guide_source_extracted_contents_ck_guide_extracted_c_988f CHECK (((source_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_guide_source_extracted_contents_ck_guide_extracted_c_a759 CHECK (((status)::text = 'extracted'::text)), + CONSTRAINT ck_guide_source_extracted_contents_ck_guide_extracted_c_fb79 CHECK ((source_byte_count >= 0)) +); +CREATE TABLE public.guide_source_extraction_attempts ( + id character varying(36) NOT NULL, + binding_id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + classification_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + detected_format character varying(40) NOT NULL, + extractor_name character varying(100) NOT NULL, + extractor_version character varying(40) NOT NULL, + policy_version character varying(80) NOT NULL, + attempt_number bigint NOT NULL, + status character varying(40) NOT NULL, + error_code character varying(80), + bounded_facts json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_extraction_attempts_ck_guide_extraction_3927 CHECK ((attempt_number > 0)), + CONSTRAINT ck_guide_source_extraction_attempts_ck_guide_extraction_940d CHECK ((((status)::text = 'extracted'::text) = (error_code IS NULL))), + CONSTRAINT ck_guide_source_extraction_attempts_ck_guide_extraction_ff6d CHECK (((status)::text = ANY ((ARRAY['extracted'::character varying, 'unsupported'::character varying, 'ambiguous'::character varying, 'malformed'::character varying, 'limit_exceeded'::character varying, 'parser_failure'::character varying, 'cancelled'::character varying, 'artifact_incident'::character varying])::text[]))) +); +CREATE TABLE public.guide_source_extraction_retry_budgets ( + binding_id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + classification_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + policy_version character varying(80) NOT NULL, + claimed_slots integer NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_extraction_retry_budgets_ck_guide_extra_99c3 CHECK (((claimed_slots >= 1) AND (claimed_slots <= 2))) +); +CREATE TABLE public.guide_source_extraction_usages ( + id character varying(36) NOT NULL, + extracted_content_id character varying(36) NOT NULL, + extraction_attempt_id character varying(36) NOT NULL, + attempt_status character varying(40) NOT NULL, + binding_id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + source_item_id character varying(36) NOT NULL, + project_setup_run_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_extraction_usages_ck_guide_extraction_u_a2fd CHECK (((attempt_status)::text = 'extracted'::text)) +); +CREATE TABLE public.guide_source_format_classifications ( + id character varying(36) NOT NULL, + binding_id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + verified_replica_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + sha256 character varying(71) NOT NULL, + byte_count bigint NOT NULL, + media_type character varying(255) NOT NULL, + detected_format character varying(40) NOT NULL, + status character varying(40) NOT NULL, + detector_name character varying(100) NOT NULL, + detector_version character varying(40) NOT NULL, + classification_facts json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_guide_source_format_classifications_ck_guide_classif_8737 CHECK (((status)::text = ANY ((ARRAY['classified'::character varying, 'unsupported'::character varying, 'ambiguous'::character varying, 'malformed'::character varying, 'limit_exceeded'::character varying])::text[]))), + CONSTRAINT ck_guide_source_format_classifications_ck_guide_source__0dd2 CHECK (((sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_guide_source_format_classifications_ck_guide_source__7235 CHECK ((byte_count >= 0)) +); +CREATE TABLE public.guide_source_snapshot_items ( + id character varying(36) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + item_order integer NOT NULL, + source_kind character varying(50) NOT NULL, + source_label text NOT NULL, + ingestion_adapter character varying(100) NOT NULL, + media_type character varying(100), + created_at timestamp with time zone DEFAULT now() NOT NULL +); +CREATE TABLE public.guide_source_snapshots ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + manifest_schema_version character varying(50) NOT NULL, + manifest_json json NOT NULL, + bundle_hash character varying(71) NOT NULL, + captured_by character varying(100) NOT NULL, + captured_at timestamp with time zone DEFAULT now() NOT NULL, + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + creation_scope_type character varying(16), + creation_scope_project_id character varying(36), + creation_action_id character varying(160), + authorization_decision_event_id character varying(36), + creation_generation integer, + CONSTRAINT ck_guide_source_snapshots_source_snapshot_creation_auth_2f3e CHECK ((((creation_generation IS NULL) AND (created_by_actor_profile_id IS NULL) AND (created_via_identity_link_id IS NULL) AND (created_by_admin_role_grant_id IS NULL) AND (creation_scope_type IS NULL) AND (creation_scope_project_id IS NULL) AND (creation_action_id IS NULL) AND (authorization_decision_event_id IS NULL)) OR ((creation_generation > 0) AND (created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (created_by_admin_role_grant_id IS NOT NULL) AND ((creation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND ((((creation_scope_type)::text = 'system'::text) AND (creation_scope_project_id IS NULL)) OR (((creation_scope_type)::text = 'project'::text) AND ((creation_scope_project_id)::text = (project_id)::text))) AND ((creation_action_id)::text = 'project.guide_source_snapshot.create'::text) AND (authorization_decision_event_id IS NOT NULL)))) +); +CREATE TABLE public.guide_sufficiency_mutation_idempotency_records ( + id uuid NOT NULL, + actor_profile_id character varying(36) NOT NULL, + identity_link_id character varying(36) NOT NULL, + action_id character varying(160) NOT NULL, + idempotency_key uuid NOT NULL, + request_digest character varying(71) NOT NULL, + resource_context_digest character varying(71) NOT NULL, + operation_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + report_id character varying(36), + setup_run_id character varying(36), + setup_generation bigint NOT NULL, + status character varying(16) NOT NULL, + response_json json, + created_at timestamp with time zone DEFAULT now() NOT NULL, + committed_at timestamp with time zone, + CONSTRAINT ck_guide_sufficiency_mutation_idempotency_records_ck_su_1033 CHECK ((setup_generation > 0)), + CONSTRAINT ck_guide_sufficiency_mutation_idempotency_records_ck_su_177a CHECK ((((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((resource_context_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_guide_sufficiency_mutation_idempotency_records_ck_su_6651 CHECK (((action_id)::text = ANY ((ARRAY['project.guide_sufficiency_report.create'::character varying, 'project.guide_sufficiency.run'::character varying, 'project.guide_sufficiency.warnings.acknowledge'::character varying])::text[]))), + CONSTRAINT ck_guide_sufficiency_mutation_idempotency_records_ck_su_87dd CHECK (((status)::text = ANY ((ARRAY['pending'::character varying, 'committed'::character varying])::text[]))), + CONSTRAINT ck_guide_sufficiency_mutation_idempotency_records_ck_su_e7f6 CHECK (((((status)::text = 'pending'::text) AND (response_json IS NULL) AND (committed_at IS NULL)) OR (((status)::text = 'committed'::text) AND (response_json IS NOT NULL) AND (committed_at IS NOT NULL) AND ((((action_id)::text = 'project.guide_sufficiency.run'::text) AND ((setup_run_id IS NOT NULL) OR (report_id IS NOT NULL))) OR (((action_id)::text <> 'project.guide_sufficiency.run'::text) AND (report_id IS NOT NULL)))))) +); +CREATE TABLE public.guide_sufficiency_report_source_usages ( + id character varying(36) NOT NULL, + report_id character varying(36) NOT NULL, + item_order integer NOT NULL, + source_item_id character varying(36) NOT NULL, + binding_id character varying(36) NOT NULL, + content_id character varying(36) NOT NULL, + extraction_usage_id character varying(36) NOT NULL, + extraction_attempt_id character varying(36) NOT NULL, + extracted_content_id character varying(36) NOT NULL, + project_setup_run_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + canonical_output_sha256 character varying(71) NOT NULL, + CONSTRAINT ck_guide_sufficiency_report_source_usages_ck_sufficienc_2983 CHECK ((setup_generation > 0)), + CONSTRAINT ck_guide_sufficiency_report_source_usages_ck_sufficienc_8148 CHECK (((canonical_output_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_guide_sufficiency_report_source_usages_ck_sufficienc_eb12 CHECK ((item_order >= 0)) +); +CREATE TABLE public.guide_sufficiency_reports ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + status character varying(30) NOT NULL, + findings json NOT NULL, + summary text, + agent_name character varying(100), + agent_version character varying(50), + created_by character varying(100) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + warnings_acknowledged_by_role character varying(50), + warnings_acknowledged_by_actor character varying(100), + warnings_acknowledged_at timestamp with time zone, + acknowledgement_note text, + project_setup_run_id character varying(36), + setup_generation bigint, + agent_material_sha256 character varying(71), + agent_material_byte_count bigint, + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + created_by_service_identity character varying(160), + creation_scope_type character varying(16), + creation_scope_project_id character varying(36), + creation_action_id character varying(160), + authorization_decision_event_id character varying(36), + warnings_acknowledged_by_actor_profile_id character varying(36), + warnings_acknowledged_via_identity_link_id character varying(36), + warnings_acknowledged_by_admin_role_grant_id uuid, + warning_acknowledgement_scope_type character varying(16), + warning_acknowledgement_scope_project_id character varying(36), + warning_acknowledgement_action_id character varying(160), + warning_acknowledgement_decision_event_id character varying(36), + CONSTRAINT ck_guide_sufficiency_ack_authority_shape CHECK ((((warnings_acknowledged_by_actor_profile_id IS NULL) AND (warnings_acknowledged_via_identity_link_id IS NULL) AND (warnings_acknowledged_by_admin_role_grant_id IS NULL) AND (warning_acknowledgement_scope_type IS NULL) AND (warning_acknowledgement_scope_project_id IS NULL) AND (warning_acknowledgement_action_id IS NULL) AND (warning_acknowledgement_decision_event_id IS NULL)) OR ((warnings_acknowledged_by_actor_profile_id IS NOT NULL) AND (warnings_acknowledged_via_identity_link_id IS NOT NULL) AND (warnings_acknowledged_by_admin_role_grant_id IS NOT NULL) AND ((warning_acknowledgement_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND (warning_acknowledgement_scope_project_id IS NOT NULL) AND ((warning_acknowledgement_action_id)::text = 'project.guide_sufficiency.warnings.acknowledge'::text) AND (warning_acknowledgement_decision_event_id IS NOT NULL)))), + CONSTRAINT ck_guide_sufficiency_creation_authority_shape CHECK ((((created_by_actor_profile_id IS NULL) AND (created_via_identity_link_id IS NULL) AND (created_by_admin_role_grant_id IS NULL) AND (created_by_service_identity IS NULL) AND (creation_scope_type IS NULL) AND (creation_scope_project_id IS NULL) AND (creation_action_id IS NULL) AND (authorization_decision_event_id IS NULL)) OR ((created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (creation_scope_project_id IS NOT NULL) AND ((creation_action_id)::text = ANY ((ARRAY['project.guide_sufficiency_report.create'::character varying, 'project.guide_sufficiency.run'::character varying])::text[])) AND (authorization_decision_event_id IS NOT NULL) AND (((created_by_admin_role_grant_id IS NOT NULL) AND (created_by_service_identity IS NULL) AND ((creation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[]))) OR ((created_by_admin_role_grant_id IS NULL) AND ((created_by_service_identity)::text = 'workstream.project.setup'::text) AND ((creation_scope_type)::text = 'service'::text) AND ((creation_action_id)::text = 'project.guide_sufficiency.run'::text) AND (project_setup_run_id IS NOT NULL) AND (setup_generation IS NOT NULL) AND (agent_material_sha256 IS NOT NULL) AND (agent_material_byte_count IS NOT NULL)))))), + CONSTRAINT ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_31bb CHECK (((agent_material_byte_count IS NULL) OR (agent_material_byte_count >= 0))), + CONSTRAINT ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_3e43 CHECK (((setup_generation IS NULL) OR (setup_generation > 0))), + CONSTRAINT ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_4640 CHECK ((((project_setup_run_id IS NULL) AND (setup_generation IS NULL) AND (agent_material_sha256 IS NULL) AND (agent_material_byte_count IS NULL)) OR ((project_setup_run_id IS NOT NULL) AND (setup_generation IS NOT NULL) AND (agent_material_sha256 IS NOT NULL) AND (agent_material_byte_count IS NOT NULL)))), + CONSTRAINT ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_841c CHECK (((status)::text = ANY ((ARRAY['passed'::character varying, 'blocked'::character varying, 'passed_with_warnings'::character varying])::text[]))), + CONSTRAINT ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_b3ec CHECK (((agent_material_sha256 IS NULL) OR ((agent_material_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text))) +); +CREATE TABLE public.iso_4217_currency_codes ( + code character varying(3) NOT NULL, + CONSTRAINT ck_iso_4217_currency_codes_code CHECK (((code)::text ~ '^[A-Z]{3}$'::text)) +); +CREATE TABLE public.legacy_actor_identities ( + actor_id character varying(100) NOT NULL, + external_subject character varying(200) NOT NULL, + external_issuer character varying(200) NOT NULL, + display_name character varying(200), + email character varying(320), + last_seen_roles json NOT NULL, + last_claim_snapshot json NOT NULL, + auth_source character varying(50) NOT NULL, + is_dev_auth boolean NOT NULL, + first_seen_at timestamp with time zone DEFAULT now() NOT NULL, + last_seen_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL +); +CREATE TABLE public.legacy_workflow_eligibility ( + id character varying(36) NOT NULL, + actor_id character varying(100) NOT NULL, + profile_type character varying(50) NOT NULL, + status character varying(30) NOT NULL, + skill_tags json NOT NULL, + scope_type character varying(50) NOT NULL, + scope_id character varying(100) NOT NULL, + profile_metadata json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_legacy_workflow_eligibility_profile_type CHECK (((profile_type)::text = ANY ((ARRAY['worker'::character varying, 'reviewer'::character varying, 'admin'::character varying, 'project_manager'::character varying, 'project_owner'::character varying])::text[]))), + CONSTRAINT ck_legacy_workflow_eligibility_status CHECK (((status)::text = ANY ((ARRAY['observed'::character varying, 'active'::character varying, 'disabled'::character varying])::text[]))) +); +CREATE TABLE public.outbox_events ( + event_id uuid NOT NULL, + event_type character varying(128) NOT NULL, + event_version smallint NOT NULL, + producer character varying(32) DEFAULT 'workstream'::character varying NOT NULL, + aggregate_type character varying(64) NOT NULL, + aggregate_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + correlation_id character varying(200) NOT NULL, + causation_event_id uuid, + idempotency_key character varying(200) NOT NULL, + payload jsonb NOT NULL, + payload_digest character varying(71) NOT NULL, + occurred_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + delivery_state character varying(16) DEFAULT 'pending'::character varying NOT NULL, + attempt_count integer DEFAULT 0 NOT NULL, + next_attempt_at timestamp with time zone DEFAULT statement_timestamp(), + claim_owner character varying(120), + claim_generation bigint DEFAULT '0'::bigint NOT NULL, + claimed_at timestamp with time zone, + claim_expires_at timestamp with time zone, + last_attempt_at timestamp with time zone, + last_error_code character varying(80), + finalized_at timestamp with time zone, + archived_at timestamp with time zone, + CONSTRAINT ck_outbox_events_aggregate_type CHECK (((aggregate_type)::text ~ '^[a-z][a-z0-9_]{0,63}$'::text)), + CONSTRAINT ck_outbox_events_claim_owner CHECK (((claim_owner IS NULL) OR ((claim_owner)::text ~ '^[A-Za-z0-9._:-]{1,120}$'::text))), + CONSTRAINT ck_outbox_events_correlation_id CHECK (((correlation_id)::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)), + CONSTRAINT ck_outbox_events_delivery_counters CHECK (((attempt_count >= 0) AND (claim_generation >= 0) AND (attempt_count = claim_generation))), + CONSTRAINT ck_outbox_events_delivery_state CHECK (((delivery_state)::text = ANY ((ARRAY['pending'::character varying, 'claimed'::character varying, 'retryable'::character varying, 'acknowledged'::character varying, 'dead_letter'::character varying, 'cancelled'::character varying])::text[]))), + CONSTRAINT ck_outbox_events_delivery_state_shape CHECK (((((delivery_state)::text = 'pending'::text) AND (attempt_count = 0) AND (next_attempt_at IS NOT NULL) AND (claim_owner IS NULL) AND (claimed_at IS NULL) AND (claim_expires_at IS NULL) AND (last_attempt_at IS NULL) AND (last_error_code IS NULL) AND (finalized_at IS NULL) AND (archived_at IS NULL)) OR (((delivery_state)::text = 'claimed'::text) AND (attempt_count > 0) AND (next_attempt_at IS NULL) AND (claim_owner IS NOT NULL) AND (claimed_at IS NOT NULL) AND (claim_expires_at IS NOT NULL) AND (last_attempt_at = claimed_at) AND (finalized_at IS NULL) AND (archived_at IS NULL)) OR (((delivery_state)::text = 'retryable'::text) AND (attempt_count > 0) AND (next_attempt_at IS NOT NULL) AND (claim_owner IS NULL) AND (claimed_at IS NULL) AND (claim_expires_at IS NULL) AND (last_attempt_at IS NOT NULL) AND (last_error_code IS NOT NULL) AND (finalized_at IS NULL) AND (archived_at IS NULL)) OR (((delivery_state)::text = 'acknowledged'::text) AND (attempt_count > 0) AND (next_attempt_at IS NULL) AND (claim_owner IS NULL) AND (claimed_at IS NULL) AND (claim_expires_at IS NULL) AND (last_attempt_at IS NOT NULL) AND (finalized_at IS NOT NULL)) OR (((delivery_state)::text = 'dead_letter'::text) AND (attempt_count > 0) AND (next_attempt_at IS NULL) AND (claim_owner IS NULL) AND (claimed_at IS NULL) AND (claim_expires_at IS NULL) AND (last_attempt_at IS NOT NULL) AND (last_error_code IS NOT NULL) AND (finalized_at IS NOT NULL)) OR (((delivery_state)::text = 'cancelled'::text) AND (next_attempt_at IS NULL) AND (claim_owner IS NULL) AND (claimed_at IS NULL) AND (claim_expires_at IS NULL) AND (finalized_at IS NOT NULL) AND (((attempt_count = 0) AND (last_attempt_at IS NULL) AND (last_error_code IS NULL)) OR ((attempt_count > 0) AND (last_attempt_at IS NOT NULL)))))), + CONSTRAINT ck_outbox_events_delivery_timestamps CHECK ((((next_attempt_at IS NULL) OR (next_attempt_at >= occurred_at)) AND ((claimed_at IS NULL) OR (claimed_at >= occurred_at)) AND ((last_attempt_at IS NULL) OR (last_attempt_at >= occurred_at)) AND ((claim_expires_at IS NULL) OR (claim_expires_at > claimed_at)) AND ((finalized_at IS NULL) OR (finalized_at >= occurred_at)) AND ((finalized_at IS NULL) OR (last_attempt_at IS NULL) OR (finalized_at >= last_attempt_at)) AND ((archived_at IS NULL) OR (archived_at >= finalized_at)))), + CONSTRAINT ck_outbox_events_error_code CHECK (((last_error_code IS NULL) OR ((last_error_code)::text ~ '^[A-Z][A-Z0-9_]{0,79}$'::text))), + CONSTRAINT ck_outbox_events_event_type CHECK (((event_type)::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'::text)), + CONSTRAINT ck_outbox_events_event_version CHECK (((event_version >= 1) AND (event_version <= 32767))), + CONSTRAINT ck_outbox_events_idempotency_key CHECK (((idempotency_key)::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)), + CONSTRAINT ck_outbox_events_payload_digest CHECK (((payload_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_outbox_events_payload_shape CHECK (((jsonb_typeof(payload) = 'object'::text) AND (octet_length((payload)::text) <= 262144))), + CONSTRAINT ck_outbox_events_producer CHECK (((producer)::text = 'workstream'::text)), + CONSTRAINT ck_outbox_events_project_id CHECK (((project_id)::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)) +); +CREATE TABLE public.payment_policies ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + base_amount numeric(12,2), + currency character varying(20), + payout_type character varying(50), + revision_payment_rule text, + rejection_payment_rule text, + accepted_payment_rule text, + created_at timestamp with time zone DEFAULT now() NOT NULL +); +CREATE TABLE public.policy_mutation_idempotency_records ( + id uuid NOT NULL, + actor_profile_id character varying(36) NOT NULL, + identity_link_id character varying(36) NOT NULL, + action_id character varying(160) NOT NULL, + idempotency_key uuid NOT NULL, + request_digest character varying(71) NOT NULL, + policy_hash character varying(71) NOT NULL, + resource_context_digest character varying(71) NOT NULL, + operation_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + policy_id character varying(36) NOT NULL, + policy_generation integer NOT NULL, + status character varying(16) NOT NULL, + response_json json, + created_at timestamp with time zone DEFAULT now() NOT NULL, + committed_at timestamp with time zone, + CONSTRAINT ck_policy_mutation_idempotency_records_ck_policy_mutati_26aa CHECK (((((status)::text = 'pending'::text) AND (response_json IS NULL) AND (committed_at IS NULL)) OR (((status)::text = 'committed'::text) AND (response_json IS NOT NULL) AND (committed_at IS NOT NULL)))), + CONSTRAINT ck_policy_mutation_idempotency_records_ck_policy_mutati_595e CHECK ((((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((policy_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((resource_context_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_policy_mutation_idempotency_records_ck_policy_mutati_7f7f CHECK (((action_id)::text = ANY ((ARRAY['project.review_policy.update'::character varying, 'project.revision_policy.update'::character varying])::text[]))), + CONSTRAINT ck_policy_mutation_idempotency_records_ck_policy_mutati_8b22 CHECK ((policy_generation > 0)), + CONSTRAINT ck_policy_mutation_idempotency_records_ck_policy_mutati_dc05 CHECK (((status)::text = ANY ((ARRAY['pending'::character varying, 'committed'::character varying])::text[]))) +); +CREATE TABLE public.pre_submit_checker_policies ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + effective_policy_id character varying(36) NOT NULL, + effective_policy_hash character varying(71) NOT NULL, + lifecycle_status character varying(30) NOT NULL, + compiler_version character varying(50), + compiled_bundle json, + compiled_bundle_hash character varying(71), + checker_names json NOT NULL, + checker_configs json NOT NULL, + created_by character varying(100) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + supersedes_pre_submit_checker_policy_id character varying(36), + superseded_at timestamp with time zone, + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + creation_scope_type character varying(16), + creation_scope_project_id character varying(36), + creation_action_id character varying(160), + creation_decision_event_id character varying(36), + CONSTRAINT ck_pre_submit_checker_policies_ck_pre_submit_checker_po_5010 CHECK ((((lifecycle_status)::text <> 'compiled'::text) OR ((compiler_version IS NOT NULL) AND (compiled_bundle IS NOT NULL) AND (compiled_bundle_hash IS NOT NULL) AND ((compiled_bundle_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text)))), + CONSTRAINT ck_pre_submit_checker_policies_ck_pre_submit_checker_po_a935 CHECK (((lifecycle_status)::text = ANY ((ARRAY['pending_compilation'::character varying, 'compiled'::character varying, 'superseded'::character varying])::text[]))), + CONSTRAINT ck_pre_submit_checker_policies_ck_pre_submit_policy_aut_90fc CHECK ((((created_by_actor_profile_id IS NULL) AND (created_via_identity_link_id IS NULL) AND (created_by_admin_role_grant_id IS NULL) AND (creation_scope_type IS NULL) AND (creation_scope_project_id IS NULL) AND (creation_action_id IS NULL) AND (creation_decision_event_id IS NULL)) OR ((created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (created_by_admin_role_grant_id IS NOT NULL) AND (creation_scope_type IS NOT NULL) AND (creation_action_id IS NOT NULL) AND ((creation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND (creation_scope_project_id IS NOT NULL) AND ((creation_scope_project_id)::text = (project_id)::text) AND ((creation_action_id)::text = 'project.submission_artifact_policy.approve'::text) AND (creation_decision_event_id IS NOT NULL)))) +); +CREATE TABLE public.pre_submit_evidence_results ( + id character varying(36) NOT NULL, + evidence_set_id character varying(36) NOT NULL, + result_order integer NOT NULL, + schema_version character varying(80) NOT NULL, + dispatch_authority character varying(160) NOT NULL, + definition_id character varying(160) NOT NULL, + definition_version character varying(40) NOT NULL, + public_name character varying(160) NOT NULL, + source character varying(160) NOT NULL, + phase character varying(40) NOT NULL, + classification character varying(40) NOT NULL, + severity character varying(16) NOT NULL, + status character varying(40) NOT NULL, + failure_code character varying(160), + message_code character varying(160) NOT NULL, + effective_plan_sha256 character varying(71) NOT NULL, + rule_instance_id character varying(71), + locked_policy_sha256 character varying(71) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_cla_b0de CHECK (((classification)::text = ANY ((ARRAY['mandatory_security'::character varying, 'mandatory_integrity'::character varying, 'mandatory_accountability'::character varying, 'advisory'::character varying])::text[]))), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_cla_f04e CHECK (((((classification)::text = 'advisory'::text) AND ((severity)::text = 'warning'::text)) OR (((classification)::text <> 'advisory'::text) AND ((severity)::text = 'blocking'::text)))), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_order CHECK ((result_order >= 0)), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_phase CHECK (((phase)::text = ANY ((ARRAY['custody'::character varying, 'identity'::character varying, 'materialization'::character varying, 'default_policy'::character varying, 'project_policy'::character varying])::text[]))), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_plan_sha256 CHECK (((effective_plan_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_pol_cef4 CHECK (((locked_policy_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_rul_321f CHECK (((((phase)::text = 'project_policy'::text) AND (rule_instance_id IS NOT NULL) AND ((rule_instance_id)::text ~ '^sha256:[0-9a-f]{64}$'::text)) OR (((phase)::text <> 'project_policy'::text) AND (rule_instance_id IS NULL)))), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_severity CHECK (((severity)::text = ANY ((ARRAY['blocking'::character varying, 'warning'::character varying])::text[]))), + CONSTRAINT ck_pre_submit_evidence_results_ck_pre_submit_result_status CHECK (((status)::text = ANY ((ARRAY['passed'::character varying, 'warning'::character varying, 'advisory_disabled'::character varying, 'dependency_not_run'::character varying, 'failed'::character varying])::text[]))), + CONSTRAINT ck_pre_submit_evidence_results_result_failure_shape CHECK (((((status)::text = 'failed'::text) AND (failure_code IS NOT NULL)) OR (((status)::text <> 'failed'::text) AND (failure_code IS NULL)))) +); +CREATE TABLE public.pre_submit_evidence_sets ( + id character varying(36) NOT NULL, + operation_identity character varying(71) NOT NULL, + actor_profile_id character varying(36) NOT NULL, + identity_link_id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + assignment_id character varying(36) NOT NULL, + predecessor_submission_id character varying(36), + predecessor_submission_version integer, + prepared_generation_id character varying(36) NOT NULL, + archive_sha256 character varying(71) NOT NULL, + archive_byte_count bigint NOT NULL, + semantic_manifest_id character varying(36) NOT NULL, + semantic_manifest_sha256 character varying(71) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_sha256 character varying(71) NOT NULL, + locked_guide_sha256 character varying(71) NOT NULL, + effective_policy_id character varying(36) NOT NULL, + locked_artifact_policy_sha256 character varying(71) NOT NULL, + pre_submit_policy_id character varying(36) NOT NULL, + locked_checker_policy_sha256 character varying(71) NOT NULL, + effective_plan_sha256 character varying(71) NOT NULL, + catalogue_id character varying(160) NOT NULL, + catalogue_version character varying(40) NOT NULL, + catalogue_manifest_sha256 character varying(71) NOT NULL, + storage_scheme character varying(16) NOT NULL, + terminal_status character varying(16) NOT NULL, + eligible boolean NOT NULL, + result_count integer NOT NULL, + result_manifest_sha256 character varying(71) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + locked_policy_context_hash character varying(71) NOT NULL, + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arch_8e95 CHECK (((archive_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_archive_size CHECK ((archive_byte_count >= 0)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arti_16f8 CHECK (((locked_artifact_policy_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_cata_ffcb CHECK (((catalogue_manifest_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_chec_765d CHECK (((locked_checker_policy_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_guide_sha256 CHECK (((locked_guide_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_mani_7268 CHECK (((semantic_manifest_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_oper_f617 CHECK (((operation_identity)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_plan_sha256 CHECK (((effective_plan_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_pred_bd87 CHECK ((((predecessor_submission_id IS NULL) AND (predecessor_submission_version IS NULL)) OR ((predecessor_submission_id IS NOT NULL) AND (predecessor_submission_version IS NOT NULL)))), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_resu_0b46 CHECK (((result_manifest_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_result_count CHECK ((result_count > 0)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_sour_982b CHECK (((source_snapshot_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stat_1ae6 CHECK (((((terminal_status)::text = 'passed'::text) AND eligible) OR (((terminal_status)::text = 'blocked'::text) AND (NOT eligible)))), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stor_022c CHECK (((storage_scheme)::text = ANY ((ARRAY['local'::character varying, 's3'::character varying])::text[]))), + CONSTRAINT ck_pre_submit_evidence_sets_ck_pre_submit_evidence_term_a512 CHECK (((terminal_status)::text = ANY ((ARRAY['passed'::character varying, 'blocked'::character varying])::text[]))), + CONSTRAINT ck_pre_submit_evidence_sets_policy_context_sha256 CHECK (((locked_policy_context_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text)) +); +CREATE TABLE public.project_compensation_adapter_bindings ( + id uuid NOT NULL, + project_id character varying(36) NOT NULL, + instrument_type character varying(32) NOT NULL, + adapter_actor_id character varying(36) NOT NULL, + route_key character varying(120) NOT NULL, + status character varying(16) DEFAULT 'active'::character varying NOT NULL, + binding_lifecycle_version integer DEFAULT 1 NOT NULL, + created_by character varying(36) NOT NULL, + created_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + suspended_by character varying(36), + suspended_at timestamp with time zone, + retired_by character varying(36), + retired_at timestamp with time zone, + CONSTRAINT ck_project_compensation_adapter_bindings_ck_project_com_1870 CHECK ((binding_lifecycle_version > 0)), + CONSTRAINT ck_project_compensation_adapter_bindings_ck_project_com_3372 CHECK (((instrument_type)::text = ANY ((ARRAY['money'::character varying, 'project_points'::character varying])::text[]))), + CONSTRAINT ck_project_compensation_adapter_bindings_ck_project_com_6958 CHECK (((route_key)::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'::text)), + CONSTRAINT ck_project_compensation_adapter_bindings_ck_project_com_95ba CHECK ((((status)::text = 'active'::text) AND (binding_lifecycle_version = 1) AND (suspended_by IS NULL) AND (suspended_at IS NULL) AND (retired_by IS NULL) AND (retired_at IS NULL))), + CONSTRAINT ck_project_compensation_adapter_bindings_ck_project_com_ade1 CHECK ((((suspended_at IS NULL) OR (suspended_at >= created_at)) AND ((retired_at IS NULL) OR (retired_at >= created_at)) AND ((retired_at IS NULL) OR (suspended_at IS NULL) OR (retired_at >= suspended_at)))), + CONSTRAINT ck_project_compensation_adapter_bindings_ck_project_com_da73 CHECK (((status)::text = ANY ((ARRAY['active'::character varying, 'suspended'::character varying, 'retired'::character varying])::text[]))), + CONSTRAINT ck_project_compensation_adapter_bindings_ck_project_com_f32d CHECK (((route_key)::text !~~ '%..%'::text)) +); +CREATE TABLE public.project_compensation_units ( + project_id character varying(36) NOT NULL, + instrument_type character varying(32) NOT NULL, + unit_code character varying(32) NOT NULL, + iso_currency_code character varying(3), + status character varying(16) DEFAULT 'active'::character varying NOT NULL, + created_by character varying(36) NOT NULL, + created_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + retired_by character varying(36), + retired_at timestamp with time zone, + CONSTRAINT ck_project_compensation_units_instrument_type CHECK (((instrument_type)::text = ANY ((ARRAY['money'::character varying, 'project_points'::character varying])::text[]))), + CONSTRAINT ck_project_compensation_units_lifecycle_shape CHECK (((((status)::text = 'active'::text) AND (retired_by IS NULL) AND (retired_at IS NULL)) OR (((status)::text = 'retired'::text) AND (retired_by IS NOT NULL) AND (retired_at IS NOT NULL)))), + CONSTRAINT ck_project_compensation_units_retirement_time CHECK (((retired_at IS NULL) OR (retired_at >= created_at))), + CONSTRAINT ck_project_compensation_units_status CHECK (((status)::text = ANY ((ARRAY['active'::character varying, 'retired'::character varying])::text[]))), + CONSTRAINT ck_project_compensation_units_unit_identity CHECK (((((instrument_type)::text = 'money'::text) AND (iso_currency_code IS NOT NULL) AND ((unit_code)::text = (iso_currency_code)::text)) OR (((instrument_type)::text = 'project_points'::text) AND (iso_currency_code IS NULL) AND ((unit_code)::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$'::text)))) +); +CREATE TABLE public.project_create_idempotency_records ( + id uuid NOT NULL, + actor_profile_id character varying(36) NOT NULL, + identity_link_id character varying(36) NOT NULL, + action_id character varying(160) NOT NULL, + idempotency_key uuid NOT NULL, + request_digest character varying(71) NOT NULL, + operation_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + operation_generation integer NOT NULL, + status character varying(16) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + committed_at timestamp with time zone, + CONSTRAINT ck_project_create_idempotency_records_ck_project_create_0a41 CHECK (((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_project_create_idempotency_records_ck_project_create_100d CHECK ((operation_generation = 1)), + CONSTRAINT ck_project_create_idempotency_records_ck_project_create_3aa0 CHECK (((((status)::text = 'pending'::text) AND (committed_at IS NULL)) OR (((status)::text = 'committed'::text) AND (committed_at IS NOT NULL)))), + CONSTRAINT ck_project_create_idempotency_records_ck_project_create_action CHECK (((action_id)::text = 'project.create'::text)), + CONSTRAINT ck_project_create_idempotency_records_ck_project_create_status CHECK (((status)::text = ANY ((ARRAY['pending'::character varying, 'committed'::character varying])::text[]))) +); +CREATE TABLE public.project_guide_compilation_attempts ( + id uuid NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + setup_run_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + canonical_input_hash character varying(71) NOT NULL, + guide_material_hash character varying(71) NOT NULL, + pre_catalogue_id character varying(160) NOT NULL, + pre_catalogue_version character varying(100) NOT NULL, + pre_catalogue_schema_version character varying(160) NOT NULL, + pre_catalogue_manifest_hash character varying(71) NOT NULL, + post_catalogue_id character varying(160) NOT NULL, + post_catalogue_version character varying(100) NOT NULL, + post_catalogue_schema_version character varying(160) NOT NULL, + post_catalogue_manifest_hash character varying(71) NOT NULL, + agent_identity character varying(100) NOT NULL, + agent_version character varying(100) NOT NULL, + instruction_version character varying(100) NOT NULL, + provider_idempotency_key uuid NOT NULL, + status character varying(32) NOT NULL, + canonical_result json, + result_hash character varying(71), + component_hashes json, + failure_code character varying(100), + persisted_compilation_id uuid, + reserved_at timestamp with time zone DEFAULT now() NOT NULL, + provider_uncertain_at timestamp with time zone, + accepted_at timestamp with time zone, + terminal_at timestamp with time zone, + persisted_at timestamp with time zone, + CONSTRAINT ck_project_guide_compilation_attempts_ck_compilation_at_00d8 CHECK ((((source_snapshot_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((canonical_input_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((guide_material_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((pre_catalogue_manifest_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((post_catalogue_manifest_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_project_guide_compilation_attempts_ck_compilation_at_31c4 CHECK (((component_hashes IS NULL) OR ((json_typeof(component_hashes) = 'object'::text) AND ((component_hashes)::jsonb = jsonb_build_object('sufficiency_hash', (component_hashes ->> 'sufficiency_hash'::text), 'artifact_policy_hash', (component_hashes ->> 'artifact_policy_hash'::text), 'requirement_inventory_hash', (component_hashes ->> 'requirement_inventory_hash'::text), 'pre_submit_hash', (component_hashes ->> 'pre_submit_hash'::text), 'post_submit_hash', (component_hashes ->> 'post_submit_hash'::text), 'capability_suggestions_hash', (component_hashes ->> 'capability_suggestions_hash'::text), 'setup_notes_hash', (component_hashes ->> 'setup_notes_hash'::text))) AND COALESCE(((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false)))), + CONSTRAINT ck_project_guide_compilation_attempts_ck_compilation_at_444c CHECK (((((status)::text = 'compilation_reserved'::text) AND (provider_uncertain_at IS NULL) AND (accepted_at IS NULL) AND (terminal_at IS NULL) AND (persisted_at IS NULL) AND (canonical_result IS NULL) AND (result_hash IS NULL) AND (component_hashes IS NULL) AND (failure_code IS NULL) AND (persisted_compilation_id IS NULL)) OR (((status)::text = 'compilation_provider_uncertain'::text) AND (provider_uncertain_at IS NOT NULL) AND (accepted_at IS NULL) AND (terminal_at IS NULL) AND (persisted_at IS NULL) AND (canonical_result IS NULL) AND (result_hash IS NULL) AND (component_hashes IS NULL) AND (failure_code IS NULL) AND (persisted_compilation_id IS NULL)) OR (((status)::text = 'provider_result_accepted'::text) AND (accepted_at IS NOT NULL) AND (terminal_at IS NULL) AND (persisted_at IS NULL) AND (canonical_result IS NOT NULL) AND (result_hash IS NOT NULL) AND (component_hashes IS NOT NULL) AND (failure_code IS NULL) AND (persisted_compilation_id IS NULL)) OR (((status)::text = 'compilation_persisted'::text) AND (accepted_at IS NOT NULL) AND (persisted_at IS NOT NULL) AND (terminal_at IS NULL) AND (canonical_result IS NOT NULL) AND (result_hash IS NOT NULL) AND (component_hashes IS NOT NULL) AND (failure_code IS NULL) AND (persisted_compilation_id IS NOT NULL)) OR (((status)::text = 'compilation_invalid_terminal'::text) AND (terminal_at IS NOT NULL) AND (accepted_at IS NULL) AND (persisted_at IS NULL) AND (canonical_result IS NULL) AND (result_hash IS NULL) AND (component_hashes IS NULL) AND (persisted_compilation_id IS NULL) AND ((failure_code)::text = ANY ((ARRAY['schema_invalid'::character varying, 'unsafe_text'::character varying, 'hash_mismatch'::character varying, 'context_mismatch'::character varying])::text[]))))), + CONSTRAINT ck_project_guide_compilation_attempts_ck_compilation_at_513e CHECK ((setup_generation > 0)), + CONSTRAINT ck_project_guide_compilation_attempts_ck_compilation_at_6057 CHECK (((canonical_result IS NULL) OR (octet_length((canonical_result)::text) <= 4194304))), + CONSTRAINT ck_project_guide_compilation_attempts_ck_compilation_at_6609 CHECK (((result_hash IS NULL) OR ((result_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_project_guide_compilation_attempts_ck_compilation_at_6c82 CHECK (((status)::text = ANY ((ARRAY['compilation_reserved'::character varying, 'compilation_provider_uncertain'::character varying, 'provider_result_accepted'::character varying, 'compilation_invalid_terminal'::character varying, 'compilation_persisted'::character varying])::text[]))) +); +CREATE TABLE public.project_guide_compilations ( + id uuid NOT NULL, + attempt_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + setup_run_id character varying(36) NOT NULL, + setup_generation bigint NOT NULL, + canonical_input_hash character varying(71) NOT NULL, + guide_material_hash character varying(71) NOT NULL, + pre_catalogue_manifest_hash character varying(71) NOT NULL, + post_catalogue_manifest_hash character varying(71) NOT NULL, + agent_identity character varying(100) NOT NULL, + agent_version character varying(100) NOT NULL, + instruction_version character varying(100) NOT NULL, + canonical_result json NOT NULL, + result_hash character varying(71) NOT NULL, + component_hashes json NOT NULL, + supersedes_compilation_id uuid, + created_by_actor_profile_id character varying(36) NOT NULL, + created_via_identity_link_id character varying(36) NOT NULL, + created_by_service_identity character varying(160) NOT NULL, + creation_action_id character varying(160) NOT NULL, + authorization_decision_event_id character varying(36) NOT NULL, + authorization_resource_context_digest character varying(71) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_project_guide_compilations_ck_project_guide_compilat_8a51 CHECK (((setup_generation > 0) AND ((created_by_service_identity)::text = 'workstream.project.setup'::text) AND ((creation_action_id)::text = 'project.guide_compilation.execute'::text))), + CONSTRAINT ck_project_guide_compilations_ck_project_guide_compilat_9cd9 CHECK ((((source_snapshot_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((canonical_input_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((guide_material_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((pre_catalogue_manifest_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((post_catalogue_manifest_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((result_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_project_guide_compilations_ck_project_guide_compilat_d554 CHECK (((authorization_resource_context_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_project_guide_compilations_ck_project_guide_compilat_dafe CHECK (((octet_length((canonical_result)::text) <= 4194304) AND (json_typeof(component_hashes) = 'object'::text) AND ((component_hashes)::jsonb = jsonb_build_object('sufficiency_hash', (component_hashes ->> 'sufficiency_hash'::text), 'artifact_policy_hash', (component_hashes ->> 'artifact_policy_hash'::text), 'requirement_inventory_hash', (component_hashes ->> 'requirement_inventory_hash'::text), 'pre_submit_hash', (component_hashes ->> 'pre_submit_hash'::text), 'post_submit_hash', (component_hashes ->> 'post_submit_hash'::text), 'capability_suggestions_hash', (component_hashes ->> 'capability_suggestions_hash'::text), 'setup_notes_hash', (component_hashes ->> 'setup_notes_hash'::text))) AND COALESCE(((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false) AND COALESCE(((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text), false))) +); +CREATE TABLE public.project_guides ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + version character varying(50) NOT NULL, + status character varying(30) NOT NULL, + content_markdown text NOT NULL, + approved_by character varying(100), + effective_at timestamp with time zone, + change_summary text, + created_by character varying(100) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + superseded_at timestamp with time zone, + last_mutated_by_actor_profile_id character varying(36), + last_mutated_via_identity_link_id character varying(36), + last_mutated_by_admin_role_grant_id uuid, + last_mutation_scope_type character varying(16), + last_mutation_scope_project_id character varying(36), + last_mutation_action_id character varying(160), + last_authorization_decision_event_id character varying(36), + mutation_generation integer, + selected_review_policy_id character varying(36), + selected_review_policy_hash character varying(71), + selected_revision_policy_id character varying(36), + selected_revision_policy_hash character varying(71), + selected_review_policy_generation integer, + selected_revision_policy_generation integer, + CONSTRAINT ck_project_guides_active_policy_selection_required CHECK ((((status)::text <> ALL ((ARRAY['active'::character varying, 'superseded'::character varying])::text[])) OR ((selected_review_policy_id IS NOT NULL) AND (selected_review_policy_generation IS NOT NULL) AND (selected_review_policy_hash IS NOT NULL) AND (selected_revision_policy_id IS NOT NULL) AND (selected_revision_policy_generation IS NOT NULL) AND (selected_revision_policy_hash IS NOT NULL)))), + CONSTRAINT ck_project_guides_guide_mutation_authority_shape CHECK ((((mutation_generation IS NULL) AND (last_mutated_by_actor_profile_id IS NULL) AND (last_mutated_via_identity_link_id IS NULL) AND (last_mutated_by_admin_role_grant_id IS NULL) AND (last_mutation_scope_type IS NULL) AND (last_mutation_scope_project_id IS NULL) AND (last_mutation_action_id IS NULL) AND (last_authorization_decision_event_id IS NULL)) OR ((mutation_generation > 0) AND (last_mutated_by_actor_profile_id IS NOT NULL) AND (last_mutated_via_identity_link_id IS NOT NULL) AND (last_mutated_by_admin_role_grant_id IS NOT NULL) AND ((last_mutation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND ((((last_mutation_scope_type)::text = 'system'::text) AND (last_mutation_scope_project_id IS NULL)) OR (((last_mutation_scope_type)::text = 'project'::text) AND ((last_mutation_scope_project_id)::text = (project_id)::text))) AND ((last_mutation_action_id)::text = ANY ((ARRAY['project.guide.create'::character varying, 'project.guide.update'::character varying, 'project.guide_source_snapshot.create'::character varying])::text[])) AND (last_authorization_decision_event_id IS NOT NULL)))), + CONSTRAINT ck_project_guides_policy_selection_shape CHECK (((((selected_review_policy_id IS NULL) AND (selected_review_policy_generation IS NULL) AND (selected_review_policy_hash IS NULL)) OR ((selected_review_policy_id IS NOT NULL) AND (selected_review_policy_generation IS NOT NULL) AND (selected_review_policy_hash IS NOT NULL))) AND (((selected_revision_policy_id IS NULL) AND (selected_revision_policy_generation IS NULL) AND (selected_revision_policy_hash IS NULL)) OR ((selected_revision_policy_id IS NOT NULL) AND (selected_revision_policy_generation IS NOT NULL) AND (selected_revision_policy_hash IS NOT NULL))))) +); +CREATE TABLE public.project_role_grants ( + id uuid NOT NULL, + project_id character varying(36) NOT NULL, + actor_profile_id character varying(36) NOT NULL, + role character varying(24) NOT NULL, + status character varying(16) DEFAULT 'active'::character varying NOT NULL, + version smallint DEFAULT '1'::smallint NOT NULL, + grant_method character varying(16) DEFAULT 'manual'::character varying NOT NULL, + qualification_snapshot_id uuid NOT NULL, + granted_by_actor_profile_id character varying(36) NOT NULL, + granted_by_admin_role_grant_id uuid NOT NULL, + grant_reason text NOT NULL, + granted_at timestamp with time zone DEFAULT now() NOT NULL, + revoked_by_actor_profile_id character varying(36), + revoked_by_admin_role_grant_id uuid, + revoked_reason text, + revoked_at timestamp with time zone, + CONSTRAINT ck_project_role_grants_grant_method CHECK (((grant_method)::text = 'manual'::text)), + CONSTRAINT ck_project_role_grants_lifecycle CHECK (((((status)::text = 'active'::text) AND (version = 1) AND (revoked_by_actor_profile_id IS NULL) AND (revoked_by_admin_role_grant_id IS NULL) AND (revoked_reason IS NULL) AND (revoked_at IS NULL)) OR (((status)::text = 'revoked'::text) AND (version = 2) AND (revoked_by_actor_profile_id IS NOT NULL) AND (revoked_by_admin_role_grant_id IS NOT NULL) AND (revoked_reason IS NOT NULL) AND (revoked_at IS NOT NULL)))), + CONSTRAINT ck_project_role_grants_reason CHECK ((public.project_role_reason_is_safe(grant_reason) AND ((revoked_reason IS NULL) OR public.project_role_reason_is_safe(revoked_reason)))), + CONSTRAINT ck_project_role_grants_role CHECK (((role)::text = ANY ((ARRAY['submitter'::character varying, 'reviewer'::character varying, 'adjudicator'::character varying])::text[]))) +); +CREATE TABLE public.project_role_qualification_snapshots ( + id uuid NOT NULL, + project_id character varying(36) NOT NULL, + actor_profile_id character varying(36) NOT NULL, + requested_role character varying(24) NOT NULL, + skills_snapshot jsonb NOT NULL, + reputation_snapshot jsonb NOT NULL, + prior_project_work_refs jsonb NOT NULL, + external_expertise_refs jsonb NOT NULL, + captured_by_actor_profile_id character varying(36) NOT NULL, + captured_by_admin_role_grant_id uuid NOT NULL, + captured_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_project_role_qualification_snapshots_availability CHECK ((public.project_role_availability_is_safe(skills_snapshot) AND public.project_role_availability_is_safe(reputation_snapshot))), + CONSTRAINT ck_project_role_qualification_snapshots_external_expertise_refs CHECK (public.project_role_reference_array_is_safe(external_expertise_refs, false)), + CONSTRAINT ck_project_role_qualification_snapshots_prior_work_refs CHECK (public.project_role_reference_array_is_safe(prior_project_work_refs, true)), + CONSTRAINT ck_project_role_qualification_snapshots_role CHECK (((requested_role)::text = ANY ((ARRAY['submitter'::character varying, 'reviewer'::character varying, 'adjudicator'::character varying])::text[]))) +); +CREATE TABLE public.project_setup_runs ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + celery_task_id character varying(155), + status character varying(50) NOT NULL, + current_step character varying(100) NOT NULL, + output_sufficiency_report_id character varying(36), + output_submission_artifact_policy_id character varying(36), + error_code character varying(100), + error_summary text, + created_by character varying(100) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + started_at timestamp with time zone, + finished_at timestamp with time zone, + output_post_submit_checker_policy_id character varying(36), + post_submit_derivation_summary json, + setup_generation bigint NOT NULL, + authorized_by_actor_profile_id character varying(36), + authorized_via_identity_link_id character varying(36), + authorized_by_admin_role_grant_id uuid, + authorization_scope_type character varying(16), + authorization_scope_project_id character varying(36), + authorization_action_id character varying(160), + authorization_decision_event_id character varying(36), + error_artifact_incident_id character varying(36), + continuation_verification_job_id character varying(36), + continuation_started_at timestamp with time zone, + CONSTRAINT ck_project_setup_runs_ck_project_setup_runs_generation_positive CHECK ((setup_generation > 0)), + CONSTRAINT ck_project_setup_runs_ck_project_setup_runs_status CHECK (((status)::text = ANY ((ARRAY['queued'::character varying, 'dispatch_pending'::character varying, 'enqueue_failed'::character varying, 'enqueue_identity_mismatch'::character varying, 'running_sufficiency_agent'::character varying, 'sufficiency_blocked'::character varying, 'running_policy_derivation_agent'::character varying, 'policy_draft_ready'::character varying, 'running_post_submit_derivation_agent'::character varying, 'post_submit_setup_blocked'::character varying, 'post_submit_policy_compiled'::character varying, 'setup_blocked'::character varying, 'failed'::character varying])::text[]))), + CONSTRAINT ck_project_setup_runs_setup_run_authority_shape CHECK ((((authorized_by_actor_profile_id IS NULL) AND (authorized_via_identity_link_id IS NULL) AND (authorized_by_admin_role_grant_id IS NULL) AND (authorization_scope_type IS NULL) AND (authorization_scope_project_id IS NULL) AND (authorization_action_id IS NULL) AND (authorization_decision_event_id IS NULL)) OR ((authorized_by_actor_profile_id IS NOT NULL) AND (authorized_via_identity_link_id IS NOT NULL) AND (authorized_by_admin_role_grant_id IS NOT NULL) AND ((authorization_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND ((((authorization_scope_type)::text = 'system'::text) AND (authorization_scope_project_id IS NULL)) OR (((authorization_scope_type)::text = 'project'::text) AND ((authorization_scope_project_id)::text = (project_id)::text))) AND ((authorization_action_id)::text = 'project.guide_source_snapshot.create'::text) AND (authorization_decision_event_id IS NOT NULL)))) +); +CREATE TABLE public.projects ( + id character varying(36) NOT NULL, + name character varying(200) NOT NULL, + slug character varying(120) NOT NULL, + description text, + status character varying(30) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + creation_scope_type character varying(16), + creation_action_id character varying(160), + authorization_decision_event_id character varying(36), + CONSTRAINT ck_projects_creation_authority_shape CHECK ((((created_by_actor_profile_id IS NULL) AND (created_via_identity_link_id IS NULL) AND (created_by_admin_role_grant_id IS NULL) AND (creation_scope_type IS NULL) AND (creation_action_id IS NULL) AND (authorization_decision_event_id IS NULL)) OR ((created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (created_by_admin_role_grant_id IS NOT NULL) AND ((creation_scope_type)::text = 'system'::text) AND ((creation_action_id)::text = 'project.create'::text) AND (authorization_decision_event_id IS NOT NULL)))) +); +CREATE TABLE public.review_admission_idempotency_records ( + id uuid NOT NULL, + idempotency_key uuid NOT NULL, + operation_id uuid NOT NULL, + request_digest character varying(71) NOT NULL, + project_id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + submission_id character varying(36) NOT NULL, + submission_version integer NOT NULL, + admitting_checker_run_id character varying(36) NOT NULL, + status character varying(16) DEFAULT 'pending'::character varying NOT NULL, + review_queue_entry_id uuid, + created_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + committed_at timestamp with time zone, + CONSTRAINT ck_review_admission_idempotency_records_ck_review_admis_2b6d CHECK ((submission_version > 0)), + CONSTRAINT ck_review_admission_idempotency_records_ck_review_admis_4cd5 CHECK (((((status)::text = 'pending'::text) AND (review_queue_entry_id IS NULL) AND (committed_at IS NULL)) OR (((status)::text = 'committed'::text) AND (review_queue_entry_id IS NOT NULL) AND (committed_at IS NOT NULL)))), + CONSTRAINT ck_review_admission_idempotency_records_ck_review_admis_88bf CHECK (((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_review_admission_idempotency_records_ck_review_admis_b8b8 CHECK (((status)::text = ANY ((ARRAY['pending'::character varying, 'committed'::character varying])::text[]))) +); +CREATE TABLE public.review_leases ( + id uuid NOT NULL, + review_queue_entry_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + submission_id character varying(36) NOT NULL, + submission_version integer NOT NULL, + reviewer_id character varying(36) NOT NULL, + reviewer_contribution_policy_version_id uuid NOT NULL, + attempt_generation integer NOT NULL, + status character varying(16) DEFAULT 'active'::character varying NOT NULL, + claimed_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + expires_at timestamp with time zone NOT NULL, + closed_at timestamp with time zone, + close_reason character varying(32), + CONSTRAINT ck_review_leases_attempt_generation_positive CHECK ((attempt_generation > 0)), + CONSTRAINT ck_review_leases_closure_after_claim CHECK (((closed_at IS NULL) OR (closed_at >= claimed_at))), + CONSTRAINT ck_review_leases_expiry_after_claim CHECK ((expires_at > claimed_at)), + CONSTRAINT ck_review_leases_lifecycle_shape CHECK (((((status)::text = 'active'::text) AND (closed_at IS NULL) AND (close_reason IS NULL)) OR (((status)::text = 'consumed'::text) AND (closed_at IS NOT NULL) AND ((close_reason)::text = 'review_recorded'::text)) OR (((status)::text = 'released'::text) AND (closed_at IS NOT NULL) AND ((close_reason)::text = 'manual_release'::text)) OR (((status)::text = 'expired'::text) AND (closed_at IS NOT NULL) AND ((close_reason)::text = 'lease_expired'::text)) OR (((status)::text = 'revoked'::text) AND (closed_at IS NOT NULL) AND ((close_reason)::text = ANY ((ARRAY['grant_revoked'::character varying, 'admin_override'::character varying])::text[]))))), + CONSTRAINT ck_review_leases_status CHECK (((status)::text = ANY ((ARRAY['active'::character varying, 'consumed'::character varying, 'released'::character varying, 'expired'::character varying, 'revoked'::character varying])::text[]))) +); +CREATE TABLE public.review_policies ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + requires_second_review boolean NOT NULL, + allowed_decisions json NOT NULL, + minimum_finding_fields json NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + policy_generation integer NOT NULL, + policy_hash character varying(71) NOT NULL, + semantics_status character varying(24) NOT NULL, + supersedes_policy_id character varying(36), + review_preference_window_seconds integer, + review_lease_duration_seconds integer, + max_active_review_leases_per_reviewer integer, + self_review_allowed boolean, + reject_policy character varying(32), + finding_evidence_requirement character varying(32), + predecessor_policy_hash character varying(71), + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + creation_scope_type character varying(16), + creation_scope_project_id character varying(36), + creation_action_id character varying(160), + authorization_decision_event_id character varying(36), + CONSTRAINT ck_review_policies_review_policy_authority_shape CHECK ((((semantics_status)::text = 'legacy_incomplete'::text) OR ((created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (created_by_admin_role_grant_id IS NOT NULL) AND ((creation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND ((creation_action_id)::text = 'project.review_policy.update'::text) AND (authorization_decision_event_id IS NOT NULL)))), + CONSTRAINT ck_review_policies_review_policy_identity_shape CHECK (((policy_generation > 0) AND ((policy_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((semantics_status)::text = ANY ((ARRAY['complete'::character varying, 'legacy_incomplete'::character varying])::text[])))), + CONSTRAINT ck_review_policies_review_policy_predecessor_shape CHECK ((((supersedes_policy_id IS NULL) AND (predecessor_policy_hash IS NULL) AND (policy_generation = 1)) OR ((supersedes_policy_id IS NOT NULL) AND ((predecessor_policy_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND (policy_generation > 1)) OR ((semantics_status)::text = 'legacy_incomplete'::text))), + CONSTRAINT ck_review_policies_review_policy_semantics_shape CHECK ((((semantics_status)::text = 'legacy_incomplete'::text) OR ((review_preference_window_seconds > 0) AND (review_lease_duration_seconds > 0) AND (max_active_review_leases_per_reviewer = 1) AND (self_review_allowed = false) AND ((reject_policy)::text = 'close_task'::text) AND ((finding_evidence_requirement)::text = ANY ((ARRAY['optional'::character varying, 'required_for_blocking'::character varying, 'required_for_all'::character varying])::text[]))))) +); +CREATE TABLE public.review_queue_entries ( + id uuid NOT NULL, + project_id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + submission_id character varying(36) NOT NULL, + submission_version integer NOT NULL, + admitting_checker_run_id character varying(36) NOT NULL, + queue_state character varying(16) DEFAULT 'pending'::character varying NOT NULL, + routing_mode character varying(16) NOT NULL, + routing_reason character varying(32) NOT NULL, + first_queued_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + available_since timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + preferred_reviewer_id character varying(36), + preference_expires_at timestamp with time zone, + closed_at timestamp with time zone, + closed_reason character varying(32), + routing_generation integer DEFAULT 1 NOT NULL, + lifecycle_generation integer DEFAULT 1 NOT NULL, + created_at timestamp with time zone DEFAULT statement_timestamp() NOT NULL, + active_lease_id uuid, + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_availab_d484 CHECK ((available_since >= first_queued_at)), + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_generat_38b7 CHECK (((routing_generation > 0) AND (lifecycle_generation > 0))), + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_lifecycle_shape CHECK (((((queue_state)::text = 'pending'::text) AND (active_lease_id IS NULL) AND (closed_at IS NULL) AND (closed_reason IS NULL)) OR (((queue_state)::text = 'leased'::text) AND (active_lease_id IS NOT NULL) AND (closed_at IS NULL) AND (closed_reason IS NULL)) OR (((queue_state)::text = 'closed'::text) AND (active_lease_id IS NULL) AND (closed_at IS NOT NULL) AND ((closed_reason)::text = ANY ((ARRAY['review_recorded'::character varying, 'task_closed'::character varying, 'admin_cancelled'::character varying])::text[])) AND (closed_at >= first_queued_at)))), + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_queue_state CHECK (((queue_state)::text = ANY ((ARRAY['pending'::character varying, 'leased'::character varying, 'closed'::character varying])::text[]))), + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_routing_mode CHECK (((routing_mode)::text = ANY ((ARRAY['open'::character varying, 'preferred'::character varying])::text[]))), + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_routing_reason CHECK (((routing_reason)::text = ANY ((ARRAY['first_submission'::character varying, 'revision_return'::character varying, 'admin_assignment'::character varying])::text[]))), + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_routing_shape CHECK (((((routing_mode)::text = 'open'::text) AND (preferred_reviewer_id IS NULL) AND (preference_expires_at IS NULL)) OR (((routing_mode)::text = 'preferred'::text) AND (preferred_reviewer_id IS NOT NULL) AND (preference_expires_at IS NOT NULL) AND (preference_expires_at > first_queued_at)))), + CONSTRAINT ck_review_queue_entries_ck_review_queue_entries_submiss_2f6b CHECK ((submission_version > 0)) +); +CREATE TABLE public.revision_policies ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + max_revision_rounds integer NOT NULL, + revision_deadline_hours integer NOT NULL, + allowed_resubmission_states json NOT NULL, + reviewer_reassignment_rule text, + created_at timestamp with time zone DEFAULT now() NOT NULL, + policy_generation integer NOT NULL, + policy_hash character varying(71) NOT NULL, + semantics_status character varying(24) NOT NULL, + supersedes_policy_id character varying(36), + predecessor_policy_hash character varying(71), + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + creation_scope_type character varying(16), + creation_scope_project_id character varying(36), + creation_action_id character varying(160), + authorization_decision_event_id character varying(36), + CONSTRAINT ck_revision_policies_revision_policy_authority_shape CHECK ((((semantics_status)::text = 'legacy_incomplete'::text) OR ((created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (created_by_admin_role_grant_id IS NOT NULL) AND ((creation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND ((creation_action_id)::text = 'project.revision_policy.update'::text) AND (authorization_decision_event_id IS NOT NULL)))), + CONSTRAINT ck_revision_policies_revision_policy_identity_shape CHECK (((policy_generation > 0) AND ((policy_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((semantics_status)::text = ANY ((ARRAY['complete'::character varying, 'legacy_incomplete'::character varying])::text[])))), + CONSTRAINT ck_revision_policies_revision_policy_predecessor_shape CHECK ((((supersedes_policy_id IS NULL) AND (predecessor_policy_hash IS NULL) AND (policy_generation = 1)) OR ((supersedes_policy_id IS NOT NULL) AND ((predecessor_policy_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND (policy_generation > 1)) OR ((semantics_status)::text = 'legacy_incomplete'::text))), + CONSTRAINT ck_revision_policies_revision_policy_semantics_shape CHECK ((((semantics_status)::text = 'legacy_incomplete'::text) OR ((max_revision_rounds > 0) AND (revision_deadline_hours > 0)))) +); +CREATE TABLE public.submission_artifact_policies ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + guide_version character varying(50) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + source_snapshot_hash character varying(71) NOT NULL, + policy_version character varying(50) NOT NULL, + lifecycle_status character varying(30) NOT NULL, + policy_body json NOT NULL, + policy_hash character varying(71) NOT NULL, + derivation_source character varying(100) NOT NULL, + source_material_refs json NOT NULL, + derivation_agent_name character varying(100), + derivation_agent_version character varying(50), + created_by character varying(100) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + approved_by_role character varying(50), + approved_by_actor character varying(100), + approved_at timestamp with time zone, + supersedes_policy_id character varying(36), + superseded_at timestamp with time zone, + change_summary text, + created_by_actor_profile_id character varying(36), + created_via_identity_link_id character varying(36), + created_by_admin_role_grant_id uuid, + created_by_service_identity character varying(160), + creation_scope_type character varying(16), + creation_scope_project_id character varying(36), + creation_action_id character varying(160), + creation_decision_event_id character varying(36), + approved_by_actor_profile_id character varying(36), + approved_via_identity_link_id character varying(36), + approved_by_admin_role_grant_id uuid, + approval_scope_type character varying(16), + approval_scope_project_id character varying(36), + approval_action_id character varying(160), + approval_decision_event_id character varying(36), + CONSTRAINT ck_submission_artifact_policies_ck_submission_artifact__20ca CHECK (((lifecycle_status)::text = ANY ((ARRAY['draft'::character varying, 'approved'::character varying, 'superseded'::character varying])::text[]))), + CONSTRAINT ck_submission_artifact_policies_ck_submission_artifact__52ca CHECK ((((lifecycle_status)::text <> 'approved'::text) OR (((approved_by_role)::text = ANY ((ARRAY['admin'::character varying, 'project_manager'::character varying])::text[])) AND (approved_by_actor IS NOT NULL) AND (approved_at IS NOT NULL)))), + CONSTRAINT ck_submission_artifact_policies_ck_submission_policy_ap_0e4d CHECK ((((approved_by_actor_profile_id IS NULL) AND (approved_via_identity_link_id IS NULL) AND (approved_by_admin_role_grant_id IS NULL) AND (approval_scope_type IS NULL) AND (approval_scope_project_id IS NULL) AND (approval_action_id IS NULL) AND (approval_decision_event_id IS NULL)) OR ((approved_by_actor_profile_id IS NOT NULL) AND (approved_via_identity_link_id IS NOT NULL) AND (approved_by_admin_role_grant_id IS NOT NULL) AND (approval_scope_type IS NOT NULL) AND (approval_action_id IS NOT NULL) AND ((approval_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[])) AND (approval_scope_project_id IS NOT NULL) AND ((approval_scope_project_id)::text = (project_id)::text) AND ((approval_action_id)::text = 'project.submission_artifact_policy.approve'::text) AND (approval_decision_event_id IS NOT NULL)))), + CONSTRAINT ck_submission_artifact_policies_ck_submission_policy_cr_0629 CHECK ((((created_by_actor_profile_id IS NULL) AND (created_via_identity_link_id IS NULL) AND (created_by_admin_role_grant_id IS NULL) AND (created_by_service_identity IS NULL) AND (creation_scope_type IS NULL) AND (creation_scope_project_id IS NULL) AND (creation_action_id IS NULL) AND (creation_decision_event_id IS NULL)) OR ((created_by_actor_profile_id IS NOT NULL) AND (created_via_identity_link_id IS NOT NULL) AND (creation_scope_type IS NOT NULL) AND (creation_action_id IS NOT NULL) AND (creation_scope_project_id IS NOT NULL) AND ((creation_scope_project_id)::text = (project_id)::text) AND (creation_decision_event_id IS NOT NULL) AND ((creation_action_id)::text = ANY ((ARRAY['project.submission_artifact_policy.create'::character varying, 'project.submission_artifact_policy.derive'::character varying, 'project.submission_artifact_policy.update'::character varying])::text[])) AND (((created_by_admin_role_grant_id IS NOT NULL) AND (created_by_service_identity IS NULL) AND ((creation_scope_type)::text = ANY ((ARRAY['system'::character varying, 'project'::character varying])::text[]))) OR ((created_by_admin_role_grant_id IS NULL) AND (created_by_service_identity IS NOT NULL) AND ((created_by_service_identity)::text = 'workstream.project.setup'::text) AND ((creation_scope_type)::text = 'service'::text) AND ((creation_action_id)::text = 'project.submission_artifact_policy.derive'::text)))))) +); +CREATE TABLE public.submission_bundle_admissions ( + id character varying(36) NOT NULL, + durable_intent_id character varying(36) NOT NULL, + pre_submit_evidence_set_id character varying(36) NOT NULL, + put_attempt_id character varying(36) NOT NULL, + artifact_content_id character varying(36) NOT NULL, + verified_replica_id character varying(36) NOT NULL, + verification_receipt_id character varying(36) NOT NULL, + put_operation_receipt_id character varying(36), + put_observation_receipt_id character varying(36), + actor_profile_id character varying(36) NOT NULL, + identity_link_id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + assignment_id character varying(36) NOT NULL, + predecessor_submission_id character varying(36), + predecessor_submission_version integer, + locked_policy_context_hash character varying(71) NOT NULL, + semantic_manifest_id character varying(36) NOT NULL, + semantic_manifest_sha256 character varying(71) NOT NULL, + archive_sha256 character varying(71) NOT NULL, + archive_byte_count bigint NOT NULL, + status character varying(16) DEFAULT 'ready'::character varying NOT NULL, + ready_at timestamp with time zone NOT NULL, + consumed_at timestamp with time zone, + consumed_by_submission_id character varying(36), + stale_at timestamp with time zone, + stale_reason character varying(500), + created_at timestamp with time zone DEFAULT now() NOT NULL, + CONSTRAINT ck_submission_bundle_admissions_archive_sha256 CHECK (((archive_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_submission_bundle_admissions_archive_size CHECK ((archive_byte_count >= 0)), + CONSTRAINT ck_submission_bundle_admissions_manifest_sha256 CHECK (((semantic_manifest_sha256)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_submission_bundle_admissions_policy_context_hash CHECK (((locked_policy_context_hash)::text ~ '^sha256:[0-9a-f]{64}$'::text)), + CONSTRAINT ck_submission_bundle_admissions_predecessor_shape CHECK (((predecessor_submission_id IS NULL) = (predecessor_submission_version IS NULL))), + CONSTRAINT ck_submission_bundle_admissions_status CHECK (((status)::text = ANY ((ARRAY['ready'::character varying, 'consumed'::character varying, 'stale'::character varying])::text[]))), + CONSTRAINT ck_submission_bundle_admissions_terminal_shape CHECK (((((status)::text = 'ready'::text) AND (consumed_at IS NULL) AND (consumed_by_submission_id IS NULL) AND (stale_at IS NULL) AND (stale_reason IS NULL)) OR (((status)::text = 'consumed'::text) AND (consumed_at IS NOT NULL) AND (consumed_by_submission_id IS NOT NULL) AND (stale_at IS NULL) AND (stale_reason IS NULL)) OR (((status)::text = 'stale'::text) AND (consumed_at IS NULL) AND (consumed_by_submission_id IS NULL) AND (stale_at IS NOT NULL) AND ((octet_length((stale_reason)::text) >= 1) AND (octet_length((stale_reason)::text) <= 500))))), + CONSTRAINT ck_submission_bundle_admissions_write_receipt_shape CHECK (((((put_operation_receipt_id IS NOT NULL))::integer + ((put_observation_receipt_id IS NOT NULL))::integer) = 1)) +); +CREATE TABLE public.submission_bundle_durable_intents ( + id character varying(36) NOT NULL, + pre_submit_evidence_set_id character varying(36) NOT NULL, + put_attempt_id character varying(36) NOT NULL, + created_at timestamp with time zone DEFAULT now() NOT NULL +); +CREATE TABLE public.submission_policy_mutation_idempotency_records ( + id uuid NOT NULL, + actor_profile_id character varying(36) NOT NULL, + identity_link_id character varying(36) NOT NULL, + service_identity character varying(160), + action_id character varying(160) NOT NULL, + idempotency_key uuid, + request_digest character varying(71) NOT NULL, + resource_context_digest character varying(71) NOT NULL, + resource_context_json json NOT NULL, + operation_id uuid NOT NULL, + project_id character varying(36) NOT NULL, + guide_id character varying(36) NOT NULL, + source_snapshot_id character varying(36) NOT NULL, + policy_id character varying(36) NOT NULL, + setup_run_id character varying(36), + setup_generation bigint NOT NULL, + setup_task_id uuid, + correlation_id uuid, + status character varying(16) NOT NULL, + response_json json, + committed_policy_id character varying(36), + committed_effective_policy_id character varying(36), + committed_pre_submit_policy_id character varying(36), + created_at timestamp with time zone DEFAULT now() NOT NULL, + committed_at timestamp with time zone, + CONSTRAINT ck_submission_policy_mutation_idempotency_records_ck_su_0119 CHECK ((((request_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text) AND ((resource_context_digest)::text ~ '^sha256:[0-9a-f]{64}$'::text))), + CONSTRAINT ck_submission_policy_mutation_idempotency_records_ck_su_0dbe CHECK (((action_id)::text = ANY ((ARRAY['project.submission_artifact_policy.create'::character varying, 'project.submission_artifact_policy.derive'::character varying, 'project.submission_artifact_policy.update'::character varying, 'project.submission_artifact_policy.approve'::character varying])::text[]))), + CONSTRAINT ck_submission_policy_mutation_idempotency_records_ck_su_2b53 CHECK ((setup_generation > 0)), + CONSTRAINT ck_submission_policy_mutation_idempotency_records_ck_su_58d4 CHECK (((((status)::text = ANY ((ARRAY['reserved'::character varying, 'pending'::character varying])::text[])) AND (response_json IS NULL) AND (committed_at IS NULL) AND (committed_policy_id IS NULL) AND (committed_effective_policy_id IS NULL) AND (committed_pre_submit_policy_id IS NULL)) OR (((status)::text = 'committed'::text) AND (response_json IS NOT NULL) AND (committed_at IS NOT NULL) AND (committed_policy_id IS NOT NULL) AND ((((action_id)::text = 'project.submission_artifact_policy.approve'::text) AND (committed_effective_policy_id IS NOT NULL) AND (committed_pre_submit_policy_id IS NOT NULL)) OR (((action_id)::text <> 'project.submission_artifact_policy.approve'::text) AND (committed_effective_policy_id IS NULL) AND (committed_pre_submit_policy_id IS NULL)))))), + CONSTRAINT ck_submission_policy_mutation_idempotency_records_ck_su_a824 CHECK (((status)::text = ANY ((ARRAY['reserved'::character varying, 'pending'::character varying, 'committed'::character varying])::text[]))), + CONSTRAINT ck_submission_policy_mutation_idempotency_records_ck_su_b357 CHECK ((((service_identity IS NULL) AND (idempotency_key IS NOT NULL) AND (setup_run_id IS NULL) AND (setup_task_id IS NULL) AND (correlation_id IS NULL)) OR ((service_identity IS NOT NULL) AND ((service_identity)::text = 'workstream.project.setup'::text) AND (idempotency_key IS NULL) AND ((action_id)::text = 'project.submission_artifact_policy.derive'::text) AND (setup_run_id IS NOT NULL) AND (setup_task_id IS NOT NULL) AND (correlation_id IS NOT NULL)))) +); +CREATE TABLE public.submissions ( + id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + contributor_id character varying(36) NOT NULL, + version integer NOT NULL, + status character varying(30) NOT NULL, + summary text NOT NULL, + package_uri character varying(1000), + package_hash character varying(128) NOT NULL, + artifact_hash_manifest json NOT NULL, + worker_attestation text NOT NULL, + locked_guide_version character varying(50) NOT NULL, + locked_payment_policy_version character varying(50) NOT NULL, + submitted_at timestamp with time zone DEFAULT now() NOT NULL, + locked_at timestamp with time zone, + supersedes_submission_id character varying(36), + locked_guide_source_snapshot_id character varying(36), + locked_guide_source_snapshot_hash character varying(71), + locked_effective_project_submission_artifact_policy_id character varying(36), + locked_effective_project_submission_artifact_policy_hash character varying(71), + locked_pre_submit_checker_policy_id character varying(36), + locked_pre_submit_checker_bundle_hash character varying(71), + locked_post_submit_checker_policy_id character varying(36), + locked_post_submit_checker_policy_version character varying(50), + locked_post_submit_checker_policy_hash character varying(71), + locked_post_submit_checker_policy_body json, + locked_review_policy_id character varying(36) NOT NULL, + locked_review_policy_generation integer NOT NULL, + locked_review_policy_hash character varying(71) NOT NULL, + locked_revision_policy_id character varying(36) NOT NULL, + locked_revision_policy_generation integer NOT NULL, + locked_revision_policy_hash character varying(71) NOT NULL, + CONSTRAINT ck_submissions_post_submit_policy_lock_complete CHECK (((locked_post_submit_checker_policy_id IS NOT NULL) AND (locked_post_submit_checker_policy_version IS NOT NULL) AND (locked_post_submit_checker_policy_hash IS NOT NULL) AND (locked_post_submit_checker_policy_body IS NOT NULL))) +); +CREATE TABLE public.task_assignments ( + id character varying(36) NOT NULL, + task_id character varying(36) NOT NULL, + contributor_id character varying(36) NOT NULL, + assigned_by character varying(100) NOT NULL, + assigned_at timestamp with time zone DEFAULT now() NOT NULL, + accepted_at timestamp with time zone, + released_at timestamp with time zone, + status character varying(30) NOT NULL +); +CREATE TABLE public.workstream_tasks ( + id character varying(36) NOT NULL, + project_id character varying(36) NOT NULL, + locked_guide_version character varying(50), + locked_payment_policy_version character varying(50), + source_type character varying(50) NOT NULL, + source_ref character varying(500), + source_payload_hash character varying(128), + import_batch_id character varying(100), + external_task_id character varying(200), + title character varying(300) NOT NULL, + description text NOT NULL, + task_type character varying(100), + difficulty character varying(50), + skill_tags json NOT NULL, + estimated_time_minutes integer, + base_amount numeric(12,2), + currency character varying(20), + payout_type character varying(50), + status character varying(30) NOT NULL, + acceptance_criteria text, + rejection_criteria text, + deadline_at timestamp with time zone, + created_by character varying(100) NOT NULL, + assigned_to character varying(100), + created_at timestamp with time zone DEFAULT now() NOT NULL, + updated_at timestamp with time zone DEFAULT now() NOT NULL, + locked_guide_source_snapshot_id character varying(36), + locked_guide_source_snapshot_hash character varying(71), + locked_effective_project_submission_artifact_policy_id character varying(36), + locked_effective_project_submission_artifact_policy_hash character varying(71), + locked_pre_submit_checker_policy_id character varying(36), + locked_pre_submit_checker_bundle_hash character varying(71), + locked_post_submit_checker_policy_id character varying(36), + locked_post_submit_checker_policy_version character varying(50), + locked_post_submit_checker_policy_hash character varying(71), + locked_post_submit_checker_policy_body json, + locked_review_policy_id character varying(36), + locked_review_policy_generation integer, + locked_review_policy_hash character varying(71), + locked_revision_policy_id character varying(36), + locked_revision_policy_generation integer, + locked_revision_policy_hash character varying(71), + CONSTRAINT ck_workstream_tasks_post_submit_policy_lock_complete CHECK ((((status)::text = 'draft'::text) OR ((locked_post_submit_checker_policy_id IS NOT NULL) AND (locked_post_submit_checker_policy_version IS NOT NULL) AND (locked_post_submit_checker_policy_hash IS NOT NULL) AND (locked_post_submit_checker_policy_body IS NOT NULL)))), + CONSTRAINT ck_workstream_tasks_review_revision_policy_lock_required CHECK ((((status)::text = 'draft'::text) OR ((locked_review_policy_id IS NOT NULL) AND (locked_review_policy_generation IS NOT NULL) AND (locked_review_policy_hash IS NOT NULL) AND (locked_revision_policy_id IS NOT NULL) AND (locked_revision_policy_generation IS NOT NULL) AND (locked_revision_policy_hash IS NOT NULL)))), + CONSTRAINT ck_workstream_tasks_review_revision_policy_lock_shape CHECK ((((locked_review_policy_id IS NULL) AND (locked_review_policy_generation IS NULL) AND (locked_review_policy_hash IS NULL) AND (locked_revision_policy_id IS NULL) AND (locked_revision_policy_generation IS NULL) AND (locked_revision_policy_hash IS NULL)) OR ((locked_review_policy_id IS NOT NULL) AND (locked_review_policy_generation IS NOT NULL) AND (locked_review_policy_hash IS NOT NULL) AND (locked_revision_policy_id IS NOT NULL) AND (locked_revision_policy_generation IS NOT NULL) AND (locked_revision_policy_hash IS NOT NULL)))) +); +ALTER TABLE ONLY public.actor_profile_migration_state ALTER COLUMN id SET DEFAULT nextval('public.actor_profile_migration_state_id_seq'::regclass); +ALTER TABLE ONLY public.authority_control ALTER COLUMN id SET DEFAULT nextval('public.authority_control_id_seq'::regclass); +ALTER TABLE ONLY public.project_role_qualification_snapshots + ADD CONSTRAINT grant_reference UNIQUE (id, actor_profile_id, project_id, requested_role); +ALTER TABLE ONLY public.actor_identity_links + ADD CONSTRAINT pk_actor_identity_links PRIMARY KEY (id); +ALTER TABLE ONLY public.actor_profile_migration_state + ADD CONSTRAINT pk_actor_profile_migration_state PRIMARY KEY (id); +ALTER TABLE ONLY public.actor_profiles + ADD CONSTRAINT pk_actor_profiles PRIMARY KEY (id); +ALTER TABLE ONLY public.admin_role_grants + ADD CONSTRAINT pk_admin_role_grants PRIMARY KEY (id); +ALTER TABLE ONLY public.api_rate_control_counters + ADD CONSTRAINT pk_api_rate_control_counters PRIMARY KEY (control_scope, key_digest); +ALTER TABLE ONLY public.artifact_admission_charges + ADD CONSTRAINT pk_artifact_admission_charges PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_admission_scopes + ADD CONSTRAINT pk_artifact_admission_scopes PRIMARY KEY (scope_type, scope_id); +ALTER TABLE ONLY public.artifact_bindings + ADD CONSTRAINT pk_artifact_bindings PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_contents + ADD CONSTRAINT pk_artifact_contents PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_operation_receipts + ADD CONSTRAINT pk_artifact_operation_receipts PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_put_attempt_charges + ADD CONSTRAINT pk_artifact_put_attempt_charges PRIMARY KEY (attempt_id, charge_id); +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT pk_artifact_put_attempts PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_put_observation_receipts + ADD CONSTRAINT pk_artifact_put_observation_receipts PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT pk_artifact_recovery_attempts PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_replicas + ADD CONSTRAINT pk_artifact_replicas PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_storage_namespaces + ADD CONSTRAINT pk_artifact_storage_namespaces PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_verification_jobs + ADD CONSTRAINT pk_artifact_verification_jobs PRIMARY KEY (id); +ALTER TABLE ONLY public.artifact_verification_receipts + ADD CONSTRAINT pk_artifact_verification_receipts PRIMARY KEY (id); +ALTER TABLE ONLY public.audit_events + ADD CONSTRAINT pk_audit_events PRIMARY KEY (id); +ALTER TABLE ONLY public.authority_control + ADD CONSTRAINT pk_authority_control PRIMARY KEY (id); +ALTER TABLE ONLY public.authority_idempotency_records + ADD CONSTRAINT pk_authority_idempotency_records PRIMARY KEY (id); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT pk_checker_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.checker_results + ADD CONSTRAINT pk_checker_results PRIMARY KEY (id); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT pk_checker_runs PRIMARY KEY (id); +ALTER TABLE ONLY public.contribution_award_definitions + ADD CONSTRAINT pk_contribution_award_definitions PRIMARY KEY (id); +ALTER TABLE ONLY public.contribution_policies + ADD CONSTRAINT pk_contribution_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT pk_contribution_policy_versions PRIMARY KEY (id); +ALTER TABLE ONLY public.contribution_rules + ADD CONSTRAINT pk_contribution_rules PRIMARY KEY (id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT pk_effective_project_submission_artifact_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.evidence_items + ADD CONSTRAINT pk_evidence_items PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_mutation_idempotency_records + ADD CONSTRAINT pk_guide_mutation_idempotency_records PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT pk_guide_source_artifact_bindings PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_artifact_incidents + ADD CONSTRAINT pk_guide_source_artifact_incidents PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_artifact_ingests + ADD CONSTRAINT pk_guide_source_artifact_ingests PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_extracted_contents + ADD CONSTRAINT pk_guide_source_extracted_contents PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_extraction_attempts + ADD CONSTRAINT pk_guide_source_extraction_attempts PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_extraction_retry_budgets + ADD CONSTRAINT pk_guide_source_extraction_retry_budgets PRIMARY KEY (binding_id); +ALTER TABLE ONLY public.guide_source_extraction_usages + ADD CONSTRAINT pk_guide_source_extraction_usages PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_format_classifications + ADD CONSTRAINT pk_guide_source_format_classifications PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_snapshot_items + ADD CONSTRAINT pk_guide_source_snapshot_items PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT pk_guide_source_snapshots PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT pk_guide_sufficiency_mutation_idempotency_records PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_sufficiency_report_source_usages + ADD CONSTRAINT pk_guide_sufficiency_report_source_usages PRIMARY KEY (id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT pk_guide_sufficiency_reports PRIMARY KEY (id); +ALTER TABLE ONLY public.iso_4217_currency_codes + ADD CONSTRAINT pk_iso_4217_currency_codes PRIMARY KEY (code); +ALTER TABLE ONLY public.legacy_actor_identities + ADD CONSTRAINT pk_legacy_actor_identities PRIMARY KEY (actor_id); +ALTER TABLE ONLY public.legacy_workflow_eligibility + ADD CONSTRAINT pk_legacy_workflow_eligibility PRIMARY KEY (id); +ALTER TABLE ONLY public.outbox_events + ADD CONSTRAINT pk_outbox_events PRIMARY KEY (event_id); +ALTER TABLE ONLY public.payment_policies + ADD CONSTRAINT pk_payment_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.policy_mutation_idempotency_records + ADD CONSTRAINT pk_policy_mutation_idempotency_records PRIMARY KEY (id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT pk_pre_submit_checker_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.pre_submit_evidence_results + ADD CONSTRAINT pk_pre_submit_evidence_results PRIMARY KEY (id); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT pk_pre_submit_evidence_sets PRIMARY KEY (id); +ALTER TABLE ONLY public.project_compensation_adapter_bindings + ADD CONSTRAINT pk_project_compensation_adapter_bindings PRIMARY KEY (id); +ALTER TABLE ONLY public.project_compensation_units + ADD CONSTRAINT pk_project_compensation_units PRIMARY KEY (project_id, instrument_type, unit_code); +ALTER TABLE ONLY public.project_create_idempotency_records + ADD CONSTRAINT pk_project_create_idempotency_records PRIMARY KEY (id); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT pk_project_guide_compilation_attempts PRIMARY KEY (id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT pk_project_guide_compilations PRIMARY KEY (id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT pk_project_guides PRIMARY KEY (id); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT pk_project_role_grants PRIMARY KEY (id); +ALTER TABLE ONLY public.project_role_qualification_snapshots + ADD CONSTRAINT pk_project_role_qualification_snapshots PRIMARY KEY (id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT pk_project_setup_runs PRIMARY KEY (id); +ALTER TABLE ONLY public.projects + ADD CONSTRAINT pk_projects PRIMARY KEY (id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT pk_review_admission_idempotency_records PRIMARY KEY (id); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT pk_review_leases PRIMARY KEY (id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT pk_review_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT pk_review_queue_entries PRIMARY KEY (id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT pk_revision_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT pk_submission_artifact_policies PRIMARY KEY (id); +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT pk_submission_bundle_admissions PRIMARY KEY (id); +ALTER TABLE ONLY public.submission_bundle_durable_intents + ADD CONSTRAINT pk_submission_bundle_durable_intents PRIMARY KEY (id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT pk_submission_policy_mutation_idempotency_records PRIMARY KEY (id); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT pk_submissions PRIMARY KEY (id); +ALTER TABLE ONLY public.task_assignments + ADD CONSTRAINT pk_task_assignments PRIMARY KEY (id); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT pk_workstream_tasks PRIMARY KEY (id); +ALTER TABLE ONLY public.actor_profiles + ADD CONSTRAINT service_identity UNIQUE (service_identity); +ALTER TABLE ONLY public.actor_identity_links + ADD CONSTRAINT uq_actor_identity_links_actor_profile UNIQUE (actor_profile_id); +ALTER TABLE ONLY public.actor_identity_links + ADD CONSTRAINT uq_actor_identity_links_external_identity UNIQUE (issuer, subject); +ALTER TABLE ONLY public.actor_identity_links + ADD CONSTRAINT uq_actor_identity_links_id_profile UNIQUE (id, actor_profile_id); +ALTER TABLE ONLY public.artifact_admission_charges + ADD CONSTRAINT uq_artifact_admission_charge_scope_content UNIQUE (scope_type, scope_id, sha256, byte_count); +ALTER TABLE ONLY public.artifact_bindings + ADD CONSTRAINT uq_artifact_binding_scope_version UNIQUE (project_id, resource_type, resource_id, logical_role, scope_version); +ALTER TABLE ONLY public.artifact_bindings + ADD CONSTRAINT uq_artifact_binding_supersedes UNIQUE (supersedes_binding_id); +ALTER TABLE ONLY public.artifact_contents + ADD CONSTRAINT uq_artifact_content_digest_size UNIQUE (sha256, byte_count); +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT uq_artifact_put_attempt_operation UNIQUE (operation_identity); +ALTER TABLE ONLY public.artifact_put_observation_receipts + ADD CONSTRAINT uq_artifact_put_observation_fence UNIQUE (put_attempt_id, execution_generation); +ALTER TABLE ONLY public.artifact_operation_receipts + ADD CONSTRAINT uq_artifact_receipt_put_attempt UNIQUE (put_attempt_id); +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT uq_artifact_recovery_idempotency UNIQUE (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key); +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT uq_artifact_recovery_retry_job UNIQUE (retry_verification_job_id); +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT uq_artifact_recovery_source_job UNIQUE (source_verification_job_id); +ALTER TABLE ONLY public.artifact_replicas + ADD CONSTRAINT uq_artifact_replica_provider_object UNIQUE (storage_namespace_id, provider_object_ref); +ALTER TABLE ONLY public.artifact_replicas + ADD CONSTRAINT uq_artifact_replicas_id_content UNIQUE (id, content_id); +ALTER TABLE ONLY public.artifact_storage_namespaces + ADD CONSTRAINT uq_artifact_storage_namespace_fingerprint UNIQUE (namespace_fingerprint); +ALTER TABLE ONLY public.artifact_storage_namespaces + ADD CONSTRAINT uq_artifact_storage_namespace_id_fingerprint UNIQUE (id, namespace_fingerprint); +ALTER TABLE ONLY public.artifact_verification_receipts + ADD CONSTRAINT uq_artifact_verification_fence UNIQUE (verification_job_id, execution_generation); +ALTER TABLE ONLY public.artifact_verification_jobs + ADD CONSTRAINT uq_artifact_verification_parent UNIQUE (parent_verification_job_id); +ALTER TABLE ONLY public.authority_idempotency_records + ADD CONSTRAINT uq_authority_idempotency_records_actor_reference UNIQUE (id, actor_ref_kind, actor_ref); +ALTER TABLE ONLY public.authority_idempotency_records + ADD CONSTRAINT uq_authority_idempotency_records_replay_namespace UNIQUE (actor_ref_kind, actor_ref, operation, idempotency_key); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT uq_checker_policies_id_version_hash UNIQUE (id, guide_version, policy_hash); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT uq_checker_runs_submission_attempt UNIQUE (submission_id, attempt_number); +ALTER TABLE ONLY public.project_compensation_adapter_bindings + ADD CONSTRAINT uq_compensation_binding_ownership UNIQUE (id, project_id, instrument_type); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT uq_compilation_attempt_provider_key UNIQUE (provider_idempotency_key); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT uq_compilation_attempt_setup_generation UNIQUE (setup_run_id, setup_generation); +ALTER TABLE ONLY public.contribution_award_definitions + ADD CONSTRAINT uq_contribution_award_definition_instrument UNIQUE (contribution_rule_id, instrument_type); +ALTER TABLE ONLY public.contribution_policies + ADD CONSTRAINT uq_contribution_policy_ownership UNIQUE (id, project_id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT uq_contribution_policy_version_number UNIQUE (contribution_policy_id, version_number); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT uq_contribution_policy_version_ownership UNIQUE (id, contribution_policy_id, project_id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT uq_contribution_policy_version_project UNIQUE (id, project_id); +ALTER TABLE ONLY public.contribution_rules + ADD CONSTRAINT uq_contribution_rule_ownership UNIQUE (id, contribution_policy_version_id, project_id, contribution_type); +ALTER TABLE ONLY public.contribution_rules + ADD CONSTRAINT uq_contribution_rule_type UNIQUE (contribution_policy_version_id, contribution_type); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT uq_effective_project_submission_artifact_policies_id_hash UNIQUE (id, effective_policy_hash); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT uq_guide_bindings_exact_read UNIQUE (id, content_id, verified_replica_id, setup_generation); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT uq_guide_bindings_extraction_attempt_lineage UNIQUE (id, content_id, setup_generation); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT uq_guide_bindings_extraction_lineage UNIQUE (id, content_id, source_item_id, project_setup_run_id, setup_generation); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT uq_guide_bindings_item_generation UNIQUE (source_item_id, setup_generation); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT uq_guide_bindings_supersedes UNIQUE (supersedes_binding_id); +ALTER TABLE ONLY public.guide_source_format_classifications + ADD CONSTRAINT uq_guide_classifications_binding UNIQUE (binding_id); +ALTER TABLE ONLY public.guide_source_format_classifications + ADD CONSTRAINT uq_guide_classifications_extraction_lineage UNIQUE (id, binding_id, content_id, setup_generation); +ALTER TABLE ONLY public.guide_source_extracted_contents + ADD CONSTRAINT uq_guide_extracted_contents_exact_usage UNIQUE (id, content_id); +ALTER TABLE ONLY public.guide_source_extracted_contents + ADD CONSTRAINT uq_guide_extracted_contents_identity UNIQUE (content_id, detected_format, extractor_name, extractor_version, policy_version); +ALTER TABLE ONLY public.guide_source_extraction_attempts + ADD CONSTRAINT uq_guide_extraction_attempts UNIQUE (binding_id, policy_version, attempt_number); +ALTER TABLE ONLY public.guide_source_extraction_attempts + ADD CONSTRAINT uq_guide_extraction_attempts_exact_usage UNIQUE (id, binding_id, content_id, setup_generation, status); +ALTER TABLE ONLY public.guide_source_extraction_usages + ADD CONSTRAINT uq_guide_extraction_usages UNIQUE (binding_id, extracted_content_id); +ALTER TABLE ONLY public.guide_source_extraction_usages + ADD CONSTRAINT uq_guide_extraction_usages_exact_provenance UNIQUE (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation); +ALTER TABLE ONLY public.guide_mutation_idempotency_records + ADD CONSTRAINT uq_guide_mutation_operation_identity UNIQUE (operation_id); +ALTER TABLE ONLY public.guide_mutation_idempotency_records + ADD CONSTRAINT uq_guide_mutation_replay_namespace UNIQUE (actor_profile_id, action_id, idempotency_key); +ALTER TABLE ONLY public.guide_source_artifact_ingests + ADD CONSTRAINT uq_guide_source_artifact_ingests_source_item_id UNIQUE (source_item_id); +ALTER TABLE ONLY public.guide_source_snapshot_items + ADD CONSTRAINT uq_guide_source_snapshot_items_exact_lineage UNIQUE (id, source_snapshot_id); +ALTER TABLE ONLY public.guide_source_snapshot_items + ADD CONSTRAINT uq_guide_source_snapshot_items_snapshot_order UNIQUE (source_snapshot_id, item_order); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT uq_guide_source_snapshots_exact_lineage UNIQUE (id, project_id, guide_id); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT uq_guide_source_snapshots_id_hash UNIQUE (id, bundle_hash); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT uq_guide_source_snapshots_project_version_hash UNIQUE (project_id, guide_version, bundle_hash); +ALTER TABLE ONLY public.legacy_actor_identities + ADD CONSTRAINT uq_legacy_actor_identities_external_identity UNIQUE (external_issuer, external_subject); +ALTER TABLE ONLY public.legacy_workflow_eligibility + ADD CONSTRAINT uq_legacy_workflow_eligibility_actor_type_scope UNIQUE (actor_id, profile_type, scope_type, scope_id); +ALTER TABLE ONLY public.outbox_events + ADD CONSTRAINT uq_outbox_events_idempotency_key UNIQUE (idempotency_key); +ALTER TABLE ONLY public.payment_policies + ADD CONSTRAINT uq_payment_policies_project_version UNIQUE (project_id, guide_version); +ALTER TABLE ONLY public.policy_mutation_idempotency_records + ADD CONSTRAINT uq_policy_mutation_operation_identity UNIQUE (operation_id); +ALTER TABLE ONLY public.policy_mutation_idempotency_records + ADD CONSTRAINT uq_policy_mutation_replay_namespace UNIQUE (actor_profile_id, action_id, idempotency_key); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT uq_pre_submit_checker_policies_id_compiled_bundle_hash UNIQUE (id, compiled_bundle_hash); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT uq_pre_submit_evidence_operation UNIQUE (operation_identity); +ALTER TABLE ONLY public.pre_submit_evidence_results + ADD CONSTRAINT uq_pre_submit_result_definition UNIQUE (evidence_set_id, definition_id); +ALTER TABLE ONLY public.pre_submit_evidence_results + ADD CONSTRAINT uq_pre_submit_result_order UNIQUE (evidence_set_id, result_order); +ALTER TABLE ONLY public.project_create_idempotency_records + ADD CONSTRAINT uq_project_create_operation_identity UNIQUE (operation_id); +ALTER TABLE ONLY public.project_create_idempotency_records + ADD CONSTRAINT uq_project_create_project_identity UNIQUE (project_id); +ALTER TABLE ONLY public.project_create_idempotency_records + ADD CONSTRAINT uq_project_create_replay_namespace UNIQUE (actor_profile_id, action_id, idempotency_key); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT uq_project_guide_compilation_attempt UNIQUE (attempt_id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT uq_project_guide_compilation_id_attempt UNIQUE (id, attempt_id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT uq_project_guide_compilation_predecessor UNIQUE (supersedes_compilation_id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT uq_project_guide_compilation_scope UNIQUE (id, project_id, guide_id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT uq_project_guides_id_project_version UNIQUE (id, project_id, version); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT uq_project_guides_project_version UNIQUE (project_id, version); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT uq_project_setup_runs_exact_generation UNIQUE (id, project_id, guide_id, source_snapshot_id, setup_generation); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT uq_project_setup_runs_guide_generation UNIQUE (guide_id, setup_generation); +ALTER TABLE ONLY public.projects + ADD CONSTRAINT uq_projects_slug UNIQUE (slug); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT uq_review_admission_checker_run UNIQUE (admitting_checker_run_id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT uq_review_admission_operation UNIQUE (operation_id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT uq_review_admission_replay_key UNIQUE (idempotency_key); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT uq_review_lease_attempt UNIQUE (review_queue_entry_id, attempt_generation); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT uq_review_lease_queue_identity UNIQUE (review_queue_entry_id, id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT uq_review_policies_project_version_generation UNIQUE (project_id, guide_version, policy_generation); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT uq_review_policy_lineage UNIQUE (id, policy_generation, policy_hash); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT uq_review_policy_scoped_lineage UNIQUE (project_id, guide_version, id, policy_generation, policy_hash); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT uq_review_queue_admission_identity UNIQUE (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT uq_review_queue_lease_lineage UNIQUE (id, project_id, task_id, submission_id, submission_version); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT uq_review_queue_submission UNIQUE (submission_id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT uq_revision_policies_project_version_generation UNIQUE (project_id, guide_version, policy_generation); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT uq_revision_policy_lineage UNIQUE (id, policy_generation, policy_hash); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT uq_revision_policy_scoped_lineage UNIQUE (project_id, guide_version, id, policy_generation, policy_hash); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT uq_submission_artifact_policies_id_hash UNIQUE (id, policy_hash); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT uq_submission_artifact_policies_project_version_policy UNIQUE (project_id, guide_version, policy_version); +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT uq_submission_bundle_admission_evidence UNIQUE (pre_submit_evidence_set_id); +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT uq_submission_bundle_admission_intent UNIQUE (durable_intent_id); +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT uq_submission_bundle_admission_verification UNIQUE (verification_receipt_id); +ALTER TABLE ONLY public.submission_bundle_durable_intents + ADD CONSTRAINT uq_submission_bundle_intent_evidence UNIQUE (pre_submit_evidence_set_id); +ALTER TABLE ONLY public.submission_bundle_durable_intents + ADD CONSTRAINT uq_submission_bundle_intent_put_attempt UNIQUE (put_attempt_id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT uq_submission_policy_operation_identity UNIQUE (operation_id); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT uq_submissions_id_locked_post_submit_policy_hash UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT uq_submissions_id_task_version UNIQUE (id, task_id, version); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT uq_submissions_id_version UNIQUE (id, version); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT uq_submissions_task_version UNIQUE (task_id, version); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT uq_sufficiency_mutation_operation_identity UNIQUE (operation_id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT uq_sufficiency_mutation_replay_namespace UNIQUE (actor_profile_id, idempotency_key); +ALTER TABLE ONLY public.guide_sufficiency_report_source_usages + ADD CONSTRAINT uq_sufficiency_report_extraction_usage UNIQUE (report_id, extraction_usage_id); +ALTER TABLE ONLY public.guide_sufficiency_report_source_usages + ADD CONSTRAINT uq_sufficiency_report_item_order UNIQUE (report_id, item_order); +ALTER TABLE ONLY public.task_assignments + ADD CONSTRAINT uq_task_assignments_id_task_contributor UNIQUE (id, task_id, contributor_id); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_effective_policy_hash UNIQUE (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_guide UNIQUE (id, locked_guide_version); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_payment_policy UNIQUE (id, locked_payment_policy_version); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_post_submit_policy_hash UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_pre_submit_checker_hash UNIQUE (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_review_policy UNIQUE (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_revision_policy UNIQUE (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_locked_source_snapshot_hash UNIQUE (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT uq_workstream_tasks_id_project UNIQUE (id, project_id); +CREATE INDEX ix_actor_identity_links_issuer_subject_status ON public.actor_identity_links USING btree (issuer, subject, status); +CREATE INDEX ix_actor_profiles_last_seen_at ON public.actor_profiles USING btree (last_seen_at); +CREATE INDEX ix_actor_profiles_status_actor_kind ON public.actor_profiles USING btree (status, actor_kind); +CREATE INDEX ix_admin_role_grants_effective_candidate ON public.admin_role_grants USING btree (target_actor_profile_id, status, scope_type, scope_project_id); +CREATE INDEX ix_admin_role_grants_final_access_admin ON public.admin_role_grants USING btree (role, status) WHERE (((role)::text = 'access_administrator'::text) AND ((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text)); +CREATE INDEX ix_admin_role_grants_history ON public.admin_role_grants USING btree (target_actor_profile_id, granted_at, id); +CREATE INDEX ix_api_rate_control_counters_window_expires_at ON public.api_rate_control_counters USING btree (window_expires_at); +CREATE INDEX ix_artifact_bindings_content_id ON public.artifact_bindings USING btree (content_id); +CREATE INDEX ix_artifact_bindings_project_id ON public.artifact_bindings USING btree (project_id); +CREATE INDEX ix_artifact_bindings_scope ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version DESC); +CREATE INDEX ix_artifact_bindings_supersedes_binding_id ON public.artifact_bindings USING btree (supersedes_binding_id); +CREATE INDEX ix_artifact_contents_sha256 ON public.artifact_contents USING btree (sha256); +CREATE INDEX ix_artifact_operation_receipts_put_attempt_id ON public.artifact_operation_receipts USING btree (put_attempt_id); +CREATE INDEX ix_artifact_operation_receipts_replica_id ON public.artifact_operation_receipts USING btree (replica_id); +CREATE INDEX ix_artifact_put_attempts_checker_run_id ON public.artifact_put_attempts USING btree (checker_run_id); +CREATE INDEX ix_artifact_put_attempts_guide_source_item_id ON public.artifact_put_attempts USING btree (guide_source_item_id); +CREATE INDEX ix_artifact_put_attempts_next_run_at ON public.artifact_put_attempts USING btree (next_run_at); +CREATE INDEX ix_artifact_put_attempts_project_id ON public.artifact_put_attempts USING btree (project_id); +CREATE INDEX ix_artifact_put_attempts_receipt_id ON public.artifact_put_attempts USING btree (receipt_id); +CREATE INDEX ix_artifact_put_attempts_replica_id ON public.artifact_put_attempts USING btree (replica_id); +CREATE INDEX ix_artifact_put_attempts_status ON public.artifact_put_attempts USING btree (status); +CREATE INDEX ix_artifact_put_attempts_task_id ON public.artifact_put_attempts USING btree (task_id); +CREATE INDEX ix_artifact_put_observation_receipts_put_attempt_id ON public.artifact_put_observation_receipts USING btree (put_attempt_id); +CREATE INDEX ix_artifact_recovery_attempts_parent_recovery_attempt_id ON public.artifact_recovery_attempts USING btree (parent_recovery_attempt_id); +CREATE INDEX ix_artifact_recovery_attempts_project_id ON public.artifact_recovery_attempts USING btree (project_id); +CREATE INDEX ix_artifact_recovery_attempts_requester_actor_profile_id ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id); +CREATE INDEX ix_artifact_recovery_attempts_submission_id ON public.artifact_recovery_attempts USING btree (submission_id); +CREATE INDEX ix_artifact_recovery_attempts_task_id ON public.artifact_recovery_attempts USING btree (task_id); +CREATE INDEX ix_artifact_replicas_content_id ON public.artifact_replicas USING btree (content_id); +CREATE INDEX ix_artifact_replicas_storage_namespace_id ON public.artifact_replicas USING btree (storage_namespace_id); +CREATE INDEX ix_artifact_verification_jobs_next_run_at ON public.artifact_verification_jobs USING btree (next_run_at); +CREATE INDEX ix_artifact_verification_jobs_originating_put_attempt_id ON public.artifact_verification_jobs USING btree (originating_put_attempt_id); +CREATE INDEX ix_artifact_verification_jobs_parent_verification_job_id ON public.artifact_verification_jobs USING btree (parent_verification_job_id); +CREATE INDEX ix_artifact_verification_jobs_replica_id ON public.artifact_verification_jobs USING btree (replica_id); +CREATE INDEX ix_artifact_verification_jobs_status ON public.artifact_verification_jobs USING btree (status); +CREATE INDEX ix_artifact_verification_receipts_verification_job_id ON public.artifact_verification_receipts USING btree (verification_job_id); +CREATE INDEX ix_audit_events_actor_id ON public.audit_events USING btree (actor_id); +CREATE INDEX ix_audit_events_actor_ref ON public.audit_events USING btree (actor_ref_kind, actor_id); +CREATE INDEX ix_audit_events_correlation_id ON public.audit_events USING btree (correlation_id); +CREATE INDEX ix_audit_events_entity_id ON public.audit_events USING btree (entity_id); +CREATE INDEX ix_audit_events_entity_type ON public.audit_events USING btree (entity_type); +CREATE INDEX ix_audit_events_event_type ON public.audit_events USING btree (event_type); +CREATE INDEX ix_audit_events_occurred_at ON public.audit_events USING btree (occurred_at); +CREATE INDEX ix_audit_events_project_id ON public.audit_events USING btree (project_id); +CREATE INDEX ix_audit_events_request_id ON public.audit_events USING btree (request_id); +CREATE INDEX ix_checker_policies_effective_policy_hash ON public.checker_policies USING btree (effective_policy_hash); +CREATE INDEX ix_checker_policies_effective_policy_id ON public.checker_policies USING btree (effective_policy_id); +CREATE INDEX ix_checker_policies_guide_id ON public.checker_policies USING btree (guide_id); +CREATE INDEX ix_checker_policies_pre_submit_checker_bundle_hash ON public.checker_policies USING btree (pre_submit_checker_bundle_hash); +CREATE INDEX ix_checker_policies_pre_submit_checker_policy_id ON public.checker_policies USING btree (pre_submit_checker_policy_id); +CREATE INDEX ix_checker_policies_project_id ON public.checker_policies USING btree (project_id); +CREATE INDEX ix_checker_policies_source_snapshot_id ON public.checker_policies USING btree (source_snapshot_id); +CREATE INDEX ix_checker_policies_supersedes_policy_id ON public.checker_policies USING btree (supersedes_policy_id); +CREATE INDEX ix_checker_results_checker_name ON public.checker_results USING btree (checker_name); +CREATE INDEX ix_checker_results_checker_run_id ON public.checker_results USING btree (checker_run_id); +CREATE INDEX ix_checker_results_submission_id ON public.checker_results USING btree (submission_id); +CREATE INDEX ix_checker_results_task_id ON public.checker_results USING btree (task_id); +CREATE INDEX ix_checker_results_worker_visible ON public.checker_results USING btree (worker_visible); +CREATE INDEX ix_checker_runs_audit_event_id ON public.checker_runs USING btree (audit_event_id); +CREATE INDEX ix_checker_runs_locked_post_submit_policy_hash ON public.checker_runs USING btree (locked_post_submit_checker_policy_hash); +CREATE INDEX ix_checker_runs_routing_recommendation ON public.checker_runs USING btree (routing_recommendation); +CREATE INDEX ix_checker_runs_status ON public.checker_runs USING btree (status); +CREATE INDEX ix_checker_runs_submission_id ON public.checker_runs USING btree (submission_id); +CREATE INDEX ix_checker_runs_supersedes_checker_run_id ON public.checker_runs USING btree (supersedes_checker_run_id); +CREATE INDEX ix_checker_runs_task_id ON public.checker_runs USING btree (task_id); +CREATE INDEX ix_compensation_binding_adapter_actor ON public.project_compensation_adapter_bindings USING btree (adapter_actor_id, status, id); +CREATE INDEX ix_effective_psap_effective_hash ON public.effective_project_submission_artifact_policies USING btree (effective_policy_hash); +CREATE INDEX ix_effective_psap_guide ON public.effective_project_submission_artifact_policies USING btree (guide_id); +CREATE INDEX ix_effective_psap_lifecycle ON public.effective_project_submission_artifact_policies USING btree (lifecycle_status); +CREATE INDEX ix_effective_psap_project ON public.effective_project_submission_artifact_policies USING btree (project_id); +CREATE INDEX ix_effective_psap_source_snapshot ON public.effective_project_submission_artifact_policies USING btree (source_snapshot_id); +CREATE INDEX ix_effective_psap_submission_policy ON public.effective_project_submission_artifact_policies USING btree (submission_artifact_policy_id); +CREATE INDEX ix_evidence_items_submission_id ON public.evidence_items USING btree (submission_id); +CREATE INDEX ix_evidence_items_type ON public.evidence_items USING btree (type); +CREATE INDEX ix_guide_source_artifact_bindings_content_id ON public.guide_source_artifact_bindings USING btree (content_id); +CREATE INDEX ix_guide_source_artifact_bindings_guide_id ON public.guide_source_artifact_bindings USING btree (guide_id); +CREATE INDEX ix_guide_source_artifact_bindings_project_id ON public.guide_source_artifact_bindings USING btree (project_id); +CREATE INDEX ix_guide_source_artifact_bindings_project_setup_run_id ON public.guide_source_artifact_bindings USING btree (project_setup_run_id); +CREATE INDEX ix_guide_source_artifact_bindings_source_item_id ON public.guide_source_artifact_bindings USING btree (source_item_id); +CREATE INDEX ix_guide_source_artifact_bindings_source_snapshot_id ON public.guide_source_artifact_bindings USING btree (source_snapshot_id); +CREATE INDEX ix_guide_source_artifact_bindings_supersedes_binding_id ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id); +CREATE INDEX ix_guide_source_artifact_bindings_verified_replica_id ON public.guide_source_artifact_bindings USING btree (verified_replica_id); +CREATE INDEX ix_guide_source_artifact_incidents_binding_id ON public.guide_source_artifact_incidents USING btree (binding_id); +CREATE INDEX ix_guide_source_artifact_incidents_content_id ON public.guide_source_artifact_incidents USING btree (content_id); +CREATE INDEX ix_guide_source_artifact_incidents_verified_replica_id ON public.guide_source_artifact_incidents USING btree (verified_replica_id); +CREATE INDEX ix_guide_source_artifact_ingests_actor_profile_id ON public.guide_source_artifact_ingests USING btree (actor_profile_id); +CREATE UNIQUE INDEX ix_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id); +CREATE INDEX ix_guide_source_extracted_contents_content_id ON public.guide_source_extracted_contents USING btree (content_id); +CREATE INDEX ix_guide_source_extraction_attempts_binding_id ON public.guide_source_extraction_attempts USING btree (binding_id); +CREATE INDEX ix_guide_source_extraction_attempts_content_id ON public.guide_source_extraction_attempts USING btree (content_id); +CREATE INDEX ix_guide_source_extraction_usages_binding_id ON public.guide_source_extraction_usages USING btree (binding_id); +CREATE INDEX ix_guide_source_extraction_usages_content_id ON public.guide_source_extraction_usages USING btree (content_id); +CREATE INDEX ix_guide_source_extraction_usages_extracted_content_id ON public.guide_source_extraction_usages USING btree (extracted_content_id); +CREATE INDEX ix_guide_source_extraction_usages_project_setup_run_id ON public.guide_source_extraction_usages USING btree (project_setup_run_id); +CREATE INDEX ix_guide_source_extraction_usages_source_item_id ON public.guide_source_extraction_usages USING btree (source_item_id); +CREATE INDEX ix_guide_source_format_classifications_binding_id ON public.guide_source_format_classifications USING btree (binding_id); +CREATE INDEX ix_guide_source_format_classifications_content_id ON public.guide_source_format_classifications USING btree (content_id); +CREATE INDEX ix_guide_source_format_classifications_verified_replica_id ON public.guide_source_format_classifications USING btree (verified_replica_id); +CREATE INDEX ix_guide_source_snapshot_items_source_snapshot_id ON public.guide_source_snapshot_items USING btree (source_snapshot_id); +CREATE INDEX ix_guide_source_snapshots_bundle_hash ON public.guide_source_snapshots USING btree (bundle_hash); +CREATE INDEX ix_guide_source_snapshots_guide_id ON public.guide_source_snapshots USING btree (guide_id); +CREATE INDEX ix_guide_source_snapshots_project_id ON public.guide_source_snapshots USING btree (project_id); +CREATE INDEX ix_guide_sufficiency_reports_guide_id ON public.guide_sufficiency_reports USING btree (guide_id); +CREATE INDEX ix_guide_sufficiency_reports_project_id ON public.guide_sufficiency_reports USING btree (project_id); +CREATE INDEX ix_guide_sufficiency_reports_project_setup_run_id ON public.guide_sufficiency_reports USING btree (project_setup_run_id); +CREATE INDEX ix_guide_sufficiency_reports_source_snapshot_id ON public.guide_sufficiency_reports USING btree (source_snapshot_id); +CREATE INDEX ix_guide_sufficiency_reports_status ON public.guide_sufficiency_reports USING btree (status); +CREATE INDEX ix_legacy_workflow_eligibility_actor_id ON public.legacy_workflow_eligibility USING btree (actor_id); +CREATE INDEX ix_legacy_workflow_eligibility_profile_type ON public.legacy_workflow_eligibility USING btree (profile_type); +CREATE INDEX ix_legacy_workflow_eligibility_status ON public.legacy_workflow_eligibility USING btree (status); +CREATE INDEX ix_outbox_events_aggregate ON public.outbox_events USING btree (aggregate_type, aggregate_id, occurred_at, event_id); +CREATE INDEX ix_outbox_events_eligible ON public.outbox_events USING btree (event_type, delivery_state, next_attempt_at, occurred_at, event_id) WHERE ((delivery_state)::text = ANY ((ARRAY['pending'::character varying, 'retryable'::character varying])::text[])); +CREATE INDEX ix_outbox_events_expired_claims ON public.outbox_events USING btree (claim_expires_at, event_id) WHERE ((delivery_state)::text = 'claimed'::text); +CREATE INDEX ix_outbox_events_project_drain ON public.outbox_events USING btree (project_id, delivery_state, occurred_at, event_id); +CREATE INDEX ix_outbox_events_retention ON public.outbox_events USING btree (finalized_at, event_id) WHERE (((delivery_state)::text = ANY ((ARRAY['acknowledged'::character varying, 'dead_letter'::character varying, 'cancelled'::character varying])::text[])) AND (archived_at IS NULL)); +CREATE INDEX ix_payment_policies_project_id ON public.payment_policies USING btree (project_id); +CREATE INDEX ix_policy_mutation_custody_lookup ON public.policy_mutation_idempotency_records USING btree (policy_id, action_id, policy_generation, status); +CREATE INDEX ix_pre_submit_checker_compiled_hash ON public.pre_submit_checker_policies USING btree (compiled_bundle_hash); +CREATE INDEX ix_pre_submit_checker_effective ON public.pre_submit_checker_policies USING btree (effective_policy_id); +CREATE INDEX ix_pre_submit_checker_effective_hash ON public.pre_submit_checker_policies USING btree (effective_policy_hash); +CREATE INDEX ix_pre_submit_checker_guide ON public.pre_submit_checker_policies USING btree (guide_id); +CREATE INDEX ix_pre_submit_checker_lifecycle ON public.pre_submit_checker_policies USING btree (lifecycle_status); +CREATE INDEX ix_pre_submit_checker_project ON public.pre_submit_checker_policies USING btree (project_id); +CREATE INDEX ix_pre_submit_checker_source_snapshot ON public.pre_submit_checker_policies USING btree (source_snapshot_id); +CREATE INDEX ix_pre_submit_evidence_results_evidence_set_id ON public.pre_submit_evidence_results USING btree (evidence_set_id); +CREATE INDEX ix_pre_submit_evidence_sets_actor_profile_id ON public.pre_submit_evidence_sets USING btree (actor_profile_id); +CREATE INDEX ix_pre_submit_evidence_sets_project_id ON public.pre_submit_evidence_sets USING btree (project_id); +CREATE INDEX ix_pre_submit_evidence_sets_task_id ON public.pre_submit_evidence_sets USING btree (task_id); +CREATE INDEX ix_project_guide_compilation_attempts_guide_id ON public.project_guide_compilation_attempts USING btree (guide_id); +CREATE INDEX ix_project_guide_compilation_attempts_project_id ON public.project_guide_compilation_attempts USING btree (project_id); +CREATE INDEX ix_project_guide_compilation_attempts_setup_run_id ON public.project_guide_compilation_attempts USING btree (setup_run_id); +CREATE INDEX ix_project_guide_compilation_attempts_source_snapshot_id ON public.project_guide_compilation_attempts USING btree (source_snapshot_id); +CREATE INDEX ix_project_guide_compilations_guide_id ON public.project_guide_compilations USING btree (guide_id); +CREATE INDEX ix_project_guide_compilations_project_id ON public.project_guide_compilations USING btree (project_id); +CREATE INDEX ix_project_guide_compilations_setup_run_id ON public.project_guide_compilations USING btree (setup_run_id); +CREATE INDEX ix_project_guide_compilations_source_snapshot_id ON public.project_guide_compilations USING btree (source_snapshot_id); +CREATE INDEX ix_project_guides_project_id ON public.project_guides USING btree (project_id); +CREATE INDEX ix_project_guides_status ON public.project_guides USING btree (status); +CREATE INDEX ix_project_role_grants_actor_role_status ON public.project_role_grants USING btree (actor_profile_id, role, status); +CREATE INDEX ix_project_role_grants_project_actor_role_status ON public.project_role_grants USING btree (project_id, actor_profile_id, role, status); +CREATE INDEX ix_project_role_qualification_snapshots_history ON public.project_role_qualification_snapshots USING btree (project_id, actor_profile_id, requested_role, captured_at); +CREATE INDEX ix_project_setup_runs_celery_task_id ON public.project_setup_runs USING btree (celery_task_id); +CREATE INDEX ix_project_setup_runs_continuation_verification_job_id ON public.project_setup_runs USING btree (continuation_verification_job_id); +CREATE INDEX ix_project_setup_runs_error_artifact_incident_id ON public.project_setup_runs USING btree (error_artifact_incident_id); +CREATE INDEX ix_project_setup_runs_guide_id ON public.project_setup_runs USING btree (guide_id); +CREATE INDEX ix_project_setup_runs_output_post_submit_checker_policy_id ON public.project_setup_runs USING btree (output_post_submit_checker_policy_id); +CREATE INDEX ix_project_setup_runs_output_submission_artifact_policy_id ON public.project_setup_runs USING btree (output_submission_artifact_policy_id); +CREATE INDEX ix_project_setup_runs_output_sufficiency_report_id ON public.project_setup_runs USING btree (output_sufficiency_report_id); +CREATE INDEX ix_project_setup_runs_project_id ON public.project_setup_runs USING btree (project_id); +CREATE INDEX ix_project_setup_runs_source_snapshot_id ON public.project_setup_runs USING btree (source_snapshot_id); +CREATE INDEX ix_project_setup_runs_status ON public.project_setup_runs USING btree (status); +CREATE INDEX ix_projects_slug ON public.projects USING btree (slug); +CREATE INDEX ix_projects_status ON public.projects USING btree (status); +CREATE INDEX ix_review_admission_submission ON public.review_admission_idempotency_records USING btree (submission_id, status, created_at, id); +CREATE INDEX ix_review_lease_expiry ON public.review_leases USING btree (status, expires_at, id); +CREATE INDEX ix_review_policies_project_id ON public.review_policies USING btree (project_id); +CREATE INDEX ix_review_queue_preference ON public.review_queue_entries USING btree (preferred_reviewer_id, queue_state, preference_expires_at, id); +CREATE INDEX ix_review_queue_selection ON public.review_queue_entries USING btree (project_id, queue_state, routing_mode, first_queued_at, id); +CREATE INDEX ix_revision_policies_project_id ON public.revision_policies USING btree (project_id); +CREATE INDEX ix_submission_artifact_policies_guide_id ON public.submission_artifact_policies USING btree (guide_id); +CREATE INDEX ix_submission_artifact_policies_lifecycle_status ON public.submission_artifact_policies USING btree (lifecycle_status); +CREATE INDEX ix_submission_artifact_policies_policy_hash ON public.submission_artifact_policies USING btree (policy_hash); +CREATE INDEX ix_submission_artifact_policies_project_id ON public.submission_artifact_policies USING btree (project_id); +CREATE INDEX ix_submission_artifact_policies_source_snapshot_id ON public.submission_artifact_policies USING btree (source_snapshot_id); +CREATE INDEX ix_submission_bundle_admissions_actor_profile_id ON public.submission_bundle_admissions USING btree (actor_profile_id); +CREATE INDEX ix_submission_bundle_admissions_artifact_content_id ON public.submission_bundle_admissions USING btree (artifact_content_id); +CREATE INDEX ix_submission_bundle_admissions_pre_submit_evidence_set_id ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id); +CREATE INDEX ix_submission_bundle_admissions_project_id ON public.submission_bundle_admissions USING btree (project_id); +CREATE INDEX ix_submission_bundle_admissions_status ON public.submission_bundle_admissions USING btree (status); +CREATE INDEX ix_submission_bundle_admissions_task_id ON public.submission_bundle_admissions USING btree (task_id); +CREATE INDEX ix_submission_bundle_durable_intents_pre_submit_evidence_set_id ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id); +CREATE INDEX ix_submission_bundle_durable_intents_put_attempt_id ON public.submission_bundle_durable_intents USING btree (put_attempt_id); +CREATE INDEX ix_submissions_contributor_id ON public.submissions USING btree (contributor_id); +CREATE INDEX ix_submissions_locked_effective_policy_hash ON public.submissions USING btree (locked_effective_project_submission_artifact_policy_hash); +CREATE INDEX ix_submissions_locked_post_submit_policy_hash ON public.submissions USING btree (locked_post_submit_checker_policy_hash); +CREATE INDEX ix_submissions_locked_pre_submit_checker_hash ON public.submissions USING btree (locked_pre_submit_checker_bundle_hash); +CREATE INDEX ix_submissions_locked_source_snapshot ON public.submissions USING btree (locked_guide_source_snapshot_id); +CREATE INDEX ix_submissions_status ON public.submissions USING btree (status); +CREATE INDEX ix_submissions_supersedes_submission_id ON public.submissions USING btree (supersedes_submission_id); +CREATE INDEX ix_submissions_task_id ON public.submissions USING btree (task_id); +CREATE INDEX ix_sufficiency_report_source_usage_report_id ON public.guide_sufficiency_report_source_usages USING btree (report_id); +CREATE INDEX ix_task_assignments_contributor_id ON public.task_assignments USING btree (contributor_id); +CREATE INDEX ix_task_assignments_status ON public.task_assignments USING btree (status); +CREATE INDEX ix_task_assignments_task_id ON public.task_assignments USING btree (task_id); +CREATE INDEX ix_workstream_tasks_assigned_to ON public.workstream_tasks USING btree (assigned_to); +CREATE INDEX ix_workstream_tasks_locked_effective_policy_hash ON public.workstream_tasks USING btree (locked_effective_project_submission_artifact_policy_hash); +CREATE INDEX ix_workstream_tasks_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (locked_post_submit_checker_policy_hash); +CREATE INDEX ix_workstream_tasks_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (locked_pre_submit_checker_bundle_hash); +CREATE INDEX ix_workstream_tasks_locked_source_snapshot ON public.workstream_tasks USING btree (locked_guide_source_snapshot_id); +CREATE INDEX ix_workstream_tasks_project_id ON public.workstream_tasks USING btree (project_id); +CREATE INDEX ix_workstream_tasks_status ON public.workstream_tasks USING btree (status); +CREATE UNIQUE INDEX uq_admin_role_grants_active_project ON public.admin_role_grants USING btree (target_actor_profile_id, role, scope_project_id) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'project'::text)); +CREATE UNIQUE INDEX uq_admin_role_grants_active_system ON public.admin_role_grants USING btree (target_actor_profile_id, role) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text)); +CREATE UNIQUE INDEX uq_artifact_verification_initial_origin ON public.artifact_verification_jobs USING btree (originating_put_attempt_id) WHERE (parent_verification_job_id IS NULL); +CREATE UNIQUE INDEX uq_checker_policies_current_project_version ON public.checker_policies USING btree (project_id, guide_version) WHERE ((lifecycle_status)::text = ANY ((ARRAY['compiled'::character varying, 'approved'::character varying])::text[])); +CREATE UNIQUE INDEX uq_checker_runs_current_per_submission ON public.checker_runs USING btree (submission_id) WHERE (is_current_for_submission = true); +CREATE UNIQUE INDEX uq_compensation_binding_active_project_instrument ON public.project_compensation_adapter_bindings USING btree (project_id, instrument_type) WHERE ((status)::text = 'active'::text); +CREATE UNIQUE INDEX uq_contribution_policy_active_project ON public.contribution_policies USING btree (project_id) WHERE ((status)::text = 'active'::text); +CREATE UNIQUE INDEX uq_guide_sufficiency_reports_diagnostic_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NULL); +CREATE UNIQUE INDEX uq_guide_sufficiency_reports_verified_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NOT NULL); +CREATE UNIQUE INDEX uq_project_guide_compilation_root ON public.project_guide_compilations USING btree (project_id, guide_id) WHERE (supersedes_compilation_id IS NULL); +CREATE UNIQUE INDEX uq_project_guides_one_active_per_project ON public.project_guides USING btree (project_id) WHERE ((status)::text = 'active'::text); +CREATE UNIQUE INDEX uq_project_role_grants_active_exact_role ON public.project_role_grants USING btree (project_id, actor_profile_id, role) WHERE ((status)::text = 'active'::text); +CREATE UNIQUE INDEX uq_review_lease_active_queue ON public.review_leases USING btree (review_queue_entry_id) WHERE ((status)::text = 'active'::text); +CREATE UNIQUE INDEX uq_review_lease_active_reviewer ON public.review_leases USING btree (reviewer_id) WHERE ((status)::text = 'active'::text); +CREATE UNIQUE INDEX uq_submission_bundle_admission_consumer ON public.submission_bundle_admissions USING btree (consumed_by_submission_id) WHERE (consumed_by_submission_id IS NOT NULL); +CREATE UNIQUE INDEX uq_submission_policy_committed_policy_action ON public.submission_policy_mutation_idempotency_records USING btree (committed_policy_id, action_id) WHERE ((status)::text = 'committed'::text); +CREATE UNIQUE INDEX uq_submission_policy_human_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key) WHERE (service_identity IS NULL); +CREATE UNIQUE INDEX uq_submission_policy_service_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, setup_run_id, setup_generation, setup_task_id, correlation_id, action_id) WHERE (service_identity IS NOT NULL); +CREATE UNIQUE INDEX uq_task_assignments_one_active_per_task ON public.task_assignments USING btree (task_id) WHERE ((status)::text = 'active'::text); +CREATE TRIGGER actor_identity_link_history_guard BEFORE DELETE OR UPDATE ON public.actor_identity_links FOR EACH ROW EXECUTE FUNCTION public.guard_actor_identity_link_history(); +CREATE CONSTRAINT TRIGGER actor_identity_link_profile_guard AFTER INSERT OR UPDATE ON public.actor_identity_links DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_canonical_actor_link(); +CREATE TRIGGER actor_profile_history_guard BEFORE DELETE OR UPDATE ON public.actor_profiles FOR EACH ROW EXECUTE FUNCTION public.guard_actor_profile_history(); +CREATE CONSTRAINT TRIGGER actor_profile_link_guard AFTER INSERT OR UPDATE ON public.actor_profiles DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_canonical_actor_link(); +CREATE CONSTRAINT TRIGGER admin_role_grants_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON public.admin_role_grants DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_bootstrap_authority_state(); +CREATE TRIGGER admin_role_grants_guard BEFORE INSERT OR DELETE OR UPDATE ON public.admin_role_grants FOR EACH ROW EXECUTE FUNCTION public.guard_admin_role_grant(); +CREATE TRIGGER admin_role_grants_reject_truncate BEFORE TRUNCATE ON public.admin_role_grants FOR EACH STATEMENT EXECUTE FUNCTION public.reject_admin_role_grant_truncate(); +CREATE TRIGGER artifact_receipt_producer_reference BEFORE INSERT OR UPDATE OF put_attempt_id, guide_source_item_id, checker_run_id, logical_role ON public.artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION public.guard_artifact_receipt_producer_reference(); +CREATE TRIGGER artifact_recovery_attempt_custody BEFORE INSERT OR DELETE OR UPDATE ON public.artifact_recovery_attempts FOR EACH ROW EXECUTE FUNCTION public.validate_artifact_recovery_attempt(); +CREATE TRIGGER artifact_verification_lineage_custody BEFORE UPDATE ON public.artifact_verification_jobs FOR EACH ROW EXECUTE FUNCTION public.validate_artifact_verification_lineage(); +CREATE TRIGGER audit_events_reject_truncate BEFORE TRUNCATE ON public.audit_events FOR EACH STATEMENT EXECUTE FUNCTION public.reject_audit_event_mutation(); +CREATE TRIGGER audit_events_reject_update_delete BEFORE DELETE OR UPDATE ON public.audit_events FOR EACH ROW EXECUTE FUNCTION public.reject_audit_event_mutation(); +CREATE TRIGGER audit_events_set_authority_time BEFORE INSERT ON public.audit_events FOR EACH ROW EXECUTE FUNCTION public.set_authority_audit_database_time(); +CREATE TRIGGER audit_events_validate_idempotency BEFORE INSERT ON public.audit_events FOR EACH ROW EXECUTE FUNCTION public.validate_linked_authority_event(); +CREATE CONSTRAINT TRIGGER authority_control_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON public.authority_control DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_bootstrap_authority_state(); +CREATE TRIGGER authority_control_guard BEFORE INSERT OR DELETE OR UPDATE ON public.authority_control FOR EACH ROW EXECUTE FUNCTION public.guard_authority_control(); +CREATE TRIGGER authority_control_reject_truncate BEFORE TRUNCATE ON public.authority_control FOR EACH STATEMENT EXECUTE FUNCTION public.reject_authority_control_truncate(); +CREATE TRIGGER authority_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON public.authority_idempotency_records FOR EACH ROW EXECUTE FUNCTION public.guard_authority_idempotency_record(); +CREATE CONSTRAINT TRIGGER authority_idempotency_pending_guard AFTER INSERT OR UPDATE ON public.authority_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.reject_pending_authority_idempotency(); +CREATE TRIGGER authority_idempotency_reject_truncate BEFORE TRUNCATE ON public.authority_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION public.reject_authority_idempotency_truncate(); +CREATE TRIGGER contribution_award_definitions_content_guard BEFORE INSERT OR DELETE OR UPDATE ON public.contribution_award_definitions FOR EACH ROW EXECUTE FUNCTION public.guard_contribution_policy_children(); +CREATE CONSTRAINT TRIGGER contribution_award_definitions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON public.contribution_award_definitions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_contribution_policy_graph(); +CREATE TRIGGER contribution_award_definitions_reject_truncate BEFORE TRUNCATE ON public.contribution_award_definitions FOR EACH STATEMENT EXECUTE FUNCTION public.reject_contribution_policy_truncate(); +CREATE CONSTRAINT TRIGGER contribution_policies_graph_guard AFTER INSERT OR DELETE OR UPDATE ON public.contribution_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_contribution_policy_graph(); +CREATE TRIGGER contribution_policies_reject_truncate BEFORE TRUNCATE ON public.contribution_policies FOR EACH STATEMENT EXECUTE FUNCTION public.reject_contribution_policy_truncate(); +CREATE TRIGGER contribution_policy_versions_content_guard BEFORE DELETE OR UPDATE ON public.contribution_policy_versions FOR EACH ROW EXECUTE FUNCTION public.guard_contribution_policy_version_content(); +CREATE CONSTRAINT TRIGGER contribution_policy_versions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON public.contribution_policy_versions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_contribution_policy_graph(); +CREATE TRIGGER contribution_policy_versions_reject_truncate BEFORE TRUNCATE ON public.contribution_policy_versions FOR EACH STATEMENT EXECUTE FUNCTION public.reject_contribution_policy_truncate(); +CREATE TRIGGER contribution_rules_content_guard BEFORE INSERT OR DELETE OR UPDATE ON public.contribution_rules FOR EACH ROW EXECUTE FUNCTION public.guard_contribution_policy_children(); +CREATE CONSTRAINT TRIGGER contribution_rules_graph_guard AFTER INSERT OR DELETE OR UPDATE ON public.contribution_rules DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_contribution_policy_graph(); +CREATE TRIGGER contribution_rules_reject_truncate BEFORE TRUNCATE ON public.contribution_rules FOR EACH STATEMENT EXECUTE FUNCTION public.reject_contribution_policy_truncate(); +CREATE CONSTRAINT TRIGGER effective_submission_policy_custody AFTER INSERT OR UPDATE ON public.effective_project_submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_submission_policy_authority_custody(); +CREATE TRIGGER effective_submission_policy_provenance_immutable BEFORE UPDATE ON public.effective_project_submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION public.protect_submission_policy_output_provenance(); +CREATE TRIGGER guide_lineage_lifecycle_guard BEFORE UPDATE ON public.project_guides FOR EACH ROW EXECUTE FUNCTION public.guard_guide_lineage_and_lifecycle(); +CREATE TRIGGER guide_mutation_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON public.guide_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION public.guard_guide_mutation_idempotency(); +CREATE TRIGGER guide_mutation_idempotency_reject_truncate BEFORE TRUNCATE ON public.guide_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION public.reject_guide_mutation_idempotency_truncate(); +CREATE CONSTRAINT TRIGGER guide_mutation_product_custody AFTER INSERT OR UPDATE ON public.project_guides DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_guide_mutation_custody(); +CREATE CONSTRAINT TRIGGER guide_mutation_reservation_custody AFTER INSERT OR UPDATE ON public.guide_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_guide_mutation_custody(); +CREATE CONSTRAINT TRIGGER guide_source_snapshot_items_custody AFTER INSERT ON public.guide_source_snapshot_items DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_guide_source_snapshot_items(); +CREATE TRIGGER guide_source_snapshot_items_immutable BEFORE DELETE OR UPDATE OR TRUNCATE ON public.guide_source_snapshot_items FOR EACH STATEMENT EXECUTE FUNCTION public.reject_guide_source_snapshot_item_mutation(); +CREATE TRIGGER iso_4217_currency_codes_immutable BEFORE INSERT OR DELETE OR UPDATE ON public.iso_4217_currency_codes FOR EACH ROW EXECUTE FUNCTION public.guard_iso_4217_currency_codes(); +CREATE TRIGGER iso_4217_currency_codes_reject_truncate BEFORE TRUNCATE ON public.iso_4217_currency_codes FOR EACH STATEMENT EXECUTE FUNCTION public.reject_contribution_policy_truncate(); +CREATE TRIGGER outbox_events_custody BEFORE INSERT OR DELETE OR UPDATE ON public.outbox_events FOR EACH ROW EXECUTE FUNCTION public.guard_outbox_event(); +CREATE TRIGGER outbox_events_reject_truncate BEFORE TRUNCATE ON public.outbox_events FOR EACH STATEMENT EXECUTE FUNCTION public.guard_outbox_event(); +CREATE CONSTRAINT TRIGGER policy_mutation_replay_custody AFTER INSERT OR UPDATE ON public.policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_policy_mutation_custody(); +CREATE TRIGGER policy_mutation_replay_immutable BEFORE INSERT OR DELETE OR UPDATE ON public.policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION public.guard_policy_mutation_replay(); +CREATE TRIGGER policy_mutation_replay_reject_truncate BEFORE TRUNCATE ON public.policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION public.reject_policy_mutation_replay_truncate(); +CREATE TRIGGER pre_submit_evidence_results_immutable BEFORE DELETE OR UPDATE ON public.pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION public.guard_pre_submit_evidence_results_immutable(); +CREATE TRIGGER pre_submit_evidence_results_membership BEFORE INSERT ON public.pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION public.guard_pre_submit_evidence_result_membership(); +CREATE TRIGGER pre_submit_evidence_results_no_truncate BEFORE TRUNCATE ON public.pre_submit_evidence_results FOR EACH STATEMENT EXECUTE FUNCTION public.guard_pre_submit_evidence_results_immutable(); +CREATE TRIGGER pre_submit_evidence_sets_creation BEFORE INSERT ON public.pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION public.guard_pre_submit_evidence_set_creation(); +CREATE TRIGGER pre_submit_evidence_sets_immutable BEFORE DELETE OR UPDATE ON public.pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION public.guard_pre_submit_evidence_sets_immutable(); +CREATE TRIGGER pre_submit_evidence_sets_no_truncate BEFORE TRUNCATE ON public.pre_submit_evidence_sets FOR EACH STATEMENT EXECUTE FUNCTION public.guard_pre_submit_evidence_sets_immutable(); +CREATE CONSTRAINT TRIGGER pre_submit_policy_custody AFTER INSERT OR UPDATE ON public.pre_submit_checker_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_submission_policy_authority_custody(); +CREATE TRIGGER pre_submit_policy_provenance_immutable BEFORE UPDATE ON public.pre_submit_checker_policies FOR EACH ROW EXECUTE FUNCTION public.protect_submission_policy_output_provenance(); +CREATE TRIGGER project_compensation_binding_update_guard BEFORE UPDATE ON public.project_compensation_adapter_bindings FOR EACH ROW EXECUTE FUNCTION public.enforce_compensation_binding_lifecycle(); +CREATE TRIGGER project_compensation_units_lifecycle_guard BEFORE INSERT OR DELETE OR UPDATE ON public.project_compensation_units FOR EACH ROW EXECUTE FUNCTION public.guard_project_compensation_units(); +CREATE TRIGGER project_compensation_units_reject_truncate BEFORE TRUNCATE ON public.project_compensation_units FOR EACH STATEMENT EXECUTE FUNCTION public.reject_contribution_policy_truncate(); +CREATE TRIGGER project_create_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON public.project_create_idempotency_records FOR EACH ROW EXECUTE FUNCTION public.guard_project_create_idempotency(); +CREATE TRIGGER project_create_idempotency_reject_truncate BEFORE TRUNCATE ON public.project_create_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION public.reject_project_create_idempotency_truncate(); +CREATE CONSTRAINT TRIGGER project_create_reservation_custody AFTER INSERT OR UPDATE ON public.project_create_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_project_create_custody(); +CREATE CONSTRAINT TRIGGER project_creation_custody AFTER INSERT OR UPDATE OF created_by_actor_profile_id, created_via_identity_link_id, created_by_admin_role_grant_id, creation_scope_type, creation_action_id, authorization_decision_event_id ON public.projects DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_project_create_custody(); +CREATE TRIGGER project_guides_policy_selection_immutable BEFORE UPDATE ON public.project_guides FOR EACH ROW EXECUTE FUNCTION public.guard_project_guide_policy_selection(); +CREATE TRIGGER review_admission_idempotency_records_reject_truncate BEFORE TRUNCATE ON public.review_admission_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION public.reject_review_queue_foundation_truncate(); +CREATE TRIGGER review_admission_records_guard BEFORE INSERT OR DELETE OR UPDATE ON public.review_admission_idempotency_records FOR EACH ROW EXECUTE FUNCTION public.guard_review_admission_record(); +CREATE CONSTRAINT TRIGGER review_leases_active_lease_guard AFTER INSERT OR UPDATE ON public.review_leases DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_review_active_lease(); +CREATE TRIGGER review_leases_guard BEFORE INSERT OR DELETE OR UPDATE ON public.review_leases FOR EACH ROW EXECUTE FUNCTION public.guard_review_lease(); +CREATE TRIGGER review_leases_reject_truncate BEFORE TRUNCATE ON public.review_leases FOR EACH STATEMENT EXECUTE FUNCTION public.reject_review_lease_truncate(); +CREATE TRIGGER review_policies_immutable BEFORE DELETE OR UPDATE ON public.review_policies FOR EACH ROW EXECUTE FUNCTION public.guard_review_policies_immutable(); +CREATE TRIGGER review_policies_reject_truncate BEFORE TRUNCATE ON public.review_policies FOR EACH STATEMENT EXECUTE FUNCTION public.guard_review_policies_immutable(); +CREATE CONSTRAINT TRIGGER review_policy_mutation_custody AFTER INSERT OR UPDATE ON public.review_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_policy_mutation_custody(); +CREATE CONSTRAINT TRIGGER review_queue_entries_active_lease_guard AFTER INSERT OR UPDATE ON public.review_queue_entries DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_review_active_lease(); +CREATE TRIGGER review_queue_entries_guard BEFORE INSERT OR DELETE OR UPDATE ON public.review_queue_entries FOR EACH ROW EXECUTE FUNCTION public.guard_review_queue_entry(); +CREATE TRIGGER review_queue_entries_reject_truncate BEFORE TRUNCATE ON public.review_queue_entries FOR EACH STATEMENT EXECUTE FUNCTION public.reject_review_queue_foundation_truncate(); +CREATE TRIGGER revision_policies_immutable BEFORE DELETE OR UPDATE ON public.revision_policies FOR EACH ROW EXECUTE FUNCTION public.guard_revision_policies_immutable(); +CREATE TRIGGER revision_policies_reject_truncate BEFORE TRUNCATE ON public.revision_policies FOR EACH STATEMENT EXECUTE FUNCTION public.guard_revision_policies_immutable(); +CREATE CONSTRAINT TRIGGER revision_policy_mutation_custody AFTER INSERT OR UPDATE ON public.revision_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_policy_mutation_custody(); +CREATE TRIGGER service_identity_migration_evidence_row_guard BEFORE DELETE OR UPDATE ON public.actor_profile_migration_state FOR EACH ROW EXECUTE FUNCTION public.guard_service_identity_migration_evidence(); +CREATE TRIGGER service_identity_migration_evidence_truncate_guard BEFORE TRUNCATE ON public.actor_profile_migration_state FOR EACH STATEMENT EXECUTE FUNCTION public.guard_service_identity_migration_evidence(); +CREATE CONSTRAINT TRIGGER source_setup_run_custody AFTER INSERT OR UPDATE ON public.project_setup_runs DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_guide_mutation_custody(); +CREATE CONSTRAINT TRIGGER source_snapshot_product_custody AFTER INSERT OR UPDATE ON public.guide_source_snapshots DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_guide_mutation_custody(); +CREATE TRIGGER submission_bundle_admission_delete BEFORE DELETE OR TRUNCATE ON public.submission_bundle_admissions FOR EACH STATEMENT EXECUTE FUNCTION public.guard_submission_bundle_admission_delete(); +CREATE TRIGGER submission_bundle_admission_lineage BEFORE UPDATE ON public.submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION public.guard_submission_bundle_admission_lineage(); +CREATE TRIGGER submission_bundle_admission_verified_lineage BEFORE INSERT ON public.submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION public.guard_submission_bundle_admission_verified_lineage(); +CREATE TRIGGER submission_bundle_durable_intent_put_attempt BEFORE INSERT ON public.submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt(); +CREATE TRIGGER submission_bundle_durable_intents_immutable BEFORE DELETE OR UPDATE ON public.submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION public.guard_submission_bundle_durable_intents_immutable(); +CREATE TRIGGER submission_bundle_durable_intents_no_truncate BEFORE TRUNCATE ON public.submission_bundle_durable_intents FOR EACH STATEMENT EXECUTE FUNCTION public.guard_submission_bundle_durable_intents_immutable(); +CREATE TRIGGER submission_policy_approval_provenance_immutable BEFORE UPDATE ON public.submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION public.protect_submission_policy_approval_provenance(); +CREATE CONSTRAINT TRIGGER submission_policy_creation_custody AFTER INSERT OR UPDATE ON public.submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_submission_policy_creation_custody(); +CREATE TRIGGER submission_policy_creation_provenance_immutable BEFORE UPDATE ON public.submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION public.protect_submission_policy_creation_provenance(); +CREATE CONSTRAINT TRIGGER submission_policy_product_custody AFTER INSERT OR UPDATE ON public.submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION public.validate_submission_policy_authority_custody(); +CREATE CONSTRAINT TRIGGER submission_policy_replay_custody AFTER INSERT OR UPDATE ON public.submission_policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW WHEN (((new.status)::text = 'committed'::text)) EXECUTE FUNCTION public.validate_submission_policy_authority_custody(); +CREATE TRIGGER submissions_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON public.submissions FOR EACH ROW EXECUTE FUNCTION public.require_human_actor_profile_reference('contributor_id'); +CREATE TRIGGER task_assignments_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON public.task_assignments FOR EACH ROW EXECUTE FUNCTION public.require_human_actor_profile_reference('contributor_id'); +CREATE CONSTRAINT TRIGGER trg_artifact_binding_history AFTER INSERT ON public.artifact_bindings DEFERRABLE INITIALLY IMMEDIATE FOR EACH ROW EXECUTE FUNCTION public.validate_artifact_binding_history(); +CREATE TRIGGER trg_artifact_bindings_immutable BEFORE DELETE OR UPDATE ON public.artifact_bindings FOR EACH ROW EXECUTE FUNCTION public.reject_artifact_fact_mutation(); +CREATE TRIGGER trg_artifact_contents_immutable BEFORE DELETE OR UPDATE ON public.artifact_contents FOR EACH ROW EXECUTE FUNCTION public.reject_artifact_fact_mutation(); +CREATE TRIGGER trg_artifact_operation_receipts_immutable BEFORE DELETE OR UPDATE ON public.artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION public.reject_artifact_fact_mutation(); +CREATE TRIGGER trg_artifact_put_observation_receipts_immutable BEFORE DELETE OR UPDATE ON public.artifact_put_observation_receipts FOR EACH ROW EXECUTE FUNCTION public.reject_artifact_fact_mutation(); +CREATE TRIGGER trg_artifact_storage_namespaces_immutable BEFORE DELETE OR UPDATE ON public.artifact_storage_namespaces FOR EACH ROW EXECUTE FUNCTION public.reject_artifact_fact_mutation(); +CREATE TRIGGER trg_artifact_verification_receipts_immutable BEFORE DELETE OR UPDATE ON public.artifact_verification_receipts FOR EACH ROW EXECUTE FUNCTION public.reject_artifact_fact_mutation(); +CREATE TRIGGER trg_compilation_attempt_delete BEFORE DELETE OR TRUNCATE ON public.project_guide_compilation_attempts FOR EACH STATEMENT EXECUTE FUNCTION public.reject_project_guide_compilation_mutation(); +CREATE TRIGGER trg_compilation_attempt_update BEFORE UPDATE ON public.project_guide_compilation_attempts FOR EACH ROW EXECUTE FUNCTION public.guard_project_guide_compilation_attempt_update(); +CREATE TRIGGER trg_compilation_insert BEFORE INSERT ON public.project_guide_compilations FOR EACH ROW EXECUTE FUNCTION public.guard_project_guide_compilation_insert(); +CREATE TRIGGER trg_compilation_mutation BEFORE DELETE OR UPDATE OR TRUNCATE ON public.project_guide_compilations FOR EACH STATEMENT EXECUTE FUNCTION public.reject_project_guide_compilation_mutation(); +CREATE TRIGGER trg_project_role_grants_history BEFORE INSERT OR DELETE OR UPDATE ON public.project_role_grants FOR EACH ROW EXECUTE FUNCTION public.guard_project_role_grant_history(); +CREATE TRIGGER trg_project_role_grants_reject_truncate BEFORE TRUNCATE ON public.project_role_grants FOR EACH STATEMENT EXECUTE FUNCTION public.reject_project_role_history_truncate(); +CREATE TRIGGER trg_project_role_qualification_snapshots_immutable BEFORE INSERT OR DELETE OR UPDATE ON public.project_role_qualification_snapshots FOR EACH ROW EXECUTE FUNCTION public.guard_project_role_snapshot_history(); +CREATE TRIGGER trg_project_role_snapshots_reject_truncate BEFORE TRUNCATE ON public.project_role_qualification_snapshots FOR EACH STATEMENT EXECUTE FUNCTION public.reject_project_role_history_truncate(); +CREATE TRIGGER trg_submission_policy_replay_immutable BEFORE DELETE OR UPDATE ON public.submission_policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION public.reject_submission_policy_replay_mutation(); +CREATE TRIGGER trg_submission_policy_replay_no_truncate BEFORE TRUNCATE ON public.submission_policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION public.reject_submission_policy_replay_truncate(); +CREATE TRIGGER trg_sufficiency_replay_immutable BEFORE DELETE OR UPDATE ON public.guide_sufficiency_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION public.reject_sufficiency_replay_mutation(); +CREATE TRIGGER trg_sufficiency_replay_no_truncate BEFORE TRUNCATE ON public.guide_sufficiency_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION public.reject_sufficiency_replay_truncate(); +ALTER TABLE ONLY public.actor_identity_links + ADD CONSTRAINT fk_actor_identity_links_actor_profile_id_actor_profiles FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.admin_role_grants + ADD CONSTRAINT fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles FOREIGN KEY (granted_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.admin_role_grants + ADD CONSTRAINT fk_admin_role_grants_granted_by_admin_role_grant_id_adm_81e0 FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.admin_role_grants + ADD CONSTRAINT fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.admin_role_grants + ADD CONSTRAINT fk_admin_role_grants_revoked_by_admin_role_grant_id_adm_78b5 FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.admin_role_grants + ADD CONSTRAINT fk_admin_role_grants_scope_project_id_projects FOREIGN KEY (scope_project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.admin_role_grants + ADD CONSTRAINT fk_admin_role_grants_target_actor_profile_id_actor_profiles FOREIGN KEY (target_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.artifact_admission_charges + ADD CONSTRAINT fk_artifact_admission_charges_scope FOREIGN KEY (scope_type, scope_id) REFERENCES public.artifact_admission_scopes(scope_type, scope_id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_bindings + ADD CONSTRAINT fk_artifact_bindings_content_id_artifact_contents FOREIGN KEY (content_id) REFERENCES public.artifact_contents(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_bindings + ADD CONSTRAINT fk_artifact_bindings_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_bindings + ADD CONSTRAINT fk_artifact_bindings_supersedes_binding_id_artifact_bindings FOREIGN KEY (supersedes_binding_id) REFERENCES public.artifact_bindings(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_operation_receipts + ADD CONSTRAINT fk_artifact_operation_receipts_replica_id_artifact_replicas FOREIGN KEY (replica_id) REFERENCES public.artifact_replicas(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempt_charges + ADD CONSTRAINT fk_artifact_put_attempt_charges_attempt_id_artifact_put_b25d FOREIGN KEY (attempt_id) REFERENCES public.artifact_put_attempts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempt_charges + ADD CONSTRAINT fk_artifact_put_attempt_charges_charge_id_artifact_admi_85a9 FOREIGN KEY (charge_id) REFERENCES public.artifact_admission_charges(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT fk_artifact_put_attempts_checker_run_id_checker_runs FOREIGN KEY (checker_run_id) REFERENCES public.checker_runs(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT fk_artifact_put_attempts_guide_source_item_id_guide_sou_e48c FOREIGN KEY (guide_source_item_id) REFERENCES public.guide_source_snapshot_items(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT fk_artifact_put_attempts_namespace_fingerprint FOREIGN KEY (storage_namespace_id, namespace_fingerprint) REFERENCES public.artifact_storage_namespaces(id, namespace_fingerprint) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT fk_artifact_put_attempts_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT fk_artifact_put_attempts_receipt_id_artifact_operation_receipts FOREIGN KEY (receipt_id) REFERENCES public.artifact_operation_receipts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT fk_artifact_put_attempts_replica_id_artifact_replicas FOREIGN KEY (replica_id) REFERENCES public.artifact_replicas(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_attempts + ADD CONSTRAINT fk_artifact_put_attempts_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_put_observation_receipts + ADD CONSTRAINT fk_artifact_put_observation_receipts_put_attempt_id_art_237d FOREIGN KEY (put_attempt_id) REFERENCES public.artifact_put_attempts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_operation_receipts + ADD CONSTRAINT fk_artifact_receipt_checker_run FOREIGN KEY (checker_run_id) REFERENCES public.checker_runs(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_operation_receipts + ADD CONSTRAINT fk_artifact_receipt_guide_item FOREIGN KEY (guide_source_item_id) REFERENCES public.guide_source_snapshot_items(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_operation_receipts + ADD CONSTRAINT fk_artifact_receipt_put_attempt FOREIGN KEY (put_attempt_id) REFERENCES public.artifact_put_attempts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_initiation_audit_event_id_2af7 FOREIGN KEY (initiation_audit_event_id) REFERENCES public.audit_events(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_parent_recovery_attempt_i_130d FOREIGN KEY (parent_recovery_attempt_id) REFERENCES public.artifact_recovery_attempts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_requester_actor_profile_i_77f5 FOREIGN KEY (requester_actor_profile_id) REFERENCES public.actor_profiles(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_requester_identity_link_i_3619 FOREIGN KEY (requester_identity_link_id) REFERENCES public.actor_identity_links(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_retry_verification_job_id_b330 FOREIGN KEY (retry_verification_job_id) REFERENCES public.artifact_verification_jobs(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_source_verification_job_i_5eac FOREIGN KEY (source_verification_job_id) REFERENCES public.artifact_verification_jobs(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_submission_id_submissions FOREIGN KEY (submission_id) REFERENCES public.submissions(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_recovery_attempts + ADD CONSTRAINT fk_artifact_recovery_attempts_terminal_audit_event_id_a_47ab FOREIGN KEY (terminal_audit_event_id) REFERENCES public.audit_events(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_replicas + ADD CONSTRAINT fk_artifact_replicas_content_id_artifact_contents FOREIGN KEY (content_id) REFERENCES public.artifact_contents(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_replicas + ADD CONSTRAINT fk_artifact_replicas_storage_namespace_id_artifact_stor_d6cc FOREIGN KEY (storage_namespace_id) REFERENCES public.artifact_storage_namespaces(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_verification_jobs + ADD CONSTRAINT fk_artifact_verification_jobs_originating_put_attempt_i_3260 FOREIGN KEY (originating_put_attempt_id) REFERENCES public.artifact_put_attempts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_verification_jobs + ADD CONSTRAINT fk_artifact_verification_jobs_replica_id_artifact_replicas FOREIGN KEY (replica_id) REFERENCES public.artifact_replicas(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_verification_jobs + ADD CONSTRAINT fk_artifact_verification_parent FOREIGN KEY (parent_verification_job_id) REFERENCES public.artifact_verification_jobs(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.artifact_verification_receipts + ADD CONSTRAINT fk_artifact_verification_receipts_verification_job_id_a_dabf FOREIGN KEY (verification_job_id) REFERENCES public.artifact_verification_jobs(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.audit_events + ADD CONSTRAINT fk_audit_events_authority_idempotency FOREIGN KEY (idempotency_reference, actor_ref_kind, actor_id) REFERENCES public.authority_idempotency_records(id, actor_ref_kind, actor_ref) NOT VALID; +ALTER TABLE ONLY public.audit_events + ADD CONSTRAINT fk_audit_events_invalidation_cause FOREIGN KEY (invalidation_cause_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.authority_control + ADD CONSTRAINT fk_authority_control_bootstrap_grant_id_admin_role_grants FOREIGN KEY (bootstrap_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT fk_checker_policies_effective_policy_hash FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES public.effective_project_submission_artifact_policies(id, effective_policy_hash); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT fk_checker_policies_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT fk_checker_policies_pre_submit_checker_hash FOREIGN KEY (pre_submit_checker_policy_id, pre_submit_checker_bundle_hash) REFERENCES public.pre_submit_checker_policies(id, compiled_bundle_hash); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT fk_checker_policies_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT fk_checker_policies_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT fk_checker_policies_source_snapshot_hash FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.checker_policies + ADD CONSTRAINT fk_checker_policies_supersedes_policy_id FOREIGN KEY (supersedes_policy_id) REFERENCES public.checker_policies(id); +ALTER TABLE ONLY public.checker_results + ADD CONSTRAINT fk_checker_results_checker_run_id_checker_runs FOREIGN KEY (checker_run_id) REFERENCES public.checker_runs(id); +ALTER TABLE ONLY public.checker_results + ADD CONSTRAINT fk_checker_results_submission_id_submissions FOREIGN KEY (submission_id) REFERENCES public.submissions(id); +ALTER TABLE ONLY public.checker_results + ADD CONSTRAINT fk_checker_results_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_audit_event_id_audit_events FOREIGN KEY (audit_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_locked_post_submit_policy_hash FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES public.checker_policies(id, guide_version, policy_hash); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_submission_id_submissions FOREIGN KEY (submission_id) REFERENCES public.submissions(id); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_submission_locked_post_submit_policy_hash FOREIGN KEY (submission_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES public.submissions(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_submission_version FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES public.submissions(id, task_id, version); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_supersedes_checker_run_id_checker_runs FOREIGN KEY (supersedes_checker_run_id) REFERENCES public.checker_runs(id); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_task_locked_guide FOREIGN KEY (task_id, locked_guide_version) REFERENCES public.workstream_tasks(id, locked_guide_version); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_task_locked_payment_policy FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES public.workstream_tasks(id, locked_payment_policy_version); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_task_locked_review_policy FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES public.workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash); +ALTER TABLE ONLY public.checker_runs + ADD CONSTRAINT fk_checker_runs_task_locked_revision_policy FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES public.workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash); +ALTER TABLE ONLY public.project_compensation_adapter_bindings + ADD CONSTRAINT fk_compensation_binding_adapter_actor FOREIGN KEY (adapter_actor_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_compensation_adapter_bindings + ADD CONSTRAINT fk_compensation_binding_created_by FOREIGN KEY (created_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_compensation_adapter_bindings + ADD CONSTRAINT fk_compensation_binding_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_compensation_adapter_bindings + ADD CONSTRAINT fk_compensation_binding_retired_by FOREIGN KEY (retired_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_compensation_adapter_bindings + ADD CONSTRAINT fk_compensation_binding_suspended_by FOREIGN KEY (suspended_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT fk_compilation_attempt_exact_persisted_compilation FOREIGN KEY (persisted_compilation_id, id) REFERENCES public.project_guide_compilations(id, attempt_id); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT fk_compilation_attempt_exact_setup FOREIGN KEY (setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES public.project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT fk_compilation_attempt_snapshot_hash FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.contribution_award_definitions + ADD CONSTRAINT fk_contribution_award_definition_binding FOREIGN KEY (adapter_binding_id, project_id, instrument_type) REFERENCES public.project_compensation_adapter_bindings(id, project_id, instrument_type); +ALTER TABLE ONLY public.contribution_award_definitions + ADD CONSTRAINT fk_contribution_award_definition_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.contribution_award_definitions + ADD CONSTRAINT fk_contribution_award_definition_rule FOREIGN KEY (contribution_rule_id, contribution_policy_version_id, project_id, contribution_type) REFERENCES public.contribution_rules(id, contribution_policy_version_id, project_id, contribution_type); +ALTER TABLE ONLY public.contribution_award_definitions + ADD CONSTRAINT fk_contribution_award_definition_unit FOREIGN KEY (project_id, instrument_type, unit_code) REFERENCES public.project_compensation_units(project_id, instrument_type, unit_code); +ALTER TABLE ONLY public.contribution_policies + ADD CONSTRAINT fk_contribution_policy_created_by FOREIGN KEY (created_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.contribution_policies + ADD CONSTRAINT fk_contribution_policy_current_version FOREIGN KEY (current_published_version_id, id, project_id) REFERENCES public.contribution_policy_versions(id, contribution_policy_id, project_id) DEFERRABLE INITIALLY DEFERRED; +ALTER TABLE ONLY public.contribution_policies + ADD CONSTRAINT fk_contribution_policy_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.contribution_policies + ADD CONSTRAINT fk_contribution_policy_retired_by FOREIGN KEY (retired_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT fk_contribution_policy_version_created_by FOREIGN KEY (created_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT fk_contribution_policy_version_policy FOREIGN KEY (contribution_policy_id, project_id) REFERENCES public.contribution_policies(id, project_id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT fk_contribution_policy_version_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT fk_contribution_policy_version_published_by FOREIGN KEY (published_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.contribution_policy_versions + ADD CONSTRAINT fk_contribution_policy_version_retired_by FOREIGN KEY (retired_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.contribution_rules + ADD CONSTRAINT fk_contribution_rule_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.contribution_rules + ADD CONSTRAINT fk_contribution_rule_version FOREIGN KEY (contribution_policy_version_id, project_id) REFERENCES public.contribution_policy_versions(id, project_id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_policy_creation_actor FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_policy_creation_decision FOREIGN KEY (creation_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_policy_creation_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_policy_creation_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_policy_creation_project FOREIGN KEY (creation_scope_project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_project_submission_artifact_policies_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_psap_guide FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_psap_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_psap_source_snapshot_hash FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_psap_submission_policy_hash FOREIGN KEY (submission_artifact_policy_id, submission_artifact_policy_hash) REFERENCES public.submission_artifact_policies(id, policy_hash); +ALTER TABLE ONLY public.effective_project_submission_artifact_policies + ADD CONSTRAINT fk_effective_psap_supersedes FOREIGN KEY (supersedes_effective_policy_id) REFERENCES public.effective_project_submission_artifact_policies(id); +ALTER TABLE ONLY public.evidence_items + ADD CONSTRAINT fk_evidence_items_submission_id_submissions FOREIGN KEY (submission_id) REFERENCES public.submissions(id); +ALTER TABLE ONLY public.guide_source_snapshot_items + ADD CONSTRAINT fk_gssi_source_snapshot FOREIGN KEY (source_snapshot_id) REFERENCES public.guide_source_snapshots(id); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT fk_guide_bindings_exact_item FOREIGN KEY (source_item_id, source_snapshot_id) REFERENCES public.guide_source_snapshot_items(id, source_snapshot_id); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT fk_guide_bindings_exact_setup_generation FOREIGN KEY (project_setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES public.project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT fk_guide_bindings_exact_snapshot FOREIGN KEY (source_snapshot_id, project_id, guide_id) REFERENCES public.guide_source_snapshots(id, project_id, guide_id); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT fk_guide_bindings_verified_replica_content FOREIGN KEY (verified_replica_id, content_id) REFERENCES public.artifact_replicas(id, content_id); +ALTER TABLE ONLY public.guide_source_format_classifications + ADD CONSTRAINT fk_guide_classifications_exact_binding FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES public.guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation); +ALTER TABLE ONLY public.guide_source_extraction_attempts + ADD CONSTRAINT fk_guide_extraction_attempts_exact_binding FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES public.guide_source_artifact_bindings(id, content_id, setup_generation); +ALTER TABLE ONLY public.guide_source_extraction_attempts + ADD CONSTRAINT fk_guide_extraction_attempts_exact_classification FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES public.guide_source_format_classifications(id, binding_id, content_id, setup_generation); +ALTER TABLE ONLY public.guide_source_extraction_retry_budgets + ADD CONSTRAINT fk_guide_extraction_retry_budgets_exact_binding FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES public.guide_source_artifact_bindings(id, content_id, setup_generation); +ALTER TABLE ONLY public.guide_source_extraction_retry_budgets + ADD CONSTRAINT fk_guide_extraction_retry_budgets_exact_classification FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES public.guide_source_format_classifications(id, binding_id, content_id, setup_generation); +ALTER TABLE ONLY public.guide_source_extraction_usages + ADD CONSTRAINT fk_guide_extraction_usages_exact_attempt FOREIGN KEY (extraction_attempt_id, binding_id, content_id, setup_generation, attempt_status) REFERENCES public.guide_source_extraction_attempts(id, binding_id, content_id, setup_generation, status); +ALTER TABLE ONLY public.guide_source_extraction_usages + ADD CONSTRAINT fk_guide_extraction_usages_exact_binding FOREIGN KEY (binding_id, content_id, source_item_id, project_setup_run_id, setup_generation) REFERENCES public.guide_source_artifact_bindings(id, content_id, source_item_id, project_setup_run_id, setup_generation); +ALTER TABLE ONLY public.guide_source_extraction_usages + ADD CONSTRAINT fk_guide_extraction_usages_exact_content FOREIGN KEY (extracted_content_id, content_id) REFERENCES public.guide_source_extracted_contents(id, content_id); +ALTER TABLE ONLY public.guide_source_artifact_incidents + ADD CONSTRAINT fk_guide_incidents_exact_binding FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES public.guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation); +ALTER TABLE ONLY public.guide_mutation_idempotency_records + ADD CONSTRAINT fk_guide_mutation_idempotency_records_actor_profile_id__2ee3 FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.guide_mutation_idempotency_records + ADD CONSTRAINT fk_guide_mutation_idempotency_records_identity_link_id__3ddf FOREIGN KEY (identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.guide_mutation_idempotency_records + ADD CONSTRAINT fk_guide_mutation_idempotency_records_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.guide_mutation_idempotency_records + ADD CONSTRAINT fk_guide_mutation_idempotency_records_setup_run_id_proj_7dc3 FOREIGN KEY (setup_run_id) REFERENCES public.project_setup_runs(id); +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT fk_guide_source_artifact_bindings_content_id_artifact_contents FOREIGN KEY (content_id) REFERENCES public.artifact_contents(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.guide_source_artifact_bindings + ADD CONSTRAINT fk_guide_source_artifact_bindings_supersedes_binding_id_bfa2 FOREIGN KEY (supersedes_binding_id) REFERENCES public.guide_source_artifact_bindings(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.guide_source_artifact_ingests + ADD CONSTRAINT fk_guide_source_artifact_ingests_actor_profile_id_actor_22c1 FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.guide_source_artifact_ingests + ADD CONSTRAINT fk_guide_source_artifact_ingests_source_item_id_guide_s_7ba9 FOREIGN KEY (source_item_id) REFERENCES public.guide_source_snapshot_items(id); +ALTER TABLE ONLY public.guide_source_extracted_contents + ADD CONSTRAINT fk_guide_source_extracted_contents_content_id_artifact_contents FOREIGN KEY (content_id) REFERENCES public.artifact_contents(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT fk_guide_source_snapshots_created_actor FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT fk_guide_source_snapshots_created_admin_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT fk_guide_source_snapshots_created_decision FOREIGN KEY (authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT fk_guide_source_snapshots_created_identity_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT fk_guide_source_snapshots_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT fk_guide_source_snapshots_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.guide_source_snapshots + ADD CONSTRAINT fk_guide_source_snapshots_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT fk_guide_sufficiency_mutation_idempotency_records_actor_16d8 FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT fk_guide_sufficiency_mutation_idempotency_records_guide_1d2b FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT fk_guide_sufficiency_mutation_idempotency_records_ident_2378 FOREIGN KEY (identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT fk_guide_sufficiency_mutation_idempotency_records_proje_7f82 FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT fk_guide_sufficiency_mutation_idempotency_records_repor_48c3 FOREIGN KEY (report_id) REFERENCES public.guide_sufficiency_reports(id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT fk_guide_sufficiency_mutation_idempotency_records_setup_7059 FOREIGN KEY (setup_run_id) REFERENCES public.project_setup_runs(id); +ALTER TABLE ONLY public.guide_sufficiency_mutation_idempotency_records + ADD CONSTRAINT fk_guide_sufficiency_mutation_idempotency_records_sourc_9985 FOREIGN KEY (source_snapshot_id) REFERENCES public.guide_source_snapshots(id); +ALTER TABLE ONLY public.guide_sufficiency_report_source_usages + ADD CONSTRAINT fk_guide_sufficiency_report_source_usages_report_id_gui_1d57 FOREIGN KEY (report_id) REFERENCES public.guide_sufficiency_reports(id) ON DELETE CASCADE; +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_guide_sufficiency_reports_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_guide_sufficiency_reports_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_guide_sufficiency_reports_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_guide_sufficiency_reports_source_snapshot_hash FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.legacy_workflow_eligibility + ADD CONSTRAINT fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities FOREIGN KEY (actor_id) REFERENCES public.legacy_actor_identities(actor_id); +ALTER TABLE ONLY public.outbox_events + ADD CONSTRAINT fk_outbox_events_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.payment_policies + ADD CONSTRAINT fk_payment_policies_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.payment_policies + ADD CONSTRAINT fk_payment_policies_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.policy_mutation_idempotency_records + ADD CONSTRAINT fk_policy_mutation_idempotency_records_actor_profile_id_41c2 FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.policy_mutation_idempotency_records + ADD CONSTRAINT fk_policy_mutation_idempotency_records_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.policy_mutation_idempotency_records + ADD CONSTRAINT fk_policy_mutation_idempotency_records_identity_link_id_b806 FOREIGN KEY (identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.policy_mutation_idempotency_records + ADD CONSTRAINT fk_policy_mutation_idempotency_records_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_checker_policies_effective_hash FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES public.effective_project_submission_artifact_policies(id, effective_policy_hash); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_checker_policies_guide FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_checker_policies_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_checker_policies_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_checker_policies_source_snapshot_hash FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_checker_policies_supersedes FOREIGN KEY (supersedes_pre_submit_checker_policy_id) REFERENCES public.pre_submit_checker_policies(id); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_assignment FOREIGN KEY (assignment_id, task_id, actor_profile_id) REFERENCES public.task_assignments(id, task_id, contributor_id); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_guide_lineage FOREIGN KEY (guide_id, project_id, guide_version) REFERENCES public.project_guides(id, project_id, version); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_identity_actor FOREIGN KEY (identity_link_id, actor_profile_id) REFERENCES public.actor_identity_links(id, actor_profile_id); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_predecessor FOREIGN KEY (predecessor_submission_id, task_id, predecessor_submission_version) REFERENCES public.submissions(id, task_id, version); +ALTER TABLE ONLY public.pre_submit_evidence_results + ADD CONSTRAINT fk_pre_submit_evidence_results_evidence_set_id_pre_subm_096e FOREIGN KEY (evidence_set_id) REFERENCES public.pre_submit_evidence_sets(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_actor_profile_id_actor_profiles FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_assignment_id_task_assignments FOREIGN KEY (assignment_id) REFERENCES public.task_assignments(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_effective_policy_id_effecti_6a99 FOREIGN KEY (effective_policy_id) REFERENCES public.effective_project_submission_artifact_policies(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_identity_link_id_actor_iden_5cef FOREIGN KEY (identity_link_id) REFERENCES public.actor_identity_links(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_pre_submit_policy_id_pre_su_c77f FOREIGN KEY (pre_submit_policy_id) REFERENCES public.pre_submit_checker_policies(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_predecessor_submission_id_s_6ec2 FOREIGN KEY (predecessor_submission_id) REFERENCES public.submissions(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_source_snapshot_id_guide_so_1667 FOREIGN KEY (source_snapshot_id) REFERENCES public.guide_source_snapshots(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_sets_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_task_artifact_policy FOREIGN KEY (task_id, effective_policy_id, locked_artifact_policy_sha256) REFERENCES public.workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_task_checker_policy FOREIGN KEY (task_id, pre_submit_policy_id, locked_checker_policy_sha256) REFERENCES public.workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_task_guide FOREIGN KEY (task_id, guide_version) REFERENCES public.workstream_tasks(id, locked_guide_version); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_task_project FOREIGN KEY (task_id, project_id) REFERENCES public.workstream_tasks(id, project_id); +ALTER TABLE ONLY public.pre_submit_evidence_sets + ADD CONSTRAINT fk_pre_submit_evidence_task_source_snapshot FOREIGN KEY (task_id, source_snapshot_id, source_snapshot_sha256) REFERENCES public.workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_policy_creation_actor FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_policy_creation_decision FOREIGN KEY (creation_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_policy_creation_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_policy_creation_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.pre_submit_checker_policies + ADD CONSTRAINT fk_pre_submit_policy_creation_project FOREIGN KEY (creation_scope_project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_compensation_units + ADD CONSTRAINT fk_project_compensation_unit_created_by FOREIGN KEY (created_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_compensation_units + ADD CONSTRAINT fk_project_compensation_unit_iso_currency FOREIGN KEY (iso_currency_code) REFERENCES public.iso_4217_currency_codes(code); +ALTER TABLE ONLY public.project_compensation_units + ADD CONSTRAINT fk_project_compensation_unit_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_compensation_units + ADD CONSTRAINT fk_project_compensation_unit_retired_by FOREIGN KEY (retired_by) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_create_idempotency_records + ADD CONSTRAINT fk_project_create_idempotency_records_actor_profile_id__ebb1 FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_create_idempotency_records + ADD CONSTRAINT fk_project_create_idempotency_records_identity_link_id__ddce FOREIGN KEY (identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT fk_project_guide_compilation_attempts_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.project_guide_compilation_attempts + ADD CONSTRAINT fk_project_guide_compilation_attempts_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilation_predecessor FOREIGN KEY (supersedes_compilation_id, project_id, guide_id) REFERENCES public.project_guide_compilations(id, project_id, guide_id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_attempt_id_project_guide__0e94 FOREIGN KEY (attempt_id) REFERENCES public.project_guide_compilation_attempts(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_authorization_decision_ev_42ad FOREIGN KEY (authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_created_by_actor_profile__953f FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_created_via_identity_link_b250 FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_setup_run_id_project_setup_runs FOREIGN KEY (setup_run_id) REFERENCES public.project_setup_runs(id); +ALTER TABLE ONLY public.project_guide_compilations + ADD CONSTRAINT fk_project_guide_compilations_source_snapshot_id_guide__033a FOREIGN KEY (source_snapshot_id) REFERENCES public.guide_source_snapshots(id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT fk_project_guides_last_mutated_actor FOREIGN KEY (last_mutated_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT fk_project_guides_last_mutated_admin_grant FOREIGN KEY (last_mutated_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT fk_project_guides_last_mutated_decision FOREIGN KEY (last_authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT fk_project_guides_last_mutated_identity_link FOREIGN KEY (last_mutated_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT fk_project_guides_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT fk_project_guides_selected_review_policy FOREIGN KEY (project_id, version, selected_review_policy_id, selected_review_policy_generation, selected_review_policy_hash) REFERENCES public.review_policies(project_id, guide_version, id, policy_generation, policy_hash); +ALTER TABLE ONLY public.project_guides + ADD CONSTRAINT fk_project_guides_selected_revision_policy FOREIGN KEY (project_id, version, selected_revision_policy_id, selected_revision_policy_generation, selected_revision_policy_hash) REFERENCES public.revision_policies(project_id, guide_version, id, policy_generation, policy_hash); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT fk_project_role_grants_actor_profile_id_actor_profiles FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT fk_project_role_grants_granted_by_actor_profile_id_acto_c240 FOREIGN KEY (granted_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT fk_project_role_grants_granted_by_admin_role_grant_id_a_71d7 FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT fk_project_role_grants_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT fk_project_role_grants_revoked_by_actor_profile_id_acto_a5dd FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT fk_project_role_grants_revoked_by_admin_role_grant_id_a_aa4d FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.project_role_qualification_snapshots + ADD CONSTRAINT fk_project_role_qualification_snapshots_actor_profile_i_aedc FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_role_qualification_snapshots + ADD CONSTRAINT fk_project_role_qualification_snapshots_captured_by_act_ab57 FOREIGN KEY (captured_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_role_qualification_snapshots + ADD CONSTRAINT fk_project_role_qualification_snapshots_captured_by_adm_c8b8 FOREIGN KEY (captured_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.project_role_qualification_snapshots + ADD CONSTRAINT fk_project_role_qualification_snapshots_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_artifact_incident FOREIGN KEY (error_artifact_incident_id) REFERENCES public.guide_source_artifact_incidents(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_authorized_actor FOREIGN KEY (authorized_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_authorized_admin_grant FOREIGN KEY (authorized_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_authorized_decision FOREIGN KEY (authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_authorized_identity_link FOREIGN KEY (authorized_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_continuation_verification_job FOREIGN KEY (continuation_verification_job_id) REFERENCES public.artifact_verification_jobs(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_post_submit_checker_policy FOREIGN KEY (output_post_submit_checker_policy_id) REFERENCES public.checker_policies(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_source_snapshot_hash FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_source_snapshot_id_guide_source_snapshots FOREIGN KEY (source_snapshot_id) REFERENCES public.guide_source_snapshots(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_submission_artifact_policy FOREIGN KEY (output_submission_artifact_policy_id) REFERENCES public.submission_artifact_policies(id); +ALTER TABLE ONLY public.project_setup_runs + ADD CONSTRAINT fk_project_setup_runs_sufficiency_report FOREIGN KEY (output_sufficiency_report_id) REFERENCES public.guide_sufficiency_reports(id); +ALTER TABLE ONLY public.projects + ADD CONSTRAINT fk_projects_creation_actor FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.projects + ADD CONSTRAINT fk_projects_creation_admin_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.projects + ADD CONSTRAINT fk_projects_creation_decision FOREIGN KEY (authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.projects + ADD CONSTRAINT fk_projects_creation_identity_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT fk_review_admission_checker FOREIGN KEY (admitting_checker_run_id) REFERENCES public.checker_runs(id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT fk_review_admission_committed_queue FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id) REFERENCES public.review_queue_entries(id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT fk_review_admission_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT fk_review_admission_queue FOREIGN KEY (review_queue_entry_id) REFERENCES public.review_queue_entries(id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT fk_review_admission_submission FOREIGN KEY (submission_id) REFERENCES public.submissions(id); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT fk_review_admission_submission_lineage FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES public.submissions(id, task_id, version); +ALTER TABLE ONLY public.review_admission_idempotency_records + ADD CONSTRAINT fk_review_admission_task FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT fk_review_lease_policy_version FOREIGN KEY (reviewer_contribution_policy_version_id, project_id) REFERENCES public.contribution_policy_versions(id, project_id); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT fk_review_lease_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT fk_review_lease_queue_lineage FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version) REFERENCES public.review_queue_entries(id, project_id, task_id, submission_id, submission_version); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT fk_review_lease_reviewer FOREIGN KEY (reviewer_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT fk_review_lease_submission FOREIGN KEY (submission_id) REFERENCES public.submissions(id); +ALTER TABLE ONLY public.review_leases + ADD CONSTRAINT fk_review_lease_task FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT fk_review_policies_actor_profile FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT fk_review_policies_admin_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT fk_review_policies_decision_event FOREIGN KEY (authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT fk_review_policies_identity_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT fk_review_policies_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT fk_review_policies_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.review_policies + ADD CONSTRAINT fk_review_policies_supersedes FOREIGN KEY (supersedes_policy_id) REFERENCES public.review_policies(id); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT fk_review_queue_active_lease FOREIGN KEY (active_lease_id, id) REFERENCES public.review_leases(id, review_queue_entry_id) DEFERRABLE INITIALLY DEFERRED; +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT fk_review_queue_checker FOREIGN KEY (admitting_checker_run_id) REFERENCES public.checker_runs(id); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT fk_review_queue_preferred_reviewer FOREIGN KEY (preferred_reviewer_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT fk_review_queue_project FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT fk_review_queue_submission FOREIGN KEY (submission_id) REFERENCES public.submissions(id); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT fk_review_queue_submission_lineage FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES public.submissions(id, task_id, version); +ALTER TABLE ONLY public.review_queue_entries + ADD CONSTRAINT fk_review_queue_task FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT fk_revision_policies_actor_profile FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT fk_revision_policies_admin_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT fk_revision_policies_decision_event FOREIGN KEY (authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT fk_revision_policies_identity_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT fk_revision_policies_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT fk_revision_policies_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.revision_policies + ADD CONSTRAINT fk_revision_policies_supersedes FOREIGN KEY (supersedes_policy_id) REFERENCES public.revision_policies(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_sap_supersedes_policy FOREIGN KEY (supersedes_policy_id) REFERENCES public.submission_artifact_policies(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_artifact_policies_guide_id_project_guides FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_artifact_policies_project_guide FOREIGN KEY (project_id, guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_artifact_policies_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_artifact_policies_source_snapshot_hash FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_actor_profile_id_actor_profiles FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_artifact_content_id_art_12c8 FOREIGN KEY (artifact_content_id) REFERENCES public.artifact_contents(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_assignment_id_task_assignments FOREIGN KEY (assignment_id) REFERENCES public.task_assignments(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_consumed_by_submission__2b23 FOREIGN KEY (consumed_by_submission_id) REFERENCES public.submissions(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_durable_intent_id_submi_102c FOREIGN KEY (durable_intent_id) REFERENCES public.submission_bundle_durable_intents(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_identity_link_id_actor__d29d FOREIGN KEY (identity_link_id) REFERENCES public.actor_identity_links(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_pre_submit_evidence_set_a752 FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES public.pre_submit_evidence_sets(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_predecessor_submission__242d FOREIGN KEY (predecessor_submission_id) REFERENCES public.submissions(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_put_attempt_id_artifact_bbc3 FOREIGN KEY (put_attempt_id) REFERENCES public.artifact_put_attempts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_put_observation_receipt_5136 FOREIGN KEY (put_observation_receipt_id) REFERENCES public.artifact_put_observation_receipts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_put_operation_receipt_i_9602 FOREIGN KEY (put_operation_receipt_id) REFERENCES public.artifact_operation_receipts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_verification_receipt_id_0ea1 FOREIGN KEY (verification_receipt_id) REFERENCES public.artifact_verification_receipts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_admissions + ADD CONSTRAINT fk_submission_bundle_admissions_verified_replica_id_art_3a4e FOREIGN KEY (verified_replica_id) REFERENCES public.artifact_replicas(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_durable_intents + ADD CONSTRAINT fk_submission_bundle_durable_intents_pre_submit_evidenc_c406 FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES public.pre_submit_evidence_sets(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_bundle_durable_intents + ADD CONSTRAINT fk_submission_bundle_durable_intents_put_attempt_id_art_b4e4 FOREIGN KEY (put_attempt_id) REFERENCES public.artifact_put_attempts(id) ON DELETE RESTRICT; +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_approval_actor FOREIGN KEY (approved_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_approval_decision FOREIGN KEY (approval_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_approval_grant FOREIGN KEY (approved_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_approval_link FOREIGN KEY (approved_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_approval_project FOREIGN KEY (approval_scope_project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_creation_actor FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_creation_decision FOREIGN KEY (creation_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_creation_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_creation_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.submission_artifact_policies + ADD CONSTRAINT fk_submission_policy_creation_project FOREIGN KEY (creation_scope_project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_actor_f5bb FOREIGN KEY (actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_commi_4fa6 FOREIGN KEY (committed_effective_policy_id) REFERENCES public.effective_project_submission_artifact_policies(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_commi_571a FOREIGN KEY (committed_policy_id) REFERENCES public.submission_artifact_policies(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_commi_baa9 FOREIGN KEY (committed_pre_submit_policy_id) REFERENCES public.pre_submit_checker_policies(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_guide_ed8d FOREIGN KEY (guide_id) REFERENCES public.project_guides(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_ident_2567 FOREIGN KEY (identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_proje_442a FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_setup_a102 FOREIGN KEY (setup_run_id) REFERENCES public.project_setup_runs(id); +ALTER TABLE ONLY public.submission_policy_mutation_idempotency_records + ADD CONSTRAINT fk_submission_policy_mutation_idempotency_records_sourc_536e FOREIGN KEY (source_snapshot_id) REFERENCES public.guide_source_snapshots(id); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_contributor_id_actor_profiles FOREIGN KEY (contributor_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_locked_effective_policy_hash FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES public.effective_project_submission_artifact_policies(id, effective_policy_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_locked_post_submit_policy_hash FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES public.checker_policies(id, guide_version, policy_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_locked_pre_submit_checker_hash FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES public.pre_submit_checker_policies(id, compiled_bundle_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_locked_source_snapshot_hash FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_supersedes_submission_id_submissions FOREIGN KEY (supersedes_submission_id) REFERENCES public.submissions(id); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_effective_policy_hash FOREIGN KEY (task_id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES public.workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_guide FOREIGN KEY (task_id, locked_guide_version) REFERENCES public.workstream_tasks(id, locked_guide_version); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_payment_policy FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES public.workstream_tasks(id, locked_payment_policy_version); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_post_submit_policy_hash FOREIGN KEY (task_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES public.workstream_tasks(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_pre_submit_checker_hash FOREIGN KEY (task_id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES public.workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_review_policy FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES public.workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_revision_policy FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES public.workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash); +ALTER TABLE ONLY public.submissions + ADD CONSTRAINT fk_submissions_task_locked_source_snapshot_hash FOREIGN KEY (task_id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES public.workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_ack_actor FOREIGN KEY (warnings_acknowledged_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_ack_decision FOREIGN KEY (warning_acknowledgement_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_ack_grant FOREIGN KEY (warnings_acknowledged_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_ack_link FOREIGN KEY (warnings_acknowledged_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_ack_project FOREIGN KEY (warning_acknowledgement_scope_project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_create_actor FOREIGN KEY (created_by_actor_profile_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_create_decision FOREIGN KEY (authorization_decision_event_id) REFERENCES public.audit_events(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_create_grant FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES public.admin_role_grants(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_create_link FOREIGN KEY (created_via_identity_link_id) REFERENCES public.actor_identity_links(id); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_suff_create_project FOREIGN KEY (creation_scope_project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.guide_sufficiency_report_source_usages + ADD CONSTRAINT fk_sufficiency_report_source_usage_exact_extraction FOREIGN KEY (extraction_usage_id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation) REFERENCES public.guide_source_extraction_usages(id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation); +ALTER TABLE ONLY public.guide_sufficiency_reports + ADD CONSTRAINT fk_sufficiency_reports_setup_run FOREIGN KEY (project_setup_run_id) REFERENCES public.project_setup_runs(id); +ALTER TABLE ONLY public.task_assignments + ADD CONSTRAINT fk_task_assignments_contributor_id_actor_profiles FOREIGN KEY (contributor_id) REFERENCES public.actor_profiles(id); +ALTER TABLE ONLY public.task_assignments + ADD CONSTRAINT fk_task_assignments_task_id_workstream_tasks FOREIGN KEY (task_id) REFERENCES public.workstream_tasks(id); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_effective_policy_hash FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES public.effective_project_submission_artifact_policies(id, effective_policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_guide FOREIGN KEY (project_id, locked_guide_version) REFERENCES public.project_guides(project_id, version); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_payment_policy FOREIGN KEY (project_id, locked_payment_policy_version) REFERENCES public.payment_policies(project_id, guide_version); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_post_submit_policy_hash FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES public.checker_policies(id, guide_version, policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_pre_submit_checker_hash FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES public.pre_submit_checker_policies(id, compiled_bundle_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_review_policy FOREIGN KEY (project_id, locked_guide_version, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES public.review_policies(project_id, guide_version, id, policy_generation, policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_revision_policy FOREIGN KEY (project_id, locked_guide_version, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES public.revision_policies(project_id, guide_version, id, policy_generation, policy_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_locked_source_snapshot_hash FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES public.guide_source_snapshots(id, bundle_hash); +ALTER TABLE ONLY public.workstream_tasks + ADD CONSTRAINT fk_workstream_tasks_project_id_projects FOREIGN KEY (project_id) REFERENCES public.projects(id); +ALTER TABLE ONLY public.project_role_grants + ADD CONSTRAINT qualification_ownership FOREIGN KEY (qualification_snapshot_id, actor_profile_id, project_id, role) REFERENCES public.project_role_qualification_snapshots(id, actor_profile_id, project_id, requested_role) ON DELETE RESTRICT; diff --git a/backend/alembic/env.py b/backend/alembic/env.py index 962194626..c2eafd1fe 100644 --- a/backend/alembic/env.py +++ b/backend/alembic/env.py @@ -6,6 +6,7 @@ from alembic import context from sqlalchemy import pool from sqlalchemy.engine import Connection +from sqlalchemy import text from sqlalchemy.ext.asyncio import async_engine_from_config from app.core.config import get_settings @@ -19,6 +20,12 @@ target_metadata = Base.metadata +_BASELINE_REVISION = "0001_v01_baseline" +_RECREATE_GUIDANCE = ( + "Workstream v0.1 requires a fresh database; recreate this database before " + "running the 0001_v01_baseline migration" +) + def get_database_url() -> str: database_url = get_settings().database_url @@ -28,18 +35,28 @@ def get_database_url() -> str: def run_migrations_offline() -> None: - context.configure( - url=get_database_url(), - target_metadata=target_metadata, - literal_binds=True, - dialect_opts={"paramstyle": "named"}, + raise RuntimeError( + "offline migration generation is disabled because the v0.1 fresh-database " + "preflight requires a live PostgreSQL target" ) - with context.begin_transaction(): - context.run_migrations() - def do_run_migrations(connection: Connection) -> None: + version_table_exists = bool( + connection.scalar(text("select to_regclass('public.alembic_version') is not null")) + ) + if version_table_exists: + revisions = tuple( + connection.execute(text("select version_num from public.alembic_version")) + .scalars() + .all() + ) + if revisions not in ((), (_BASELINE_REVISION,)): + raise RuntimeError(_RECREATE_GUIDANCE) + # The read-only preflight autobegins a SQLAlchemy transaction. End that + # transaction before Alembic establishes the migration transaction; + # otherwise connection disposal would roll back a successful migration. + connection.commit() context.configure(connection=connection, target_metadata=target_metadata) with context.begin_transaction(): diff --git a/backend/alembic/versions/0001_initial_baseline.py b/backend/alembic/versions/0001_initial_baseline.py deleted file mode 100644 index 082998a13..000000000 --- a/backend/alembic/versions/0001_initial_baseline.py +++ /dev/null @@ -1,22 +0,0 @@ -"""initial baseline - -Revision ID: 0001_initial_baseline -Revises: -Create Date: 2026-06-04 -""" - -from __future__ import annotations - -revision = "0001_initial_baseline" -down_revision = None -branch_labels = None -depends_on = None - - -def upgrade() -> None: - pass - - -def downgrade() -> None: - pass - diff --git a/backend/alembic/versions/0001_v01_baseline.py b/backend/alembic/versions/0001_v01_baseline.py new file mode 100644 index 000000000..b08ff64b9 --- /dev/null +++ b/backend/alembic/versions/0001_v01_baseline.py @@ -0,0 +1,86 @@ +"""Install the clean v0.1 Workstream schema baseline.""" + +from __future__ import annotations + +from pathlib import Path + +from alembic import op +from sqlalchemy import text + +from scripts.schema_baseline_sql import split_sql_statements + +revision = "0001_v01_baseline" +down_revision = None +branch_labels = None +depends_on = None + +_BASELINE_DIRECTORY = Path(__file__).resolve().parents[1] / "baseline" +_RECREATE_GUIDANCE = ( + "Workstream v0.1 requires a fresh database; recreate this database before " + "running the 0001_v01_baseline migration" +) + + +def _public_schema_has_product_objects() -> bool: + connection = op.get_bind() + return bool( + connection.scalar( + text( + "select exists (" + "select 1 from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "where n.nspname='public' and c.relname <> 'alembic_version' " + "and c.relkind in ('r','p','S','v','m','f') " + "union all select 1 from pg_proc p join pg_namespace n " + "on n.oid=p.pronamespace where n.nspname='public' " + "union all select 1 from pg_type t join pg_namespace n " + "on n.oid=t.typnamespace where n.nspname='public' and t.typrelid=0 " + "and t.typcategory <> 'A' " + "union all select 1 from pg_collation c join pg_namespace n " + "on n.oid=c.collnamespace where n.nspname='public' " + "union all select 1 from pg_opclass o join pg_namespace n " + "on n.oid=o.opcnamespace where n.nspname='public'" + ")" + ) + ) + ) + + +def _execute(statements: tuple[str, ...]) -> None: + if not statements: + return + batch_tag = "$workstream_baseline_batch$" + commands: list[str] = [] + for index, statement in enumerate(statements): + tag = f"$workstream_statement_{index}$" + if tag in statement or batch_tag in statement: + raise RuntimeError("baseline SQL contains a reserved execution delimiter") + commands.append(f"EXECUTE {tag}{statement}{tag};") + op.execute(text(f"DO {batch_tag} BEGIN {' '.join(commands)} END {batch_tag}")) + + +def upgrade() -> None: + """Install the exact v0.1 schema only into a fresh database.""" + if _public_schema_has_product_objects(): + raise RuntimeError(_RECREATE_GUIDANCE) + + # pg_dump orders functions before tables; some PL/pgSQL declarations use + # table row types. Limit deferred body validation to this migration + # transaction and let the completed-schema parity tests validate every body. + op.execute(text("set local check_function_bodies = false")) + + schema = split_sql_statements( + (_BASELINE_DIRECTORY / "v01_schema.sql").read_text(encoding="utf-8") + ) + triggers = tuple(statement for statement in schema if statement.startswith("CREATE TRIGGER ")) + _execute(tuple(statement for statement in schema if statement not in triggers)) + _execute( + split_sql_statements( + (_BASELINE_DIRECTORY / "v01_reference_data.sql").read_text(encoding="utf-8") + ) + ) + _execute(triggers) + + +def downgrade() -> None: + """Reject destructive downgrade of the clean v0.1 baseline.""" + raise RuntimeError("0001_v01_baseline cannot be downgraded; recreate the database") diff --git a/backend/alembic/versions/0002_project_guide_foundation.py b/backend/alembic/versions/0002_project_guide_foundation.py deleted file mode 100644 index b906a3c78..000000000 --- a/backend/alembic/versions/0002_project_guide_foundation.py +++ /dev/null @@ -1,169 +0,0 @@ -"""project guide foundation - -Revision ID: 0002_project_guide_foundation -Revises: 0001_initial_baseline -Create Date: 2026-06-05 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0002_project_guide_foundation" -down_revision = "0001_initial_baseline" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - op.create_table( - "projects", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("name", sa.String(length=200), nullable=False), - sa.Column("slug", sa.String(length=120), nullable=False), - sa.Column("description", sa.Text(), nullable=True), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("id", name=op.f("pk_projects")), - sa.UniqueConstraint("slug", name=op.f("uq_projects_slug")), - ) - op.create_index(op.f("ix_projects_slug"), "projects", ["slug"], unique=False) - op.create_index(op.f("ix_projects_status"), "projects", ["status"], unique=False) - - op.create_table( - "project_guides", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("version", sa.String(length=50), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("content_markdown", sa.Text(), nullable=False), - sa.Column("approved_by", sa.String(length=100), nullable=True), - sa.Column("effective_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("change_summary", sa.Text(), nullable=True), - sa.Column("created_by", sa.String(length=100), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("superseded_at", sa.DateTime(timezone=True), nullable=True), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], name=op.f("fk_project_guides_project_id_projects")), - sa.PrimaryKeyConstraint("id", name=op.f("pk_project_guides")), - sa.UniqueConstraint("project_id", "version", name="uq_project_guides_project_version"), - ) - op.create_index(op.f("ix_project_guides_project_id"), "project_guides", ["project_id"], unique=False) - op.create_index(op.f("ix_project_guides_status"), "project_guides", ["status"], unique=False) - op.create_index( - "uq_project_guides_one_active_per_project", - "project_guides", - ["project_id"], - unique=True, - postgresql_where=sa.text("status = 'active'"), - ) - - op.create_table( - "checker_policies", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("required_checkers", sa.JSON(), nullable=False), - sa.Column("warning_checkers", sa.JSON(), nullable=False), - sa.Column("blocking_severities", sa.JSON(), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], name=op.f("fk_checker_policies_project_id_projects")), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_checker_policies_project_guide", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_checker_policies")), - sa.UniqueConstraint("project_id", "guide_version", name="uq_checker_policies_project_version"), - ) - op.create_index(op.f("ix_checker_policies_project_id"), "checker_policies", ["project_id"], unique=False) - - op.create_table( - "payment_policies", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("base_amount", sa.Numeric(12, 2), nullable=True), - sa.Column("currency", sa.String(length=20), nullable=True), - sa.Column("payout_type", sa.String(length=50), nullable=True), - sa.Column("revision_payment_rule", sa.Text(), nullable=True), - sa.Column("rejection_payment_rule", sa.Text(), nullable=True), - sa.Column("accepted_payment_rule", sa.Text(), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], name=op.f("fk_payment_policies_project_id_projects")), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_payment_policies_project_guide", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_payment_policies")), - sa.UniqueConstraint("project_id", "guide_version", name="uq_payment_policies_project_version"), - ) - op.create_index(op.f("ix_payment_policies_project_id"), "payment_policies", ["project_id"], unique=False) - - op.create_table( - "review_policies", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("requires_second_review", sa.Boolean(), nullable=False), - sa.Column("allowed_decisions", sa.JSON(), nullable=False), - sa.Column("minimum_finding_fields", sa.JSON(), nullable=False), - sa.Column("sla_hours", sa.Integer(), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], name=op.f("fk_review_policies_project_id_projects")), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_review_policies_project_guide", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_review_policies")), - sa.UniqueConstraint("project_id", "guide_version", name="uq_review_policies_project_version"), - ) - op.create_index(op.f("ix_review_policies_project_id"), "review_policies", ["project_id"], unique=False) - - op.create_table( - "revision_policies", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("max_revision_rounds", sa.Integer(), nullable=False), - sa.Column("revision_deadline_hours", sa.Integer(), nullable=False), - sa.Column("auto_reject_after_limit", sa.Boolean(), nullable=False), - sa.Column("allowed_resubmission_states", sa.JSON(), nullable=False), - sa.Column("reviewer_reassignment_rule", sa.Text(), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name=op.f("fk_revision_policies_project_id_projects"), - ), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_revision_policies_project_guide", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_revision_policies")), - sa.UniqueConstraint("project_id", "guide_version", name="uq_revision_policies_project_version"), - ) - op.create_index(op.f("ix_revision_policies_project_id"), "revision_policies", ["project_id"], unique=False) - - -def downgrade() -> None: - op.drop_index(op.f("ix_revision_policies_project_id"), table_name="revision_policies") - op.drop_table("revision_policies") - op.drop_index(op.f("ix_review_policies_project_id"), table_name="review_policies") - op.drop_table("review_policies") - op.drop_index(op.f("ix_payment_policies_project_id"), table_name="payment_policies") - op.drop_table("payment_policies") - op.drop_index(op.f("ix_checker_policies_project_id"), table_name="checker_policies") - op.drop_table("checker_policies") - op.drop_index("uq_project_guides_one_active_per_project", table_name="project_guides") - op.drop_index(op.f("ix_project_guides_status"), table_name="project_guides") - op.drop_index(op.f("ix_project_guides_project_id"), table_name="project_guides") - op.drop_table("project_guides") - op.drop_index(op.f("ix_projects_status"), table_name="projects") - op.drop_index(op.f("ix_projects_slug"), table_name="projects") - op.drop_table("projects") diff --git a/backend/alembic/versions/0003_task_queue_assignment.py b/backend/alembic/versions/0003_task_queue_assignment.py deleted file mode 100644 index b3a628ca9..000000000 --- a/backend/alembic/versions/0003_task_queue_assignment.py +++ /dev/null @@ -1,181 +0,0 @@ -"""task queue assignment - -Revision ID: 0003_task_queue_assignment -Revises: 0002_project_guide_foundation -Create Date: 2026-06-07 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0003_task_queue_assignment" -down_revision = "0002_project_guide_foundation" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Create task queue, assignment, profile, and audit tables.""" - op.create_table( - "worker_profiles", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("actor_id", sa.String(length=100), nullable=False), - sa.Column("external_subject", sa.String(length=200), nullable=False), - sa.Column("external_issuer", sa.String(length=200), nullable=False), - sa.Column("display_name", sa.String(length=200), nullable=True), - sa.Column("email", sa.String(length=320), nullable=True), - sa.Column("skill_tags", sa.JSON(), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("id", name=op.f("pk_worker_profiles")), - sa.UniqueConstraint("actor_id", name=op.f("uq_worker_profiles_actor_id")), - ) - op.create_index(op.f("ix_worker_profiles_status"), "worker_profiles", ["status"], unique=False) - - op.create_table( - "reviewer_profiles", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("actor_id", sa.String(length=100), nullable=False), - sa.Column("external_subject", sa.String(length=200), nullable=False), - sa.Column("external_issuer", sa.String(length=200), nullable=False), - sa.Column("display_name", sa.String(length=200), nullable=True), - sa.Column("email", sa.String(length=320), nullable=True), - sa.Column("skill_tags", sa.JSON(), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("id", name=op.f("pk_reviewer_profiles")), - sa.UniqueConstraint("actor_id", name=op.f("uq_reviewer_profiles_actor_id")), - ) - op.create_index(op.f("ix_reviewer_profiles_status"), "reviewer_profiles", ["status"], unique=False) - - op.create_table( - "workstream_tasks", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("locked_guide_version", sa.String(length=50), nullable=True), - sa.Column("locked_review_policy_version", sa.String(length=50), nullable=True), - sa.Column("locked_revision_policy_version", sa.String(length=50), nullable=True), - sa.Column("locked_payment_policy_version", sa.String(length=50), nullable=True), - sa.Column("source_type", sa.String(length=50), nullable=False), - sa.Column("source_ref", sa.String(length=500), nullable=True), - sa.Column("source_payload_hash", sa.String(length=128), nullable=True), - sa.Column("import_batch_id", sa.String(length=100), nullable=True), - sa.Column("external_task_id", sa.String(length=200), nullable=True), - sa.Column("title", sa.String(length=300), nullable=False), - sa.Column("description", sa.Text(), nullable=False), - sa.Column("task_type", sa.String(length=100), nullable=True), - sa.Column("difficulty", sa.String(length=50), nullable=True), - sa.Column("skill_tags", sa.JSON(), nullable=False), - sa.Column("estimated_time_minutes", sa.Integer(), nullable=True), - sa.Column("base_amount", sa.Numeric(12, 2), nullable=True), - sa.Column("currency", sa.String(length=20), nullable=True), - sa.Column("payout_type", sa.String(length=50), nullable=True), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("acceptance_criteria", sa.Text(), nullable=True), - sa.Column("rejection_criteria", sa.Text(), nullable=True), - sa.Column("deadline_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("created_by", sa.String(length=100), nullable=False), - sa.Column("assigned_to", sa.String(length=100), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], name=op.f("fk_workstream_tasks_project_id_projects")), - sa.ForeignKeyConstraint( - ["project_id", "locked_guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_workstream_tasks_locked_guide", - ), - sa.ForeignKeyConstraint( - ["project_id", "locked_review_policy_version"], - ["review_policies.project_id", "review_policies.guide_version"], - name="fk_workstream_tasks_locked_review_policy", - ), - sa.ForeignKeyConstraint( - ["project_id", "locked_revision_policy_version"], - ["revision_policies.project_id", "revision_policies.guide_version"], - name="fk_workstream_tasks_locked_revision_policy", - ), - sa.ForeignKeyConstraint( - ["project_id", "locked_payment_policy_version"], - ["payment_policies.project_id", "payment_policies.guide_version"], - name="fk_workstream_tasks_locked_payment_policy", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_workstream_tasks")), - ) - op.create_index(op.f("ix_workstream_tasks_assigned_to"), "workstream_tasks", ["assigned_to"], unique=False) - op.create_index(op.f("ix_workstream_tasks_project_id"), "workstream_tasks", ["project_id"], unique=False) - op.create_index(op.f("ix_workstream_tasks_status"), "workstream_tasks", ["status"], unique=False) - - op.create_table( - "task_assignments", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("task_id", sa.String(length=36), nullable=False), - sa.Column("worker_id", sa.String(length=100), nullable=False), - sa.Column("assigned_by", sa.String(length=100), nullable=False), - sa.Column("assigned_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("accepted_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("released_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("status", sa.String(length=30), nullable=False), - sa.ForeignKeyConstraint(["task_id"], ["workstream_tasks.id"], name=op.f("fk_task_assignments_task_id_workstream_tasks")), - sa.PrimaryKeyConstraint("id", name=op.f("pk_task_assignments")), - ) - op.create_index(op.f("ix_task_assignments_task_id"), "task_assignments", ["task_id"], unique=False) - op.create_index(op.f("ix_task_assignments_worker_id"), "task_assignments", ["worker_id"], unique=False) - op.create_index(op.f("ix_task_assignments_status"), "task_assignments", ["status"], unique=False) - op.create_index( - "uq_task_assignments_one_active_per_task", - "task_assignments", - ["task_id"], - unique=True, - postgresql_where=sa.text("status = 'active'"), - ) - - op.create_table( - "audit_events", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("entity_type", sa.String(length=80), nullable=False), - sa.Column("entity_id", sa.String(length=36), nullable=False), - sa.Column("event_type", sa.String(length=100), nullable=False), - sa.Column("from_status", sa.String(length=30), nullable=True), - sa.Column("to_status", sa.String(length=30), nullable=True), - sa.Column("actor_id", sa.String(length=100), nullable=False), - sa.Column("external_subject", sa.String(length=200), nullable=False), - sa.Column("external_issuer", sa.String(length=200), nullable=False), - sa.Column("actor_roles", sa.JSON(), nullable=False), - sa.Column("claim_snapshot", sa.JSON(), nullable=False), - sa.Column("auth_source", sa.String(length=30), nullable=False), - sa.Column("is_dev_auth", sa.Boolean(), nullable=False), - sa.Column("reason", sa.Text(), nullable=True), - sa.Column("event_payload", sa.JSON(), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("id", name=op.f("pk_audit_events")), - ) - op.create_index(op.f("ix_audit_events_actor_id"), "audit_events", ["actor_id"], unique=False) - op.create_index(op.f("ix_audit_events_entity_id"), "audit_events", ["entity_id"], unique=False) - op.create_index(op.f("ix_audit_events_entity_type"), "audit_events", ["entity_type"], unique=False) - op.create_index(op.f("ix_audit_events_event_type"), "audit_events", ["event_type"], unique=False) - - -def downgrade() -> None: - """Drop task queue, assignment, profile, and audit tables.""" - op.drop_index(op.f("ix_audit_events_event_type"), table_name="audit_events") - op.drop_index(op.f("ix_audit_events_entity_type"), table_name="audit_events") - op.drop_index(op.f("ix_audit_events_entity_id"), table_name="audit_events") - op.drop_index(op.f("ix_audit_events_actor_id"), table_name="audit_events") - op.drop_table("audit_events") - op.drop_index("uq_task_assignments_one_active_per_task", table_name="task_assignments") - op.drop_index(op.f("ix_task_assignments_status"), table_name="task_assignments") - op.drop_index(op.f("ix_task_assignments_worker_id"), table_name="task_assignments") - op.drop_index(op.f("ix_task_assignments_task_id"), table_name="task_assignments") - op.drop_table("task_assignments") - op.drop_index(op.f("ix_workstream_tasks_status"), table_name="workstream_tasks") - op.drop_index(op.f("ix_workstream_tasks_project_id"), table_name="workstream_tasks") - op.drop_index(op.f("ix_workstream_tasks_assigned_to"), table_name="workstream_tasks") - op.drop_table("workstream_tasks") - op.drop_index(op.f("ix_reviewer_profiles_status"), table_name="reviewer_profiles") - op.drop_table("reviewer_profiles") - op.drop_index(op.f("ix_worker_profiles_status"), table_name="worker_profiles") - op.drop_table("worker_profiles") diff --git a/backend/alembic/versions/0004_submission_packet_foundation.py b/backend/alembic/versions/0004_submission_packet_foundation.py deleted file mode 100644 index b7c97b5f8..000000000 --- a/backend/alembic/versions/0004_submission_packet_foundation.py +++ /dev/null @@ -1,149 +0,0 @@ -"""submission packet foundation - -Revision ID: 0004_submission_packets -Revises: 0003_task_queue_assignment -Create Date: 2026-06-07 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0004_submission_packets" -down_revision = "0003_task_queue_assignment" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Create submission packet and evidence tables.""" - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_guide", - "workstream_tasks", - ["id", "locked_guide_version"], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_review_policy", - "workstream_tasks", - ["id", "locked_review_policy_version"], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_revision_policy", - "workstream_tasks", - ["id", "locked_revision_policy_version"], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_payment_policy", - "workstream_tasks", - ["id", "locked_payment_policy_version"], - ) - - op.create_table( - "submissions", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("task_id", sa.String(length=36), nullable=False), - sa.Column("worker_id", sa.String(length=100), nullable=False), - sa.Column("version", sa.Integer(), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("summary", sa.Text(), nullable=False), - sa.Column("package_uri", sa.String(length=1000), nullable=True), - sa.Column("package_hash", sa.String(length=128), nullable=False), - sa.Column("artifact_hash_manifest", sa.JSON(), nullable=False), - sa.Column("worker_attestation", sa.Text(), nullable=False), - sa.Column("locked_guide_version", sa.String(length=50), nullable=False), - sa.Column("locked_review_policy_version", sa.String(length=50), nullable=False), - sa.Column("locked_revision_policy_version", sa.String(length=50), nullable=False), - sa.Column("locked_payment_policy_version", sa.String(length=50), nullable=False), - sa.Column("submitted_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("locked_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("supersedes_submission_id", sa.String(length=36), nullable=True), - sa.ForeignKeyConstraint(["task_id"], ["workstream_tasks.id"], name=op.f("fk_submissions_task_id_workstream_tasks")), - sa.ForeignKeyConstraint( - ["task_id", "locked_guide_version"], - ["workstream_tasks.id", "workstream_tasks.locked_guide_version"], - name="fk_submissions_task_locked_guide", - ), - sa.ForeignKeyConstraint( - ["task_id", "locked_review_policy_version"], - ["workstream_tasks.id", "workstream_tasks.locked_review_policy_version"], - name="fk_submissions_task_locked_review_policy", - ), - sa.ForeignKeyConstraint( - ["task_id", "locked_revision_policy_version"], - ["workstream_tasks.id", "workstream_tasks.locked_revision_policy_version"], - name="fk_submissions_task_locked_revision_policy", - ), - sa.ForeignKeyConstraint( - ["task_id", "locked_payment_policy_version"], - ["workstream_tasks.id", "workstream_tasks.locked_payment_policy_version"], - name="fk_submissions_task_locked_payment_policy", - ), - sa.ForeignKeyConstraint( - ["supersedes_submission_id"], - ["submissions.id"], - name=op.f("fk_submissions_supersedes_submission_id_submissions"), - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_submissions")), - sa.UniqueConstraint("task_id", "version", name="uq_submissions_task_version"), - sa.UniqueConstraint("id", "version", name="uq_submissions_id_version"), - ) - op.create_index(op.f("ix_submissions_task_id"), "submissions", ["task_id"], unique=False) - op.create_index(op.f("ix_submissions_worker_id"), "submissions", ["worker_id"], unique=False) - op.create_index(op.f("ix_submissions_status"), "submissions", ["status"], unique=False) - op.create_index( - op.f("ix_submissions_supersedes_submission_id"), - "submissions", - ["supersedes_submission_id"], - unique=False, - ) - - op.create_table( - "evidence_items", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("submission_id", sa.String(length=36), nullable=False), - sa.Column("type", sa.String(length=50), nullable=False), - sa.Column("label", sa.String(length=200), nullable=False), - sa.Column("uri", sa.String(length=1000), nullable=True), - sa.Column("hash", sa.String(length=128), nullable=True), - sa.Column("size_bytes", sa.Integer(), nullable=True), - sa.Column("locked_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("metadata", sa.JSON(), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint( - ["submission_id"], - ["submissions.id"], - name=op.f("fk_evidence_items_submission_id_submissions"), - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_evidence_items")), - ) - op.create_index(op.f("ix_evidence_items_submission_id"), "evidence_items", ["submission_id"], unique=False) - op.create_index(op.f("ix_evidence_items_type"), "evidence_items", ["type"], unique=False) - - -def downgrade() -> None: - """Drop submission packet and evidence tables.""" - op.drop_index(op.f("ix_evidence_items_type"), table_name="evidence_items") - op.drop_index(op.f("ix_evidence_items_submission_id"), table_name="evidence_items") - op.drop_table("evidence_items") - op.drop_index(op.f("ix_submissions_supersedes_submission_id"), table_name="submissions") - op.drop_index(op.f("ix_submissions_status"), table_name="submissions") - op.drop_index(op.f("ix_submissions_worker_id"), table_name="submissions") - op.drop_index(op.f("ix_submissions_task_id"), table_name="submissions") - op.drop_table("submissions") - op.drop_constraint( - "uq_workstream_tasks_id_locked_payment_policy", - "workstream_tasks", - type_="unique", - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_revision_policy", - "workstream_tasks", - type_="unique", - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_review_policy", - "workstream_tasks", - type_="unique", - ) - op.drop_constraint("uq_workstream_tasks_id_locked_guide", "workstream_tasks", type_="unique") diff --git a/backend/alembic/versions/0005_checker_runs.py b/backend/alembic/versions/0005_checker_runs.py deleted file mode 100644 index 61cc37f53..000000000 --- a/backend/alembic/versions/0005_checker_runs.py +++ /dev/null @@ -1,184 +0,0 @@ -"""checker run records - -Revision ID: 0005_checker_runs -Revises: 0004_submission_packets -Create Date: 2026-06-09 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0005_checker_runs" -down_revision = "0004_submission_packets" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Create durable checker run and result tables.""" - op.create_table( - "checker_runs", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("task_id", sa.String(length=36), nullable=False), - sa.Column("submission_id", sa.String(length=36), nullable=False), - sa.Column("submission_version", sa.Integer(), nullable=False), - sa.Column("trigger_source", sa.String(length=50), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("routing_recommendation", sa.String(length=50), nullable=False), - sa.Column("outcome_source", sa.String(length=50), nullable=False), - sa.Column("triggered_by", sa.String(length=100), nullable=False), - sa.Column("triggered_by_subject", sa.String(length=200), nullable=False), - sa.Column("triggered_by_issuer", sa.String(length=200), nullable=False), - sa.Column("trigger_auth_source", sa.String(length=30), nullable=False), - sa.Column("trigger_reason", sa.Text(), nullable=True), - sa.Column("audit_event_id", sa.String(length=36), nullable=True), - sa.Column("attempt_number", sa.Integer(), nullable=False), - sa.Column("supersedes_checker_run_id", sa.String(length=36), nullable=True), - sa.Column("is_current_for_submission", sa.Boolean(), nullable=False), - sa.Column("locked_guide_version", sa.String(length=50), nullable=False), - sa.Column("locked_review_policy_version", sa.String(length=50), nullable=False), - sa.Column("locked_revision_policy_version", sa.String(length=50), nullable=False), - sa.Column("locked_payment_policy_version", sa.String(length=50), nullable=False), - sa.Column("package_hash", sa.String(length=128), nullable=False), - sa.Column("artifact_hash_manifest", sa.JSON(), nullable=False), - sa.Column("artifact_manifest_hash", sa.String(length=128), nullable=False), - sa.Column("passed_count", sa.Integer(), nullable=False), - sa.Column("warning_count", sa.Integer(), nullable=False), - sa.Column("failed_count", sa.Integer(), nullable=False), - sa.Column("blocking_count", sa.Integer(), nullable=False), - sa.Column("queued_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("started_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("completed_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("failure_code", sa.String(length=100), nullable=True), - sa.Column("failure_message", sa.Text(), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint( - ["audit_event_id"], - ["audit_events.id"], - name=op.f("fk_checker_runs_audit_event_id_audit_events"), - ), - sa.ForeignKeyConstraint( - ["submission_id"], - ["submissions.id"], - name=op.f("fk_checker_runs_submission_id_submissions"), - ), - sa.ForeignKeyConstraint( - ["submission_id", "submission_version"], - ["submissions.id", "submissions.version"], - name="fk_checker_runs_submission_version", - ), - sa.ForeignKeyConstraint( - ["supersedes_checker_run_id"], - ["checker_runs.id"], - name=op.f("fk_checker_runs_supersedes_checker_run_id_checker_runs"), - ), - sa.ForeignKeyConstraint( - ["task_id"], - ["workstream_tasks.id"], - name=op.f("fk_checker_runs_task_id_workstream_tasks"), - ), - sa.ForeignKeyConstraint( - ["task_id", "locked_guide_version"], - ["workstream_tasks.id", "workstream_tasks.locked_guide_version"], - name="fk_checker_runs_task_locked_guide", - ), - sa.ForeignKeyConstraint( - ["task_id", "locked_review_policy_version"], - ["workstream_tasks.id", "workstream_tasks.locked_review_policy_version"], - name="fk_checker_runs_task_locked_review_policy", - ), - sa.ForeignKeyConstraint( - ["task_id", "locked_revision_policy_version"], - ["workstream_tasks.id", "workstream_tasks.locked_revision_policy_version"], - name="fk_checker_runs_task_locked_revision_policy", - ), - sa.ForeignKeyConstraint( - ["task_id", "locked_payment_policy_version"], - ["workstream_tasks.id", "workstream_tasks.locked_payment_policy_version"], - name="fk_checker_runs_task_locked_payment_policy", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_checker_runs")), - sa.UniqueConstraint( - "submission_id", - "attempt_number", - name="uq_checker_runs_submission_attempt", - ), - ) - op.create_index(op.f("ix_checker_runs_audit_event_id"), "checker_runs", ["audit_event_id"], unique=False) - op.create_index(op.f("ix_checker_runs_routing_recommendation"), "checker_runs", ["routing_recommendation"], unique=False) - op.create_index(op.f("ix_checker_runs_status"), "checker_runs", ["status"], unique=False) - op.create_index(op.f("ix_checker_runs_submission_id"), "checker_runs", ["submission_id"], unique=False) - op.create_index( - op.f("ix_checker_runs_supersedes_checker_run_id"), - "checker_runs", - ["supersedes_checker_run_id"], - unique=False, - ) - op.create_index(op.f("ix_checker_runs_task_id"), "checker_runs", ["task_id"], unique=False) - op.create_index( - "uq_checker_runs_current_per_submission", - "checker_runs", - ["submission_id"], - unique=True, - postgresql_where=sa.text("is_current_for_submission = true"), - ) - - op.create_table( - "checker_results", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("checker_run_id", sa.String(length=36), nullable=False), - sa.Column("task_id", sa.String(length=36), nullable=False), - sa.Column("submission_id", sa.String(length=36), nullable=False), - sa.Column("checker_name", sa.String(length=100), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("severity", sa.String(length=30), nullable=False), - sa.Column("blocks_review", sa.Boolean(), nullable=False), - sa.Column("message", sa.Text(), nullable=False), - sa.Column("worker_message", sa.Text(), nullable=True), - sa.Column("worker_suggested_fix", sa.Text(), nullable=True), - sa.Column("worker_evidence_refs", sa.JSON(), nullable=False), - sa.Column("worker_visible", sa.Boolean(), nullable=False), - sa.Column("metadata", sa.JSON(), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.ForeignKeyConstraint( - ["checker_run_id"], - ["checker_runs.id"], - name=op.f("fk_checker_results_checker_run_id_checker_runs"), - ), - sa.ForeignKeyConstraint( - ["submission_id"], - ["submissions.id"], - name=op.f("fk_checker_results_submission_id_submissions"), - ), - sa.ForeignKeyConstraint( - ["task_id"], - ["workstream_tasks.id"], - name=op.f("fk_checker_results_task_id_workstream_tasks"), - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_checker_results")), - ) - op.create_index(op.f("ix_checker_results_checker_name"), "checker_results", ["checker_name"], unique=False) - op.create_index(op.f("ix_checker_results_checker_run_id"), "checker_results", ["checker_run_id"], unique=False) - op.create_index(op.f("ix_checker_results_submission_id"), "checker_results", ["submission_id"], unique=False) - op.create_index(op.f("ix_checker_results_task_id"), "checker_results", ["task_id"], unique=False) - op.create_index(op.f("ix_checker_results_worker_visible"), "checker_results", ["worker_visible"], unique=False) - - -def downgrade() -> None: - """Drop durable checker run and result tables.""" - op.drop_index(op.f("ix_checker_results_worker_visible"), table_name="checker_results") - op.drop_index(op.f("ix_checker_results_task_id"), table_name="checker_results") - op.drop_index(op.f("ix_checker_results_submission_id"), table_name="checker_results") - op.drop_index(op.f("ix_checker_results_checker_run_id"), table_name="checker_results") - op.drop_index(op.f("ix_checker_results_checker_name"), table_name="checker_results") - op.drop_table("checker_results") - op.drop_index("uq_checker_runs_current_per_submission", table_name="checker_runs") - op.drop_index(op.f("ix_checker_runs_task_id"), table_name="checker_runs") - op.drop_index(op.f("ix_checker_runs_supersedes_checker_run_id"), table_name="checker_runs") - op.drop_index(op.f("ix_checker_runs_submission_id"), table_name="checker_runs") - op.drop_index(op.f("ix_checker_runs_status"), table_name="checker_runs") - op.drop_index(op.f("ix_checker_runs_routing_recommendation"), table_name="checker_runs") - op.drop_index(op.f("ix_checker_runs_audit_event_id"), table_name="checker_runs") - op.drop_table("checker_runs") diff --git a/backend/alembic/versions/0006_submission_artifact_policy_foundation.py b/backend/alembic/versions/0006_submission_artifact_policy_foundation.py deleted file mode 100644 index 9e9539ca3..000000000 --- a/backend/alembic/versions/0006_submission_artifact_policy_foundation.py +++ /dev/null @@ -1,642 +0,0 @@ -"""submission artifact policy foundation - -Revision ID: 0006_submission_policy -Revises: 0005_checker_runs -Create Date: 2026-06-27 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0006_submission_policy" -down_revision = "0005_checker_runs" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Create guide-source snapshot and submission artifact policy tables.""" - op.create_table( - "guide_source_snapshots", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("manifest_schema_version", sa.String(length=50), nullable=False), - sa.Column("manifest_json", sa.JSON(), nullable=False), - sa.Column("bundle_hash", sa.String(length=71), nullable=False), - sa.Column("captured_by", sa.String(length=100), nullable=False), - sa.Column( - "captured_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.ForeignKeyConstraint( - ["guide_id"], - ["project_guides.id"], - name=op.f("fk_guide_source_snapshots_guide_id_project_guides"), - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name=op.f("fk_guide_source_snapshots_project_id_projects"), - ), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_guide_source_snapshots_project_guide", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_guide_source_snapshots")), - sa.UniqueConstraint("id", "bundle_hash", name="uq_guide_source_snapshots_id_hash"), - sa.UniqueConstraint( - "project_id", - "guide_version", - "bundle_hash", - name="uq_guide_source_snapshots_project_version_hash", - ), - ) - op.create_index( - op.f("ix_guide_source_snapshots_bundle_hash"), - "guide_source_snapshots", - ["bundle_hash"], - unique=False, - ) - op.create_index( - op.f("ix_guide_source_snapshots_guide_id"), - "guide_source_snapshots", - ["guide_id"], - unique=False, - ) - op.create_index( - op.f("ix_guide_source_snapshots_project_id"), - "guide_source_snapshots", - ["project_id"], - unique=False, - ) - - op.create_table( - "guide_source_snapshot_items", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - sa.Column("item_order", sa.Integer(), nullable=False), - sa.Column("source_kind", sa.String(length=50), nullable=False), - sa.Column("durable_ref", sa.Text(), nullable=False), - sa.Column("ingestion_adapter", sa.String(length=100), nullable=False), - sa.Column("content_hash", sa.String(length=71), nullable=False), - sa.Column("content_cid", sa.String(length=200), nullable=True), - sa.Column("media_type", sa.String(length=100), nullable=True), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id"], - ["guide_source_snapshots.id"], - name="fk_gssi_source_snapshot", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_guide_source_snapshot_items")), - sa.UniqueConstraint( - "source_snapshot_id", - "source_kind", - "durable_ref", - name="uq_guide_source_snapshot_items_snapshot_kind_ref", - ), - ) - op.create_index( - op.f("ix_guide_source_snapshot_items_source_snapshot_id"), - "guide_source_snapshot_items", - ["source_snapshot_id"], - unique=False, - ) - - op.create_table( - "guide_sufficiency_reports", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - sa.Column("source_snapshot_hash", sa.String(length=71), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("findings", sa.JSON(), nullable=False), - sa.Column("summary", sa.Text(), nullable=True), - sa.Column("agent_name", sa.String(length=100), nullable=True), - sa.Column("agent_version", sa.String(length=50), nullable=True), - sa.Column("created_by", sa.String(length=100), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column("warnings_acknowledged_by_role", sa.String(length=50), nullable=True), - sa.Column("warnings_acknowledged_by_actor", sa.String(length=100), nullable=True), - sa.Column("warnings_acknowledged_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("acknowledgement_note", sa.Text(), nullable=True), - sa.CheckConstraint( - "status in ('passed', 'blocked', 'passed_with_warnings')", - name="ck_guide_sufficiency_reports_status", - ), - sa.ForeignKeyConstraint( - ["guide_id"], - ["project_guides.id"], - name=op.f("fk_guide_sufficiency_reports_guide_id_project_guides"), - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name=op.f("fk_guide_sufficiency_reports_project_id_projects"), - ), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_guide_sufficiency_reports_project_guide", - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id", "source_snapshot_hash"], - ["guide_source_snapshots.id", "guide_source_snapshots.bundle_hash"], - name="fk_guide_sufficiency_reports_source_snapshot_hash", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_guide_sufficiency_reports")), - sa.UniqueConstraint( - "source_snapshot_id", - name="uq_guide_sufficiency_reports_source_snapshot", - ), - ) - op.create_index( - op.f("ix_guide_sufficiency_reports_guide_id"), - "guide_sufficiency_reports", - ["guide_id"], - unique=False, - ) - op.create_index( - op.f("ix_guide_sufficiency_reports_project_id"), - "guide_sufficiency_reports", - ["project_id"], - unique=False, - ) - op.create_index( - op.f("ix_guide_sufficiency_reports_source_snapshot_id"), - "guide_sufficiency_reports", - ["source_snapshot_id"], - unique=False, - ) - op.create_index( - op.f("ix_guide_sufficiency_reports_status"), - "guide_sufficiency_reports", - ["status"], - unique=False, - ) - - op.create_table( - "submission_artifact_policies", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - sa.Column("source_snapshot_hash", sa.String(length=71), nullable=False), - sa.Column("policy_version", sa.String(length=50), nullable=False), - sa.Column("lifecycle_status", sa.String(length=30), nullable=False), - sa.Column("policy_body", sa.JSON(), nullable=False), - sa.Column("policy_hash", sa.String(length=71), nullable=False), - sa.Column("derivation_source", sa.String(length=100), nullable=False), - sa.Column("source_material_refs", sa.JSON(), nullable=False), - sa.Column("derivation_agent_name", sa.String(length=100), nullable=True), - sa.Column("derivation_agent_version", sa.String(length=50), nullable=True), - sa.Column("created_by", sa.String(length=100), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column("approved_by_role", sa.String(length=50), nullable=True), - sa.Column("approved_by_actor", sa.String(length=100), nullable=True), - sa.Column("approved_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("supersedes_policy_id", sa.String(length=36), nullable=True), - sa.Column("superseded_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("change_summary", sa.Text(), nullable=True), - sa.CheckConstraint( - "lifecycle_status in ('draft', 'approved', 'superseded')", - name="ck_submission_artifact_policies_lifecycle_status", - ), - sa.CheckConstraint( - "lifecycle_status != 'approved' or " - "(approved_by_role in ('admin', 'project_manager') and " - "approved_by_actor is not null and approved_at is not null)", - name="ck_submission_artifact_policies_approval_provenance", - ), - sa.ForeignKeyConstraint( - ["guide_id"], - ["project_guides.id"], - name=op.f("fk_submission_artifact_policies_guide_id_project_guides"), - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name=op.f("fk_submission_artifact_policies_project_id_projects"), - ), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_submission_artifact_policies_project_guide", - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id", "source_snapshot_hash"], - ["guide_source_snapshots.id", "guide_source_snapshots.bundle_hash"], - name="fk_submission_artifact_policies_source_snapshot_hash", - ), - sa.ForeignKeyConstraint( - ["supersedes_policy_id"], - ["submission_artifact_policies.id"], - name="fk_sap_supersedes_policy", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_submission_artifact_policies")), - sa.UniqueConstraint( - "id", - "policy_hash", - name="uq_submission_artifact_policies_id_hash", - ), - sa.UniqueConstraint( - "project_id", - "guide_version", - "policy_version", - name="uq_submission_artifact_policies_project_version_policy", - ), - ) - op.create_index( - op.f("ix_submission_artifact_policies_guide_id"), - "submission_artifact_policies", - ["guide_id"], - unique=False, - ) - op.create_index( - op.f("ix_submission_artifact_policies_lifecycle_status"), - "submission_artifact_policies", - ["lifecycle_status"], - unique=False, - ) - op.create_index( - op.f("ix_submission_artifact_policies_policy_hash"), - "submission_artifact_policies", - ["policy_hash"], - unique=False, - ) - op.create_index( - op.f("ix_submission_artifact_policies_project_id"), - "submission_artifact_policies", - ["project_id"], - unique=False, - ) - op.create_index( - op.f("ix_submission_artifact_policies_source_snapshot_id"), - "submission_artifact_policies", - ["source_snapshot_id"], - unique=False, - ) - op.create_table( - "effective_project_submission_artifact_policies", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - sa.Column("source_snapshot_hash", sa.String(length=71), nullable=False), - sa.Column("submission_artifact_policy_id", sa.String(length=36), nullable=False), - sa.Column("submission_artifact_policy_hash", sa.String(length=71), nullable=False), - sa.Column("lifecycle_status", sa.String(length=30), nullable=False), - sa.Column("merge_algorithm_version", sa.String(length=50), nullable=False), - sa.Column("effective_policy", sa.JSON(), nullable=False), - sa.Column("effective_policy_hash", sa.String(length=71), nullable=False), - sa.Column("created_by", sa.String(length=100), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column("supersedes_effective_policy_id", sa.String(length=36), nullable=True), - sa.Column("superseded_at", sa.DateTime(timezone=True), nullable=True), - sa.CheckConstraint( - "lifecycle_status in ('approved', 'superseded')", - name="ck_effective_psap_lifecycle_status", - ), - sa.ForeignKeyConstraint( - ["guide_id"], - ["project_guides.id"], - name="fk_effective_psap_guide", - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name="fk_effective_psap_project", - ), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_effective_project_submission_artifact_policies_project_guide", - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id", "source_snapshot_hash"], - ["guide_source_snapshots.id", "guide_source_snapshots.bundle_hash"], - name="fk_effective_psap_source_snapshot_hash", - ), - sa.ForeignKeyConstraint( - ["submission_artifact_policy_id", "submission_artifact_policy_hash"], - ["submission_artifact_policies.id", "submission_artifact_policies.policy_hash"], - name="fk_effective_psap_submission_policy_hash", - ), - sa.ForeignKeyConstraint( - ["supersedes_effective_policy_id"], - ["effective_project_submission_artifact_policies.id"], - name="fk_effective_psap_supersedes", - ), - sa.PrimaryKeyConstraint( - "id", - name=op.f("pk_effective_project_submission_artifact_policies"), - ), - sa.UniqueConstraint( - "id", - "effective_policy_hash", - name="uq_effective_project_submission_artifact_policies_id_hash", - ), - ) - op.create_index( - "ix_effective_psap_effective_hash", - "effective_project_submission_artifact_policies", - ["effective_policy_hash"], - unique=False, - ) - op.create_index( - "ix_effective_psap_guide", - "effective_project_submission_artifact_policies", - ["guide_id"], - unique=False, - ) - op.create_index( - "ix_effective_psap_lifecycle", - "effective_project_submission_artifact_policies", - ["lifecycle_status"], - unique=False, - ) - op.create_index( - "ix_effective_psap_project", - "effective_project_submission_artifact_policies", - ["project_id"], - unique=False, - ) - op.create_index( - "ix_effective_psap_source_snapshot", - "effective_project_submission_artifact_policies", - ["source_snapshot_id"], - unique=False, - ) - op.create_index( - "ix_effective_psap_submission_policy", - "effective_project_submission_artifact_policies", - ["submission_artifact_policy_id"], - unique=False, - ) - op.create_table( - "pre_submit_checker_policies", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - sa.Column("source_snapshot_hash", sa.String(length=71), nullable=False), - sa.Column("effective_policy_id", sa.String(length=36), nullable=False), - sa.Column("effective_policy_hash", sa.String(length=71), nullable=False), - sa.Column("lifecycle_status", sa.String(length=30), nullable=False), - sa.Column("compiler_version", sa.String(length=50), nullable=True), - sa.Column("compiled_bundle", sa.JSON(), nullable=True), - sa.Column("compiled_bundle_hash", sa.String(length=71), nullable=True), - sa.Column("checker_names", sa.JSON(), nullable=False), - sa.Column("checker_configs", sa.JSON(), nullable=False), - sa.Column("created_by", sa.String(length=100), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column("supersedes_pre_submit_checker_policy_id", sa.String(length=36), nullable=True), - sa.Column("superseded_at", sa.DateTime(timezone=True), nullable=True), - sa.CheckConstraint( - "lifecycle_status in ('pending_compilation', 'compiled', 'superseded')", - name="ck_pre_submit_checker_policies_lifecycle_status", - ), - sa.CheckConstraint( - "lifecycle_status != 'compiled' or " - "(compiler_version is not null and compiled_bundle is not null and " - "compiled_bundle_hash is not null and " - "compiled_bundle_hash ~ '^sha256:[0-9a-f]{64}$')", - name="ck_pre_submit_checker_policies_compiled_fields", - ), - sa.ForeignKeyConstraint( - ["effective_policy_id", "effective_policy_hash"], - [ - "effective_project_submission_artifact_policies.id", - "effective_project_submission_artifact_policies.effective_policy_hash", - ], - name="fk_pre_submit_checker_policies_effective_hash", - ), - sa.ForeignKeyConstraint( - ["guide_id"], - ["project_guides.id"], - name="fk_pre_submit_checker_policies_guide", - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name="fk_pre_submit_checker_policies_project", - ), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_pre_submit_checker_policies_project_guide", - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id", "source_snapshot_hash"], - ["guide_source_snapshots.id", "guide_source_snapshots.bundle_hash"], - name="fk_pre_submit_checker_policies_source_snapshot_hash", - ), - sa.ForeignKeyConstraint( - ["supersedes_pre_submit_checker_policy_id"], - ["pre_submit_checker_policies.id"], - name="fk_pre_submit_checker_policies_supersedes", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_pre_submit_checker_policies")), - ) - op.create_index( - "ix_pre_submit_checker_compiled_hash", - "pre_submit_checker_policies", - ["compiled_bundle_hash"], - unique=False, - ) - op.create_index( - "ix_pre_submit_checker_effective", - "pre_submit_checker_policies", - ["effective_policy_id"], - unique=False, - ) - op.create_index( - "ix_pre_submit_checker_effective_hash", - "pre_submit_checker_policies", - ["effective_policy_hash"], - unique=False, - ) - op.create_index( - "ix_pre_submit_checker_guide", - "pre_submit_checker_policies", - ["guide_id"], - unique=False, - ) - op.create_index( - "ix_pre_submit_checker_lifecycle", - "pre_submit_checker_policies", - ["lifecycle_status"], - unique=False, - ) - op.create_index( - "ix_pre_submit_checker_project", - "pre_submit_checker_policies", - ["project_id"], - unique=False, - ) - op.create_index( - "ix_pre_submit_checker_source_snapshot", - "pre_submit_checker_policies", - ["source_snapshot_id"], - unique=False, - ) - -def downgrade() -> None: - """Drop submission artifact policy tables in dependency order.""" - op.drop_index( - "ix_pre_submit_checker_source_snapshot", - table_name="pre_submit_checker_policies", - ) - op.drop_index( - "ix_pre_submit_checker_project", - table_name="pre_submit_checker_policies", - ) - op.drop_index( - "ix_pre_submit_checker_lifecycle", - table_name="pre_submit_checker_policies", - ) - op.drop_index( - "ix_pre_submit_checker_guide", - table_name="pre_submit_checker_policies", - ) - op.drop_index( - "ix_pre_submit_checker_effective_hash", - table_name="pre_submit_checker_policies", - ) - op.drop_index( - "ix_pre_submit_checker_effective", - table_name="pre_submit_checker_policies", - ) - op.drop_index( - "ix_pre_submit_checker_compiled_hash", - table_name="pre_submit_checker_policies", - ) - op.drop_table("pre_submit_checker_policies") - - op.drop_index( - "ix_effective_psap_submission_policy", - table_name="effective_project_submission_artifact_policies", - ) - op.drop_index( - "ix_effective_psap_source_snapshot", - table_name="effective_project_submission_artifact_policies", - ) - op.drop_index( - "ix_effective_psap_project", - table_name="effective_project_submission_artifact_policies", - ) - op.drop_index( - "ix_effective_psap_lifecycle", - table_name="effective_project_submission_artifact_policies", - ) - op.drop_index( - "ix_effective_psap_guide", - table_name="effective_project_submission_artifact_policies", - ) - op.drop_index( - "ix_effective_psap_effective_hash", - table_name="effective_project_submission_artifact_policies", - ) - op.drop_table("effective_project_submission_artifact_policies") - - op.drop_index( - op.f("ix_submission_artifact_policies_source_snapshot_id"), - table_name="submission_artifact_policies", - ) - op.drop_index( - op.f("ix_submission_artifact_policies_project_id"), - table_name="submission_artifact_policies", - ) - op.drop_index( - op.f("ix_submission_artifact_policies_policy_hash"), - table_name="submission_artifact_policies", - ) - op.drop_index( - op.f("ix_submission_artifact_policies_lifecycle_status"), - table_name="submission_artifact_policies", - ) - op.drop_index( - op.f("ix_submission_artifact_policies_guide_id"), - table_name="submission_artifact_policies", - ) - op.drop_table("submission_artifact_policies") - - op.drop_index( - op.f("ix_guide_sufficiency_reports_status"), - table_name="guide_sufficiency_reports", - ) - op.drop_index( - op.f("ix_guide_sufficiency_reports_source_snapshot_id"), - table_name="guide_sufficiency_reports", - ) - op.drop_index( - op.f("ix_guide_sufficiency_reports_project_id"), - table_name="guide_sufficiency_reports", - ) - op.drop_index( - op.f("ix_guide_sufficiency_reports_guide_id"), - table_name="guide_sufficiency_reports", - ) - op.drop_table("guide_sufficiency_reports") - - op.drop_index( - op.f("ix_guide_source_snapshot_items_source_snapshot_id"), - table_name="guide_source_snapshot_items", - ) - op.drop_table("guide_source_snapshot_items") - - op.drop_index( - op.f("ix_guide_source_snapshots_project_id"), - table_name="guide_source_snapshots", - ) - op.drop_index( - op.f("ix_guide_source_snapshots_guide_id"), - table_name="guide_source_snapshots", - ) - op.drop_index( - op.f("ix_guide_source_snapshots_bundle_hash"), - table_name="guide_source_snapshots", - ) - op.drop_table("guide_source_snapshots") diff --git a/backend/alembic/versions/0007_task_locked_submission_context.py b/backend/alembic/versions/0007_task_locked_submission_context.py deleted file mode 100644 index b258385fb..000000000 --- a/backend/alembic/versions/0007_task_locked_submission_context.py +++ /dev/null @@ -1,316 +0,0 @@ -"""task locked submission context - -Revision ID: 0007_task_locked_context -Revises: 0006_submission_policy -Create Date: 2026-07-02 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0007_task_locked_context" -down_revision = "0006_submission_policy" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Add locked project policy context to tasks and submissions.""" - op.create_unique_constraint( - "uq_pre_submit_checker_policies_id_compiled_bundle_hash", - "pre_submit_checker_policies", - ["id", "compiled_bundle_hash"], - ) - op.add_column( - "workstream_tasks", - sa.Column("locked_guide_source_snapshot_id", sa.String(length=36), nullable=True), - ) - op.add_column( - "workstream_tasks", - sa.Column("locked_guide_source_snapshot_hash", sa.String(length=71), nullable=True), - ) - op.add_column( - "workstream_tasks", - sa.Column( - "locked_effective_project_submission_artifact_policy_id", - sa.String(length=36), - nullable=True, - ), - ) - op.add_column( - "workstream_tasks", - sa.Column( - "locked_effective_project_submission_artifact_policy_hash", - sa.String(length=71), - nullable=True, - ), - ) - op.add_column( - "workstream_tasks", - sa.Column("locked_pre_submit_checker_policy_id", sa.String(length=36), nullable=True), - ) - op.add_column( - "workstream_tasks", - sa.Column("locked_pre_submit_checker_bundle_hash", sa.String(length=71), nullable=True), - ) - op.create_foreign_key( - "fk_workstream_tasks_locked_source_snapshot_hash", - "workstream_tasks", - "guide_source_snapshots", - ["locked_guide_source_snapshot_id", "locked_guide_source_snapshot_hash"], - ["id", "bundle_hash"], - ) - op.create_foreign_key( - "fk_workstream_tasks_locked_effective_policy_hash", - "workstream_tasks", - "effective_project_submission_artifact_policies", - [ - "locked_effective_project_submission_artifact_policy_id", - "locked_effective_project_submission_artifact_policy_hash", - ], - ["id", "effective_policy_hash"], - ) - op.create_foreign_key( - "fk_workstream_tasks_locked_pre_submit_checker_hash", - "workstream_tasks", - "pre_submit_checker_policies", - ["locked_pre_submit_checker_policy_id", "locked_pre_submit_checker_bundle_hash"], - ["id", "compiled_bundle_hash"], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_source_snapshot_hash", - "workstream_tasks", - ["id", "locked_guide_source_snapshot_id", "locked_guide_source_snapshot_hash"], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_effective_policy_hash", - "workstream_tasks", - [ - "id", - "locked_effective_project_submission_artifact_policy_id", - "locked_effective_project_submission_artifact_policy_hash", - ], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_pre_submit_checker_hash", - "workstream_tasks", - ["id", "locked_pre_submit_checker_policy_id", "locked_pre_submit_checker_bundle_hash"], - ) - op.create_index( - "ix_workstream_tasks_locked_source_snapshot", - "workstream_tasks", - ["locked_guide_source_snapshot_id"], - unique=False, - ) - op.create_index( - "ix_workstream_tasks_locked_effective_policy_hash", - "workstream_tasks", - ["locked_effective_project_submission_artifact_policy_hash"], - unique=False, - ) - op.create_index( - "ix_workstream_tasks_locked_pre_submit_checker_hash", - "workstream_tasks", - ["locked_pre_submit_checker_bundle_hash"], - unique=False, - ) - - op.add_column( - "submissions", - sa.Column("locked_guide_source_snapshot_id", sa.String(length=36), nullable=True), - ) - op.add_column( - "submissions", - sa.Column("locked_guide_source_snapshot_hash", sa.String(length=71), nullable=True), - ) - op.add_column( - "submissions", - sa.Column( - "locked_effective_project_submission_artifact_policy_id", - sa.String(length=36), - nullable=True, - ), - ) - op.add_column( - "submissions", - sa.Column( - "locked_effective_project_submission_artifact_policy_hash", - sa.String(length=71), - nullable=True, - ), - ) - op.add_column( - "submissions", - sa.Column("locked_pre_submit_checker_policy_id", sa.String(length=36), nullable=True), - ) - op.add_column( - "submissions", - sa.Column("locked_pre_submit_checker_bundle_hash", sa.String(length=71), nullable=True), - ) - op.create_foreign_key( - "fk_submissions_locked_source_snapshot_hash", - "submissions", - "guide_source_snapshots", - ["locked_guide_source_snapshot_id", "locked_guide_source_snapshot_hash"], - ["id", "bundle_hash"], - ) - op.create_foreign_key( - "fk_submissions_locked_effective_policy_hash", - "submissions", - "effective_project_submission_artifact_policies", - [ - "locked_effective_project_submission_artifact_policy_id", - "locked_effective_project_submission_artifact_policy_hash", - ], - ["id", "effective_policy_hash"], - ) - op.create_foreign_key( - "fk_submissions_task_locked_source_snapshot_hash", - "submissions", - "workstream_tasks", - ["task_id", "locked_guide_source_snapshot_id", "locked_guide_source_snapshot_hash"], - ["id", "locked_guide_source_snapshot_id", "locked_guide_source_snapshot_hash"], - ) - op.create_foreign_key( - "fk_submissions_task_locked_effective_policy_hash", - "submissions", - "workstream_tasks", - [ - "task_id", - "locked_effective_project_submission_artifact_policy_id", - "locked_effective_project_submission_artifact_policy_hash", - ], - [ - "id", - "locked_effective_project_submission_artifact_policy_id", - "locked_effective_project_submission_artifact_policy_hash", - ], - ) - op.create_foreign_key( - "fk_submissions_task_locked_pre_submit_checker_hash", - "submissions", - "workstream_tasks", - ["task_id", "locked_pre_submit_checker_policy_id", "locked_pre_submit_checker_bundle_hash"], - ["id", "locked_pre_submit_checker_policy_id", "locked_pre_submit_checker_bundle_hash"], - ) - op.create_foreign_key( - "fk_submissions_locked_pre_submit_checker_hash", - "submissions", - "pre_submit_checker_policies", - ["locked_pre_submit_checker_policy_id", "locked_pre_submit_checker_bundle_hash"], - ["id", "compiled_bundle_hash"], - ) - op.create_index( - "ix_submissions_locked_source_snapshot", - "submissions", - ["locked_guide_source_snapshot_id"], - unique=False, - ) - op.create_index( - "ix_submissions_locked_effective_policy_hash", - "submissions", - ["locked_effective_project_submission_artifact_policy_hash"], - unique=False, - ) - op.create_index( - "ix_submissions_locked_pre_submit_checker_hash", - "submissions", - ["locked_pre_submit_checker_bundle_hash"], - unique=False, - ) - - -def downgrade() -> None: - """Remove locked project policy context from tasks and submissions.""" - op.drop_index("ix_submissions_locked_pre_submit_checker_hash", table_name="submissions") - op.drop_index("ix_submissions_locked_effective_policy_hash", table_name="submissions") - op.drop_index("ix_submissions_locked_source_snapshot", table_name="submissions") - op.drop_constraint( - "fk_submissions_locked_pre_submit_checker_hash", - "submissions", - type_="foreignkey", - ) - op.drop_constraint( - "fk_submissions_task_locked_pre_submit_checker_hash", - "submissions", - type_="foreignkey", - ) - op.drop_constraint( - "fk_submissions_task_locked_effective_policy_hash", - "submissions", - type_="foreignkey", - ) - op.drop_constraint( - "fk_submissions_task_locked_source_snapshot_hash", - "submissions", - type_="foreignkey", - ) - op.drop_constraint( - "fk_submissions_locked_effective_policy_hash", - "submissions", - type_="foreignkey", - ) - op.drop_constraint( - "fk_submissions_locked_source_snapshot_hash", - "submissions", - type_="foreignkey", - ) - op.drop_column("submissions", "locked_pre_submit_checker_bundle_hash") - op.drop_column("submissions", "locked_pre_submit_checker_policy_id") - op.drop_column("submissions", "locked_effective_project_submission_artifact_policy_hash") - op.drop_column("submissions", "locked_effective_project_submission_artifact_policy_id") - op.drop_column("submissions", "locked_guide_source_snapshot_hash") - op.drop_column("submissions", "locked_guide_source_snapshot_id") - - op.drop_index("ix_workstream_tasks_locked_pre_submit_checker_hash", table_name="workstream_tasks") - op.drop_index("ix_workstream_tasks_locked_effective_policy_hash", table_name="workstream_tasks") - op.drop_index("ix_workstream_tasks_locked_source_snapshot", table_name="workstream_tasks") - op.drop_constraint( - "fk_workstream_tasks_locked_pre_submit_checker_hash", - "workstream_tasks", - type_="foreignkey", - ) - op.drop_constraint( - "fk_workstream_tasks_locked_effective_policy_hash", - "workstream_tasks", - type_="foreignkey", - ) - op.drop_constraint( - "fk_workstream_tasks_locked_source_snapshot_hash", - "workstream_tasks", - type_="foreignkey", - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_pre_submit_checker_hash", - "workstream_tasks", - type_="unique", - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_effective_policy_hash", - "workstream_tasks", - type_="unique", - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_source_snapshot_hash", - "workstream_tasks", - type_="unique", - ) - op.drop_column("workstream_tasks", "locked_pre_submit_checker_bundle_hash") - op.drop_column("workstream_tasks", "locked_pre_submit_checker_policy_id") - op.drop_column( - "workstream_tasks", - "locked_effective_project_submission_artifact_policy_hash", - ) - op.drop_column( - "workstream_tasks", - "locked_effective_project_submission_artifact_policy_id", - ) - op.drop_column("workstream_tasks", "locked_guide_source_snapshot_hash") - op.drop_column("workstream_tasks", "locked_guide_source_snapshot_id") - op.drop_constraint( - "uq_pre_submit_checker_policies_id_compiled_bundle_hash", - "pre_submit_checker_policies", - type_="unique", - ) diff --git a/backend/alembic/versions/0008_post_submit_checker_policy_provenance.py b/backend/alembic/versions/0008_post_submit_checker_policy_provenance.py deleted file mode 100644 index 10bad8d18..000000000 --- a/backend/alembic/versions/0008_post_submit_checker_policy_provenance.py +++ /dev/null @@ -1,298 +0,0 @@ -"""post submit checker policy provenance - -Revision ID: 0008_post_submit_checker_policy -Revises: 0007_task_locked_context -Create Date: 2026-07-03 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0008_post_submit_checker_policy" -down_revision = "0007_task_locked_context" -branch_labels = None -depends_on = None - - -def _preflight_no_pre_provenance_runtime_rows() -> None: - """Stop before schema changes when runtime rows cannot receive trusted provenance.""" - bind = op.get_bind() - counts = { - "non_draft_tasks": bind.scalar( - sa.text("select count(*) from workstream_tasks where status <> 'draft'") - ), - "submissions": bind.scalar(sa.text("select count(*) from submissions")), - "checker_runs": bind.scalar(sa.text("select count(*) from checker_runs")), - } - if any(counts.values()): - detail = ", ".join(f"{name}={count}" for name, count in counts.items()) - raise RuntimeError( - "0008_post_submit_checker_policy cannot infer locked post-submit " - "checker policy provenance for existing v0.1 runtime rows. " - f"Found {detail}. Export or reset those runtime rows before upgrading." - ) - - -def upgrade() -> None: - """Add explicit post-submit checker policy provenance locks.""" - _preflight_no_pre_provenance_runtime_rows() - - op.add_column( - "checker_policies", - sa.Column("policy_hash", sa.String(length=71), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("policy_body", sa.JSON(), nullable=True), - ) - op.create_unique_constraint( - "uq_checker_policies_id_version_hash", - "checker_policies", - ["id", "guide_version", "policy_hash"], - ) - op.create_check_constraint( - "policy_hash_shape", - "checker_policies", - "policy_hash is null or policy_hash ~ '^sha256:[0-9a-f]{64}$'", - ) - - for table_name in ("workstream_tasks", "submissions", "checker_runs"): - op.add_column( - table_name, - sa.Column( - "locked_post_submit_checker_policy_id", - sa.String(length=36), - nullable=True, - ), - ) - op.add_column( - table_name, - sa.Column( - "locked_post_submit_checker_policy_version", - sa.String(length=50), - nullable=True, - ), - ) - op.add_column( - table_name, - sa.Column( - "locked_post_submit_checker_policy_hash", - sa.String(length=71), - nullable=True, - ), - ) - op.add_column( - table_name, - sa.Column( - "locked_post_submit_checker_policy_body", - sa.JSON(), - nullable=True, - ), - ) - op.create_foreign_key( - f"fk_{table_name}_locked_post_submit_policy_hash", - table_name, - "checker_policies", - [ - "locked_post_submit_checker_policy_id", - "locked_post_submit_checker_policy_version", - "locked_post_submit_checker_policy_hash", - ], - ["id", "guide_version", "policy_hash"], - ) - op.create_index( - f"ix_{table_name}_locked_post_submit_policy_hash", - table_name, - ["locked_post_submit_checker_policy_hash"], - unique=False, - ) - - op.create_check_constraint( - "post_submit_policy_lock_complete", - "workstream_tasks", - """ - status = 'draft' - or ( - locked_post_submit_checker_policy_id is not null - and locked_post_submit_checker_policy_version is not null - and locked_post_submit_checker_policy_hash is not null - and locked_post_submit_checker_policy_body is not null - ) - """, - ) - op.create_check_constraint( - "post_submit_policy_lock_complete", - "submissions", - """ - locked_post_submit_checker_policy_id is not null - and locked_post_submit_checker_policy_version is not null - and locked_post_submit_checker_policy_hash is not null - and locked_post_submit_checker_policy_body is not null - """, - ) - op.create_check_constraint( - "post_submit_policy_lock_complete", - "checker_runs", - """ - locked_post_submit_checker_policy_id is not null - and locked_post_submit_checker_policy_version is not null - and locked_post_submit_checker_policy_hash is not null - and locked_post_submit_checker_policy_body is not null - """, - ) - - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_post_submit_policy_hash", - "workstream_tasks", - [ - "id", - "locked_post_submit_checker_policy_id", - "locked_post_submit_checker_policy_version", - "locked_post_submit_checker_policy_hash", - ], - ) - op.create_foreign_key( - "fk_submissions_task_locked_post_submit_policy_hash", - "submissions", - "workstream_tasks", - [ - "task_id", - "locked_post_submit_checker_policy_id", - "locked_post_submit_checker_policy_version", - "locked_post_submit_checker_policy_hash", - ], - [ - "id", - "locked_post_submit_checker_policy_id", - "locked_post_submit_checker_policy_version", - "locked_post_submit_checker_policy_hash", - ], - ) - op.create_unique_constraint( - "uq_submissions_id_locked_post_submit_policy_hash", - "submissions", - [ - "id", - "locked_post_submit_checker_policy_id", - "locked_post_submit_checker_policy_version", - "locked_post_submit_checker_policy_hash", - ], - ) - op.create_foreign_key( - "fk_checker_runs_submission_locked_post_submit_policy_hash", - "checker_runs", - "submissions", - [ - "submission_id", - "locked_post_submit_checker_policy_id", - "locked_post_submit_checker_policy_version", - "locked_post_submit_checker_policy_hash", - ], - [ - "id", - "locked_post_submit_checker_policy_id", - "locked_post_submit_checker_policy_version", - "locked_post_submit_checker_policy_hash", - ], - ) - - -def downgrade() -> None: - """Remove explicit post-submit checker policy provenance locks.""" - op.drop_constraint( - "post_submit_policy_lock_complete", - "checker_runs", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "ck_checker_runs_post_submit_policy_lock_complete", - "checker_runs", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "post_submit_policy_lock_complete", - "submissions", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "ck_submissions_post_submit_policy_lock_complete", - "submissions", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "post_submit_policy_lock_complete", - "workstream_tasks", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "ck_workstream_tasks_post_submit_policy_lock_complete", - "workstream_tasks", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "fk_checker_runs_submission_locked_post_submit_policy_hash", - "checker_runs", - type_="foreignkey", - ) - op.drop_constraint( - "uq_submissions_id_locked_post_submit_policy_hash", - "submissions", - type_="unique", - ) - op.drop_constraint( - "fk_submissions_task_locked_post_submit_policy_hash", - "submissions", - type_="foreignkey", - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_post_submit_policy_hash", - "workstream_tasks", - type_="unique", - ) - for table_name in ("checker_runs", "submissions", "workstream_tasks"): - op.drop_index( - f"ix_{table_name}_locked_post_submit_policy_hash", - table_name=table_name, - ) - op.drop_constraint( - f"fk_{table_name}_locked_post_submit_policy_hash", - table_name, - type_="foreignkey", - ) - op.execute( - sa.text( - f"alter table {table_name} " - "drop column if exists locked_post_submit_checker_policy_body" - ) - ) - op.drop_column(table_name, "locked_post_submit_checker_policy_hash") - op.drop_column(table_name, "locked_post_submit_checker_policy_version") - op.drop_column(table_name, "locked_post_submit_checker_policy_id") - - op.drop_constraint( - "policy_hash_shape", - "checker_policies", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "ck_checker_policies_policy_hash_shape", - "checker_policies", - type_="check", - if_exists=True, - ) - op.drop_constraint( - "uq_checker_policies_id_version_hash", - "checker_policies", - type_="unique", - ) - op.execute(sa.text("alter table checker_policies drop column if exists policy_body")) - op.drop_column("checker_policies", "policy_hash") diff --git a/backend/alembic/versions/0009_evaluation_pending_status.py b/backend/alembic/versions/0009_evaluation_pending_status.py deleted file mode 100644 index 991a38ae4..000000000 --- a/backend/alembic/versions/0009_evaluation_pending_status.py +++ /dev/null @@ -1,21 +0,0 @@ -"""evaluation pending task status marker - -Revision ID: 0009_evaluation_pending_status -Revises: 0008_post_submit_checker_policy -Create Date: 2026-07-04 -""" - -from __future__ import annotations - -revision = "0009_evaluation_pending_status" -down_revision = "0008_post_submit_checker_policy" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """No-op marker; the current schema only uses evaluation_pending.""" - - -def downgrade() -> None: - """No-op downgrade; discarded task status names are not restored.""" diff --git a/backend/alembic/versions/0010_project_guide_contract_marker.py b/backend/alembic/versions/0010_project_guide_contract_marker.py deleted file mode 100644 index d39301bfb..000000000 --- a/backend/alembic/versions/0010_project_guide_contract_marker.py +++ /dev/null @@ -1,21 +0,0 @@ -"""project guide contract marker - -Revision ID: 0010_guide_cleanup -Revises: 0009_evaluation_pending_status -Create Date: 2026-07-05 -""" - -from __future__ import annotations - -revision = "0010_guide_cleanup" -down_revision = "0009_evaluation_pending_status" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """No-op marker after squashing removed construction-state guide fields.""" - - -def downgrade() -> None: - """No-op downgrade; discarded construction-state guide fields are not restored.""" diff --git a/backend/alembic/versions/0011_task_artifact_contract_marker.py b/backend/alembic/versions/0011_task_artifact_contract_marker.py deleted file mode 100644 index 7c499b189..000000000 --- a/backend/alembic/versions/0011_task_artifact_contract_marker.py +++ /dev/null @@ -1,21 +0,0 @@ -"""task artifact contract marker - -Revision ID: 0011_task_artifact_cleanup -Revises: 0010_guide_cleanup -Create Date: 2026-07-05 -""" - -from __future__ import annotations - -revision = "0011_task_artifact_cleanup" -down_revision = "0010_guide_cleanup" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """No-op marker after squashing removed task-owned artifact fields.""" - - -def downgrade() -> None: - """No-op downgrade; discarded task-owned artifact fields are not restored.""" diff --git a/backend/alembic/versions/0012_actor_identity_profile_registry.py b/backend/alembic/versions/0012_actor_identity_profile_registry.py deleted file mode 100644 index c69adbfb8..000000000 --- a/backend/alembic/versions/0012_actor_identity_profile_registry.py +++ /dev/null @@ -1,125 +0,0 @@ -"""actor identity profile registry - -Revision ID: 0012_actor_identity_profiles -Revises: 0011_task_artifact_cleanup -Create Date: 2026-07-06 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0012_actor_identity_profiles" -down_revision = "0011_task_artifact_cleanup" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Create actor registry tables and remove obsolete profile stores.""" - op.create_table( - "actor_identities", - sa.Column("actor_id", sa.String(length=100), nullable=False), - sa.Column("external_subject", sa.String(length=200), nullable=False), - sa.Column("external_issuer", sa.String(length=200), nullable=False), - sa.Column("display_name", sa.String(length=200), nullable=True), - sa.Column("email", sa.String(length=320), nullable=True), - sa.Column("last_seen_roles", sa.JSON(), nullable=False), - sa.Column("last_claim_snapshot", sa.JSON(), nullable=False), - sa.Column("auth_source", sa.String(length=50), nullable=False), - sa.Column("is_dev_auth", sa.Boolean(), nullable=False), - sa.Column("first_seen_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("last_seen_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("actor_id", name=op.f("pk_actor_identities")), - sa.UniqueConstraint( - "external_issuer", - "external_subject", - name="uq_actor_identities_external_identity", - ), - ) - op.create_table( - "actor_profiles", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("actor_id", sa.String(length=100), nullable=False), - sa.Column("profile_type", sa.String(length=50), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("skill_tags", sa.JSON(), nullable=False), - sa.Column("scope_type", sa.String(length=50), nullable=False), - sa.Column("scope_id", sa.String(length=100), nullable=False), - sa.Column("profile_metadata", sa.JSON(), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.CheckConstraint( - "profile_type in ('worker', 'reviewer', 'admin', 'project_manager', 'project_owner')", - name="ck_actor_profiles_profile_type", - ), - sa.CheckConstraint( - "status in ('observed', 'active', 'disabled')", - name="ck_actor_profiles_status", - ), - sa.ForeignKeyConstraint( - ["actor_id"], - ["actor_identities.actor_id"], - name=op.f("fk_actor_profiles_actor_id_actor_identities"), - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_actor_profiles")), - sa.UniqueConstraint( - "actor_id", - "profile_type", - "scope_type", - "scope_id", - name="uq_actor_profiles_actor_type_scope", - ), - ) - op.create_index(op.f("ix_actor_profiles_actor_id"), "actor_profiles", ["actor_id"], unique=False) - op.create_index(op.f("ix_actor_profiles_profile_type"), "actor_profiles", ["profile_type"], unique=False) - op.create_index(op.f("ix_actor_profiles_status"), "actor_profiles", ["status"], unique=False) - - op.drop_index(op.f("ix_reviewer_profiles_status"), table_name="reviewer_profiles") - op.drop_table("reviewer_profiles") - op.drop_index(op.f("ix_worker_profiles_status"), table_name="worker_profiles") - op.drop_table("worker_profiles") - - -def downgrade() -> None: - """Restore prior schema shape without preserving obsolete profile data.""" - op.create_table( - "worker_profiles", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("actor_id", sa.String(length=100), nullable=False), - sa.Column("external_subject", sa.String(length=200), nullable=False), - sa.Column("external_issuer", sa.String(length=200), nullable=False), - sa.Column("display_name", sa.String(length=200), nullable=True), - sa.Column("email", sa.String(length=320), nullable=True), - sa.Column("skill_tags", sa.JSON(), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("id", name=op.f("pk_worker_profiles")), - sa.UniqueConstraint("actor_id", name=op.f("uq_worker_profiles_actor_id")), - ) - op.create_index(op.f("ix_worker_profiles_status"), "worker_profiles", ["status"], unique=False) - op.create_table( - "reviewer_profiles", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("actor_id", sa.String(length=100), nullable=False), - sa.Column("external_subject", sa.String(length=200), nullable=False), - sa.Column("external_issuer", sa.String(length=200), nullable=False), - sa.Column("display_name", sa.String(length=200), nullable=True), - sa.Column("email", sa.String(length=320), nullable=True), - sa.Column("skill_tags", sa.JSON(), nullable=False), - sa.Column("status", sa.String(length=30), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("id", name=op.f("pk_reviewer_profiles")), - sa.UniqueConstraint("actor_id", name=op.f("uq_reviewer_profiles_actor_id")), - ) - op.create_index(op.f("ix_reviewer_profiles_status"), "reviewer_profiles", ["status"], unique=False) - - op.drop_index(op.f("ix_actor_profiles_status"), table_name="actor_profiles") - op.drop_index(op.f("ix_actor_profiles_profile_type"), table_name="actor_profiles") - op.drop_index(op.f("ix_actor_profiles_actor_id"), table_name="actor_profiles") - op.drop_table("actor_profiles") - op.drop_table("actor_identities") diff --git a/backend/alembic/versions/0013_project_setup_runs.py b/backend/alembic/versions/0013_project_setup_runs.py deleted file mode 100644 index f7d424173..000000000 --- a/backend/alembic/versions/0013_project_setup_runs.py +++ /dev/null @@ -1,166 +0,0 @@ -"""project setup run ledger - -Revision ID: 0013_project_setup_runs -Revises: 0012_actor_identity_profiles -Create Date: 2026-07-07 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0013_project_setup_runs" -down_revision = "0012_actor_identity_profiles" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Create the automatic project setup run ledger.""" - op.create_table( - "project_setup_runs", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_id", sa.String(length=36), nullable=False), - sa.Column("guide_version", sa.String(length=50), nullable=False), - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - sa.Column("source_snapshot_hash", sa.String(length=71), nullable=False), - sa.Column("celery_task_id", sa.String(length=155), nullable=True), - sa.Column("status", sa.String(length=50), nullable=False), - sa.Column("current_step", sa.String(length=100), nullable=False), - sa.Column("output_sufficiency_report_id", sa.String(length=36), nullable=True), - sa.Column("output_submission_artifact_policy_id", sa.String(length=36), nullable=True), - sa.Column("error_code", sa.String(length=100), nullable=True), - sa.Column("error_summary", sa.Text(), nullable=True), - sa.Column("created_by", sa.String(length=100), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column("started_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("finished_at", sa.DateTime(timezone=True), nullable=True), - sa.CheckConstraint( - "status in (" - "'queued', " - "'enqueue_failed', " - "'running_sufficiency_agent', " - "'sufficiency_blocked', " - "'running_policy_derivation_agent', " - "'policy_draft_ready', " - "'setup_blocked', " - "'failed'" - ")", - name="ck_project_setup_runs_status", - ), - sa.ForeignKeyConstraint( - ["guide_id"], - ["project_guides.id"], - name=op.f("fk_project_setup_runs_guide_id_project_guides"), - ), - sa.ForeignKeyConstraint( - ["output_submission_artifact_policy_id"], - ["submission_artifact_policies.id"], - name="fk_project_setup_runs_submission_artifact_policy", - ), - sa.ForeignKeyConstraint( - ["output_sufficiency_report_id"], - ["guide_sufficiency_reports.id"], - name="fk_project_setup_runs_sufficiency_report", - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name=op.f("fk_project_setup_runs_project_id_projects"), - ), - sa.ForeignKeyConstraint( - ["project_id", "guide_version"], - ["project_guides.project_id", "project_guides.version"], - name="fk_project_setup_runs_project_guide", - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id"], - ["guide_source_snapshots.id"], - name=op.f("fk_project_setup_runs_source_snapshot_id_guide_source_snapshots"), - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id", "source_snapshot_hash"], - ["guide_source_snapshots.id", "guide_source_snapshots.bundle_hash"], - name="fk_project_setup_runs_source_snapshot_hash", - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_project_setup_runs")), - ) - op.create_index( - op.f("ix_project_setup_runs_celery_task_id"), - "project_setup_runs", - ["celery_task_id"], - unique=False, - ) - op.create_index( - op.f("ix_project_setup_runs_guide_id"), - "project_setup_runs", - ["guide_id"], - unique=False, - ) - op.create_index( - op.f("ix_project_setup_runs_output_submission_artifact_policy_id"), - "project_setup_runs", - ["output_submission_artifact_policy_id"], - unique=False, - ) - op.create_index( - op.f("ix_project_setup_runs_output_sufficiency_report_id"), - "project_setup_runs", - ["output_sufficiency_report_id"], - unique=False, - ) - op.create_index( - op.f("ix_project_setup_runs_project_id"), - "project_setup_runs", - ["project_id"], - unique=False, - ) - op.create_index( - op.f("ix_project_setup_runs_source_snapshot_id"), - "project_setup_runs", - ["source_snapshot_id"], - unique=False, - ) - op.create_index( - op.f("ix_project_setup_runs_status"), - "project_setup_runs", - ["status"], - unique=False, - ) - - -def downgrade() -> None: - """Drop the automatic project setup run ledger.""" - op.drop_index(op.f("ix_project_setup_runs_status"), table_name="project_setup_runs") - op.drop_index( - op.f("ix_project_setup_runs_source_snapshot_id"), - table_name="project_setup_runs", - ) - op.drop_index(op.f("ix_project_setup_runs_project_id"), table_name="project_setup_runs") - op.drop_index( - op.f("ix_project_setup_runs_output_sufficiency_report_id"), - table_name="project_setup_runs", - ) - op.drop_index( - op.f("ix_project_setup_runs_output_submission_artifact_policy_id"), - table_name="project_setup_runs", - ) - op.drop_index(op.f("ix_project_setup_runs_guide_id"), table_name="project_setup_runs") - op.drop_index( - op.f("ix_project_setup_runs_celery_task_id"), - table_name="project_setup_runs", - ) - op.drop_table("project_setup_runs") diff --git a/backend/alembic/versions/0014_post_submit_setup_continuation.py b/backend/alembic/versions/0014_post_submit_setup_continuation.py deleted file mode 100644 index a68969f44..000000000 --- a/backend/alembic/versions/0014_post_submit_setup_continuation.py +++ /dev/null @@ -1,350 +0,0 @@ -"""post-submit setup continuation state - -Revision ID: 0014_post_submit_setup -Revises: 0013_project_setup_runs -Create Date: 2026-07-09 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0014_post_submit_setup" -down_revision = "0013_project_setup_runs" -branch_labels = None -depends_on = None - - -def _preflight_no_legacy_checker_policy_rows() -> None: - """Reject old checker rows that cannot be bound to setup provenance.""" - bind = op.get_bind() - count = bind.scalar(sa.text("select count(*) from checker_policies")) - if count: - raise RuntimeError( - "0014_post_submit_setup cannot infer setup provenance for existing " - "checker_policies rows. Reset those draft-era rows before upgrading." - ) - - -def upgrade() -> None: - """Add post-submit setup continuation outputs to setup runs.""" - _preflight_no_legacy_checker_policy_rows() - - op.add_column( - "checker_policies", - sa.Column("guide_id", sa.String(length=36), nullable=False), - ) - op.add_column( - "checker_policies", - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - ) - op.add_column( - "checker_policies", - sa.Column("source_snapshot_hash", sa.String(length=71), nullable=False), - ) - op.add_column( - "checker_policies", - sa.Column("effective_policy_id", sa.String(length=36), nullable=False), - ) - op.add_column( - "checker_policies", - sa.Column("effective_policy_hash", sa.String(length=71), nullable=False), - ) - op.add_column( - "checker_policies", - sa.Column("pre_submit_checker_policy_id", sa.String(length=36), nullable=False), - ) - op.add_column( - "checker_policies", - sa.Column("pre_submit_checker_bundle_hash", sa.String(length=71), nullable=False), - ) - op.add_column( - "checker_policies", - sa.Column( - "lifecycle_status", - sa.String(length=30), - nullable=False, - server_default="compiled", - ), - ) - op.alter_column("checker_policies", "lifecycle_status", server_default=None) - op.add_column( - "checker_policies", - sa.Column("approved_by_role", sa.String(length=50), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("approved_by_actor", sa.String(length=100), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("approved_at", sa.DateTime(timezone=True), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("created_by", sa.String(length=100), nullable=False), - ) - op.create_foreign_key( - op.f("fk_checker_policies_guide_id_project_guides"), - "checker_policies", - "project_guides", - ["guide_id"], - ["id"], - ) - op.create_foreign_key( - op.f("fk_checker_policies_source_snapshot_hash"), - "checker_policies", - "guide_source_snapshots", - ["source_snapshot_id", "source_snapshot_hash"], - ["id", "bundle_hash"], - ) - op.create_foreign_key( - op.f("fk_checker_policies_effective_policy_hash"), - "checker_policies", - "effective_project_submission_artifact_policies", - ["effective_policy_id", "effective_policy_hash"], - ["id", "effective_policy_hash"], - ) - op.create_foreign_key( - op.f("fk_checker_policies_pre_submit_checker_hash"), - "checker_policies", - "pre_submit_checker_policies", - ["pre_submit_checker_policy_id", "pre_submit_checker_bundle_hash"], - ["id", "compiled_bundle_hash"], - ) - op.create_index( - op.f("ix_checker_policies_guide_id"), - "checker_policies", - ["guide_id"], - unique=False, - ) - op.create_index( - op.f("ix_checker_policies_source_snapshot_id"), - "checker_policies", - ["source_snapshot_id"], - unique=False, - ) - op.create_index( - op.f("ix_checker_policies_effective_policy_id"), - "checker_policies", - ["effective_policy_id"], - unique=False, - ) - op.create_index( - op.f("ix_checker_policies_effective_policy_hash"), - "checker_policies", - ["effective_policy_hash"], - unique=False, - ) - op.create_index( - op.f("ix_checker_policies_pre_submit_checker_policy_id"), - "checker_policies", - ["pre_submit_checker_policy_id"], - unique=False, - ) - op.create_index( - op.f("ix_checker_policies_pre_submit_checker_bundle_hash"), - "checker_policies", - ["pre_submit_checker_bundle_hash"], - unique=False, - ) - op.create_check_constraint( - "lifecycle_status", - "checker_policies", - "lifecycle_status in ('compiled', 'approved', 'superseded')", - ) - op.create_check_constraint( - "approval_provenance", - "checker_policies", - """ - lifecycle_status != 'approved' - or ( - approved_by_role in ('admin', 'project_manager') - and approved_by_actor is not null - and approved_at is not null - ) - """, - ) - op.add_column( - "project_setup_runs", - sa.Column("output_post_submit_checker_policy_id", sa.String(length=36), nullable=True), - ) - op.add_column( - "project_setup_runs", - sa.Column("post_submit_derivation_summary", sa.JSON(), nullable=True), - ) - op.create_foreign_key( - "fk_project_setup_runs_post_submit_checker_policy", - "project_setup_runs", - "checker_policies", - ["output_post_submit_checker_policy_id"], - ["id"], - ) - op.create_index( - op.f("ix_project_setup_runs_output_post_submit_checker_policy_id"), - "project_setup_runs", - ["output_post_submit_checker_policy_id"], - unique=False, - ) - op.drop_constraint( - "ck_project_setup_runs_status", - "project_setup_runs", - type_="check", - ) - op.create_check_constraint( - "ck_project_setup_runs_status", - "project_setup_runs", - "status in (" - "'queued', " - "'enqueue_failed', " - "'running_sufficiency_agent', " - "'sufficiency_blocked', " - "'running_policy_derivation_agent', " - "'policy_draft_ready', " - "'running_post_submit_derivation_agent', " - "'post_submit_setup_blocked', " - "'post_submit_policy_compiled', " - "'setup_blocked', " - "'failed'" - ")", - ) - - -def downgrade() -> None: - """Remove post-submit setup continuation outputs.""" - op.drop_constraint( - "ck_project_setup_runs_status", - "project_setup_runs", - type_="check", - ) - op.execute( - sa.text( - "update project_setup_runs set status = 'setup_blocked' " - "where status in (" - "'running_post_submit_derivation_agent', " - "'post_submit_setup_blocked'" - ")" - ) - ) - op.execute( - sa.text( - "update project_setup_runs set status = 'policy_draft_ready' " - "where status = 'post_submit_policy_compiled'" - ) - ) - op.create_check_constraint( - "ck_project_setup_runs_status", - "project_setup_runs", - "status in (" - "'queued', " - "'enqueue_failed', " - "'running_sufficiency_agent', " - "'sufficiency_blocked', " - "'running_policy_derivation_agent', " - "'policy_draft_ready', " - "'setup_blocked', " - "'failed'" - ")", - ) - op.execute( - sa.text( - "drop index if exists ix_project_setup_runs_output_post_submit_checker_policy_id" - ) - ) - op.execute( - sa.text( - "alter table project_setup_runs " - "drop constraint if exists fk_project_setup_runs_post_submit_checker_policy" - ) - ) - op.execute( - sa.text("alter table project_setup_runs drop column if exists post_submit_derivation_summary") - ) - op.execute( - sa.text( - "alter table project_setup_runs " - "drop column if exists output_post_submit_checker_policy_id" - ) - ) - op.execute( - sa.text( - "alter table checker_policies " - "drop constraint if exists ck_checker_policies_approval_provenance" - ) - ) - op.execute( - sa.text( - "alter table checker_policies " - "drop constraint if exists ck_checker_policies_ck_checker_policies_approval_provenance" - ) - ) - op.execute( - sa.text( - "alter table checker_policies " - "drop constraint if exists ck_checker_policies_lifecycle_status" - ) - ) - op.execute( - sa.text( - "alter table checker_policies " - "drop constraint if exists ck_checker_policies_ck_checker_policies_lifecycle_status" - ) - ) - op.execute(sa.text("alter table checker_policies drop column if exists approved_at")) - op.execute(sa.text("alter table checker_policies drop column if exists approved_by_actor")) - op.execute(sa.text("alter table checker_policies drop column if exists approved_by_role")) - op.execute(sa.text("alter table checker_policies drop column if exists lifecycle_status")) - op.execute( - sa.text( - "drop index if exists ix_checker_policies_pre_submit_checker_bundle_hash" - ) - ) - op.execute( - sa.text( - "drop index if exists ix_checker_policies_pre_submit_checker_policy_id" - ) - ) - op.execute(sa.text("drop index if exists ix_checker_policies_effective_policy_hash")) - op.execute(sa.text("drop index if exists ix_checker_policies_effective_policy_id")) - op.execute(sa.text("drop index if exists ix_checker_policies_source_snapshot_id")) - op.execute(sa.text("drop index if exists ix_checker_policies_guide_id")) - op.drop_constraint( - op.f("fk_checker_policies_pre_submit_checker_hash"), - "checker_policies", - type_="foreignkey", - ) - op.drop_constraint( - op.f("fk_checker_policies_effective_policy_hash"), - "checker_policies", - type_="foreignkey", - ) - op.drop_constraint( - op.f("fk_checker_policies_source_snapshot_hash"), - "checker_policies", - type_="foreignkey", - ) - op.execute( - sa.text( - "alter table checker_policies " - "drop constraint if exists fk_checker_policies_guide_id_project_guides" - ) - ) - op.execute(sa.text("alter table checker_policies drop column if exists created_by")) - op.execute( - sa.text( - "alter table checker_policies " - "drop column if exists pre_submit_checker_bundle_hash" - ) - ) - op.execute( - sa.text( - "alter table checker_policies " - "drop column if exists pre_submit_checker_policy_id" - ) - ) - op.execute(sa.text("alter table checker_policies drop column if exists effective_policy_hash")) - op.execute(sa.text("alter table checker_policies drop column if exists effective_policy_id")) - op.execute(sa.text("alter table checker_policies drop column if exists source_snapshot_hash")) - op.execute(sa.text("alter table checker_policies drop column if exists source_snapshot_id")) - op.execute(sa.text("alter table checker_policies drop column if exists guide_id")) diff --git a/backend/alembic/versions/0015_post_submit_policy_correction_audit.py b/backend/alembic/versions/0015_post_submit_policy_correction_audit.py deleted file mode 100644 index 4f9063c59..000000000 --- a/backend/alembic/versions/0015_post_submit_policy_correction_audit.py +++ /dev/null @@ -1,119 +0,0 @@ -"""preserve post-submit policy correction audit history - -Revision ID: 0015_post_submit_correction -Revises: 0014_post_submit_setup -Create Date: 2026-07-11 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0015_post_submit_correction" -down_revision = "0014_post_submit_setup" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Make rejected compiled policies append-only correction records.""" - op.add_column( - "checker_policies", - sa.Column("supersedes_policy_id", sa.String(length=36), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("superseded_at", sa.DateTime(timezone=True), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("superseded_by_role", sa.String(length=50), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("superseded_by_actor", sa.String(length=100), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("supersession_kind", sa.String(length=50), nullable=True), - ) - op.add_column( - "checker_policies", - sa.Column("supersession_reason", sa.Text(), nullable=True), - ) - op.create_foreign_key( - "fk_checker_policies_supersedes_policy_id", - "checker_policies", - "checker_policies", - ["supersedes_policy_id"], - ["id"], - ) - op.create_index( - op.f("ix_checker_policies_supersedes_policy_id"), - "checker_policies", - ["supersedes_policy_id"], - unique=False, - ) - op.drop_constraint( - "uq_checker_policies_project_version", - "checker_policies", - type_="unique", - ) - op.create_index( - "uq_checker_policies_current_project_version", - "checker_policies", - ["project_id", "guide_version"], - unique=True, - postgresql_where=sa.text("lifecycle_status in ('compiled', 'approved')"), - ) - op.create_check_constraint( - "correction_provenance", - "checker_policies", - """ - lifecycle_status != 'superseded' - or ( - superseded_at is not null - and superseded_by_role in ('admin', 'project_manager') - and superseded_by_actor is not null - and supersession_kind in ('correction_requested', 'upstream_policy_changed') - and supersession_reason is not null - and length(btrim(supersession_reason)) > 0 - ) - """, - ) - - -def downgrade() -> None: - """Restore the single-row checker-policy schema.""" - op.drop_constraint( - "correction_provenance", - "checker_policies", - type_="check", - ) - op.drop_index( - "uq_checker_policies_current_project_version", - table_name="checker_policies", - ) - op.execute(sa.text("update checker_policies set supersedes_policy_id = null")) - op.execute(sa.text("delete from checker_policies where lifecycle_status = 'superseded'")) - op.create_unique_constraint( - "uq_checker_policies_project_version", - "checker_policies", - ["project_id", "guide_version"], - ) - op.drop_index( - op.f("ix_checker_policies_supersedes_policy_id"), - table_name="checker_policies", - ) - op.drop_constraint( - "fk_checker_policies_supersedes_policy_id", - "checker_policies", - type_="foreignkey", - ) - op.drop_column("checker_policies", "supersession_reason") - op.drop_column("checker_policies", "supersession_kind") - op.drop_column("checker_policies", "superseded_by_actor") - op.drop_column("checker_policies", "superseded_by_role") - op.drop_column("checker_policies", "superseded_at") - op.drop_column("checker_policies", "supersedes_policy_id") diff --git a/backend/alembic/versions/0016_artifact_domain_local_adapter.py b/backend/alembic/versions/0016_artifact_domain_local_adapter.py deleted file mode 100644 index bebacc5ef..000000000 --- a/backend/alembic/versions/0016_artifact_domain_local_adapter.py +++ /dev/null @@ -1,382 +0,0 @@ -"""add immutable artifact domain foundation - -Revision ID: 0016_artifact_domain -Revises: 0015_post_submit_correction -Create Date: 2026-07-12 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0016_artifact_domain" -down_revision = "0015_post_submit_correction" -branch_labels = None -depends_on = None - -_ARTIFACT_TABLES = ( - "artifact_operation_receipts", - "artifact_replicas", - "artifact_bindings", - "artifact_upload_items", - "artifact_contents", - "artifact_upload_sessions", -) - - -def upgrade() -> None: - """Create additive artifact records without promoting legacy declarations.""" - op.create_table( - "artifact_upload_sessions", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("actor_id", sa.String(100), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=True), - sa.Column("guide_id", sa.String(36), nullable=True), - sa.Column("permitted_roles", sa.JSON(), nullable=False), - sa.Column("state", sa.String(30), nullable=False), - sa.Column("maximum_bytes", sa.Integer(), nullable=False), - sa.Column("current_bytes", sa.Integer(), nullable=False), - sa.Column("reserved_bytes", sa.Integer(), nullable=False), - sa.Column("maximum_items", sa.Integer(), nullable=False), - sa.Column("current_items", sa.Integer(), nullable=False), - sa.Column("reserved_items", sa.Integer(), nullable=False), - sa.Column("artifact_set_hash", sa.String(71), nullable=True), - sa.Column("expires_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("consumed_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("cas_version", sa.Integer(), nullable=False), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.Column( - "updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], ondelete="RESTRICT"), - sa.CheckConstraint( - "state in ('open', 'sealed', 'consumed', 'expired', 'cancelled')", - name="state", - ), - sa.CheckConstraint( - "maximum_bytes >= 0 and current_bytes >= 0 and reserved_bytes >= 0", - name="byte_counts_nonnegative", - ), - sa.CheckConstraint( - "maximum_items >= 0 and current_items >= 0 and reserved_items >= 0", - name="item_counts_nonnegative", - ), - sa.CheckConstraint( - "current_bytes + reserved_bytes <= maximum_bytes", name="byte_limit" - ), - sa.CheckConstraint( - "current_items + reserved_items <= maximum_items", name="item_limit" - ), - sa.CheckConstraint("cas_version >= 0", name="cas_nonnegative"), - sa.CheckConstraint( - "artifact_set_hash is null or artifact_set_hash ~ '^sha256:[0-9a-f]{64}$'", - name="artifact_set_hash_shape", - ), - sa.CheckConstraint( - "(state = 'consumed') = (consumed_at is not null)", name="consumed_timestamp" - ), - sa.CheckConstraint( - "state not in ('sealed', 'consumed') or artifact_set_hash is not null", - name="sealed_hash_required", - ), - ) - op.create_index("ix_artifact_upload_sessions_actor_id", "artifact_upload_sessions", ["actor_id"]) - op.create_index("ix_artifact_upload_sessions_project_id", "artifact_upload_sessions", ["project_id"]) - op.create_index("ix_artifact_upload_sessions_task_id", "artifact_upload_sessions", ["task_id"]) - op.create_index("ix_artifact_upload_sessions_guide_id", "artifact_upload_sessions", ["guide_id"]) - op.create_index("ix_artifact_upload_sessions_state", "artifact_upload_sessions", ["state"]) - - op.create_table( - "artifact_contents", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("sha256", sa.String(71), nullable=False), - sa.Column("byte_count", sa.Integer(), nullable=False), - sa.Column("media_type", sa.String(200), nullable=True), - sa.Column("normalized_display_name", sa.String(500), nullable=True), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.UniqueConstraint("sha256", "byte_count", name="uq_artifact_content_digest_size"), - sa.CheckConstraint("sha256 ~ '^sha256:[0-9a-f]{64}$'", name="sha256_shape"), - sa.CheckConstraint("byte_count >= 0", name="byte_count_nonnegative"), - ) - op.create_index("ix_artifact_contents_sha256", "artifact_contents", ["sha256"]) - - op.create_table( - "artifact_upload_items", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("session_id", sa.String(36), nullable=False), - sa.Column("logical_role", sa.String(100), nullable=False), - sa.Column("display_name", sa.String(500), nullable=False), - sa.Column("media_type", sa.String(200), nullable=True), - sa.Column("reserved_bytes", sa.Integer(), nullable=False), - sa.Column("expected_sha256", sa.String(71), nullable=True), - sa.Column("expected_size", sa.Integer(), nullable=True), - sa.Column("idempotency_key", sa.String(200), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("state", sa.String(30), nullable=False), - sa.Column("cas_version", sa.Integer(), nullable=False), - sa.Column("provider_operation_reference", sa.String(200), nullable=True), - sa.Column("content_id", sa.String(36), nullable=True), - sa.Column("error_code", sa.String(100), nullable=True), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.Column( - "updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.ForeignKeyConstraint(["session_id"], ["artifact_upload_sessions.id"], ondelete="CASCADE"), - sa.ForeignKeyConstraint(["content_id"], ["artifact_contents.id"], ondelete="RESTRICT"), - sa.UniqueConstraint("session_id", "idempotency_key", name="uq_artifact_item_operation"), - sa.CheckConstraint( - "state in ('reserved', 'uploading', 'provider_committed', " - "'replay_required', 'ready', 'failed', 'cancelled')", - name="state", - ), - sa.CheckConstraint( - "reserved_bytes >= 0 and cas_version >= 0 and " - "(expected_size is null or expected_size >= 0)", - name="counts_nonnegative", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", name="request_digest_shape" - ), - sa.CheckConstraint( - "expected_sha256 is null or expected_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="expected_sha256_shape", - ), - sa.CheckConstraint( - "(state = 'ready') = " - "(content_id is not null and provider_operation_reference is not null)", - name="ready_result_required", - ), - sa.CheckConstraint("state != 'failed' or error_code is not null", name="failed_error_required"), - ) - op.create_index("ix_artifact_upload_items_session_id", "artifact_upload_items", ["session_id"]) - op.create_index("ix_artifact_upload_items_content_id", "artifact_upload_items", ["content_id"]) - op.create_index("ix_artifact_upload_items_state", "artifact_upload_items", ["state"]) - - op.create_table( - "artifact_bindings", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("resource_type", sa.String(80), nullable=False), - sa.Column("resource_id", sa.String(100), nullable=False), - sa.Column("logical_role", sa.String(100), nullable=False), - sa.Column("scope_version", sa.Integer(), nullable=False), - sa.Column("actor_id", sa.String(100), nullable=False), - sa.Column("attribution_type", sa.String(30), nullable=False), - sa.Column("supersedes_binding_id", sa.String(36), nullable=True), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.ForeignKeyConstraint(["content_id"], ["artifact_contents.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["supersedes_binding_id"], ["artifact_bindings.id"], ondelete="RESTRICT" - ), - sa.UniqueConstraint( - "project_id", "resource_type", "resource_id", "logical_role", "scope_version", - name="uq_artifact_binding_scope_version", - ), - sa.UniqueConstraint("supersedes_binding_id", name="uq_artifact_binding_supersedes"), - sa.CheckConstraint("scope_version > 0", name="scope_version_positive"), - sa.CheckConstraint( - "(scope_version = 1 and supersedes_binding_id is null) or " - "(scope_version > 1 and supersedes_binding_id is not null)", - name="scope_version_predecessor", - ), - ) - op.create_index("ix_artifact_bindings_content_id", "artifact_bindings", ["content_id"]) - op.create_index("ix_artifact_bindings_project_id", "artifact_bindings", ["project_id"]) - op.create_index("ix_artifact_bindings_supersedes_binding_id", "artifact_bindings", ["supersedes_binding_id"]) - op.create_index( - "ix_artifact_bindings_scope", - "artifact_bindings", - ["project_id", "resource_type", "resource_id", "logical_role", sa.text("scope_version DESC")], - ) - - op.create_table( - "artifact_replicas", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("adapter", sa.String(50), nullable=False), - sa.Column("provider_artifact_id", sa.String(200), nullable=False), - sa.Column("provider_manifest_id", sa.String(200), nullable=True), - sa.Column("verification_state", sa.String(30), nullable=False), - sa.Column("retention_state", sa.String(30), nullable=False), - sa.Column("availability_state", sa.String(30), nullable=False), - sa.Column("integrity_state", sa.String(30), nullable=False), - sa.Column("last_reconciled_at", sa.DateTime(timezone=True), nullable=True), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.Column( - "updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.ForeignKeyConstraint(["content_id"], ["artifact_contents.id"], ondelete="RESTRICT"), - sa.UniqueConstraint("adapter", "provider_artifact_id", name="uq_artifact_replica_provider"), - sa.CheckConstraint( - "verification_state in ('pending', 'verified', 'failed')", name="verification_state" - ), - sa.CheckConstraint( - "retention_state in ('unretained', 'retained', 'released')", name="retention_state" - ), - sa.CheckConstraint( - "availability_state in ('available', 'unavailable', 'missing')", - name="availability_state", - ), - sa.CheckConstraint( - "integrity_state in ('unknown', 'valid', 'quarantined')", - name="integrity_state", - ), - ) - op.create_index("ix_artifact_replicas_content_id", "artifact_replicas", ["content_id"]) - - op.create_table( - "artifact_operation_receipts", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("upload_item_id", sa.String(36), nullable=True), - sa.Column("replica_id", sa.String(36), nullable=True), - sa.Column("adapter", sa.String(50), nullable=False), - sa.Column("service_principal", sa.String(200), nullable=False), - sa.Column("operation", sa.String(30), nullable=False), - sa.Column("idempotency_key", sa.String(200), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("response_digest", sa.String(71), nullable=False), - sa.Column("provider_receipt_id", sa.String(200), nullable=False), - sa.Column("provider_operation_reference", sa.String(200), nullable=False), - sa.Column("outcome", sa.String(30), nullable=False), - sa.Column("attempt_number", sa.Integer(), nullable=False), - sa.Column("correlation_id", sa.String(100), nullable=False), - sa.Column("retention_reference", sa.String(200), nullable=True), - sa.Column("retention_class", sa.String(100), nullable=True), - sa.Column("retention_owner", sa.String(200), nullable=True), - sa.Column("provider_recorded_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("details", sa.JSON(), nullable=False), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.ForeignKeyConstraint(["upload_item_id"], ["artifact_upload_items.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["replica_id"], ["artifact_replicas.id"], ondelete="RESTRICT"), - sa.UniqueConstraint( - "adapter", "service_principal", "operation", "idempotency_key", - name="uq_artifact_receipt_operation", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", name="request_digest_shape" - ), - sa.CheckConstraint( - "response_digest ~ '^sha256:[0-9a-f]{64}$'", name="response_digest_shape" - ), - sa.CheckConstraint("operation in ('store', 'verify', 'retain', 'release')", name="operation"), - sa.CheckConstraint( - "outcome in ('stored', 'verified', 'retained', 'released')", name="outcome" - ), - sa.CheckConstraint( - "(operation = 'store' and outcome = 'stored') or " - "(operation = 'verify' and outcome = 'verified') or " - "(operation = 'retain' and outcome = 'retained') or " - "(operation = 'release' and outcome = 'released')", - name="operation_outcome", - ), - sa.CheckConstraint("attempt_number > 0", name="attempt_positive"), - sa.CheckConstraint( - "operation != 'retain' or " - "(retention_reference is not null and retention_class is not null " - "and retention_owner is not null)", - name="retain_fields", - ), - sa.CheckConstraint( - "operation != 'release' or " - "(retention_reference is not null and retention_class is not null " - "and retention_owner is not null)", - name="release_reference", - ), - sa.CheckConstraint( - "operation in ('retain', 'release') or " - "(retention_reference is null and retention_class is null " - "and retention_owner is null)", - name="non_retention_fields_empty", - ), - ) - op.create_index("ix_artifact_operation_receipts_upload_item_id", "artifact_operation_receipts", ["upload_item_id"]) - op.create_index("ix_artifact_operation_receipts_replica_id", "artifact_operation_receipts", ["replica_id"]) - - _create_artifact_guards() - - -def _create_artifact_guards() -> None: - """Install immutable-row and binding-history database guards.""" - op.execute( - """ - create function reject_artifact_fact_mutation() returns trigger - language plpgsql as $$ - begin - raise exception '% rows are immutable', tg_table_name; - end; - $$ - """ - ) - for table_name in ("artifact_contents", "artifact_bindings", "artifact_operation_receipts"): - op.execute( - sa.text( - f""" - create trigger trg_{table_name}_immutable - before update or delete on {table_name} - for each row execute function reject_artifact_fact_mutation() - """ - ) - ) - op.execute( - """ - create function validate_artifact_binding_history() returns trigger - language plpgsql as $$ - declare predecessor artifact_bindings%rowtype; - begin - if new.scope_version = 1 then - return new; - end if; - select * into predecessor - from artifact_bindings where id = new.supersedes_binding_id; - if not found - or predecessor.project_id != new.project_id - or predecessor.resource_type != new.resource_type - or predecessor.resource_id != new.resource_id - or predecessor.logical_role != new.logical_role - or predecessor.scope_version + 1 != new.scope_version then - raise exception 'artifact binding predecessor is invalid'; - end if; - return new; - end; - $$ - """ - ) - op.execute( - """ - create constraint trigger trg_artifact_binding_history - after insert on artifact_bindings - deferrable initially immediate - for each row execute function validate_artifact_binding_history() - """ - ) - - -def downgrade() -> None: - """Drop the additive foundation only when it contains no artifact facts.""" - connection = op.get_bind() - for table_name in _ARTIFACT_TABLES: - if connection.execute(sa.text(f"select exists(select 1 from {table_name})")).scalar(): - raise RuntimeError("cannot downgrade non-empty artifact foundation") - op.execute("drop trigger trg_artifact_binding_history on artifact_bindings") - op.execute("drop function validate_artifact_binding_history()") - for table_name in ("artifact_operation_receipts", "artifact_bindings", "artifact_contents"): - op.execute(f"drop trigger trg_{table_name}_immutable on {table_name}") - op.execute("drop function reject_artifact_fact_mutation()") - for table_name in _ARTIFACT_TABLES: - op.drop_table(table_name) diff --git a/backend/alembic/versions/0017_api_controls.py b/backend/alembic/versions/0017_api_controls.py deleted file mode 100644 index a8f5c41ba..000000000 --- a/backend/alembic/versions/0017_api_controls.py +++ /dev/null @@ -1,71 +0,0 @@ -"""add durable API rate controls - -Revision ID: 0017_api_controls -Revises: 0016_artifact_domain -Create Date: 2026-07-13 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0017_api_controls" -down_revision = "0016_artifact_domain" -branch_labels = None -depends_on = None - - -def upgrade() -> None: - """Create the privacy-keyed cross-replica counter table.""" - op.create_table( - "api_rate_control_counters", - sa.Column("control_scope", sa.String(32), nullable=False), - sa.Column("key_digest", sa.LargeBinary(), nullable=False), - sa.Column("window_started_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("window_expires_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("request_count", sa.BigInteger(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), nullable=False), - sa.PrimaryKeyConstraint( - "control_scope", - "key_digest", - name="pk_api_rate_control_counters", - ), - sa.CheckConstraint( - "control_scope in ('first_access', 'admin_mutation')", - name=op.f("ck_api_rate_control_counters_scope_token"), - ), - sa.CheckConstraint( - "octet_length(key_digest) = 32", - name=op.f("ck_api_rate_control_counters_digest_length"), - ), - sa.CheckConstraint( - "request_count between 1 and 9223372036854775807", - name=op.f("ck_api_rate_control_counters_request_count"), - ), - sa.CheckConstraint( - "window_started_at < window_expires_at", - name=op.f("ck_api_rate_control_counters_window_order"), - ), - ) - op.create_index( - "ix_api_rate_control_counters_window_expires_at", - "api_rate_control_counters", - ["window_expires_at"], - ) - - -def downgrade() -> None: - """Drop only an empty rate-control table.""" - bind = op.get_bind() - bind.execute(sa.text("lock table api_rate_control_counters in access exclusive mode")) - has_rows = bind.execute( - sa.text("select exists(select 1 from api_rate_control_counters)") - ).scalar_one() - if has_rows: - raise RuntimeError("cannot downgrade non-empty API rate controls") - op.drop_index( - "ix_api_rate_control_counters_window_expires_at", - table_name="api_rate_control_counters", - ) - op.drop_table("api_rate_control_counters") diff --git a/backend/alembic/versions/0018_authority_audit_evidence.py b/backend/alembic/versions/0018_authority_audit_evidence.py deleted file mode 100644 index 02700d4fd..000000000 --- a/backend/alembic/versions/0018_authority_audit_evidence.py +++ /dev/null @@ -1,604 +0,0 @@ -"""add append-only authority audit evidence - -Revision ID: 0018_authority_audit_evidence -Revises: 0017_api_controls -Create Date: 2026-07-14 -""" - -from alembic import op -import sqlalchemy as sa - -revision = "0018_authority_audit_evidence" -down_revision = "0017_api_controls" -branch_labels = depends_on = None - -AUTHORITY_EVENT_TYPES = ( - "ActorProfileProvisioned", - "ServiceActorProvisioned", - "ActorIdentityLinked", - "ActorIdentityLinkRevoked", - "ActorIdentityLinkReactivated", - "ActorProfileSuspended", - "ActorProfileReactivated", - "ActorProfileDeactivated", - "InitialAccessAdministratorBootstrapped", - "AdminRoleGrantIssued", - "AdminRoleGrantRevoked", - "AdminRoleGrantIssueDenied", - "LastAccessAdministratorOperationDenied", - "ProjectRoleQualificationSnapshotCaptured", - "ProjectRoleGrantIssued", - "ProjectRoleGrantReplaced", - "ProjectRoleGrantRevoked", - "SensitiveAuthorizationAllowed", - "SensitiveAuthorizationDenied", - "AuthorityInvalidationRequested", -) -PERMISSIONS = """actor.profile.read_self actor.profile.update_self actor.profile.read_any -actor.profile.suspend actor.profile.reactivate actor.profile.deactivate actor.identity_link.read -actor.identity_link.revoke actor.identity_link.reactivate actor.service.provision admin_role.read -admin_role.grant admin_role.revoke project.create project.read project.update project.archive -project.guide.manage project.effective_policy.manage project.task.manage project.review_policy.manage -project.role_grant.read project.role_grant.manage task.queue.read task.claim submission.create -submission.read_own submission.read_for_review review.queue.read review.queue.inspect review.claim -review.release review.decline_preference review.decision review.lease.force_release review.chain.read -contribution.read_self contribution.read_project compensation.policy.manage -compensation.adapter_binding.manage compensation.award.read compensation.delivery.reconcile -operations.status.read operations.timer.run operations.reconcile.run operations.outbox.retry -operations.projection.rebuild audit.read audit.export""".split() -DENIAL_CODES = """required_scope_missing unsupported_subject_kind service_actor_not_provisioned -identity_link_revoked actor_suspended actor_deactivated permission_not_granted scope_not_authorized -self_grant_forbidden self_role_revoke_forbidden resource_guard_denied actor_not_found grant_not_found -resource_not_found actor_already_suspended actor_not_suspended actor_deactivated_terminal -last_access_administrator admin_role_grant_exists project_role_grant_exists identity_link_conflict -resource_project_mismatch idempotency_mismatch invalid_role_scope invalid_project_role -qualification_snapshot_invalid""".split() -REASONS = { - "ActorProfileProvisioned": ("automatic_first_access",), - "ServiceActorProvisioned": ("manual_service_provisioning",), - "ActorIdentityLinked": ("identity_lifecycle_change",), - "ActorIdentityLinkRevoked": ("identity_lifecycle_change",), - "ActorIdentityLinkReactivated": ("identity_lifecycle_change",), - "ActorProfileSuspended": ("security_response", "administrative_correction"), - "ActorProfileReactivated": ("administrative_correction",), - "ActorProfileDeactivated": ("security_response", "administrative_correction"), - "InitialAccessAdministratorBootstrapped": ("initial_access_bootstrap",), - "AdminRoleGrantIssued": ("authority_assignment",), - "AdminRoleGrantRevoked": ("authority_revocation",), - "AdminRoleGrantIssueDenied": ("authorization_policy_denial",), - "LastAccessAdministratorOperationDenied": ("authorization_policy_denial",), - "ProjectRoleQualificationSnapshotCaptured": ("qualification_evidence_captured",), - "ProjectRoleGrantIssued": ("authority_assignment",), - "ProjectRoleGrantReplaced": ("authority_replacement",), - "ProjectRoleGrantRevoked": ("authority_revocation",), - "SensitiveAuthorizationAllowed": ("authorization_evaluation",), - "SensitiveAuthorizationDenied": ("authorization_evaluation",), - "AuthorityInvalidationRequested": ("authority_state_changed",), -} - - -def _sql_tokens(values) -> str: - return ", ".join(f"'{value}'" for value in values) - - -def upgrade() -> None: - """Extend the shared audit table and install normal-DML custody guards.""" - columns = ( - sa.Column( - "event_domain", - sa.String(24), - nullable=False, - server_default="legacy_lifecycle", - ), - sa.Column("event_version", sa.Integer(), nullable=True), - sa.Column("occurred_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("actor_ref_kind", sa.String(32), nullable=True), - sa.Column("request_id", sa.Uuid(), nullable=True), - sa.Column("correlation_id", sa.Uuid(), nullable=True), - sa.Column("target_actor_ref_kind", sa.String(32), nullable=True), - sa.Column("target_actor_ref", sa.String(100), nullable=True), - sa.Column("matched_grant_id", sa.String(100), nullable=True), - sa.Column("permission_id", sa.String(120), nullable=True), - sa.Column("project_id", sa.String(36), nullable=True), - sa.Column("resource_type", sa.String(80), nullable=True), - sa.Column("resource_id", sa.String(100), nullable=True), - sa.Column("target_ref_kind", sa.String(32), nullable=True), - sa.Column("target_ref_id", sa.String(100), nullable=True), - sa.Column("denial_code", sa.String(80), nullable=True), - sa.Column("idempotency_reference", sa.Uuid(), nullable=True), - sa.Column("invalidation_cause_event_id", sa.String(36), nullable=True), - sa.Column("invalidation_target_kind", sa.String(32), nullable=True), - sa.Column("invalidation_target_ref", sa.String(100), nullable=True), - sa.Column("before_facts", sa.JSON(), nullable=True), - sa.Column("after_facts", sa.JSON(), nullable=True), - ) - for column in columns: - op.add_column("audit_events", column) - op.alter_column("audit_events", "external_subject", existing_type=sa.String(200), nullable=True) - op.alter_column("audit_events", "external_issuer", existing_type=sa.String(200), nullable=True) - op.execute( - """ - create function authority_facts_are_safe(facts json) - returns boolean language sql immutable strict as $$ - select json_typeof(facts) = 'object' - and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) - and not exists ( - select 1 from json_each(facts) item - where item.key not in ( - 'status', 'subject_kind', 'provisioning_method', 'role', - 'scope_type', 'scope_id', 'effective', 'allowed' - ) - or case item.key - when 'status' then item.value #>> '{}' not in ( - 'active', 'suspended', 'deactivated', 'revoked', 'captured' - ) - when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') - when 'provisioning_method' then item.value #>> '{}' not in ( - 'automatic_first_access', 'manual_service_provisioning' - ) - when 'role' then item.value #>> '{}' not in ( - 'access_administrator', 'operator', 'project_manager', - 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' - ) - when 'scope_type' then item.value #>> '{}' not in ('system', 'project') - when 'scope_id' then (item.value #>> '{}') !~ - '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' - when 'effective' then json_typeof(item.value) <> 'boolean' - when 'allowed' then json_typeof(item.value) <> 'boolean' - else true - end - ) - $$ - """ - ) - op.execute( - """ - create function authority_grant_facts_are_safe( - facts json, roles text[], expected_status text, - expected_effective boolean, envelope_project_id text - ) returns boolean language sql immutable as $$ - select authority_facts_are_safe(facts) - and facts->>'role' = any(roles) - and facts->>'status' = expected_status - and (facts->>'effective')::boolean = expected_effective - and ( - ( - facts->>'scope_type' = 'system' - and envelope_project_id is null - and not facts::jsonb ? 'scope_id' - and facts->>'role' not in ('submitter', 'reviewer', 'both') - and (select count(*) from json_each(facts)) = 4 - ) or ( - facts->>'scope_type' = 'project' - and envelope_project_id is not null - and facts->>'scope_id' = envelope_project_id - and facts->>'role' not in ('access_administrator', 'operator') - and (select count(*) from json_each(facts)) = 5 - ) - ) - $$ - """ - ) - op.execute( - """ - create function authority_event_facts_are_safe( - event_name text, before_state json, after_state json, envelope_project_id text - ) returns boolean language plpgsql immutable as $$ - begin - if (before_state is not null and not authority_facts_are_safe(before_state)) - or (after_state is not null and not authority_facts_are_safe(after_state)) then - return false; - end if; - case event_name - when 'ActorProfileProvisioned' then - return before_state is null and after_state::jsonb = - '{"status":"active","subject_kind":"human",' - '"provisioning_method":"automatic_first_access"}'::jsonb; - when 'ServiceActorProvisioned' then - return before_state is null and after_state::jsonb = - '{"status":"active","subject_kind":"service",' - '"provisioning_method":"manual_service_provisioning"}'::jsonb; - when 'ActorIdentityLinked' then - return before_state is null and after_state::jsonb in ( - '{"status":"active","subject_kind":"human"}'::jsonb, - '{"status":"active","subject_kind":"service"}'::jsonb - ); - when 'ActorIdentityLinkRevoked' then - return before_state::jsonb = '{"status":"active"}'::jsonb - and after_state::jsonb = '{"status":"revoked"}'::jsonb; - when 'ActorIdentityLinkReactivated' then - return before_state::jsonb = '{"status":"revoked"}'::jsonb - and after_state::jsonb = '{"status":"active"}'::jsonb; - when 'ActorProfileSuspended' then - return before_state::jsonb = '{"status":"active"}'::jsonb - and after_state::jsonb = '{"status":"suspended"}'::jsonb; - when 'ActorProfileReactivated' then - return before_state::jsonb = '{"status":"suspended"}'::jsonb - and after_state::jsonb = '{"status":"active"}'::jsonb; - when 'ActorProfileDeactivated' then - return before_state::jsonb in ( - '{"status":"active"}'::jsonb, '{"status":"suspended"}'::jsonb - ) and after_state::jsonb = '{"status":"deactivated"}'::jsonb; - when 'InitialAccessAdministratorBootstrapped' then - return before_state is null and authority_grant_facts_are_safe( - after_state, array['access_administrator'], 'active', true, null - ); - when 'AdminRoleGrantIssued' then - return before_state is null and authority_grant_facts_are_safe( - after_state, - array[ - 'access_administrator', 'operator', 'project_manager', - 'finance_authority', 'audit_authority' - ], 'active', true, envelope_project_id - ); - when 'ProjectRoleGrantIssued' then - return before_state is null and authority_grant_facts_are_safe( - after_state, array['submitter', 'reviewer', 'both'], - 'active', true, envelope_project_id - ); - when 'AdminRoleGrantRevoked', 'ProjectRoleGrantRevoked' then - return authority_grant_facts_are_safe( - before_state, - case when event_name = 'AdminRoleGrantRevoked' then - array[ - 'access_administrator', 'operator', 'project_manager', - 'finance_authority', 'audit_authority' - ] - else array['submitter', 'reviewer', 'both'] end, - 'active', true, envelope_project_id - ) and authority_grant_facts_are_safe( - after_state, - case when event_name = 'AdminRoleGrantRevoked' then - array[ - 'access_administrator', 'operator', 'project_manager', - 'finance_authority', 'audit_authority' - ] - else array['submitter', 'reviewer', 'both'] end, - 'revoked', false, envelope_project_id - ) and before_state->>'role' = after_state->>'role' - and before_state->>'scope_type' = after_state->>'scope_type' - and coalesce(before_state->>'scope_id', '') = - coalesce(after_state->>'scope_id', ''); - when 'ProjectRoleGrantReplaced' then - return authority_grant_facts_are_safe( - before_state, array['submitter', 'reviewer', 'both'], - 'active', true, envelope_project_id - ) and authority_grant_facts_are_safe( - after_state, array['submitter', 'reviewer', 'both'], - 'active', true, envelope_project_id - ) and before_state->>'scope_id' = after_state->>'scope_id'; - when 'ProjectRoleQualificationSnapshotCaptured' then - return before_state is null - and after_state::jsonb = '{"status":"captured"}'::jsonb; - when 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied' then - return before_state is null and after_state is null; - when 'SensitiveAuthorizationAllowed' then - return before_state is null and after_state::jsonb = '{"allowed": true}'::jsonb; - when 'SensitiveAuthorizationDenied' then - return before_state is null and after_state::jsonb = '{"allowed": false}'::jsonb; - when 'AuthorityInvalidationRequested' then - return before_state::jsonb = '{"effective": true}'::jsonb - and after_state::jsonb = '{"effective": false}'::jsonb; - else return false; - end case; - end - $$ - """ - ) - - event_tokens = _sql_tokens(AUTHORITY_EVENT_TYPES) - permission_tokens = _sql_tokens(PERMISSIONS) - denial_tokens = _sql_tokens(DENIAL_CODES) - reason_rules = " or ".join( - f"(event_type = '{event}' and reason in ({_sql_tokens(reasons)}))" - for event, reasons in REASONS.items() - ) - entity_tokens = _sql_tokens( - ( - "actor_profile", - "actor_identity_link", - "admin_role_grant", - "qualification_snapshot", - "project_role_grant", - "authorization_decision", - "authority_invalidation", - ) - ) - resource_tokens = _sql_tokens( - """actor_profile actor_identity_link admin_role_grant project project_role_grant task - submission review contribution compensation_award compensation_delivery operations - audit_event""".split() - ) - uuid_target_tokens = _sql_tokens( - ( - "actor_profile", - "actor_identity_link", - "admin_role_grant", - "qualification_snapshot", - "project_role_grant", - ) - ) - uuid_pattern = r"^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" - op.create_check_constraint( - "domain_shape", - "audit_events", - """ - ( - event_domain = 'legacy_lifecycle' - and event_version is null and occurred_at is null and actor_ref_kind is null - and request_id is null and correlation_id is null and target_actor_ref_kind is null - and target_actor_ref is null and matched_grant_id is null and permission_id is null - and project_id is null and resource_type is null and resource_id is null - and target_ref_kind is null and target_ref_id is null and denial_code is null - and idempotency_reference is null and invalidation_cause_event_id is null - and invalidation_target_kind is null and invalidation_target_ref is null - and before_facts is null and after_facts is null - and external_subject is not null and external_issuer is not null - ) or ( - event_domain = 'authority' and event_version = 1 and occurred_at is not null - and actor_ref_kind in ('legacy_actor', 'actor_profile', 'system_principal') - and request_id is not null and correlation_id is not null - and from_status is null and to_status is null and reason is not null - and external_subject is null and external_issuer is null - and actor_roles::jsonb = '[]'::jsonb and claim_snapshot::jsonb = '{}'::jsonb - and auth_source = 'local_authority' and is_dev_auth = false - and event_payload::jsonb = '{}'::jsonb - ) - """, - ) - op.create_check_constraint( - "authority_tokens", - "audit_events", - f"event_domain <> 'authority' or event_type in ({event_tokens})", - ) - op.create_check_constraint( - "authority_registries", - "audit_events", - f""" - event_domain <> 'authority' or ( - reason is not null and ({reason_rules}) - and (permission_id is null or permission_id in ({permission_tokens})) - and (denial_code is null or denial_code in ({denial_tokens})) - ) - """, - ) - op.create_check_constraint( - "reference_pairs", - "audit_events", - """ - (target_actor_ref_kind is null) = (target_actor_ref is null) - and (resource_type is not null or resource_id is null) - and (target_ref_kind is null) = (target_ref_id is null) - and (invalidation_target_kind is null) = (invalidation_target_ref is null) - and (invalidation_cause_event_id is null or invalidation_cause_event_id <> id) - """, - ) - op.create_check_constraint( - "authority_privacy_bounds", - "audit_events", - f""" - event_domain <> 'authority' or ( - id ~ '{uuid_pattern}' and entity_type in ({entity_tokens}) and entity_id ~ '{uuid_pattern}' - and ( - (actor_ref_kind in ('legacy_actor', 'actor_profile') and actor_id ~ '{uuid_pattern}') - or (actor_ref_kind = 'system_principal' and actor_id = 'workstream:system:bootstrap') - ) - and ( - target_actor_ref is null - or (target_actor_ref_kind = 'actor_profile' and target_actor_ref ~ '{uuid_pattern}') - ) - and (matched_grant_id is null or matched_grant_id ~ '{uuid_pattern}') - and (project_id is null or project_id ~ '{uuid_pattern}') - and (resource_type is null or resource_type in ({resource_tokens})) - and (resource_id is null or resource_id ~ '{uuid_pattern}') - and ( - target_ref_kind is null - or (target_ref_kind in ({uuid_target_tokens}) and target_ref_id ~ '{uuid_pattern}') - or (target_ref_kind = 'permission_registry' and target_ref_id in ({permission_tokens})) - ) - and ( - invalidation_target_kind is null - or ( - invalidation_target_kind in ({uuid_target_tokens}) - and invalidation_target_ref ~ '{uuid_pattern}' - ) - or ( - invalidation_target_kind = 'permission_registry' - and invalidation_target_ref in ({permission_tokens}) - ) - ) - and ( - entity_type not in ('authorization_decision', 'authority_invalidation') - or entity_id = id - ) - and ( - resource_type <> 'project' or resource_id is null - or (project_id is not null and resource_id = project_id) - ) - ) - """, - ) - op.create_check_constraint( - "fact_bounds", - "audit_events", - """ - event_domain <> 'authority' or ( - (before_facts is null or octet_length(before_facts::text) <= 4096) - and (after_facts is null or octet_length(after_facts::text) <= 4096) - and coalesce( - authority_event_facts_are_safe(event_type, before_facts, after_facts, project_id), - false - ) - ) - """, - ) - op.create_foreign_key( - "fk_audit_events_invalidation_cause", - "audit_events", - "audit_events", - ["invalidation_cause_event_id"], - ["id"], - ) - op.create_check_constraint( - "foundation_shapes", - "audit_events", - """ - event_domain <> 'authority' - or event_type not in ( - 'SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', - 'AuthorityInvalidationRequested', 'AdminRoleGrantIssueDenied', - 'LastAccessAdministratorOperationDenied' - ) - or ( - event_type in ('AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied') - and denial_code is not null - ) - or ( - event_type = 'SensitiveAuthorizationAllowed' and permission_id is not null - and denial_code is null and invalidation_cause_event_id is null - and invalidation_target_kind is null - ) - or ( - event_type = 'SensitiveAuthorizationDenied' and permission_id is not null - and denial_code is not null and invalidation_cause_event_id is null - and invalidation_target_kind is null and idempotency_reference is null - ) - or ( - event_type = 'AuthorityInvalidationRequested' - and invalidation_cause_event_id is not null - and invalidation_target_kind is not null and denial_code is null - ) - """, - ) - for name, fields in ( - ("ix_audit_events_request_id", ["request_id"]), - ("ix_audit_events_correlation_id", ["correlation_id"]), - ("ix_audit_events_occurred_at", ["occurred_at"]), - ("ix_audit_events_project_id", ["project_id"]), - ("ix_audit_events_actor_ref", ["actor_ref_kind", "actor_id"]), - ): - op.create_index(name, "audit_events", fields) - - op.execute( - """ - create function set_authority_audit_database_time() - returns trigger language plpgsql as $$ - begin - if new.event_domain = 'authority' then - if new.invalidation_cause_event_id is not null and not exists ( - select 1 from audit_events - where id = new.invalidation_cause_event_id and event_domain = 'authority' - ) then - raise exception 'invalid authority invalidation cause' using errcode = '23503'; - end if; - new.occurred_at = statement_timestamp(); - else - new.occurred_at = null; - end if; - return new; - end - $$ - """ - ) - op.execute( - """ - create trigger audit_events_set_authority_time - before insert on audit_events for each row - execute function set_authority_audit_database_time() - """ - ) - op.execute( - """ - create function reject_audit_event_mutation() - returns trigger language plpgsql as $$ - begin - raise exception 'audit events are append-only' using errcode = '55000'; - end - $$ - """ - ) - op.execute( - """ - create trigger audit_events_reject_update_delete - before update or delete on audit_events for each row - execute function reject_audit_event_mutation() - """ - ) - op.execute( - """ - create trigger audit_events_reject_truncate - before truncate on audit_events for each statement - execute function reject_audit_event_mutation() - """ - ) - - -def downgrade() -> None: - """Remove only unused authority-envelope schema while preserving legacy rows.""" - bind = op.get_bind() - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - has_authority = bind.execute( - sa.text("select exists(select 1 from audit_events where event_domain = 'authority')") - ).scalar_one() - if has_authority: - raise RuntimeError("cannot downgrade non-empty authority audit evidence") - - for trigger in ( - "audit_events_reject_truncate", - "audit_events_reject_update_delete", - "audit_events_set_authority_time", - ): - op.execute(f"drop trigger {trigger} on audit_events") - op.execute("drop function reject_audit_event_mutation()") - op.execute("drop function set_authority_audit_database_time()") - for name in ( - "ix_audit_events_actor_ref", - "ix_audit_events_project_id", - "ix_audit_events_occurred_at", - "ix_audit_events_correlation_id", - "ix_audit_events_request_id", - ): - op.drop_index(name, table_name="audit_events") - op.drop_constraint("fk_audit_events_invalidation_cause", "audit_events", type_="foreignkey") - for name in ( - "foundation_shapes", - "fact_bounds", - "authority_privacy_bounds", - "reference_pairs", - "authority_registries", - "authority_tokens", - "domain_shape", - ): - op.drop_constraint(name, "audit_events", type_="check") - op.execute("drop function authority_event_facts_are_safe(text, json, json, text)") - op.execute("drop function authority_grant_facts_are_safe(json, text[], text, boolean, text)") - op.execute("drop function authority_facts_are_safe(json)") - for column in reversed( - ( - "event_version", - "occurred_at", - "actor_ref_kind", - "request_id", - "correlation_id", - "target_actor_ref_kind", - "target_actor_ref", - "matched_grant_id", - "permission_id", - "project_id", - "resource_type", - "resource_id", - "target_ref_kind", - "target_ref_id", - "denial_code", - "idempotency_reference", - "invalidation_cause_event_id", - "invalidation_target_kind", - "invalidation_target_ref", - "before_facts", - "after_facts", - "event_domain", - ) - ): - op.drop_column("audit_events", column) - op.alter_column("audit_events", "external_issuer", existing_type=sa.String(200), nullable=False) - op.alter_column("audit_events", "external_subject", existing_type=sa.String(200), nullable=False) diff --git a/backend/alembic/versions/0019_authority_idempotency.py b/backend/alembic/versions/0019_authority_idempotency.py deleted file mode 100644 index f4f2e1187..000000000 --- a/backend/alembic/versions/0019_authority_idempotency.py +++ /dev/null @@ -1,319 +0,0 @@ -"""add authority idempotency and linked invalidation enforcement - -Revision ID: 0019_authority_idempotency -Revises: 0018_authority_audit_evidence -Create Date: 2026-07-14 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0019_authority_idempotency" -down_revision = "0018_authority_audit_evidence" -branch_labels = None -depends_on = None - -OPERATIONS = ( - "service_actor.create", "admin_role_grant.issue", "admin_role_grant.revoke", - "project_role_grant.issue", "project_role_grant.revoke", "actor_profile.suspend", - "actor_profile.reactivate", "actor_profile.deactivate", "actor_identity_link.revoke", - "actor_identity_link.reactivate", -) - - -def _tokens(values: tuple[str, ...]) -> str: - return ", ".join(f"'{value}'" for value in values) - - -def upgrade() -> None: - """Create immutable reservations and enforce new audit-reference integrity.""" - op.create_table( - "authority_idempotency_records", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("idempotency_key", sa.Uuid(), nullable=False), - sa.Column("actor_ref_kind", sa.String(32), nullable=False), - sa.Column("actor_ref", sa.String(100), nullable=False), - sa.Column("operation", sa.String(48), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("status", sa.String(16), nullable=False), - sa.Column("response_resource_type", sa.String(32)), - sa.Column("response_resource_id", sa.Uuid()), - sa.Column("response_resource_version", sa.BigInteger()), - sa.Column("response_http_status", sa.SmallInteger()), - sa.Column( - "created_at", sa.DateTime(timezone=True), nullable=False, - server_default=sa.text("statement_timestamp()"), - ), - sa.Column("committed_at", sa.DateTime(timezone=True)), - sa.PrimaryKeyConstraint("id", name="pk_authority_idempotency_records"), - sa.UniqueConstraint( - "actor_ref_kind", "actor_ref", "operation", "idempotency_key", - name="uq_authority_idempotency_records_replay_namespace", - ), - sa.UniqueConstraint( - "id", "actor_ref_kind", "actor_ref", - name="uq_authority_idempotency_records_actor_reference", - ), - sa.CheckConstraint( - "actor_ref_kind in ('legacy_actor', 'actor_profile', 'system_principal')", - name="actor_kind", - ), - sa.CheckConstraint( - "((actor_ref_kind = 'system_principal' and actor_ref = " - "'workstream:system:bootstrap') or (actor_ref_kind <> 'system_principal' " - "and actor_ref ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'))", - name="actor_reference", - ), - sa.CheckConstraint( - f"operation in ({_tokens(OPERATIONS)})", - name="operation", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", - name="request_digest", - ), - sa.CheckConstraint( - "status in ('pending', 'committed')", - name="status", - ), - sa.CheckConstraint( - "response_resource_version is null or response_resource_version > 0", - name="response_version", - ), - sa.CheckConstraint( - "(status = 'pending' and response_resource_type is null and " - "response_resource_id is null and response_resource_version is null and " - "response_http_status is null and committed_at is null) or " - "(status = 'committed' and response_resource_type is not null and " - "response_resource_id is not null and response_http_status is not null and " - "committed_at is not null)", - name="state_shape", - ), - sa.CheckConstraint( - "(operation = 'service_actor.create' and (response_resource_type is null or " - "response_resource_type = 'actor_profile')) or " - "(operation like 'admin_role_grant.%' and (response_resource_type is null or " - "response_resource_type = 'admin_role_grant')) or " - "(operation like 'project_role_grant.%' and (response_resource_type is null or " - "response_resource_type = 'project_role_grant')) or " - "(operation like 'actor_profile.%' and (response_resource_type is null or " - "response_resource_type = 'actor_profile')) or " - "(operation like 'actor_identity_link.%' and (response_resource_type is null or " - "response_resource_type = 'actor_identity_link'))", - name="response_type", - ), - sa.CheckConstraint( - "response_http_status is null or ((operation in ('service_actor.create', " - "'admin_role_grant.issue', 'project_role_grant.issue') and " - "response_http_status = 201) or (operation not in ('service_actor.create', " - "'admin_role_grant.issue', 'project_role_grant.issue') and " - "response_http_status = 200))", - name="response_status", - ), - ) - op.execute( - "alter table audit_events add constraint fk_audit_events_authority_idempotency " - "foreign key (idempotency_reference, actor_ref_kind, actor_id) references " - "authority_idempotency_records (id, actor_ref_kind, actor_ref) not valid" - ) - _create_functions_and_triggers() - - -def _create_functions_and_triggers() -> None: - op.execute( - """ - create function guard_authority_idempotency_record() returns trigger - language plpgsql as $$ - declare success_count integer; invalidation_count integer; success_id text; - success_row audit_events%rowtype; - begin - if tg_op = 'INSERT' then - if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; - new.created_at := statement_timestamp(); new.committed_at := null; return new; - elsif tg_op = 'DELETE' then - raise exception 'authority idempotency records are immutable' using errcode='55000'; - end if; - if old.status <> 'pending' or new.status <> 'committed' - or (new.id, new.idempotency_key, new.actor_ref_kind, new.actor_ref, - new.operation, new.request_digest, new.created_at) - is distinct from - (old.id, old.idempotency_key, old.actor_ref_kind, old.actor_ref, - old.operation, old.request_digest, old.created_at) then - raise exception 'invalid authority idempotency transition' using errcode='23514'; - end if; - select count(*), min(id) into success_count, success_id - from audit_events where event_domain='authority' and idempotency_reference=new.id - and event_type <> 'AuthorityInvalidationRequested'; - select count(*) into invalidation_count from audit_events - where event_domain='authority' and idempotency_reference=new.id - and event_type='AuthorityInvalidationRequested'; - if success_count <> 1 or invalidation_count <> 1 then - raise exception 'authority evidence pair required' using errcode='23514'; - end if; - select * into success_row from audit_events where id=success_id; - if success_row.resource_type <> new.response_resource_type - or success_row.resource_id <> new.response_resource_id::text then - raise exception 'authority response does not match evidence' using errcode='23514'; - end if; - new.committed_at := statement_timestamp(); return new; - end $$ - """ - ) - op.execute( - """ - create function reject_pending_authority_idempotency() returns trigger - language plpgsql as $$ begin - if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then - raise exception 'pending authority idempotency cannot commit' using errcode='23514'; - end if; return null; - end $$ - """ - ) - op.execute( - """ - create function reject_authority_idempotency_truncate() returns trigger - language plpgsql as $$ begin - raise exception 'authority idempotency records are immutable' using errcode='55000'; - end $$ - """ - ) - op.execute( - """ - create function validate_linked_authority_event() returns trigger - language plpgsql as $$ - declare record_row authority_idempotency_records%rowtype; - cause_row audit_events%rowtype; expected_permission text; - expected_resource text; valid_success boolean; - begin - if new.event_domain <> 'authority' then return new; end if; - valid_success := new.event_type in ( - 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', - 'ProjectRoleGrantIssued','ProjectRoleGrantReplaced','ProjectRoleGrantRevoked', - 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', - 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); - if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then - if new.idempotency_reference is not null then - raise exception 'invalid authority idempotency event' using errcode='23514'; - end if; return new; - end if; - if new.idempotency_reference is null then - raise exception 'authority event requires idempotency reference' using errcode='23514'; - end if; - select * into record_row from authority_idempotency_records - where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; - if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; - if record_row.status <> 'pending' then - raise exception 'committed authority idempotency is closed' using errcode='23514'; - end if; - expected_permission := case record_row.operation - when 'service_actor.create' then 'actor.service.provision' - when 'admin_role_grant.issue' then 'admin_role.grant' - when 'admin_role_grant.revoke' then 'admin_role.revoke' - when 'project_role_grant.issue' then 'project.role_grant.manage' - when 'project_role_grant.revoke' then 'project.role_grant.manage' - when 'actor_profile.suspend' then 'actor.profile.suspend' - when 'actor_profile.reactivate' then 'actor.profile.reactivate' - when 'actor_profile.deactivate' then 'actor.profile.deactivate' - when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' - when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; - expected_resource := case - when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' - when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' - when record_row.operation like 'project_role_grant.%' then 'project_role_grant' - else 'actor_identity_link' end; - if new.permission_id <> expected_permission or new.resource_type <> expected_resource - or new.resource_id is null then - raise exception 'authority event does not match operation' using errcode='23514'; - end if; - if new.event_type='AuthorityInvalidationRequested' then - select * into cause_row from audit_events where id=new.invalidation_cause_event_id; - if not found or cause_row.idempotency_reference is distinct from record_row.id - or cause_row.actor_ref_kind is distinct from new.actor_ref_kind - or cause_row.actor_id is distinct from new.actor_id - or cause_row.permission_id is distinct from new.permission_id - or cause_row.resource_type is distinct from new.invalidation_target_kind - or cause_row.resource_id is distinct from new.invalidation_target_ref - or cause_row.resource_type is distinct from new.resource_type - or cause_row.resource_id is distinct from new.resource_id - or cause_row.target_ref_kind is distinct from cause_row.resource_type - or cause_row.target_ref_id is distinct from cause_row.resource_id - or cause_row.request_id is distinct from new.request_id - or cause_row.correlation_id is distinct from new.correlation_id - or cause_row.project_id is distinct from new.project_id - or new.entity_type <> 'authority_invalidation' - or new.entity_id <> new.id - or not ( - (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or - (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or - (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or - (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued','ProjectRoleGrantReplaced')) or - (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or - (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or - (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or - (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or - (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or - (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then - raise exception 'invalid linked authority cause' using errcode='23514'; - end if; - else - if new.entity_type <> expected_resource or new.entity_id <> new.resource_id - or new.target_ref_kind is distinct from expected_resource - or new.target_ref_id is distinct from new.resource_id - or new.invalidation_cause_event_id is not null - or new.invalidation_target_kind is not null - or new.invalidation_target_ref is not null - or not ( - (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or - (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or - (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or - (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued','ProjectRoleGrantReplaced')) or - (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or - (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or - (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or - (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or - (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or - (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then - raise exception 'authority success event does not match operation' using errcode='23514'; - end if; - end if; return new; - end $$ - """ - ) - op.execute( - "create trigger authority_idempotency_guard before insert or update or delete " - "on authority_idempotency_records for each row execute function guard_authority_idempotency_record()" - ) - op.execute( - "create constraint trigger authority_idempotency_pending_guard after insert or update " - "on authority_idempotency_records deferrable initially deferred for each row " - "execute function reject_pending_authority_idempotency()" - ) - op.execute( - "create trigger authority_idempotency_reject_truncate before truncate " - "on authority_idempotency_records execute function reject_authority_idempotency_truncate()" - ) - op.execute( - "create trigger audit_events_validate_idempotency before insert on audit_events " - "for each row execute function validate_linked_authority_event()" - ) - - -def downgrade() -> None: - """Drop 0019 only when no durable idempotency/evidence pair exists.""" - bind = op.get_bind() - bind.execute(sa.text("lock table authority_idempotency_records in access exclusive mode")) - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - if bind.execute(sa.text("select exists(select 1 from authority_idempotency_records)")).scalar_one(): - raise RuntimeError("cannot downgrade non-empty authority idempotency") - op.execute("drop trigger audit_events_validate_idempotency on audit_events") - op.execute("drop function validate_linked_authority_event()") - op.drop_constraint("fk_audit_events_authority_idempotency", "audit_events", type_="foreignkey") - op.execute("drop trigger authority_idempotency_pending_guard on authority_idempotency_records") - op.execute("drop trigger authority_idempotency_reject_truncate on authority_idempotency_records") - op.execute("drop trigger authority_idempotency_guard on authority_idempotency_records") - op.execute("drop function reject_pending_authority_idempotency()") - op.execute("drop function reject_authority_idempotency_truncate()") - op.execute("drop function guard_authority_idempotency_record()") - op.drop_table("authority_idempotency_records") diff --git a/backend/alembic/versions/0020_canonical_actor_profile.py b/backend/alembic/versions/0020_canonical_actor_profile.py deleted file mode 100644 index c965c3060..000000000 --- a/backend/alembic/versions/0020_canonical_actor_profile.py +++ /dev/null @@ -1,388 +0,0 @@ -"""migrate classified actors to canonical profiles and identity links - -Revision ID: 0020_canonical_actor_profile -Revises: 0019_authority_idempotency -Create Date: 2026-07-15 -""" - -from __future__ import annotations - -from uuid import NAMESPACE_URL, uuid5 - -from alembic import op -from pydantic import ValidationError -import sqlalchemy as sa - -from app.modules.actors.legacy_classification import ( - LegacyClassificationError, - LegacyActorRow, - database_binding_identifier, - load_migration_envelope_from_environment, - source_row_set_sha256, -) - -revision = "0020_canonical_actor_profile" -down_revision = "0019_authority_idempotency" -branch_labels = depends_on = None - -UUID_PATTERN = r"^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" - - -def _legacy_rows(bind) -> tuple[LegacyActorRow, ...]: - rows = bind.execute( - sa.text( - "select actor_id, external_issuer, external_subject " - "from actor_identities order by actor_id" - ) - ).all() - try: - return tuple( - LegacyActorRow(actor_id=row[0], issuer=row[1], subject=row[2]) for row in rows - ) - except ValidationError: - raise LegacyClassificationError("invalid_source_rows") from None - - -def _classification(bind, rows: tuple[LegacyActorRow, ...]): - if not rows: - return None - database_name, database_oid = bind.execute( - sa.text( - "select current_database(), oid from pg_database " - "where datname = current_database()" - ) - ).one() - return load_migration_envelope_from_environment( - rows, - database_binding=database_binding_identifier(database_name, database_oid), - ) - - -def _rename_legacy_tables() -> None: - op.rename_table("actor_profiles", "legacy_workflow_eligibility") - op.rename_table("actor_identities", "legacy_actor_identities") - statements = ( - "alter table legacy_actor_identities rename constraint pk_actor_identities to pk_legacy_actor_identities", - "alter table legacy_actor_identities rename constraint uq_actor_identities_external_identity to uq_legacy_actor_identities_external_identity", - "alter table legacy_workflow_eligibility rename constraint pk_actor_profiles to pk_legacy_workflow_eligibility", - "alter table legacy_workflow_eligibility rename constraint ck_actor_profiles_ck_actor_profiles_profile_type to ck_legacy_workflow_eligibility_profile_type", - "alter table legacy_workflow_eligibility rename constraint ck_actor_profiles_ck_actor_profiles_status to ck_legacy_workflow_eligibility_status", - "alter table legacy_workflow_eligibility rename constraint uq_actor_profiles_actor_type_scope to uq_legacy_workflow_eligibility_actor_type_scope", - "alter table legacy_workflow_eligibility rename constraint fk_actor_profiles_actor_id_actor_identities to fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities", - "alter index ix_actor_profiles_actor_id rename to ix_legacy_workflow_eligibility_actor_id", - "alter index ix_actor_profiles_profile_type rename to ix_legacy_workflow_eligibility_profile_type", - "alter index ix_actor_profiles_status rename to ix_legacy_workflow_eligibility_status", - ) - for statement in statements: - op.execute(statement) - - -def _create_canonical_tables() -> None: - op.create_table( - "actor_profiles", - sa.Column("id", sa.String(36), nullable=False), - sa.Column("actor_kind", sa.String(16), nullable=False), - sa.Column("status", sa.String(16), nullable=False), - sa.Column("provisioning_method", sa.String(32), nullable=False), - sa.Column("display_name", sa.String(200)), - sa.Column("contact_email", sa.String(320)), - sa.Column("created_by", sa.String(120), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("last_seen_at", sa.DateTime(timezone=True)), - sa.Column("suspended_by", sa.String(120)), - sa.Column("suspended_at", sa.DateTime(timezone=True)), - sa.Column("suspension_reason", sa.String(500)), - sa.Column("deactivated_by", sa.String(120)), - sa.Column("deactivated_at", sa.DateTime(timezone=True)), - sa.Column("deactivation_reason", sa.String(500)), - sa.PrimaryKeyConstraint("id", name=op.f("pk_actor_profiles")), - sa.CheckConstraint(f"id ~ '{UUID_PATTERN}'", name=op.f("ck_actor_profiles_id_uuid")), - sa.CheckConstraint("actor_kind in ('human','service')", name=op.f("ck_actor_profiles_actor_kind")), - sa.CheckConstraint("status in ('active','suspended','deactivated')", name=op.f("ck_actor_profiles_status")), - sa.CheckConstraint( - "provisioning_method in ('automatic_first_access','manual_service_provisioning')", - name=op.f("ck_actor_profiles_provisioning_method"), - ), - sa.CheckConstraint( - "(actor_kind='human' and provisioning_method='automatic_first_access') or " - "(actor_kind='service' and provisioning_method='manual_service_provisioning')", - name=op.f("ck_actor_profiles_kind_provisioning"), - ), - sa.CheckConstraint( - "(status='active' and suspended_by is null and suspended_at is null and " - "suspension_reason is null and deactivated_by is null and deactivated_at is null " - "and deactivation_reason is null) or " - "(status='suspended' and suspended_by is not null and suspended_at is not null " - "and suspension_reason is not null and deactivated_by is null and " - "deactivated_at is null and deactivation_reason is null) or " - "(status='deactivated' and deactivated_by is not null and deactivated_at is not null " - "and deactivation_reason is not null)", - name=op.f("ck_actor_profiles_lifecycle_fields"), - ), - ) - op.create_index( - op.f("ix_actor_profiles_status_actor_kind"), - "actor_profiles", - ["status", "actor_kind"], - ) - op.create_index( - op.f("ix_actor_profiles_last_seen_at"), - "actor_profiles", - ["last_seen_at"], - ) - - op.create_table( - "actor_identity_links", - sa.Column("id", sa.String(36), nullable=False), - sa.Column("actor_profile_id", sa.String(36), nullable=False), - sa.Column("issuer", sa.String(200), nullable=False), - sa.Column("subject", sa.String(200), nullable=False), - sa.Column("subject_kind", sa.String(16), nullable=False), - sa.Column("status", sa.String(16), nullable=False), - sa.Column("linked_by", sa.String(120), nullable=False), - sa.Column("linked_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("last_verified_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("revoked_by", sa.String(120)), - sa.Column("revoked_at", sa.DateTime(timezone=True)), - sa.Column("revoked_reason", sa.String(500)), - sa.Column("reactivated_by", sa.String(120)), - sa.Column("reactivated_at", sa.DateTime(timezone=True)), - sa.Column("reactivation_reason", sa.String(500)), - sa.PrimaryKeyConstraint("id", name=op.f("pk_actor_identity_links")), - sa.ForeignKeyConstraint( - ["actor_profile_id"], ["actor_profiles.id"], name=op.f("fk_actor_identity_links_actor_profile_id_actor_profiles") - ), - sa.UniqueConstraint("issuer", "subject", name=op.f("uq_actor_identity_links_external_identity")), - sa.UniqueConstraint("actor_profile_id", name=op.f("uq_actor_identity_links_actor_profile")), - sa.CheckConstraint(f"id ~ '{UUID_PATTERN}'", name=op.f("ck_actor_identity_links_id_uuid")), - sa.CheckConstraint("length(btrim(issuer)) between 1 and 200", name=op.f("ck_actor_identity_links_issuer")), - sa.CheckConstraint("length(btrim(subject)) between 1 and 200", name=op.f("ck_actor_identity_links_subject")), - sa.CheckConstraint("subject_kind in ('human','service')", name=op.f("ck_actor_identity_links_subject_kind")), - sa.CheckConstraint("status in ('active','revoked')", name=op.f("ck_actor_identity_links_status")), - sa.CheckConstraint( - "(status='active' and revoked_by is null and revoked_at is null and revoked_reason is null) or " - "(status='revoked' and revoked_by is not null and revoked_at is not null and revoked_reason is not null)", - name=op.f("ck_actor_identity_links_revocation_fields"), - ), - ) - op.create_index( - op.f("ix_actor_identity_links_issuer_subject_status"), - "actor_identity_links", - ["issuer", "subject", "status"], - ) - - -def _install_guards() -> None: - op.execute( - """ - create function guard_actor_profile_history() returns trigger language plpgsql as $$ - begin - if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; - if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) - is distinct from - (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then - raise exception 'actor profile identity is immutable' using errcode='55000'; - end if; - if old.status='deactivated' and new.status <> 'deactivated' then - raise exception 'deactivated actor is terminal' using errcode='23514'; - end if; - new.updated_at = statement_timestamp(); return new; - end $$ - """ - ) - op.execute( - "create trigger actor_profile_history_guard before update or delete on actor_profiles " - "for each row execute function guard_actor_profile_history()" - ) - op.execute( - """ - create function guard_actor_identity_link_history() returns trigger language plpgsql as $$ - begin - if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; - if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) - is distinct from - (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then - raise exception 'actor identity link anchor is immutable' using errcode='55000'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger actor_identity_link_history_guard before update or delete on actor_identity_links " - "for each row execute function guard_actor_identity_link_history()" - ) - op.execute( - """ - create function validate_canonical_actor_link() returns trigger language plpgsql as $$ - declare profile_row actor_profiles%rowtype; link_count integer; - begin - if tg_table_name='actor_profiles' then - select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; - if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; - if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then - raise exception 'actor and identity kind mismatch' using errcode='23514'; - end if; - else - select * into profile_row from actor_profiles where id=new.actor_profile_id; - if not found or profile_row.actor_kind <> new.subject_kind then - raise exception 'actor and identity kind mismatch' using errcode='23514'; - end if; - end if; return new; - end $$ - """ - ) - op.execute( - "create constraint trigger actor_profile_link_guard after insert or update on actor_profiles " - "deferrable initially deferred for each row execute function validate_canonical_actor_link()" - ) - op.execute( - "create constraint trigger actor_identity_link_profile_guard after insert or update on actor_identity_links " - "deferrable initially deferred for each row execute function validate_canonical_actor_link()" - ) - - -def upgrade() -> None: - """Consume classified legacy evidence and install one canonical actor root.""" - bind = op.get_bind() - bind.execute(sa.text("lock table actor_profiles in access exclusive mode")) - bind.execute(sa.text("lock table actor_identities in access exclusive mode")) - rows = _legacy_rows(bind) - envelope = _classification(bind, rows) - kinds = {entry.actor_id: entry.subject_kind for entry in envelope.classifications} if envelope else {} - - _rename_legacy_tables() - _create_canonical_tables() - op.create_table( - "actor_profile_migration_state", - sa.Column("id", sa.Integer(), nullable=False), - sa.Column("schema_version", sa.Integer(), nullable=False), - sa.Column("classified_count", sa.Integer(), nullable=False), - sa.Column("source_row_set_sha256", sa.String(64), nullable=False), - sa.Column("manifest_sha256", sa.String(64)), - sa.Column("envelope_sha256", sa.String(64)), - sa.Column("migrated_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.PrimaryKeyConstraint("id", name=op.f("pk_actor_profile_migration_state")), - sa.CheckConstraint("id=1 and schema_version=1 and classified_count >= 0", name=op.f("ck_actor_profile_migration_state_singleton")), - sa.CheckConstraint( - "(classified_count=0 and manifest_sha256 is null and envelope_sha256 is null) or " - "(classified_count>0 and manifest_sha256 is not null and envelope_sha256 is not null)", - name=op.f("ck_actor_profile_migration_state_evidence"), - ), - ) - bind.execute( - sa.text( - "insert into actor_profile_migration_state " - "(id,schema_version,classified_count,source_row_set_sha256,manifest_sha256,envelope_sha256) " - "values (1,1,:count,:source,:manifest,:envelope)" - ), - { - "count": len(rows), - "source": envelope.source_row_set_sha256 if envelope else source_row_set_sha256(()), - "manifest": envelope.manifest_sha256 if envelope else None, - "envelope": envelope.envelope_sha256 if envelope else None, - }, - ) - legacy = bind.execute( - sa.text( - "select actor_id, external_subject, external_issuer, " - "first_seen_at, last_seen_at, updated_at from legacy_actor_identities order by actor_id" - ) - ).all() - for row in legacy: - kind = kinds[row.actor_id] - profile_method = "automatic_first_access" if kind == "human" else "manual_service_provisioning" - creator = row.actor_id if kind == "human" else "workstream:system:legacy-migration" - link_id = str(uuid5(NAMESPACE_URL, f"workstream:identity-link:{row.actor_id}")) - bind.execute( - sa.text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,display_name,contact_email,created_by,created_at,updated_at,last_seen_at) " - "values (:id,:kind,'active',:method,null,null,:creator,:created,:updated,:last_seen)" - ), - { - "id": row.actor_id, - "kind": kind, - "method": profile_method, - "creator": creator, - "created": row.first_seen_at, - "updated": row.updated_at, - "last_seen": row.last_seen_at, - }, - ) - bind.execute( - sa.text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by,linked_at,last_verified_at) " - "values (:id,:profile,:issuer,:subject,:kind,'active',:linked_by,:linked_at,:verified_at)" - ), - { - "id": link_id, - "profile": row.actor_id, - "issuer": row.external_issuer, - "subject": row.external_subject, - "kind": kind, - "linked_by": creator, - "linked_at": row.first_seen_at, - "verified_at": row.last_seen_at, - }, - ) - _install_guards() - - -def downgrade() -> None: - """Restore the legacy registry using only durable database state.""" - bind = op.get_bind() - bind.execute(sa.text("lock table actor_profiles in access exclusive mode")) - bind.execute(sa.text("lock table actor_identity_links in access exclusive mode")) - bind.execute(sa.text("lock table legacy_actor_identities in access exclusive mode")) - unsafe_state = bind.execute( - sa.text( - "select exists(" - "select 1 from actor_profiles p join actor_identity_links l " - "on l.actor_profile_id=p.id " - "where p.status <> 'active' or l.status <> 'active'" - ")" - ) - ).scalar_one() - if unsafe_state: - raise RuntimeError("canonical actor downgrade refused: inactive authority state") - bind.execute( - sa.text( - "insert into legacy_actor_identities " - "(actor_id,external_subject,external_issuer,display_name,email,last_seen_roles,last_claim_snapshot,auth_source,is_dev_auth,first_seen_at,last_seen_at,updated_at) " - "select p.id,l.subject,l.issuer,p.display_name,p.contact_email,'[]'::json,'{}'::json,'flow',false,p.created_at,coalesce(p.last_seen_at,p.created_at),p.updated_at " - "from actor_profiles p join actor_identity_links l on l.actor_profile_id=p.id " - "on conflict (actor_id) do update set " - "display_name=excluded.display_name,email=excluded.email," - "last_seen_at=excluded.last_seen_at,updated_at=excluded.updated_at" - ) - ) - op.execute("drop trigger actor_identity_link_profile_guard on actor_identity_links") - op.execute("drop trigger actor_profile_link_guard on actor_profiles") - op.execute("drop function validate_canonical_actor_link()") - op.execute("drop trigger actor_identity_link_history_guard on actor_identity_links") - op.execute("drop function guard_actor_identity_link_history()") - op.execute("drop trigger actor_profile_history_guard on actor_profiles") - op.execute("drop function guard_actor_profile_history()") - op.drop_table("actor_identity_links") - op.drop_table("actor_profiles") - op.drop_table("actor_profile_migration_state") - - statements = ( - "alter table legacy_actor_identities rename constraint pk_legacy_actor_identities to pk_actor_identities", - "alter table legacy_actor_identities rename constraint uq_legacy_actor_identities_external_identity to uq_actor_identities_external_identity", - "alter table legacy_workflow_eligibility rename constraint pk_legacy_workflow_eligibility to pk_actor_profiles", - "alter table legacy_workflow_eligibility rename constraint ck_legacy_workflow_eligibility_profile_type to ck_actor_profiles_ck_actor_profiles_profile_type", - "alter table legacy_workflow_eligibility rename constraint ck_legacy_workflow_eligibility_status to ck_actor_profiles_ck_actor_profiles_status", - "alter table legacy_workflow_eligibility rename constraint uq_legacy_workflow_eligibility_actor_type_scope to uq_actor_profiles_actor_type_scope", - "alter table legacy_workflow_eligibility rename constraint fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities to fk_actor_profiles_actor_id_actor_identities", - "alter index ix_legacy_workflow_eligibility_actor_id rename to ix_actor_profiles_actor_id", - "alter index ix_legacy_workflow_eligibility_profile_type rename to ix_actor_profiles_profile_type", - "alter index ix_legacy_workflow_eligibility_status rename to ix_actor_profiles_status", - ) - for statement in statements: - op.execute(statement) - op.rename_table("legacy_actor_identities", "actor_identities") - op.rename_table("legacy_workflow_eligibility", "actor_profiles") diff --git a/backend/alembic/versions/0021_authorization_action_evidence.py b/backend/alembic/versions/0021_authorization_action_evidence.py deleted file mode 100644 index d3d7a8034..000000000 --- a/backend/alembic/versions/0021_authorization_action_evidence.py +++ /dev/null @@ -1,297 +0,0 @@ -"""add closed permission and action audit parity - -Revision ID: 0021_auth_action_evidence -Revises: 0020_canonical_actor_profile -Create Date: 2026-07-15 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0021_auth_action_evidence" -down_revision = "0020_canonical_actor_profile" -branch_labels = None -depends_on = None - -HISTORICAL_PERMISSIONS = """actor.profile.read_self actor.profile.update_self actor.profile.read_any -actor.profile.suspend actor.profile.reactivate actor.profile.deactivate actor.identity_link.read -actor.identity_link.revoke actor.identity_link.reactivate actor.service.provision admin_role.read -admin_role.grant admin_role.revoke project.create project.read project.update project.archive -project.guide.manage project.effective_policy.manage project.task.manage project.review_policy.manage -project.role_grant.read project.role_grant.manage task.queue.read task.claim submission.create -submission.read_own submission.read_for_review review.queue.read review.queue.inspect review.claim -review.release review.decline_preference review.decision review.lease.force_release review.chain.read -contribution.read_self contribution.read_project compensation.policy.manage -compensation.adapter_binding.manage compensation.award.read compensation.delivery.reconcile -operations.status.read operations.timer.run operations.reconcile.run operations.outbox.retry -operations.projection.rebuild audit.read audit.export""".split() - -NEW_PERMISSIONS = """operations.task.start_override operations.submission_gate.repair -operations.checker.retry artifact.binding.read artifact.replica.read artifact.receipt.read -artifact.verification_job.read artifact.verification_job.retry artifact.recovery_attempt.read -artifact.audit.read artifact.guide_source.ingest artifact.upload_session.create -artifact.upload_session.read artifact.upload_item.write artifact.upload_session.seal -artifact.upload_session.cancel artifact.upload_session.expire artifact.binding.create -artifact.verification.execute artifact.pending_work.scan artifact.put_attempt.resolve -artifact.guide_source.read artifact.checker_input.materialize artifact.checker_output.write -review.queue.override""".split() - -PERMISSIONS = HISTORICAL_PERMISSIONS + NEW_PERMISSIONS - -ACTION_PERMISSION_PAIRS = ( - ("actor.profile.read_self", "actor.profile.read_self"), - ("actor.profile.update_self", "actor.profile.update_self"), - ("operations.task.start_override", "operations.task.start_override"), - ("operations.submission_gate.repair", "operations.submission_gate.repair"), - ("operations.checker.retry", "operations.checker.retry"), - ("submission.create", "submission.create"), - ("review.queue.read", "review.queue.read"), - ("review.queue.inspect", "review.queue.inspect"), - ("review.claim", "review.claim"), - ("review.release", "review.release"), - ("review.decline_preference", "review.decline_preference"), - ("review.preference_expiry.run", "operations.timer.run"), - ("review.lease_expiry.run", "operations.timer.run"), - ("review.context.read", "submission.read_for_review"), - ("review.chain.read", "review.chain.read"), - ("review.finding_evidence.ingest", "review.decision"), - ("review.decision", "review.decision"), - ("review.finding_response_evidence.ingest", "submission.create"), - ("review.lease.force_release", "review.lease.force_release"), - ("review.queue.routing.override", "review.queue.override"), - ("review.queue.routing.correct", "review.queue.override"), - ("review.queue.close", "review.queue.override"), - ("review.reconcile.run", "operations.reconcile.run"), - ("review.artifact_reference.reconcile", "operations.reconcile.run"), - ("review.projection.rebuild", "operations.projection.rebuild"), - ("artifact.binding.read", "artifact.binding.read"), - ("artifact.replica.read", "artifact.replica.read"), - ("artifact.receipt.read", "artifact.receipt.read"), - ("artifact.verification_job.read", "artifact.verification_job.read"), - ("artifact.verification_job.retry", "artifact.verification_job.retry"), - ("artifact.recovery_attempt.read", "artifact.recovery_attempt.read"), - ("artifact.audit.read", "artifact.audit.read"), - ("operations.artifact_storage_admission.read", "operations.status.read"), - ("artifact.guide_source.ingest", "artifact.guide_source.ingest"), - ("artifact.guide_source.read", "artifact.guide_source.read"), - ("artifact.upload_session.create", "artifact.upload_session.create"), - ("artifact.upload_session.read", "artifact.upload_session.read"), - ("artifact.upload_item.write", "artifact.upload_item.write"), - ("artifact.upload_session.seal", "artifact.upload_session.seal"), - ("artifact.upload_session.cancel", "artifact.upload_session.cancel"), - ("artifact.upload_session.expire", "artifact.upload_session.expire"), - ("artifact.guide_source.binding.create", "artifact.binding.create"), - ("artifact.submission.binding.create", "artifact.binding.create"), - ("artifact.checker_output.binding.create", "artifact.binding.create"), - ("artifact.verification.execute", "artifact.verification.execute"), - ("artifact.pending_work.scan", "artifact.pending_work.scan"), - ("artifact.put_attempt.resolve", "artifact.put_attempt.resolve"), - ( - "artifact.pre_submit.checker_input.materialize", - "artifact.checker_input.materialize", - ), - ( - "artifact.post_submit.checker_input.materialize", - "artifact.checker_input.materialize", - ), - ("artifact.checker_output.write", "artifact.checker_output.write"), -) - -DENIAL_CODES = """required_scope_missing unsupported_subject_kind service_actor_not_provisioned -identity_link_revoked actor_suspended actor_deactivated permission_not_granted scope_not_authorized -self_grant_forbidden self_role_revoke_forbidden resource_guard_denied actor_not_found grant_not_found -resource_not_found actor_already_suspended actor_not_suspended actor_deactivated_terminal -last_access_administrator admin_role_grant_exists project_role_grant_exists identity_link_conflict -resource_project_mismatch idempotency_mismatch invalid_role_scope invalid_project_role -qualification_snapshot_invalid""".split() - -REASONS = { - "ActorProfileProvisioned": ("automatic_first_access",), - "ServiceActorProvisioned": ("manual_service_provisioning",), - "ActorIdentityLinked": ("identity_lifecycle_change",), - "ActorIdentityLinkRevoked": ("identity_lifecycle_change",), - "ActorIdentityLinkReactivated": ("identity_lifecycle_change",), - "ActorProfileSuspended": ("security_response", "administrative_correction"), - "ActorProfileReactivated": ("administrative_correction",), - "ActorProfileDeactivated": ("security_response", "administrative_correction"), - "InitialAccessAdministratorBootstrapped": ("initial_access_bootstrap",), - "AdminRoleGrantIssued": ("authority_assignment",), - "AdminRoleGrantRevoked": ("authority_revocation",), - "AdminRoleGrantIssueDenied": ("authorization_policy_denial",), - "LastAccessAdministratorOperationDenied": ("authorization_policy_denial",), - "ProjectRoleQualificationSnapshotCaptured": ("qualification_evidence_captured",), - "ProjectRoleGrantIssued": ("authority_assignment",), - "ProjectRoleGrantReplaced": ("authority_replacement",), - "ProjectRoleGrantRevoked": ("authority_revocation",), - "SensitiveAuthorizationAllowed": ("authorization_evaluation",), - "SensitiveAuthorizationDenied": ("authorization_evaluation",), - "AuthorityInvalidationRequested": ("authority_state_changed",), -} - - -def _tokens(values: list[str] | tuple[str, ...]) -> str: - return ", ".join(f"'{value}'" for value in values) - - -def _pair_tokens() -> str: - return ", ".join( - f"('{action}', '{permission}')" for action, permission in ACTION_PERMISSION_PAIRS - ) - - -def _create_registry_constraint(permissions: list[str]) -> None: - reason_rules = " or ".join( - f"(event_type = '{event}' and reason in ({_tokens(reasons)}))" - for event, reasons in REASONS.items() - ) - op.create_check_constraint( - "authority_registries", - "audit_events", - f""" - event_domain <> 'authority' or ( - reason is not null and ({reason_rules}) - and (permission_id is null or permission_id in ({_tokens(permissions)})) - and (denial_code is null or denial_code in ({_tokens(DENIAL_CODES)})) - ) - """, - ) - - -def _create_privacy_constraint(permissions: list[str]) -> None: - entity_tokens = _tokens( - ( - "actor_profile", - "actor_identity_link", - "admin_role_grant", - "qualification_snapshot", - "project_role_grant", - "authorization_decision", - "authority_invalidation", - ) - ) - resource_tokens = _tokens( - """actor_profile actor_identity_link admin_role_grant project project_role_grant task - submission review contribution compensation_award compensation_delivery operations - audit_event""".split() - ) - uuid_target_tokens = _tokens( - ( - "actor_profile", - "actor_identity_link", - "admin_role_grant", - "qualification_snapshot", - "project_role_grant", - ) - ) - uuid_pattern = r"^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" - permission_tokens = _tokens(permissions) - op.create_check_constraint( - "authority_privacy_bounds", - "audit_events", - f""" - event_domain <> 'authority' or ( - id ~ '{uuid_pattern}' and entity_type in ({entity_tokens}) and entity_id ~ '{uuid_pattern}' - and ( - (actor_ref_kind in ('legacy_actor', 'actor_profile') and actor_id ~ '{uuid_pattern}') - or (actor_ref_kind = 'system_principal' and actor_id = 'workstream:system:bootstrap') - ) - and ( - target_actor_ref is null - or (target_actor_ref_kind = 'actor_profile' and target_actor_ref ~ '{uuid_pattern}') - ) - and (matched_grant_id is null or matched_grant_id ~ '{uuid_pattern}') - and (project_id is null or project_id ~ '{uuid_pattern}') - and (resource_type is null or resource_type in ({resource_tokens})) - and (resource_id is null or resource_id ~ '{uuid_pattern}') - and ( - target_ref_kind is null - or (target_ref_kind in ({uuid_target_tokens}) and target_ref_id ~ '{uuid_pattern}') - or (target_ref_kind = 'permission_registry' and target_ref_id in ({permission_tokens})) - ) - and ( - invalidation_target_kind is null - or ( - invalidation_target_kind in ({uuid_target_tokens}) - and invalidation_target_ref ~ '{uuid_pattern}' - ) - or ( - invalidation_target_kind = 'permission_registry' - and invalidation_target_ref in ({permission_tokens}) - ) - ) - and ( - entity_type not in ('authorization_decision', 'authority_invalidation') - or entity_id = id - ) - and ( - resource_type <> 'project' or resource_id is null - or (project_id is not null and resource_id = project_id) - ) - ) - """, - ) - - -def upgrade() -> None: - """Install action-aware audit constraints without activating any action.""" - op.add_column("audit_events", sa.Column("action_id", sa.String(160), nullable=True)) - op.drop_constraint("authority_registries", "audit_events", type_="check") - op.drop_constraint("authority_privacy_bounds", "audit_events", type_="check") - _create_registry_constraint(PERMISSIONS) - _create_privacy_constraint(PERMISSIONS) - - # Availability is typed lifecycle state; SQL remains stable across owner activation. - pair_tokens = _pair_tokens() - op.create_check_constraint( - "authorization_action_evidence", - "audit_events", - f""" - ( - event_domain = 'legacy_lifecycle' and action_id is null - ) or ( - event_domain = 'authority' - and ( - action_id is null or ( - event_type in ('SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied') - and permission_id is not null - and (action_id, permission_id) in ({pair_tokens}) - ) - ) - and ( - permission_id is null - or permission_id not in ({_tokens(NEW_PERMISSIONS)}) - or ( - action_id is not null - and (action_id, permission_id) in ({pair_tokens}) - ) - ) - ) - """, - ) - - -def downgrade() -> None: - """Remove action parity only when no forward evidence would be discarded.""" - bind = op.get_bind() - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - has_forward_evidence = bind.execute( - sa.text( - "select exists(select 1 from audit_events where action_id is not null " - f"or permission_id in ({_tokens(NEW_PERMISSIONS)}) " - "or (target_ref_kind = 'permission_registry' " - f"and target_ref_id in ({_tokens(NEW_PERMISSIONS)})) " - "or (invalidation_target_kind = 'permission_registry' " - f"and invalidation_target_ref in ({_tokens(NEW_PERMISSIONS)})))" - ) - ).scalar_one() - if has_forward_evidence: - raise RuntimeError("cannot downgrade non-empty authorization action evidence") - - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - op.drop_constraint("authority_registries", "audit_events", type_="check") - op.drop_constraint("authority_privacy_bounds", "audit_events", type_="check") - _create_registry_constraint(HISTORICAL_PERMISSIONS) - _create_privacy_constraint(HISTORICAL_PERMISSIONS) - op.drop_column("audit_events", "action_id") diff --git a/backend/alembic/versions/0022_bootstrap_admin_grants.py b/backend/alembic/versions/0022_bootstrap_admin_grants.py deleted file mode 100644 index ccdaab10b..000000000 --- a/backend/alembic/versions/0022_bootstrap_admin_grants.py +++ /dev/null @@ -1,630 +0,0 @@ -"""add one-time bootstrap and immutable administrative grants - -Revision ID: 0022_bootstrap_admin_grants -Revises: 0021_auth_action_evidence -Create Date: 2026-07-15 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0022_bootstrap_admin_grants" -down_revision = "0021_auth_action_evidence" -branch_labels = depends_on = None - -AUTH_08_ACTIONS = ( - "authorization.permission_catalogue.read", - "authorization.admin_role_definitions.read", - "admin_role_grant.list", - "actor.admin_role_grant_history.read", - "admin_role_grant.issue", - "admin_role_grant.revoke", - "admin_role_grant.bootstrap", -) - -AUTH_08_EVIDENCE_EVENTS = ( - "InitialAccessAdministratorBootstrapped", - "AdminRoleGrantIssued", - "AdminRoleGrantRevoked", - "AdminRoleGrantIssueDenied", - "LastAccessAdministratorOperationDenied", -) - -ACTION_PERMISSION_PAIRS = ( - ("actor.profile.read_self", "actor.profile.read_self"), - ("actor.profile.update_self", "actor.profile.update_self"), - ("operations.task.start_override", "operations.task.start_override"), - ("operations.submission_gate.repair", "operations.submission_gate.repair"), - ("operations.checker.retry", "operations.checker.retry"), - ("submission.create", "submission.create"), - ("review.queue.read", "review.queue.read"), - ("review.queue.inspect", "review.queue.inspect"), - ("review.claim", "review.claim"), - ("review.release", "review.release"), - ("review.decline_preference", "review.decline_preference"), - ("review.preference_expiry.run", "operations.timer.run"), - ("review.lease_expiry.run", "operations.timer.run"), - ("review.context.read", "submission.read_for_review"), - ("review.chain.read", "review.chain.read"), - ("review.finding_evidence.ingest", "review.decision"), - ("review.decision", "review.decision"), - ("review.finding_response_evidence.ingest", "submission.create"), - ("review.lease.force_release", "review.lease.force_release"), - ("review.queue.routing.override", "review.queue.override"), - ("review.queue.routing.correct", "review.queue.override"), - ("review.queue.close", "review.queue.override"), - ("review.reconcile.run", "operations.reconcile.run"), - ("review.artifact_reference.reconcile", "operations.reconcile.run"), - ("review.projection.rebuild", "operations.projection.rebuild"), - ("artifact.binding.read", "artifact.binding.read"), - ("artifact.replica.read", "artifact.replica.read"), - ("artifact.receipt.read", "artifact.receipt.read"), - ("artifact.verification_job.read", "artifact.verification_job.read"), - ("artifact.verification_job.retry", "artifact.verification_job.retry"), - ("artifact.recovery_attempt.read", "artifact.recovery_attempt.read"), - ("artifact.audit.read", "artifact.audit.read"), - ("operations.artifact_storage_admission.read", "operations.status.read"), - ("artifact.guide_source.ingest", "artifact.guide_source.ingest"), - ("artifact.guide_source.read", "artifact.guide_source.read"), - ("artifact.upload_session.create", "artifact.upload_session.create"), - ("artifact.upload_session.read", "artifact.upload_session.read"), - ("artifact.upload_item.write", "artifact.upload_item.write"), - ("artifact.upload_session.seal", "artifact.upload_session.seal"), - ("artifact.upload_session.cancel", "artifact.upload_session.cancel"), - ("artifact.upload_session.expire", "artifact.upload_session.expire"), - ("artifact.guide_source.binding.create", "artifact.binding.create"), - ("artifact.submission.binding.create", "artifact.binding.create"), - ("artifact.checker_output.binding.create", "artifact.binding.create"), - ("artifact.verification.execute", "artifact.verification.execute"), - ("artifact.pending_work.scan", "artifact.pending_work.scan"), - ("artifact.put_attempt.resolve", "artifact.put_attempt.resolve"), - ("artifact.pre_submit.checker_input.materialize", "artifact.checker_input.materialize"), - ("artifact.post_submit.checker_input.materialize", "artifact.checker_input.materialize"), - ("artifact.checker_output.write", "artifact.checker_output.write"), - ("authorization.permission_catalogue.read", "admin_role.read"), - ("authorization.admin_role_definitions.read", "admin_role.read"), - ("admin_role_grant.list", "admin_role.read"), - ("actor.admin_role_grant_history.read", "admin_role.read"), - ("admin_role_grant.issue", "admin_role.grant"), - ("admin_role_grant.revoke", "admin_role.revoke"), - ("admin_role_grant.bootstrap", "admin_role.grant"), -) - - -def _tokens(values: tuple[str, ...]) -> str: - return ", ".join(f"'{value}'" for value in values) - - -def _pair_tokens(pairs: tuple[tuple[str, str], ...]) -> str: - return ", ".join(f"('{action}', '{permission}')" for action, permission in pairs) - - -def _create_action_constraint(pairs: tuple[tuple[str, str], ...]) -> None: - new_permissions = tuple( - "operations.task.start_override operations.submission_gate.repair operations.checker.retry " - "artifact.binding.read artifact.replica.read artifact.receipt.read " - "artifact.verification_job.read artifact.verification_job.retry " - "artifact.recovery_attempt.read artifact.audit.read artifact.guide_source.ingest " - "artifact.upload_session.create artifact.upload_session.read artifact.upload_item.write " - "artifact.upload_session.seal artifact.upload_session.cancel artifact.upload_session.expire " - "artifact.binding.create artifact.verification.execute artifact.pending_work.scan " - "artifact.put_attempt.resolve artifact.guide_source.read " - "artifact.checker_input.materialize artifact.checker_output.write review.queue.override".split() - ) - pair_tokens = _pair_tokens(pairs) - op.create_check_constraint( - "authorization_action_evidence", - "audit_events", - f""" - (event_domain = 'legacy_lifecycle' and action_id is null) or ( - event_domain = 'authority' - and ( - action_id is null or ( - event_type in ('SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied') - and permission_id is not null - and (action_id, permission_id) in ({pair_tokens}) - ) - ) - and ( - permission_id is null or permission_id not in ({_tokens(new_permissions)}) - or (action_id is not null and (action_id, permission_id) in ({pair_tokens})) - ) - ) - """, - ) - - -def _replace_fact_function(*, admin_issue_direction: bool) -> None: - invalidation = ( - "(before_state::jsonb = '{\"effective\": true}'::jsonb and " - "after_state::jsonb = '{\"effective\": false}'::jsonb) or " - "(before_state::jsonb = '{\"effective\": false}'::jsonb and " - "after_state::jsonb = '{\"effective\": true}'::jsonb)" - if admin_issue_direction - else "before_state::jsonb = '{\"effective\": true}'::jsonb and " - "after_state::jsonb = '{\"effective\": false}'::jsonb" - ) - op.execute( - f""" - create or replace function authority_event_facts_are_safe( - event_name text, before_state json, after_state json, envelope_project_id text - ) returns boolean language plpgsql immutable as $$ - begin - if (before_state is not null and not authority_facts_are_safe(before_state)) - or (after_state is not null and not authority_facts_are_safe(after_state)) then - return false; - end if; - case event_name - when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = - '{{"status":"active","subject_kind":"human","provisioning_method":"automatic_first_access"}}'::jsonb; - when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = - '{{"status":"active","subject_kind":"service","provisioning_method":"manual_service_provisioning"}}'::jsonb; - when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( - '{{"status":"active","subject_kind":"human"}}'::jsonb, - '{{"status":"active","subject_kind":"service"}}'::jsonb); - when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{{"status":"active"}}'::jsonb and after_state::jsonb='{{"status":"revoked"}}'::jsonb; - when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{{"status":"revoked"}}'::jsonb and after_state::jsonb='{{"status":"active"}}'::jsonb; - when 'ActorProfileSuspended' then return before_state::jsonb='{{"status":"active"}}'::jsonb and after_state::jsonb='{{"status":"suspended"}}'::jsonb; - when 'ActorProfileReactivated' then return before_state::jsonb='{{"status":"suspended"}}'::jsonb and after_state::jsonb='{{"status":"active"}}'::jsonb; - when 'ActorProfileDeactivated' then return before_state::jsonb in ('{{"status":"active"}}'::jsonb,'{{"status":"suspended"}}'::jsonb) and after_state::jsonb='{{"status":"deactivated"}}'::jsonb; - when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); - when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); - when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','both'],'active',true,envelope_project_id); - when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then - return authority_grant_facts_are_safe(before_state, - case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','both'] end, - 'active',true,envelope_project_id) - and authority_grant_facts_are_safe(after_state, - case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','both'] end, - 'revoked',false,envelope_project_id) - and before_state->>'role'=after_state->>'role' - and before_state->>'scope_type'=after_state->>'scope_type' - and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); - when 'ProjectRoleGrantReplaced' then return - authority_grant_facts_are_safe(before_state,array['submitter','reviewer','both'],'active',true,envelope_project_id) - and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','both'],'active',true,envelope_project_id) - and before_state->>'scope_id'=after_state->>'scope_id'; - when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{{"status":"captured"}}'::jsonb; - when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; - when 'SensitiveAuthorizationAllowed' then return before_state is null and after_state::jsonb='{{"allowed": true}}'::jsonb; - when 'SensitiveAuthorizationDenied' then return before_state is null and after_state::jsonb='{{"allowed": false}}'::jsonb; - when 'AuthorityInvalidationRequested' then return {invalidation}; - else return false; - end case; - end $$ - """ - ) - - -def _replace_linked_function(*, admin_projection: bool) -> None: - admin_branch = "record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke')" - direction_checks = """ - or (record_row.operation='admin_role_grant.issue' and - (new.before_facts::jsonb <> '{"effective": false}'::jsonb or new.after_facts::jsonb <> '{"effective": true}'::jsonb)) - or (record_row.operation='admin_role_grant.revoke' and - (new.before_facts::jsonb <> '{"effective": true}'::jsonb or new.after_facts::jsonb <> '{"effective": false}'::jsonb)) - or (not (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke')) and - (new.before_facts::jsonb <> '{"effective": true}'::jsonb or new.after_facts::jsonb <> '{"effective": false}'::jsonb)) - """ - if not admin_projection: - admin_branch = "false" - direction_checks = """ - or (new.before_facts::jsonb <> '{"effective": true}'::jsonb - or new.after_facts::jsonb <> '{"effective": false}'::jsonb) - """ - op.execute( - f""" - create or replace function validate_linked_authority_event() returns trigger - language plpgsql as $$ - declare record_row authority_idempotency_records%rowtype; - cause_row audit_events%rowtype; expected_permission text; - expected_resource text; expected_invalidation_resource text; - expected_invalidation_id text; valid_success boolean; - begin - if new.event_domain <> 'authority' then return new; end if; - valid_success := new.event_type in ( - 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', - 'ProjectRoleGrantIssued','ProjectRoleGrantReplaced','ProjectRoleGrantRevoked', - 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', - 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); - if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then - if new.idempotency_reference is not null then - raise exception 'invalid authority idempotency event' using errcode='23514'; - end if; return new; - end if; - if new.idempotency_reference is null then - raise exception 'authority event requires idempotency reference' using errcode='23514'; - end if; - select * into record_row from authority_idempotency_records - where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; - if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; - if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; - expected_permission := case record_row.operation - when 'service_actor.create' then 'actor.service.provision' - when 'admin_role_grant.issue' then 'admin_role.grant' - when 'admin_role_grant.revoke' then 'admin_role.revoke' - when 'project_role_grant.issue' then 'project.role_grant.manage' - when 'project_role_grant.revoke' then 'project.role_grant.manage' - when 'actor_profile.suspend' then 'actor.profile.suspend' - when 'actor_profile.reactivate' then 'actor.profile.reactivate' - when 'actor_profile.deactivate' then 'actor.profile.deactivate' - when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' - when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; - expected_resource := case - when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' - when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' - when record_row.operation like 'project_role_grant.%' then 'project_role_grant' - else 'actor_identity_link' end; - if new.permission_id <> expected_permission or new.resource_id is null then - raise exception 'authority event does not match operation' using errcode='23514'; - end if; - if new.event_type='AuthorityInvalidationRequested' then - select * into cause_row from audit_events where id=new.invalidation_cause_event_id; - expected_invalidation_resource := case when {admin_branch} then 'actor_profile' else expected_resource end; - expected_invalidation_id := case when {admin_branch} then cause_row.target_actor_ref else cause_row.resource_id end; - if not found or cause_row.idempotency_reference is distinct from record_row.id - or cause_row.actor_ref_kind is distinct from new.actor_ref_kind - or cause_row.actor_id is distinct from new.actor_id - or cause_row.permission_id is distinct from new.permission_id - or cause_row.resource_type is distinct from expected_resource - or new.resource_type is distinct from expected_invalidation_resource - or new.resource_id is distinct from expected_invalidation_id - or new.invalidation_target_kind is distinct from expected_invalidation_resource - or new.invalidation_target_ref is distinct from expected_invalidation_id - or cause_row.target_ref_kind is distinct from cause_row.resource_type - or cause_row.target_ref_id is distinct from cause_row.resource_id - or cause_row.request_id is distinct from new.request_id - or cause_row.correlation_id is distinct from new.correlation_id - or cause_row.project_id is distinct from new.project_id - or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id - or ({admin_branch} and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) - {direction_checks} - or not ( - (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or - (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or - (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or - (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued','ProjectRoleGrantReplaced')) or - (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or - (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or - (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or - (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or - (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or - (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then - raise exception 'invalid linked authority cause' using errcode='23514'; - end if; - else - if new.resource_type <> expected_resource or new.entity_type <> expected_resource - or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource - or new.target_ref_id is distinct from new.resource_id - or new.invalidation_cause_event_id is not null - or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null - or not ( - (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or - (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or - (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or - (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued','ProjectRoleGrantReplaced')) or - (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or - (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or - (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or - (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or - (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or - (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then - raise exception 'authority success event does not match operation' using errcode='23514'; - end if; - end if; return new; - end $$ - """ - ) - - -def _create_tables() -> None: - op.create_table( - "admin_role_grants", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("target_actor_profile_id", sa.String(36), nullable=False), - sa.Column("role", sa.String(40), nullable=False), - sa.Column("scope_type", sa.String(16), nullable=False), - sa.Column("scope_project_id", sa.String(36)), - sa.Column("status", sa.String(16), nullable=False, server_default="active"), - sa.Column("version", sa.SmallInteger(), nullable=False, server_default="1"), - sa.Column("granted_by_actor_profile_id", sa.String(36)), - sa.Column("granted_by_system_principal", sa.String(100)), - sa.Column("granted_by_admin_role_grant_id", sa.Uuid()), - sa.Column("grant_reason", sa.Text(), nullable=False), - sa.Column( - "granted_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.text("clock_timestamp()"), - ), - sa.Column("revoked_by_actor_profile_id", sa.String(36)), - sa.Column("revoked_by_admin_role_grant_id", sa.Uuid()), - sa.Column("revoked_reason", sa.Text()), - sa.Column("revoked_at", sa.DateTime(timezone=True)), - sa.PrimaryKeyConstraint("id", name=op.f("pk_admin_role_grants")), - sa.ForeignKeyConstraint( - ["target_actor_profile_id"], - ["actor_profiles.id"], - name=op.f("fk_admin_role_grants_target_actor_profile_id_actor_profiles"), - ), - sa.ForeignKeyConstraint( - ["scope_project_id"], - ["projects.id"], - name=op.f("fk_admin_role_grants_scope_project_id_projects"), - ), - sa.ForeignKeyConstraint( - ["granted_by_actor_profile_id"], - ["actor_profiles.id"], - name=op.f("fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles"), - ), - sa.ForeignKeyConstraint( - ["granted_by_admin_role_grant_id"], - ["admin_role_grants.id"], - name=op.f("fk_admin_role_grants_granted_by_admin_role_grant_id_admin_role_grants"), - ), - sa.ForeignKeyConstraint( - ["revoked_by_actor_profile_id"], - ["actor_profiles.id"], - name=op.f("fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles"), - ), - sa.ForeignKeyConstraint( - ["revoked_by_admin_role_grant_id"], - ["admin_role_grants.id"], - name=op.f("fk_admin_role_grants_revoked_by_admin_role_grant_id_admin_role_grants"), - ), - sa.CheckConstraint( - "role in ('access_administrator','operator','project_manager','finance_authority','audit_authority')", - name=op.f("ck_admin_role_grants_role"), - ), - sa.CheckConstraint( - "scope_type in ('system','project')", name=op.f("ck_admin_role_grants_scope_type") - ), - sa.CheckConstraint( - "(scope_type='system' and scope_project_id is null) or (scope_type='project' and scope_project_id is not null and role not in ('access_administrator','operator'))", - name=op.f("ck_admin_role_grants_role_scope"), - ), - sa.CheckConstraint( - "(granted_by_system_principal='workstream:system:bootstrap' and granted_by_actor_profile_id is null and granted_by_admin_role_grant_id is null) or (granted_by_system_principal is null and granted_by_actor_profile_id is not null and granted_by_admin_role_grant_id is not null)", - name=op.f("ck_admin_role_grants_grant_attribution"), - ), - sa.CheckConstraint( - "octet_length(grant_reason) between 1 and 500", - name=op.f("ck_admin_role_grants_grant_reason"), - ), - sa.CheckConstraint( - "(status='active' and version=1 and revoked_by_actor_profile_id is null and revoked_by_admin_role_grant_id is null and revoked_reason is null and revoked_at is null) or (status='revoked' and version=2 and revoked_by_actor_profile_id is not null and revoked_by_admin_role_grant_id is not null and revoked_reason is not null and octet_length(revoked_reason) between 1 and 500 and revoked_at is not null)", - name=op.f("ck_admin_role_grants_lifecycle"), - ), - ) - op.create_index( - "uq_admin_role_grants_active_system", - "admin_role_grants", - ["target_actor_profile_id", "role"], - unique=True, - postgresql_where=sa.text("status='active' and scope_type='system'"), - ) - op.create_index( - "uq_admin_role_grants_active_project", - "admin_role_grants", - ["target_actor_profile_id", "role", "scope_project_id"], - unique=True, - postgresql_where=sa.text("status='active' and scope_type='project'"), - ) - op.create_index( - "ix_admin_role_grants_effective_candidate", - "admin_role_grants", - ["target_actor_profile_id", "status", "scope_type", "scope_project_id"], - ) - op.create_index( - "ix_admin_role_grants_history", - "admin_role_grants", - ["target_actor_profile_id", "granted_at", "id"], - ) - op.create_index( - "ix_admin_role_grants_final_access_admin", - "admin_role_grants", - ["role", "status"], - postgresql_where=sa.text( - "role='access_administrator' and status='active' and scope_type='system'" - ), - ) - - op.create_table( - "authority_control", - sa.Column("id", sa.SmallInteger(), nullable=False), - sa.Column("bootstrap_completed", sa.Boolean(), nullable=False, server_default=sa.false()), - sa.Column("bootstrap_grant_id", sa.Uuid()), - sa.Column("version", sa.SmallInteger(), nullable=False, server_default="0"), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.text("clock_timestamp()"), - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.text("clock_timestamp()"), - ), - sa.PrimaryKeyConstraint("id", name=op.f("pk_authority_control")), - sa.ForeignKeyConstraint( - ["bootstrap_grant_id"], - ["admin_role_grants.id"], - name=op.f("fk_authority_control_bootstrap_grant_id_admin_role_grants"), - ), - sa.CheckConstraint("id=1", name=op.f("ck_authority_control_singleton")), - sa.CheckConstraint( - "(bootstrap_completed=false and bootstrap_grant_id is null and version=0) or (bootstrap_completed=true and bootstrap_grant_id is not null and version=1)", - name=op.f("ck_authority_control_bootstrap_state"), - ), - ) - op.execute( - "insert into authority_control(id,bootstrap_completed,bootstrap_grant_id,version) values (1,false,null,0)" - ) - - -def _create_table_guards() -> None: - statements = ( - """ - create function guard_admin_role_grant() returns trigger language plpgsql as $$ - declare target_kind text; authorizer admin_role_grants%rowtype; - bootstrap_done boolean; - begin - if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; - if tg_op='INSERT' then - select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; - if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; - new.granted_at := clock_timestamp(); - if new.granted_by_system_principal is not null then - if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; - select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; - if bootstrap_done is distinct from false - or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then - raise exception 'bootstrap already completed' using errcode='23514'; - end if; - else - select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; - if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id - or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' - or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; - end if; - return new; - end if; - if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 - or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, - new.granted_by_actor_profile_id,new.granted_by_system_principal, - new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) - is distinct from - (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, - old.granted_by_actor_profile_id,old.granted_by_system_principal, - old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then - raise exception 'invalid admin role grant transition' using errcode='23514'; - end if; - select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; - if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id - or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' - or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; - new.revoked_at := clock_timestamp(); return new; - end $$ - """, - "create trigger admin_role_grants_guard before insert or update or delete on admin_role_grants for each row execute function guard_admin_role_grant()", - """create function reject_admin_role_grant_truncate() returns trigger language plpgsql as $$ - begin raise exception 'admin role grants are immutable' using errcode='55000'; end $$""", - "create trigger admin_role_grants_reject_truncate before truncate on admin_role_grants execute function reject_admin_role_grant_truncate()", - """ - create function guard_authority_control() returns trigger language plpgsql as $$ - begin - if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; - if old.id <> 1 or old.bootstrap_completed or old.version <> 0 - or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 - or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then - raise exception 'invalid authority control transition' using errcode='23514'; - end if; - new.updated_at := clock_timestamp(); return new; - end $$ - """, - "create trigger authority_control_guard before insert or update or delete on authority_control for each row execute function guard_authority_control()", - """create function reject_authority_control_truncate() returns trigger language plpgsql as $$ - begin raise exception 'authority control is immutable' using errcode='55000'; end $$""", - "create trigger authority_control_reject_truncate before truncate on authority_control execute function reject_authority_control_truncate()", - """ - create function validate_bootstrap_authority_state() returns trigger language plpgsql as $$ - declare control authority_control%rowtype; - bootstrap_count bigint; - referenced_bootstrap boolean; - begin - select * into control from authority_control where id=1; - if not found then - raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; - end if; - select count(*) into bootstrap_count from admin_role_grants - where granted_by_system_principal='workstream:system:bootstrap'; - referenced_bootstrap := exists( - select 1 from admin_role_grants - where id=control.bootstrap_grant_id - and granted_by_system_principal='workstream:system:bootstrap' - ); - if (not control.bootstrap_completed and - (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) - or (control.bootstrap_completed and - (control.bootstrap_grant_id is null or control.version <> 1 - or bootstrap_count <> 1 or not referenced_bootstrap)) then - raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; - end if; - return null; - end $$ - """, - "create constraint trigger admin_role_grants_bootstrap_invariant after insert or update or delete on admin_role_grants deferrable initially deferred for each row execute function validate_bootstrap_authority_state()", - "create constraint trigger authority_control_bootstrap_invariant after insert or update or delete on authority_control deferrable initially deferred for each row execute function validate_bootstrap_authority_state()", - ) - for statement in statements: - op.execute(statement) - - -def upgrade() -> None: - """Install irreversible bootstrap state and immutable admin grants.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table authority_idempotency_records, audit_events in access exclusive mode" - ) - ) - if bind.execute( - sa.text( - f"select exists(select 1 from audit_events where event_domain='authority' and event_type in ({_tokens(AUTH_08_EVIDENCE_EVENTS)}))" - ) - ).scalar_one(): - raise RuntimeError("cannot adopt orphan administrative grant evidence") - if bind.execute( - sa.text( - "select exists(select 1 from authority_idempotency_records where operation like 'admin_role_grant.%')" - ) - ).scalar_one(): - raise RuntimeError("cannot adopt orphan administrative idempotency") - _create_tables() - _create_table_guards() - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - _create_action_constraint(ACTION_PERMISSION_PAIRS) - _replace_fact_function(admin_issue_direction=True) - _replace_linked_function(admin_projection=True) - - -def downgrade() -> None: - """Restore 0021 only when no AUTH-08 durable state exists.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table authority_control, admin_role_grants, authority_idempotency_records, audit_events in access exclusive mode" - ) - ) - blocked = bind.execute( - sa.text(f""" - select exists(select 1 from admin_role_grants) - or exists(select 1 from authority_control where bootstrap_completed) - or exists(select 1 from authority_idempotency_records where operation like 'admin_role_grant.%') - or exists(select 1 from audit_events where action_id in ({_tokens(AUTH_08_ACTIONS)}) - or event_type in ({_tokens(AUTH_08_EVIDENCE_EVENTS)})) - """) - ).scalar_one() - if blocked: - raise RuntimeError("cannot downgrade non-empty administrative authority") - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - _create_action_constraint(ACTION_PERMISSION_PAIRS[:-7]) - _replace_fact_function(admin_issue_direction=False) - _replace_linked_function(admin_projection=False) - op.execute("drop trigger authority_control_bootstrap_invariant on authority_control") - op.execute("drop trigger admin_role_grants_bootstrap_invariant on admin_role_grants") - op.execute("drop function validate_bootstrap_authority_state()") - op.execute("drop trigger authority_control_reject_truncate on authority_control") - op.execute("drop trigger authority_control_guard on authority_control") - op.execute("drop function reject_authority_control_truncate()") - op.execute("drop function guard_authority_control()") - op.execute("drop trigger admin_role_grants_reject_truncate on admin_role_grants") - op.execute("drop trigger admin_role_grants_guard on admin_role_grants") - op.execute("drop function reject_admin_role_grant_truncate()") - op.execute("drop function guard_admin_role_grant()") - op.drop_table("authority_control") - op.drop_table("admin_role_grants") diff --git a/backend/alembic/versions/0023_service_actor_identity.py b/backend/alembic/versions/0023_service_actor_identity.py deleted file mode 100644 index 189071bea..000000000 --- a/backend/alembic/versions/0023_service_actor_identity.py +++ /dev/null @@ -1,366 +0,0 @@ -"""add fixed service identities and planned AUTH-09 actions - -Revision ID: 0023_service_actor_identity -Revises: 0022_bootstrap_admin_grants -Create Date: 2026-07-16 -""" - -from __future__ import annotations - -from alembic import op -from pathlib import Path -from pydantic import ValidationError -import sqlalchemy as sa - -from migration_contracts.service_identity_0023 import ( - ExistingServiceActorRow, - SERVICE_IDENTITY_VALUES, - ServiceIdentityMappingError, - database_binding_identifier, - load_migration_mapping, - source_row_set_sha256, -) - -revision = "0023_service_actor_identity" -down_revision = "0022_bootstrap_admin_grants" -branch_labels = depends_on = None -MIGRATION_REPOSITORY_ROOT = Path(__file__).resolve().parents[3] - -AUTH_09_ACTIONS = ( - "actor.profile.read", - "actor.profile.suspend", - "actor.profile.reactivate", - "actor.profile.deactivate", - "actor.identity_link.read", - "actor.identity_link.revoke", - "actor.identity_link.reactivate", - "actor.service.provision", -) - -ACTION_PERMISSION_PAIRS = ( - ("actor.profile.read_self", "actor.profile.read_self"), - ("actor.profile.update_self", "actor.profile.update_self"), - ("operations.task.start_override", "operations.task.start_override"), - ("operations.submission_gate.repair", "operations.submission_gate.repair"), - ("operations.checker.retry", "operations.checker.retry"), - ("submission.create", "submission.create"), - ("review.queue.read", "review.queue.read"), - ("review.queue.inspect", "review.queue.inspect"), - ("review.claim", "review.claim"), - ("review.release", "review.release"), - ("review.decline_preference", "review.decline_preference"), - ("review.preference_expiry.run", "operations.timer.run"), - ("review.lease_expiry.run", "operations.timer.run"), - ("review.context.read", "submission.read_for_review"), - ("review.chain.read", "review.chain.read"), - ("review.finding_evidence.ingest", "review.decision"), - ("review.decision", "review.decision"), - ("review.finding_response_evidence.ingest", "submission.create"), - ("review.lease.force_release", "review.lease.force_release"), - ("review.queue.routing.override", "review.queue.override"), - ("review.queue.routing.correct", "review.queue.override"), - ("review.queue.close", "review.queue.override"), - ("review.reconcile.run", "operations.reconcile.run"), - ("review.artifact_reference.reconcile", "operations.reconcile.run"), - ("review.projection.rebuild", "operations.projection.rebuild"), - ("artifact.binding.read", "artifact.binding.read"), - ("artifact.replica.read", "artifact.replica.read"), - ("artifact.receipt.read", "artifact.receipt.read"), - ("artifact.verification_job.read", "artifact.verification_job.read"), - ("artifact.verification_job.retry", "artifact.verification_job.retry"), - ("artifact.recovery_attempt.read", "artifact.recovery_attempt.read"), - ("artifact.audit.read", "artifact.audit.read"), - ("operations.artifact_storage_admission.read", "operations.status.read"), - ("artifact.guide_source.ingest", "artifact.guide_source.ingest"), - ("artifact.guide_source.read", "artifact.guide_source.read"), - ("artifact.upload_session.create", "artifact.upload_session.create"), - ("artifact.upload_session.read", "artifact.upload_session.read"), - ("artifact.upload_item.write", "artifact.upload_item.write"), - ("artifact.upload_session.seal", "artifact.upload_session.seal"), - ("artifact.upload_session.cancel", "artifact.upload_session.cancel"), - ("artifact.upload_session.expire", "artifact.upload_session.expire"), - ("artifact.guide_source.binding.create", "artifact.binding.create"), - ("artifact.submission.binding.create", "artifact.binding.create"), - ("artifact.checker_output.binding.create", "artifact.binding.create"), - ("artifact.verification.execute", "artifact.verification.execute"), - ("artifact.pending_work.scan", "artifact.pending_work.scan"), - ("artifact.put_attempt.resolve", "artifact.put_attempt.resolve"), - ("artifact.pre_submit.checker_input.materialize", "artifact.checker_input.materialize"), - ("artifact.post_submit.checker_input.materialize", "artifact.checker_input.materialize"), - ("artifact.checker_output.write", "artifact.checker_output.write"), - ("authorization.permission_catalogue.read", "admin_role.read"), - ("authorization.admin_role_definitions.read", "admin_role.read"), - ("admin_role_grant.list", "admin_role.read"), - ("actor.admin_role_grant_history.read", "admin_role.read"), - ("admin_role_grant.issue", "admin_role.grant"), - ("admin_role_grant.revoke", "admin_role.revoke"), - ("admin_role_grant.bootstrap", "admin_role.grant"), - ("actor.profile.read", "actor.profile.read_any"), - ("actor.profile.suspend", "actor.profile.suspend"), - ("actor.profile.reactivate", "actor.profile.reactivate"), - ("actor.profile.deactivate", "actor.profile.deactivate"), - ("actor.identity_link.read", "actor.identity_link.read"), - ("actor.identity_link.revoke", "actor.identity_link.revoke"), - ("actor.identity_link.reactivate", "actor.identity_link.reactivate"), - ("actor.service.provision", "actor.service.provision"), -) - - -def _tokens(values: tuple[str, ...]) -> str: - return ", ".join(f"'{value}'" for value in values) - - -def _pair_tokens(pairs: tuple[tuple[str, str], ...]) -> str: - return ", ".join(f"('{action}', '{permission}')" for action, permission in pairs) - - -def _create_action_constraint(pairs: tuple[tuple[str, str], ...]) -> None: - new_permissions = tuple( - "operations.task.start_override operations.submission_gate.repair operations.checker.retry " - "artifact.binding.read artifact.replica.read artifact.receipt.read " - "artifact.verification_job.read artifact.verification_job.retry " - "artifact.recovery_attempt.read artifact.audit.read artifact.guide_source.ingest " - "artifact.upload_session.create artifact.upload_session.read artifact.upload_item.write " - "artifact.upload_session.seal artifact.upload_session.cancel artifact.upload_session.expire " - "artifact.binding.create artifact.verification.execute artifact.pending_work.scan " - "artifact.put_attempt.resolve artifact.guide_source.read " - "artifact.checker_input.materialize artifact.checker_output.write review.queue.override".split() - ) - pair_tokens = _pair_tokens(pairs) - op.create_check_constraint( - "authorization_action_evidence", - "audit_events", - f""" - (event_domain = 'legacy_lifecycle' and action_id is null) or ( - event_domain = 'authority' - and ( - action_id is null or ( - event_type in ('SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied') - and permission_id is not null - and (action_id, permission_id) in ({pair_tokens}) - ) - ) - and ( - permission_id is null or permission_id not in ({_tokens(new_permissions)}) - or (action_id is not null and (action_id, permission_id) in ({pair_tokens})) - ) - ) - """, - ) - - -def _existing_service_rows(bind) -> tuple[ExistingServiceActorRow, ...]: - raw_rows = bind.execute( - sa.text( - "select p.id,l.issuer,l.subject from actor_profiles p " - "join actor_identity_links l on l.actor_profile_id=p.id " - "where p.actor_kind='service' order by p.id" - ) - ).all() - try: - return tuple( - ExistingServiceActorRow( - actor_profile_id=row[0], - issuer=row[1], - subject=row[2], - ) - for row in raw_rows - ) - except ValidationError: - raise ServiceIdentityMappingError("service_mapping_source_invalid") from None - - -def _database_binding(bind) -> str: - database_name, database_oid = bind.execute( - sa.text( - "select current_database(),oid from pg_database where datname=current_database()" - ) - ).one() - return database_binding_identifier(database_name, database_oid) - - -def _replace_actor_history_guard(*, with_service_identity: bool) -> None: - immutable = "new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at" - if with_service_identity: - immutable = ( - "new.id,new.actor_kind,new.provisioning_method,new.service_identity," - "new.created_by,new.created_at" - ) - old_immutable = immutable.replace("new.", "old.") - op.execute( - f""" - create or replace function guard_actor_profile_history() returns trigger language plpgsql as $$ - begin - if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; - if ({immutable}) is distinct from ({old_immutable}) then - raise exception 'actor profile identity is immutable' using errcode='55000'; - end if; - if old.status='deactivated' and new.status <> 'deactivated' then - raise exception 'deactivated actor is terminal' using errcode='23514'; - end if; - new.updated_at = statement_timestamp(); return new; - end $$ - """ - ) - - -def _add_mapping_state( - *, - mapped_count: int, - source_digest: str, - manifest_digest: str | None, - envelope_digest: str | None, - database_binding: str, -) -> None: - columns = ( - sa.Column("service_identity_mapped_count", sa.Integer()), - sa.Column("service_identity_source_row_set_sha256", sa.String(64)), - sa.Column("service_identity_manifest_sha256", sa.String(64)), - sa.Column("service_identity_envelope_sha256", sa.String(64)), - sa.Column("service_identity_database_binding", sa.String(76)), - ) - for column in columns: - op.add_column("actor_profile_migration_state", column) - op.execute( - sa.text( - "update actor_profile_migration_state set " - "service_identity_mapped_count=:count," - "service_identity_source_row_set_sha256=:source," - "service_identity_manifest_sha256=:manifest," - "service_identity_envelope_sha256=:envelope," - "service_identity_database_binding=:binding where id=1" - ).bindparams( - count=mapped_count, - source=source_digest, - manifest=manifest_digest, - envelope=envelope_digest, - binding=database_binding, - ) - ) - for name in ( - "service_identity_mapped_count", - "service_identity_source_row_set_sha256", - "service_identity_database_binding", - ): - op.alter_column("actor_profile_migration_state", name, nullable=False) - op.create_check_constraint( - "service_identity_evidence", - "actor_profile_migration_state", - "service_identity_mapped_count between 0 and 7 " - "and service_identity_source_row_set_sha256 ~ '^[0-9a-f]{64}$' " - "and service_identity_database_binding ~ '^postgres-v1:[0-9a-f]{64}$' " - "and ((service_identity_mapped_count=0 " - "and service_identity_manifest_sha256 is null " - "and service_identity_envelope_sha256 is null) or " - "(service_identity_mapped_count between 1 and 7 " - "and service_identity_manifest_sha256 ~ '^[0-9a-f]{64}$' " - "and service_identity_envelope_sha256 ~ '^[0-9a-f]{64}$'))", - ) - op.execute( - """ - create function guard_service_identity_migration_evidence() returns trigger - language plpgsql as $$ begin - raise exception 'service identity migration evidence is immutable' using errcode='55000'; - end $$ - """ - ) - op.execute( - "create trigger service_identity_migration_evidence_row_guard " - "before update or delete on actor_profile_migration_state for each row " - "execute function guard_service_identity_migration_evidence()" - ) - op.execute( - "create trigger service_identity_migration_evidence_truncate_guard " - "before truncate on actor_profile_migration_state for each statement " - "execute function guard_service_identity_migration_evidence()" - ) - - -def upgrade() -> None: - """Add fixed service identities without activating any AUTH-09 action.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table actor_profiles,actor_identity_links,actor_profile_migration_state," - "audit_events in access exclusive mode" - ) - ) - rows = _existing_service_rows(bind) - binding = _database_binding(bind) - envelope = load_migration_mapping( - rows, - database_binding=binding, - repository_root=MIGRATION_REPOSITORY_ROOT, - ) - mapping = {row.actor_profile_id: row.service_identity.value for row in envelope.mappings} if envelope else {} - - op.add_column("actor_profiles", sa.Column("service_identity", sa.String(80))) - op.create_unique_constraint("service_identity", "actor_profiles", ["service_identity"]) - for actor_profile_id, service_identity in mapping.items(): - bind.execute( - sa.text( - "update actor_profiles set service_identity=:identity where id=:actor_id" - ), - {"identity": service_identity, "actor_id": actor_profile_id}, - ) - bind.execute(sa.text("set constraints all immediate")) - op.create_check_constraint( - "kind_service_identity", - "actor_profiles", - "(actor_kind='human' and service_identity is null) or " - f"(actor_kind='service' and service_identity in ({_tokens(SERVICE_IDENTITY_VALUES)}))", - ) - _replace_actor_history_guard(with_service_identity=True) - _add_mapping_state( - mapped_count=len(rows), - source_digest=source_row_set_sha256(rows), - manifest_digest=envelope.manifest_sha256 if envelope else None, - envelope_digest=envelope.envelope_sha256 if envelope else None, - database_binding=binding, - ) - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - _create_action_constraint(ACTION_PERMISSION_PAIRS) - - -def downgrade() -> None: - """Restore 0022 only when no fixed service identity or new action evidence exists.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table actor_profiles,actor_identity_links,actor_profile_migration_state," - "audit_events in access exclusive mode" - ) - ) - blocked = bind.execute( - sa.text( - "select exists(select 1 from actor_profiles where service_identity is not null) " - f"or exists(select 1 from audit_events where action_id in ({_tokens(AUTH_09_ACTIONS)}))" - ) - ).scalar_one() - if blocked: - raise RuntimeError("cannot downgrade fixed service identity authority") - - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - _create_action_constraint(ACTION_PERMISSION_PAIRS[:-8]) - op.execute( - "drop trigger service_identity_migration_evidence_truncate_guard " - "on actor_profile_migration_state" - ) - op.execute( - "drop trigger service_identity_migration_evidence_row_guard " - "on actor_profile_migration_state" - ) - op.execute("drop function guard_service_identity_migration_evidence()") - op.drop_constraint("service_identity_evidence", "actor_profile_migration_state", type_="check") - for name in ( - "service_identity_database_binding", - "service_identity_envelope_sha256", - "service_identity_manifest_sha256", - "service_identity_source_row_set_sha256", - "service_identity_mapped_count", - ): - op.drop_column("actor_profile_migration_state", name) - _replace_actor_history_guard(with_service_identity=False) - op.drop_constraint("kind_service_identity", "actor_profiles", type_="check") - op.drop_constraint("service_identity", "actor_profiles", type_="unique") - op.drop_column("actor_profiles", "service_identity") diff --git a/backend/alembic/versions/0024_service_link_verification.py b/backend/alembic/versions/0024_service_link_verification.py deleted file mode 100644 index 468f12256..000000000 --- a/backend/alembic/versions/0024_service_link_verification.py +++ /dev/null @@ -1,57 +0,0 @@ -"""allow unverified service identity links - -Revision ID: 0024_service_link_verification -Revises: 0023_service_actor_identity -Create Date: 2026-07-17 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0024_service_link_verification" -down_revision = "0023_service_actor_identity" -branch_labels = depends_on = None - - -def upgrade() -> None: - """Make service verification explicit while preserving human invariants.""" - op.alter_column( - "actor_identity_links", - "last_verified_at", - existing_type=sa.DateTime(timezone=True), - server_default=None, - nullable=True, - ) - op.create_check_constraint( - op.f("ck_actor_identity_links_human_verified"), - "actor_identity_links", - "subject_kind = 'service' or last_verified_at is not null", - ) - - -def downgrade() -> None: - """Restore the historical implicit timestamp only when no proof is lost.""" - bind = op.get_bind() - bind.execute(sa.text("lock table actor_identity_links in access exclusive mode")) - has_unverified_service = bind.execute( - sa.text( - "select exists(select 1 from actor_identity_links " - "where subject_kind='service' and last_verified_at is null)" - ) - ).scalar_one() - if has_unverified_service: - raise RuntimeError("cannot downgrade with unverified service identity links") - op.drop_constraint( - op.f("ck_actor_identity_links_human_verified"), - "actor_identity_links", - type_="check", - ) - op.alter_column( - "actor_identity_links", - "last_verified_at", - existing_type=sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ) diff --git a/backend/alembic/versions/0025_artifact_store_v2_clean_cut.py b/backend/alembic/versions/0025_artifact_store_v2_clean_cut.py deleted file mode 100644 index 77946c69f..000000000 --- a/backend/alembic/versions/0025_artifact_store_v2_clean_cut.py +++ /dev/null @@ -1,422 +0,0 @@ -"""replace artifact provider v1 with byte-only v2 - -Revision ID: 0025_artifact_store_v2 -Revises: 0024_service_link_verification -Create Date: 2026-07-16 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0025_artifact_store_v2" -down_revision = "0024_service_link_verification" -branch_labels = depends_on = None - -_ARTIFACT_TABLES = ( - "artifact_operation_receipts", - "artifact_replicas", - "artifact_bindings", - "artifact_upload_items", - "artifact_contents", - "artifact_upload_sessions", -) - - -def _refuse_populated_artifact_rows(*, include_namespace: bool) -> None: - """Refuse to invent v2 provenance or downgrade durable v2 facts.""" - connection = op.get_bind() - tables = _ARTIFACT_TABLES + (("artifact_storage_namespaces",) if include_namespace else ()) - connection.execute( - sa.text(f"lock table {', '.join(tables)} in access exclusive mode") - ) - populated = [ - table_name - for table_name in tables - if connection.execute( - sa.text(f"select exists(select 1 from {table_name})") - ).scalar() - ] - if populated: - raise RuntimeError("artifact storage clean cut requires empty pre-production tables") - - -def upgrade() -> None: - """Install v2 only when no v1 artifact fact requires fabrication.""" - _refuse_populated_artifact_rows(include_namespace=False) - - op.create_table( - "artifact_storage_namespaces", - sa.Column("id", sa.String(20), primary_key=True), - sa.Column("backend", sa.String(50), nullable=False), - sa.Column("adapter", sa.String(50), nullable=False), - sa.Column("provider_profile", sa.String(100), nullable=False), - sa.Column("namespace_descriptor", sa.JSON(), nullable=False), - sa.Column("namespace_fingerprint", sa.String(71), nullable=False), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.CheckConstraint("id = 'primary'", name="singleton_id"), - sa.CheckConstraint( - "namespace_fingerprint ~ '^sha256:[0-9a-f]{64}$'", name="fingerprint_shape" - ), - sa.UniqueConstraint( - "namespace_fingerprint", name="uq_artifact_storage_namespace_fingerprint" - ), - ) - op.execute( - """ - create trigger trg_artifact_storage_namespaces_immutable - before update or delete on artifact_storage_namespaces - for each row execute function reject_artifact_fact_mutation() - """ - ) - - op.drop_constraint( - op.f("ck_artifact_upload_items_ready_result_required"), - "artifact_upload_items", - type_="check", - ) - op.drop_constraint( - op.f("ck_artifact_upload_items_state"), "artifact_upload_items", type_="check" - ) - op.alter_column( - "artifact_upload_items", - "provider_operation_reference", - new_column_name="provider_object_ref", - type_=sa.String(1024), - existing_type=sa.String(200), - ) - op.create_check_constraint( - "state", - "artifact_upload_items", - "state in ('reserved', 'uploading', 'replay_required', " - "'stored_pending_verification', 'ready', 'failed', 'cancelled')", - ) - op.create_check_constraint( - "stored_result_required", - "artifact_upload_items", - "((state in ('stored_pending_verification', 'ready')) and " - "content_id is not null and provider_object_ref is not null) or " - "((state not in ('stored_pending_verification', 'ready')) and " - "content_id is null and provider_object_ref is null)", - ) - - op.drop_constraint( - op.f("uq_artifact_replica_provider"), "artifact_replicas", type_="unique" - ) - for constraint in ( - "ck_artifact_replicas_verification_state", - "ck_artifact_replicas_retention_state", - "ck_artifact_replicas_availability_state", - "ck_artifact_replicas_integrity_state", - ): - op.drop_constraint(op.f(constraint), "artifact_replicas", type_="check") - op.drop_column("artifact_replicas", "retention_state") - op.drop_column("artifact_replicas", "provider_manifest_id") - op.alter_column( - "artifact_replicas", - "provider_artifact_id", - new_column_name="provider_object_ref", - type_=sa.String(1024), - existing_type=sa.String(200), - ) - op.add_column( - "artifact_replicas", sa.Column("storage_namespace_id", sa.String(20), nullable=False) - ) - op.add_column( - "artifact_replicas", sa.Column("namespace_fingerprint", sa.String(71), nullable=False) - ) - op.add_column( - "artifact_replicas", sa.Column("provider_profile", sa.String(100), nullable=False) - ) - op.create_foreign_key( - op.f("fk_artifact_replicas_storage_namespace_id_artifact_storage_namespaces"), - "artifact_replicas", - "artifact_storage_namespaces", - ["storage_namespace_id"], - ["id"], - ondelete="RESTRICT", - ) - op.create_index( - op.f("ix_artifact_replicas_storage_namespace_id"), - "artifact_replicas", - ["storage_namespace_id"], - ) - op.create_unique_constraint( - op.f("uq_artifact_replica_provider_object"), - "artifact_replicas", - ["storage_namespace_id", "provider_object_ref"], - ) - op.create_check_constraint( - "verification_state", - "artifact_replicas", - "verification_state in ('pending', 'verified', 'missing', 'integrity_mismatch')", - ) - op.create_check_constraint( - "availability_state", - "artifact_replicas", - "availability_state in ('unknown', 'available', 'unavailable')", - ) - op.create_check_constraint( - "integrity_state", - "artifact_replicas", - "integrity_state in ('unknown', 'valid', 'invalid')", - ) - op.create_check_constraint( - "fingerprint_shape", - "artifact_replicas", - "namespace_fingerprint ~ '^sha256:[0-9a-f]{64}$'", - ) - - op.execute("drop trigger trg_artifact_operation_receipts_immutable on artifact_operation_receipts") - op.drop_table("artifact_operation_receipts") - _create_v2_receipts() - - -def _create_v2_receipts() -> None: - op.create_table( - "artifact_operation_receipts", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("upload_item_id", sa.String(36), nullable=False), - sa.Column("replica_id", sa.String(36), nullable=False), - sa.Column("operation", sa.String(30), nullable=False), - sa.Column("idempotency_key", sa.String(200), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("provider_object_ref", sa.String(1024), nullable=False), - sa.Column("replayed", sa.Boolean(), nullable=False), - sa.Column("outcome", sa.String(30), nullable=False), - sa.Column("attempt_number", sa.Integer(), nullable=False), - sa.Column("correlation_id", sa.String(100), nullable=False), - sa.Column("details", sa.JSON(), nullable=False), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.ForeignKeyConstraint( - ["upload_item_id"], ["artifact_upload_items.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint(["replica_id"], ["artifact_replicas.id"], ondelete="RESTRICT"), - sa.UniqueConstraint("upload_item_id", name="uq_artifact_receipt_upload_item"), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", name="request_digest_shape" - ), - sa.CheckConstraint("operation = 'put'", name="operation"), - sa.CheckConstraint("outcome = 'stored_pending_verification'", name="outcome"), - sa.CheckConstraint("attempt_number > 0", name="attempt_positive"), - ) - op.create_index( - "ix_artifact_operation_receipts_upload_item_id", - "artifact_operation_receipts", - ["upload_item_id"], - ) - op.create_index( - "ix_artifact_operation_receipts_replica_id", - "artifact_operation_receipts", - ["replica_id"], - ) - op.execute( - """ - create trigger trg_artifact_operation_receipts_immutable - before update or delete on artifact_operation_receipts - for each row execute function reject_artifact_fact_mutation() - """ - ) - - -def downgrade() -> None: - """Restore the empty v1 shape without converting any v2 fact.""" - _refuse_populated_artifact_rows(include_namespace=True) - - op.execute("drop trigger trg_artifact_operation_receipts_immutable on artifact_operation_receipts") - op.drop_table("artifact_operation_receipts") - - for constraint in ( - "ck_artifact_replicas_verification_state", - "ck_artifact_replicas_availability_state", - "ck_artifact_replicas_integrity_state", - "ck_artifact_replicas_fingerprint_shape", - ): - op.drop_constraint(op.f(constraint), "artifact_replicas", type_="check") - op.drop_constraint( - op.f("uq_artifact_replica_provider_object"), "artifact_replicas", type_="unique" - ) - op.drop_index( - op.f("ix_artifact_replicas_storage_namespace_id"), table_name="artifact_replicas" - ) - op.drop_constraint( - op.f("fk_artifact_replicas_storage_namespace_id_artifact_storage_namespaces"), - "artifact_replicas", - type_="foreignkey", - ) - op.drop_column("artifact_replicas", "provider_profile") - op.drop_column("artifact_replicas", "namespace_fingerprint") - op.drop_column("artifact_replicas", "storage_namespace_id") - op.alter_column( - "artifact_replicas", - "provider_object_ref", - new_column_name="provider_artifact_id", - type_=sa.String(200), - existing_type=sa.String(1024), - ) - op.add_column( - "artifact_replicas", sa.Column("provider_manifest_id", sa.String(200), nullable=True) - ) - op.add_column( - "artifact_replicas", sa.Column("retention_state", sa.String(30), nullable=False) - ) - op.create_unique_constraint( - "uq_artifact_replica_provider", - "artifact_replicas", - ["adapter", "provider_artifact_id"], - ) - op.create_check_constraint( - "verification_state", - "artifact_replicas", - "verification_state in ('pending', 'verified', 'failed')", - ) - op.create_check_constraint( - "retention_state", - "artifact_replicas", - "retention_state in ('unretained', 'retained', 'released')", - ) - op.create_check_constraint( - "availability_state", - "artifact_replicas", - "availability_state in ('available', 'unavailable', 'missing')", - ) - op.create_check_constraint( - "integrity_state", - "artifact_replicas", - "integrity_state in ('unknown', 'valid', 'quarantined')", - ) - - op.drop_constraint( - op.f("ck_artifact_upload_items_stored_result_required"), - "artifact_upload_items", - type_="check", - ) - op.drop_constraint( - op.f("ck_artifact_upload_items_state"), - "artifact_upload_items", - type_="check", - ) - op.alter_column( - "artifact_upload_items", - "provider_object_ref", - new_column_name="provider_operation_reference", - type_=sa.String(200), - existing_type=sa.String(1024), - ) - op.create_check_constraint( - "state", - "artifact_upload_items", - "state in ('reserved', 'uploading', 'provider_committed', " - "'replay_required', 'ready', 'failed', 'cancelled')", - ) - op.create_check_constraint( - "ready_result_required", - "artifact_upload_items", - "(state = 'ready') = " - "(content_id is not null and provider_operation_reference is not null)", - ) - - op.execute("drop trigger trg_artifact_storage_namespaces_immutable on artifact_storage_namespaces") - op.drop_table("artifact_storage_namespaces") - _create_v1_receipts() - - -def _create_v1_receipts() -> None: - """Restore the exact empty receipt shape expected by migration 0016.""" - op.create_table( - "artifact_operation_receipts", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("upload_item_id", sa.String(36), nullable=True), - sa.Column("replica_id", sa.String(36), nullable=True), - sa.Column("adapter", sa.String(50), nullable=False), - sa.Column("service_principal", sa.String(200), nullable=False), - sa.Column("operation", sa.String(30), nullable=False), - sa.Column("idempotency_key", sa.String(200), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("response_digest", sa.String(71), nullable=False), - sa.Column("provider_receipt_id", sa.String(200), nullable=False), - sa.Column("provider_operation_reference", sa.String(200), nullable=False), - sa.Column("outcome", sa.String(30), nullable=False), - sa.Column("attempt_number", sa.Integer(), nullable=False), - sa.Column("correlation_id", sa.String(100), nullable=False), - sa.Column("retention_reference", sa.String(200), nullable=True), - sa.Column("retention_class", sa.String(100), nullable=True), - sa.Column("retention_owner", sa.String(200), nullable=True), - sa.Column("provider_recorded_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("details", sa.JSON(), nullable=False), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.ForeignKeyConstraint( - ["upload_item_id"], ["artifact_upload_items.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint(["replica_id"], ["artifact_replicas.id"], ondelete="RESTRICT"), - sa.UniqueConstraint( - "adapter", - "service_principal", - "operation", - "idempotency_key", - name="uq_artifact_receipt_operation", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", name="request_digest_shape" - ), - sa.CheckConstraint( - "response_digest ~ '^sha256:[0-9a-f]{64}$'", name="response_digest_shape" - ), - sa.CheckConstraint( - "operation in ('store', 'verify', 'retain', 'release')", name="operation" - ), - sa.CheckConstraint( - "outcome in ('stored', 'verified', 'retained', 'released')", name="outcome" - ), - sa.CheckConstraint( - "(operation = 'store' and outcome = 'stored') or " - "(operation = 'verify' and outcome = 'verified') or " - "(operation = 'retain' and outcome = 'retained') or " - "(operation = 'release' and outcome = 'released')", - name="operation_outcome", - ), - sa.CheckConstraint("attempt_number > 0", name="attempt_positive"), - sa.CheckConstraint( - "operation != 'retain' or " - "(retention_reference is not null and retention_class is not null " - "and retention_owner is not null)", - name="retain_fields", - ), - sa.CheckConstraint( - "operation != 'release' or " - "(retention_reference is not null and retention_class is not null " - "and retention_owner is not null)", - name="release_reference", - ), - sa.CheckConstraint( - "operation in ('retain', 'release') or " - "(retention_reference is null and retention_class is null " - "and retention_owner is null)", - name="non_retention_fields_empty", - ), - ) - op.create_index( - "ix_artifact_operation_receipts_upload_item_id", - "artifact_operation_receipts", - ["upload_item_id"], - ) - op.create_index( - "ix_artifact_operation_receipts_replica_id", - "artifact_operation_receipts", - ["replica_id"], - ) - op.execute( - """ - create trigger trg_artifact_operation_receipts_immutable - before update or delete on artifact_operation_receipts - for each row execute function reject_artifact_fact_mutation() - """ - ) diff --git a/backend/alembic/versions/0026_actor_profile_lifecycle.py b/backend/alembic/versions/0026_actor_profile_lifecycle.py deleted file mode 100644 index 292dbea37..000000000 --- a/backend/alembic/versions/0026_actor_profile_lifecycle.py +++ /dev/null @@ -1,394 +0,0 @@ -"""repair actor lifecycle provenance and authority evidence - -Revision ID: 0026_actor_profile_lifecycle -Revises: 0025_artifact_store_v2 -Create Date: 2026-07-18 -""" - -from __future__ import annotations - -from alembic import op -import re -import sqlalchemy as sa - -revision = "0026_actor_profile_lifecycle" -down_revision = "0025_artifact_store_v2" -branch_labels = depends_on = None - -_NEW_DENIAL_CODES = ( - "identity_link_already_revoked", - "identity_link_not_revoked", -) -# Historical capture of str.strip() across the supported Python runtimes. -_PYTHON_STRIP_CHARACTERS_SQL = ( - "(E' \\t\\n\\r\\f\\013'" - "||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)" - "||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)" - "||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)" - "||chr(8233)||chr(8239)||chr(8287)||chr(12288))" -) - - -def _replace_denial_registry(*, add: bool) -> None: - """Extend the exact prior registry without coupling history to live constants.""" - bind = op.get_bind() - name = "ck_audit_events_authority_registries" - definition = bind.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass and conname=:name" - ), - {"name": name}, - ).scalar_one() - cast = r"(?P::(?:character varying|text))?" - marker = re.compile(rf"'identity_link_conflict'{cast}") - if add: - matches = tuple(marker.finditer(definition)) - if len(matches) != 1 or any(value in definition for value in _NEW_DENIAL_CODES): - raise RuntimeError("unexpected authority denial registry definition") - match = matches[0] - suffix = match.group("cast") or "" - inserted = ", ".join(f"'{value}'{suffix}" for value in _NEW_DENIAL_CODES) - replacement = definition[: match.end()] + ", " + inserted + definition[match.end() :] - else: - first = ( - r"(?:\('identity_link_already_revoked'::character varying\)::text|" - r"'identity_link_already_revoked'(?:::(?:character varying|text))?)" - ) - second = ( - r"(?:\('identity_link_not_revoked'::character varying\)::text|" - r"'identity_link_not_revoked'(?:::(?:character varying|text))?)" - ) - removal = re.compile( - rf",\s*{first}\s*,\s*{second}" - ) - if len(tuple(removal.finditer(definition))) != 1: - raise RuntimeError("unexpected authority denial registry definition") - replacement = removal.sub("", definition, count=1) - op.drop_constraint("authority_registries", "audit_events", type_="check") - op.execute(f"alter table audit_events add constraint {name} {replacement}") - - -def _replace_linked_authority_guard(*, lifecycle_reactivation: bool) -> None: - projection_branch = ( - "record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke'," - "'actor_identity_link.revoke','actor_identity_link.reactivate')" - if lifecycle_reactivation - else "record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke')" - ) - if lifecycle_reactivation: - direction_checks = """ - or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and - (new.before_facts::jsonb <> '{"effective": false}'::jsonb or new.after_facts::jsonb <> '{"effective": true}'::jsonb)) - or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and - (new.before_facts::jsonb <> '{"effective": true}'::jsonb or new.after_facts::jsonb <> '{"effective": false}'::jsonb)) - """ - else: - direction_checks = """ - or (record_row.operation='admin_role_grant.issue' and - (new.before_facts::jsonb <> '{"effective": false}'::jsonb or new.after_facts::jsonb <> '{"effective": true}'::jsonb)) - or (record_row.operation='admin_role_grant.revoke' and - (new.before_facts::jsonb <> '{"effective": true}'::jsonb or new.after_facts::jsonb <> '{"effective": false}'::jsonb)) - or (not (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke')) and - (new.before_facts::jsonb <> '{"effective": true}'::jsonb or new.after_facts::jsonb <> '{"effective": false}'::jsonb)) - """ - op.execute( - f""" - create or replace function validate_linked_authority_event() returns trigger - language plpgsql as $$ - declare record_row authority_idempotency_records%rowtype; - cause_row audit_events%rowtype; expected_permission text; - expected_resource text; expected_invalidation_resource text; - expected_invalidation_id text; valid_success boolean; - begin - if new.event_domain <> 'authority' then return new; end if; - valid_success := new.event_type in ( - 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', - 'ProjectRoleGrantIssued','ProjectRoleGrantReplaced','ProjectRoleGrantRevoked', - 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', - 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); - if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then - if new.idempotency_reference is not null then - raise exception 'invalid authority idempotency event' using errcode='23514'; - end if; return new; - end if; - if new.idempotency_reference is null then - raise exception 'authority event requires idempotency reference' using errcode='23514'; - end if; - select * into record_row from authority_idempotency_records - where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; - if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; - if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; - expected_permission := case record_row.operation - when 'service_actor.create' then 'actor.service.provision' - when 'admin_role_grant.issue' then 'admin_role.grant' - when 'admin_role_grant.revoke' then 'admin_role.revoke' - when 'project_role_grant.issue' then 'project.role_grant.manage' - when 'project_role_grant.revoke' then 'project.role_grant.manage' - when 'actor_profile.suspend' then 'actor.profile.suspend' - when 'actor_profile.reactivate' then 'actor.profile.reactivate' - when 'actor_profile.deactivate' then 'actor.profile.deactivate' - when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' - when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; - expected_resource := case - when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' - when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' - when record_row.operation like 'project_role_grant.%' then 'project_role_grant' - else 'actor_identity_link' end; - if new.permission_id <> expected_permission or new.resource_id is null then - raise exception 'authority event does not match operation' using errcode='23514'; - end if; - if new.event_type='AuthorityInvalidationRequested' then - select * into cause_row from audit_events where id=new.invalidation_cause_event_id; - expected_invalidation_resource := case when {projection_branch} then 'actor_profile' else expected_resource end; - expected_invalidation_id := case when {projection_branch} then cause_row.target_actor_ref else cause_row.resource_id end; - if not found or cause_row.idempotency_reference is distinct from record_row.id - or cause_row.actor_ref_kind is distinct from new.actor_ref_kind - or cause_row.actor_id is distinct from new.actor_id - or cause_row.permission_id is distinct from new.permission_id - or cause_row.resource_type is distinct from expected_resource - or new.resource_type is distinct from expected_invalidation_resource - or new.resource_id is distinct from expected_invalidation_id - or new.invalidation_target_kind is distinct from expected_invalidation_resource - or new.invalidation_target_ref is distinct from expected_invalidation_id - or cause_row.target_ref_kind is distinct from cause_row.resource_type - or cause_row.target_ref_id is distinct from cause_row.resource_id - or cause_row.request_id is distinct from new.request_id - or cause_row.correlation_id is distinct from new.correlation_id - or cause_row.project_id is distinct from new.project_id - or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id - or ({projection_branch} and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) - {direction_checks} - or not ( - (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or - (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or - (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or - (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued','ProjectRoleGrantReplaced')) or - (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or - (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or - (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or - (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or - (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or - (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then - raise exception 'invalid linked authority cause' using errcode='23514'; - end if; - else - if new.resource_type <> expected_resource or new.entity_type <> expected_resource - or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource - or new.target_ref_id is distinct from new.resource_id - or new.invalidation_cause_event_id is not null - or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null - or not ( - (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or - (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or - (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or - (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued','ProjectRoleGrantReplaced')) or - (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or - (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or - (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or - (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or - (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or - (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then - raise exception 'authority success event does not match operation' using errcode='23514'; - end if; - end if; return new; - end $$ - """ - ) - - -def _replace_lifecycle_guards(*, upgraded: bool) -> None: - if upgraded: - profile_function = """ - create or replace function guard_actor_profile_history() returns trigger language plpgsql as $$ - begin - if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; - if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) - is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then - raise exception 'actor profile identity is immutable' using errcode='55000'; - end if; - if old.status='deactivated' and new.status <> 'deactivated' then - raise exception 'deactivated actor is terminal' using errcode='23514'; - end if; - if new.status = old.status and - (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, - new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from - (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, - old.deactivated_by,old.deactivated_at,old.deactivation_reason) then - raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; - end if; - if old.status='active' and new.status='suspended' and - (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) - is distinct from - (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then - raise exception 'invalid actor suspension attribution' using errcode='23514'; - end if; - if old.status='suspended' and new.status='active' and - ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) - or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) - or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from - (old.reactivated_by,old.reactivated_at,old.reactivation_reason) - or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from - (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then - raise exception 'invalid actor reactivation attribution' using errcode='23514'; - end if; - if new.status='deactivated' and old.status in ('active','suspended') and - (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) - is distinct from - (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then - raise exception 'invalid actor deactivation attribution' using errcode='23514'; - end if; - if new.status <> old.status and not ( - (old.status='active' and new.status in ('suspended','deactivated')) or - (old.status='suspended' and new.status in ('active','deactivated'))) then - raise exception 'invalid actor lifecycle transition' using errcode='23514'; - end if; - new.updated_at = statement_timestamp(); return new; - end $$ - """ - link_function = """ - create or replace function guard_actor_identity_link_history() returns trigger language plpgsql as $$ - begin - if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; - if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) - is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then - raise exception 'actor identity link anchor is immutable' using errcode='55000'; - end if; - if new.status=old.status and - (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) - is distinct from - (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then - raise exception 'identity link attribution requires a transition' using errcode='23514'; - end if; - if old.status='active' and new.status='revoked' and - (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from - (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then - raise exception 'invalid identity link revocation attribution' using errcode='23514'; - end if; - if old.status='revoked' and new.status='active' and - ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) - or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) - or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from - (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then - raise exception 'invalid identity link reactivation attribution' using errcode='23514'; - end if; - if new.status <> old.status and not ( - (old.status='active' and new.status='revoked') or - (old.status='revoked' and new.status='active')) then - raise exception 'invalid identity link lifecycle transition' using errcode='23514'; - end if; - return new; - end $$ - """ - else: - profile_function = """ - create or replace function guard_actor_profile_history() returns trigger language plpgsql as $$ - begin - if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; - if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) - is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then - raise exception 'actor profile identity is immutable' using errcode='55000'; - end if; - if old.status='deactivated' and new.status <> 'deactivated' then - raise exception 'deactivated actor is terminal' using errcode='23514'; - end if; - new.updated_at = statement_timestamp(); return new; - end $$ - """ - link_function = """ - create or replace function guard_actor_identity_link_history() returns trigger language plpgsql as $$ - begin - if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; - if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) - is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then - raise exception 'actor identity link anchor is immutable' using errcode='55000'; - end if; - return new; - end $$ - """ - op.execute(profile_function) - op.execute(link_function) - - -def _dirty_lifecycle_rows(bind) -> bool: - return bool( - bind.execute( - sa.text( - "select exists(select 1 from actor_identity_links where " - "(reactivated_by is null)::int + (reactivated_at is null)::int + " - "(reactivation_reason is null)::int not in (0,3)) or exists(" - "select 1 from actor_profiles where " - f"(suspension_reason is not null and (suspension_reason<>btrim(suspension_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) or octet_length(suspension_reason) not between 1 and 500)) or " - f"(deactivation_reason is not null and (deactivation_reason<>btrim(deactivation_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) or octet_length(deactivation_reason) not between 1 and 500))) or exists(" - "select 1 from actor_identity_links where " - f"(revoked_reason is not null and (revoked_reason<>btrim(revoked_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) or octet_length(revoked_reason) not between 1 and 500)) or " - f"(reactivation_reason is not null and (reactivation_reason<>btrim(reactivation_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) or octet_length(reactivation_reason) not between 1 and 500)))" - ) - ).scalar_one() - ) - - -def upgrade() -> None: - """Install truthful profile lifecycle provenance and evidence guards.""" - bind = op.get_bind() - bind.execute(sa.text("lock table actor_profiles, actor_identity_links, audit_events in access exclusive mode")) - if _dirty_lifecycle_rows(bind): - raise RuntimeError("cannot adopt dirty actor lifecycle rows") - - op.add_column("actor_profiles", sa.Column("reactivated_by", sa.String(120))) - op.add_column("actor_profiles", sa.Column("reactivated_at", sa.DateTime(timezone=True))) - op.add_column("actor_profiles", sa.Column("reactivation_reason", sa.String(500))) - op.create_check_constraint( - op.f("ck_actor_profiles_reactivation_fields"), - "actor_profiles", - "(reactivated_by is null and reactivated_at is null and reactivation_reason is null) or " - "(reactivated_by is not null and reactivated_at is not null and reactivation_reason is not null)", - ) - op.create_check_constraint( - op.f("ck_actor_profiles_lifecycle_reason_bounds"), - "actor_profiles", - f"(suspension_reason is null or (suspension_reason=btrim(suspension_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) and octet_length(suspension_reason) between 1 and 500)) and " - f"(reactivation_reason is null or (reactivation_reason=btrim(reactivation_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) and octet_length(reactivation_reason) between 1 and 500)) and " - f"(deactivation_reason is null or (deactivation_reason=btrim(deactivation_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) and octet_length(deactivation_reason) between 1 and 500))", - ) - op.create_check_constraint( - op.f("ck_actor_identity_links_reactivation_fields"), - "actor_identity_links", - "(reactivated_by is null and reactivated_at is null and reactivation_reason is null) or " - "(reactivated_by is not null and reactivated_at is not null and reactivation_reason is not null)", - ) - op.create_check_constraint( - op.f("ck_actor_identity_links_lifecycle_reason_bounds"), - "actor_identity_links", - f"(revoked_reason is null or (revoked_reason=btrim(revoked_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) and octet_length(revoked_reason) between 1 and 500)) and " - f"(reactivation_reason is null or (reactivation_reason=btrim(reactivation_reason, {_PYTHON_STRIP_CHARACTERS_SQL}) and octet_length(reactivation_reason) between 1 and 500))", - ) - _replace_denial_registry(add=True) - _replace_linked_authority_guard(lifecycle_reactivation=True) - _replace_lifecycle_guards(upgraded=True) - - -def downgrade() -> None: - """Restore 0025 only before any forward lifecycle evidence exists.""" - bind = op.get_bind() - bind.execute(sa.text("lock table actor_profiles, actor_identity_links, audit_events in access exclusive mode")) - blocked = bind.execute( - sa.text( - "select exists(select 1 from actor_profiles where reactivated_by is not null or reactivated_at is not null or reactivation_reason is not null) " - "or exists(select 1 from audit_events where event_domain='authority' and (" - "event_type in ('ActorProfileReactivated','ActorIdentityLinkReactivated') or " - "denial_code in ('identity_link_already_revoked','identity_link_not_revoked')))" - ) - ).scalar_one() - if blocked: - raise RuntimeError("cannot downgrade actor lifecycle evidence") - _replace_lifecycle_guards(upgraded=False) - _replace_linked_authority_guard(lifecycle_reactivation=False) - _replace_denial_registry(add=False) - op.drop_constraint(op.f("ck_actor_identity_links_lifecycle_reason_bounds"), "actor_identity_links", type_="check") - op.drop_constraint(op.f("ck_actor_identity_links_reactivation_fields"), "actor_identity_links", type_="check") - op.drop_constraint(op.f("ck_actor_profiles_lifecycle_reason_bounds"), "actor_profiles", type_="check") - op.drop_constraint(op.f("ck_actor_profiles_reactivation_fields"), "actor_profiles", type_="check") - op.drop_column("actor_profiles", "reactivation_reason") - op.drop_column("actor_profiles", "reactivated_at") - op.drop_column("actor_profiles", "reactivated_by") diff --git a/backend/alembic/versions/0027_contributor_foundation.py b/backend/alembic/versions/0027_contributor_foundation.py deleted file mode 100644 index 6db1516f4..000000000 --- a/backend/alembic/versions/0027_contributor_foundation.py +++ /dev/null @@ -1,281 +0,0 @@ -"""clean-cut contributor attribution to canonical human actors - -Revision ID: 0027_contributor_foundation -Revises: 0026_actor_profile_lifecycle -Create Date: 2026-07-19 -""" - -from __future__ import annotations - -import json - -from alembic import op -import sqlalchemy as sa - -revision = "0027_contributor_foundation" -down_revision = "0026_actor_profile_lifecycle" -branch_labels = depends_on = None - -UUID_PATTERN = r"^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$" -FUNCTION_NAME = "require_human_actor_profile_reference" -LINEAGE_OBJECTS = ( - ( - "task_assignments", - "task_assignments_contributor_human", - "fk_task_assignments_contributor_id_actor_profiles", - ), - ( - "submissions", - "submissions_contributor_human", - "fk_submissions_contributor_id_actor_profiles", - ), -) - - -def _preflight() -> None: - """Reject source rows that cannot become canonical human references.""" - bind = op.get_bind() - failures: dict[str, dict[str, dict[str, object]]] = {} - for table in ("task_assignments", "submissions"): - rows = bind.execute( - sa.text( - f""" - select source.id as row_id, source.worker_id as actor_profile_id, - case - when source.worker_id !~ :uuid_pattern then 'malformed' - when profile.id is null then 'missing' - when profile.actor_kind <> 'human' then 'service' - end as failure_class - from {table} source - left join actor_profiles profile on profile.id = source.worker_id - where source.worker_id !~ :uuid_pattern - or profile.id is null - or profile.actor_kind <> 'human' - order by failure_class, source.id, source.worker_id - """ - ), - {"uuid_pattern": UUID_PATTERN}, - ).mappings() - table_failures: dict[str, dict[str, object]] = {} - for row in rows: - failure_class = str(row["failure_class"]) - bucket = table_failures.setdefault( - failure_class, - {"total": 0, "rows": []}, - ) - bucket["total"] = int(bucket["total"]) + 1 - bounded_rows = bucket["rows"] - if isinstance(bounded_rows, list) and len(bounded_rows) < 20: - actor_profile_id = ( - "" - if failure_class == "malformed" - else str(row["actor_profile_id"]) - ) - bounded_rows.append( - [str(row["row_id"]), actor_profile_id] - ) - if table_failures: - failures[table] = table_failures - if failures: - raise RuntimeError( - "contributor foundation preflight failed: " - + json.dumps(failures, sort_keys=True, separators=(",", ":")) - ) - - -def _create_lineage_function() -> None: - op.execute( - f""" - create function public.{FUNCTION_NAME}() returns trigger - language plpgsql security invoker as $$ - declare referenced_id text; referenced_kind text; - begin - if tg_nargs <> 1 or tg_argv[0] is null - or not (to_jsonb(new) ? tg_argv[0]) then - raise exception 'human actor reference trigger is misconfigured' - using errcode='55000'; - end if; - referenced_id := to_jsonb(new) ->> tg_argv[0]; - if referenced_id is null then return new; end if; - select profile.actor_kind into referenced_kind - from public.actor_profiles profile where profile.id=referenced_id; - if not found then return new; end if; - if referenced_kind <> 'human' then - raise exception 'actor reference must identify a human profile' - using errcode='23514', constraint='{FUNCTION_NAME}'; - end if; - return new; - end $$ - """ - ) - - -def _downstream_dependencies() -> tuple[int, tuple[str, ...]]: - """Return bounded descriptions of dependencies beyond this migration's triggers.""" - bind = op.get_bind() - rows = bind.execute( - sa.text( - f""" - with owned_triggers as ( - select trigger_row.oid - from pg_trigger trigger_row - join pg_class table_row on table_row.oid=trigger_row.tgrelid - join pg_namespace namespace_row on namespace_row.oid=table_row.relnamespace - where namespace_row.nspname='public' - and (table_row.relname,trigger_row.tgname) in ( - ('task_assignments','task_assignments_contributor_human'), - ('submissions','submissions_contributor_human') - ) - ) - select description, total - from ( - select - pg_describe_object( - dependency.classid, - dependency.objid, - dependency.objsubid - ) as description, - count(*) over () as total - from pg_depend dependency - where dependency.refclassid='pg_proc'::regclass - and dependency.refobjid='public.{FUNCTION_NAME}()'::regprocedure - and not ( - dependency.classid='pg_trigger'::regclass - and dependency.objid in (select oid from owned_triggers) - ) - ) dependencies - order by description - limit 20 - """ - ) - ).all() - if not rows: - return 0, () - return int(rows[0].total), tuple(str(row.description) for row in rows) - - -def upgrade() -> None: - """Install canonical-human contributor attribution without guessing data.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table actor_profiles, task_assignments, submissions " - "in access exclusive mode" - ) - ) - _preflight() - - op.alter_column( - "task_assignments", - "worker_id", - new_column_name="contributor_id", - existing_type=sa.String(100), - existing_nullable=False, - ) - op.alter_column( - "task_assignments", - "contributor_id", - type_=sa.String(36), - existing_type=sa.String(100), - existing_nullable=False, - ) - op.execute( - "alter index ix_task_assignments_worker_id " - "rename to ix_task_assignments_contributor_id" - ) - op.alter_column( - "submissions", - "worker_id", - new_column_name="contributor_id", - existing_type=sa.String(100), - existing_nullable=False, - ) - op.alter_column( - "submissions", - "contributor_id", - type_=sa.String(36), - existing_type=sa.String(100), - existing_nullable=False, - ) - op.execute( - "alter index ix_submissions_worker_id rename to ix_submissions_contributor_id" - ) - - for table, _, foreign_key in LINEAGE_OBJECTS: - op.create_foreign_key( - foreign_key, - table, - "actor_profiles", - ["contributor_id"], - ["id"], - ) - _create_lineage_function() - for table, trigger, _ in LINEAGE_OBJECTS: - op.execute( - f"create trigger {trigger} before insert or update of contributor_id " - f"on {table} for each row execute function " - f"public.{FUNCTION_NAME}('contributor_id')" - ) - - -def downgrade() -> None: - """Restore prior names only while no later lineage consumer depends on them.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table actor_profiles, task_assignments, submissions " - "in access exclusive mode" - ) - ) - dependency_total, dependencies = _downstream_dependencies() - if dependency_total: - raise RuntimeError( - "cannot downgrade contributor lineage dependencies: " - + json.dumps( - {"total": dependency_total, "objects": dependencies}, - sort_keys=True, - separators=(",", ":"), - ) - ) - - for table, trigger, _ in LINEAGE_OBJECTS: - op.execute(f"drop trigger {trigger} on {table}") - for table, _, foreign_key in LINEAGE_OBJECTS: - op.drop_constraint(foreign_key, table, type_="foreignkey") - op.execute(f"drop function public.{FUNCTION_NAME}() restrict") - - op.execute( - "alter index ix_task_assignments_contributor_id " - "rename to ix_task_assignments_worker_id" - ) - op.alter_column( - "task_assignments", - "contributor_id", - type_=sa.String(100), - existing_type=sa.String(36), - existing_nullable=False, - ) - op.alter_column( - "task_assignments", - "contributor_id", - new_column_name="worker_id", - existing_type=sa.String(100), - existing_nullable=False, - ) - op.execute( - "alter index ix_submissions_contributor_id rename to ix_submissions_worker_id" - ) - op.alter_column( - "submissions", - "contributor_id", - type_=sa.String(100), - existing_type=sa.String(36), - existing_nullable=False, - ) - op.alter_column( - "submissions", - "contributor_id", - new_column_name="worker_id", - existing_type=sa.String(100), - existing_nullable=False, - ) diff --git a/backend/alembic/versions/0028_artifact_admission.py b/backend/alembic/versions/0028_artifact_admission.py deleted file mode 100644 index c51a49a0b..000000000 --- a/backend/alembic/versions/0028_artifact_admission.py +++ /dev/null @@ -1,384 +0,0 @@ -"""add durable-byte admission and prepared put attempts - -Revision ID: 0028_artifact_admission -Revises: 0027_contributor_foundation -Create Date: 2026-07-19 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0028_artifact_admission" -down_revision = "0027_contributor_foundation" -branch_labels = depends_on = None - -_ADMISSION_TABLES = ( - "artifact_put_attempt_charges", - "artifact_put_attempts", - "artifact_admission_charges", - "artifact_admission_scopes", -) - - -def _refuse_populated_admission_downgrade() -> None: - """Refuse to destroy durable admission, charge, or attempt evidence.""" - connection = op.get_bind() - connection.execute( - sa.text( - "lock table " - + ", ".join(_ADMISSION_TABLES) - + " in access exclusive mode" - ) - ) - if any( - connection.execute( - sa.text(f"select exists(select 1 from {table_name})") - ).scalar() - for table_name in _ADMISSION_TABLES - ): - raise RuntimeError("cannot downgrade populated artifact admission ledger") - - -def upgrade() -> None: - """Install generic admission and pre-I/O attempt state.""" - op.create_unique_constraint( - "uq_artifact_storage_namespace_id_fingerprint", - "artifact_storage_namespaces", - ["id", "namespace_fingerprint"], - ) - - op.create_table( - "artifact_admission_scopes", - sa.Column("scope_type", sa.String(20), nullable=False), - sa.Column("scope_id", sa.String(120), nullable=False), - sa.Column("limit_bytes", sa.BigInteger(), nullable=False), - sa.Column("counted_bytes", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column("cas_version", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.CheckConstraint( - "scope_type in ('deployment', 'project', 'producer', 'task')", - name="scope_type", - ), - sa.CheckConstraint( - "octet_length(scope_id) between 1 and 120", - name="scope_id_bounds", - ), - sa.CheckConstraint("limit_bytes > 0", name="limit_positive"), - sa.CheckConstraint( - "counted_bytes >= 0 and counted_bytes <= limit_bytes", - name="counted_bytes_within_limit", - ), - sa.CheckConstraint("cas_version >= 0", name="cas_nonnegative"), - sa.PrimaryKeyConstraint("scope_type", "scope_id"), - ) - - op.create_table( - "artifact_admission_charges", - sa.Column("id", sa.String(36), nullable=False), - sa.Column("scope_type", sa.String(20), nullable=False), - sa.Column("scope_id", sa.String(120), nullable=False), - sa.Column("sha256", sa.String(71), nullable=False), - sa.Column("byte_count", sa.BigInteger(), nullable=False), - sa.Column("producer_type", sa.String(30), nullable=False), - sa.Column("producer_ref", sa.String(120), nullable=False), - sa.Column("creating_operation_identity", sa.String(71), nullable=False), - sa.Column("state", sa.String(20), nullable=False, server_default="provisional"), - sa.Column("cas_version", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column( - "reserved_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.Column("completed_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("released_at", sa.DateTime(timezone=True), nullable=True), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.CheckConstraint( - "sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="sha256_shape", - ), - sa.CheckConstraint("byte_count >= 0", name="byte_count_nonnegative"), - sa.CheckConstraint( - "producer_type in ('actor_profile', 'service_identity')", - name="producer_type", - ), - sa.CheckConstraint( - "creating_operation_identity ~ '^sha256:[0-9a-f]{64}$'", - name="operation_identity_shape", - ), - sa.CheckConstraint( - "state in ('provisional', 'completed', 'released')", - name="state", - ), - sa.CheckConstraint("cas_version >= 0", name="cas_nonnegative"), - sa.CheckConstraint( - "(state = 'completed') = (completed_at is not null)", - name="completed_timestamp", - ), - sa.CheckConstraint( - "(state = 'released') = (released_at is not null)", - name="released_timestamp", - ), - sa.ForeignKeyConstraint( - ["scope_type", "scope_id"], - [ - "artifact_admission_scopes.scope_type", - "artifact_admission_scopes.scope_id", - ], - name="fk_artifact_admission_charges_scope", - ondelete="RESTRICT", - ), - sa.PrimaryKeyConstraint("id"), - sa.UniqueConstraint( - "scope_type", - "scope_id", - "sha256", - "byte_count", - name="uq_artifact_admission_charge_scope_content", - ), - ) - - op.create_table( - "artifact_put_attempts", - sa.Column("id", sa.String(36), nullable=False), - sa.Column("producer_request_type", sa.String(30), nullable=False), - sa.Column("producer_type", sa.String(30), nullable=False), - sa.Column("producer_ref", sa.String(120), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=True), - sa.Column("guide_source_item_id", sa.String(36), nullable=True), - sa.Column("upload_item_id", sa.String(36), nullable=True), - sa.Column("checker_run_id", sa.String(36), nullable=True), - sa.Column("logical_role", sa.String(100), nullable=True), - sa.Column("sha256", sa.String(71), nullable=False), - sa.Column("byte_count", sa.BigInteger(), nullable=False), - sa.Column("media_type", sa.String(255), nullable=False), - sa.Column("storage_namespace_id", sa.String(20), nullable=False), - sa.Column("namespace_fingerprint", sa.String(71), nullable=False), - sa.Column("canonical_target", sa.String(1024), nullable=False), - sa.Column("operation_identity", sa.String(71), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("status", sa.String(40), nullable=False, server_default="prepared"), - sa.Column( - "next_run_at", - sa.DateTime(timezone=True), - nullable=True, - ), - sa.Column("executor_id", sa.String(36), nullable=True), - sa.Column("lease_expires_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("execution_generation", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column("terminal_result_code", sa.String(100), nullable=True), - sa.Column("replica_id", sa.String(36), nullable=True), - sa.Column("receipt_id", sa.String(36), nullable=True), - sa.Column("cas_version", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column( - "prepared_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.Column("terminal_at", sa.DateTime(timezone=True), nullable=True), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.CheckConstraint( - "producer_request_type in ('guide', 'contributor', 'checker_output')", - name="producer_request_type", - ), - sa.CheckConstraint( - "producer_type in ('actor_profile', 'service_identity')", - name="producer_type", - ), - sa.CheckConstraint( - "((producer_request_type in ('guide', 'contributor') " - "and producer_type = 'actor_profile' and " - "producer_ref ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-" - "[89ab][0-9a-f]{3}-[0-9a-f]{12}$') or " - "(producer_request_type = 'checker_output' " - "and producer_type = 'service_identity' " - "and producer_ref = 'workstream.artifact.checker_output'))", - name="producer_identity", - ), - sa.CheckConstraint("sha256 ~ '^sha256:[0-9a-f]{64}$'", name="sha256_shape"), - sa.CheckConstraint("byte_count >= 0", name="byte_count_nonnegative"), - sa.CheckConstraint( - "canonical_target ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'", - name="canonical_target_shape", - ), - sa.CheckConstraint( - "operation_identity ~ '^sha256:[0-9a-f]{64}$'", - name="operation_identity_shape", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", - name="request_digest_shape", - ), - sa.CheckConstraint( - "status in ('prepared', 'put_in_flight', 'acknowledgement_unknown', " - "'object_confirmed', 'absent_replay_required', 'integrity_mismatch', " - "'provider_unavailable', 'conflict')", - name="status", - ), - sa.CheckConstraint( - "(executor_id is null) = (lease_expires_at is null)", - name="executor_lease_pair", - ), - sa.CheckConstraint( - "execution_generation >= 0 and cas_version >= 0", - name="versions_nonnegative", - ), - sa.CheckConstraint( - "status != 'prepared' or (next_run_at is null and executor_id is null " - "and lease_expires_at is null " - "and execution_generation = 0 and terminal_result_code is null " - "and terminal_at is null and replica_id is null and receipt_id is null)", - name="prepared_execution_inactive", - ), - sa.CheckConstraint( - "(producer_request_type = 'guide' and guide_source_item_id is not null " - "and upload_item_id is null and checker_run_id is null and task_id is null " - "and logical_role is null) or " - "(producer_request_type = 'contributor' and guide_source_item_id is null " - "and upload_item_id is not null and checker_run_id is null " - "and task_id is not null and logical_role is null) or " - "(producer_request_type = 'checker_output' and guide_source_item_id is null " - "and upload_item_id is null and checker_run_id is not null " - "and task_id is not null and octet_length(logical_role) between 1 and 100)", - name="producer_reference", - ), - sa.ForeignKeyConstraint( - ["storage_namespace_id", "namespace_fingerprint"], - [ - "artifact_storage_namespaces.id", - "artifact_storage_namespaces.namespace_fingerprint", - ], - name="fk_artifact_put_attempts_namespace_fingerprint", - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["task_id"], ["workstream_tasks.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["guide_source_item_id"], - ["guide_source_snapshot_items.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint( - ["upload_item_id"], ["artifact_upload_items.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["checker_run_id"], ["checker_runs.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["replica_id"], ["artifact_replicas.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["receipt_id"], ["artifact_operation_receipts.id"], ondelete="RESTRICT" - ), - sa.PrimaryKeyConstraint("id"), - sa.UniqueConstraint( - "operation_identity", - name="uq_artifact_put_attempt_operation", - ), - ) - for column in ( - "project_id", - "task_id", - "guide_source_item_id", - "upload_item_id", - "checker_run_id", - "status", - "next_run_at", - "replica_id", - "receipt_id", - ): - op.create_index( - f"ix_artifact_put_attempts_{column}", - "artifact_put_attempts", - [column], - ) - - op.create_table( - "artifact_put_attempt_charges", - sa.Column("attempt_id", sa.String(36), nullable=False), - sa.Column("charge_id", sa.String(36), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.ForeignKeyConstraint( - ["attempt_id"], ["artifact_put_attempts.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["charge_id"], ["artifact_admission_charges.id"], ondelete="RESTRICT" - ), - sa.PrimaryKeyConstraint("attempt_id", "charge_id"), - ) - - -def downgrade() -> None: - """Remove only an empty admission foundation.""" - _refuse_populated_admission_downgrade() - op.drop_table("artifact_put_attempt_charges") - for column in reversed( - ( - "project_id", - "task_id", - "guide_source_item_id", - "upload_item_id", - "checker_run_id", - "status", - "next_run_at", - "replica_id", - "receipt_id", - ) - ): - op.drop_index( - f"ix_artifact_put_attempts_{column}", - table_name="artifact_put_attempts", - ) - op.drop_table("artifact_put_attempts") - op.drop_table("artifact_admission_charges") - op.drop_table("artifact_admission_scopes") - op.drop_constraint( - "uq_artifact_storage_namespace_id_fingerprint", - "artifact_storage_namespaces", - type_="unique", - ) diff --git a/backend/alembic/versions/0029_shared_transactional_outbox.py b/backend/alembic/versions/0029_shared_transactional_outbox.py deleted file mode 100644 index ea6aba6c8..000000000 --- a/backend/alembic/versions/0029_shared_transactional_outbox.py +++ /dev/null @@ -1,330 +0,0 @@ -"""add shared transactional outbox persistence - -Revision ID: 0029_shared_transactional_outbox -Revises: 0028_artifact_admission -Create Date: 2026-07-18 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa -from sqlalchemy.dialects import postgresql - -revision = "0029_shared_transactional_outbox" -down_revision = "0028_artifact_admission" -branch_labels = depends_on = None - - -def upgrade() -> None: - """Create immutable event truth and the closed generic delivery-state shape.""" - op.create_table( - "outbox_events", - sa.Column("event_id", sa.Uuid(), nullable=False), - sa.Column("event_type", sa.String(128), nullable=False), - sa.Column("event_version", sa.SmallInteger(), nullable=False), - sa.Column("producer", sa.String(32), nullable=False, server_default="workstream"), - sa.Column("aggregate_type", sa.String(64), nullable=False), - sa.Column("aggregate_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("correlation_id", sa.String(200), nullable=False), - sa.Column("causation_event_id", sa.Uuid()), - sa.Column("idempotency_key", sa.String(200), nullable=False), - sa.Column("payload", postgresql.JSONB(astext_type=sa.Text()), nullable=False), - sa.Column("payload_digest", sa.String(71), nullable=False), - sa.Column( - "occurred_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.text("statement_timestamp()"), - ), - sa.Column("delivery_state", sa.String(16), nullable=False, server_default="pending"), - sa.Column("attempt_count", sa.Integer(), nullable=False, server_default="0"), - sa.Column( - "next_attempt_at", - sa.DateTime(timezone=True), - nullable=True, - server_default=sa.text("statement_timestamp()"), - ), - sa.Column("claim_owner", sa.String(120)), - sa.Column("claim_generation", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column("claimed_at", sa.DateTime(timezone=True)), - sa.Column("claim_expires_at", sa.DateTime(timezone=True)), - sa.Column("last_attempt_at", sa.DateTime(timezone=True)), - sa.Column("last_error_code", sa.String(80)), - sa.Column("finalized_at", sa.DateTime(timezone=True)), - sa.Column("archived_at", sa.DateTime(timezone=True)), - sa.PrimaryKeyConstraint("event_id", name="pk_outbox_events"), - sa.UniqueConstraint("idempotency_key", name="uq_outbox_events_idempotency_key"), - sa.ForeignKeyConstraint( - ["project_id"], ["projects.id"], name="fk_outbox_events_project_id_projects" - ), - sa.CheckConstraint( - "event_type ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'", - name="event_type", - ), - sa.CheckConstraint( - "event_version between 1 and 32767", - name="event_version", - ), - sa.CheckConstraint("producer = 'workstream'", name="producer"), - sa.CheckConstraint( - "aggregate_type ~ '^[a-z][a-z0-9_]{0,63}$'", - name="aggregate_type", - ), - sa.CheckConstraint( - "project_id ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'", - name="project_id", - ), - sa.CheckConstraint( - "correlation_id ~ '^[A-Za-z0-9._:-]{1,200}$'", - name="correlation_id", - ), - sa.CheckConstraint( - "idempotency_key ~ '^[A-Za-z0-9._:-]{1,200}$'", - name="idempotency_key", - ), - sa.CheckConstraint( - "payload_digest ~ '^sha256:[0-9a-f]{64}$'", - name="payload_digest", - ), - sa.CheckConstraint( - "jsonb_typeof(payload) = 'object' and octet_length(payload::text) <= 262144", - name="payload_shape", - ), - sa.CheckConstraint( - "delivery_state in ('pending','claimed','retryable','acknowledged'," - "'dead_letter','cancelled')", - name="delivery_state", - ), - sa.CheckConstraint( - "attempt_count >= 0 and claim_generation >= 0 " - "and attempt_count = claim_generation", - name="delivery_counters", - ), - sa.CheckConstraint( - "claim_owner is null or claim_owner ~ '^[A-Za-z0-9._:-]{1,120}$'", - name="claim_owner", - ), - sa.CheckConstraint( - "last_error_code is null or last_error_code ~ '^[A-Z][A-Z0-9_]{0,79}$'", - name="error_code", - ), - sa.CheckConstraint( - "(next_attempt_at is null or next_attempt_at >= occurred_at) and " - "(claimed_at is null or claimed_at >= occurred_at) and " - "(last_attempt_at is null or last_attempt_at >= occurred_at) and " - "(claim_expires_at is null or claim_expires_at > claimed_at) and " - "(finalized_at is null or finalized_at >= occurred_at) and " - "(finalized_at is null or last_attempt_at is null or finalized_at >= last_attempt_at) and " - "(archived_at is null or archived_at >= finalized_at)", - name="delivery_timestamps", - ), - sa.CheckConstraint(_state_shape(), name="delivery_state_shape"), - ) - _create_indexes() - _create_custody_triggers() - - -def _state_shape() -> str: - """Return the frozen closed-state constraint shared with the ORM model.""" - return ( - "(delivery_state = 'pending' and attempt_count = 0 and next_attempt_at is not null " - "and claim_owner is null and claimed_at is null and claim_expires_at is null " - "and last_attempt_at is null and last_error_code is null and finalized_at is null " - "and archived_at is null) or " - "(delivery_state = 'claimed' and attempt_count > 0 and next_attempt_at is null " - "and claim_owner is not null and claimed_at is not null " - "and claim_expires_at is not null and last_attempt_at = claimed_at " - "and finalized_at is null and archived_at is null) or " - "(delivery_state = 'retryable' and attempt_count > 0 and next_attempt_at is not null " - "and claim_owner is null and claimed_at is null and claim_expires_at is null " - "and last_attempt_at is not null and last_error_code is not null " - "and finalized_at is null and archived_at is null) or " - "(delivery_state = 'acknowledged' and attempt_count > 0 and next_attempt_at is null " - "and claim_owner is null and claimed_at is null and claim_expires_at is null " - "and last_attempt_at is not null and finalized_at is not null) or " - "(delivery_state = 'dead_letter' and attempt_count > 0 and next_attempt_at is null " - "and claim_owner is null and claimed_at is null and claim_expires_at is null " - "and last_attempt_at is not null and last_error_code is not null " - "and finalized_at is not null) or " - "(delivery_state = 'cancelled' and next_attempt_at is null and claim_owner is null " - "and claimed_at is null and claim_expires_at is null and finalized_at is not null " - "and ((attempt_count = 0 and last_attempt_at is null and last_error_code is null) " - "or (attempt_count > 0 and last_attempt_at is not null)))" - ) - - -def _create_indexes() -> None: - op.create_index( - "ix_outbox_events_eligible", - "outbox_events", - ["event_type", "delivery_state", "next_attempt_at", "occurred_at", "event_id"], - postgresql_where=sa.text("delivery_state in ('pending','retryable')"), - ) - op.create_index( - "ix_outbox_events_expired_claims", - "outbox_events", - ["claim_expires_at", "event_id"], - postgresql_where=sa.text("delivery_state = 'claimed'"), - ) - op.create_index( - "ix_outbox_events_project_drain", - "outbox_events", - ["project_id", "delivery_state", "occurred_at", "event_id"], - ) - op.create_index( - "ix_outbox_events_retention", - "outbox_events", - ["finalized_at", "event_id"], - postgresql_where=sa.text( - "delivery_state in ('acknowledged','dead_letter','cancelled') " - "and archived_at is null" - ), - ) - op.create_index( - "ix_outbox_events_aggregate", - "outbox_events", - ["aggregate_type", "aggregate_id", "occurred_at", "event_id"], - ) - - -def _create_custody_triggers() -> None: - op.execute( - """ - create function guard_outbox_event() returns trigger - language plpgsql as $$ - declare event_time timestamptz; - begin - if tg_op = 'TRUNCATE' then - raise exception 'outbox events cannot be truncated' using errcode='55000'; - elsif tg_op = 'DELETE' then - raise exception 'outbox events cannot be deleted' using errcode='55000'; - elsif tg_op = 'INSERT' then - event_time := statement_timestamp(); - new.producer := 'workstream'; - new.occurred_at := event_time; - new.delivery_state := 'pending'; - new.attempt_count := 0; - new.next_attempt_at := event_time; - new.claim_owner := null; - new.claim_generation := 0; - new.claimed_at := null; - new.claim_expires_at := null; - new.last_attempt_at := null; - new.last_error_code := null; - new.finalized_at := null; - new.archived_at := null; - return new; - end if; - - if (new.event_id, new.event_type, new.event_version, new.producer, - new.aggregate_type, new.aggregate_id, new.project_id, - new.correlation_id, new.causation_event_id, new.idempotency_key, - new.payload, new.payload_digest, new.occurred_at) - is distinct from - (old.event_id, old.event_type, old.event_version, old.producer, - old.aggregate_type, old.aggregate_id, old.project_id, - old.correlation_id, old.causation_event_id, old.idempotency_key, - old.payload, old.payload_digest, old.occurred_at) then - raise exception 'outbox event envelope is immutable' using errcode='55000'; - end if; - if new.attempt_count < old.attempt_count - or new.claim_generation < old.claim_generation - or new.attempt_count <> new.claim_generation then - raise exception 'outbox counters cannot regress' using errcode='23514'; - end if; - if old.archived_at is not null and - (new.delivery_state, new.attempt_count, new.next_attempt_at, - new.claim_owner, new.claim_generation, new.claimed_at, - new.claim_expires_at, new.last_attempt_at, new.last_error_code, - new.finalized_at, new.archived_at) - is distinct from - (old.delivery_state, old.attempt_count, old.next_attempt_at, - old.claim_owner, old.claim_generation, old.claimed_at, - old.claim_expires_at, old.last_attempt_at, old.last_error_code, - old.finalized_at, old.archived_at) then - raise exception 'archived outbox event is closed' using errcode='55000'; - end if; - - if old.delivery_state in ('pending', 'retryable') - and new.delivery_state = 'claimed' then - if new.attempt_count <> old.attempt_count + 1 - or new.claim_generation <> old.claim_generation + 1 - or new.last_error_code is distinct from old.last_error_code then - raise exception 'outbox claim generation must increment once' using errcode='23514'; - end if; - elsif old.delivery_state = 'claimed' - and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then - if new.attempt_count <> old.attempt_count - or new.claim_generation <> old.claim_generation - or new.last_attempt_at is distinct from old.last_attempt_at then - raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; - end if; - elsif old.delivery_state = 'dead_letter' - and new.delivery_state = 'retryable' and old.archived_at is null then - if new.attempt_count <> old.attempt_count - or new.claim_generation <> old.claim_generation - or new.last_attempt_at is distinct from old.last_attempt_at - or new.last_error_code is distinct from old.last_error_code then - raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; - end if; - elsif old.delivery_state in ('pending','retryable') - and new.delivery_state = 'cancelled' then - if new.attempt_count <> old.attempt_count - or new.claim_generation <> old.claim_generation - or new.last_attempt_at is distinct from old.last_attempt_at - or new.last_error_code is distinct from old.last_error_code then - raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; - end if; - elsif old.delivery_state in ('pending','retryable') - and new.delivery_state = old.delivery_state then - if (new.attempt_count, new.claim_owner, new.claim_generation, - new.claimed_at, new.claim_expires_at, new.last_attempt_at, - new.last_error_code, new.finalized_at, new.archived_at) - is distinct from - (old.attempt_count, old.claim_owner, old.claim_generation, - old.claimed_at, old.claim_expires_at, old.last_attempt_at, - old.last_error_code, old.finalized_at, old.archived_at) then - raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; - end if; - elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') - and new.delivery_state = old.delivery_state then - if (new.attempt_count, new.next_attempt_at, new.claim_owner, - new.claim_generation, new.claimed_at, new.claim_expires_at, - new.last_attempt_at, new.last_error_code, new.finalized_at) - is distinct from - (old.attempt_count, old.next_attempt_at, old.claim_owner, - old.claim_generation, old.claimed_at, old.claim_expires_at, - old.last_attempt_at, old.last_error_code, old.finalized_at) - or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) - or (old.archived_at is null and new.archived_at is null) then - raise exception 'terminal outbox event permits archival only' using errcode='23514'; - end if; - else - raise exception 'illegal outbox delivery transition' using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger outbox_events_custody before insert or update or delete " - "on outbox_events for each row execute function guard_outbox_event()" - ) - op.execute( - "create trigger outbox_events_reject_truncate before truncate on outbox_events " - "for each statement execute function guard_outbox_event()" - ) - - -def downgrade() -> None: - """Remove the empty outbox only after excluding concurrent append writers.""" - bind = op.get_bind() - bind.execute(sa.text("lock table outbox_events in access exclusive mode")) - if bind.execute(sa.text("select exists(select 1 from outbox_events)")).scalar_one(): - raise RuntimeError("cannot downgrade with shared outbox events") - op.execute("drop trigger outbox_events_reject_truncate on outbox_events") - op.execute("drop trigger outbox_events_custody on outbox_events") - op.execute("drop function guard_outbox_event()") - op.drop_table("outbox_events") diff --git a/backend/alembic/versions/0030_artifact_verification_fencing.py b/backend/alembic/versions/0030_artifact_verification_fencing.py deleted file mode 100644 index 8422d7dcf..000000000 --- a/backend/alembic/versions/0030_artifact_verification_fencing.py +++ /dev/null @@ -1,340 +0,0 @@ -"""add artifact verification publication and execution fencing - -Revision ID: 0030_artifact_verification -Revises: 0029_shared_transactional_outbox -Create Date: 2026-07-19 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0030_artifact_verification" -down_revision = "0029_shared_transactional_outbox" -branch_labels = depends_on = None - - -def upgrade() -> None: - """Install polymorphic receipts, verification jobs, and generation fences.""" - op.add_column( - "artifact_put_attempts", - sa.Column("execution_mode", sa.String(20), nullable=True), - ) - op.add_column( - "artifact_put_attempts", - sa.Column("observation_count", sa.BigInteger(), nullable=False, server_default="0"), - ) - op.add_column( - "artifact_put_attempts", - sa.Column("maximum_observations", sa.BigInteger(), nullable=False, server_default="5"), - ) - op.create_check_constraint( - "execution_mode", - "artifact_put_attempts", - "execution_mode is null or execution_mode in ('caller_put', 'observation')", - ) - op.create_check_constraint( - "observation_counts", - "artifact_put_attempts", - "observation_count >= 0 and maximum_observations > 0", - ) - op.create_check_constraint( - "unavailable_exhausted", - "artifact_put_attempts", - "status != 'provider_unavailable' or (observation_count >= maximum_observations " - "and next_run_at is null and terminal_at is not null)", - ) - op.create_check_constraint( - "inflight_fence", - "artifact_put_attempts", - "(status = 'put_in_flight') = (executor_id is not null)", - ) - - op.drop_constraint( - "uq_artifact_receipt_upload_item", "artifact_operation_receipts", type_="unique" - ) - op.alter_column("artifact_operation_receipts", "upload_item_id", nullable=True) - op.add_column( - "artifact_operation_receipts", - sa.Column("contract_version", sa.Integer(), nullable=False, server_default="1"), - ) - op.add_column( - "artifact_operation_receipts", sa.Column("put_attempt_id", sa.String(36), nullable=True) - ) - op.add_column( - "artifact_operation_receipts", - sa.Column("guide_source_item_id", sa.String(36), nullable=True), - ) - op.add_column( - "artifact_operation_receipts", sa.Column("checker_run_id", sa.String(36), nullable=True) - ) - op.add_column( - "artifact_operation_receipts", sa.Column("logical_role", sa.String(100), nullable=True) - ) - # The receipt table is append-only at runtime. Migration-owned promotion - # of linked v1 contributor receipts is the sole controlled update. - op.execute( - "alter table artifact_operation_receipts " - "disable trigger trg_artifact_operation_receipts_immutable" - ) - op.execute( - "update artifact_operation_receipts r set put_attempt_id = a.id, contract_version = 2 " - "from artifact_put_attempts a where a.receipt_id = r.id" - ) - op.execute( - "alter table artifact_operation_receipts " - "enable trigger trg_artifact_operation_receipts_immutable" - ) - op.create_foreign_key( - "fk_artifact_receipt_put_attempt", - "artifact_operation_receipts", - "artifact_put_attempts", - ["put_attempt_id"], - ["id"], - ondelete="RESTRICT", - ) - op.create_foreign_key( - "fk_artifact_receipt_guide_item", - "artifact_operation_receipts", - "guide_source_snapshot_items", - ["guide_source_item_id"], - ["id"], - ondelete="RESTRICT", - ) - op.create_foreign_key( - "fk_artifact_receipt_checker_run", - "artifact_operation_receipts", - "checker_runs", - ["checker_run_id"], - ["id"], - ondelete="RESTRICT", - ) - op.create_unique_constraint( - "uq_artifact_receipt_put_attempt", "artifact_operation_receipts", ["put_attempt_id"] - ) - op.create_check_constraint( - "contract_producer_reference", - "artifact_operation_receipts", - "(contract_version = 1 and put_attempt_id is null and upload_item_id is not null " - "and guide_source_item_id is null and checker_run_id is null) or " - "(contract_version = 2 and put_attempt_id is not null and " - "((upload_item_id is not null)::int + (guide_source_item_id is not null)::int + " - "(checker_run_id is not null)::int) = 1)", - ) - op.create_index( - "ix_artifact_operation_receipts_put_attempt_id", - "artifact_operation_receipts", - ["put_attempt_id"], - ) - - op.create_table( - "artifact_put_observation_receipts", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("put_attempt_id", sa.String(36), nullable=False, index=True), - sa.Column("execution_generation", sa.BigInteger(), nullable=False), - sa.Column("outcome", sa.String(40), nullable=False), - sa.Column("expected_sha256", sa.String(71), nullable=False), - sa.Column("expected_byte_count", sa.BigInteger(), nullable=False), - sa.Column("observed_sha256", sa.String(71), nullable=True), - sa.Column("observed_byte_count", sa.BigInteger(), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now()), - sa.ForeignKeyConstraint( - ["put_attempt_id"], ["artifact_put_attempts.id"], ondelete="RESTRICT" - ), - sa.UniqueConstraint( - "put_attempt_id", "execution_generation", name="uq_artifact_put_observation_fence" - ), - sa.CheckConstraint( - "outcome in ('observed_confirmed', 'observed_missing', " - "'observed_integrity_mismatch', 'conflict')", - name="outcome", - ), - sa.CheckConstraint("expected_sha256 ~ '^sha256:[0-9a-f]{64}$'", name="expected_sha256"), - sa.CheckConstraint( - "observed_sha256 is null or observed_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="observed_sha256", - ), - sa.CheckConstraint("expected_byte_count >= 0", name="expected_size"), - sa.CheckConstraint( - "observed_byte_count is null or observed_byte_count >= 0", name="observed_size" - ), - sa.CheckConstraint( - "(outcome in ('observed_confirmed', 'observed_integrity_mismatch')) = " - "(observed_sha256 is not null and observed_byte_count is not null)", - name="observed_facts", - ), - ) - op.execute( - """ - create trigger trg_artifact_put_observation_receipts_immutable - before update or delete on artifact_put_observation_receipts - for each row execute function reject_artifact_fact_mutation() - """ - ) - - op.create_table( - "artifact_verification_jobs", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("originating_put_attempt_id", sa.String(36), nullable=False), - sa.Column("replica_id", sa.String(36), nullable=False), - sa.Column("status", sa.String(40), nullable=False, server_default="pending"), - sa.Column("attempt_count", sa.Integer(), nullable=False, server_default="0"), - sa.Column("maximum_attempts", sa.Integer(), nullable=False), - sa.Column("next_run_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("executor_id", sa.String(36), nullable=True), - sa.Column("lease_expires_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("execution_generation", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column("cas_version", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column("terminal_result_code", sa.String(100), nullable=True), - sa.Column("terminal_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now()), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now()), - sa.ForeignKeyConstraint( - ["originating_put_attempt_id"], ["artifact_put_attempts.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint(["replica_id"], ["artifact_replicas.id"], ondelete="RESTRICT"), - sa.UniqueConstraint("originating_put_attempt_id", name="uq_artifact_verification_origin"), - sa.CheckConstraint( - "status in ('pending', 'running', 'verified', 'missing', 'integrity_mismatch', 'provider_unavailable', 'conflict')", - name="status", - ), - sa.CheckConstraint("attempt_count >= 0 and maximum_attempts > 0", name="attempts"), - sa.CheckConstraint("execution_generation >= 0 and cas_version >= 0", name="versions"), - sa.CheckConstraint("(executor_id is null) = (lease_expires_at is null)", name="fence_pair"), - sa.CheckConstraint( - "(status = 'running') = (executor_id is not null)", name="running_fence" - ), - sa.CheckConstraint( - "status != 'provider_unavailable' or ((next_run_at is not null and terminal_at is null and attempt_count < maximum_attempts) or (next_run_at is null and terminal_at is not null and attempt_count >= maximum_attempts))", - name="unavailable_retryability", - ), - ) - for column in ("originating_put_attempt_id", "replica_id", "status", "next_run_at"): - op.create_index( - f"ix_artifact_verification_jobs_{column}", "artifact_verification_jobs", [column] - ) - - op.create_table( - "artifact_verification_receipts", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("verification_job_id", sa.String(36), nullable=False), - sa.Column("execution_generation", sa.BigInteger(), nullable=False), - sa.Column("outcome", sa.String(40), nullable=False), - sa.Column("observed_sha256", sa.String(71), nullable=True), - sa.Column("observed_byte_count", sa.BigInteger(), nullable=True), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now()), - sa.ForeignKeyConstraint( - ["verification_job_id"], ["artifact_verification_jobs.id"], ondelete="RESTRICT" - ), - sa.UniqueConstraint( - "verification_job_id", "execution_generation", name="uq_artifact_verification_fence" - ), - sa.CheckConstraint( - "outcome in ('verified', 'missing', 'integrity_mismatch', 'conflict')", name="outcome" - ), - sa.CheckConstraint( - "observed_sha256 is null or observed_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="observed_sha256", - ), - sa.CheckConstraint( - "observed_byte_count is null or observed_byte_count >= 0", name="observed_size" - ), - sa.CheckConstraint( - "(outcome in ('verified', 'integrity_mismatch')) = " - "(observed_sha256 is not null and observed_byte_count is not null)", - name="observed_facts", - ), - ) - op.execute( - """ - create trigger trg_artifact_verification_receipts_immutable - before update or delete on artifact_verification_receipts - for each row execute function reject_artifact_fact_mutation() - """ - ) - op.create_index( - "ix_artifact_verification_receipts_verification_job_id", - "artifact_verification_receipts", - ["verification_job_id"], - ) - - -def downgrade() -> None: - """Remove verification mechanics only when all new evidence is empty.""" - connection = op.get_bind() - connection.execute( - sa.text( - "lock table artifact_verification_receipts, artifact_verification_jobs, artifact_put_observation_receipts, artifact_operation_receipts, artifact_put_attempts in access exclusive mode" - ) - ) - if any( - connection.execute(sa.text(f"select exists(select 1 from {table})")).scalar() - for table in ( - "artifact_verification_receipts", - "artifact_verification_jobs", - "artifact_put_observation_receipts", - ) - ): - raise RuntimeError("cannot downgrade populated artifact verification evidence") - if connection.execute( - sa.text( - "select exists(select 1 from artifact_operation_receipts where upload_item_id is null)" - ) - ).scalar(): - raise RuntimeError("cannot downgrade polymorphic artifact operation receipts") - op.drop_index( - "ix_artifact_verification_receipts_verification_job_id", - table_name="artifact_verification_receipts", - ) - op.execute( - "drop trigger trg_artifact_verification_receipts_immutable " - "on artifact_verification_receipts" - ) - op.drop_table("artifact_verification_receipts") - for column in reversed(("originating_put_attempt_id", "replica_id", "status", "next_run_at")): - op.drop_index( - f"ix_artifact_verification_jobs_{column}", table_name="artifact_verification_jobs" - ) - op.drop_table("artifact_verification_jobs") - op.execute( - "drop trigger trg_artifact_put_observation_receipts_immutable " - "on artifact_put_observation_receipts" - ) - op.drop_table("artifact_put_observation_receipts") - op.drop_index( - "ix_artifact_operation_receipts_put_attempt_id", table_name="artifact_operation_receipts" - ) - op.drop_constraint("contract_producer_reference", "artifact_operation_receipts", type_="check") - op.drop_constraint( - "uq_artifact_receipt_put_attempt", "artifact_operation_receipts", type_="unique" - ) - op.drop_constraint( - "fk_artifact_receipt_checker_run", "artifact_operation_receipts", type_="foreignkey" - ) - op.drop_constraint( - "fk_artifact_receipt_guide_item", "artifact_operation_receipts", type_="foreignkey" - ) - op.drop_constraint( - "fk_artifact_receipt_put_attempt", "artifact_operation_receipts", type_="foreignkey" - ) - for column in ( - "logical_role", - "checker_run_id", - "guide_source_item_id", - "put_attempt_id", - "contract_version", - ): - op.drop_column("artifact_operation_receipts", column) - op.alter_column("artifact_operation_receipts", "upload_item_id", nullable=False) - op.create_unique_constraint( - "uq_artifact_receipt_upload_item", "artifact_operation_receipts", ["upload_item_id"] - ) - op.drop_constraint("execution_mode", "artifact_put_attempts", type_="check") - op.drop_constraint("inflight_fence", "artifact_put_attempts", type_="check") - op.drop_constraint("unavailable_exhausted", "artifact_put_attempts", type_="check") - op.drop_constraint("observation_counts", "artifact_put_attempts", type_="check") - op.drop_column("artifact_put_attempts", "maximum_observations") - op.drop_column("artifact_put_attempts", "observation_count") - op.drop_column("artifact_put_attempts", "execution_mode") diff --git a/backend/alembic/versions/0031_project_role_grants.py b/backend/alembic/versions/0031_project_role_grants.py deleted file mode 100644 index 83bb44686..000000000 --- a/backend/alembic/versions/0031_project_role_grants.py +++ /dev/null @@ -1,461 +0,0 @@ -"""add independent project-role grants and qualification evidence - -Revision ID: 0031_project_role_grants -Revises: 0030_artifact_verification -Create Date: 2026-07-21 -""" - -from __future__ import annotations - -import re - -from alembic import op -import sqlalchemy as sa -from sqlalchemy.dialects import postgresql - - -revision = "0031_project_role_grants" -down_revision = "0030_artifact_verification" -branch_labels = depends_on = None - -_ACTIONS = ( - ("project.contributor_candidate.list", "project.role_grant.manage"), - ("project_role_grant.list", "project.role_grant.read"), - ("project_role_grant.read", "project.role_grant.read"), - ("project_role_grant.issue", "project.role_grant.manage"), - ("project_role_grant.revoke", "project.role_grant.manage"), -) -_DENIALS = ( - "project_role_grant_already_revoked", - "project_role_grant_replay_state_changed", -) -_STRIP = ( - "(E' \\t\\n\\r\\f\\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)" - "||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)" - "||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)" - "||chr(8239)||chr(8287)||chr(12288))" -) - - -def _constraint_definition(name: str) -> str: - return ( - op.get_bind() - .execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass and conname=:name" - ), - {"name": f"ck_audit_events_{name}"}, - ) - .scalar_one() - ) - - -def _replace_constraint(name: str, definition: str) -> None: - op.drop_constraint(name, "audit_events", type_="check") - op.execute(f"alter table audit_events add constraint ck_audit_events_{name} {definition}") - - -def _replace_action_registry(*, add: bool) -> None: - definition = _constraint_definition("authorization_action_evidence") - marker = ( - "(((action_id)::text = 'actor.service.provision'::text) AND " - "((permission_id)::text = 'actor.service.provision'::text))" - ) - additions = " OR ".join( - f"(((action_id)::text = '{action}'::text) AND ((permission_id)::text = '{permission}'::text))" - for action, permission in _ACTIONS - ) - if add: - if definition.count(marker) != 2 or any(action in definition for action, _ in _ACTIONS): - raise RuntimeError("unexpected authority action registry definition") - definition = definition.replace(marker, marker + " OR " + additions) - else: - suffix = " OR " + additions - if definition.count(suffix) != 2: - raise RuntimeError("unexpected authority action registry definition") - definition = definition.replace(suffix, "") - _replace_constraint("authorization_action_evidence", definition) - - -def _replace_authority_registries(*, add: bool) -> None: - definition = _constraint_definition("authority_registries") - if add: - obsolete = re.compile( - r"\s+OR \(\(\(event_type\)::text = 'ProjectRoleGrantReplaced'::text\) " - r"AND \(reason = 'authority_replacement'::text\)\)" - ) - if len(tuple(obsolete.finditer(definition))) != 1: - raise RuntimeError("unexpected authority registry definition") - definition = obsolete.sub("", definition, count=1) - marker = "('identity_link_conflict'::character varying)::text" - additions = ", ".join(f"('{value}'::character varying)::text" for value in _DENIALS) - if definition.count(marker) != 1 or any(value in definition for value in _DENIALS): - raise RuntimeError("unexpected authority denial registry definition") - definition = definition.replace(marker, marker + ", " + additions) - else: - additions = ", " + ", ".join(f"('{value}'::character varying)::text" for value in _DENIALS) - if definition.count(additions) != 1: - raise RuntimeError("unexpected authority denial registry definition") - definition = definition.replace(additions, "") - marker = ( - "(((event_type)::text = 'ProjectRoleGrantIssued'::text) AND " - "(reason = 'authority_assignment'::text))" - ) - restored = ( - marker + " OR (((event_type)::text = 'ProjectRoleGrantReplaced'::text) " - "AND (reason = 'authority_replacement'::text))" - ) - if definition.count(marker) != 1: - raise RuntimeError("unexpected authority registry definition") - definition = definition.replace(marker, restored, 1) - _replace_constraint("authority_registries", definition) - - -def _function_definition(name: str) -> str: - return ( - op.get_bind() - .execute(sa.text("select pg_get_functiondef(cast(:name as regproc))"), {"name": name}) - .scalar_one() - ) - - -def _replace_audit_functions(*, add: bool) -> None: - facts = _function_definition("authority_event_facts_are_safe") - linked = _function_definition("validate_linked_authority_event") - old_roles = "array['submitter','reviewer','both']" - new_roles = "array['submitter','reviewer','adjudicator']" - replacement_case = re.compile( - r"\s*when 'ProjectRoleGrantReplaced' then return.*?;(?=\s+when)", re.S - ) - if add: - if old_roles not in facts or len(replacement_case.findall(facts)) != 1: - raise RuntimeError("unexpected authority fact validator definition") - facts = facts.replace(old_roles, new_roles) - facts = replacement_case.sub("", facts, count=1) - linked_pairs = ( - ("'ProjectRoleGrantIssued','ProjectRoleGrantReplaced'", "'ProjectRoleGrantIssued'"), - ) - else: - if new_roles not in facts or replacement_case.search(facts): - raise RuntimeError("unexpected authority fact validator definition") - facts = facts.replace(new_roles, old_roles) - marker = "when 'ProjectRoleQualificationSnapshotCaptured' then" - restored = ( - "when 'ProjectRoleGrantReplaced' then return\n" - " authority_grant_facts_are_safe(before_state,array['submitter','reviewer','both'],'active',true,envelope_project_id)\n" - " and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','both'],'active',true,envelope_project_id)\n" - " and before_state->>'scope_id'=after_state->>'scope_id';\n " - ) - if facts.count(marker) != 1: - raise RuntimeError("unexpected authority fact validator definition") - facts = facts.replace(marker, restored + marker) - linked_pairs = ( - ("'ProjectRoleGrantIssued'", "'ProjectRoleGrantIssued','ProjectRoleGrantReplaced'"), - ) - changed = 0 - for old, new in linked_pairs: - count = linked.count(old) - if count: - linked = linked.replace(old, new) - changed += count - if changed != 3: - raise RuntimeError("unexpected linked authority validator definition") - op.execute(facts) - op.execute(linked) - - -def _create_helpers() -> None: - statements = ( - r""" - create function project_role_reference_token_is_safe(value text) returns boolean - language sql immutable strict as $$ - select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 - $$ - """, - r""" - create function project_role_reference_array_is_safe(value jsonb, uuid_only boolean) - returns boolean language sql immutable strict as $$ - select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 - and not exists ( - select 1 from jsonb_array_elements(value) item - where jsonb_typeof(item)<>'string' or - case when uuid_only then not (item #>> '{}') ~ - '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' - else not project_role_reference_token_is_safe(item #>> '{}') end - ) - $$ - """, - r""" - create function project_role_availability_is_safe(value jsonb) returns boolean - language sql immutable strict as $$ - select jsonb_typeof(value)='object' and - (select count(*)=3 from jsonb_object_keys(value)) and - value ?& array['availability','reference_ids','unavailable_reason'] and - project_role_reference_array_is_safe(value->'reference_ids',false) and ( - (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 - and value->'unavailable_reason'='null'::jsonb) or - (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 - and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) - ) - $$ - """, - r""" - create function project_role_reason_is_safe(value text) returns boolean - language plpgsql immutable strict as $$ - declare point integer; index integer; - begin - if octet_length(value) not between 1 and 500 or value <> btrim(value, """ - + _STRIP - + r""") then return false; end if; - for index in 1..char_length(value) loop - point := ascii(substr(value,index,1)); - if point between 0 and 31 or point between 127 and 159 - or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then - return false; - end if; - end loop; - return true; - end $$ - """, - ) - for statement in statements: - op.execute(statement) - - -def _create_history_guards() -> None: - statements = ( - """ - create function guard_project_role_snapshot_history() returns trigger language plpgsql as $$ - begin - if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; - raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; - end $$ - """, - """ - create trigger trg_project_role_qualification_snapshots_immutable - before insert or update or delete on project_role_qualification_snapshots - for each row execute function guard_project_role_snapshot_history() - """, - """ - create function guard_project_role_grant_history() returns trigger language plpgsql as $$ - begin - if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; - if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; - if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, - new.qualification_snapshot_id,new.granted_by_actor_profile_id, - new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) - is distinct from - (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, - old.qualification_snapshot_id,old.granted_by_actor_profile_id, - old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) - or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 - or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null - or new.revoked_reason is null then - raise exception 'invalid project-role grant history transition' using errcode='23514'; - end if; - new.revoked_at := clock_timestamp(); - return new; - end $$ - """, - """ - create trigger trg_project_role_grants_history before insert or update or delete on project_role_grants - for each row execute function guard_project_role_grant_history() - """, - """ - create function reject_project_role_history_truncate() returns trigger language plpgsql as $$ - begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $$ - """, - """ - create trigger trg_project_role_snapshots_reject_truncate before truncate - on project_role_qualification_snapshots execute function reject_project_role_history_truncate() - """, - """ - create trigger trg_project_role_grants_reject_truncate before truncate - on project_role_grants execute function reject_project_role_history_truncate() - """, - ) - for statement in statements: - op.execute(statement) - - -def upgrade() -> None: - """Install exact-role history only after proving no replacement-era state exists.""" - bind = op.get_bind() - bind.execute( - sa.text("lock table audit_events, authority_idempotency_records in access exclusive mode") - ) - blocked = bind.execute( - sa.text(""" - select exists(select 1 from audit_events where event_domain='authority' and ( - before_facts->>'role'='both' or after_facts->>'role'='both' or - before_facts::jsonb ? 'replaced_grant_id' or after_facts::jsonb ? 'replaced_grant_id' or - event_type='ProjectRoleGrantReplaced' or reason='authority_replacement')) or - exists(select 1 from authority_idempotency_records where operation in - ('project_role_grant.issue','project_role_grant.revoke')) - """) - ).scalar_one() - if blocked: - raise RuntimeError("cannot safely upgrade replacement-era project-role evidence") - _create_helpers() - op.create_table( - "project_role_qualification_snapshots", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column("project_id", sa.String(36), sa.ForeignKey("projects.id"), nullable=False), - sa.Column( - "actor_profile_id", sa.String(36), sa.ForeignKey("actor_profiles.id"), nullable=False - ), - sa.Column("requested_role", sa.String(24), nullable=False), - sa.Column("skills_snapshot", postgresql.JSONB(), nullable=False), - sa.Column("reputation_snapshot", postgresql.JSONB(), nullable=False), - sa.Column("prior_project_work_refs", postgresql.JSONB(), nullable=False), - sa.Column("external_expertise_refs", postgresql.JSONB(), nullable=False), - sa.Column( - "captured_by_actor_profile_id", - sa.String(36), - sa.ForeignKey("actor_profiles.id"), - nullable=False, - ), - sa.Column( - "captured_by_admin_role_grant_id", - sa.Uuid(), - sa.ForeignKey("admin_role_grants.id"), - nullable=False, - ), - sa.Column( - "captured_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.func.now() - ), - sa.CheckConstraint("requested_role in ('submitter','reviewer','adjudicator')", name="role"), - sa.CheckConstraint( - "project_role_availability_is_safe(skills_snapshot) and project_role_availability_is_safe(reputation_snapshot)", - name="availability", - ), - sa.CheckConstraint( - "project_role_reference_array_is_safe(prior_project_work_refs,true)", - name="prior_work_refs", - ), - sa.CheckConstraint( - "project_role_reference_array_is_safe(external_expertise_refs,false)", - name="external_expertise_refs", - ), - sa.UniqueConstraint( - "id", "actor_profile_id", "project_id", "requested_role", name="grant_reference" - ), - ) - op.create_index( - "ix_project_role_qualification_snapshots_history", - "project_role_qualification_snapshots", - ["project_id", "actor_profile_id", "requested_role", "captured_at"], - ) - op.create_table( - "project_role_grants", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column("project_id", sa.String(36), sa.ForeignKey("projects.id"), nullable=False), - sa.Column( - "actor_profile_id", sa.String(36), sa.ForeignKey("actor_profiles.id"), nullable=False - ), - sa.Column("role", sa.String(24), nullable=False), - sa.Column("status", sa.String(16), nullable=False, server_default="active"), - sa.Column("version", sa.SmallInteger(), nullable=False, server_default="1"), - sa.Column("grant_method", sa.String(16), nullable=False, server_default="manual"), - sa.Column("qualification_snapshot_id", sa.Uuid(), nullable=False), - sa.Column( - "granted_by_actor_profile_id", - sa.String(36), - sa.ForeignKey("actor_profiles.id"), - nullable=False, - ), - sa.Column( - "granted_by_admin_role_grant_id", - sa.Uuid(), - sa.ForeignKey("admin_role_grants.id"), - nullable=False, - ), - sa.Column("grant_reason", sa.Text(), nullable=False), - sa.Column( - "granted_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.func.now() - ), - sa.Column("revoked_by_actor_profile_id", sa.String(36), sa.ForeignKey("actor_profiles.id")), - sa.Column( - "revoked_by_admin_role_grant_id", sa.Uuid(), sa.ForeignKey("admin_role_grants.id") - ), - sa.Column("revoked_reason", sa.Text()), - sa.Column("revoked_at", sa.DateTime(timezone=True)), - sa.CheckConstraint("role in ('submitter','reviewer','adjudicator')", name="role"), - sa.CheckConstraint("grant_method='manual'", name="grant_method"), - sa.CheckConstraint( - "project_role_reason_is_safe(grant_reason) and (revoked_reason is null or project_role_reason_is_safe(revoked_reason))", - name="reason", - ), - sa.CheckConstraint( - "(status='active' and version=1 and revoked_by_actor_profile_id is null and revoked_by_admin_role_grant_id is null and revoked_reason is null and revoked_at is null) or (status='revoked' and version=2 and revoked_by_actor_profile_id is not null and revoked_by_admin_role_grant_id is not null and revoked_reason is not null and revoked_at is not null)", - name="lifecycle", - ), - sa.ForeignKeyConstraint( - ["qualification_snapshot_id", "actor_profile_id", "project_id", "role"], - [ - "project_role_qualification_snapshots.id", - "project_role_qualification_snapshots.actor_profile_id", - "project_role_qualification_snapshots.project_id", - "project_role_qualification_snapshots.requested_role", - ], - name="qualification_ownership", - ondelete="RESTRICT", - ), - ) - op.create_index( - "uq_project_role_grants_active_exact_role", - "project_role_grants", - ["project_id", "actor_profile_id", "role"], - unique=True, - postgresql_where=sa.text("status='active'"), - ) - op.create_index( - "ix_project_role_grants_project_actor_role_status", - "project_role_grants", - ["project_id", "actor_profile_id", "role", "status"], - ) - op.create_index( - "ix_project_role_grants_actor_role_status", - "project_role_grants", - ["actor_profile_id", "role", "status"], - ) - _create_history_guards() - _replace_authority_registries(add=True) - _replace_action_registry(add=True) - _replace_audit_functions(add=True) - - -def downgrade() -> None: - """Restore 0030 only when no 10A-owned truth or evidence exists.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table project_role_grants, project_role_qualification_snapshots, audit_events in access exclusive mode" - ) - ) - blocked = bind.execute( - sa.text(""" - select exists(select 1 from project_role_grants) or - exists(select 1 from project_role_qualification_snapshots) or - exists(select 1 from audit_events where event_domain='authority' and ( - before_facts->>'role'='adjudicator' or after_facts->>'role'='adjudicator' or - action_id in ('project.contributor_candidate.list','project_role_grant.list', - 'project_role_grant.read','project_role_grant.issue','project_role_grant.revoke') or - denial_code in ('project_role_grant_already_revoked','project_role_grant_replay_state_changed'))) - """) - ).scalar_one() - if blocked: - raise RuntimeError("cannot downgrade project-role grant evidence") - _replace_audit_functions(add=False) - _replace_action_registry(add=False) - _replace_authority_registries(add=False) - op.drop_table("project_role_grants") - op.drop_table("project_role_qualification_snapshots") - op.execute("drop function guard_project_role_grant_history()") - op.execute("drop function guard_project_role_snapshot_history()") - op.execute("drop function reject_project_role_history_truncate()") - op.execute("drop function project_role_availability_is_safe(jsonb)") - op.execute("drop function project_role_reference_array_is_safe(jsonb,boolean)") - op.execute("drop function project_role_reference_token_is_safe(text)") - op.execute("drop function project_role_reason_is_safe(text)") diff --git a/backend/alembic/versions/0032_artifact_recovery_attempts.py b/backend/alembic/versions/0032_artifact_recovery_attempts.py deleted file mode 100644 index 37a16100d..000000000 --- a/backend/alembic/versions/0032_artifact_recovery_attempts.py +++ /dev/null @@ -1,290 +0,0 @@ -"""add artifact recovery attempts and verification retry lineage - -Revision ID: 0032_artifact_recovery -Revises: 0031_project_role_grants -Create Date: 2026-07-21 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0032_artifact_recovery" -down_revision = "0031_project_role_grants" -branch_labels = depends_on = None - - -def upgrade() -> None: - """Install immutable recovery envelopes and retry-job lineage.""" - op.drop_constraint( - "uq_artifact_verification_origin", "artifact_verification_jobs", type_="unique" - ) - op.add_column( - "artifact_verification_jobs", - sa.Column("parent_verification_job_id", sa.String(36), nullable=True), - ) - op.create_foreign_key( - "fk_artifact_verification_parent", - "artifact_verification_jobs", - "artifact_verification_jobs", - ["parent_verification_job_id"], - ["id"], - ondelete="RESTRICT", - ) - op.create_unique_constraint( - "uq_artifact_verification_parent", - "artifact_verification_jobs", - ["parent_verification_job_id"], - ) - op.create_index( - "ix_artifact_verification_jobs_parent_verification_job_id", - "artifact_verification_jobs", - ["parent_verification_job_id"], - ) - op.create_index( - "uq_artifact_verification_initial_origin", - "artifact_verification_jobs", - ["originating_put_attempt_id"], - unique=True, - postgresql_where=sa.text("parent_verification_job_id is null"), - ) - - op.create_table( - "artifact_recovery_attempts", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("requester_actor_profile_id", sa.String(36), nullable=False), - sa.Column("requester_identity_link_id", sa.String(36), nullable=False), - sa.Column("authorization_request_id", sa.String(36), nullable=False), - sa.Column("authorization_correlation_id", sa.String(36), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=True), - sa.Column("submission_id", sa.String(36), nullable=True), - sa.Column("source_verification_job_id", sa.String(36), nullable=False), - sa.Column("retry_verification_job_id", sa.String(36), nullable=False), - sa.Column("parent_recovery_attempt_id", sa.String(36), nullable=True), - sa.Column("recovery_class", sa.String(40), nullable=False), - sa.Column("reason", sa.String(1000), nullable=False), - sa.Column("client_idempotency_key", sa.String(200), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("status", sa.String(20), nullable=False, server_default="requested"), - sa.Column("terminal_result_code", sa.String(40), nullable=True), - sa.Column("initiation_audit_event_id", sa.String(36), nullable=False), - sa.Column("terminal_audit_event_id", sa.String(36), nullable=True), - sa.Column("cas_version", sa.BigInteger(), nullable=False, server_default="0"), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now()), - sa.Column("terminal_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.func.now()), - sa.ForeignKeyConstraint( - ["requester_actor_profile_id"], ["actor_profiles.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["requester_identity_link_id"], ["actor_identity_links.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["task_id"], ["workstream_tasks.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["submission_id"], ["submissions.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["source_verification_job_id"], - ["artifact_verification_jobs.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint( - ["retry_verification_job_id"], - ["artifact_verification_jobs.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint( - ["parent_recovery_attempt_id"], - ["artifact_recovery_attempts.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint( - ["initiation_audit_event_id"], ["audit_events.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["terminal_audit_event_id"], ["audit_events.id"], ondelete="RESTRICT" - ), - sa.UniqueConstraint( - "requester_actor_profile_id", - "source_verification_job_id", - "recovery_class", - "client_idempotency_key", - name="uq_artifact_recovery_idempotency", - ), - sa.UniqueConstraint( - "source_verification_job_id", name="uq_artifact_recovery_source_job" - ), - sa.UniqueConstraint( - "retry_verification_job_id", name="uq_artifact_recovery_retry_job" - ), - sa.CheckConstraint( - "source_verification_job_id <> retry_verification_job_id", name="distinct_jobs" - ), - sa.CheckConstraint("recovery_class = 'provider_observation'", name="recovery_class"), - sa.CheckConstraint("status in ('requested','succeeded','failed')", name="status"), - sa.CheckConstraint("request_digest ~ '^sha256:[0-9a-f]{64}$'", name="request_digest"), - sa.CheckConstraint("cas_version >= 0", name="cas_nonnegative"), - sa.CheckConstraint( - "(status='requested' and terminal_result_code is null and terminal_at is null " - "and terminal_audit_event_id is null) or " - "(status in ('succeeded','failed') and terminal_result_code is not null " - "and terminal_at is not null and terminal_audit_event_id is not null)", - name="terminal_shape", - ), - sa.CheckConstraint( - "(status='succeeded' and terminal_result_code='verified') or " - "(status='failed' and terminal_result_code in " - "('provider_unavailable','missing','integrity_mismatch','conflict')) or " - "status='requested'", - name="terminal_result", - ), - ) - for column in ( - "requester_actor_profile_id", - "project_id", - "task_id", - "submission_id", - "parent_recovery_attempt_id", - ): - op.create_index( - f"ix_artifact_recovery_attempts_{column}", - "artifact_recovery_attempts", - [column], - ) - op.execute( - """ - create function validate_artifact_recovery_attempt() returns trigger - language plpgsql as $$ - declare - source_row artifact_verification_jobs%rowtype; - retry_row artifact_verification_jobs%rowtype; - expected_parent text; - begin - if tg_op = 'DELETE' then - raise exception 'artifact recovery attempts are append-only' using errcode='55000'; - end if; - if tg_op = 'UPDATE' and ( - to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', - 'terminal_at','cas_version','updated_at'] - is distinct from - to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', - 'terminal_at','cas_version','updated_at'] - ) then - raise exception 'artifact recovery identity is immutable' using errcode='55000'; - end if; - select * into source_row from artifact_verification_jobs - where id=new.source_verification_job_id; - select * into retry_row from artifact_verification_jobs - where id=new.retry_verification_job_id; - if source_row.id is null or retry_row.id is null - or source_row.status <> 'provider_unavailable' - or source_row.terminal_result_code <> 'provider_unavailable' - or source_row.terminal_at is null or source_row.next_run_at is not null - or source_row.executor_id is not null - or source_row.attempt_count < source_row.maximum_attempts - or retry_row.parent_verification_job_id <> source_row.id - or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id - or retry_row.replica_id <> source_row.replica_id then - raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; - end if; - if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) - or (tg_op = 'UPDATE' and ( - retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null - )) then - raise exception 'invalid artifact recovery retry state' using errcode='23514'; - end if; - select id into expected_parent from artifact_recovery_attempts - where retry_verification_job_id=source_row.id; - if new.parent_recovery_attempt_id is distinct from expected_parent then - raise exception 'invalid artifact recovery parent chain' using errcode='23514'; - end if; - if not exists ( - select 1 from audit_events where id=new.initiation_audit_event_id - and entity_type='artifact_recovery_attempt' and entity_id=new.id - and event_type='ArtifactRecoveryInitiated' - ) then - raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; - end if; - if new.terminal_audit_event_id is not null and not exists ( - select 1 from audit_events where id=new.terminal_audit_event_id - and entity_type='artifact_recovery_attempt' and entity_id=new.id - and event_type='ArtifactRecoveryCompleted' - ) then - raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - """ - create trigger artifact_recovery_attempt_custody - before insert or update or delete on artifact_recovery_attempts - for each row execute function validate_artifact_recovery_attempt() - """ - ) - op.execute( - """ - create function validate_artifact_verification_lineage() returns trigger - language plpgsql as $$ - begin - if ( - old.parent_verification_job_id is not null - or exists( - select 1 from artifact_recovery_attempts - where source_verification_job_id = old.id - or retry_verification_job_id = old.id - ) - ) and ( - old.originating_put_attempt_id is distinct from new.originating_put_attempt_id - or old.replica_id is distinct from new.replica_id - or old.parent_verification_job_id is distinct from new.parent_verification_job_id - ) then - raise exception 'artifact verification lineage is immutable' using errcode='55000'; - end if; - return new; - end $$ - """ - ) - op.execute( - """ - create trigger artifact_verification_lineage_custody - before update on artifact_verification_jobs - for each row execute function validate_artifact_verification_lineage() - """ - ) - - -def downgrade() -> None: - """Remove recovery only when no durable recovery lineage exists.""" - bind = op.get_bind() - if bind.execute(sa.text("select exists(select 1 from artifact_recovery_attempts)")).scalar(): - raise RuntimeError("cannot downgrade populated artifact recovery attempts") - op.execute( - "drop trigger artifact_verification_lineage_custody on artifact_verification_jobs" - ) - op.execute("drop function validate_artifact_verification_lineage()") - op.execute("drop trigger artifact_recovery_attempt_custody on artifact_recovery_attempts") - op.execute("drop function validate_artifact_recovery_attempt()") - op.drop_table("artifact_recovery_attempts") - op.drop_index( - "uq_artifact_verification_initial_origin", table_name="artifact_verification_jobs" - ) - op.drop_index( - "ix_artifact_verification_jobs_parent_verification_job_id", - table_name="artifact_verification_jobs", - ) - op.drop_constraint( - "uq_artifact_verification_parent", "artifact_verification_jobs", type_="unique" - ) - op.drop_constraint( - "fk_artifact_verification_parent", "artifact_verification_jobs", type_="foreignkey" - ) - op.drop_column("artifact_verification_jobs", "parent_verification_job_id") - op.create_unique_constraint( - "uq_artifact_verification_origin", - "artifact_verification_jobs", - ["originating_put_attempt_id"], - ) diff --git a/backend/alembic/versions/0033_authorization_read_rate_control.py b/backend/alembic/versions/0033_authorization_read_rate_control.py deleted file mode 100644 index 02643669c..000000000 --- a/backend/alembic/versions/0033_authorization_read_rate_control.py +++ /dev/null @@ -1,75 +0,0 @@ -"""add durable authorization-read rate-control scope - -Revision ID: 0033_authorization_read_rate -Revises: 0032_artifact_recovery -Create Date: 2026-07-21 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0033_authorization_read_rate" -down_revision = "0032_artifact_recovery" -branch_labels = depends_on = None - -_TABLE = "api_rate_control_counters" -_CONSTRAINT = "ck_api_rate_control_counters_scope_token" -_OLD_SCOPE_SQL = "control_scope in ('first_access', 'admin_mutation')" -_NEW_SCOPE_SQL = ( - "control_scope in ('first_access', 'admin_mutation', 'authorization_read')" -) -_OLD_SCOPE_EXPRESSION = ( - "((control_scope)::text = ANY ((ARRAY['first_access'::character varying, " - "'admin_mutation'::character varying])::text[]))" -) -_NEW_SCOPE_EXPRESSION = ( - "((control_scope)::text = ANY ((ARRAY['first_access'::character varying, " - "'admin_mutation'::character varying, 'authorization_read'::character varying])::text[]))" -) - - -def _require_scope_constraint(expected: str) -> None: - definition = op.get_bind().execute( - sa.text( - "select pg_get_expr(conbin,conrelid) from pg_constraint " - "where conrelid=cast(:table as regclass) and conname=:constraint" - ), - {"table": _TABLE, "constraint": _CONSTRAINT}, - ).scalar_one_or_none() - if definition != expected: - raise RuntimeError("unexpected API rate-control scope constraint") - - -def _replace_scope_constraint(definition: str) -> None: - op.execute(sa.text(f"alter table {_TABLE} drop constraint {_CONSTRAINT}")) - op.execute( - sa.text( - f"alter table {_TABLE} add constraint {_CONSTRAINT} check ({definition})" - ) - ) - - -def upgrade() -> None: - """Add one closed scope while preserving all existing counters.""" - op.execute(sa.text(f"lock table {_TABLE} in access exclusive mode")) - _require_scope_constraint(_OLD_SCOPE_EXPRESSION) - _replace_scope_constraint(_NEW_SCOPE_SQL) - - -def downgrade() -> None: - """Restore the prior scope only when no authorization-read counters exist.""" - bind = op.get_bind() - bind.execute(sa.text(f"lock table {_TABLE} in access exclusive mode")) - _require_scope_constraint(_NEW_SCOPE_EXPRESSION) - has_rows = bind.execute( - sa.text( - f"select exists(select 1 from {_TABLE} " - "where control_scope='authorization_read')" - ) - ).scalar_one() - if has_rows: - raise RuntimeError("cannot downgrade live authorization-read rate controls") - _replace_scope_constraint(_OLD_SCOPE_SQL) diff --git a/backend/alembic/versions/0034_project_role_issue_evidence.py b/backend/alembic/versions/0034_project_role_issue_evidence.py deleted file mode 100644 index 05088b9ec..000000000 --- a/backend/alembic/versions/0034_project_role_issue_evidence.py +++ /dev/null @@ -1,490 +0,0 @@ -"""admit the exact two-event project-role issue evidence envelope - -Revision ID: 0034_project_role_issue_evidence -Revises: 0033_authorization_read_rate -Create Date: 2026-07-24 -""" - -from __future__ import annotations - -import hashlib -import re - -from alembic import op -import sqlalchemy as sa - - -revision = "0034_project_role_issue_evidence" -down_revision = "0033_authorization_read_rate" -branch_labels = depends_on = None - -_PREDECESSOR_GUARD_SHA256 = "fe4d302e7405e79d4ca0f5731275f589f2680da5d4ebf033f98d028214671498" -_PREDECESSOR_LINKED_SHA256 = "a05288dc0192e2f984a6e1592d086879bbe32c20cfba0d284a2c13fce6c7e506" -_PREDECESSOR_FACTS_SHA256 = "ee5e1bd8d2958ff60238e9200acd7ba226bf64f191f515881dc5741c7f36d9bb" -_FORWARD_GUARD_SHA256 = "4ff567e26aa28be36f28e4908039d0d4c0e9d1d8e6226dfb4d28c8b0f1523a56" -_FORWARD_LINKED_SHA256 = "e5d9dc01a65c3865267c89e79e6eedcf270ab5c559d424a593c939e3693f154e" -_FORWARD_FACTS_SHA256 = "202354d75f8fc6b60e8f3bedfd8eafcf75aa24f682c1ef4762abf81fa74a1e5d" -_FACT_CONSTRAINT_SHA256 = "c6f99a1a9ef6cc59fe52af6a117a5265cda8daa9c7fa084ed2ff8bdad851ae2f" -_PREDECESSOR_PRIVACY_SHA256 = "b76a5df89d66215f6aaba6d03ee0322497cfba99c3072404d7b06f742e71b56e" -_FORWARD_PRIVACY_SHA256 = "c02c0edccf921bbacbeff81524deb6d57cad6273784029d647c1df02ab18ed26" -_TRIGGER_SHA256 = { - "authority_idempotency_guard": "84da74f8180fd5023b7364840b659a3fe781752c937c12dea6b2411eba5d7874", - "audit_events_validate_idempotency": "524d24197c96ad05cbaecc867a4e5cdd2ee9e33e3a60380466e280a253a397bf", -} - -_RESOURCE_MARKERS = ( - ("'project'::character varying, 'project_role_grant'::character varying", "'project'::character varying, 'qualification_snapshot'::character varying, 'project_role_grant'::character varying"), - ("('project'::character varying)::text, ('project_role_grant'::character varying)::text", "('project'::character varying)::text, ('qualification_snapshot'::character varying)::text, ('project_role_grant'::character varying)::text"), -) - -_LINKED_VALID_MARKER = ( - "'ProjectRoleGrantIssued','ProjectRoleGrantRevoked'," -) -_LINKED_VALID_FORWARD = ( - "'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued'," - "'ProjectRoleGrantRevoked'," -) -_LINKED_BRANCH_MARKER = " if new.event_type='AuthorityInvalidationRequested' then" -_LINKED_ISSUE_BRANCH = """ if new.event_type='ProjectRoleQualificationSnapshotCaptured' then - if record_row.operation <> 'project_role_grant.issue' - or new.resource_type <> 'qualification_snapshot' - or new.entity_type <> 'qualification_snapshot' - or new.entity_id <> new.resource_id - or new.target_ref_kind is distinct from 'qualification_snapshot' - or new.target_ref_id is distinct from new.resource_id - or new.invalidation_cause_event_id is not null - or new.invalidation_target_kind is not null - or new.invalidation_target_ref is not null - or exists(select 1 from audit_events where idempotency_reference=record_row.id) then - raise exception 'invalid project role qualification evidence' using errcode='23514'; - end if; - elsif record_row.operation='project_role_grant.issue' - and new.event_type='ProjectRoleGrantIssued' then - select * into cause_row from audit_events - where idempotency_reference=record_row.id - and event_type='ProjectRoleQualificationSnapshotCaptured'; - if not found - or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 - or cause_row.request_id is distinct from new.request_id - or cause_row.correlation_id is distinct from new.correlation_id - or cause_row.actor_ref_kind is distinct from new.actor_ref_kind - or cause_row.actor_id is distinct from new.actor_id - or cause_row.permission_id is distinct from new.permission_id - or cause_row.project_id is distinct from new.project_id - or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind - or cause_row.target_actor_ref is distinct from new.target_actor_ref - or cause_row.matched_grant_id is distinct from new.matched_grant_id - or new.resource_type <> 'project_role_grant' - or new.entity_type <> 'project_role_grant' - or new.entity_id <> new.resource_id - or new.target_ref_kind is distinct from 'project_role_grant' - or new.target_ref_id is distinct from new.resource_id - or new.invalidation_cause_event_id is not null - or new.invalidation_target_kind is not null - or new.invalidation_target_ref is not null then - raise exception 'invalid project role issue evidence' using errcode='23514'; - end if; - elsif record_row.operation='project_role_grant.revoke' - and new.event_type='AuthorityInvalidationRequested' then - select * into cause_row from audit_events where id=new.invalidation_cause_event_id; - if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' - or cause_row.idempotency_reference is distinct from record_row.id - or cause_row.actor_ref_kind is distinct from new.actor_ref_kind - or cause_row.actor_id is distinct from new.actor_id - or cause_row.permission_id is distinct from new.permission_id - or cause_row.request_id is distinct from new.request_id - or cause_row.correlation_id is distinct from new.correlation_id - or cause_row.project_id is distinct from new.project_id - or cause_row.target_actor_ref_kind is distinct from 'actor_profile' - or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind - or cause_row.target_actor_ref is distinct from new.target_actor_ref - or cause_row.resource_type <> 'project_role_grant' - or cause_row.target_ref_kind <> 'project_role_grant' - or cause_row.target_ref_id is distinct from cause_row.resource_id - or new.resource_type <> 'project_role_grant' - or new.resource_id is distinct from cause_row.resource_id - or new.target_ref_kind is distinct from 'project_role_grant' - or new.target_ref_id is distinct from cause_row.resource_id - or new.invalidation_target_kind <> 'project_role_grant' - or new.invalidation_target_ref is distinct from cause_row.resource_id - or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id - or new.before_facts::jsonb->>'effective' <> 'true' - or new.after_facts::jsonb->>'effective' <> 'false' - or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') - or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' - or new.before_facts::jsonb->>'scope_type' <> 'project' - or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id - or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' - or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' - or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') - or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') - or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then - raise exception 'invalid project role revoke invalidation' using errcode='23514'; - end if; - elsif record_row.operation='project_role_grant.issue' - and new.event_type='AuthorityInvalidationRequested' then - raise exception 'project role issue forbids invalidation' using errcode='23514'; - elsif new.event_type='AuthorityInvalidationRequested' then""" - -_FACTS_TOP = """ if (before_state is not null and not authority_facts_are_safe(before_state)) - or (after_state is not null and not authority_facts_are_safe(after_state)) then - return false; - end if;""" -_FACTS_TOP_FORWARD = """ if not (event_name='AuthorityInvalidationRequested' - and before_state is not null - and after_state is not null - and coalesce(before_state::jsonb ? 'future_obligation', false) - and coalesce(after_state::jsonb ? 'future_obligation', false)) - and ((before_state is not null and not authority_facts_are_safe(before_state)) - or (after_state is not null and not authority_facts_are_safe(after_state))) then - return false; - end if;""" -_FACTS_BRANCH = """ when 'AuthorityInvalidationRequested' then return (before_state::jsonb = '{"effective": true}'::jsonb and after_state::jsonb = '{"effective": false}'::jsonb) or (before_state::jsonb = '{"effective": false}'::jsonb and after_state::jsonb = '{"effective": true}'::jsonb);""" -_FACTS_BRANCH_FORWARD = """ when 'AuthorityInvalidationRequested' then return - (before_state::jsonb = '{"effective": true}'::jsonb - and after_state::jsonb = '{"effective": false}'::jsonb) - or (before_state::jsonb = '{"effective": false}'::jsonb - and after_state::jsonb = '{"effective": true}'::jsonb) - or ( - jsonb_typeof(before_state::jsonb)='object' - and jsonb_typeof(after_state::jsonb)='object' - and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 - and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 - and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] - and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] - and before_state::jsonb->'effective'='true'::jsonb - and after_state::jsonb->'effective'='false'::jsonb - and jsonb_typeof(before_state::jsonb->'role')='string' - and jsonb_typeof(before_state::jsonb->'scope_type')='string' - and jsonb_typeof(before_state::jsonb->'scope_id')='string' - and jsonb_typeof(before_state::jsonb->'future_obligation')='string' - and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') - and before_state::jsonb->>'scope_type'='project' - and before_state::jsonb->>'scope_id'=envelope_project_id - and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') - or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') - or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) - );""" - -_PREDECESSOR_GUARD = """ -create or replace function guard_authority_idempotency_record() returns trigger -language plpgsql as $$ - declare success_count integer; invalidation_count integer; success_id text; - success_row audit_events%rowtype; - begin - if tg_op = 'INSERT' then - if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; - new.created_at := statement_timestamp(); new.committed_at := null; return new; - elsif tg_op = 'DELETE' then - raise exception 'authority idempotency records are immutable' using errcode='55000'; - end if; - if old.status <> 'pending' or new.status <> 'committed' - or (new.id, new.idempotency_key, new.actor_ref_kind, new.actor_ref, - new.operation, new.request_digest, new.created_at) - is distinct from - (old.id, old.idempotency_key, old.actor_ref_kind, old.actor_ref, - old.operation, old.request_digest, old.created_at) then - raise exception 'invalid authority idempotency transition' using errcode='23514'; - end if; - select count(*), min(id) into success_count, success_id - from audit_events where event_domain='authority' and idempotency_reference=new.id - and event_type <> 'AuthorityInvalidationRequested'; - select count(*) into invalidation_count from audit_events - where event_domain='authority' and idempotency_reference=new.id - and event_type='AuthorityInvalidationRequested'; - if success_count <> 1 or invalidation_count <> 1 then - raise exception 'authority evidence pair required' using errcode='23514'; - end if; - select * into success_row from audit_events where id=success_id; - if success_row.resource_type <> new.response_resource_type - or success_row.resource_id <> new.response_resource_id::text then - raise exception 'authority response does not match evidence' using errcode='23514'; - end if; - new.committed_at := statement_timestamp(); return new; - end $$ -""" - -_FORWARD_GUARD = """ -create or replace function guard_authority_idempotency_record() returns trigger -language plpgsql as $$ -declare success_count integer; invalidation_count integer; success_id text; - qualification_row audit_events%rowtype; success_row audit_events%rowtype; - grant_row project_role_grants%rowtype; - snapshot_row project_role_qualification_snapshots%rowtype; -begin - if tg_op = 'INSERT' then - if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; - new.created_at := statement_timestamp(); new.committed_at := null; return new; - elsif tg_op = 'DELETE' then - raise exception 'authority idempotency records are immutable' using errcode='55000'; - end if; - if old.status <> 'pending' or new.status <> 'committed' - or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, - new.request_digest,new.created_at) is distinct from - (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, - old.request_digest,old.created_at) then - raise exception 'invalid authority idempotency transition' using errcode='23514'; - end if; - select count(*), min(id) into success_count, success_id from audit_events - where event_domain='authority' and idempotency_reference=new.id - and event_type <> 'AuthorityInvalidationRequested'; - select count(*) into invalidation_count from audit_events - where event_domain='authority' and idempotency_reference=new.id - and event_type='AuthorityInvalidationRequested'; - if new.operation='project_role_grant.issue' then - if success_count <> 2 or invalidation_count <> 0 - or (select count(*) from audit_events where idempotency_reference=new.id - and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 - or (select count(*) from audit_events where idempotency_reference=new.id - and event_type='ProjectRoleGrantIssued') <> 1 then - raise exception 'project role issue evidence pair required' using errcode='23514'; - end if; - select * into qualification_row from audit_events where idempotency_reference=new.id - and event_type='ProjectRoleQualificationSnapshotCaptured'; - select * into success_row from audit_events where idempotency_reference=new.id - and event_type='ProjectRoleGrantIssued'; - select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; - select * into snapshot_row from project_role_qualification_snapshots - where id=qualification_row.resource_id::uuid; - if not found or grant_row.id is null or snapshot_row.id is null - or grant_row.qualification_snapshot_id <> snapshot_row.id - or grant_row.project_id <> snapshot_row.project_id - or grant_row.actor_profile_id <> snapshot_row.actor_profile_id - or grant_row.role <> snapshot_row.requested_role - or qualification_row.project_id is distinct from grant_row.project_id - or success_row.project_id is distinct from grant_row.project_id - or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id - or success_row.target_actor_ref is distinct from grant_row.actor_profile_id - or qualification_row.request_id is distinct from success_row.request_id - or qualification_row.correlation_id is distinct from success_row.correlation_id - or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind - or qualification_row.actor_id is distinct from success_row.actor_id - or qualification_row.permission_id is distinct from success_row.permission_id - or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then - raise exception 'project role issue evidence mismatch' using errcode='23514'; - end if; - else - if success_count <> 1 or invalidation_count <> 1 then - raise exception 'authority evidence pair required' using errcode='23514'; - end if; - select * into success_row from audit_events where id=success_id; - end if; - if success_row.resource_type <> new.response_resource_type - or success_row.resource_id <> new.response_resource_id::text then - raise exception 'authority response does not match evidence' using errcode='23514'; - end if; - new.committed_at := statement_timestamp(); return new; -end $$ -""" - - -def _definition(name: str) -> str: - return op.get_bind().execute( - sa.text("select pg_get_functiondef(cast(:name as regproc))"), {"name": name} - ).scalar_one() - - -def _digest(value: str) -> str: - return hashlib.sha256(value.encode()).hexdigest() - - -def _assert_triggers() -> None: - expected = { - "authority_idempotency_guard": ( - "authority_idempotency_records", "guard_authority_idempotency_record" - ), - "audit_events_validate_idempotency": ("audit_events", "validate_linked_authority_event"), - } - rows = op.get_bind().execute(sa.text(""" - select t.tgname,c.relname,p.proname,t.tgenabled,t.tgdeferrable,t.tginitdeferred, - pg_get_triggerdef(t.oid,true) definition - from pg_trigger t join pg_class c on c.oid=t.tgrelid - join pg_proc p on p.oid=t.tgfoid where t.tgname in - ('authority_idempotency_guard','audit_events_validate_idempotency') - """)).mappings().all() - if len(rows) != 2: - raise RuntimeError("unexpected authority evidence trigger inventory") - for row in rows: - table, function = expected[row["tgname"]] - if ( - row["relname"] != table - or row["proname"] != function - or row["tgenabled"] not in ("O", b"O") - or row["tgdeferrable"] not in (False, "f") - or row["tginitdeferred"] not in (False, "f") - or _digest(row["definition"]) != _TRIGGER_SHA256[row["tgname"]] - ): - raise RuntimeError(f"unexpected authority evidence trigger binding: {dict(row)!r}") - - -def _assert_fact_constraint() -> None: - row = op.get_bind().execute(sa.text(""" - select c.relname table_name,q.convalidated,pg_get_constraintdef(q.oid) definition - from pg_constraint q join pg_class c on c.oid=q.conrelid - where q.conname='ck_audit_events_fact_bounds' - """)).mappings().one_or_none() - if ( - row is None - or row["table_name"] != "audit_events" - or not row["convalidated"] - or _digest(row["definition"]) != _FACT_CONSTRAINT_SHA256 - ): - raise RuntimeError("unexpected authority fact constraint") - - -def _privacy(*, add: bool) -> None: - bind = op.get_bind() - definition = bind.execute(sa.text(""" - select pg_get_constraintdef(oid) from pg_constraint - where conrelid='audit_events'::regclass - and conname='ck_audit_events_authority_privacy_bounds' - """)).scalar_one() - expected = _PREDECESSOR_PRIVACY_SHA256 if add else _FORWARD_PRIVACY_SHA256 - if _digest(definition) != expected: - raise RuntimeError("unexpected authority privacy constraint") - matches = [(old, new) for old, new in _RESOURCE_MARKERS if (new if not add else old) in definition] - if add: - matches = [(old, new) for old, new in matches if new not in definition] - if not matches: - raise RuntimeError("unexpected authority privacy constraint") - old, new = max(matches, key=lambda item: len(item[1])) - source, target = (old, new) if add else (new, old) - if definition.count(source) != 1: - raise RuntimeError("unexpected authority privacy constraint") - definition = definition.replace(source, target) - if not add: - # Rebuild the predecessor through its original IN/NOT IN expression form. - # Re-executing pg_get_constraintdef() directly produces a semantically equal - # but structurally different ANY/ALL tree and would not restore 0033 exactly. - definition = re.sub( - r"\('([^']+)'::character varying\)::text", - r"'\1'", - definition, - ) - definition = re.sub( - r"\(\((\w+)\)::text = ANY \(ARRAY\[([^]]+)\]\)\)", - r"\1 in (\2)", - definition, - ) - definition = re.sub( - r"\(\((\w+)\)::text <> ALL \(ARRAY\[([^]]+)\]\)\)", - r"\1 not in (\2)", - definition, - ) - op.execute( - "alter table audit_events drop constraint " - "ck_audit_events_authority_privacy_bounds" - ) - op.execute(f"alter table audit_events add constraint ck_audit_events_authority_privacy_bounds {definition}") - installed = bind.execute(sa.text(""" - select pg_get_constraintdef(oid) from pg_constraint - where conrelid='audit_events'::regclass - and conname='ck_audit_events_authority_privacy_bounds' - """)).scalar_one() - installed_expected = _FORWARD_PRIVACY_SHA256 if add else _PREDECESSOR_PRIVACY_SHA256 - if _digest(installed) != installed_expected: - raise RuntimeError("unexpected installed authority privacy constraint") - - -def _linked(*, add: bool) -> None: - linked = _definition("validate_linked_authority_event") - if add: - if linked.count(_LINKED_VALID_MARKER) != 1 or linked.count(_LINKED_BRANCH_MARKER) != 1: - raise RuntimeError("unexpected linked authority validator definition") - linked = linked.replace(_LINKED_VALID_MARKER, _LINKED_VALID_FORWARD) - linked = linked.replace(_LINKED_BRANCH_MARKER, _LINKED_ISSUE_BRANCH) - else: - if linked.count(_LINKED_VALID_FORWARD) != 1 or linked.count(_LINKED_ISSUE_BRANCH) != 1: - raise RuntimeError("unexpected linked authority validator definition") - linked = linked.replace(_LINKED_VALID_FORWARD, _LINKED_VALID_MARKER) - linked = linked.replace(_LINKED_ISSUE_BRANCH, _LINKED_BRANCH_MARKER) - op.execute(linked) - - -def _facts(*, add: bool) -> None: - facts = _definition("authority_event_facts_are_safe") - old_top, new_top = (_FACTS_TOP, _FACTS_TOP_FORWARD) if add else (_FACTS_TOP_FORWARD, _FACTS_TOP) - old_branch, new_branch = ( - (_FACTS_BRANCH, _FACTS_BRANCH_FORWARD) - if add - else (_FACTS_BRANCH_FORWARD, _FACTS_BRANCH) - ) - if facts.count(old_top) != 1 or facts.count(old_branch) != 1: - raise RuntimeError("unexpected authority fact validator definition") - op.execute(facts.replace(old_top, new_top).replace(old_branch, new_branch)) - - -def _refuse_incompatible(*, downgrade: bool) -> None: - bind = op.get_bind() - if downgrade: - query = """select exists( - select 1 from authority_idempotency_records r - where r.operation='project_role_grant.issue' and - (r.status<>'pending' or r.response_resource_type is not null - or r.response_resource_id is not null or r.response_resource_version is not null - or r.response_http_status is not null or r.committed_at is not null - or exists(select 1 from audit_events e where e.idempotency_reference=r.id)) - union all select 1 from audit_events - where event_type='ProjectRoleQualificationSnapshotCaptured' - or (idempotency_reference is not null and event_type='ProjectRoleGrantIssued') - or (event_type='AuthorityInvalidationRequested' and - (before_facts::jsonb ? 'future_obligation' - or after_facts::jsonb ? 'future_obligation')))""" - else: - query = """select exists( - select 1 from authority_idempotency_records r - where r.operation='project_role_grant.issue' and - (r.status<>'pending' or r.response_resource_type is not null - or r.response_resource_id is not null or r.response_resource_version is not null - or r.response_http_status is not null or r.committed_at is not null - or exists(select 1 from audit_events e where e.idempotency_reference=r.id)) - union all select 1 from audit_events e where - e.event_type='ProjectRoleQualificationSnapshotCaptured' - or (e.idempotency_reference is not null and e.event_type='ProjectRoleGrantIssued' - and not exists(select 1 from authority_idempotency_records r - where r.id=e.idempotency_reference and r.operation='project_role_grant.issue')))""" - if bind.execute(sa.text(query)).scalar_one(): - raise RuntimeError("incompatible project-role issue evidence") - - -def upgrade() -> None: - bind = op.get_bind() - bind.execute(sa.text("lock table authority_idempotency_records in access exclusive mode")) - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - _assert_triggers() - _assert_fact_constraint() - # Frozen hashes make definition drift a hard failure; marker checks below remain a - # readable diagnostic across PostgreSQL formatting versions. - guard, linked = _definition("guard_authority_idempotency_record"), _definition("validate_linked_authority_event") - facts = _definition("authority_event_facts_are_safe") - if (_digest(guard) != _PREDECESSOR_GUARD_SHA256 - or _digest(linked) != _PREDECESSOR_LINKED_SHA256 - or _digest(facts) != _PREDECESSOR_FACTS_SHA256): - raise RuntimeError("unexpected predecessor authority evidence definition") - _refuse_incompatible(downgrade=False) - _privacy(add=True) - op.execute(_FORWARD_GUARD) - _linked(add=True) - _facts(add=True) - - -def downgrade() -> None: - bind = op.get_bind() - bind.execute(sa.text("lock table authority_idempotency_records in access exclusive mode")) - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - _assert_triggers() - _assert_fact_constraint() - guard = _definition("guard_authority_idempotency_record") - linked = _definition("validate_linked_authority_event") - facts = _definition("authority_event_facts_are_safe") - if ( - _digest(guard) != _FORWARD_GUARD_SHA256 - or _digest(linked) != _FORWARD_LINKED_SHA256 - or _digest(facts) != _FORWARD_FACTS_SHA256 - ): - raise RuntimeError("unexpected forward authority evidence definition") - _refuse_incompatible(downgrade=True) - _linked(add=False) - _facts(add=False) - op.execute(_PREDECESSOR_GUARD) - _privacy(add=False) diff --git a/backend/alembic/versions/0035_project_read_action_evidence.py b/backend/alembic/versions/0035_project_read_action_evidence.py deleted file mode 100644 index f269faf17..000000000 --- a/backend/alembic/versions/0035_project_read_action_evidence.py +++ /dev/null @@ -1,139 +0,0 @@ -"""register project-read permissions and action evidence - -Revision ID: 0035_project_read_evidence -Revises: 0034_project_role_issue_evidence -Create Date: 2026-07-26 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0035_project_read_evidence" -down_revision = "0034_project_role_issue_evidence" -branch_labels = depends_on = None - -_PERMISSIONS = ( - "project.setup_diagnostic.read", - "project.effective_policy.read", -) -_ACTIONS = ( - ("project.read", "project.read"), - ("actor.authorization_context.read", "actor.profile.read_self"), - ("project.setup_run.read", _PERMISSIONS[0]), - ("project.guide_sufficiency_report.list", _PERMISSIONS[0]), - ("project.guide_sufficiency_report.read", _PERMISSIONS[0]), - ("project.submission_artifact_policy.list", _PERMISSIONS[1]), - ("project.submission_artifact_policy.read", _PERMISSIONS[1]), - ("project.post_submit_checker_policy_setup.read", _PERMISSIONS[1]), - ("project.effective_submission_artifact_policy.read", _PERMISSIONS[1]), - ("project.pre_submit_checker_policy.read", _PERMISSIONS[1]), - ("project.active_guide.read", "project.read"), -) - - -def _definition(name: str) -> str: - return ( - op.get_bind() - .execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass and conname=:name" - ), - {"name": f"ck_audit_events_{name}"}, - ) - .scalar_one() - ) - - -def _replace(name: str, definition: str) -> None: - op.drop_constraint(name, "audit_events", type_="check") - op.execute(f"alter table audit_events add constraint ck_audit_events_{name} {definition}") - - -def _permission_tokens(*, add: bool) -> None: - marker = "('project.role_grant.manage'::character varying)::text" - addition = ", " + ", ".join( - f"('{permission}'::character varying)::text" for permission in _PERMISSIONS - ) - for name in ("authority_registries", "authority_privacy_bounds"): - definition = _definition(name) - if add: - if definition.count(marker) < 1 or any(value in definition for value in _PERMISSIONS): - raise RuntimeError(f"unexpected {name} permission registry definition") - definition = definition.replace(marker, marker + addition) - else: - if definition.count(addition) < 1: - raise RuntimeError(f"unexpected {name} permission registry definition") - definition = definition.replace(addition, "") - _replace(name, definition) - - -def _action_pairs(*, add: bool) -> None: - name = "authorization_action_evidence" - definition = _definition(name) - marker = ( - "(((action_id)::text = 'project_role_grant.revoke'::text) AND " - "((permission_id)::text = 'project.role_grant.manage'::text))" - ) - additions = " OR ".join( - f"(((action_id)::text = '{action}'::text) AND ((permission_id)::text = '{permission}'::text))" - for action, permission in _ACTIONS - ) - suffix = " OR " + additions - if add: - if definition.count(marker) != 2 or any(action in definition for action, _ in _ACTIONS): - raise RuntimeError("unexpected authorization action registry definition") - definition = definition.replace(marker, marker + suffix) - else: - if definition.count(suffix) != 2: - raise RuntimeError("unexpected authorization action registry definition") - definition = definition.replace(suffix, "") - _replace(name, definition) - - -def _action_permission_tokens(*, add: bool) -> None: - name = "authorization_action_evidence" - definition = _definition(name) - marker = "('review.queue.override'::character varying)::text" - addition = ", " + ", ".join( - f"('{permission}'::character varying)::text" for permission in _PERMISSIONS - ) - if add: - if definition.count(marker) != 1 or addition in definition: - raise RuntimeError("unexpected authorization permission registry definition") - definition = definition.replace(marker, marker + addition) - else: - if definition.count(addition) != 1: - raise RuntimeError("unexpected authorization permission registry definition") - definition = definition.replace(addition, "") - _replace(name, definition) - - -def upgrade() -> None: - """Add availability-neutral project-read registry parity.""" - _permission_tokens(add=True) - _action_pairs(add=True) - _action_permission_tokens(add=True) - - -def downgrade() -> None: - """Remove project-read parity only when no forward evidence exists.""" - bind = op.get_bind() - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - blocked = bind.execute( - sa.text( - "select exists(select 1 from audit_events where " - "action_id = any(:actions) or permission_id = any(:permissions) or " - "(target_ref_kind='permission_registry' and target_ref_id = any(:permissions)) or " - "(invalidation_target_kind='permission_registry' and invalidation_target_ref = any(:permissions)))" - ), - {"actions": [action for action, _ in _ACTIONS], "permissions": list(_PERMISSIONS)}, - ).scalar_one() - if blocked: - raise RuntimeError("cannot downgrade non-empty project-read action evidence") - _action_permission_tokens(add=False) - _action_pairs(add=False) - _permission_tokens(add=False) diff --git a/backend/alembic/versions/0036_art_auth_catalogue_reconciliation.py b/backend/alembic/versions/0036_art_auth_catalogue_reconciliation.py deleted file mode 100644 index cbe2418ff..000000000 --- a/backend/alembic/versions/0036_art_auth_catalogue_reconciliation.py +++ /dev/null @@ -1,196 +0,0 @@ -"""reconcile the complete ART authorization catalogue - -Revision ID: 0036_art_auth_catalogue -Revises: 0035_project_read_evidence -Create Date: 2026-07-27 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0036_art_auth_catalogue" -down_revision = "0035_project_read_evidence" -branch_labels = depends_on = None - -_REMOVED_PERMISSIONS = ( - "artifact.upload_session.create", - "artifact.upload_session.read", - "artifact.upload_item.write", - "artifact.upload_session.seal", - "artifact.upload_session.cancel", - "artifact.upload_session.expire", -) -_ADDED_PERMISSIONS = ("artifact.review_packet.materialize",) -_REMOVED_ACTIONS = tuple((value, value) for value in _REMOVED_PERMISSIONS) -_ADDED_ACTIONS = ( - ("artifact.submission_bundle.prepare", "submission.create"), - ("artifact.review_packet.materialize", "artifact.review_packet.materialize"), - ("artifact.review_evidence.binding.create", "artifact.binding.create"), -) - - -def _definition(name: str) -> str: - return ( - op.get_bind() - .execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass and conname=:name" - ), - {"name": f"ck_audit_events_{name}"}, - ) - .scalar_one() - ) - - -def _replace(name: str, definition: str) -> None: - op.drop_constraint(name, "audit_events", type_="check") - op.execute(f"alter table audit_events add constraint ck_audit_events_{name} {definition}") - - -def _permission_token(value: str) -> str: - return f"('{value}'::character varying)::text" - - -def _pair_token(action: str, permission: str) -> str: - return ( - f"(((action_id)::text = '{action}'::text) AND " - f"((permission_id)::text = '{permission}'::text))" - ) - - -def _rewrite_permission_registry(*, forward: bool) -> None: - remove = _REMOVED_PERMISSIONS if forward else _ADDED_PERMISSIONS - add = _ADDED_PERMISSIONS if forward else _REMOVED_PERMISSIONS - marker = _permission_token("artifact.binding.create") - for name in ("authority_registries", "authority_privacy_bounds"): - definition = _definition(name) - for value in remove: - token = _permission_token(value) - if definition.count(token) < 1: - raise RuntimeError(f"unexpected {name} removed permission definition") - definition = definition.replace(", " + token, "") - if token in definition: - raise RuntimeError(f"unexpected {name} removed permission definition") - additions = ", ".join(_permission_token(value) for value in add) - if definition.count(marker) < 1 or any( - _permission_token(value) in definition for value in add - ): - raise RuntimeError(f"unexpected {name} added permission definition") - replacement = marker + ", " + additions if forward else additions + ", " + marker - definition = definition.replace(marker, replacement) - _replace(name, definition) - - -def _rewrite_action_registry(*, forward: bool) -> None: - remove = _REMOVED_ACTIONS if forward else _ADDED_ACTIONS - add = _ADDED_ACTIONS if forward else _REMOVED_ACTIONS - name = "authorization_action_evidence" - definition = _definition(name) - for action, permission in remove: - token = _pair_token(action, permission) - if definition.count(token) != 2: - raise RuntimeError("unexpected removed authorization action definition") - definition = definition.replace(" OR " + token, "") - if token in definition: - raise RuntimeError("unexpected removed authorization action definition") - marker = _pair_token( - "artifact.guide_source.ingest" if forward else "artifact.guide_source.read", - "artifact.guide_source.ingest" if forward else "artifact.guide_source.read", - ) - additions = " OR " + " OR ".join(_pair_token(*pair) for pair in add) - if definition.count(marker) != 2 or any(_pair_token(*pair) in definition for pair in add): - raise RuntimeError("unexpected added authorization action definition") - definition = definition.replace(marker, marker + additions) - _replace(name, definition) - - -def _rewrite_action_permission_registry(*, forward: bool) -> None: - remove = _REMOVED_PERMISSIONS if forward else _ADDED_PERMISSIONS - add = _ADDED_PERMISSIONS if forward else _REMOVED_PERMISSIONS - name = "authorization_action_evidence" - definition = _definition(name) - for value in remove: - token = _permission_token(value) - if definition.count(token) != 1: - raise RuntimeError("unexpected removed action permission definition") - definition = definition.replace(", " + token, "") - if token in definition: - raise RuntimeError("unexpected removed action permission definition") - marker = _permission_token("artifact.binding.create") - additions = ", ".join(_permission_token(value) for value in add) - if definition.count(marker) != 1 or any( - _permission_token(value) in definition for value in add - ): - raise RuntimeError("unexpected added action permission definition") - replacement = marker + ", " + additions if forward else additions + ", " + marker - definition = definition.replace(marker, replacement) - _replace(name, definition) - - -def _lock_evidence() -> None: - bind = op.get_bind() - bind.execute(sa.text("lock table authority_idempotency_records in share row exclusive mode")) - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - - -def _evidence_predicate(*, prefix: str, action_bind: str, permission_bind: str) -> str: - return ( - f"{prefix}action_id = any(:{action_bind}) or " - f"{prefix}permission_id = any(:{permission_bind}) or " - f"({prefix}target_ref_kind='permission_registry' and " - f"{prefix}target_ref_id = any(:{permission_bind})) or " - f"({prefix}invalidation_target_kind='permission_registry' and " - f"{prefix}invalidation_target_ref = any(:{permission_bind}))" - ) - - -def _has_evidence(actions: tuple[str, ...], permissions: tuple[str, ...]) -> bool: - direct = _evidence_predicate(prefix="", action_bind="actions", permission_bind="permissions") - linked = _evidence_predicate( - prefix="event.", - action_bind="linked_actions", - permission_bind="linked_permissions", - ) - return bool( - op.get_bind() - .execute( - sa.text( - "select exists(select 1 from audit_events where " - f"{direct}) or " - "exists(select 1 from authority_idempotency_records record " - "join audit_events event on event.idempotency_reference=record.id " - f"where {linked})" - ), - { - "actions": list(actions), - "permissions": list(permissions), - "linked_actions": list(actions), - "linked_permissions": list(permissions), - }, - ) - .scalar_one() - ) - - -def upgrade() -> None: - """Replace obsolete upload authority with planned bundle/review authority.""" - _lock_evidence() - if _has_evidence(tuple(action for action, _ in _REMOVED_ACTIONS), _REMOVED_PERMISSIONS): - raise RuntimeError("cannot remove non-empty obsolete artifact authority evidence") - _rewrite_permission_registry(forward=True) - _rewrite_action_registry(forward=True) - _rewrite_action_permission_registry(forward=True) - - -def downgrade() -> None: - """Restore the prior catalogue only when new ART authority has no evidence.""" - _lock_evidence() - if _has_evidence(tuple(action for action, _ in _ADDED_ACTIONS), _ADDED_PERMISSIONS): - raise RuntimeError("cannot downgrade non-empty ART authorization evidence") - _rewrite_action_permission_registry(forward=False) - _rewrite_action_registry(forward=False) - _rewrite_permission_registry(forward=False) diff --git a/backend/alembic/versions/0037_artifact_authorization_context_evidence.py b/backend/alembic/versions/0037_artifact_authorization_context_evidence.py deleted file mode 100644 index ba09f637a..000000000 --- a/backend/alembic/versions/0037_artifact_authorization_context_evidence.py +++ /dev/null @@ -1,99 +0,0 @@ -"""bind ART authorization evidence to its exact resource context - -Revision ID: 0037_art_auth_context_evidence -Revises: 0036_art_auth_catalogue -Create Date: 2026-07-27 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0037_art_auth_context_evidence" -down_revision = "0036_art_auth_catalogue" -branch_labels = depends_on = None - -_OLD_KEYS = """ 'scope_type', 'scope_id', 'effective', 'allowed' -""" -_NEW_KEYS = """ 'scope_type', 'scope_id', 'effective', 'allowed', - 'resource_context_digest' -""" -_OLD_ALLOWED_CASE = """ when 'allowed' then json_typeof(item.value) <> 'boolean' - else true -""" -_NEW_ALLOWED_CASE = """ when 'allowed' then json_typeof(item.value) <> 'boolean' - when 'resource_context_digest' then (item.value #>> '{}') !~ - '^sha256:[0-9a-f]{64}$' - else true -""" -_OLD_ALLOWED_BRANCH = """ when 'SensitiveAuthorizationAllowed' then return before_state is null and after_state::jsonb='{"allowed": true}'::jsonb; - when 'SensitiveAuthorizationDenied' then return before_state is null and after_state::jsonb='{"allowed": false}'::jsonb; -""" -_NEW_ALLOWED_BRANCH = """ when 'SensitiveAuthorizationAllowed' then - return before_state is null and ( - after_state::jsonb = '{"allowed": true}'::jsonb or ( - after_state::jsonb->'allowed' = 'true'::jsonb - and after_state::jsonb ? 'resource_context_digest' - and (select count(*) from json_each(after_state)) = 2 - ) - ); - when 'SensitiveAuthorizationDenied' then - return before_state is null and ( - after_state::jsonb = '{"allowed": false}'::jsonb or ( - after_state::jsonb->'allowed' = 'false'::jsonb - and after_state::jsonb ? 'resource_context_digest' - and (select count(*) from json_each(after_state)) = 2 - ) - ); -""" - - -def _definition(signature: str) -> str: - value = op.get_bind().execute( - sa.text("select pg_get_functiondef(to_regprocedure(:signature))"), - {"signature": signature}, - ).scalar_one_or_none() - if not isinstance(value, str): - raise RuntimeError("required authority evidence function is unavailable") - return value - - -def _replace_once(definition: str, old: str, new: str) -> str: - if definition.count(old) != 1: - raise RuntimeError("unexpected authority evidence function definition") - return definition.replace(old, new) - - -def _replace(*, forward: bool) -> None: - facts = _definition("authority_facts_are_safe(json)") - events = _definition("authority_event_facts_are_safe(text,json,json,text)") - if forward: - facts = _replace_once(facts, _OLD_KEYS, _NEW_KEYS) - facts = _replace_once(facts, _OLD_ALLOWED_CASE, _NEW_ALLOWED_CASE) - events = _replace_once(events, _OLD_ALLOWED_BRANCH, _NEW_ALLOWED_BRANCH) - else: - facts = _replace_once(facts, _NEW_KEYS, _OLD_KEYS) - facts = _replace_once(facts, _NEW_ALLOWED_CASE, _OLD_ALLOWED_CASE) - events = _replace_once(events, _NEW_ALLOWED_BRANCH, _OLD_ALLOWED_BRANCH) - op.execute(facts) - op.execute(events) - - -def upgrade() -> None: - op.execute("lock table audit_events in access exclusive mode") - _replace(forward=True) - - -def downgrade() -> None: - op.execute("lock table audit_events in access exclusive mode") - exists = op.get_bind().execute( - sa.text( - "select exists(select 1 from audit_events where event_domain='authority' " - "and after_facts::jsonb ? 'resource_context_digest')" - ) - ).scalar_one() - if exists: - raise RuntimeError("artifact authorization context evidence prevents downgrade") - _replace(forward=False) diff --git a/backend/alembic/versions/0038_guide_source_artifact_ingests.py b/backend/alembic/versions/0038_guide_source_artifact_ingests.py deleted file mode 100644 index 8ae852f34..000000000 --- a/backend/alembic/versions/0038_guide_source_artifact_ingests.py +++ /dev/null @@ -1,82 +0,0 @@ -"""add server-owned guide source artifact ingest facts - -Revision ID: 0038_guide_source_ingest -Revises: 0037_art_auth_context_evidence -Create Date: 2026-07-28 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0038_guide_source_ingest" -down_revision = "0037_art_auth_context_evidence" -branch_labels = depends_on = None - - -def upgrade() -> None: - op.create_table( - "guide_source_artifact_ingests", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("source_item_id", sa.String(length=36), nullable=False), - sa.Column("actor_profile_id", sa.String(length=36), nullable=False), - sa.Column("sha256", sa.String(length=71), nullable=False), - sa.Column("byte_count", sa.BigInteger(), nullable=False), - sa.Column("media_type", sa.String(length=255), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ), - sa.CheckConstraint( - "byte_count >= 0", - name="ck_guide_source_artifact_ingests_bytes", - ), - sa.CheckConstraint( - "sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="ck_guide_source_artifact_ingests_sha256", - ), - sa.ForeignKeyConstraint( - ["actor_profile_id"], - ["actor_profiles.id"], - ), - sa.ForeignKeyConstraint( - ["source_item_id"], - ["guide_source_snapshot_items.id"], - ), - sa.PrimaryKeyConstraint("id"), - sa.UniqueConstraint("source_item_id"), - ) - op.create_index( - op.f("ix_guide_source_artifact_ingests_actor_profile_id"), - "guide_source_artifact_ingests", - ["actor_profile_id"], - unique=False, - ) - op.create_index( - op.f("ix_guide_source_artifact_ingests_source_item_id"), - "guide_source_artifact_ingests", - ["source_item_id"], - unique=True, - ) - - -def downgrade() -> None: - bind = op.get_bind() - bind.execute(sa.text("lock table guide_source_artifact_ingests in access exclusive mode")) - if bind.execute( - sa.text("select exists(select 1 from guide_source_artifact_ingests)") - ).scalar_one(): - raise RuntimeError("cannot downgrade populated guide source artifact ingests") - op.drop_index( - op.f("ix_guide_source_artifact_ingests_source_item_id"), - table_name="guide_source_artifact_ingests", - ) - op.drop_index( - op.f("ix_guide_source_artifact_ingests_actor_profile_id"), - table_name="guide_source_artifact_ingests", - ) - op.drop_table("guide_source_artifact_ingests") diff --git a/backend/alembic/versions/0039_guide_source_bindings.py b/backend/alembic/versions/0039_guide_source_bindings.py deleted file mode 100644 index edc0d97ba..000000000 --- a/backend/alembic/versions/0039_guide_source_bindings.py +++ /dev/null @@ -1,215 +0,0 @@ -"""add exact guide source bindings and setup generations - -Revision ID: 0039_guide_source_bindings -Revises: 0038_guide_source_ingest -Create Date: 2026-07-29 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0039_guide_source_bindings" -down_revision = "0038_guide_source_ingest" -branch_labels = depends_on = None - - -def upgrade() -> None: - op.add_column( - "project_setup_runs", - sa.Column("setup_generation", sa.BigInteger(), nullable=True), - ) - op.execute( - sa.text( - """ - with generations as ( - select id, - row_number() over ( - partition by guide_id - order by created_at, id - ) as setup_generation - from project_setup_runs - ) - update project_setup_runs as runs - set setup_generation = generations.setup_generation - from generations - where runs.id = generations.id - """ - ) - ) - op.alter_column("project_setup_runs", "setup_generation", nullable=False) - op.create_check_constraint( - "ck_project_setup_runs_generation_positive", - "project_setup_runs", - "setup_generation > 0", - ) - op.create_unique_constraint( - "uq_project_setup_runs_guide_generation", - "project_setup_runs", - ["guide_id", "setup_generation"], - ) - op.create_unique_constraint( - "uq_project_setup_runs_exact_generation", - "project_setup_runs", - ["id", "project_id", "guide_id", "source_snapshot_id", "setup_generation"], - ) - op.create_unique_constraint( - "uq_guide_source_snapshots_exact_lineage", - "guide_source_snapshots", - ["id", "project_id", "guide_id"], - ) - op.create_unique_constraint( - "uq_guide_source_snapshot_items_exact_lineage", - "guide_source_snapshot_items", - ["id", "source_snapshot_id"], - ) - op.create_unique_constraint( - "uq_artifact_replicas_id_content", - "artifact_replicas", - ["id", "content_id"], - ) - - op.create_table( - "guide_source_artifact_bindings", - sa.Column("id", sa.String(length=36), nullable=False), - sa.Column("project_id", sa.String(length=36), nullable=False), - sa.Column("guide_id", sa.String(length=36), nullable=False), - sa.Column("source_snapshot_id", sa.String(length=36), nullable=False), - sa.Column("source_item_id", sa.String(length=36), nullable=False), - sa.Column("project_setup_run_id", sa.String(length=36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("content_id", sa.String(length=36), nullable=False), - sa.Column("verified_replica_id", sa.String(length=36), nullable=False), - sa.Column("logical_role", sa.String(length=100), nullable=False), - sa.Column("supersedes_binding_id", sa.String(length=36), nullable=True), - sa.Column("created_by_service", sa.String(length=100), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ), - sa.CheckConstraint( - "setup_generation > 0", - name="ck_guide_bindings_generation_positive", - ), - sa.CheckConstraint( - "logical_role = 'guide_source_original'", - name="ck_guide_bindings_role", - ), - sa.ForeignKeyConstraint( - ["content_id"], - ["artifact_contents.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint( - ["source_snapshot_id", "project_id", "guide_id"], - [ - "guide_source_snapshots.id", - "guide_source_snapshots.project_id", - "guide_source_snapshots.guide_id", - ], - name="fk_guide_bindings_exact_snapshot", - ), - sa.ForeignKeyConstraint( - ["source_item_id", "source_snapshot_id"], - ["guide_source_snapshot_items.id", "guide_source_snapshot_items.source_snapshot_id"], - name="fk_guide_bindings_exact_item", - ), - sa.ForeignKeyConstraint( - [ - "project_setup_run_id", - "project_id", - "guide_id", - "source_snapshot_id", - "setup_generation", - ], - [ - "project_setup_runs.id", - "project_setup_runs.project_id", - "project_setup_runs.guide_id", - "project_setup_runs.source_snapshot_id", - "project_setup_runs.setup_generation", - ], - name="fk_guide_bindings_exact_setup_generation", - ), - sa.ForeignKeyConstraint( - ["verified_replica_id", "content_id"], - ["artifact_replicas.id", "artifact_replicas.content_id"], - name="fk_guide_bindings_verified_replica_content", - ), - sa.ForeignKeyConstraint( - ["supersedes_binding_id"], - ["guide_source_artifact_bindings.id"], - ondelete="RESTRICT", - ), - sa.PrimaryKeyConstraint("id"), - sa.UniqueConstraint( - "source_item_id", - "setup_generation", - name="uq_guide_bindings_item_generation", - ), - sa.UniqueConstraint( - "supersedes_binding_id", - name="uq_guide_bindings_supersedes", - ), - ) - for column in ( - "project_id", - "guide_id", - "source_snapshot_id", - "source_item_id", - "project_setup_run_id", - "content_id", - "verified_replica_id", - "supersedes_binding_id", - ): - op.create_index( - op.f(f"ix_guide_source_artifact_bindings_{column}"), - "guide_source_artifact_bindings", - [column], - unique=False, - ) - - -def downgrade() -> None: - bind = op.get_bind() - bind.execute(sa.text("lock table guide_source_artifact_bindings in access exclusive mode")) - if bind.execute( - sa.text("select exists(select 1 from guide_source_artifact_bindings)") - ).scalar_one(): - raise RuntimeError("cannot downgrade populated guide source artifact bindings") - op.drop_table("guide_source_artifact_bindings") - op.drop_constraint( - "uq_artifact_replicas_id_content", - "artifact_replicas", - type_="unique", - ) - op.drop_constraint( - "uq_guide_source_snapshot_items_exact_lineage", - "guide_source_snapshot_items", - type_="unique", - ) - op.drop_constraint( - "uq_guide_source_snapshots_exact_lineage", - "guide_source_snapshots", - type_="unique", - ) - op.drop_constraint( - "uq_project_setup_runs_exact_generation", - "project_setup_runs", - type_="unique", - ) - op.drop_constraint( - "uq_project_setup_runs_guide_generation", - "project_setup_runs", - type_="unique", - ) - op.drop_constraint( - "ck_project_setup_runs_generation_positive", - "project_setup_runs", - type_="check", - ) - op.drop_column("project_setup_runs", "setup_generation") diff --git a/backend/alembic/versions/0040_guide_materialization.py b/backend/alembic/versions/0040_guide_materialization.py deleted file mode 100644 index 750a946af..000000000 --- a/backend/alembic/versions/0040_guide_materialization.py +++ /dev/null @@ -1,131 +0,0 @@ -"""add verified guide classifications and bounded incidents - -Revision ID: 0040_guide_materialization -Revises: 0039_guide_source_bindings -Create Date: 2026-07-29 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0040_guide_materialization" -down_revision = "0039_guide_source_bindings" -branch_labels = depends_on = None - - -def upgrade() -> None: - op.create_unique_constraint( - "uq_guide_bindings_exact_read", - "guide_source_artifact_bindings", - ["id", "content_id", "verified_replica_id", "setup_generation"], - ) - op.create_table( - "guide_source_format_classifications", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("binding_id", sa.String(36), nullable=False), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("verified_replica_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("sha256", sa.String(71), nullable=False), - sa.Column("byte_count", sa.BigInteger(), nullable=False), - sa.Column("media_type", sa.String(255), nullable=False), - sa.Column("detected_format", sa.String(40), nullable=False), - sa.Column("status", sa.String(40), nullable=False), - sa.Column("detector_name", sa.String(100), nullable=False), - sa.Column("detector_version", sa.String(40), nullable=False), - sa.Column("classification_facts", sa.JSON(), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ), - sa.ForeignKeyConstraint( - ["binding_id", "content_id", "verified_replica_id", "setup_generation"], - [ - "guide_source_artifact_bindings.id", - "guide_source_artifact_bindings.content_id", - "guide_source_artifact_bindings.verified_replica_id", - "guide_source_artifact_bindings.setup_generation", - ], - name="fk_guide_classifications_exact_binding", - ), - sa.UniqueConstraint("binding_id", name="uq_guide_classifications_binding"), - sa.CheckConstraint( - "status in ('classified','unsupported','ambiguous','malformed','limit_exceeded')", - name="ck_guide_classifications_status", - ), - sa.CheckConstraint( - "sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="ck_guide_source_format_classifications_sha256_shape", - ), - sa.CheckConstraint( - "byte_count >= 0", name="ck_guide_source_format_classifications_byte_count_nonnegative" - ), - ) - op.create_table( - "guide_source_artifact_incidents", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("binding_id", sa.String(36), nullable=False), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("verified_replica_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("code", sa.String(40), nullable=False), - sa.Column("observed_sha256", sa.String(71), nullable=True), - sa.Column("observed_byte_count", sa.BigInteger(), nullable=True), - sa.Column("bounded_facts", sa.JSON(), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ), - sa.ForeignKeyConstraint( - ["binding_id", "content_id", "verified_replica_id", "setup_generation"], - [ - "guide_source_artifact_bindings.id", - "guide_source_artifact_bindings.content_id", - "guide_source_artifact_bindings.verified_replica_id", - "guide_source_artifact_bindings.setup_generation", - ], - name="fk_guide_incidents_exact_binding", - ), - sa.CheckConstraint( - "code in ('missing','changed','truncated','unavailable','stale','conflict')", - name="ck_guide_incidents_code", - ), - sa.CheckConstraint( - "observed_byte_count is null or observed_byte_count >= 0", - name="ck_guide_source_artifact_incidents_size", - ), - sa.CheckConstraint( - "observed_sha256 is null or observed_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="ck_guide_source_artifact_incidents_sha256", - ), - ) - for table in ("guide_source_format_classifications", "guide_source_artifact_incidents"): - for column in ("binding_id", "content_id", "verified_replica_id"): - op.create_index(op.f(f"ix_{table}_{column}"), table, [column]) - - -def downgrade() -> None: - bind = op.get_bind() - bind.execute( - sa.text( - "lock table guide_source_format_classifications, guide_source_artifact_incidents in access exclusive mode" - ) - ) - if bind.execute( - sa.text( - "select exists(select 1 from guide_source_format_classifications) or exists(select 1 from guide_source_artifact_incidents)" - ) - ).scalar_one(): - raise RuntimeError("cannot downgrade populated guide materialization evidence") - op.drop_table("guide_source_artifact_incidents") - op.drop_table("guide_source_format_classifications") - op.drop_constraint( - "uq_guide_bindings_exact_read", "guide_source_artifact_bindings", type_="unique" - ) diff --git a/backend/alembic/versions/0041_project_mutation_action_evidence.py b/backend/alembic/versions/0041_project_mutation_action_evidence.py deleted file mode 100644 index d295763fa..000000000 --- a/backend/alembic/versions/0041_project_mutation_action_evidence.py +++ /dev/null @@ -1,129 +0,0 @@ -"""register planned project-mutation action evidence - -Revision ID: 0041_project_mutation_evidence -Revises: 0040_guide_materialization -Create Date: 2026-07-29 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0041_project_mutation_evidence" -down_revision = "0040_guide_materialization" -branch_labels = depends_on = None - -_ACTIONS = ( - ("project.create", "project.create"), - ("project.guide.create", "project.guide.manage"), - ("project.guide.update", "project.guide.manage"), - ("project.guide_source_snapshot.create", "project.guide.manage"), - ("project.review_policy.update", "project.review_policy.manage"), - ("project.revision_policy.update", "project.review_policy.manage"), - ("project.guide_sufficiency_report.create", "project.guide.manage"), - ("project.guide_sufficiency.run", "project.guide.manage"), - ("project.guide_sufficiency.warnings.acknowledge", "project.guide.manage"), - ("project.submission_artifact_policy.create", "project.effective_policy.manage"), - ("project.submission_artifact_policy.derive", "project.effective_policy.manage"), - ("project.submission_artifact_policy.update", "project.effective_policy.manage"), - ("project.submission_artifact_policy.approve", "project.effective_policy.manage"), - ("project.post_submit_checker_policy.approve", "project.effective_policy.manage"), - ( - "project.post_submit_checker_policy.correction.request", - "project.effective_policy.manage", - ), - ("project.post_submit_checker_policy.derive", "project.effective_policy.manage"), - ("project.setup_run.update", "project.guide.manage"), - ("project.guide.activate", "project.guide.manage"), -) - - -def _definition() -> str: - return ( - op.get_bind() - .execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authorization_action_evidence'" - ) - ) - .scalar_one() - ) - - -def _replace(definition: str) -> None: - op.drop_constraint( - "authorization_action_evidence", - "audit_events", - type_="check", - ) - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authorization_action_evidence {definition}" - ) - - -def _pair_token(action: str, permission: str) -> str: - # Keep this byte-for-byte aligned with PostgreSQL's pg_get_constraintdef - # rendering; _rewrite's marker-count guards fail closed if that format drifts. - return ( - f"(((action_id)::text = '{action}'::text) AND " - f"((permission_id)::text = '{permission}'::text))" - ) - - -def _rewrite(*, add: bool) -> None: - definition = _definition() - additions = " OR " + " OR ".join(_pair_token(*pair) for pair in _ACTIONS) - marker = _pair_token("project.active_guide.read", "project.read") - if add: - if definition.count(marker) != 2 or any( - _pair_token(*pair) in definition for pair in _ACTIONS - ): - raise RuntimeError("unexpected project-mutation action registry definition") - definition = definition.replace(marker, marker + additions) - else: - if definition.count(additions) != 2: - raise RuntimeError("unexpected project-mutation action registry definition") - definition = definition.replace(additions, "") - _replace(definition) - - -def _lock_evidence() -> None: - bind = op.get_bind() - bind.execute(sa.text("lock table authority_idempotency_records in share row exclusive mode")) - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - - -def _has_evidence() -> bool: - actions = [action for action, _ in _ACTIONS] - return bool( - op.get_bind() - .execute( - sa.text( - "select exists(select 1 from audit_events where action_id = any(:actions)) or " - "exists(select 1 from authority_idempotency_records record " - "join audit_events event on event.idempotency_reference=record.id " - "where event.action_id = any(:actions))" - ), - {"actions": actions}, - ) - .scalar_one() - ) - - -def upgrade() -> None: - """Register the eighteen project-mutation pairs without activating them.""" - _lock_evidence() - _rewrite(add=True) - - -def downgrade() -> None: - """Remove project-mutation pairs only when no forward evidence exists.""" - _lock_evidence() - if _has_evidence(): - raise RuntimeError("cannot downgrade non-empty project-mutation action evidence") - _rewrite(add=False) diff --git a/backend/alembic/versions/0042_guide_extraction.py b/backend/alembic/versions/0042_guide_extraction.py deleted file mode 100644 index 8fbc17175..000000000 --- a/backend/alembic/versions/0042_guide_extraction.py +++ /dev/null @@ -1,277 +0,0 @@ -"""add bounded guide extraction provenance - -Revision ID: 0042_guide_extraction -Revises: 0041_project_mutation_evidence -Create Date: 2026-07-29 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0042_guide_extraction" -down_revision = "0041_project_mutation_evidence" -branch_labels = depends_on = None - - -def upgrade() -> None: - op.create_unique_constraint( - "uq_guide_bindings_extraction_attempt_lineage", - "guide_source_artifact_bindings", - ["id", "content_id", "setup_generation"], - ) - op.create_unique_constraint( - "uq_guide_bindings_extraction_lineage", - "guide_source_artifact_bindings", - ["id", "content_id", "source_item_id", "project_setup_run_id", "setup_generation"], - ) - op.create_unique_constraint( - "uq_guide_classifications_extraction_lineage", - "guide_source_format_classifications", - ["id", "binding_id", "content_id", "setup_generation"], - ) - op.create_table( - "guide_source_extraction_attempts", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("binding_id", sa.String(36), nullable=False), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("classification_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("detected_format", sa.String(40), nullable=False), - sa.Column("extractor_name", sa.String(100), nullable=False), - sa.Column("extractor_version", sa.String(40), nullable=False), - sa.Column("policy_version", sa.String(80), nullable=False), - sa.Column("attempt_number", sa.BigInteger(), nullable=False), - sa.Column("status", sa.String(40), nullable=False), - sa.Column("error_code", sa.String(80), nullable=True), - sa.Column("bounded_facts", sa.JSON(), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ), - sa.ForeignKeyConstraint( - ["binding_id", "content_id", "setup_generation"], - [ - "guide_source_artifact_bindings.id", - "guide_source_artifact_bindings.content_id", - "guide_source_artifact_bindings.setup_generation", - ], - name="fk_guide_extraction_attempts_exact_binding", - ), - sa.ForeignKeyConstraint( - ["classification_id", "binding_id", "content_id", "setup_generation"], - [ - "guide_source_format_classifications.id", - "guide_source_format_classifications.binding_id", - "guide_source_format_classifications.content_id", - "guide_source_format_classifications.setup_generation", - ], - name="fk_guide_extraction_attempts_exact_classification", - ), - sa.UniqueConstraint( - "binding_id", "policy_version", "attempt_number", name="uq_guide_extraction_attempts" - ), - sa.UniqueConstraint( - "id", - "binding_id", - "content_id", - "setup_generation", - "status", - name="uq_guide_extraction_attempts_exact_usage", - ), - sa.CheckConstraint("attempt_number > 0", name="ck_guide_extraction_attempts_number"), - sa.CheckConstraint( - "(status = 'extracted') = (error_code is null)", - name="ck_guide_extraction_attempts_error", - ), - sa.CheckConstraint( - "status in ('extracted','unsupported','ambiguous','malformed','limit_exceeded','parser_failure','cancelled','artifact_incident')", - name="ck_guide_extraction_attempts_status", - ), - ) - op.create_table( - "guide_source_extracted_contents", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column( - "content_id", - sa.String(36), - sa.ForeignKey("artifact_contents.id", ondelete="RESTRICT"), - nullable=False, - ), - sa.Column("detected_format", sa.String(40), nullable=False), - sa.Column("extractor_name", sa.String(100), nullable=False), - sa.Column("extractor_version", sa.String(40), nullable=False), - sa.Column("policy_version", sa.String(80), nullable=False), - sa.Column("source_sha256", sa.String(71), nullable=False), - sa.Column("source_byte_count", sa.BigInteger(), nullable=False), - sa.Column("status", sa.String(40), nullable=False), - sa.Column("output_sha256", sa.String(71), nullable=False), - sa.Column("canonical_output", sa.Text(), nullable=False), - sa.Column("omission_facts", sa.JSON(), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ), - sa.UniqueConstraint( - "content_id", - "detected_format", - "extractor_name", - "extractor_version", - "policy_version", - name="uq_guide_extracted_contents_identity", - ), - sa.UniqueConstraint("id", "content_id", name="uq_guide_extracted_contents_exact_usage"), - sa.CheckConstraint("status = 'extracted'", name="ck_guide_extracted_contents_status"), - sa.CheckConstraint( - "source_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="ck_guide_extracted_contents_source_sha256", - ), - sa.CheckConstraint( - "output_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="ck_guide_extracted_contents_output_sha256", - ), - sa.CheckConstraint( - "source_byte_count >= 0", name="ck_guide_extracted_contents_source_size" - ), - sa.CheckConstraint( - "octet_length(canonical_output) <= 4194304", - name="ck_guide_extracted_contents_output_size", - ), - ) - op.create_table( - "guide_source_extraction_retry_budgets", - sa.Column("binding_id", sa.String(36), primary_key=True), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("classification_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("policy_version", sa.String(80), nullable=False), - sa.Column("claimed_slots", sa.Integer(), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.text("now()"), nullable=False), - sa.Column("updated_at", sa.DateTime(timezone=True), server_default=sa.text("now()"), nullable=False), - sa.ForeignKeyConstraint( - ["binding_id", "content_id", "setup_generation"], - ["guide_source_artifact_bindings.id", "guide_source_artifact_bindings.content_id", "guide_source_artifact_bindings.setup_generation"], - name="fk_guide_extraction_retry_budgets_exact_binding", - ), - sa.ForeignKeyConstraint( - ["classification_id", "binding_id", "content_id", "setup_generation"], - ["guide_source_format_classifications.id", "guide_source_format_classifications.binding_id", "guide_source_format_classifications.content_id", "guide_source_format_classifications.setup_generation"], - name="fk_guide_extraction_retry_budgets_exact_classification", - ), - sa.CheckConstraint("claimed_slots between 1 and 2", name="ck_guide_extraction_retry_budgets_slots"), - ) - op.create_table( - "guide_source_extraction_usages", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("extracted_content_id", sa.String(36), nullable=False), - sa.Column("extraction_attempt_id", sa.String(36), nullable=False), - sa.Column("attempt_status", sa.String(40), nullable=False), - sa.Column("binding_id", sa.String(36), nullable=False), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("source_item_id", sa.String(36), nullable=False), - sa.Column("project_setup_run_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("now()"), - nullable=False, - ), - sa.ForeignKeyConstraint( - [ - "binding_id", - "content_id", - "source_item_id", - "project_setup_run_id", - "setup_generation", - ], - [ - "guide_source_artifact_bindings.id", - "guide_source_artifact_bindings.content_id", - "guide_source_artifact_bindings.source_item_id", - "guide_source_artifact_bindings.project_setup_run_id", - "guide_source_artifact_bindings.setup_generation", - ], - name="fk_guide_extraction_usages_exact_binding", - ), - sa.ForeignKeyConstraint( - [ - "extraction_attempt_id", - "binding_id", - "content_id", - "setup_generation", - "attempt_status", - ], - [ - "guide_source_extraction_attempts.id", - "guide_source_extraction_attempts.binding_id", - "guide_source_extraction_attempts.content_id", - "guide_source_extraction_attempts.setup_generation", - "guide_source_extraction_attempts.status", - ], - name="fk_guide_extraction_usages_exact_attempt", - ), - sa.ForeignKeyConstraint( - ["extracted_content_id", "content_id"], - ["guide_source_extracted_contents.id", "guide_source_extracted_contents.content_id"], - name="fk_guide_extraction_usages_exact_content", - ), - sa.UniqueConstraint( - "binding_id", "extracted_content_id", name="uq_guide_extraction_usages" - ), - sa.CheckConstraint( - "attempt_status = 'extracted'", - name="ck_guide_extraction_usages_successful_attempt", - ), - ) - for table, columns in { - "guide_source_extraction_attempts": ("binding_id", "content_id"), - "guide_source_extracted_contents": ("content_id",), - "guide_source_extraction_usages": ( - "extracted_content_id", - "binding_id", - "content_id", - "source_item_id", - "project_setup_run_id", - ), - }.items(): - for column in columns: - op.create_index(op.f(f"ix_{table}_{column}"), table, [column]) - - -def downgrade() -> None: - bind = op.get_bind() - bind.execute( - sa.text( - "lock table guide_source_extraction_usages, guide_source_extracted_contents, guide_source_extraction_retry_budgets, guide_source_extraction_attempts in access exclusive mode" - ) - ) - if bind.execute( - sa.text( - "select exists(select 1 from guide_source_extraction_usages) or exists(select 1 from guide_source_extracted_contents) or exists(select 1 from guide_source_extraction_attempts) or exists(select 1 from guide_source_extraction_retry_budgets)" - ) - ).scalar_one(): - raise RuntimeError("cannot downgrade populated guide extraction evidence") - op.drop_table("guide_source_extraction_usages") - op.drop_table("guide_source_extraction_retry_budgets") - op.drop_table("guide_source_extracted_contents") - op.drop_table("guide_source_extraction_attempts") - op.drop_constraint( - "uq_guide_classifications_extraction_lineage", - "guide_source_format_classifications", - type_="unique", - ) - op.drop_constraint( - "uq_guide_bindings_extraction_lineage", "guide_source_artifact_bindings", type_="unique" - ) - op.drop_constraint( - "uq_guide_bindings_extraction_attempt_lineage", - "guide_source_artifact_bindings", - type_="unique", - ) diff --git a/backend/alembic/versions/0043_project_setup_service.py b/backend/alembic/versions/0043_project_setup_service.py deleted file mode 100644 index 7e48630b7..000000000 --- a/backend/alembic/versions/0043_project_setup_service.py +++ /dev/null @@ -1,62 +0,0 @@ -"""register the fixed project-setup service identity - -Revision ID: 0043_project_setup_service -Revises: 0042_guide_extraction -Create Date: 2026-07-30 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0043_project_setup_service" -down_revision = "0042_guide_extraction" -branch_labels = depends_on = None - -_HISTORICAL_IDENTITIES = ( - "workstream.artifact.verifier", - "workstream.artifact.put_resolver", - "workstream.artifact.scheduler", - "workstream.artifact.binding", - "workstream.artifact.guide_reader", - "workstream.artifact.materializer", - "workstream.artifact.checker_output", -) -_PROJECT_SETUP_IDENTITY = "workstream.project.setup" - - -def _tokens(values: tuple[str, ...]) -> str: - return ",".join(f"'{value}'" for value in values) - - -def _replace_identity_constraint(values: tuple[str, ...]) -> None: - op.drop_constraint("kind_service_identity", "actor_profiles", type_="check") - op.create_check_constraint( - "kind_service_identity", - "actor_profiles", - "(actor_kind='human' and service_identity is null) or " - f"(actor_kind='service' and service_identity in ({_tokens(values)}))", - ) - - -def upgrade() -> None: - """Admit the eighth closed identity without creating a service actor.""" - op.get_bind().execute(sa.text("lock table actor_profiles in access exclusive mode")) - _replace_identity_constraint((*_HISTORICAL_IDENTITIES, _PROJECT_SETUP_IDENTITY)) - - -def downgrade() -> None: - """Restore the seven-identity constraint only when the new identity is unused.""" - bind = op.get_bind() - bind.execute(sa.text("lock table actor_profiles in access exclusive mode")) - in_use = bind.execute( - sa.text( - "select exists(select 1 from actor_profiles where service_identity=:identity)" - ), - {"identity": _PROJECT_SETUP_IDENTITY}, - ).scalar_one() - if in_use: - raise RuntimeError("cannot downgrade project setup service identity") - _replace_identity_constraint(_HISTORICAL_IDENTITIES) diff --git a/backend/alembic/versions/0044_project_create_authority.py b/backend/alembic/versions/0044_project_create_authority.py deleted file mode 100644 index 34dd3b640..000000000 --- a/backend/alembic/versions/0044_project_create_authority.py +++ /dev/null @@ -1,336 +0,0 @@ -"""activate transaction-bound project creation authority - -Revision ID: 0044_project_create_authority -Revises: 0043_project_setup_service -Create Date: 2026-07-30 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0044_project_create_authority" -down_revision = "0043_project_setup_service" -branch_labels = depends_on = None - -_RESOURCE_MARKER = "('audit_event'::character varying)::text" -_RESOURCE_ADDITION = ", ('project_create_operation'::character varying)::text" -_TARGET_MARKER = "('project_role_grant'::character varying)::text" -_TARGET_ADDITION = ", ('project'::character varying)::text" - - -def _rewrite_audit_privacy(*, add: bool) -> None: - bind = op.get_bind() - definition = bind.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_privacy_bounds'" - ) - ).scalar_one() - resource_new = _RESOURCE_MARKER + _RESOURCE_ADDITION - resource_source, resource_target = ( - (_RESOURCE_MARKER, resource_new) if add else (resource_new, _RESOURCE_MARKER) - ) - if definition.count(resource_source) != 1 or (add and resource_new in definition): - raise RuntimeError("unexpected authority privacy constraint") - definition = definition.replace(resource_source, resource_target, 1) - - target_new = _TARGET_MARKER + _TARGET_ADDITION - target_source, target_target = ( - (_TARGET_MARKER, target_new) if add else (target_new, _TARGET_MARKER) - ) - anchor = "((target_ref_kind)::text = ANY (ARRAY[" - anchor_index = definition.find(anchor) - source_index = definition.find(target_source, anchor_index) - invalidation_index = definition.find("invalidation_target_kind", anchor_index) - if ( - anchor_index < 0 - or source_index < 0 - or invalidation_index < 0 - or source_index > invalidation_index - or (add and target_new in definition[anchor_index:invalidation_index]) - ): - raise RuntimeError("unexpected authority privacy constraint") - definition = ( - definition[:source_index] - + target_target - + definition[source_index + len(target_source) :] - ) - op.drop_constraint("authority_privacy_bounds", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authority_privacy_bounds {definition}" - ) - - -def upgrade() -> None: - """Add nullable historical provenance and project-owned replay state.""" - op.execute("lock table audit_events in access exclusive mode") - _rewrite_audit_privacy(add=True) - op.add_column("projects", sa.Column("created_by_actor_profile_id", sa.String(36))) - op.add_column("projects", sa.Column("created_via_identity_link_id", sa.String(36))) - op.add_column( - "projects", sa.Column("created_by_admin_role_grant_id", sa.Uuid()) - ) - op.add_column("projects", sa.Column("creation_scope_type", sa.String(16))) - op.add_column("projects", sa.Column("creation_action_id", sa.String(160))) - op.add_column( - "projects", sa.Column("authorization_decision_event_id", sa.String(36)) - ) - op.create_foreign_key( - "fk_projects_creation_actor", - "projects", - "actor_profiles", - ["created_by_actor_profile_id"], - ["id"], - ) - op.create_foreign_key( - "fk_projects_creation_identity_link", - "projects", - "actor_identity_links", - ["created_via_identity_link_id"], - ["id"], - ) - op.create_foreign_key( - "fk_projects_creation_admin_grant", - "projects", - "admin_role_grants", - ["created_by_admin_role_grant_id"], - ["id"], - ) - op.create_foreign_key( - "fk_projects_creation_decision", - "projects", - "audit_events", - ["authorization_decision_event_id"], - ["id"], - ) - op.create_check_constraint( - "creation_authority_shape", - "projects", - "(created_by_actor_profile_id is null and created_via_identity_link_id is null " - "and created_by_admin_role_grant_id is null and creation_scope_type is null " - "and creation_action_id is null and authorization_decision_event_id is null) or " - "(created_by_actor_profile_id is not null and created_via_identity_link_id is not null " - "and created_by_admin_role_grant_id is not null and creation_scope_type = 'system' " - "and creation_action_id = 'project.create' and authorization_decision_event_id is not null)", - ) - - op.create_table( - "project_create_idempotency_records", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column( - "actor_profile_id", - sa.String(36), - sa.ForeignKey("actor_profiles.id"), - nullable=False, - ), - sa.Column( - "identity_link_id", - sa.String(36), - sa.ForeignKey("actor_identity_links.id"), - nullable=False, - ), - sa.Column("action_id", sa.String(160), nullable=False), - sa.Column("idempotency_key", sa.Uuid(), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("operation_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("operation_generation", sa.Integer(), nullable=False), - sa.Column("status", sa.String(16), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.func.now(), - nullable=False, - ), - sa.Column("committed_at", sa.DateTime(timezone=True)), - sa.UniqueConstraint( - "actor_profile_id", "action_id", "idempotency_key", name="uq_project_create_replay_namespace" - ), - sa.UniqueConstraint("operation_id", name="uq_project_create_operation_identity"), - sa.UniqueConstraint("project_id", name="uq_project_create_project_identity"), - sa.CheckConstraint("action_id = 'project.create'", name="ck_project_create_action"), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", - name="ck_project_create_request_digest", - ), - sa.CheckConstraint("operation_generation = 1", name="ck_project_create_generation"), - sa.CheckConstraint( - "status in ('pending','committed')", name="ck_project_create_status" - ), - sa.CheckConstraint( - "(status = 'pending' and committed_at is null) or " - "(status = 'committed' and committed_at is not null)", - name="ck_project_create_state_shape", - ), - ) - op.execute( - """ - create function guard_project_create_idempotency() returns trigger - language plpgsql as $$ - begin - if tg_op = 'INSERT' then - if new.status <> 'pending' or new.committed_at is not null then - raise exception 'project create reservation must begin pending' using errcode='23514'; - end if; - return new; - elsif tg_op = 'DELETE' then - raise exception 'project create reservations are immutable' using errcode='55000'; - end if; - if new is not distinct from old then - return new; - end if; - if old.status <> 'pending' or new.status <> 'committed' - or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, - new.idempotency_key, new.request_digest, new.operation_id, - new.project_id, new.operation_generation, new.created_at) - is distinct from - (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, - old.idempotency_key, old.request_digest, old.operation_id, - old.project_id, old.operation_generation, old.created_at) then - raise exception 'invalid project create reservation transition' using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger project_create_idempotency_guard before insert or update or delete " - "on project_create_idempotency_records for each row " - "execute function guard_project_create_idempotency()" - ) - op.execute( - """ - create function reject_project_create_idempotency_truncate() returns trigger - language plpgsql as $$ begin - raise exception 'project create reservations are immutable' using errcode='55000'; - end $$ - """ - ) - op.execute( - "create trigger project_create_idempotency_reject_truncate before truncate " - "on project_create_idempotency_records execute function " - "reject_project_create_idempotency_truncate()" - ) - op.execute( - """ - create function validate_project_create_custody() returns trigger - language plpgsql as $$ - declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; - evidence audit_events%rowtype; - begin - if tg_table_name = 'projects' then - if tg_op = 'INSERT' and new.creation_action_id is null then - raise exception 'new projects require creation authority' using errcode='23514'; - end if; - if new.creation_action_id is null then return null; end if; - project_row := new; - select * into reservation from project_create_idempotency_records - where project_id=project_row.id and status='committed'; - else - select * into reservation from project_create_idempotency_records - where id=new.id; - if reservation.status <> 'committed' then - raise exception 'pending project create reservation cannot commit' using errcode='23514'; - end if; - select * into project_row from projects where id=reservation.project_id; - end if; - if project_row.id is null or reservation.id is null - or project_row.created_by_actor_profile_id - is distinct from reservation.actor_profile_id - or project_row.created_via_identity_link_id - is distinct from reservation.identity_link_id - or project_row.creation_action_id is distinct from reservation.action_id then - raise exception 'project create custody mismatch' using errcode='23514'; - end if; - select * into evidence from audit_events - where id=project_row.authorization_decision_event_id; - if evidence.id is null - or evidence.event_domain is distinct from 'authority' - or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' - or evidence.denial_code is not null - or evidence.actor_ref_kind is distinct from 'actor_profile' - or evidence.actor_id is distinct from project_row.created_by_actor_profile_id - or evidence.matched_grant_id - is distinct from project_row.created_by_admin_role_grant_id::text - or evidence.permission_id is distinct from 'project.create' - or evidence.action_id is distinct from 'project.create' - or evidence.resource_type is distinct from 'project_create_operation' - or evidence.resource_id is distinct from reservation.operation_id::text - or evidence.target_ref_kind is distinct from 'project' - or evidence.target_ref_id is distinct from project_row.id - or evidence.after_facts->>'allowed' is distinct from 'true' - or coalesce( - evidence.after_facts->>'resource_context_digest' - !~ '^sha256:[0-9a-f]{64}$', - true - ) then - raise exception 'project create evidence mismatch' using errcode='23514'; - end if; - return null; - end $$ - """ - ) - op.execute( - "create constraint trigger project_creation_custody after insert or update " - "of created_by_actor_profile_id, created_via_identity_link_id, " - "created_by_admin_role_grant_id, creation_scope_type, creation_action_id, " - "authorization_decision_event_id on projects deferrable initially deferred " - "for each row execute function validate_project_create_custody()" - ) - op.execute( - "create constraint trigger project_create_reservation_custody after insert or update " - "on project_create_idempotency_records deferrable initially deferred for each row " - "execute function validate_project_create_custody()" - ) - - -def downgrade() -> None: - """Remove the seam only before any project-create authority is used.""" - bind = op.get_bind() - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - bind.execute(sa.text("lock table projects in share row exclusive mode")) - bind.execute( - sa.text("lock table project_create_idempotency_records in share row exclusive mode") - ) - used = bind.execute( - sa.text( - "select exists(select 1 from projects where creation_action_id is not null) " - "or exists(select 1 from project_create_idempotency_records)" - ) - ).scalar_one() - if used: - raise RuntimeError("cannot downgrade non-empty project creation authority") - op.execute("drop trigger project_creation_custody on projects") - op.execute( - "drop trigger project_create_reservation_custody on " - "project_create_idempotency_records" - ) - op.execute( - "drop trigger project_create_idempotency_reject_truncate on " - "project_create_idempotency_records" - ) - op.execute( - "drop trigger project_create_idempotency_guard on " - "project_create_idempotency_records" - ) - op.execute("drop function validate_project_create_custody()") - op.execute("drop function reject_project_create_idempotency_truncate()") - op.execute("drop function guard_project_create_idempotency()") - op.drop_table("project_create_idempotency_records") - op.drop_constraint("creation_authority_shape", "projects", type_="check") - op.drop_constraint("fk_projects_creation_decision", "projects", type_="foreignkey") - op.drop_constraint("fk_projects_creation_admin_grant", "projects", type_="foreignkey") - op.drop_constraint("fk_projects_creation_identity_link", "projects", type_="foreignkey") - op.drop_constraint("fk_projects_creation_actor", "projects", type_="foreignkey") - op.drop_column("projects", "authorization_decision_event_id") - op.drop_column("projects", "creation_action_id") - op.drop_column("projects", "creation_scope_type") - op.drop_column("projects", "created_by_admin_role_grant_id") - op.drop_column("projects", "created_via_identity_link_id") - op.drop_column("projects", "created_by_actor_profile_id") - _rewrite_audit_privacy(add=False) diff --git a/backend/alembic/versions/0045_guide_source_metadata_authority.py b/backend/alembic/versions/0045_guide_source_metadata_authority.py deleted file mode 100644 index 0b4cd3426..000000000 --- a/backend/alembic/versions/0045_guide_source_metadata_authority.py +++ /dev/null @@ -1,515 +0,0 @@ -"""activate transaction-bound guide source-metadata authority - -Revision ID: 0045_guide_metadata_authority -Revises: 0044_project_create_authority -Create Date: 2026-07-31 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0045_guide_metadata_authority" -down_revision = "0044_project_create_authority" -branch_labels = depends_on = None - -_ACTIONS = "'project.guide.create','project.guide.update','project.guide_source_snapshot.create'" - - -def _authority_columns(table: str, *, prefix: str) -> None: - metadata_prefix = { - "last_mutated": "last_mutation", - "created": "creation", - "authorized": "authorization", - }[prefix] - op.add_column(table, sa.Column(f"{prefix}_by_actor_profile_id", sa.String(36))) - op.add_column(table, sa.Column(f"{prefix}_via_identity_link_id", sa.String(36))) - op.add_column(table, sa.Column(f"{prefix}_by_admin_role_grant_id", sa.Uuid())) - op.add_column(table, sa.Column(f"{metadata_prefix}_scope_type", sa.String(16))) - op.add_column(table, sa.Column(f"{metadata_prefix}_scope_project_id", sa.String(36))) - op.add_column(table, sa.Column(f"{metadata_prefix}_action_id", sa.String(160))) - decision_column = ( - "last_authorization_decision_event_id" - if prefix == "last_mutated" - else "authorization_decision_event_id" - ) - op.add_column(table, sa.Column(decision_column, sa.String(36))) - for suffix, target, target_column in ( - ("actor", "actor_profiles", "id"), - ("identity_link", "actor_identity_links", "id"), - ("admin_grant", "admin_role_grants", "id"), - ("decision", "audit_events", "id"), - ): - column = { - "actor": f"{prefix}_by_actor_profile_id", - "identity_link": f"{prefix}_via_identity_link_id", - "admin_grant": f"{prefix}_by_admin_role_grant_id", - "decision": decision_column, - }[suffix] - op.create_foreign_key( - f"fk_{table}_{prefix}_{suffix}", table, target, [column], [target_column] - ) - - -def _drop_authority_columns(table: str, *, prefix: str) -> None: - metadata_prefix = { - "last_mutated": "last_mutation", - "created": "creation", - "authorized": "authorization", - }[prefix] - for suffix in ("decision", "admin_grant", "identity_link", "actor"): - op.drop_constraint(f"fk_{table}_{prefix}_{suffix}", table, type_="foreignkey") - decision_column = ( - "last_authorization_decision_event_id" - if prefix == "last_mutated" - else "authorization_decision_event_id" - ) - for column in ( - decision_column, - f"{metadata_prefix}_action_id", - f"{metadata_prefix}_scope_project_id", - f"{metadata_prefix}_scope_type", - f"{prefix}_by_admin_role_grant_id", - f"{prefix}_via_identity_link_id", - f"{prefix}_by_actor_profile_id", - ): - op.drop_column(table, column) - - -def upgrade() -> None: - """Install nullable history and mandatory custody for every new mutation.""" - _authority_columns("project_guides", prefix="last_mutated") - op.add_column("project_guides", sa.Column("mutation_generation", sa.Integer())) - op.create_check_constraint( - "guide_mutation_authority_shape", - "project_guides", - "(mutation_generation is null and last_mutated_by_actor_profile_id is null " - "and last_mutated_via_identity_link_id is null " - "and last_mutated_by_admin_role_grant_id is null " - "and last_mutation_scope_type is null and last_mutation_scope_project_id is null " - "and last_mutation_action_id is null and last_authorization_decision_event_id is null) or " - "(mutation_generation > 0 and last_mutated_by_actor_profile_id is not null " - "and last_mutated_via_identity_link_id is not null " - "and last_mutated_by_admin_role_grant_id is not null " - "and last_mutation_scope_type in ('system','project') " - "and ((last_mutation_scope_type='system' and last_mutation_scope_project_id is null) " - "or (last_mutation_scope_type='project' and last_mutation_scope_project_id=project_id)) " - f"and last_mutation_action_id in ({_ACTIONS}) " - "and last_authorization_decision_event_id is not null)", - ) - - _authority_columns("guide_source_snapshots", prefix="created") - op.add_column("guide_source_snapshots", sa.Column("creation_generation", sa.Integer())) - op.create_check_constraint( - "source_snapshot_creation_authority_shape", - "guide_source_snapshots", - "(creation_generation is null and created_by_actor_profile_id is null " - "and created_via_identity_link_id is null and created_by_admin_role_grant_id is null " - "and creation_scope_type is null and creation_scope_project_id is null " - "and creation_action_id is null and authorization_decision_event_id is null) or " - "(creation_generation > 0 and created_by_actor_profile_id is not null " - "and created_via_identity_link_id is not null " - "and created_by_admin_role_grant_id is not null " - "and creation_scope_type in ('system','project') " - "and ((creation_scope_type='system' and creation_scope_project_id is null) " - "or (creation_scope_type='project' and creation_scope_project_id=project_id)) " - "and creation_action_id='project.guide_source_snapshot.create' " - "and authorization_decision_event_id is not null)", - ) - - _authority_columns("project_setup_runs", prefix="authorized") - op.create_check_constraint( - "setup_run_authority_shape", - "project_setup_runs", - "(authorized_by_actor_profile_id is null and authorized_via_identity_link_id is null " - "and authorized_by_admin_role_grant_id is null and authorization_scope_type is null " - "and authorization_scope_project_id is null and authorization_action_id is null " - "and authorization_decision_event_id is null) or " - "(authorized_by_actor_profile_id is not null " - "and authorized_via_identity_link_id is not null " - "and authorized_by_admin_role_grant_id is not null " - "and authorization_scope_type in ('system','project') " - "and ((authorization_scope_type='system' and authorization_scope_project_id is null) " - "or (authorization_scope_type='project' and authorization_scope_project_id=project_id)) " - "and authorization_action_id='project.guide_source_snapshot.create' " - "and authorization_decision_event_id is not null)", - ) - - op.create_table( - "guide_mutation_idempotency_records", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column( - "actor_profile_id", sa.String(36), sa.ForeignKey("actor_profiles.id"), nullable=False - ), - sa.Column( - "identity_link_id", - sa.String(36), - sa.ForeignKey("actor_identity_links.id"), - nullable=False, - ), - sa.Column("action_id", sa.String(160), nullable=False), - sa.Column("idempotency_key", sa.Uuid(), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("resource_context_digest", sa.String(71), nullable=False), - sa.Column("operation_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), sa.ForeignKey("projects.id"), nullable=False), - sa.Column("resource_id", sa.String(36), nullable=False), - sa.Column("operation_generation", sa.Integer(), nullable=False), - sa.Column("status", sa.String(16), nullable=False), - sa.Column("response_json", sa.JSON()), - sa.Column("setup_run_id", sa.String(36), sa.ForeignKey("project_setup_runs.id")), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.Column("committed_at", sa.DateTime(timezone=True)), - sa.UniqueConstraint( - "actor_profile_id", - "action_id", - "idempotency_key", - name="uq_guide_mutation_replay_namespace", - ), - sa.UniqueConstraint("operation_id", name="uq_guide_mutation_operation_identity"), - sa.CheckConstraint(f"action_id in ({_ACTIONS})", name="ck_guide_mutation_action"), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", name="ck_guide_mutation_request_digest" - ), - sa.CheckConstraint( - "resource_context_digest ~ '^sha256:[0-9a-f]{64}$'", - name="ck_guide_mutation_resource_context_digest", - ), - sa.CheckConstraint("operation_generation > 0", name="ck_guide_mutation_generation"), - sa.CheckConstraint("status in ('pending','committed')", name="ck_guide_mutation_status"), - sa.CheckConstraint( - "(status='pending' and response_json is null and committed_at is null and setup_run_id is null) or " - "(status='committed' and response_json is not null and committed_at is not null)", - name="ck_guide_mutation_state_shape", - ), - ) - op.execute( - """ - create function guard_guide_mutation_idempotency() returns trigger - language plpgsql as $$ begin - if tg_op='INSERT' then - if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; - return new; - elsif tg_op='DELETE' then - raise exception 'guide mutation custody is immutable' using errcode='55000'; - end if; - if new is not distinct from old then return new; end if; - if old.status<>'pending' or new.status<>'committed' - or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, - new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, - new.operation_generation,new.created_at) - is distinct from - (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, - old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, - old.operation_generation,old.created_at) then - raise exception 'invalid guide mutation custody transition' using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger guide_mutation_idempotency_guard before insert or update or delete " - "on guide_mutation_idempotency_records for each row execute function guard_guide_mutation_idempotency()" - ) - op.execute( - """ - create function reject_guide_mutation_idempotency_truncate() returns trigger - language plpgsql as $$ begin - raise exception 'guide mutation custody is immutable' using errcode='55000'; - end $$ - """ - ) - op.execute( - "create trigger guide_mutation_idempotency_reject_truncate before truncate " - "on guide_mutation_idempotency_records execute function reject_guide_mutation_idempotency_truncate()" - ) - op.execute( - """ - create function guard_guide_lineage_and_lifecycle() returns trigger - language plpgsql as $$ begin - if (new.id,new.project_id,new.version) - is distinct from (old.id,old.project_id,old.version) then - raise exception 'guide identity and lineage are immutable' using errcode='23514'; - end if; - if (new.status,new.approved_by,new.effective_at,new.superseded_at) - is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then - raise exception 'guide lifecycle mutation requires activation authority' - using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger guide_lineage_lifecycle_guard before update on project_guides " - "for each row execute function guard_guide_lineage_and_lifecycle()" - ) - op.execute( - """ - create function validate_guide_mutation_custody() returns trigger - language plpgsql as $$ - declare reservation guide_mutation_idempotency_records%rowtype; - evidence audit_events%rowtype; - actor_id text; link_id text; grant_id uuid; action_value text; - scope_type text; scope_project text; decision_id text; - product_project text; product_resource text; product_generation integer; - begin - if tg_table_name='guide_mutation_idempotency_records' then - select * into reservation from guide_mutation_idempotency_records where id=new.id; - if reservation.status<>'committed' then - raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; - end if; - if reservation.action_id in ('project.guide.create','project.guide.update') then - select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, - last_mutated_by_admin_role_grant_id,last_mutation_action_id, - last_mutation_scope_type,last_mutation_scope_project_id, - last_authorization_decision_event_id,project_id,id,mutation_generation - into actor_id,link_id,grant_id,action_value,scope_type,scope_project, - decision_id,product_project,product_resource,product_generation - from project_guides where id=reservation.resource_id; - else - select created_by_actor_profile_id,created_via_identity_link_id, - created_by_admin_role_grant_id,creation_action_id, - creation_scope_type,creation_scope_project_id, - authorization_decision_event_id,project_id,id,creation_generation - into actor_id,link_id,grant_id,action_value,scope_type,scope_project, - decision_id,product_project,product_resource,product_generation - from guide_source_snapshots where id=reservation.resource_id; - end if; - elsif tg_table_name='project_guides' then - if tg_op='UPDATE' - and (new.content_markdown is distinct from old.content_markdown - or new.change_summary is distinct from old.change_summary) - and (new.mutation_generation is not distinct from old.mutation_generation - or new.last_authorization_decision_event_id - is not distinct from old.last_authorization_decision_event_id) then - raise exception 'guide content mutation requires fresh custody' using errcode='23514'; - end if; - if new.mutation_generation is null then - if tg_op='INSERT' then - raise exception 'new guides require mutation authority' using errcode='23514'; - end if; - return null; - end if; - actor_id:=new.last_mutated_by_actor_profile_id; - link_id:=new.last_mutated_via_identity_link_id; - grant_id:=new.last_mutated_by_admin_role_grant_id; - action_value:=new.last_mutation_action_id; - scope_type:=new.last_mutation_scope_type; - scope_project:=new.last_mutation_scope_project_id; - decision_id:=new.last_authorization_decision_event_id; - product_project:=new.project_id; product_resource:=new.id; - product_generation:=new.mutation_generation; - select * into reservation from guide_mutation_idempotency_records - where resource_id=new.id and action_id=new.last_mutation_action_id - and operation_generation=new.mutation_generation and status='committed'; - elsif tg_table_name='guide_source_snapshots' then - if tg_op='UPDATE' - and (new.project_id,new.guide_id,new.guide_version, - new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) - is distinct from - (old.project_id,old.guide_id,old.guide_version, - old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then - raise exception 'guide source snapshot content is immutable' using errcode='23514'; - end if; - if new.creation_generation is null then - raise exception 'new source snapshots require creation authority' using errcode='23514'; - end if; - actor_id:=new.created_by_actor_profile_id; - link_id:=new.created_via_identity_link_id; - grant_id:=new.created_by_admin_role_grant_id; - action_value:=new.creation_action_id; - scope_type:=new.creation_scope_type; - scope_project:=new.creation_scope_project_id; - decision_id:=new.authorization_decision_event_id; - product_project:=new.project_id; product_resource:=new.id; - product_generation:=new.creation_generation; - select * into reservation from guide_mutation_idempotency_records - where resource_id=new.id and action_id='project.guide_source_snapshot.create' - and operation_generation=new.creation_generation and status='committed'; - else - if new.authorization_action_id is null then return null; end if; - actor_id:=new.authorized_by_actor_profile_id; - link_id:=new.authorized_via_identity_link_id; - grant_id:=new.authorized_by_admin_role_grant_id; - action_value:=new.authorization_action_id; - scope_type:=new.authorization_scope_type; - scope_project:=new.authorization_scope_project_id; - decision_id:=new.authorization_decision_event_id; - product_project:=new.project_id; product_resource:=new.source_snapshot_id; - select * into reservation from guide_mutation_idempotency_records - where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' - and status='committed'; - product_generation:=reservation.operation_generation; - end if; - if reservation.id is null or product_resource is null - or reservation.actor_profile_id is distinct from actor_id - or reservation.identity_link_id is distinct from link_id - or reservation.action_id is distinct from action_value - or reservation.project_id is distinct from product_project - or reservation.resource_id is distinct from product_resource - or reservation.operation_generation is distinct from product_generation - or scope_type not in ('system','project') - or (scope_type='project' and scope_project is distinct from product_project) - or (scope_type='system' and scope_project is not null) then - raise exception 'guide mutation custody mismatch' using errcode='23514'; - end if; - select * into evidence from audit_events where id=decision_id; - if evidence.id is null - or evidence.event_domain is distinct from 'authority' - or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' - or evidence.denial_code is not null - or evidence.actor_ref_kind is distinct from 'actor_profile' - or evidence.actor_id is distinct from actor_id - or evidence.matched_grant_id is distinct from grant_id::text - or evidence.permission_id is distinct from 'project.guide.manage' - or evidence.action_id is distinct from action_value - or evidence.resource_type is distinct from 'project' - or evidence.resource_id is distinct from product_project - or evidence.target_ref_kind is distinct from 'project' - or evidence.target_ref_id is distinct from product_project - or evidence.after_facts->>'allowed' is distinct from 'true' - or evidence.after_facts->>'resource_context_digest' - is distinct from reservation.resource_context_digest then - raise exception 'guide mutation evidence mismatch' using errcode='23514'; - end if; - return null; - end $$ - """ - ) - for name, table in ( - ( - "guide_mutation_product_custody", - "project_guides", - ), - ( - "source_snapshot_product_custody", - "guide_source_snapshots", - ), - ( - "source_setup_run_custody", - "project_setup_runs", - ), - ): - op.execute( - f"create constraint trigger {name} after insert or update on {table} " - "deferrable initially deferred for each row execute function validate_guide_mutation_custody()" - ) - op.execute( - "create constraint trigger guide_mutation_reservation_custody after insert or update " - "on guide_mutation_idempotency_records deferrable initially deferred for each row " - "execute function validate_guide_mutation_custody()" - ) - op.execute( - """ - create function reject_guide_source_snapshot_item_mutation() returns trigger - language plpgsql as $$ begin - raise exception 'guide source snapshot items are immutable' using errcode='23514'; - end $$ - """ - ) - op.execute( - "create trigger guide_source_snapshot_items_immutable before update or delete or truncate " - "on guide_source_snapshot_items for each statement " - "execute function reject_guide_source_snapshot_item_mutation()" - ) - op.execute( - """ - create function validate_guide_source_snapshot_items() returns trigger - language plpgsql as $$ - declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; - begin - select jsonb_agg(item.value - 'content_excerpt' order by item.ordinality) - into expected - from guide_source_snapshots snapshot, - jsonb_array_elements(snapshot.manifest_json::jsonb->'items') - with ordinality as item(value, ordinality) - where snapshot.id=new.source_snapshot_id; - if expected is null then - raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; - end if; - select coalesce(jsonb_agg(jsonb_build_object( - 'source_kind',source_kind,'durable_ref',durable_ref, - 'ingestion_adapter',ingestion_adapter,'content_hash',content_hash, - 'content_cid',content_cid,'media_type',media_type) order by item_order),'[]'::jsonb) - into actual from guide_source_snapshot_items - where source_snapshot_id=new.source_snapshot_id; - if actual is distinct from expected then - raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; - end if; - select r.* into reservation from guide_mutation_idempotency_records r - join guide_source_snapshots s on s.id=r.resource_id - where s.id=new.source_snapshot_id - and r.action_id='project.guide_source_snapshot.create' - and r.operation_generation=s.creation_generation and r.status='committed'; - if reservation.id is null then - raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; - end if; - return null; - end $$ - """ - ) - op.execute( - "create constraint trigger guide_source_snapshot_items_custody after insert " - "on guide_source_snapshot_items deferrable initially deferred for each row " - "execute function validate_guide_source_snapshot_items()" - ) - - -def downgrade() -> None: - """Refuse removal once the authority seam has custody of any mutation.""" - bind = op.get_bind() - for table in ( - "guide_mutation_idempotency_records", - "project_guides", - "guide_source_snapshots", - "project_setup_runs", - ): - bind.execute(sa.text(f"lock table {table} in share row exclusive mode")) - used = bind.execute( - sa.text( - "select exists(select 1 from guide_mutation_idempotency_records) " - "or exists(select 1 from project_guides where mutation_generation is not null) " - "or exists(select 1 from guide_source_snapshots where creation_generation is not null) " - "or exists(select 1 from project_setup_runs where authorization_action_id is not null)" - ) - ).scalar_one() - if used: - raise RuntimeError("cannot downgrade used guide source-metadata authority") - op.execute("drop trigger guide_source_snapshot_items_custody on guide_source_snapshot_items") - op.execute("drop function validate_guide_source_snapshot_items()") - op.execute("drop trigger guide_source_snapshot_items_immutable on guide_source_snapshot_items") - op.execute("drop function reject_guide_source_snapshot_item_mutation()") - op.execute( - "drop trigger guide_mutation_reservation_custody on guide_mutation_idempotency_records" - ) - op.execute("drop trigger source_setup_run_custody on project_setup_runs") - op.execute("drop trigger source_snapshot_product_custody on guide_source_snapshots") - op.execute("drop trigger guide_mutation_product_custody on project_guides") - op.execute("drop trigger guide_lineage_lifecycle_guard on project_guides") - op.execute( - "drop trigger guide_mutation_idempotency_reject_truncate on guide_mutation_idempotency_records" - ) - op.execute( - "drop trigger guide_mutation_idempotency_guard on guide_mutation_idempotency_records" - ) - op.execute("drop function reject_guide_mutation_idempotency_truncate()") - op.execute("drop function guard_guide_mutation_idempotency()") - op.execute("drop function validate_guide_mutation_custody()") - op.execute("drop function guard_guide_lineage_and_lifecycle()") - op.drop_table("guide_mutation_idempotency_records") - op.drop_constraint("setup_run_authority_shape", "project_setup_runs", type_="check") - _drop_authority_columns("project_setup_runs", prefix="authorized") - op.drop_constraint( - "source_snapshot_creation_authority_shape", "guide_source_snapshots", type_="check" - ) - op.drop_column("guide_source_snapshots", "creation_generation") - _drop_authority_columns("guide_source_snapshots", prefix="created") - op.drop_constraint("guide_mutation_authority_shape", "project_guides", type_="check") - op.drop_column("project_guides", "mutation_generation") - _drop_authority_columns("project_guides", prefix="last_mutated") diff --git a/backend/alembic/versions/0046_guide_sufficiency_provenance.py b/backend/alembic/versions/0046_guide_sufficiency_provenance.py deleted file mode 100644 index 582b022d3..000000000 --- a/backend/alembic/versions/0046_guide_sufficiency_provenance.py +++ /dev/null @@ -1,196 +0,0 @@ -"""bind guide sufficiency reports to exact extraction usages - -Revision ID: 0046_guide_sufficiency -Revises: 0045_guide_metadata_authority -Create Date: 2026-08-01 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0046_guide_sufficiency" -down_revision = "0045_guide_metadata_authority" -branch_labels = depends_on = None - - -def upgrade() -> None: - """Install normalized exact extraction provenance for agent reports.""" - op.create_unique_constraint( - "uq_guide_extraction_usages_exact_provenance", - "guide_source_extraction_usages", - [ - "id", - "source_item_id", - "binding_id", - "content_id", - "extraction_attempt_id", - "extracted_content_id", - "project_setup_run_id", - "setup_generation", - ], - ) - op.add_column( - "project_setup_runs", sa.Column("error_artifact_incident_id", sa.String(36)) - ) - op.create_foreign_key( - "fk_project_setup_runs_artifact_incident", - "project_setup_runs", - "guide_source_artifact_incidents", - ["error_artifact_incident_id"], - ["id"], - use_alter=True, - ) - op.create_index( - "ix_project_setup_runs_error_artifact_incident_id", - "project_setup_runs", - ["error_artifact_incident_id"], - ) - for name, column in ( - ("project_setup_run_id", sa.String(36)), - ("setup_generation", sa.BigInteger), - ("agent_material_sha256", sa.String(71)), - ("agent_material_byte_count", sa.BigInteger), - ): - op.add_column("guide_sufficiency_reports", sa.Column(name, column)) - op.create_foreign_key( - "fk_sufficiency_reports_setup_run", - "guide_sufficiency_reports", - "project_setup_runs", - ["project_setup_run_id"], - ["id"], - use_alter=True, - ) - op.create_index( - "ix_guide_sufficiency_reports_project_setup_run_id", - "guide_sufficiency_reports", - ["project_setup_run_id"], - ) - for name, condition in ( - ( - "ck_guide_sufficiency_reports_generation_positive", - "setup_generation is null or setup_generation > 0", - ), - ( - "ck_guide_sufficiency_reports_material_sha256", - "agent_material_sha256 is null or " - "agent_material_sha256 ~ '^sha256:[0-9a-f]{64}$'", - ), - ( - "ck_guide_sufficiency_reports_material_size", - "agent_material_byte_count is null or agent_material_byte_count >= 0", - ), - ( - "ck_guide_sufficiency_reports_material_provenance_shape", - "(project_setup_run_id is null and setup_generation is null " - "and agent_material_sha256 is null and agent_material_byte_count is null) or " - "(project_setup_run_id is not null and setup_generation is not null " - "and agent_material_sha256 is not null and agent_material_byte_count is not null)", - ), - ): - op.create_check_constraint(name, "guide_sufficiency_reports", condition) - op.create_table( - "guide_sufficiency_report_source_usages", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column( - "report_id", - sa.String(36), - sa.ForeignKey("guide_sufficiency_reports.id", ondelete="CASCADE"), - nullable=False, - ), - sa.Column("item_order", sa.Integer, nullable=False), - sa.Column("source_item_id", sa.String(36), nullable=False), - sa.Column("binding_id", sa.String(36), nullable=False), - sa.Column("content_id", sa.String(36), nullable=False), - sa.Column("extraction_usage_id", sa.String(36), nullable=False), - sa.Column("extraction_attempt_id", sa.String(36), nullable=False), - sa.Column("extracted_content_id", sa.String(36), nullable=False), - sa.Column("project_setup_run_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger, nullable=False), - sa.Column("canonical_output_sha256", sa.String(71), nullable=False), - sa.ForeignKeyConstraint( - [ - "extraction_usage_id", - "source_item_id", - "binding_id", - "content_id", - "extraction_attempt_id", - "extracted_content_id", - "project_setup_run_id", - "setup_generation", - ], - [ - "guide_source_extraction_usages.id", - "guide_source_extraction_usages.source_item_id", - "guide_source_extraction_usages.binding_id", - "guide_source_extraction_usages.content_id", - "guide_source_extraction_usages.extraction_attempt_id", - "guide_source_extraction_usages.extracted_content_id", - "guide_source_extraction_usages.project_setup_run_id", - "guide_source_extraction_usages.setup_generation", - ], - name="fk_sufficiency_report_source_usage_exact_extraction", - ), - sa.UniqueConstraint("report_id", "item_order", name="uq_sufficiency_report_item_order"), - sa.UniqueConstraint( - "report_id", "extraction_usage_id", name="uq_sufficiency_report_extraction_usage" - ), - sa.CheckConstraint("item_order >= 0", name="ck_sufficiency_report_item_order"), - sa.CheckConstraint( - "setup_generation > 0", name="ck_sufficiency_report_usage_generation" - ), - sa.CheckConstraint( - "canonical_output_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="ck_sufficiency_report_output_sha256", - ), - ) - op.create_index( - "ix_sufficiency_report_source_usage_report_id", - "guide_sufficiency_report_source_usages", - ["report_id"], - ) - - -def downgrade() -> None: - """Remove guide sufficiency extraction provenance.""" - op.drop_index( - "ix_sufficiency_report_source_usage_report_id", - table_name="guide_sufficiency_report_source_usages", - ) - op.drop_table("guide_sufficiency_report_source_usages") - op.drop_index( - "ix_project_setup_runs_error_artifact_incident_id", - table_name="project_setup_runs", - ) - op.drop_constraint( - "fk_project_setup_runs_artifact_incident", "project_setup_runs", type_="foreignkey" - ) - op.drop_column("project_setup_runs", "error_artifact_incident_id") - op.drop_index( - "ix_guide_sufficiency_reports_project_setup_run_id", - table_name="guide_sufficiency_reports", - ) - op.drop_constraint( - "fk_sufficiency_reports_setup_run", "guide_sufficiency_reports", type_="foreignkey" - ) - for name in ( - "ck_guide_sufficiency_reports_material_provenance_shape", - "ck_guide_sufficiency_reports_material_size", - "ck_guide_sufficiency_reports_material_sha256", - "ck_guide_sufficiency_reports_generation_positive", - ): - op.drop_constraint(name, "guide_sufficiency_reports", type_="check") - for name in ( - "agent_material_byte_count", - "agent_material_sha256", - "setup_generation", - "project_setup_run_id", - ): - op.drop_column("guide_sufficiency_reports", name) - op.drop_constraint( - "uq_guide_extraction_usages_exact_provenance", - "guide_source_extraction_usages", - type_="unique", - ) diff --git a/backend/alembic/versions/0047_immutable_review_revision_policy_lineage.py b/backend/alembic/versions/0047_immutable_review_revision_policy_lineage.py deleted file mode 100644 index bf705faa0..000000000 --- a/backend/alembic/versions/0047_immutable_review_revision_policy_lineage.py +++ /dev/null @@ -1,597 +0,0 @@ -"""install immutable review and revision policy identity lineage - -Revision ID: 0047_policy_identity_lineage -Revises: 0046_guide_sufficiency -Create Date: 2026-08-01 -""" - -from __future__ import annotations - -import hashlib -import json - -from alembic import op -import sqlalchemy as sa - - -revision = "0047_policy_identity_lineage" -down_revision = "0046_guide_sufficiency" -branch_labels = depends_on = None - - -def _digest(domain: str, value: dict) -> str: - payload = json.dumps( - {"domain": domain, "semantics": value}, - sort_keys=True, - separators=(",", ":"), - ensure_ascii=False, - ).encode() - return f"sha256:{hashlib.sha256(payload).hexdigest()}" - - -def _policy_columns() -> None: - for table in ("review_policies", "revision_policies"): - op.add_column(table, sa.Column("policy_generation", sa.Integer())) - op.add_column(table, sa.Column("policy_hash", sa.String(71))) - op.add_column(table, sa.Column("semantics_status", sa.String(24))) - op.add_column(table, sa.Column("supersedes_policy_id", sa.String(36))) - op.create_foreign_key( - f"fk_{table}_supersedes", - table, - table, - ["supersedes_policy_id"], - ["id"], - ) - for name, type_ in ( - ("review_preference_window_seconds", sa.Integer()), - ("review_lease_duration_seconds", sa.Integer()), - ("max_active_review_leases_per_reviewer", sa.Integer()), - ("self_review_allowed", sa.Boolean()), - ("reject_policy", sa.String(32)), - ("finding_evidence_requirement", sa.String(32)), - ): - op.add_column("review_policies", sa.Column(name, type_)) - - -def _backfill_policy_hashes() -> None: - bind = op.get_bind() - review_rows = bind.execute( - sa.text( - "select id,requires_second_review,allowed_decisions,minimum_finding_fields,sla_hours " - "from review_policies" - ) - ).mappings() - for row in review_rows: - value = { - "requires_second_review": row["requires_second_review"], - "allowed_decisions": row["allowed_decisions"], - "minimum_finding_fields": row["minimum_finding_fields"], - "legacy_sla_hours": row["sla_hours"], - } - bind.execute( - sa.text( - "update review_policies set policy_generation=1,policy_hash=:digest," - "semantics_status='legacy_incomplete' where id=:id" - ), - {"id": row["id"], "digest": _digest("workstream.review_policy.legacy.v1", value)}, - ) - revision_rows = bind.execute( - sa.text( - "select id,max_revision_rounds,revision_deadline_hours,auto_reject_after_limit," - "allowed_resubmission_states,reviewer_reassignment_rule from revision_policies" - ) - ).mappings() - for row in revision_rows: - value = { - "max_revision_rounds": row["max_revision_rounds"], - "revision_deadline_hours": row["revision_deadline_hours"], - "legacy_auto_reject_after_limit": row["auto_reject_after_limit"], - "allowed_resubmission_states": row["allowed_resubmission_states"], - "reviewer_reassignment_rule": row["reviewer_reassignment_rule"], - } - bind.execute( - sa.text( - "update revision_policies set policy_generation=1,policy_hash=:digest," - "semantics_status='legacy_incomplete' where id=:id" - ), - {"id": row["id"], "digest": _digest("workstream.revision_policy.legacy.v1", value)}, - ) - - -def _add_lock_columns(table: str, nullable: bool) -> None: - for kind in ("review", "revision"): - op.add_column( - table, sa.Column(f"locked_{kind}_policy_id", sa.String(36), nullable=nullable) - ) - op.add_column( - table, sa.Column(f"locked_{kind}_policy_generation", sa.Integer(), nullable=nullable) - ) - op.add_column( - table, sa.Column(f"locked_{kind}_policy_hash", sa.String(71), nullable=nullable) - ) - - -def _create_immutable_guard(table: str) -> None: - op.execute( - f""" - create function guard_{table}_immutable() returns trigger language plpgsql as $$ - begin - raise exception '{table} rows are immutable' using errcode='55000'; - end $$ - """ - ) - op.execute( - f"create trigger {table}_immutable before update or delete on {table} " - f"for each row execute function guard_{table}_immutable()" - ) - op.execute( - f"create trigger {table}_reject_truncate before truncate on {table} " - f"execute function guard_{table}_immutable()" - ) - - -def upgrade() -> None: - """Move every durable lock to immutable policy identity.""" - _policy_columns() - _backfill_policy_hashes() - for table in ("review_policies", "revision_policies"): - op.alter_column(table, "policy_generation", nullable=False) - op.alter_column(table, "policy_hash", nullable=False) - op.alter_column(table, "semantics_status", nullable=False) - - for name in ( - "selected_review_policy_id", - "selected_review_policy_hash", - "selected_revision_policy_id", - "selected_revision_policy_hash", - ): - op.add_column( - "project_guides", sa.Column(name, sa.String(71 if name.endswith("hash") else 36)) - ) - op.add_column("project_guides", sa.Column("selected_review_policy_generation", sa.Integer())) - op.add_column("project_guides", sa.Column("selected_revision_policy_generation", sa.Integer())) - op.execute( - """ - update project_guides g set - selected_review_policy_id=r.id, - selected_review_policy_generation=r.policy_generation, - selected_review_policy_hash=r.policy_hash, - selected_revision_policy_id=v.id, - selected_revision_policy_generation=v.policy_generation, - selected_revision_policy_hash=v.policy_hash - from review_policies r, revision_policies v - where r.project_id=g.project_id and r.guide_version=g.version - and v.project_id=g.project_id and v.guide_version=g.version - """ - ) - op.execute("set constraints all immediate") - op.create_check_constraint( - "policy_selection_shape", - "project_guides", - "(selected_review_policy_id is null and selected_review_policy_generation is null " - "and selected_review_policy_hash is null and selected_revision_policy_id is null " - "and selected_revision_policy_generation is null and " - "selected_revision_policy_hash is null) or " - "(selected_review_policy_id is not null and " - "selected_review_policy_generation is not null and " - "selected_review_policy_hash is not null and selected_revision_policy_id is not null " - "and selected_revision_policy_generation is not null and " - "selected_revision_policy_hash is not null)", - ) - op.create_check_constraint( - "active_policy_selection_required", - "project_guides", - "status not in ('active','superseded') or " - "(selected_review_policy_id is not null and " - "selected_review_policy_generation is not null and " - "selected_review_policy_hash is not null and selected_revision_policy_id is not null " - "and selected_revision_policy_generation is not null and " - "selected_revision_policy_hash is not null)", - ) - op.execute( - """ - create function guard_project_guide_policy_selection() returns trigger language plpgsql - as $$ begin - if old.status in ('active','superseded') and ( - new.selected_review_policy_id is distinct from old.selected_review_policy_id or - new.selected_review_policy_generation is distinct from - old.selected_review_policy_generation or - new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or - new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or - new.selected_revision_policy_generation is distinct from - old.selected_revision_policy_generation or - new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash - ) then - raise exception 'active guide policy selection is immutable' using errcode='55000'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger project_guides_policy_selection_immutable before update on " - "project_guides for each row execute function guard_project_guide_policy_selection()" - ) - - _add_lock_columns("workstream_tasks", True) - _add_lock_columns("submissions", True) - _add_lock_columns("checker_runs", True) - op.drop_constraint( - "fk_checker_runs_submission_version", "checker_runs", type_="foreignkey" - ) - op.create_unique_constraint( - "uq_submissions_id_task_version", "submissions", ["id", "task_id", "version"] - ) - op.create_foreign_key( - "fk_checker_runs_submission_version", - "checker_runs", - "submissions", - ["submission_id", "task_id", "submission_version"], - ["id", "task_id", "version"], - ) - op.execute( - """ - update workstream_tasks t set - locked_review_policy_id=r.id, - locked_review_policy_generation=r.policy_generation, - locked_review_policy_hash=r.policy_hash, - locked_revision_policy_id=v.id, - locked_revision_policy_generation=v.policy_generation, - locked_revision_policy_hash=v.policy_hash - from review_policies r, revision_policies v - where r.project_id=t.project_id and r.guide_version=t.locked_review_policy_version - and v.project_id=t.project_id and v.guide_version=t.locked_revision_policy_version - """ - ) - op.create_check_constraint( - "review_revision_policy_lock_shape", - "workstream_tasks", - "(locked_review_policy_id is null and locked_review_policy_generation is null " - "and locked_review_policy_hash is null and locked_revision_policy_id is null " - "and locked_revision_policy_generation is null and locked_revision_policy_hash is null) " - "or (locked_review_policy_id is not null and " - "locked_review_policy_generation is not null and locked_review_policy_hash is not null " - "and locked_revision_policy_id is not null and " - "locked_revision_policy_generation is not null and locked_revision_policy_hash is not null)", - ) - op.create_check_constraint( - "review_revision_policy_lock_required", - "workstream_tasks", - "status='draft' or (locked_review_policy_id is not null and " - "locked_review_policy_generation is not null and locked_review_policy_hash is not null " - "and locked_revision_policy_id is not null and " - "locked_revision_policy_generation is not null and locked_revision_policy_hash is not null)", - ) - for table in ("submissions", "checker_runs"): - op.execute( - f""" - update {table} x set - locked_review_policy_id=t.locked_review_policy_id, - locked_review_policy_generation=t.locked_review_policy_generation, - locked_review_policy_hash=t.locked_review_policy_hash, - locked_revision_policy_id=t.locked_revision_policy_id, - locked_revision_policy_generation=t.locked_revision_policy_generation, - locked_revision_policy_hash=t.locked_revision_policy_hash - from workstream_tasks t where t.id=x.task_id - """ - ) - for kind in ("review", "revision"): - op.alter_column(table, f"locked_{kind}_policy_id", nullable=False) - op.alter_column(table, f"locked_{kind}_policy_generation", nullable=False) - op.alter_column(table, f"locked_{kind}_policy_hash", nullable=False) - - for table, prefix in ( - ("submissions", "submissions_task"), - ("checker_runs", "checker_runs_task"), - ): - op.drop_constraint(f"fk_{prefix}_locked_review_policy", table, type_="foreignkey") - op.drop_constraint(f"fk_{prefix}_locked_revision_policy", table, type_="foreignkey") - op.drop_constraint( - "fk_workstream_tasks_locked_review_policy", "workstream_tasks", type_="foreignkey" - ) - op.drop_constraint( - "fk_workstream_tasks_locked_revision_policy", "workstream_tasks", type_="foreignkey" - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_review_policy", "workstream_tasks", type_="unique" - ) - op.drop_constraint( - "uq_workstream_tasks_id_locked_revision_policy", "workstream_tasks", type_="unique" - ) - for table in ("workstream_tasks", "submissions", "checker_runs"): - op.drop_column(table, "locked_review_policy_version") - op.drop_column(table, "locked_revision_policy_version") - - op.drop_constraint("uq_review_policies_project_version", "review_policies", type_="unique") - op.drop_constraint("uq_revision_policies_project_version", "revision_policies", type_="unique") - op.create_unique_constraint( - "uq_review_policies_project_version_generation", - "review_policies", - ["project_id", "guide_version", "policy_generation"], - ) - op.create_unique_constraint( - "uq_revision_policies_project_version_generation", - "revision_policies", - ["project_id", "guide_version", "policy_generation"], - ) - for table, kind in (("review_policies", "review"), ("revision_policies", "revision")): - op.create_unique_constraint( - f"uq_{kind}_policy_lineage", table, ["id", "policy_generation", "policy_hash"] - ) - op.create_unique_constraint( - f"uq_{kind}_policy_scoped_lineage", - table, - ["project_id", "guide_version", "id", "policy_generation", "policy_hash"], - ) - op.create_check_constraint( - f"{kind}_policy_identity_shape", - table, - "policy_generation > 0 and policy_hash ~ '^sha256:[0-9a-f]{64}$' " - "and semantics_status in ('complete','legacy_incomplete')", - ) - op.create_check_constraint( - "review_policy_semantics_shape", - "review_policies", - "(semantics_status='legacy_incomplete') or " - "(review_preference_window_seconds > 0 and review_lease_duration_seconds > 0 " - "and max_active_review_leases_per_reviewer=1 and self_review_allowed=false " - "and reject_policy='close_task' and finding_evidence_requirement in " - "('optional','required_for_blocking','required_for_all'))", - ) - op.create_check_constraint( - "revision_policy_semantics_shape", - "revision_policies", - "(semantics_status='legacy_incomplete') or " - "(max_revision_rounds > 0 and revision_deadline_hours > 0)", - ) - # The backfill updates tables with deferrable lineage constraints. Force - # their queued checks to run before PostgreSQL is asked to ALTER those - # same tables for the new composite foreign keys. - op.execute("set constraints all immediate") - op.create_foreign_key( - "fk_project_guides_selected_review_policy", - "project_guides", - "review_policies", - [ - "project_id", - "version", - "selected_review_policy_id", - "selected_review_policy_generation", - "selected_review_policy_hash", - ], - ["project_id", "guide_version", "id", "policy_generation", "policy_hash"], - ) - op.create_foreign_key( - "fk_project_guides_selected_revision_policy", - "project_guides", - "revision_policies", - [ - "project_id", - "version", - "selected_revision_policy_id", - "selected_revision_policy_generation", - "selected_revision_policy_hash", - ], - ["project_id", "guide_version", "id", "policy_generation", "policy_hash"], - ) - for kind in ("review", "revision"): - op.create_unique_constraint( - f"uq_workstream_tasks_id_locked_{kind}_policy", - "workstream_tasks", - [ - "id", - f"locked_{kind}_policy_id", - f"locked_{kind}_policy_generation", - f"locked_{kind}_policy_hash", - ], - ) - op.create_foreign_key( - f"fk_workstream_tasks_locked_{kind}_policy", - "workstream_tasks", - f"{kind}_policies", - [ - "project_id", - "locked_guide_version", - f"locked_{kind}_policy_id", - f"locked_{kind}_policy_generation", - f"locked_{kind}_policy_hash", - ], - ["project_id", "guide_version", "id", "policy_generation", "policy_hash"], - ) - for table, prefix in ( - ("submissions", "submissions_task"), - ("checker_runs", "checker_runs_task"), - ): - op.create_foreign_key( - f"fk_{prefix}_locked_{kind}_policy", - table, - "workstream_tasks", - [ - "task_id", - f"locked_{kind}_policy_id", - f"locked_{kind}_policy_generation", - f"locked_{kind}_policy_hash", - ], - [ - "id", - f"locked_{kind}_policy_id", - f"locked_{kind}_policy_generation", - f"locked_{kind}_policy_hash", - ], - ) - op.drop_column("review_policies", "sla_hours") - op.drop_column("revision_policies", "auto_reject_after_limit") - _create_immutable_guard("review_policies") - _create_immutable_guard("revision_policies") - - -def downgrade() -> None: - """Restore the obsolete schema only when no policy meaning can be lost.""" - bind = op.get_bind() - for table in ("review_policies", "revision_policies"): - count = bind.execute(sa.text(f"select count(*) from {table}")).scalar_one() - if count: - raise RuntimeError("cannot downgrade populated immutable policy lineage") - op.execute("drop trigger project_guides_policy_selection_immutable on project_guides") - op.execute("drop function guard_project_guide_policy_selection()") - op.drop_constraint( - "review_revision_policy_lock_required", - "workstream_tasks", - type_="check", - ) - op.drop_constraint( - "review_revision_policy_lock_shape", - "workstream_tasks", - type_="check", - ) - op.drop_constraint( - "active_policy_selection_required", - "project_guides", - type_="check", - ) - op.drop_constraint( - "policy_selection_shape", "project_guides", type_="check" - ) - for table in ("review_policies", "revision_policies"): - op.execute(f"drop trigger {table}_reject_truncate on {table}") - op.execute(f"drop trigger {table}_immutable on {table}") - op.execute(f"drop function guard_{table}_immutable()") - - op.add_column("review_policies", sa.Column("sla_hours", sa.Integer())) - op.add_column( - "revision_policies", - sa.Column( - "auto_reject_after_limit", sa.Boolean(), server_default=sa.true(), nullable=False - ), - ) - op.drop_constraint( - "fk_checker_runs_submission_version", "checker_runs", type_="foreignkey" - ) - op.drop_constraint( - "uq_submissions_id_task_version", "submissions", type_="unique" - ) - op.create_foreign_key( - "fk_checker_runs_submission_version", - "checker_runs", - "submissions", - ["submission_id", "submission_version"], - ["id", "version"], - ) - for kind in ("review", "revision"): - for table, prefix in ( - ("submissions", "submissions_task"), - ("checker_runs", "checker_runs_task"), - ): - op.drop_constraint(f"fk_{prefix}_locked_{kind}_policy", table, type_="foreignkey") - op.drop_constraint( - f"fk_workstream_tasks_locked_{kind}_policy", "workstream_tasks", type_="foreignkey" - ) - op.drop_constraint( - f"uq_workstream_tasks_id_locked_{kind}_policy", "workstream_tasks", type_="unique" - ) - op.drop_constraint( - "fk_project_guides_selected_review_policy", "project_guides", type_="foreignkey" - ) - op.drop_constraint( - "fk_project_guides_selected_revision_policy", "project_guides", type_="foreignkey" - ) - for table in ("workstream_tasks", "submissions", "checker_runs"): - op.add_column(table, sa.Column("locked_review_policy_version", sa.String(50))) - op.add_column(table, sa.Column("locked_revision_policy_version", sa.String(50))) - op.execute( - """update workstream_tasks t set locked_review_policy_version=r.guide_version, - locked_revision_policy_version=v.guide_version from review_policies r, revision_policies v - where r.id=t.locked_review_policy_id and v.id=t.locked_revision_policy_id""" - ) - for table in ("submissions", "checker_runs"): - op.execute( - f"""update {table} x set locked_review_policy_version=t.locked_review_policy_version, - locked_revision_policy_version=t.locked_revision_policy_version - from workstream_tasks t where t.id=x.task_id""" - ) - op.alter_column(table, "locked_review_policy_version", nullable=False) - op.alter_column(table, "locked_revision_policy_version", nullable=False) - for table in ("workstream_tasks", "submissions", "checker_runs"): - for kind in ("review", "revision"): - op.drop_column(table, f"locked_{kind}_policy_hash") - op.drop_column(table, f"locked_{kind}_policy_generation") - op.drop_column(table, f"locked_{kind}_policy_id") - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_review_policy", - "workstream_tasks", - ["id", "locked_review_policy_version"], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_locked_revision_policy", - "workstream_tasks", - ["id", "locked_revision_policy_version"], - ) - op.create_unique_constraint( - "uq_review_policies_project_version", - "review_policies", - ["project_id", "guide_version"], - ) - op.create_unique_constraint( - "uq_revision_policies_project_version", - "revision_policies", - ["project_id", "guide_version"], - ) - op.create_foreign_key( - "fk_workstream_tasks_locked_review_policy", - "workstream_tasks", - "review_policies", - ["project_id", "locked_review_policy_version"], - ["project_id", "guide_version"], - ) - op.create_foreign_key( - "fk_workstream_tasks_locked_revision_policy", - "workstream_tasks", - "revision_policies", - ["project_id", "locked_revision_policy_version"], - ["project_id", "guide_version"], - ) - for table, prefix in ( - ("submissions", "submissions_task"), - ("checker_runs", "checker_runs_task"), - ): - for kind in ("review", "revision"): - op.create_foreign_key( - f"fk_{prefix}_locked_{kind}_policy", - table, - "workstream_tasks", - ["task_id", f"locked_{kind}_policy_version"], - ["id", f"locked_{kind}_policy_version"], - ) - for kind in ("review", "revision"): - table = f"{kind}_policies" - op.drop_constraint(f"{kind}_policy_semantics_shape", table, type_="check") - op.drop_constraint(f"{kind}_policy_identity_shape", table, type_="check") - op.drop_constraint(f"uq_{kind}_policy_scoped_lineage", table, type_="unique") - op.drop_constraint(f"uq_{kind}_policy_lineage", table, type_="unique") - op.drop_constraint(f"uq_{kind}_policies_project_version_generation", table, type_="unique") - op.drop_constraint(f"fk_{table}_supersedes", table, type_="foreignkey") - for column in ( - "supersedes_policy_id", - "semantics_status", - "policy_hash", - "policy_generation", - ): - op.drop_column(table, column) - for column in ( - "finding_evidence_requirement", - "reject_policy", - "self_review_allowed", - "max_active_review_leases_per_reviewer", - "review_lease_duration_seconds", - "review_preference_window_seconds", - ): - op.drop_column("review_policies", column) - for column in ( - "selected_revision_policy_hash", - "selected_revision_policy_generation", - "selected_revision_policy_id", - "selected_review_policy_hash", - "selected_review_policy_generation", - "selected_review_policy_id", - ): - op.drop_column("project_guides", column) diff --git a/backend/alembic/versions/0048_review_revision_policy_authority.py b/backend/alembic/versions/0048_review_revision_policy_authority.py deleted file mode 100644 index 4192a66ac..000000000 --- a/backend/alembic/versions/0048_review_revision_policy_authority.py +++ /dev/null @@ -1,413 +0,0 @@ -"""activate authorized review and revision policy mutation - -Revision ID: 0048_policy_authority -Revises: 0047_policy_identity_lineage -Create Date: 2026-08-02 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0048_policy_authority" -down_revision = "0047_policy_identity_lineage" -branch_labels = depends_on = None - - -_PROVENANCE_COLUMNS = ( - ("predecessor_policy_hash", sa.String(71)), - ("created_by_actor_profile_id", sa.String(36)), - ("created_via_identity_link_id", sa.String(36)), - ("created_by_admin_role_grant_id", sa.Uuid()), - ("creation_scope_type", sa.String(16)), - ("creation_scope_project_id", sa.String(36)), - ("creation_action_id", sa.String(160)), - ("authorization_decision_event_id", sa.String(36)), -) - - -def _add_policy_authority(table: str, kind: str) -> None: - for name, type_ in _PROVENANCE_COLUMNS: - op.add_column(table, sa.Column(name, type_)) - op.create_foreign_key( - f"fk_{table}_actor_profile", - table, - "actor_profiles", - ["created_by_actor_profile_id"], - ["id"], - ) - op.create_foreign_key( - f"fk_{table}_identity_link", - table, - "actor_identity_links", - ["created_via_identity_link_id"], - ["id"], - ) - op.create_foreign_key( - f"fk_{table}_admin_grant", - table, - "admin_role_grants", - ["created_by_admin_role_grant_id"], - ["id"], - ) - op.create_foreign_key( - f"fk_{table}_decision_event", - table, - "audit_events", - ["authorization_decision_event_id"], - ["id"], - ) - op.create_check_constraint( - f"{kind}_policy_predecessor_shape", - table, - "(supersedes_policy_id is null and predecessor_policy_hash is null and " - "policy_generation = 1) or (supersedes_policy_id is not null and " - "predecessor_policy_hash ~ '^sha256:[0-9a-f]{64}$' and policy_generation > 1) " - "or semantics_status='legacy_incomplete'", - ) - op.create_check_constraint( - f"{kind}_policy_authority_shape", - table, - "semantics_status='legacy_incomplete' or " - "(created_by_actor_profile_id is not null and " - "created_via_identity_link_id is not null and " - "created_by_admin_role_grant_id is not null and " - "creation_scope_type in ('system','project') and " - f"creation_action_id='project.{kind}_policy.update' and " - "authorization_decision_event_id is not null)", - ) - - -def upgrade() -> None: - """Install one replay ledger and complete policy mutation provenance.""" - op.drop_constraint("policy_selection_shape", "project_guides", type_="check") - op.create_check_constraint( - "policy_selection_shape", - "project_guides", - "((selected_review_policy_id is null and " - "selected_review_policy_generation is null and selected_review_policy_hash is null) or " - "(selected_review_policy_id is not null and " - "selected_review_policy_generation is not null and " - "selected_review_policy_hash is not null)) and " - "((selected_revision_policy_id is null and " - "selected_revision_policy_generation is null and " - "selected_revision_policy_hash is null) or " - "(selected_revision_policy_id is not null and " - "selected_revision_policy_generation is not null and " - "selected_revision_policy_hash is not null))", - ) - _add_policy_authority("review_policies", "review") - _add_policy_authority("revision_policies", "revision") - op.create_table( - "policy_mutation_idempotency_records", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column( - "actor_profile_id", sa.String(36), sa.ForeignKey("actor_profiles.id"), nullable=False - ), - sa.Column( - "identity_link_id", - sa.String(36), - sa.ForeignKey("actor_identity_links.id"), - nullable=False, - ), - sa.Column("action_id", sa.String(160), nullable=False), - sa.Column("idempotency_key", sa.Uuid(), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("policy_hash", sa.String(71), nullable=False), - sa.Column("resource_context_digest", sa.String(71), nullable=False), - sa.Column("operation_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), sa.ForeignKey("projects.id"), nullable=False), - sa.Column("guide_id", sa.String(36), sa.ForeignKey("project_guides.id"), nullable=False), - sa.Column("policy_id", sa.String(36), nullable=False), - sa.Column("policy_generation", sa.Integer(), nullable=False), - sa.Column("status", sa.String(16), nullable=False), - sa.Column("response_json", sa.JSON()), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.Column("committed_at", sa.DateTime(timezone=True)), - sa.UniqueConstraint( - "actor_profile_id", - "action_id", - "idempotency_key", - name="uq_policy_mutation_replay_namespace", - ), - sa.UniqueConstraint("operation_id", name="uq_policy_mutation_operation_identity"), - sa.CheckConstraint( - "action_id in ('project.review_policy.update','project.revision_policy.update')", - name="ck_policy_mutation_action", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$' and " - "policy_hash ~ '^sha256:[0-9a-f]{64}$' and " - "resource_context_digest ~ '^sha256:[0-9a-f]{64}$'", - name="ck_policy_mutation_digests", - ), - sa.CheckConstraint("policy_generation > 0", name="ck_policy_mutation_generation"), - sa.CheckConstraint("status in ('pending','committed')", name="ck_policy_mutation_status"), - sa.CheckConstraint( - "(status='pending' and response_json is null and committed_at is null) or " - "(status='committed' and response_json is not null and committed_at is not null)", - name="ck_policy_mutation_state_shape", - ), - ) - op.create_index( - "ix_policy_mutation_custody_lookup", - "policy_mutation_idempotency_records", - ["policy_id", "action_id", "policy_generation", "status"], - ) - op.execute( - """ - create function guard_policy_mutation_replay() returns trigger language plpgsql as $$ - begin - if tg_op='INSERT' then - if new.status<>'pending' then - raise exception 'policy mutation must begin pending' using errcode='23514'; - end if; - return new; - elsif tg_op='DELETE' then - raise exception 'policy mutation replay is immutable' using errcode='55000'; - elsif new is not distinct from old then - return new; - elsif old.status='pending' and new.status='committed' - and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, - new.idempotency_key,new.request_digest,new.policy_hash, - new.resource_context_digest, - new.operation_id,new.project_id,new.guide_id,new.policy_id, - new.policy_generation,new.created_at) - is not distinct from - (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, - old.idempotency_key,old.request_digest,old.policy_hash, - old.resource_context_digest, - old.operation_id,old.project_id,old.guide_id,old.policy_id, - old.policy_generation,old.created_at) then - return new; - end if; - raise exception 'policy mutation replay is immutable' using errcode='23514'; - end $$ - """ - ) - op.execute( - "create trigger policy_mutation_replay_immutable before insert or update or delete " - "on policy_mutation_idempotency_records for each row " - "execute function guard_policy_mutation_replay()" - ) - op.execute( - """ - create function reject_policy_mutation_replay_truncate() returns trigger - language plpgsql as $$ begin - raise exception 'policy mutation replay is immutable' using errcode='55000'; - end $$ - """ - ) - op.execute( - "create trigger policy_mutation_replay_reject_truncate before truncate " - "on policy_mutation_idempotency_records " - "execute function reject_policy_mutation_replay_truncate()" - ) - op.execute( - """ - create function validate_policy_mutation_custody() returns trigger language plpgsql as $$ - declare reservation policy_mutation_idempotency_records%rowtype; - evidence audit_events%rowtype; - actor_id text; link_id text; grant_id uuid; action_value text; - scope_type text; scope_project text; decision_id text; - product_project text; product_guide text; product_id text; - product_generation integer; - product_hash text; predecessor_id text; predecessor_hash text; - selector_id text; selector_generation integer; selector_hash text; - predecessor_valid boolean; - begin - if tg_table_name='policy_mutation_idempotency_records' then - select * into reservation from policy_mutation_idempotency_records where id=new.id; - if reservation.status<>'committed' then - raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; - end if; - if reservation.action_id='project.review_policy.update' then - select created_by_actor_profile_id,created_via_identity_link_id, - created_by_admin_role_grant_id,creation_action_id, - creation_scope_type,creation_scope_project_id, - authorization_decision_event_id,p.project_id,g.id,p.id, - p.policy_generation,p.policy_hash,p.supersedes_policy_id, - p.predecessor_policy_hash,g.selected_review_policy_id, - g.selected_review_policy_generation,g.selected_review_policy_hash - into actor_id,link_id,grant_id,action_value,scope_type,scope_project, - decision_id,product_project,product_guide,product_id,product_generation, - product_hash,predecessor_id,predecessor_hash,selector_id, - selector_generation,selector_hash - from review_policies p join project_guides g - on g.project_id=p.project_id and g.version=p.guide_version - where p.id=reservation.policy_id and g.id=reservation.guide_id; - else - select created_by_actor_profile_id,created_via_identity_link_id, - created_by_admin_role_grant_id,creation_action_id, - creation_scope_type,creation_scope_project_id, - authorization_decision_event_id,p.project_id,g.id,p.id, - p.policy_generation,p.policy_hash,p.supersedes_policy_id, - p.predecessor_policy_hash,g.selected_revision_policy_id, - g.selected_revision_policy_generation,g.selected_revision_policy_hash - into actor_id,link_id,grant_id,action_value,scope_type,scope_project, - decision_id,product_project,product_guide,product_id,product_generation, - product_hash,predecessor_id,predecessor_hash,selector_id, - selector_generation,selector_hash - from revision_policies p join project_guides g - on g.project_id=p.project_id and g.version=p.guide_version - where p.id=reservation.policy_id and g.id=reservation.guide_id; - end if; - else - actor_id:=new.created_by_actor_profile_id; - link_id:=new.created_via_identity_link_id; - grant_id:=new.created_by_admin_role_grant_id; - action_value:=new.creation_action_id; - scope_type:=new.creation_scope_type; - scope_project:=new.creation_scope_project_id; - decision_id:=new.authorization_decision_event_id; - product_project:=new.project_id; product_id:=new.id; - product_generation:=new.policy_generation; product_hash:=new.policy_hash; - predecessor_id:=new.supersedes_policy_id; - predecessor_hash:=new.predecessor_policy_hash; - if tg_table_name='review_policies' then - select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, - g.selected_review_policy_hash - into product_guide,selector_id,selector_generation,selector_hash - from project_guides g - where g.project_id=new.project_id and g.version=new.guide_version; - else - select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, - g.selected_revision_policy_hash - into product_guide,selector_id,selector_generation,selector_hash - from project_guides g - where g.project_id=new.project_id and g.version=new.guide_version; - end if; - select r.* into reservation from policy_mutation_idempotency_records r - where r.policy_id=new.id and r.action_id=new.creation_action_id - and r.policy_generation=new.policy_generation and r.status='committed'; - end if; - if reservation.id is null or product_id is null - or reservation.actor_profile_id is distinct from actor_id - or reservation.identity_link_id is distinct from link_id - or reservation.action_id is distinct from action_value - or reservation.project_id is distinct from product_project - or reservation.guide_id is distinct from product_guide - or reservation.policy_id is distinct from product_id - or reservation.policy_generation is distinct from product_generation - or reservation.policy_hash is distinct from product_hash - or selector_id is distinct from product_id - or selector_generation is distinct from product_generation - or selector_hash is distinct from product_hash - or scope_type not in ('system','project') - or (scope_type='project' and scope_project is distinct from product_project) - or (scope_type='system' and scope_project is not null) then - raise exception 'policy mutation custody mismatch' using errcode='23514'; - end if; - if product_generation=1 then - predecessor_valid:=predecessor_id is null and predecessor_hash is null; - elsif reservation.action_id='project.review_policy.update' then - select exists(select 1 from review_policies prior - where prior.id=predecessor_id and prior.project_id=product_project - and prior.guide_version=(select version from project_guides where id=product_guide) - and prior.policy_generation=product_generation-1 - and prior.policy_hash=predecessor_hash) into predecessor_valid; - else - select exists(select 1 from revision_policies prior - where prior.id=predecessor_id and prior.project_id=product_project - and prior.guide_version=(select version from project_guides where id=product_guide) - and prior.policy_generation=product_generation-1 - and prior.policy_hash=predecessor_hash) into predecessor_valid; - end if; - if predecessor_valid is not true then - raise exception 'policy mutation lineage mismatch' using errcode='23514'; - end if; - select * into evidence from audit_events where id=decision_id; - if evidence.id is null or evidence.event_domain is distinct from 'authority' - or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' - or evidence.denial_code is not null - or evidence.actor_ref_kind is distinct from 'actor_profile' - or evidence.actor_id is distinct from actor_id - or evidence.matched_grant_id is distinct from grant_id::text - or evidence.permission_id is distinct from 'project.review_policy.manage' - or evidence.action_id is distinct from action_value - or evidence.resource_type is distinct from 'project' - or evidence.resource_id is distinct from product_project - or evidence.target_ref_kind is distinct from 'project' - or evidence.target_ref_id is distinct from product_project - or evidence.after_facts->>'allowed' is distinct from 'true' - or evidence.after_facts->>'resource_context_digest' - is distinct from reservation.resource_context_digest then - raise exception 'policy mutation evidence mismatch' using errcode='23514'; - end if; - return null; - end $$ - """ - ) - for name, table in ( - ("review_policy_mutation_custody", "review_policies"), - ("revision_policy_mutation_custody", "revision_policies"), - ("policy_mutation_replay_custody", "policy_mutation_idempotency_records"), - ): - op.execute( - f"create constraint trigger {name} after insert or update on {table} " - "deferrable initially deferred for each row " - "execute function validate_policy_mutation_custody()" - ) - - -def downgrade() -> None: - """Remove 02B authority state while preserving 02A policy lineage.""" - bind = op.get_bind() - for table in ( - "policy_mutation_idempotency_records", - "review_policies", - "revision_policies", - ): - bind.execute(sa.text(f"lock table {table} in share row exclusive mode")) - has_custody = bool( - bind.scalar( - sa.text( - "select exists(select 1 from policy_mutation_idempotency_records) or " - "exists(select 1 from review_policies where creation_action_id=" - "'project.review_policy.update') or exists(select 1 from revision_policies " - "where creation_action_id='project.revision_policy.update')" - ) - ) - ) - if has_custody: - raise RuntimeError("cannot downgrade populated policy mutation authority") - for name, table in ( - ("review_policy_mutation_custody", "review_policies"), - ("revision_policy_mutation_custody", "revision_policies"), - ("policy_mutation_replay_custody", "policy_mutation_idempotency_records"), - ): - op.execute(f"drop trigger {name} on {table}") - op.execute("drop function validate_policy_mutation_custody()") - op.execute( - "drop trigger policy_mutation_replay_reject_truncate on policy_mutation_idempotency_records" - ) - op.execute("drop function reject_policy_mutation_replay_truncate()") - op.execute( - "drop trigger policy_mutation_replay_immutable on policy_mutation_idempotency_records" - ) - op.execute("drop function guard_policy_mutation_replay()") - op.drop_table("policy_mutation_idempotency_records") - for table, kind in (("revision_policies", "revision"), ("review_policies", "review")): - op.drop_constraint(f"{kind}_policy_authority_shape", table, type_="check") - op.drop_constraint(f"{kind}_policy_predecessor_shape", table, type_="check") - for suffix in ("decision_event", "admin_grant", "identity_link", "actor_profile"): - op.drop_constraint(f"fk_{table}_{suffix}", table, type_="foreignkey") - for name, _type in reversed(_PROVENANCE_COLUMNS): - op.drop_column(table, name) - op.drop_constraint("policy_selection_shape", "project_guides", type_="check") - op.create_check_constraint( - "policy_selection_shape", - "project_guides", - "(selected_review_policy_id is null and selected_review_policy_generation is null " - "and selected_review_policy_hash is null and selected_revision_policy_id is null " - "and selected_revision_policy_generation is null and " - "selected_revision_policy_hash is null) or (selected_review_policy_id is not null " - "and selected_review_policy_generation is not null and " - "selected_review_policy_hash is not null and selected_revision_policy_id is not null " - "and selected_revision_policy_generation is not null and " - "selected_revision_policy_hash is not null)", - ) diff --git a/backend/alembic/versions/0049_rev_auth_readiness.py b/backend/alembic/versions/0049_rev_auth_readiness.py deleted file mode 100644 index 33c45582f..000000000 --- a/backend/alembic/versions/0049_rev_auth_readiness.py +++ /dev/null @@ -1,157 +0,0 @@ -"""register unavailable REV authorization actions and service identities - -Revision ID: 0049_rev_auth_readiness -Revises: 0048_policy_authority -Create Date: 2026-08-03 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0049_rev_auth_readiness" -down_revision = "0048_policy_authority" -branch_labels = depends_on = None - -_ACTIONS = ( - ("review.revision_context.repair", "project.task.manage"), - ("review.revision_obligation.close", "project.task.manage"), - ("review.revision_context.legacy_close", "operations.reconcile.run"), - ("review.lifecycle.activation.manage", "operations.reconcile.run"), -) -_HISTORICAL_IDENTITIES = ( - "workstream.artifact.verifier", - "workstream.artifact.put_resolver", - "workstream.artifact.scheduler", - "workstream.artifact.binding", - "workstream.artifact.guide_reader", - "workstream.artifact.materializer", - "workstream.artifact.checker_output", - "workstream.project.setup", -) -_REV_IDENTITIES = ( - "workstream.review.preference_expiry", - "workstream.review.lease_expiry", - "workstream.review.authority_invalidation_reconciliation", - "workstream.review.reconciliation", - "workstream.review.artifact_reference_reconciliation", - "workstream.review.projection", -) - - -def _action_definition() -> str: - return ( - op.get_bind() - .execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authorization_action_evidence'" - ) - ) - .scalar_one() - ) - - -def _replace_action_definition(definition: str) -> None: - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authorization_action_evidence {definition}" - ) - - -def _pair_token(action: str, permission: str) -> str: - return ( - f"(((action_id)::text = '{action}'::text) AND " - f"((permission_id)::text = '{permission}'::text))" - ) - - -def _rewrite_action_registry(*, add: bool) -> None: - definition = _action_definition() - additions = " OR " + " OR ".join(_pair_token(*pair) for pair in _ACTIONS) - marker = _pair_token("review.projection.rebuild", "operations.projection.rebuild") - if add: - if definition.count(marker) != 2 or any( - _pair_token(*pair) in definition for pair in _ACTIONS - ): - raise RuntimeError("unexpected REV authorization action registry definition") - definition = definition.replace(marker, marker + additions) - else: - if definition.count(additions) != 2: - raise RuntimeError("unexpected REV authorization action registry definition") - definition = definition.replace(additions, "") - _replace_action_definition(definition) - - -def _identity_tokens(values: tuple[str, ...]) -> str: - return ",".join(f"'{value}'" for value in values) - - -def _replace_identity_constraint(values: tuple[str, ...]) -> None: - op.drop_constraint("kind_service_identity", "actor_profiles", type_="check") - op.create_check_constraint( - "kind_service_identity", - "actor_profiles", - "(actor_kind='human' and service_identity is null) or " - f"(actor_kind='service' and service_identity in ({_identity_tokens(values)}))", - ) - - -def _lock_protected_state() -> None: - bind = op.get_bind() - bind.execute(sa.text("lock table authority_idempotency_records in share row exclusive mode")) - bind.execute(sa.text("lock table audit_events in access exclusive mode")) - bind.execute(sa.text("lock table actor_profiles in access exclusive mode")) - - -def _has_action_evidence() -> bool: - actions = [action for action, _ in _ACTIONS] - return bool( - op.get_bind() - .execute( - sa.text( - "select exists(select 1 from audit_events where action_id = any(:actions)) or " - "exists(select 1 from authority_idempotency_records record " - "join audit_events event on event.idempotency_reference=record.id " - "where event.action_id = any(:actions))" - ), - {"actions": actions}, - ) - .scalar_one() - ) - - -def _has_rev_service_identity() -> bool: - return bool( - op.get_bind() - .execute( - sa.text( - "select exists(select 1 from actor_profiles " - "where service_identity = any(:identities))" - ), - {"identities": list(_REV_IDENTITIES)}, - ) - .scalar_one() - ) - - -def upgrade() -> None: - """Register unavailable REV authority without creating any principal.""" - _lock_protected_state() - _rewrite_action_registry(add=True) - _replace_identity_constraint((*_HISTORICAL_IDENTITIES, *_REV_IDENTITIES)) - - -def downgrade() -> None: - """Restore 0048 only when no new action or identity has been used.""" - _lock_protected_state() - if _has_action_evidence(): - raise RuntimeError("cannot downgrade non-empty REV authorization action evidence") - if _has_rev_service_identity(): - raise RuntimeError("cannot downgrade in-use REV service identities") - _rewrite_action_registry(add=False) - _replace_identity_constraint(_HISTORICAL_IDENTITIES) diff --git a/backend/alembic/versions/0050_guide_source_v2_cutover.py b/backend/alembic/versions/0050_guide_source_v2_cutover.py deleted file mode 100644 index 930c5f7b9..000000000 --- a/backend/alembic/versions/0050_guide_source_v2_cutover.py +++ /dev/null @@ -1,247 +0,0 @@ -"""cut guide source declarations to verified ART identity - -Revision ID: 0050_guide_source_v2 -Revises: 0049_rev_auth_readiness -Create Date: 2026-08-02 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0050_guide_source_v2" -down_revision = "0049_rev_auth_readiness" -branch_labels = depends_on = None - - -def _refuse_populated(message: str) -> None: - bind = op.get_bind() - populated = bind.execute( - sa.text( - "select exists(select 1 from guide_source_snapshots) " - "or exists(select 1 from guide_source_snapshot_items)" - ) - ).scalar_one() - if populated: - raise RuntimeError(message) - - -def upgrade() -> None: - """Install the v2 declaration only on an empty clean-cut namespace.""" - _refuse_populated( - "guide source v2 requires an empty guide-source namespace; " - "reingest authoritative bytes through verified ART custody" - ) - op.drop_constraint( - "uq_guide_source_snapshot_items_snapshot_kind_ref", - "guide_source_snapshot_items", - type_="unique", - ) - op.alter_column( - "guide_source_snapshot_items", - "durable_ref", - new_column_name="source_label", - existing_type=sa.Text(), - existing_nullable=False, - ) - op.drop_column("guide_source_snapshot_items", "content_cid") - op.drop_column("guide_source_snapshot_items", "content_hash") - op.create_unique_constraint( - "uq_guide_source_snapshot_items_snapshot_order", - "guide_source_snapshot_items", - ["source_snapshot_id", "item_order"], - ) - op.drop_constraint( - "uq_guide_sufficiency_reports_source_snapshot", - "guide_sufficiency_reports", - type_="unique", - ) - op.create_index( - "uq_guide_sufficiency_reports_verified_snapshot", - "guide_sufficiency_reports", - ["source_snapshot_id"], - unique=True, - postgresql_where=sa.text("project_setup_run_id is not null"), - ) - op.create_index( - "uq_guide_sufficiency_reports_diagnostic_snapshot", - "guide_sufficiency_reports", - ["source_snapshot_id"], - unique=True, - postgresql_where=sa.text("project_setup_run_id is null"), - ) - op.add_column( - "project_setup_runs", - sa.Column("continuation_verification_job_id", sa.String(36)), - ) - op.add_column( - "project_setup_runs", - sa.Column("continuation_started_at", sa.DateTime(timezone=True)), - ) - op.create_foreign_key( - "fk_project_setup_runs_continuation_verification_job", - "project_setup_runs", - "artifact_verification_jobs", - ["continuation_verification_job_id"], - ["id"], - ) - op.create_index( - "ix_project_setup_runs_continuation_verification_job_id", - "project_setup_runs", - ["continuation_verification_job_id"], - ) - op.drop_constraint( - op.f("ck_project_setup_runs_ck_project_setup_runs_status"), - "project_setup_runs", - type_="check", - ) - op.create_check_constraint( - op.f("ck_project_setup_runs_ck_project_setup_runs_status"), - "project_setup_runs", - "status in ('queued','dispatch_pending','enqueue_failed'," - "'running_sufficiency_agent','sufficiency_blocked'," - "'running_policy_derivation_agent','policy_draft_ready'," - "'running_post_submit_derivation_agent','post_submit_setup_blocked'," - "'post_submit_policy_compiled','setup_blocked','failed')", - ) - op.execute( - """ - create or replace function validate_guide_source_snapshot_items() returns trigger - language plpgsql as $$ - declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; - begin - select snapshot.manifest_json::jsonb->'items' into expected - from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; - if expected is null then - raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; - end if; - select coalesce(jsonb_agg(jsonb_build_object( - 'item_id',id,'item_order',item_order,'source_kind',source_kind, - 'source_label',source_label,'ingestion_adapter',ingestion_adapter, - 'media_type',media_type) order by item_order),'[]'::jsonb) - into actual from guide_source_snapshot_items - where source_snapshot_id=new.source_snapshot_id; - if actual is distinct from expected then - raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; - end if; - select r.* into reservation from guide_mutation_idempotency_records r - join guide_source_snapshots s on s.id=r.resource_id - where s.id=new.source_snapshot_id - and r.action_id='project.guide_source_snapshot.create' - and r.operation_generation=s.creation_generation and r.status='committed'; - if reservation.id is null then - raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; - end if; - return null; - end $$ - """ - ) - - -def downgrade() -> None: - """Refuse to fabricate legacy byte identity from v2 declarations.""" - # This must precede restoration of the NOT NULL legacy byte-identity columns. - _refuse_populated( - "guide source v2 downgrade requires empty guide-source tables; " - "legacy caller byte identity cannot be reconstructed" - ) - op.drop_constraint( - op.f("ck_project_setup_runs_ck_project_setup_runs_status"), - "project_setup_runs", - type_="check", - ) - op.create_check_constraint( - op.f("ck_project_setup_runs_ck_project_setup_runs_status"), - "project_setup_runs", - "status in ('queued','enqueue_failed','running_sufficiency_agent'," - "'sufficiency_blocked','running_policy_derivation_agent','policy_draft_ready'," - "'running_post_submit_derivation_agent','post_submit_setup_blocked'," - "'post_submit_policy_compiled','setup_blocked','failed')", - ) - op.drop_index( - "ix_project_setup_runs_continuation_verification_job_id", - table_name="project_setup_runs", - ) - op.drop_constraint( - "fk_project_setup_runs_continuation_verification_job", - "project_setup_runs", - type_="foreignkey", - ) - op.drop_column("project_setup_runs", "continuation_started_at") - op.drop_column("project_setup_runs", "continuation_verification_job_id") - op.drop_index( - "uq_guide_sufficiency_reports_diagnostic_snapshot", - table_name="guide_sufficiency_reports", - ) - op.drop_index( - "uq_guide_sufficiency_reports_verified_snapshot", - table_name="guide_sufficiency_reports", - ) - op.create_unique_constraint( - "uq_guide_sufficiency_reports_source_snapshot", - "guide_sufficiency_reports", - ["source_snapshot_id"], - ) - op.drop_constraint( - "uq_guide_source_snapshot_items_snapshot_order", - "guide_source_snapshot_items", - type_="unique", - ) - op.add_column( - "guide_source_snapshot_items", - sa.Column("content_hash", sa.String(71), nullable=False), - ) - op.add_column( - "guide_source_snapshot_items", - sa.Column("content_cid", sa.String(200)), - ) - op.alter_column( - "guide_source_snapshot_items", - "source_label", - new_column_name="durable_ref", - existing_type=sa.Text(), - existing_nullable=False, - ) - op.create_unique_constraint( - "uq_guide_source_snapshot_items_snapshot_kind_ref", - "guide_source_snapshot_items", - ["source_snapshot_id", "source_kind", "durable_ref"], - ) - op.execute( - """ - create or replace function validate_guide_source_snapshot_items() returns trigger - language plpgsql as $$ - declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; - begin - select jsonb_agg(item.value - 'content_excerpt' order by item.ordinality) - into expected - from guide_source_snapshots snapshot, - jsonb_array_elements(snapshot.manifest_json::jsonb->'items') - with ordinality as item(value, ordinality) - where snapshot.id=new.source_snapshot_id; - if expected is null then - raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; - end if; - select coalesce(jsonb_agg(jsonb_build_object( - 'source_kind',source_kind,'durable_ref',durable_ref, - 'ingestion_adapter',ingestion_adapter,'content_hash',content_hash, - 'content_cid',content_cid,'media_type',media_type) order by item_order),'[]'::jsonb) - into actual from guide_source_snapshot_items - where source_snapshot_id=new.source_snapshot_id; - if actual is distinct from expected then - raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; - end if; - select r.* into reservation from guide_mutation_idempotency_records r - join guide_source_snapshots s on s.id=r.resource_id - where s.id=new.source_snapshot_id - and r.action_id='project.guide_source_snapshot.create' - and r.operation_generation=s.creation_generation and r.status='committed'; - if reservation.id is null then - raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; - end if; - return null; - end $$ - """ - ) diff --git a/backend/alembic/versions/0051_review_queue_foundation.py b/backend/alembic/versions/0051_review_queue_foundation.py deleted file mode 100644 index 72c2ff724..000000000 --- a/backend/alembic/versions/0051_review_queue_foundation.py +++ /dev/null @@ -1,410 +0,0 @@ -"""add hidden review queue and admission idempotency persistence - -Revision ID: 0051_review_queue_foundation -Revises: 0050_guide_source_v2 -Create Date: 2026-08-03 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0051_review_queue_foundation" -down_revision = "0050_guide_source_v2" -branch_labels = depends_on = None - - -def _create_queue_table() -> None: - op.create_table( - "review_queue_entries", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=False), - sa.Column("submission_id", sa.String(36), nullable=False), - sa.Column("submission_version", sa.Integer(), nullable=False), - sa.Column("admitting_checker_run_id", sa.String(36), nullable=False), - sa.Column("queue_state", sa.String(16), server_default="pending", nullable=False), - sa.Column("routing_mode", sa.String(16), nullable=False), - sa.Column("routing_reason", sa.String(32), nullable=False), - sa.Column( - "first_queued_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column( - "available_since", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column("preferred_reviewer_id", sa.String(36)), - sa.Column("preference_expires_at", sa.DateTime(timezone=True)), - sa.Column("closed_at", sa.DateTime(timezone=True)), - sa.Column("closed_reason", sa.String(32)), - sa.Column("routing_generation", sa.Integer(), server_default="1", nullable=False), - sa.Column("lifecycle_generation", sa.Integer(), server_default="1", nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.CheckConstraint( - "submission_version > 0", - name="ck_review_queue_entries_submission_version_positive", - ), - sa.CheckConstraint( - "queue_state in ('pending','closed')", - name="ck_review_queue_entries_queue_state", - ), - sa.CheckConstraint( - "routing_mode in ('open','preferred')", - name="ck_review_queue_entries_routing_mode", - ), - sa.CheckConstraint( - "routing_reason in ('first_submission','revision_return','admin_assignment')", - name="ck_review_queue_entries_routing_reason", - ), - sa.CheckConstraint( - "(routing_mode='open' and preferred_reviewer_id is null " - "and preference_expires_at is null) or " - "(routing_mode='preferred' and preferred_reviewer_id is not null " - "and preference_expires_at is not null " - "and preference_expires_at > first_queued_at)", - name="ck_review_queue_entries_routing_shape", - ), - sa.CheckConstraint( - "(queue_state='pending' and closed_at is null and closed_reason is null) or " - "(queue_state='closed' and closed_at is not null and " - "closed_reason in ('review_recorded','task_closed','admin_cancelled') " - "and closed_at >= first_queued_at)", - name="ck_review_queue_entries_lifecycle_shape", - ), - sa.CheckConstraint( - "available_since >= first_queued_at", - name="ck_review_queue_entries_availability_time", - ), - sa.CheckConstraint( - "routing_generation > 0 and lifecycle_generation > 0", - name="ck_review_queue_entries_generations_positive", - ), - sa.ForeignKeyConstraint( - ["project_id"], ["projects.id"], name="fk_review_queue_project" - ), - sa.ForeignKeyConstraint( - ["task_id"], - ["workstream_tasks.id"], - name="fk_review_queue_task", - ), - sa.ForeignKeyConstraint( - ["submission_id"], - ["submissions.id"], - name="fk_review_queue_submission", - ), - sa.ForeignKeyConstraint( - ["submission_id", "task_id", "submission_version"], - ["submissions.id", "submissions.task_id", "submissions.version"], - name="fk_review_queue_submission_lineage", - ), - sa.ForeignKeyConstraint( - ["admitting_checker_run_id"], - ["checker_runs.id"], - name="fk_review_queue_checker", - ), - sa.ForeignKeyConstraint( - ["preferred_reviewer_id"], - ["actor_profiles.id"], - name="fk_review_queue_preferred_reviewer", - ), - sa.PrimaryKeyConstraint("id", name="pk_review_queue_entries"), - sa.UniqueConstraint("submission_id", name="uq_review_queue_submission"), - sa.UniqueConstraint( - "id", - "project_id", - "task_id", - "submission_id", - "submission_version", - "admitting_checker_run_id", - name="uq_review_queue_admission_identity", - ), - ) - op.create_index( - "ix_review_queue_selection", - "review_queue_entries", - ["project_id", "queue_state", "routing_mode", "first_queued_at", "id"], - ) - op.create_index( - "ix_review_queue_preference", - "review_queue_entries", - ["preferred_reviewer_id", "queue_state", "preference_expires_at", "id"], - ) - - -def _create_admission_table() -> None: - op.create_table( - "review_admission_idempotency_records", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("idempotency_key", sa.Uuid(), nullable=False), - sa.Column("operation_id", sa.Uuid(), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=False), - sa.Column("submission_id", sa.String(36), nullable=False), - sa.Column("submission_version", sa.Integer(), nullable=False), - sa.Column("admitting_checker_run_id", sa.String(36), nullable=False), - sa.Column("status", sa.String(16), server_default="pending", nullable=False), - sa.Column("review_queue_entry_id", sa.Uuid()), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column("committed_at", sa.DateTime(timezone=True)), - sa.CheckConstraint( - "submission_version > 0", - name="ck_review_admission_idempotency_records_submission_version_positive", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$'", - name="ck_review_admission_idempotency_records_request_digest", - ), - sa.CheckConstraint( - "status in ('pending','committed')", - name="ck_review_admission_idempotency_records_status", - ), - sa.CheckConstraint( - "(status='pending' and review_queue_entry_id is null and committed_at is null) or " - "(status='committed' and review_queue_entry_id is not null " - "and committed_at is not null)", - name="ck_review_admission_idempotency_records_state_shape", - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name="fk_review_admission_project", - ), - sa.ForeignKeyConstraint( - ["task_id"], - ["workstream_tasks.id"], - name="fk_review_admission_task", - ), - sa.ForeignKeyConstraint( - ["submission_id"], - ["submissions.id"], - name="fk_review_admission_submission", - ), - sa.ForeignKeyConstraint( - ["submission_id", "task_id", "submission_version"], - ["submissions.id", "submissions.task_id", "submissions.version"], - name="fk_review_admission_submission_lineage", - ), - sa.ForeignKeyConstraint( - ["admitting_checker_run_id"], - ["checker_runs.id"], - name="fk_review_admission_checker", - ), - sa.ForeignKeyConstraint( - ["review_queue_entry_id"], - ["review_queue_entries.id"], - name="fk_review_admission_queue", - ), - sa.ForeignKeyConstraint( - [ - "review_queue_entry_id", - "project_id", - "task_id", - "submission_id", - "submission_version", - "admitting_checker_run_id", - ], - [ - "review_queue_entries.id", - "review_queue_entries.project_id", - "review_queue_entries.task_id", - "review_queue_entries.submission_id", - "review_queue_entries.submission_version", - "review_queue_entries.admitting_checker_run_id", - ], - name="fk_review_admission_committed_queue", - ), - sa.PrimaryKeyConstraint("id", name="pk_review_admission_idempotency_records"), - sa.UniqueConstraint( - "idempotency_key", name="uq_review_admission_replay_key" - ), - sa.UniqueConstraint("operation_id", name="uq_review_admission_operation"), - sa.UniqueConstraint( - "admitting_checker_run_id", name="uq_review_admission_checker_run" - ), - ) - op.create_index( - "ix_review_admission_submission", - "review_admission_idempotency_records", - ["submission_id", "status", "created_at", "id"], - ) - - -def _create_guards() -> None: - op.execute( - """ - create function guard_review_queue_entry() returns trigger language plpgsql as $$ - declare - task_project text; - checker_row checker_runs%rowtype; - begin - if tg_op='DELETE' then - raise exception 'review queue entries cannot be deleted' using errcode='55000'; - end if; - if tg_op='INSERT' then - if new.queue_state <> 'pending' then - raise exception 'review queue must begin pending' using errcode='23514'; - end if; - new.first_queued_at := statement_timestamp(); - new.available_since := new.first_queued_at; - new.routing_generation := 1; - new.lifecycle_generation := 1; - new.created_at := new.first_queued_at; - end if; - if tg_op='UPDATE' then - if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, - new.admitting_checker_run_id,new.first_queued_at,new.created_at) - is distinct from - (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, - old.admitting_checker_run_id,old.first_queued_at,old.created_at) then - raise exception 'review queue identity is immutable' using errcode='55000'; - end if; - if old.queue_state='closed' and new.queue_state <> 'closed' then - raise exception 'closed review queue entries cannot reopen' using errcode='23514'; - end if; - if new.routing_generation < old.routing_generation - or new.lifecycle_generation < old.lifecycle_generation then - raise exception 'review queue generations cannot decrease' using errcode='23514'; - end if; - return new; - end if; - select project_id into task_project from workstream_tasks where id=new.task_id; - if task_project is null or task_project <> new.project_id then - raise exception 'review queue task project mismatch' using errcode='23514'; - end if; - select * into checker_row from checker_runs where id=new.admitting_checker_run_id; - if not found or checker_row.task_id <> new.task_id - or checker_row.submission_id <> new.submission_id - or checker_row.submission_version <> new.submission_version then - raise exception 'review queue checker lineage mismatch' using errcode='23514'; - end if; - if checker_row.status <> 'completed' - or checker_row.routing_recommendation <> 'allow_review' - or checker_row.is_current_for_submission is not true then - raise exception 'review queue checker is not admissible' using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger review_queue_entries_guard before insert or update or delete " - "on review_queue_entries for each row execute function guard_review_queue_entry()" - ) - op.execute( - """ - create function guard_review_admission_record() returns trigger language plpgsql as $$ - declare - task_project text; - checker_row checker_runs%rowtype; - begin - if tg_op='DELETE' then - raise exception 'review admission records cannot be deleted' using errcode='55000'; - end if; - if tg_op='INSERT' and new.status <> 'pending' then - raise exception 'review admission must begin pending' using errcode='23514'; - end if; - if tg_op='INSERT' then - new.created_at := statement_timestamp(); - end if; - if tg_op='UPDATE' then - if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, - new.task_id,new.submission_id,new.submission_version, - new.admitting_checker_run_id,new.created_at) - is distinct from - (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, - old.task_id,old.submission_id,old.submission_version, - old.admitting_checker_run_id,old.created_at) then - raise exception 'review admission identity is immutable' using errcode='55000'; - end if; - if old.status <> 'pending' or new.status <> 'committed' then - raise exception 'invalid review admission transition' using errcode='23514'; - end if; - end if; - select project_id into task_project from workstream_tasks where id=new.task_id; - if task_project is null or task_project <> new.project_id then - raise exception 'review admission task project mismatch' using errcode='23514'; - end if; - select * into checker_row from checker_runs where id=new.admitting_checker_run_id; - if not found or checker_row.task_id <> new.task_id - or checker_row.submission_id <> new.submission_id - or checker_row.submission_version <> new.submission_version then - raise exception 'review admission checker lineage mismatch' using errcode='23514'; - end if; - if new.status='committed' and ( - checker_row.status <> 'completed' - or checker_row.routing_recommendation <> 'allow_review' - or checker_row.is_current_for_submission is not true) then - raise exception 'review admission checker is not admissible' using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger review_admission_records_guard before insert or update or delete " - "on review_admission_idempotency_records for each row " - "execute function guard_review_admission_record()" - ) - op.execute( - """ - create function reject_review_queue_foundation_truncate() returns trigger - language plpgsql as $$ - begin - raise exception 'review queue foundation cannot be truncated' using errcode='55000'; - end $$ - """ - ) - for table in ("review_queue_entries", "review_admission_idempotency_records"): - op.execute( - f"create trigger {table}_reject_truncate before truncate on {table} " - "execute function reject_review_queue_foundation_truncate()" - ) - - -def upgrade() -> None: - """Install empty hidden REV persistence without admitting historical work.""" - _create_queue_table() - _create_admission_table() - _create_guards() - - -def downgrade() -> None: - """Remove only an unused queue foundation; never discard review history.""" - bind = op.get_bind() - bind.execute(sa.text("lock table review_admission_idempotency_records in access exclusive mode")) - bind.execute(sa.text("lock table review_queue_entries in access exclusive mode")) - populated = bind.execute( - sa.text( - "select exists(select 1 from review_queue_entries) or " - "exists(select 1 from review_admission_idempotency_records)" - ) - ).scalar_one() - if populated: - raise RuntimeError("cannot downgrade populated review queue foundation") - for table in ("review_admission_idempotency_records", "review_queue_entries"): - op.execute(f"drop trigger {table}_reject_truncate on {table}") - op.execute("drop trigger review_admission_records_guard on review_admission_idempotency_records") - op.execute("drop function guard_review_admission_record()") - op.execute("drop trigger review_queue_entries_guard on review_queue_entries") - op.execute("drop function guard_review_queue_entry()") - op.execute("drop function reject_review_queue_foundation_truncate()") - op.drop_table("review_admission_idempotency_records") - op.drop_table("review_queue_entries") diff --git a/backend/alembic/versions/0052_legacy_intake_removal.py b/backend/alembic/versions/0052_legacy_intake_removal.py deleted file mode 100644 index afee9b6b5..000000000 --- a/backend/alembic/versions/0052_legacy_intake_removal.py +++ /dev/null @@ -1,343 +0,0 @@ -"""remove the inactive multi-step contributor artifact intake - -Revision ID: 0052_legacy_intake_removal -Revises: 0051_review_queue_foundation -Create Date: 2026-08-04 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0052_legacy_intake_removal" -down_revision = "0051_review_queue_foundation" -branch_labels = depends_on = None - - -_PUT_PRODUCER_REFERENCE = ( - "(producer_request_type = 'guide' and guide_source_item_id is not null " - "and checker_run_id is null and task_id is null and logical_role is null) or " - "(producer_request_type = 'checker_output' and guide_source_item_id is null " - "and checker_run_id is not null and task_id is not null " - "and octet_length(logical_role) between 1 and 100)" -) -_PUT_PRODUCER_IDENTITY = ( - "((producer_request_type = 'guide' and producer_type = 'actor_profile' and " - "producer_ref ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-" - "[89ab][0-9a-f]{3}-[0-9a-f]{12}$') or " - "(producer_request_type = 'checker_output' and producer_type = 'service_identity' " - "and producer_ref = 'workstream.artifact.checker_output'))" -) -_LEGACY_PUT_PRODUCER_IDENTITY = ( - "((producer_request_type in ('guide', 'contributor') and " - "producer_type = 'actor_profile' and producer_ref ~ " - "'^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-" - "[89ab][0-9a-f]{3}-[0-9a-f]{12}$') or " - "(producer_request_type = 'checker_output' and producer_type = 'service_identity' " - "and producer_ref = 'workstream.artifact.checker_output'))" -) -_LEGACY_PUT_PRODUCER_REFERENCE = ( - "(producer_request_type = 'guide' and guide_source_item_id is not null " - "and upload_item_id is null and checker_run_id is null and task_id is null " - "and logical_role is null) or " - "(producer_request_type = 'contributor' and guide_source_item_id is null " - "and upload_item_id is not null and checker_run_id is null and task_id is not null " - "and logical_role is null) or " - "(producer_request_type = 'checker_output' and guide_source_item_id is null " - "and upload_item_id is null and checker_run_id is not null and task_id is not null " - "and octet_length(logical_role) between 1 and 100)" -) -_RECEIPT_PRODUCER_REFERENCE = ( - "contract_version = 2 and put_attempt_id is not null and " - "((guide_source_item_id is not null)::int + " - "(checker_run_id is not null)::int) = 1" -) -_LEGACY_RECEIPT_PRODUCER_REFERENCE = ( - "(contract_version = 1 and put_attempt_id is null and upload_item_id is not null " - "and guide_source_item_id is null and checker_run_id is null) or " - "(contract_version = 2 and put_attempt_id is not null and " - "((upload_item_id is not null)::int + (guide_source_item_id is not null)::int + " - "(checker_run_id is not null)::int) = 1)" -) - - -def _lock_and_refuse_populated_legacy_intake() -> None: - bind = op.get_bind() - bind.execute( - sa.text( - "lock table artifact_upload_sessions, artifact_upload_items, " - "artifact_put_attempts, artifact_operation_receipts in access exclusive mode" - ) - ) - populated = bind.execute( - sa.text( - "select exists(select 1 from artifact_upload_sessions) " - "or exists(select 1 from artifact_upload_items) " - "or exists(select 1 from artifact_put_attempts " - "where producer_request_type = 'contributor' or upload_item_id is not null) " - "or exists(select 1 from artifact_operation_receipts " - "where contract_version = 1 or upload_item_id is not null)" - ) - ).scalar_one() - if populated: - raise RuntimeError( - "legacy contributor artifact intake is populated; preserve the existing " - "schema and use a separately approved maintenance migration" - ) - - -def upgrade() -> None: - """Remove only a proven-empty legacy contributor intake.""" - _lock_and_refuse_populated_legacy_intake() - - op.drop_constraint("producer_reference", "artifact_put_attempts", type_="check") - op.drop_constraint("producer_identity", "artifact_put_attempts", type_="check") - op.drop_constraint("producer_request_type", "artifact_put_attempts", type_="check") - op.drop_constraint("contract_producer_reference", "artifact_operation_receipts", type_="check") - op.drop_constraint( - "fk_artifact_put_attempts_upload_item_id_artifact_upload_items", - "artifact_put_attempts", - type_="foreignkey", - ) - op.drop_constraint( - "fk_artifact_operation_receipts_upload_item_id_artifact__cc40", - "artifact_operation_receipts", - type_="foreignkey", - ) - op.drop_index("ix_artifact_put_attempts_upload_item_id", table_name="artifact_put_attempts") - op.drop_index( - "ix_artifact_operation_receipts_upload_item_id", - table_name="artifact_operation_receipts", - ) - op.drop_column("artifact_put_attempts", "upload_item_id") - op.drop_column("artifact_operation_receipts", "upload_item_id") - op.alter_column( - "artifact_operation_receipts", - "put_attempt_id", - existing_type=sa.String(length=36), - nullable=False, - ) - op.create_check_constraint( - "producer_request_type", - "artifact_put_attempts", - "producer_request_type in ('guide', 'checker_output')", - ) - op.create_check_constraint("producer_identity", "artifact_put_attempts", _PUT_PRODUCER_IDENTITY) - op.create_check_constraint( - "producer_reference", "artifact_put_attempts", _PUT_PRODUCER_REFERENCE - ) - op.create_check_constraint( - "contract_producer_reference", - "artifact_operation_receipts", - _RECEIPT_PRODUCER_REFERENCE, - ) - op.drop_table("artifact_upload_items") - op.drop_table("artifact_upload_sessions") - - -def downgrade() -> None: - """Recreate the exact empty legacy schema without fabricating lineage.""" - bind = op.get_bind() - bind.execute( - sa.text( - "lock table artifact_put_attempts, artifact_operation_receipts in access exclusive mode" - ) - ) - if bind.execute( - sa.text( - "select exists(select 1 from artifact_put_attempts " - "where producer_request_type = 'contributor') " - "or exists(select 1 from artifact_operation_receipts where contract_version = 1)" - ) - ).scalar_one(): - raise RuntimeError("cannot truthfully recreate legacy contributor intake") - - op.create_table( - "artifact_upload_sessions", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("actor_id", sa.String(100), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=True), - sa.Column("guide_id", sa.String(36), nullable=True), - sa.Column("permitted_roles", sa.JSON(), nullable=False), - sa.Column("state", sa.String(30), nullable=False), - sa.Column("maximum_bytes", sa.Integer(), nullable=False), - sa.Column("current_bytes", sa.Integer(), nullable=False), - sa.Column("reserved_bytes", sa.Integer(), nullable=False), - sa.Column("maximum_items", sa.Integer(), nullable=False), - sa.Column("current_items", sa.Integer(), nullable=False), - sa.Column("reserved_items", sa.Integer(), nullable=False), - sa.Column("artifact_set_hash", sa.String(71), nullable=True), - sa.Column("expires_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("consumed_at", sa.DateTime(timezone=True), nullable=True), - sa.Column("cas_version", sa.Integer(), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], ondelete="RESTRICT"), - sa.CheckConstraint( - "state in ('open', 'sealed', 'consumed', 'expired', 'cancelled')", name="state" - ), - sa.CheckConstraint( - "maximum_bytes >= 0 and current_bytes >= 0 and reserved_bytes >= 0", - name="byte_counts_nonnegative", - ), - sa.CheckConstraint( - "maximum_items >= 0 and current_items >= 0 and reserved_items >= 0", - name="item_counts_nonnegative", - ), - sa.CheckConstraint("current_bytes + reserved_bytes <= maximum_bytes", name="byte_limit"), - sa.CheckConstraint("current_items + reserved_items <= maximum_items", name="item_limit"), - sa.CheckConstraint("cas_version >= 0", name="cas_nonnegative"), - sa.CheckConstraint( - "artifact_set_hash is null or artifact_set_hash ~ '^sha256:[0-9a-f]{64}$'", - name="artifact_set_hash_shape", - ), - sa.CheckConstraint( - "(state = 'consumed') = (consumed_at is not null)", name="consumed_timestamp" - ), - sa.CheckConstraint( - "state not in ('sealed', 'consumed') or artifact_set_hash is not null", - name="sealed_hash_required", - ), - ) - for column in ("actor_id", "project_id", "task_id", "guide_id", "state"): - op.create_index( - f"ix_artifact_upload_sessions_{column}", - "artifact_upload_sessions", - [column], - ) - - op.create_table( - "artifact_upload_items", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("session_id", sa.String(36), nullable=False), - sa.Column("logical_role", sa.String(100), nullable=False), - sa.Column("display_name", sa.String(500), nullable=False), - sa.Column("media_type", sa.String(200), nullable=True), - sa.Column("reserved_bytes", sa.Integer(), nullable=False), - sa.Column("expected_sha256", sa.String(71), nullable=True), - sa.Column("expected_size", sa.Integer(), nullable=True), - sa.Column("idempotency_key", sa.String(200), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("state", sa.String(30), nullable=False), - sa.Column("cas_version", sa.Integer(), nullable=False), - sa.Column("provider_object_ref", sa.String(1024), nullable=True), - sa.Column("content_id", sa.String(36), nullable=True), - sa.Column("error_code", sa.String(100), nullable=True), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.Column( - "updated_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.ForeignKeyConstraint( - ["session_id"], ["artifact_upload_sessions.id"], ondelete="CASCADE" - ), - sa.ForeignKeyConstraint(["content_id"], ["artifact_contents.id"], ondelete="RESTRICT"), - sa.UniqueConstraint("session_id", "idempotency_key", name="uq_artifact_item_operation"), - sa.CheckConstraint( - "state in ('reserved', 'uploading', 'replay_required', " - "'stored_pending_verification', 'ready', 'failed', 'cancelled')", - name="state", - ), - sa.CheckConstraint( - "reserved_bytes >= 0 and cas_version >= 0 and " - "(expected_size is null or expected_size >= 0)", - name="counts_nonnegative", - ), - sa.CheckConstraint("request_digest ~ '^sha256:[0-9a-f]{64}$'", name="request_digest_shape"), - sa.CheckConstraint( - "expected_sha256 is null or expected_sha256 ~ '^sha256:[0-9a-f]{64}$'", - name="expected_sha256_shape", - ), - sa.CheckConstraint( - "((state in ('stored_pending_verification', 'ready')) and content_id is not null " - "and provider_object_ref is not null) or " - "((state not in ('stored_pending_verification', 'ready')) and content_id is null " - "and provider_object_ref is null)", - name="stored_result_required", - ), - sa.CheckConstraint( - "state != 'failed' or error_code is not null", name="failed_error_required" - ), - ) - for column in ("session_id", "content_id", "state"): - op.create_index(f"ix_artifact_upload_items_{column}", "artifact_upload_items", [column]) - - op.drop_constraint("producer_reference", "artifact_put_attempts", type_="check") - op.drop_constraint("producer_identity", "artifact_put_attempts", type_="check") - op.drop_constraint("producer_request_type", "artifact_put_attempts", type_="check") - op.drop_constraint("contract_producer_reference", "artifact_operation_receipts", type_="check") - op.alter_column( - "artifact_operation_receipts", - "put_attempt_id", - existing_type=sa.String(length=36), - nullable=True, - ) - op.add_column( - "artifact_put_attempts", sa.Column("upload_item_id", sa.String(36), nullable=True) - ) - op.add_column( - "artifact_operation_receipts", - sa.Column("upload_item_id", sa.String(36), nullable=True), - ) - op.create_foreign_key( - "fk_artifact_put_attempts_upload_item_id_artifact_upload_items", - "artifact_put_attempts", - "artifact_upload_items", - ["upload_item_id"], - ["id"], - ondelete="RESTRICT", - ) - op.create_foreign_key( - "fk_artifact_operation_receipts_upload_item_id_artifact__cc40", - "artifact_operation_receipts", - "artifact_upload_items", - ["upload_item_id"], - ["id"], - ondelete="RESTRICT", - ) - op.create_index( - "ix_artifact_put_attempts_upload_item_id", - "artifact_put_attempts", - ["upload_item_id"], - ) - op.create_index( - "ix_artifact_operation_receipts_upload_item_id", - "artifact_operation_receipts", - ["upload_item_id"], - ) - op.create_check_constraint( - "producer_request_type", - "artifact_put_attempts", - "producer_request_type in ('guide', 'contributor', 'checker_output')", - ) - op.create_check_constraint( - "producer_identity", "artifact_put_attempts", _LEGACY_PUT_PRODUCER_IDENTITY - ) - op.create_check_constraint( - "producer_reference", "artifact_put_attempts", _LEGACY_PUT_PRODUCER_REFERENCE - ) - op.create_check_constraint( - "contract_producer_reference", - "artifact_operation_receipts", - _LEGACY_RECEIPT_PRODUCER_REFERENCE, - ) diff --git a/backend/alembic/versions/0053_project_compensation_adapter_bindings.py b/backend/alembic/versions/0053_project_compensation_adapter_bindings.py deleted file mode 100644 index 90474cc88..000000000 --- a/backend/alembic/versions/0053_project_compensation_adapter_bindings.py +++ /dev/null @@ -1,140 +0,0 @@ -"""add project compensation adapter-binding persistence - -Revision ID: 0053_compensation_bindings -Revises: 0052_legacy_intake_removal -Create Date: 2026-08-04 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0053_compensation_bindings" -down_revision = "0052_legacy_intake_removal" -branch_labels = depends_on = None - - -def upgrade() -> None: - op.create_table( - "project_compensation_adapter_bindings", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("instrument_type", sa.String(32), nullable=False), - sa.Column("adapter_actor_id", sa.String(36), nullable=False), - sa.Column("route_key", sa.String(120), nullable=False), - sa.Column("status", sa.String(16), server_default="active", nullable=False), - sa.Column("binding_lifecycle_version", sa.Integer(), server_default="1", nullable=False), - sa.Column("created_by", sa.String(36), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column("suspended_by", sa.String(36)), - sa.Column("suspended_at", sa.DateTime(timezone=True)), - sa.Column("retired_by", sa.String(36)), - sa.Column("retired_at", sa.DateTime(timezone=True)), - sa.CheckConstraint( - "instrument_type in ('money','project_points')", - name="ck_project_compensation_adapter_bindings_instrument_type", - ), - sa.CheckConstraint( - "route_key ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'", - name="ck_project_compensation_adapter_bindings_route_key", - ), - sa.CheckConstraint( - "route_key not like '%..%'", - name="ck_project_compensation_adapter_bindings_route_key_no_traversal", - ), - sa.CheckConstraint( - "status in ('active','suspended','retired')", - name="ck_project_compensation_adapter_bindings_status", - ), - sa.CheckConstraint( - "binding_lifecycle_version > 0", - name="ck_project_compensation_adapter_bindings_lifecycle_version_positive", - ), - sa.CheckConstraint( - "status='active' and binding_lifecycle_version=1 " - "and suspended_by is null and suspended_at is null " - "and retired_by is null and retired_at is null", - name="ck_project_compensation_adapter_bindings_lifecycle_shape", - ), - sa.CheckConstraint( - "(suspended_at is null or suspended_at >= created_at) and " - "(retired_at is null or retired_at >= created_at) and " - "(retired_at is null or suspended_at is null or retired_at >= suspended_at)", - name="ck_project_compensation_adapter_bindings_lifecycle_timestamps", - ), - sa.ForeignKeyConstraint( - ["project_id"], ["projects.id"], name="fk_compensation_binding_project" - ), - sa.ForeignKeyConstraint( - ["adapter_actor_id"], - ["actor_profiles.id"], - name="fk_compensation_binding_adapter_actor", - ), - sa.ForeignKeyConstraint( - ["created_by"], ["actor_profiles.id"], name="fk_compensation_binding_created_by" - ), - sa.ForeignKeyConstraint( - ["suspended_by"], ["actor_profiles.id"], name="fk_compensation_binding_suspended_by" - ), - sa.ForeignKeyConstraint( - ["retired_by"], ["actor_profiles.id"], name="fk_compensation_binding_retired_by" - ), - sa.PrimaryKeyConstraint("id", name="pk_project_compensation_adapter_bindings"), - sa.UniqueConstraint( - "id", "project_id", "instrument_type", name="uq_compensation_binding_ownership" - ), - ) - op.create_index( - "uq_compensation_binding_active_project_instrument", - "project_compensation_adapter_bindings", - ["project_id", "instrument_type"], - unique=True, - postgresql_where=sa.text("status='active'"), - ) - op.create_index( - "ix_compensation_binding_adapter_actor", - "project_compensation_adapter_bindings", - ["adapter_actor_id", "status", "id"], - ) - op.execute( - """ - create function enforce_compensation_binding_lifecycle() returns trigger - language plpgsql as $$ - begin - raise exception 'compensation_binding_updates_deferred'; - return new; - end; - $$; - """ - ) - op.execute( - """ - create trigger project_compensation_binding_update_guard - before update on project_compensation_adapter_bindings - for each row execute function enforce_compensation_binding_lifecycle(); - """ - ) - - -def downgrade() -> None: - op.execute( - "drop trigger project_compensation_binding_update_guard " - "on project_compensation_adapter_bindings" - ) - op.execute("drop function enforce_compensation_binding_lifecycle()") - op.drop_index( - "ix_compensation_binding_adapter_actor", - table_name="project_compensation_adapter_bindings", - ) - op.drop_index( - "uq_compensation_binding_active_project_instrument", - table_name="project_compensation_adapter_bindings", - ) - op.drop_table("project_compensation_adapter_bindings") diff --git a/backend/alembic/versions/0054_guide_sufficiency_authority.py b/backend/alembic/versions/0054_guide_sufficiency_authority.py deleted file mode 100644 index bc8aa4a0e..000000000 --- a/backend/alembic/versions/0054_guide_sufficiency_authority.py +++ /dev/null @@ -1,318 +0,0 @@ -"""activate durable guide-sufficiency authorization custody - -Revision ID: 0054_guide_sufficiency_authority -Revises: 0053_compensation_bindings -Create Date: 2026-08-03 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0054_guide_sufficiency_authority" -down_revision = "0053_compensation_bindings" -branch_labels = depends_on = None - -_CREATION_COLUMNS = ( - ("created_by_actor_profile_id", sa.String(36)), - ("created_via_identity_link_id", sa.String(36)), - ("created_by_admin_role_grant_id", sa.Uuid()), - ("created_by_service_identity", sa.String(160)), - ("creation_scope_type", sa.String(16)), - ("creation_scope_project_id", sa.String(36)), - ("creation_action_id", sa.String(160)), - ("authorization_decision_event_id", sa.String(36)), -) -_ACK_COLUMNS = ( - ("warnings_acknowledged_by_actor_profile_id", sa.String(36)), - ("warnings_acknowledged_via_identity_link_id", sa.String(36)), - ("warnings_acknowledged_by_admin_role_grant_id", sa.Uuid()), - ("warning_acknowledgement_scope_type", sa.String(16)), - ("warning_acknowledgement_scope_project_id", sa.String(36)), - ("warning_acknowledgement_action_id", sa.String(160)), - ("warning_acknowledgement_decision_event_id", sa.String(36)), -) - - -def upgrade() -> None: - """Install replay and complete authorization provenance shapes.""" - op.drop_constraint( - "ck_project_setup_runs_status", "project_setup_runs", type_="check" - ) - op.create_check_constraint( - "ck_project_setup_runs_status", - "project_setup_runs", - "status in ('queued','dispatch_pending','enqueue_failed'," - "'enqueue_identity_mismatch'," - "'running_sufficiency_agent','sufficiency_blocked'," - "'running_policy_derivation_agent','policy_draft_ready'," - "'running_post_submit_derivation_agent','post_submit_setup_blocked'," - "'post_submit_policy_compiled','setup_blocked','failed')", - ) - for name, column_type in (*_CREATION_COLUMNS, *_ACK_COLUMNS): - op.add_column("guide_sufficiency_reports", sa.Column(name, column_type)) - for constraint, name, remote_table, remote_column in ( - ("fk_suff_create_actor", "created_by_actor_profile_id", "actor_profiles", "id"), - ("fk_suff_create_link", "created_via_identity_link_id", "actor_identity_links", "id"), - ("fk_suff_create_grant", "created_by_admin_role_grant_id", "admin_role_grants", "id"), - ("fk_suff_create_project", "creation_scope_project_id", "projects", "id"), - ("fk_suff_create_decision", "authorization_decision_event_id", "audit_events", "id"), - ("fk_suff_ack_actor", "warnings_acknowledged_by_actor_profile_id", "actor_profiles", "id"), - ( - "fk_suff_ack_link", - "warnings_acknowledged_via_identity_link_id", - "actor_identity_links", - "id", - ), - ( - "fk_suff_ack_grant", - "warnings_acknowledged_by_admin_role_grant_id", - "admin_role_grants", - "id", - ), - ("fk_suff_ack_project", "warning_acknowledgement_scope_project_id", "projects", "id"), - ("fk_suff_ack_decision", "warning_acknowledgement_decision_event_id", "audit_events", "id"), - ): - op.create_foreign_key( - constraint, - "guide_sufficiency_reports", - remote_table, - [name], - [remote_column], - ) - op.create_check_constraint( - op.f("ck_guide_sufficiency_creation_authority_shape"), - "guide_sufficiency_reports", - "(created_by_actor_profile_id is null and created_via_identity_link_id is null " - "and created_by_admin_role_grant_id is null and created_by_service_identity is null " - "and creation_scope_type is null and creation_scope_project_id is null " - "and creation_action_id is null and authorization_decision_event_id is null) or " - "(created_by_actor_profile_id is not null and created_via_identity_link_id is not null " - "and creation_scope_project_id is not null and creation_action_id in " - "('project.guide_sufficiency_report.create','project.guide_sufficiency.run') " - "and authorization_decision_event_id is not null and " - "((created_by_admin_role_grant_id is not null and created_by_service_identity is null " - "and creation_scope_type in ('system','project')) or " - "(created_by_admin_role_grant_id is null " - "and created_by_service_identity = 'workstream.project.setup' " - "and creation_scope_type = 'service' " - "and creation_action_id = 'project.guide_sufficiency.run' " - "and project_setup_run_id is not null and setup_generation is not null " - "and agent_material_sha256 is not null and agent_material_byte_count is not null)))", - ) - op.create_check_constraint( - op.f("ck_guide_sufficiency_ack_authority_shape"), - "guide_sufficiency_reports", - "(warnings_acknowledged_by_actor_profile_id is null " - "and warnings_acknowledged_via_identity_link_id is null " - "and warnings_acknowledged_by_admin_role_grant_id is null " - "and warning_acknowledgement_scope_type is null " - "and warning_acknowledgement_scope_project_id is null " - "and warning_acknowledgement_action_id is null " - "and warning_acknowledgement_decision_event_id is null) or " - "(warnings_acknowledged_by_actor_profile_id is not null " - "and warnings_acknowledged_via_identity_link_id is not null " - "and warnings_acknowledged_by_admin_role_grant_id is not null " - "and warning_acknowledgement_scope_type in ('system','project') " - "and warning_acknowledgement_scope_project_id is not null " - "and warning_acknowledgement_action_id = " - "'project.guide_sufficiency.warnings.acknowledge' " - "and warning_acknowledgement_decision_event_id is not null)", - ) - op.create_table( - "guide_sufficiency_mutation_idempotency_records", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column( - "actor_profile_id", - sa.String(36), - sa.ForeignKey("actor_profiles.id"), - nullable=False, - ), - sa.Column( - "identity_link_id", - sa.String(36), - sa.ForeignKey("actor_identity_links.id"), - nullable=False, - ), - sa.Column("action_id", sa.String(160), nullable=False), - sa.Column("idempotency_key", sa.Uuid(), nullable=False), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("resource_context_digest", sa.String(71), nullable=False), - sa.Column("operation_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), sa.ForeignKey("projects.id"), nullable=False), - sa.Column("guide_id", sa.String(36), sa.ForeignKey("project_guides.id"), nullable=False), - sa.Column( - "source_snapshot_id", - sa.String(36), - sa.ForeignKey("guide_source_snapshots.id"), - nullable=False, - ), - sa.Column("report_id", sa.String(36), sa.ForeignKey("guide_sufficiency_reports.id")), - sa.Column("setup_run_id", sa.String(36), sa.ForeignKey("project_setup_runs.id")), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("status", sa.String(16), nullable=False), - sa.Column("response_json", sa.JSON()), - sa.Column( - "created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False - ), - sa.Column("committed_at", sa.DateTime(timezone=True)), - sa.UniqueConstraint( - "actor_profile_id", - "idempotency_key", - name="uq_sufficiency_mutation_replay_namespace", - ), - sa.UniqueConstraint("operation_id", name="uq_sufficiency_mutation_operation_identity"), - sa.CheckConstraint( - "action_id in ('project.guide_sufficiency_report.create'," - "'project.guide_sufficiency.run'," - "'project.guide_sufficiency.warnings.acknowledge')", - name="ck_sufficiency_mutation_action", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$' and " - "resource_context_digest ~ '^sha256:[0-9a-f]{64}$'", - name="ck_sufficiency_mutation_digests", - ), - sa.CheckConstraint("setup_generation > 0", name="ck_sufficiency_mutation_generation"), - sa.CheckConstraint( - "status in ('pending','committed')", name="ck_sufficiency_mutation_status" - ), - sa.CheckConstraint( - "(status='pending' and response_json is null and committed_at is null) or " - "(status='committed' and response_json is not null and committed_at is not null " - "and ((action_id='project.guide_sufficiency.run' " - "and (setup_run_id is not null or report_id is not null)) " - "or (action_id<>'project.guide_sufficiency.run' and report_id is not null)))", - name="ck_sufficiency_mutation_state_shape", - ), - ) - op.execute( - """ - create function reject_sufficiency_replay_mutation() returns trigger - language plpgsql as $$ - begin - if tg_op = 'DELETE' then - raise exception 'guide sufficiency replay rows are append-only'; - end if; - if old.status = 'committed' or new.status <> 'committed' - or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, - new.idempotency_key,new.request_digest, - new.resource_context_digest, - new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, - new.setup_run_id,new.setup_generation,new.created_at) - is distinct from - (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, - old.idempotency_key,old.request_digest, - old.resource_context_digest, - old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, - old.setup_run_id,old.setup_generation,old.created_at) - then - raise exception 'invalid guide sufficiency replay mutation'; - end if; - return new; - end $$ - """ - ) - op.execute( - """ - create trigger trg_sufficiency_replay_immutable - before update or delete on guide_sufficiency_mutation_idempotency_records - for each row execute function reject_sufficiency_replay_mutation() - """ - ) - op.execute( - """ - create function reject_sufficiency_replay_truncate() returns trigger - language plpgsql as $$ - begin - raise exception 'guide sufficiency replay rows are append-only'; - end $$ - """ - ) - op.execute( - """ - create trigger trg_sufficiency_replay_no_truncate - before truncate on guide_sufficiency_mutation_idempotency_records - for each statement execute function reject_sufficiency_replay_truncate() - """ - ) - - -def downgrade() -> None: - """Remove 12E authority only when no activated evidence exists.""" - connection = op.get_bind() - replay_count = connection.execute( - sa.text("select count(*) from guide_sufficiency_mutation_idempotency_records") - ).scalar_one() - provenance_count = connection.execute( - sa.text( - "select count(*) from guide_sufficiency_reports where " - "created_by_actor_profile_id is not null or " - "warnings_acknowledged_by_actor_profile_id is not null" - ) - ).scalar_one() - identity_mismatch_count = connection.execute( - sa.text( - "select count(*) from project_setup_runs " - "where status = 'enqueue_identity_mismatch'" - ) - ).scalar_one() - if replay_count or provenance_count or identity_mismatch_count: - raise RuntimeError("cannot downgrade guide sufficiency authority with evidence") - op.drop_constraint( - "ck_project_setup_runs_status", "project_setup_runs", type_="check" - ) - op.create_check_constraint( - "ck_project_setup_runs_status", - "project_setup_runs", - "status in ('queued','dispatch_pending','enqueue_failed'," - "'running_sufficiency_agent'," - "'sufficiency_blocked','running_policy_derivation_agent','policy_draft_ready'," - "'running_post_submit_derivation_agent','post_submit_setup_blocked'," - "'post_submit_policy_compiled','setup_blocked','failed')", - ) - op.execute( - "drop trigger trg_sufficiency_replay_no_truncate " - "on guide_sufficiency_mutation_idempotency_records" - ) - op.execute("drop function reject_sufficiency_replay_truncate()") - op.execute( - "drop trigger trg_sufficiency_replay_immutable on guide_sufficiency_mutation_idempotency_records" - ) - op.execute("drop function reject_sufficiency_replay_mutation()") - op.drop_table("guide_sufficiency_mutation_idempotency_records") - op.drop_constraint( - op.f("ck_guide_sufficiency_ack_authority_shape"), - "guide_sufficiency_reports", - type_="check", - ) - op.drop_constraint( - op.f("ck_guide_sufficiency_creation_authority_shape"), - "guide_sufficiency_reports", - type_="check", - ) - foreign_keys = { - "created_by_actor_profile_id": "fk_suff_create_actor", - "created_via_identity_link_id": "fk_suff_create_link", - "created_by_admin_role_grant_id": "fk_suff_create_grant", - "creation_scope_project_id": "fk_suff_create_project", - "authorization_decision_event_id": "fk_suff_create_decision", - "warnings_acknowledged_by_actor_profile_id": "fk_suff_ack_actor", - "warnings_acknowledged_via_identity_link_id": "fk_suff_ack_link", - "warnings_acknowledged_by_admin_role_grant_id": "fk_suff_ack_grant", - "warning_acknowledgement_scope_project_id": "fk_suff_ack_project", - "warning_acknowledgement_decision_event_id": "fk_suff_ack_decision", - } - columns_without_foreign_keys = { - "created_by_service_identity", - "creation_scope_type", - "creation_action_id", - "warning_acknowledgement_scope_type", - "warning_acknowledgement_action_id", - } - for name, _ in reversed((*_CREATION_COLUMNS, *_ACK_COLUMNS)): - if name not in columns_without_foreign_keys: - op.drop_constraint(foreign_keys[name], "guide_sufficiency_reports", type_="foreignkey") - op.drop_column("guide_sufficiency_reports", name) diff --git a/backend/alembic/versions/0055_contribution_policy.py b/backend/alembic/versions/0055_contribution_policy.py deleted file mode 100644 index 49a481bc1..000000000 --- a/backend/alembic/versions/0055_contribution_policy.py +++ /dev/null @@ -1,627 +0,0 @@ -"""add contribution-policy persistence - -Revision ID: 0055_contribution_policy -Revises: 0054_guide_sufficiency_authority -Create Date: 2026-08-04 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0055_contribution_policy" -down_revision = "0054_guide_sufficiency_authority" -branch_labels = depends_on = None - -# SIX is the ISO 4217 Maintenance Agency. Snapshot: List One, 2026-08-04. -ISO_4217_CURRENCY_CODES = tuple( - """AED AFN ALL AMD AOA ARS AUD AWG AZN BAM BBD BDT BHD BIF BMD BND BOB BOV - BRL BSD BTN BWP BYN BZD CAD CDF CHE CHF CHW CLF CLP CNY COP COU CRC CUP CVE - CZK DJF DKK DOP DZD EGP ERN ETB EUR FJD FKP GBP GEL GHS GIP GMD GNF GTQ GYD - HKD HNL HTG HUF IDR ILS INR IQD IRR ISK JMD JOD JPY KES KGS KHR KMF KPW - KRW KWD KYD KZT LAK LBP LKR LRD LSL LYD MAD MDL MGA MKD MMK MNT MOP MRU - MUR MVR MWK MXN MXV MYR MZN NAD NGN NIO NOK NPR NZD OMR PAB PEN PGK PHP PKR - PLN PYG QAR RON RSD RUB RWF SAR SBD SCR SDG SEK SGD SHP SLE SOS SRD SSP STN - SVC SYP SZL THB TJS TMT TND TOP TRY TTD TWD TZS UAH UGX USD USN UYI UYU - UYW UZS VED VES VND VUV WST XAD XAF XAG XAU XBA XBB XBC XBD XCD XCG XDR - XOF XPD XPF XPT XSU XTS XUA XXX YER ZAR ZMW ZWG""".split() -) - - -def upgrade() -> None: - op.create_table( - "contribution_policies", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("name", sa.String(200), nullable=False), - sa.Column("status", sa.String(16), server_default="draft", nullable=False), - sa.Column("current_published_version_id", sa.Uuid()), - sa.Column("created_by", sa.String(36), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column("retired_by", sa.String(36)), - sa.Column("retired_at", sa.DateTime(timezone=True)), - sa.CheckConstraint( - "status in ('draft','active','retired')", - name="status", - ), - sa.CheckConstraint( - "char_length(btrim(name)) between 1 and 200", - name="name", - ), - sa.CheckConstraint( - "(status='draft' and current_published_version_id is null " - "and retired_by is null and retired_at is null) or " - "(status='active' and current_published_version_id is not null " - "and retired_by is null and retired_at is null) or " - "(status='retired' and current_published_version_id is not null " - "and retired_by is not null and retired_at is not null)", - name="lifecycle_shape", - ), - sa.CheckConstraint( - "retired_at is null or retired_at >= created_at", - name="retirement_timestamp", - ), - sa.ForeignKeyConstraint( - ["project_id"], ["projects.id"], name="fk_contribution_policy_project" - ), - sa.ForeignKeyConstraint( - ["created_by"], ["actor_profiles.id"], name="fk_contribution_policy_created_by" - ), - sa.ForeignKeyConstraint( - ["retired_by"], ["actor_profiles.id"], name="fk_contribution_policy_retired_by" - ), - sa.PrimaryKeyConstraint("id", name="pk_contribution_policies"), - sa.UniqueConstraint("id", "project_id", name="uq_contribution_policy_ownership"), - ) - op.create_index( - "uq_contribution_policy_active_project", - "contribution_policies", - ["project_id"], - unique=True, - postgresql_where=sa.text("status='active'"), - ) - - op.create_table( - "contribution_policy_versions", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("contribution_policy_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("version_number", sa.Integer(), nullable=False), - sa.Column("status", sa.String(16), server_default="draft", nullable=False), - sa.Column("created_by", sa.String(36), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column("published_by", sa.String(36)), - sa.Column("published_at", sa.DateTime(timezone=True)), - sa.Column("retired_by", sa.String(36)), - sa.Column("retired_at", sa.DateTime(timezone=True)), - sa.CheckConstraint( - "version_number > 0", - name="version_number_positive", - ), - sa.CheckConstraint( - "status in ('draft','published','retired')", - name="status", - ), - sa.CheckConstraint( - "(status='draft' and published_by is null and published_at is null " - "and retired_by is null and retired_at is null) or " - "(status='published' and published_by is not null and published_at is not null " - "and retired_by is null and retired_at is null) or " - "(status='retired' and published_by is not null and published_at is not null " - "and retired_by is not null and retired_at is not null)", - name="lifecycle_shape", - ), - sa.CheckConstraint( - "(published_at is null or published_at >= created_at) and " - "(retired_at is null or retired_at >= published_at)", - name="lifecycle_timestamps", - ), - sa.ForeignKeyConstraint( - ["contribution_policy_id", "project_id"], - ["contribution_policies.id", "contribution_policies.project_id"], - name="fk_contribution_policy_version_policy", - ), - sa.ForeignKeyConstraint( - ["project_id"], ["projects.id"], name="fk_contribution_policy_version_project" - ), - sa.ForeignKeyConstraint( - ["created_by"], - ["actor_profiles.id"], - name="fk_contribution_policy_version_created_by", - ), - sa.ForeignKeyConstraint( - ["published_by"], - ["actor_profiles.id"], - name="fk_contribution_policy_version_published_by", - ), - sa.ForeignKeyConstraint( - ["retired_by"], - ["actor_profiles.id"], - name="fk_contribution_policy_version_retired_by", - ), - sa.PrimaryKeyConstraint("id", name="pk_contribution_policy_versions"), - sa.UniqueConstraint( - "id", "project_id", name="uq_contribution_policy_version_project" - ), - sa.UniqueConstraint( - "id", - "contribution_policy_id", - "project_id", - name="uq_contribution_policy_version_ownership", - ), - sa.UniqueConstraint( - "contribution_policy_id", - "version_number", - name="uq_contribution_policy_version_number", - ), - ) - op.create_foreign_key( - "fk_contribution_policy_current_version", - "contribution_policies", - "contribution_policy_versions", - ["current_published_version_id", "id", "project_id"], - ["id", "contribution_policy_id", "project_id"], - deferrable=True, - initially="DEFERRED", - ) - - op.create_table( - "contribution_rules", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("contribution_policy_version_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("contribution_type", sa.String(32), nullable=False), - sa.Column("compensation_mode", sa.String(16), nullable=False), - sa.CheckConstraint( - "contribution_type in ('accepted_submission','completed_review')", - name="contribution_type", - ), - sa.CheckConstraint( - "compensation_mode in ('unpaid','compensated')", - name="compensation_mode", - ), - sa.ForeignKeyConstraint( - ["contribution_policy_version_id", "project_id"], - ["contribution_policy_versions.id", "contribution_policy_versions.project_id"], - name="fk_contribution_rule_version", - ), - sa.ForeignKeyConstraint( - ["project_id"], ["projects.id"], name="fk_contribution_rule_project" - ), - sa.PrimaryKeyConstraint("id", name="pk_contribution_rules"), - sa.UniqueConstraint( - "id", - "contribution_policy_version_id", - "project_id", - "contribution_type", - name="uq_contribution_rule_ownership", - ), - sa.UniqueConstraint( - "contribution_policy_version_id", - "contribution_type", - name="uq_contribution_rule_type", - ), - ) - - iso_currency_codes = op.create_table( - "iso_4217_currency_codes", - sa.Column("code", sa.String(3), nullable=False), - sa.CheckConstraint( - "code ~ '^[A-Z]{3}$'", name="code" - ), - sa.PrimaryKeyConstraint("code", name="pk_iso_4217_currency_codes"), - ) - op.bulk_insert( - iso_currency_codes, - [{"code": code} for code in ISO_4217_CURRENCY_CODES], - ) - op.create_table( - "project_compensation_units", - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("instrument_type", sa.String(32), nullable=False), - sa.Column("unit_code", sa.String(32), nullable=False), - sa.Column("iso_currency_code", sa.String(3)), - sa.Column("status", sa.String(16), server_default="active", nullable=False), - sa.Column("created_by", sa.String(36), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column("retired_by", sa.String(36)), - sa.Column("retired_at", sa.DateTime(timezone=True)), - sa.CheckConstraint( - "instrument_type in ('money','project_points')", - name="instrument_type", - ), - sa.CheckConstraint( - "status in ('active','retired')", - name="status", - ), - sa.CheckConstraint( - "(instrument_type='money' and iso_currency_code is not null " - "and unit_code=iso_currency_code) or " - "(instrument_type='project_points' and iso_currency_code is null " - "and unit_code ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$')", - name="unit_identity", - ), - sa.CheckConstraint( - "(status='active' and retired_by is null and retired_at is null) or " - "(status='retired' and retired_by is not null and retired_at is not null)", - name="lifecycle_shape", - ), - sa.CheckConstraint( - "retired_at is null or retired_at >= created_at", - name="retirement_time", - ), - sa.ForeignKeyConstraint( - ["project_id"], ["projects.id"], name="fk_project_compensation_unit_project" - ), - sa.ForeignKeyConstraint( - ["iso_currency_code"], - ["iso_4217_currency_codes.code"], - name="fk_project_compensation_unit_iso_currency", - ), - sa.ForeignKeyConstraint( - ["created_by"], - ["actor_profiles.id"], - name="fk_project_compensation_unit_created_by", - ), - sa.ForeignKeyConstraint( - ["retired_by"], - ["actor_profiles.id"], - name="fk_project_compensation_unit_retired_by", - ), - sa.PrimaryKeyConstraint( - "project_id", - "instrument_type", - "unit_code", - name="pk_project_compensation_units", - ), - ) - - op.create_table( - "contribution_award_definitions", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("contribution_rule_id", sa.Uuid(), nullable=False), - sa.Column("contribution_policy_version_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("contribution_type", sa.String(32), nullable=False), - sa.Column("instrument_type", sa.String(32), nullable=False), - sa.Column("unit_code", sa.String(32), nullable=False), - sa.Column("quantity", sa.Numeric(), nullable=False), - sa.Column("adapter_binding_id", sa.Uuid(), nullable=False), - sa.CheckConstraint( - "contribution_type in ('accepted_submission','completed_review')", - name="contribution_type", - ), - sa.CheckConstraint( - "instrument_type in ('money','project_points')", - name="instrument_type", - ), - sa.CheckConstraint( - "quantity > 0 and quantity < 100000000000000000000 " - "and scale(quantity) between 0 and 18", - name="quantity_exact_bounds", - ), - sa.CheckConstraint( - "instrument_type <> 'project_points' or scale(quantity)=0", - name="project_points_whole", - ), - sa.ForeignKeyConstraint( - [ - "contribution_rule_id", - "contribution_policy_version_id", - "project_id", - "contribution_type", - ], - [ - "contribution_rules.id", - "contribution_rules.contribution_policy_version_id", - "contribution_rules.project_id", - "contribution_rules.contribution_type", - ], - name="fk_contribution_award_definition_rule", - ), - sa.ForeignKeyConstraint( - ["adapter_binding_id", "project_id", "instrument_type"], - [ - "project_compensation_adapter_bindings.id", - "project_compensation_adapter_bindings.project_id", - "project_compensation_adapter_bindings.instrument_type", - ], - name="fk_contribution_award_definition_binding", - ), - sa.ForeignKeyConstraint( - ["project_id", "instrument_type", "unit_code"], - [ - "project_compensation_units.project_id", - "project_compensation_units.instrument_type", - "project_compensation_units.unit_code", - ], - name="fk_contribution_award_definition_unit", - ), - sa.ForeignKeyConstraint( - ["project_id"], - ["projects.id"], - name="fk_contribution_award_definition_project", - ), - sa.PrimaryKeyConstraint("id", name="pk_contribution_award_definitions"), - sa.UniqueConstraint( - "contribution_rule_id", - "instrument_type", - name="uq_contribution_award_definition_instrument", - ), - ) - - op.execute( - """ - create function guard_contribution_policy_version_content() returns trigger - language plpgsql as $$ - begin - if tg_op='DELETE' and old.status in ('published','retired') then - raise exception 'published contribution policy versions are immutable' - using errcode='55000'; - end if; - if tg_op='UPDATE' and old.status='retired' then - raise exception 'retired contribution policy versions are immutable' - using errcode='55000'; - end if; - if tg_op='UPDATE' and old.status='published' and not ( - new.status='retired' - and new.id=old.id - and new.contribution_policy_id=old.contribution_policy_id - and new.project_id=old.project_id - and new.version_number=old.version_number - and new.created_by=old.created_by - and new.created_at=old.created_at - and new.published_by=old.published_by - and new.published_at=old.published_at - and new.retired_by is not null - and new.retired_at is not null - ) then - raise exception 'published contribution policy version content is immutable' - using errcode='55000'; - end if; - return case when tg_op='DELETE' then old else new end; - end; - $$; - """ - ) - op.execute( - "create trigger contribution_policy_versions_content_guard " - "before update or delete on contribution_policy_versions for each row " - "execute function guard_contribution_policy_version_content()" - ) - op.execute( - """ - create function guard_iso_4217_currency_codes() returns trigger - language plpgsql as $$ - begin - raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' - using errcode='55000'; - end; - $$; - """ - ) - op.execute( - "create trigger iso_4217_currency_codes_immutable " - "before insert or update or delete on iso_4217_currency_codes for each row " - "execute function guard_iso_4217_currency_codes()" - ) - op.execute( - """ - create function guard_project_compensation_units() returns trigger - language plpgsql as $$ - begin - if tg_op in ('UPDATE','DELETE') then - raise exception 'project compensation-unit lifecycle behavior is deferred' - using errcode='55000'; - end if; - if new.status <> 'active' then - raise exception 'project compensation units must begin active' - using errcode='23514'; - end if; - return new; - end; - $$; - """ - ) - op.execute( - "create trigger project_compensation_units_lifecycle_guard " - "before insert or update or delete on project_compensation_units for each row " - "execute function guard_project_compensation_units()" - ) - op.execute( - """ - create function guard_contribution_policy_children() returns trigger - language plpgsql as $$ - declare old_parent_status text; - declare new_parent_status text; - begin - if tg_op in ('UPDATE','DELETE') then - select status into old_parent_status from contribution_policy_versions - where id=old.contribution_policy_version_id for update; - end if; - if tg_op in ('INSERT','UPDATE') then - select status into new_parent_status from contribution_policy_versions - where id=new.contribution_policy_version_id for update; - end if; - if old_parent_status in ('published','retired') - or new_parent_status in ('published','retired') then - raise exception 'published contribution policy rules and definitions are immutable' - using errcode='55000'; - end if; - return case when tg_op='DELETE' then old else new end; - end; - $$; - """ - ) - for table in ("contribution_rules", "contribution_award_definitions"): - op.execute( - f"create trigger {table}_content_guard before insert or update or delete on {table} " - "for each row execute function guard_contribution_policy_children()" - ) - - op.execute( - """ - create function validate_contribution_policy_graph() returns trigger - language plpgsql as $$ - begin - if exists ( - select 1 from contribution_policy_versions v - where v.status in ('published','retired') and ( - (select count(*) from contribution_rules r - where r.contribution_policy_version_id=v.id - and r.contribution_type='accepted_submission') <> 1 - or - (select count(*) from contribution_rules r - where r.contribution_policy_version_id=v.id - and r.contribution_type='completed_review') <> 1 - or exists ( - select 1 from contribution_rules r - where r.contribution_policy_version_id=v.id and ( - (r.compensation_mode='unpaid' and - (select count(*) from contribution_award_definitions d - where d.contribution_rule_id=r.id) <> 0) - or - (r.compensation_mode='compensated' and - (select count(*) from contribution_award_definitions d - where d.contribution_rule_id=r.id) not between 1 and 2) - ) - ) - ) - ) then - raise exception 'published contribution policy graph is incomplete' - using errcode='23514'; - end if; - - if exists ( - select 1 from contribution_policies p - left join contribution_policy_versions v - on v.id=p.current_published_version_id - and v.contribution_policy_id=p.id - and v.project_id=p.project_id - where p.status='active' and (v.id is null or v.status <> 'published') - ) then - raise exception 'active contribution policy selector is invalid' - using errcode='23514'; - end if; - return null; - end; - $$; - """ - ) - for table in ( - "contribution_policies", - "contribution_policy_versions", - "contribution_rules", - "contribution_award_definitions", - ): - op.execute( - f"create constraint trigger {table}_graph_guard " - f"after insert or update or delete on {table} deferrable initially deferred " - "for each row execute function validate_contribution_policy_graph()" - ) - op.execute( - """ - create function reject_contribution_policy_truncate() returns trigger - language plpgsql as $$ - begin - raise exception 'contribution policy persistence cannot be truncated' - using errcode='55000'; - end; - $$; - """ - ) - for table in ( - "contribution_policies", - "contribution_policy_versions", - "contribution_rules", - "contribution_award_definitions", - "project_compensation_units", - "iso_4217_currency_codes", - ): - op.execute( - f"create trigger {table}_reject_truncate before truncate on {table} " - "execute function reject_contribution_policy_truncate()" - ) - - -def downgrade() -> None: - bind = op.get_bind() - populated = sum( - bind.execute(sa.text(f"select count(*) from {table}")).scalar_one() - for table in ( - "contribution_policies", - "contribution_policy_versions", - "contribution_rules", - "contribution_award_definitions", - "project_compensation_units", - ) - ) - if populated: - raise RuntimeError("cannot downgrade populated contribution policy persistence") - - for table in ( - "contribution_policies", - "contribution_policy_versions", - "contribution_rules", - "contribution_award_definitions", - "project_compensation_units", - "iso_4217_currency_codes", - ): - op.execute(f"drop trigger {table}_reject_truncate on {table}") - op.execute("drop function reject_contribution_policy_truncate()") - for table in ( - "contribution_policies", - "contribution_policy_versions", - "contribution_rules", - "contribution_award_definitions", - ): - op.execute(f"drop trigger {table}_graph_guard on {table}") - op.execute("drop function validate_contribution_policy_graph()") - for table in ("contribution_award_definitions", "contribution_rules"): - op.execute(f"drop trigger {table}_content_guard on {table}") - op.execute("drop function guard_contribution_policy_children()") - op.execute( - "drop trigger project_compensation_units_lifecycle_guard " - "on project_compensation_units" - ) - op.execute("drop function guard_project_compensation_units()") - op.execute( - "drop trigger iso_4217_currency_codes_immutable on iso_4217_currency_codes" - ) - op.execute("drop function guard_iso_4217_currency_codes()") - op.execute( - "drop trigger contribution_policy_versions_content_guard " - "on contribution_policy_versions" - ) - op.execute("drop function guard_contribution_policy_version_content()") - op.drop_table("contribution_award_definitions") - op.drop_table("project_compensation_units") - op.drop_table("iso_4217_currency_codes") - op.drop_table("contribution_rules") - op.drop_constraint( - "fk_contribution_policy_current_version", - "contribution_policies", - type_="foreignkey", - ) - op.drop_table("contribution_policy_versions") - op.drop_index( - "uq_contribution_policy_active_project", table_name="contribution_policies" - ) - op.drop_table("contribution_policies") diff --git a/backend/alembic/versions/0056_review_lease_preference.py b/backend/alembic/versions/0056_review_lease_preference.py deleted file mode 100644 index b5c9fe716..000000000 --- a/backend/alembic/versions/0056_review_lease_preference.py +++ /dev/null @@ -1,361 +0,0 @@ -"""add hidden review lease and preference persistence - -Revision ID: 0056_review_lease_preference -Revises: 0055_contribution_policy -Create Date: 2026-08-05 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0056_review_lease_preference" -down_revision = "0055_contribution_policy" -branch_labels = depends_on = None - - -def _replace_queue_checks(*, with_leases: bool) -> None: - op.drop_constraint("ck_review_queue_entries_queue_state", "review_queue_entries", type_="check") - op.drop_constraint( - "ck_review_queue_entries_lifecycle_shape", "review_queue_entries", type_="check" - ) - states = "'pending','leased','closed'" if with_leases else "'pending','closed'" - op.create_check_constraint( - "ck_review_queue_entries_queue_state", - "review_queue_entries", - f"queue_state in ({states})", - ) - if with_leases: - shape = ( - "(queue_state='pending' and active_lease_id is null " - "and closed_at is null and closed_reason is null) or " - "(queue_state='leased' and active_lease_id is not null " - "and closed_at is null and closed_reason is null) or " - "(queue_state='closed' and active_lease_id is null and closed_at is not null " - "and closed_reason in ('review_recorded','task_closed','admin_cancelled') " - "and closed_at >= first_queued_at)" - ) - else: - shape = ( - "(queue_state='pending' and closed_at is null and closed_reason is null) or " - "(queue_state='closed' and closed_at is not null and " - "closed_reason in ('review_recorded','task_closed','admin_cancelled') " - "and closed_at >= first_queued_at)" - ) - op.create_check_constraint( - "ck_review_queue_entries_lifecycle_shape", "review_queue_entries", shape - ) - - -def _create_lease_table() -> None: - op.create_unique_constraint( - "uq_review_queue_lease_lineage", - "review_queue_entries", - ["id", "project_id", "task_id", "submission_id", "submission_version"], - ) - op.create_table( - "review_leases", - sa.Column("id", sa.Uuid(), nullable=False), - sa.Column("review_queue_entry_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=False), - sa.Column("submission_id", sa.String(36), nullable=False), - sa.Column("submission_version", sa.Integer(), nullable=False), - sa.Column("reviewer_id", sa.String(36), nullable=False), - sa.Column("reviewer_contribution_policy_version_id", sa.Uuid(), nullable=False), - sa.Column("attempt_generation", sa.Integer(), nullable=False), - sa.Column("status", sa.String(16), server_default="active", nullable=False), - sa.Column( - "claimed_at", - sa.DateTime(timezone=True), - server_default=sa.text("statement_timestamp()"), - nullable=False, - ), - sa.Column("expires_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("closed_at", sa.DateTime(timezone=True)), - sa.Column("close_reason", sa.String(32)), - sa.CheckConstraint("attempt_generation > 0", name="attempt_generation_positive"), - sa.CheckConstraint( - "status in ('active','consumed','released','expired','revoked')", name="status" - ), - sa.CheckConstraint("expires_at > claimed_at", name="expiry_after_claim"), - sa.CheckConstraint( - "(status='active' and closed_at is null and close_reason is null) or " - "(status='consumed' and closed_at is not null and close_reason='review_recorded') or " - "(status='released' and closed_at is not null and close_reason='manual_release') or " - "(status='expired' and closed_at is not null and close_reason='lease_expired') or " - "(status='revoked' and closed_at is not null " - "and close_reason in ('grant_revoked','admin_override'))", - name="lifecycle_shape", - ), - sa.CheckConstraint( - "closed_at is null or closed_at >= claimed_at", name="closure_after_claim" - ), - sa.ForeignKeyConstraint( - ["review_queue_entry_id", "project_id", "task_id", "submission_id", "submission_version"], - ["review_queue_entries.id", "review_queue_entries.project_id", "review_queue_entries.task_id", "review_queue_entries.submission_id", "review_queue_entries.submission_version"], - name="fk_review_lease_queue_lineage", - ), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], name="fk_review_lease_project"), - sa.ForeignKeyConstraint(["task_id"], ["workstream_tasks.id"], name="fk_review_lease_task"), - sa.ForeignKeyConstraint(["submission_id"], ["submissions.id"], name="fk_review_lease_submission"), - sa.ForeignKeyConstraint(["reviewer_id"], ["actor_profiles.id"], name="fk_review_lease_reviewer"), - sa.ForeignKeyConstraint( - ["reviewer_contribution_policy_version_id", "project_id"], - ["contribution_policy_versions.id", "contribution_policy_versions.project_id"], - name="fk_review_lease_policy_version", - ), - sa.PrimaryKeyConstraint("id", name="pk_review_leases"), - sa.UniqueConstraint("review_queue_entry_id", "id", name="uq_review_lease_queue_identity"), - sa.UniqueConstraint( - "review_queue_entry_id", "attempt_generation", name="uq_review_lease_attempt" - ), - ) - op.create_index( - "uq_review_lease_active_queue", - "review_leases", - ["review_queue_entry_id"], - unique=True, - postgresql_where=sa.text("status='active'"), - ) - op.create_index( - "uq_review_lease_active_reviewer", - "review_leases", - ["reviewer_id"], - unique=True, - postgresql_where=sa.text("status='active'"), - ) - op.create_index("ix_review_lease_expiry", "review_leases", ["status", "expires_at", "id"]) - - -def _create_guards() -> None: - op.execute( - """ - create function guard_review_lease() returns trigger language plpgsql as $$ - declare - actor_type text; - policy_status text; - begin - if tg_op='DELETE' then - raise exception 'review leases cannot be deleted' using errcode='55000'; - end if; - if tg_op='INSERT' then - if new.status <> 'active' then - raise exception 'review lease must begin active' using errcode='23514'; - end if; - new.claimed_at := statement_timestamp(); - new.closed_at := null; - new.close_reason := null; - else - if old.status <> 'active' then - raise exception 'terminal review leases are immutable' using errcode='55000'; - end if; - if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, - new.submission_version,new.reviewer_id, - new.reviewer_contribution_policy_version_id,new.attempt_generation, - new.claimed_at,new.expires_at) - is distinct from - (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, - old.submission_version,old.reviewer_id, - old.reviewer_contribution_policy_version_id,old.attempt_generation, - old.claimed_at,old.expires_at) then - raise exception 'review lease identity is immutable' using errcode='55000'; - end if; - if new.status='active' then - raise exception 'review lease update must close attempt' using errcode='23514'; - end if; - end if; - select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; - if actor_type is distinct from 'human' then - raise exception 'review lease reviewer must be human' using errcode='23514'; - end if; - if tg_op='INSERT' then - select status into policy_status from contribution_policy_versions - where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; - if policy_status is distinct from 'published' then - raise exception 'review lease policy version must be published' using errcode='23514'; - end if; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger review_leases_guard before insert or update or delete on review_leases " - "for each row execute function guard_review_lease()" - ) - op.execute( - """ - create function validate_review_active_lease() returns trigger language plpgsql as $$ - declare - queue_row review_queue_entries%rowtype; - active_count integer; - begin - if tg_table_name='review_queue_entries' then - queue_row := new; - else - select * into queue_row from review_queue_entries - where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); - end if; - if not found and tg_table_name='review_leases' then - raise exception 'review lease queue is missing' using errcode='23514'; - end if; - select count(*) into active_count from review_leases - where review_queue_entry_id=queue_row.id and status='active'; - if queue_row.queue_state='leased' then - if queue_row.active_lease_id is null or active_count <> 1 or not exists( - select 1 from review_leases where id=queue_row.active_lease_id - and review_queue_entry_id=queue_row.id and status='active' - ) then - raise exception 'leased queue must identify its active lease' using errcode='23514'; - end if; - elsif queue_row.active_lease_id is not null or active_count <> 0 then - raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; - end if; - return null; - end $$ - """ - ) - for table in ("review_queue_entries", "review_leases"): - op.execute( - f"create constraint trigger {table}_active_lease_guard " - f"after insert or update on {table} deferrable initially deferred " - "for each row execute function validate_review_active_lease()" - ) - op.execute( - """ - create function reject_review_lease_truncate() returns trigger language plpgsql as $$ - begin - raise exception 'review leases cannot be truncated' using errcode='55000'; - end $$ - """ - ) - op.execute( - "create trigger review_leases_reject_truncate before truncate on review_leases " - "execute function reject_review_lease_truncate()" - ) - - -def _replace_queue_guard(*, with_preference_guard: bool) -> None: - op.execute("drop trigger review_queue_entries_guard on review_queue_entries") - op.execute("drop function guard_review_queue_entry()") - preference = """ - if new.preferred_reviewer_id is not null and not exists( - select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' - ) then - raise exception 'preferred reviewer must be human' using errcode='23514'; - end if; - """ if with_preference_guard else "" - op.execute( - f""" - create function guard_review_queue_entry() returns trigger language plpgsql as $$ - declare - task_project text; - checker_row checker_runs%rowtype; - begin - if tg_op='DELETE' then - raise exception 'review queue entries cannot be deleted' using errcode='55000'; - end if; - if tg_op='INSERT' then - if new.queue_state <> 'pending' then - raise exception 'review queue must begin pending' using errcode='23514'; - end if; - new.first_queued_at := statement_timestamp(); - new.available_since := new.first_queued_at; - new.routing_generation := 1; - new.lifecycle_generation := 1; - new.created_at := new.first_queued_at; - end if; - if tg_op='UPDATE' then - if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, - new.admitting_checker_run_id,new.first_queued_at,new.created_at) - is distinct from - (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, - old.admitting_checker_run_id,old.first_queued_at,old.created_at) then - raise exception 'review queue identity is immutable' using errcode='55000'; - end if; - if old.queue_state='closed' and new.queue_state <> 'closed' then - raise exception 'closed review queue entries cannot reopen' using errcode='23514'; - end if; - if new.routing_generation < old.routing_generation - or new.lifecycle_generation < old.lifecycle_generation then - raise exception 'review queue generations cannot decrease' using errcode='23514'; - end if; - end if; - {preference} - if tg_op='UPDATE' then return new; end if; - select project_id into task_project from workstream_tasks where id=new.task_id; - if task_project is null or task_project <> new.project_id then - raise exception 'review queue task project mismatch' using errcode='23514'; - end if; - select * into checker_row from checker_runs where id=new.admitting_checker_run_id; - if not found or checker_row.task_id <> new.task_id - or checker_row.submission_id <> new.submission_id - or checker_row.submission_version <> new.submission_version then - raise exception 'review queue checker lineage mismatch' using errcode='23514'; - end if; - if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' - or checker_row.is_current_for_submission is not true then - raise exception 'review queue checker is not admissible' using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger review_queue_entries_guard before insert or update or delete " - "on review_queue_entries for each row execute function guard_review_queue_entry()" - ) - - -def upgrade() -> None: - """Install empty lease persistence after the canonical CON policy target.""" - bind = op.get_bind() - bind.execute(sa.text("lock table review_queue_entries in share row exclusive mode")) - invalid_preference = bind.execute( - sa.text( - "select exists(select 1 from review_queue_entries queue " - "left join actor_profiles actor on actor.id=queue.preferred_reviewer_id " - "where queue.preferred_reviewer_id is not null " - "and actor.actor_kind is distinct from 'human')" - ) - ).scalar_one() - if invalid_preference: - raise RuntimeError("cannot add lease persistence with nonhuman reviewer preference") - op.add_column("review_queue_entries", sa.Column("active_lease_id", sa.Uuid())) - _replace_queue_checks(with_leases=True) - _create_lease_table() - op.create_foreign_key( - "fk_review_queue_active_lease", - "review_queue_entries", - "review_leases", - ["active_lease_id", "id"], - ["id", "review_queue_entry_id"], - deferrable=True, - initially="DEFERRED", - ) - _replace_queue_guard(with_preference_guard=True) - _create_guards() - - -def downgrade() -> None: - """Remove only unused lease persistence; never discard attempt history.""" - bind = op.get_bind() - bind.execute(sa.text("lock table review_leases in access exclusive mode")) - if bind.execute(sa.text("select exists(select 1 from review_leases)" )).scalar_one(): - raise RuntimeError("cannot downgrade populated review lease persistence") - op.execute("drop trigger review_leases_reject_truncate on review_leases") - op.execute("drop function reject_review_lease_truncate()") - for table in ("review_queue_entries", "review_leases"): - op.execute(f"drop trigger {table}_active_lease_guard on {table}") - op.execute("drop function validate_review_active_lease()") - op.execute("drop trigger review_leases_guard on review_leases") - op.execute("drop function guard_review_lease()") - _replace_queue_guard(with_preference_guard=False) - op.drop_constraint("fk_review_queue_active_lease", "review_queue_entries", type_="foreignkey") - op.drop_table("review_leases") - op.drop_constraint("uq_review_queue_lease_lineage", "review_queue_entries", type_="unique") - _replace_queue_checks(with_leases=False) - op.drop_column("review_queue_entries", "active_lease_id") diff --git a/backend/alembic/versions/0057_submission_policy_authority.py b/backend/alembic/versions/0057_submission_policy_authority.py deleted file mode 100644 index eca90cbf1..000000000 --- a/backend/alembic/versions/0057_submission_policy_authority.py +++ /dev/null @@ -1,821 +0,0 @@ -"""install submission-policy authorization foundation - -Revision ID: 0057_submission_policy_authority -Revises: 0056_review_lease_preference -Create Date: 2026-08-05 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0057_submission_policy_authority" -down_revision = "0056_review_lease_preference" -branch_labels = depends_on = None - -_SUBMISSION_CREATION_COLUMNS = ( - ("created_by_actor_profile_id", sa.String(36)), - ("created_via_identity_link_id", sa.String(36)), - ("created_by_admin_role_grant_id", sa.Uuid()), - ("created_by_service_identity", sa.String(160)), - ("creation_scope_type", sa.String(16)), - ("creation_scope_project_id", sa.String(36)), - ("creation_action_id", sa.String(160)), - ("creation_decision_event_id", sa.String(36)), -) -_SUBMISSION_APPROVAL_COLUMNS = ( - ("approved_by_actor_profile_id", sa.String(36)), - ("approved_via_identity_link_id", sa.String(36)), - ("approved_by_admin_role_grant_id", sa.Uuid()), - ("approval_scope_type", sa.String(16)), - ("approval_scope_project_id", sa.String(36)), - ("approval_action_id", sa.String(160)), - ("approval_decision_event_id", sa.String(36)), -) -_APPROVAL_OUTPUT_COLUMNS = ( - ("created_by_actor_profile_id", sa.String(36)), - ("created_via_identity_link_id", sa.String(36)), - ("created_by_admin_role_grant_id", sa.Uuid()), - ("creation_scope_type", sa.String(16)), - ("creation_scope_project_id", sa.String(36)), - ("creation_action_id", sa.String(160)), - ("creation_decision_event_id", sa.String(36)), -) -_AUDIT_RESOURCE_MARKER = "('project_create_operation'::character varying)::text" -_AUDIT_RESOURCE_ADDITION = ( - ", ('project_submission_artifact_policy_mutation'::character varying)::text" -) - - -def _rewrite_audit_resource(*, add: bool) -> None: - bind = op.get_bind() - definition = bind.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_privacy_bounds'" - ) - ).scalar_one() - expanded = _AUDIT_RESOURCE_MARKER + _AUDIT_RESOURCE_ADDITION - source, target = ( - (_AUDIT_RESOURCE_MARKER, expanded) - if add - else (expanded, _AUDIT_RESOURCE_MARKER) - ) - if definition.count(source) != 1 or (add and expanded in definition): - raise RuntimeError("unexpected authority privacy constraint") - op.drop_constraint("authority_privacy_bounds", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authority_privacy_bounds {definition.replace(source, target, 1)}" - ) - - -def _add_columns(table: str, columns: tuple[tuple[str, sa.types.TypeEngine], ...]) -> None: - for name, column_type in columns: - op.add_column(table, sa.Column(name, column_type)) - - -def _add_common_foreign_keys(table: str, prefix: str, *, approval: bool = False) -> None: - stem = "approval" if approval else "creation" - actor = "approved_by_actor_profile_id" if approval else "created_by_actor_profile_id" - link = "approved_via_identity_link_id" if approval else "created_via_identity_link_id" - grant = ( - "approved_by_admin_role_grant_id" if approval else "created_by_admin_role_grant_id" - ) - project = "approval_scope_project_id" if approval else "creation_scope_project_id" - decision = "approval_decision_event_id" if approval else "creation_decision_event_id" - for suffix, column, remote_table in ( - ("actor", actor, "actor_profiles"), - ("link", link, "actor_identity_links"), - ("grant", grant, "admin_role_grants"), - ("project", project, "projects"), - ("decision", decision, "audit_events"), - ): - op.create_foreign_key( - f"fk_{prefix}_{stem}_{suffix}", table, remote_table, [column], ["id"] - ) - - -def upgrade() -> None: - """Install nullable provenance and replay custody without activation.""" - op.execute("lock table audit_events in access exclusive mode") - _rewrite_audit_resource(add=True) - _add_columns( - "submission_artifact_policies", - (*_SUBMISSION_CREATION_COLUMNS, *_SUBMISSION_APPROVAL_COLUMNS), - ) - _add_common_foreign_keys("submission_artifact_policies", "submission_policy") - _add_common_foreign_keys( - "submission_artifact_policies", "submission_policy", approval=True - ) - _add_columns("effective_project_submission_artifact_policies", _APPROVAL_OUTPUT_COLUMNS) - _add_common_foreign_keys("effective_project_submission_artifact_policies", "effective_policy") - _add_columns("pre_submit_checker_policies", _APPROVAL_OUTPUT_COLUMNS) - _add_common_foreign_keys("pre_submit_checker_policies", "pre_submit_policy") - - op.create_check_constraint( - "ck_submission_policy_creation_authority_shape", - "submission_artifact_policies", - "(created_by_actor_profile_id is null and created_via_identity_link_id is null " - "and created_by_admin_role_grant_id is null and created_by_service_identity is null " - "and creation_scope_type is null and creation_scope_project_id is null " - "and creation_action_id is null and creation_decision_event_id is null) or " - "(created_by_actor_profile_id is not null and created_via_identity_link_id is not null " - "and creation_scope_type is not null and creation_action_id is not null " - "and creation_scope_project_id is not null " - "and creation_scope_project_id=project_id and creation_decision_event_id is not null " - "and creation_action_id in ('project.submission_artifact_policy.create'," - "'project.submission_artifact_policy.derive'," - "'project.submission_artifact_policy.update') and " - "((created_by_admin_role_grant_id is not null and created_by_service_identity is null " - "and creation_scope_type in ('system','project')) or " - "(created_by_admin_role_grant_id is null " - "and created_by_service_identity is not null " - "and created_by_service_identity='workstream.project.setup' " - "and creation_scope_type='service' " - "and creation_action_id='project.submission_artifact_policy.derive')))", - ) - op.create_check_constraint( - "ck_submission_policy_approval_authority_shape", - "submission_artifact_policies", - "(approved_by_actor_profile_id is null and approved_via_identity_link_id is null " - "and approved_by_admin_role_grant_id is null and approval_scope_type is null " - "and approval_scope_project_id is null and approval_action_id is null " - "and approval_decision_event_id is null) or " - "(approved_by_actor_profile_id is not null and approved_via_identity_link_id is not null " - "and approved_by_admin_role_grant_id is not null " - "and approval_scope_type is not null and approval_action_id is not null " - "and approval_scope_type in ('system','project') " - "and approval_scope_project_id is not null " - "and approval_scope_project_id=project_id " - "and approval_action_id='project.submission_artifact_policy.approve' " - "and approval_decision_event_id is not null)", - ) - output_shape = ( - "(created_by_actor_profile_id is null and created_via_identity_link_id is null " - "and created_by_admin_role_grant_id is null and creation_scope_type is null " - "and creation_scope_project_id is null and creation_action_id is null " - "and creation_decision_event_id is null) or " - "(created_by_actor_profile_id is not null and created_via_identity_link_id is not null " - "and created_by_admin_role_grant_id is not null " - "and creation_scope_type is not null and creation_action_id is not null " - "and creation_scope_type in ('system','project') " - "and creation_scope_project_id is not null " - "and creation_scope_project_id=project_id " - "and creation_action_id='project.submission_artifact_policy.approve' " - "and creation_decision_event_id is not null)" - ) - op.create_check_constraint( - "ck_effective_submission_policy_authority_shape", - "effective_project_submission_artifact_policies", - output_shape, - ) - op.create_check_constraint( - "ck_pre_submit_policy_authority_shape", - "pre_submit_checker_policies", - output_shape, - ) - - op.create_table( - "submission_policy_mutation_idempotency_records", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column("actor_profile_id", sa.String(36), sa.ForeignKey("actor_profiles.id"), nullable=False), - sa.Column("identity_link_id", sa.String(36), sa.ForeignKey("actor_identity_links.id"), nullable=False), - sa.Column("service_identity", sa.String(160)), - sa.Column("action_id", sa.String(160), nullable=False), - sa.Column("idempotency_key", sa.Uuid()), - sa.Column("request_digest", sa.String(71), nullable=False), - sa.Column("resource_context_digest", sa.String(71), nullable=False), - sa.Column("resource_context_json", sa.JSON(), nullable=False), - sa.Column("operation_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), sa.ForeignKey("projects.id"), nullable=False), - sa.Column("guide_id", sa.String(36), sa.ForeignKey("project_guides.id"), nullable=False), - sa.Column("source_snapshot_id", sa.String(36), sa.ForeignKey("guide_source_snapshots.id"), nullable=False), - sa.Column("policy_id", sa.String(36), nullable=False), - sa.Column("setup_run_id", sa.String(36), sa.ForeignKey("project_setup_runs.id")), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("setup_task_id", sa.Uuid()), - sa.Column("correlation_id", sa.Uuid()), - sa.Column("status", sa.String(16), nullable=False), - sa.Column("response_json", sa.JSON()), - sa.Column( - "committed_policy_id", - sa.String(36), - sa.ForeignKey("submission_artifact_policies.id"), - ), - sa.Column( - "committed_effective_policy_id", - sa.String(36), - sa.ForeignKey("effective_project_submission_artifact_policies.id"), - ), - sa.Column( - "committed_pre_submit_policy_id", - sa.String(36), - sa.ForeignKey("pre_submit_checker_policies.id"), - ), - sa.Column("created_at", sa.DateTime(timezone=True), server_default=sa.func.now(), nullable=False), - sa.Column("committed_at", sa.DateTime(timezone=True)), - sa.UniqueConstraint("operation_id", name="uq_submission_policy_operation_identity"), - sa.CheckConstraint( - "action_id in ('project.submission_artifact_policy.create'," - "'project.submission_artifact_policy.derive'," - "'project.submission_artifact_policy.update'," - "'project.submission_artifact_policy.approve')", - name="ck_submission_policy_mutation_action", - ), - sa.CheckConstraint( - "request_digest ~ '^sha256:[0-9a-f]{64}$' and " - "resource_context_digest ~ '^sha256:[0-9a-f]{64}$'", - name="ck_submission_policy_mutation_digests", - ), - sa.CheckConstraint("setup_generation > 0", name="ck_submission_policy_generation"), - sa.CheckConstraint( - "(service_identity is null and idempotency_key is not null " - "and setup_run_id is null and setup_task_id is null and correlation_id is null) or " - "(service_identity is not null " - "and service_identity='workstream.project.setup' and idempotency_key is null " - "and action_id='project.submission_artifact_policy.derive' " - "and setup_run_id is not null and setup_task_id is not null " - "and correlation_id is not null)", - name="ck_submission_policy_replay_principal_shape", - ), - sa.CheckConstraint( - "status in ('pending','committed')", name="ck_submission_policy_replay_status" - ), - sa.CheckConstraint( - "(status='pending' and response_json is null and committed_at is null " - "and committed_policy_id is null and committed_effective_policy_id is null " - "and committed_pre_submit_policy_id is null) or " - "(status='committed' and response_json is not null and committed_at is not null " - "and committed_policy_id is not null and " - "((action_id='project.submission_artifact_policy.approve' " - "and committed_effective_policy_id is not null " - "and committed_pre_submit_policy_id is not null) or " - "(action_id<>'project.submission_artifact_policy.approve' " - "and committed_effective_policy_id is null " - "and committed_pre_submit_policy_id is null)))", - name="ck_submission_policy_replay_state_shape", - ), - ) - op.create_index( - "uq_submission_policy_human_replay_namespace", - "submission_policy_mutation_idempotency_records", - ["actor_profile_id", "idempotency_key"], - unique=True, - postgresql_where=sa.text("service_identity is null"), - ) - op.create_index( - "uq_submission_policy_service_replay_namespace", - "submission_policy_mutation_idempotency_records", - [ - "actor_profile_id", - "setup_run_id", - "setup_generation", - "setup_task_id", - "correlation_id", - "action_id", - ], - unique=True, - postgresql_where=sa.text("service_identity is not null"), - ) - op.create_index( - "uq_submission_policy_committed_policy_action", - "submission_policy_mutation_idempotency_records", - ["committed_policy_id", "action_id"], - unique=True, - postgresql_where=sa.text("status='committed'"), - ) - op.execute( - """ - create function reject_submission_policy_replay_mutation() returns trigger - language plpgsql as $$ - begin - if tg_op = 'DELETE' then - raise exception 'submission-policy replay rows cannot be deleted'; - end if; - if old.status <> 'pending' or new.status <> 'committed' - or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, - new.action_id,new.idempotency_key,new.request_digest, - new.resource_context_digest,new.resource_context_json::text,new.operation_id, - new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, - new.setup_run_id,new.setup_generation,new.setup_task_id, - new.correlation_id,new.created_at) - is distinct from - (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, - old.action_id,old.idempotency_key,old.request_digest, - old.resource_context_digest,old.resource_context_json::text,old.operation_id, - old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, - old.setup_run_id,old.setup_generation,old.setup_task_id, - old.correlation_id,old.created_at) - then - raise exception 'invalid submission-policy replay mutation'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger trg_submission_policy_replay_immutable before update or delete " - "on submission_policy_mutation_idempotency_records for each row " - "execute function reject_submission_policy_replay_mutation()" - ) - op.execute( - """ - create function reject_submission_policy_replay_truncate() returns trigger - language plpgsql as $$ begin - raise exception 'submission-policy replay rows cannot be truncated'; - end $$ - """ - ) - op.execute( - "create trigger trg_submission_policy_replay_no_truncate before truncate " - "on submission_policy_mutation_idempotency_records for each statement " - "execute function reject_submission_policy_replay_truncate()" - ) - op.execute( - """ - create function protect_submission_policy_creation_provenance() returns trigger - language plpgsql as $$ - begin - if old.creation_action_id is not null and - (new.created_by_actor_profile_id,new.created_via_identity_link_id, - new.created_by_admin_role_grant_id,new.created_by_service_identity, - new.creation_scope_type,new.creation_scope_project_id, - new.creation_action_id,new.creation_decision_event_id) - is distinct from - (old.created_by_actor_profile_id,old.created_via_identity_link_id, - old.created_by_admin_role_grant_id,old.created_by_service_identity, - old.creation_scope_type,old.creation_scope_project_id, - old.creation_action_id,old.creation_decision_event_id) then - raise exception 'submission-policy creation provenance is immutable' - using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger submission_policy_creation_provenance_immutable before update on " - "submission_artifact_policies for each row " - "execute function protect_submission_policy_creation_provenance()" - ) - op.execute( - """ - create function protect_submission_policy_approval_provenance() returns trigger - language plpgsql as $$ - begin - if old.approval_action_id is not null and - (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, - new.approved_by_admin_role_grant_id,new.approval_scope_type, - new.approval_scope_project_id,new.approval_action_id, - new.approval_decision_event_id) - is distinct from - (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, - old.approved_by_admin_role_grant_id,old.approval_scope_type, - old.approval_scope_project_id,old.approval_action_id, - old.approval_decision_event_id) then - raise exception 'submission-policy approval provenance is immutable' - using errcode='23514'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger submission_policy_approval_provenance_immutable before update on " - "submission_artifact_policies for each row " - "execute function protect_submission_policy_approval_provenance()" - ) - op.execute( - """ - create function protect_submission_policy_output_provenance() returns trigger - language plpgsql as $$ - begin - if old.creation_action_id is not null and - (new.created_by_actor_profile_id,new.created_via_identity_link_id, - new.created_by_admin_role_grant_id,new.creation_scope_type, - new.creation_scope_project_id,new.creation_action_id, - new.creation_decision_event_id) - is distinct from - (old.created_by_actor_profile_id,old.created_via_identity_link_id, - old.created_by_admin_role_grant_id,old.creation_scope_type, - old.creation_scope_project_id,old.creation_action_id, - old.creation_decision_event_id) then - raise exception 'submission-policy output provenance is immutable' - using errcode='23514'; - end if; - return new; - end $$ - """ - ) - for trigger, table in ( - ( - "effective_submission_policy_provenance_immutable", - "effective_project_submission_artifact_policies", - ), - ("pre_submit_policy_provenance_immutable", "pre_submit_checker_policies"), - ): - op.execute( - f"create trigger {trigger} before update on {table} for each row " - "execute function protect_submission_policy_output_provenance()" - ) - op.execute( - """ - create function validate_submission_policy_creation_custody() returns trigger - language plpgsql as $$ - declare reservation submission_policy_mutation_idempotency_records%rowtype; - evidence audit_events%rowtype; - begin - if new.creation_action_id is null then - if new.created_by_actor_profile_id is not null - or new.created_via_identity_link_id is not null - or new.created_by_admin_role_grant_id is not null - or new.created_by_service_identity is not null - or new.creation_scope_type is not null - or new.creation_scope_project_id is not null - or new.creation_decision_event_id is not null then - raise exception 'partial submission-policy creation provenance' - using errcode='23514'; - end if; - return null; - end if; - select * into reservation from submission_policy_mutation_idempotency_records - where committed_policy_id=new.id and action_id=new.creation_action_id - and status='committed'; - if reservation.id is null - or reservation.actor_profile_id - is distinct from new.created_by_actor_profile_id - or reservation.identity_link_id - is distinct from new.created_via_identity_link_id - or reservation.service_identity - is distinct from new.created_by_service_identity - or reservation.project_id is distinct from new.project_id - or reservation.policy_id is distinct from new.id - or reservation.guide_id is distinct from new.guide_id - or reservation.source_snapshot_id is distinct from new.source_snapshot_id - or reservation.resource_context_json->>'guide_version' - is distinct from new.guide_version then - raise exception 'submission-policy creation custody mismatch' using errcode='23514'; - end if; - select * into evidence from audit_events where id=new.creation_decision_event_id; - if evidence.id is null or evidence.event_domain is distinct from 'authority' - or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' - or evidence.denial_code is not null - or evidence.actor_ref_kind is distinct from 'actor_profile' - or evidence.actor_id is distinct from new.created_by_actor_profile_id - or evidence.matched_grant_id - is distinct from new.created_by_admin_role_grant_id::text - or evidence.permission_id is distinct from 'project.effective_policy.manage' - or evidence.action_id is distinct from new.creation_action_id - or evidence.resource_type - is distinct from 'project_submission_artifact_policy_mutation' - or evidence.resource_id is distinct from new.id - or evidence.project_id is distinct from reservation.project_id - or evidence.target_ref_kind is distinct from 'project' - or evidence.target_ref_id is distinct from reservation.project_id - or evidence.after_facts->>'allowed' is distinct from 'true' - or evidence.after_facts->>'resource_context_digest' - is distinct from reservation.resource_context_digest then - raise exception 'submission-policy creation evidence mismatch' - using errcode='23514'; - end if; - return null; - end $$ - """ - ) - op.execute( - "create constraint trigger submission_policy_creation_custody " - "after insert or update on submission_artifact_policies " - "deferrable initially deferred for each row " - "execute function validate_submission_policy_creation_custody()" - ) - op.execute( - """ - create function validate_submission_policy_authority_custody() returns trigger - language plpgsql as $$ - declare reservation submission_policy_mutation_idempotency_records%rowtype; - evidence audit_events%rowtype; - actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; - action_value varchar; decision_id varchar; product_project varchar; - product_id varchar; approval_outputs_valid boolean; - begin - if tg_table_name='submission_policy_mutation_idempotency_records' then - if new.status='pending' then return null; end if; - reservation:=new; - select project_id,id, - case when reservation.action_id='project.submission_artifact_policy.approve' - then approved_by_actor_profile_id else created_by_actor_profile_id end, - case when reservation.action_id='project.submission_artifact_policy.approve' - then approved_via_identity_link_id else created_via_identity_link_id end, - case when reservation.action_id='project.submission_artifact_policy.approve' - then approved_by_admin_role_grant_id - else created_by_admin_role_grant_id end, - case when reservation.action_id='project.submission_artifact_policy.approve' - then null else created_by_service_identity end, - case when reservation.action_id='project.submission_artifact_policy.approve' - then approval_action_id else creation_action_id end, - case when reservation.action_id='project.submission_artifact_policy.approve' - then approval_decision_event_id else creation_decision_event_id end - into product_project,product_id,actor_id,link_id,grant_id,service_id, - action_value,decision_id - from submission_artifact_policies where id=reservation.committed_policy_id; - if reservation.action_id='project.submission_artifact_policy.approve' then - select exists( - select 1 - from submission_artifact_policies s - join effective_project_submission_artifact_policies e - on e.id=reservation.committed_effective_policy_id - and e.submission_artifact_policy_id=s.id - and e.submission_artifact_policy_hash=s.policy_hash - join pre_submit_checker_policies p - on p.id=reservation.committed_pre_submit_policy_id - and p.project_id=e.project_id - where s.id=reservation.committed_policy_id - and s.id=reservation.policy_id - and s.guide_id=reservation.guide_id - and s.source_snapshot_id=reservation.source_snapshot_id - and s.guide_version=reservation.resource_context_json->>'guide_version' - and s.policy_hash=reservation.resource_context_json->>'policy_digest' - and e.effective_policy_hash= - reservation.resource_context_json->>'effective_output_digest' - and p.compiled_bundle_hash= - reservation.resource_context_json->>'compiled_pre_submit_output_digest' - and e.project_id=reservation.project_id - and e.guide_id=s.guide_id and p.guide_id=s.guide_id - and e.guide_version=s.guide_version - and p.guide_version=s.guide_version - and e.source_snapshot_id=s.source_snapshot_id - and p.source_snapshot_id=s.source_snapshot_id - and e.source_snapshot_hash=s.source_snapshot_hash - and p.source_snapshot_hash=s.source_snapshot_hash - and e.submission_artifact_policy_id=reservation.committed_policy_id - and p.effective_policy_id=e.id - and p.effective_policy_hash=e.effective_policy_hash - and e.created_by_actor_profile_id=reservation.actor_profile_id - and p.created_by_actor_profile_id=reservation.actor_profile_id - and e.created_via_identity_link_id=reservation.identity_link_id - and p.created_via_identity_link_id=reservation.identity_link_id - and e.created_by_admin_role_grant_id=grant_id - and p.created_by_admin_role_grant_id=grant_id - and e.creation_scope_project_id=reservation.project_id - and p.creation_scope_project_id=reservation.project_id - and e.creation_action_id=reservation.action_id - and p.creation_action_id=reservation.action_id - and e.creation_decision_event_id=decision_id - and p.creation_decision_event_id=decision_id - ) into approval_outputs_valid; - if approval_outputs_valid is not true then - raise exception 'submission-policy approval output custody mismatch' - using errcode='23514'; - end if; - end if; - elsif tg_table_name='submission_artifact_policies' then - if new.creation_action_id is null and new.approval_action_id is null then - if new.created_by_actor_profile_id is not null - or new.created_via_identity_link_id is not null - or new.created_by_admin_role_grant_id is not null - or new.created_by_service_identity is not null - or new.creation_scope_type is not null - or new.creation_scope_project_id is not null - or new.creation_decision_event_id is not null - or new.approved_by_actor_profile_id is not null - or new.approved_via_identity_link_id is not null - or new.approved_by_admin_role_grant_id is not null - or new.approval_scope_type is not null - or new.approval_scope_project_id is not null - or new.approval_decision_event_id is not null then - raise exception 'partial submission-policy provenance' - using errcode='23514'; - end if; - return null; - end if; - if new.approval_action_id is not null then - select * into reservation from submission_policy_mutation_idempotency_records - where committed_policy_id=new.id and action_id=new.approval_action_id - and status='committed'; - actor_id:=new.approved_by_actor_profile_id; - link_id:=new.approved_via_identity_link_id; - grant_id:=new.approved_by_admin_role_grant_id; - service_id:=null; action_value:=new.approval_action_id; - decision_id:=new.approval_decision_event_id; - else - select * into reservation from submission_policy_mutation_idempotency_records - where committed_policy_id=new.id and action_id=new.creation_action_id - and status='committed'; - actor_id:=new.created_by_actor_profile_id; - link_id:=new.created_via_identity_link_id; - grant_id:=new.created_by_admin_role_grant_id; - service_id:=new.created_by_service_identity; - action_value:=new.creation_action_id; - decision_id:=new.creation_decision_event_id; - end if; - product_project:=new.project_id; product_id:=new.id; - elsif tg_table_name='effective_project_submission_artifact_policies' then - if new.creation_action_id is null then - if new.created_by_actor_profile_id is not null - or new.created_via_identity_link_id is not null - or new.created_by_admin_role_grant_id is not null - or new.creation_scope_type is not null - or new.creation_scope_project_id is not null - or new.creation_decision_event_id is not null then - raise exception 'partial effective-policy provenance' - using errcode='23514'; - end if; - return null; - end if; - select * into reservation from submission_policy_mutation_idempotency_records - where committed_effective_policy_id=new.id and status='committed'; - actor_id:=new.created_by_actor_profile_id; - link_id:=new.created_via_identity_link_id; - grant_id:=new.created_by_admin_role_grant_id; - service_id:=null; action_value:=new.creation_action_id; - decision_id:=new.creation_decision_event_id; - product_project:=new.project_id; product_id:=reservation.committed_policy_id; - else - if new.creation_action_id is null then - if new.created_by_actor_profile_id is not null - or new.created_via_identity_link_id is not null - or new.created_by_admin_role_grant_id is not null - or new.creation_scope_type is not null - or new.creation_scope_project_id is not null - or new.creation_decision_event_id is not null then - raise exception 'partial pre-submit-policy provenance' - using errcode='23514'; - end if; - return null; - end if; - select * into reservation from submission_policy_mutation_idempotency_records - where committed_pre_submit_policy_id=new.id and status='committed'; - actor_id:=new.created_by_actor_profile_id; - link_id:=new.created_via_identity_link_id; - grant_id:=new.created_by_admin_role_grant_id; - service_id:=null; action_value:=new.creation_action_id; - decision_id:=new.creation_decision_event_id; - product_project:=new.project_id; product_id:=reservation.committed_policy_id; - end if; - if reservation.id is null or product_id is null - or reservation.actor_profile_id is distinct from actor_id - or reservation.identity_link_id is distinct from link_id - or reservation.action_id is distinct from action_value - or reservation.project_id is distinct from product_project - or reservation.committed_policy_id is distinct from product_id - or reservation.service_identity is distinct from service_id then - raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; - end if; - select * into evidence from audit_events where id=decision_id; - if evidence.id is null or evidence.event_domain is distinct from 'authority' - or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' - or evidence.denial_code is not null - or evidence.actor_ref_kind is distinct from 'actor_profile' - or evidence.actor_id is distinct from actor_id - or evidence.matched_grant_id is distinct from grant_id::text - or evidence.permission_id is distinct from 'project.effective_policy.manage' - or evidence.action_id is distinct from action_value - or evidence.resource_type - is distinct from 'project_submission_artifact_policy_mutation' - or evidence.resource_id is distinct from product_id - or evidence.project_id is distinct from reservation.project_id - or evidence.target_ref_kind is distinct from 'project' - or evidence.target_ref_id is distinct from reservation.project_id - or evidence.after_facts->>'allowed' is distinct from 'true' - or evidence.after_facts->>'resource_context_digest' - is distinct from reservation.resource_context_digest then - raise exception 'submission-policy authorization evidence mismatch' - using errcode='23514'; - end if; - return null; - end $$ - """ - ) - for trigger, table in ( - ("submission_policy_product_custody", "submission_artifact_policies"), - ("effective_submission_policy_custody", "effective_project_submission_artifact_policies"), - ("pre_submit_policy_custody", "pre_submit_checker_policies"), - ("submission_policy_replay_custody", "submission_policy_mutation_idempotency_records"), - ): - op.execute( - f"create constraint trigger {trigger} after insert or update on {table} " - "deferrable initially deferred for each row " - "execute function validate_submission_policy_authority_custody()" - ) - - -def downgrade() -> None: - """Remove the inactive foundation only when no replay/provenance exists.""" - connection = op.get_bind() - connection.execute(sa.text("lock table audit_events in access exclusive mode")) - for table in ( - "submission_policy_mutation_idempotency_records", - "submission_artifact_policies", - "effective_project_submission_artifact_policies", - "pre_submit_checker_policies", - ): - connection.execute(sa.text(f"lock table {table} in share row exclusive mode")) - replay_count = connection.execute( - sa.text("select count(*) from submission_policy_mutation_idempotency_records") - ).scalar_one() - provenance_count = connection.execute( - sa.text( - "select " - "(select count(*) from submission_artifact_policies where " - "created_by_actor_profile_id is not null or approved_by_actor_profile_id is not null) + " - "(select count(*) from effective_project_submission_artifact_policies where " - "created_by_actor_profile_id is not null) + " - "(select count(*) from pre_submit_checker_policies where " - "created_by_actor_profile_id is not null)" - ) - ).scalar_one() - audit_count = connection.execute( - sa.text( - "select count(*) from audit_events where " - "resource_type='project_submission_artifact_policy_mutation'" - ) - ).scalar_one() - if replay_count or provenance_count or audit_count: - raise RuntimeError("cannot downgrade submission-policy authority with evidence") - - for trigger, table in ( - ("submission_policy_replay_custody", "submission_policy_mutation_idempotency_records"), - ("pre_submit_policy_custody", "pre_submit_checker_policies"), - ("effective_submission_policy_custody", "effective_project_submission_artifact_policies"), - ("submission_policy_product_custody", "submission_artifact_policies"), - ): - op.execute(f"drop trigger {trigger} on {table}") - op.execute("drop function validate_submission_policy_authority_custody()") - op.execute( - "drop trigger submission_policy_creation_custody on submission_artifact_policies" - ) - op.execute("drop function validate_submission_policy_creation_custody()") - for trigger, table in ( - ("pre_submit_policy_provenance_immutable", "pre_submit_checker_policies"), - ( - "effective_submission_policy_provenance_immutable", - "effective_project_submission_artifact_policies", - ), - ): - op.execute(f"drop trigger {trigger} on {table}") - op.execute("drop function protect_submission_policy_output_provenance()") - op.execute( - "drop trigger submission_policy_approval_provenance_immutable " - "on submission_artifact_policies" - ) - op.execute("drop function protect_submission_policy_approval_provenance()") - op.execute( - "drop trigger submission_policy_creation_provenance_immutable " - "on submission_artifact_policies" - ) - op.execute("drop function protect_submission_policy_creation_provenance()") - - op.execute( - "drop trigger trg_submission_policy_replay_no_truncate " - "on submission_policy_mutation_idempotency_records" - ) - op.execute("drop function reject_submission_policy_replay_truncate()") - op.execute( - "drop trigger trg_submission_policy_replay_immutable " - "on submission_policy_mutation_idempotency_records" - ) - op.execute("drop function reject_submission_policy_replay_mutation()") - op.drop_table("submission_policy_mutation_idempotency_records") - - for table, constraint in ( - ("pre_submit_checker_policies", "ck_pre_submit_policy_authority_shape"), - ( - "effective_project_submission_artifact_policies", - "ck_effective_submission_policy_authority_shape", - ), - ("submission_artifact_policies", "ck_submission_policy_approval_authority_shape"), - ("submission_artifact_policies", "ck_submission_policy_creation_authority_shape"), - ): - op.drop_constraint(op.f(f"ck_{table}_{constraint}"), table, type_="check") - - for table, prefix, columns, approval in ( - ("pre_submit_checker_policies", "pre_submit_policy", _APPROVAL_OUTPUT_COLUMNS, False), - ( - "effective_project_submission_artifact_policies", - "effective_policy", - _APPROVAL_OUTPUT_COLUMNS, - False, - ), - ( - "submission_artifact_policies", - "submission_policy", - _SUBMISSION_APPROVAL_COLUMNS, - True, - ), - ( - "submission_artifact_policies", - "submission_policy", - _SUBMISSION_CREATION_COLUMNS, - False, - ), - ): - stem = "approval" if approval else "creation" - for suffix in ("actor", "link", "grant", "project", "decision"): - op.drop_constraint(f"fk_{prefix}_{stem}_{suffix}", table, type_="foreignkey") - for name, _column_type in reversed(columns): - op.drop_column(table, name) - _rewrite_audit_resource(add=False) diff --git a/backend/alembic/versions/0058_pre_submit_evidence.py b/backend/alembic/versions/0058_pre_submit_evidence.py deleted file mode 100644 index 21bac57f3..000000000 --- a/backend/alembic/versions/0058_pre_submit_evidence.py +++ /dev/null @@ -1,398 +0,0 @@ -"""install immutable pre-submit execution evidence - -Revision ID: 0058_pre_submit_evidence -Revises: 0057_submission_policy_authority -Create Date: 2026-08-05 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0058_pre_submit_evidence" -down_revision = "0057_submission_policy_authority" -branch_labels = depends_on = None - -_SHA256 = r"^sha256:[0-9a-f]{64}$" - - -def _immutable_guard(table: str) -> None: - op.execute( - f""" - create function guard_{table}_immutable() returns trigger language plpgsql as $$ - begin - raise exception '{table} rows are immutable' using errcode='55000'; - end; - $$ - """ - ) - op.execute( - f"create trigger {table}_immutable before update or delete on {table} " - f"for each row execute function guard_{table}_immutable()" - ) - op.execute( - f"create trigger {table}_no_truncate before truncate on {table} " - f"for each statement execute function guard_{table}_immutable()" - ) - - -def upgrade() -> None: - op.create_unique_constraint( - "uq_actor_identity_links_id_profile", - "actor_identity_links", - ["id", "actor_profile_id"], - ) - op.create_unique_constraint( - "uq_workstream_tasks_id_project", "workstream_tasks", ["id", "project_id"] - ) - op.create_unique_constraint( - "uq_task_assignments_id_task_contributor", - "task_assignments", - ["id", "task_id", "contributor_id"], - ) - op.create_unique_constraint( - "uq_project_guides_id_project_version", - "project_guides", - ["id", "project_id", "version"], - ) - op.create_table( - "pre_submit_evidence_sets", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("operation_identity", sa.String(71), nullable=False), - sa.Column("actor_profile_id", sa.String(36), nullable=False), - sa.Column("identity_link_id", sa.String(36), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=False), - sa.Column("assignment_id", sa.String(36), nullable=False), - sa.Column("predecessor_submission_id", sa.String(36)), - sa.Column("predecessor_submission_version", sa.Integer()), - sa.Column("prepared_generation_id", sa.String(36), nullable=False), - sa.Column("archive_sha256", sa.String(71), nullable=False), - sa.Column("archive_byte_count", sa.BigInteger(), nullable=False), - sa.Column("semantic_manifest_id", sa.String(36), nullable=False), - sa.Column("semantic_manifest_sha256", sa.String(71), nullable=False), - sa.Column("guide_id", sa.String(36), nullable=False), - sa.Column("guide_version", sa.String(50), nullable=False), - sa.Column("source_snapshot_id", sa.String(36), nullable=False), - sa.Column("source_snapshot_sha256", sa.String(71), nullable=False), - sa.Column("locked_guide_sha256", sa.String(71), nullable=False), - sa.Column("effective_policy_id", sa.String(36), nullable=False), - sa.Column("locked_artifact_policy_sha256", sa.String(71), nullable=False), - sa.Column("pre_submit_policy_id", sa.String(36), nullable=False), - sa.Column("locked_checker_policy_sha256", sa.String(71), nullable=False), - sa.Column("effective_plan_sha256", sa.String(71), nullable=False), - sa.Column("catalogue_id", sa.String(160), nullable=False), - sa.Column("catalogue_version", sa.String(40), nullable=False), - sa.Column("catalogue_manifest_sha256", sa.String(71), nullable=False), - sa.Column("storage_scheme", sa.String(16), nullable=False), - sa.Column("terminal_status", sa.String(16), nullable=False), - sa.Column("eligible", sa.Boolean(), nullable=False), - sa.Column("result_count", sa.Integer(), nullable=False), - sa.Column("result_manifest_sha256", sa.String(71), nullable=False), - sa.Column( - "created_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.func.now() - ), - sa.UniqueConstraint("operation_identity", name="uq_pre_submit_evidence_operation"), - sa.CheckConstraint( - f"operation_identity ~ '{_SHA256}'", name="ck_pre_submit_evidence_operation_sha256" - ), - sa.CheckConstraint( - f"archive_sha256 ~ '{_SHA256}'", name="ck_pre_submit_evidence_archive_sha256" - ), - sa.CheckConstraint( - f"semantic_manifest_sha256 ~ '{_SHA256}'", - name="ck_pre_submit_evidence_manifest_sha256", - ), - sa.CheckConstraint( - f"effective_plan_sha256 ~ '{_SHA256}'", name="ck_pre_submit_evidence_plan_sha256" - ), - sa.CheckConstraint( - f"catalogue_manifest_sha256 ~ '{_SHA256}'", - name="ck_pre_submit_evidence_catalogue_sha256", - ), - sa.CheckConstraint( - f"locked_guide_sha256 ~ '{_SHA256}'", name="ck_pre_submit_evidence_guide_sha256" - ), - sa.CheckConstraint( - f"source_snapshot_sha256 ~ '{_SHA256}'", - name="ck_pre_submit_evidence_source_snapshot_sha256", - ), - sa.CheckConstraint( - f"locked_artifact_policy_sha256 ~ '{_SHA256}'", - name="ck_pre_submit_evidence_artifact_policy_sha256", - ), - sa.CheckConstraint( - f"locked_checker_policy_sha256 ~ '{_SHA256}'", - name="ck_pre_submit_evidence_checker_policy_sha256", - ), - sa.CheckConstraint( - f"result_manifest_sha256 ~ '{_SHA256}'", - name="ck_pre_submit_evidence_result_manifest_sha256", - ), - sa.CheckConstraint("archive_byte_count >= 0", name="ck_pre_submit_evidence_archive_size"), - sa.CheckConstraint("result_count > 0", name="ck_pre_submit_evidence_result_count"), - sa.CheckConstraint( - "(predecessor_submission_id is null and predecessor_submission_version is null) " - "or (predecessor_submission_id is not null and " - "predecessor_submission_version is not null)", - name="ck_pre_submit_evidence_predecessor_shape", - ), - sa.CheckConstraint( - "storage_scheme in ('local','s3')", name="ck_pre_submit_evidence_storage_scheme" - ), - sa.CheckConstraint( - "terminal_status in ('passed','blocked')", - name="ck_pre_submit_evidence_terminal_status", - ), - sa.CheckConstraint( - "(terminal_status='passed' and eligible) or " - "(terminal_status='blocked' and not eligible)", - name="ck_pre_submit_evidence_status_eligibility", - ), - sa.ForeignKeyConstraint(["actor_profile_id"], ["actor_profiles.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["identity_link_id"], ["actor_identity_links.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["task_id"], ["workstream_tasks.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["assignment_id"], ["task_assignments.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["predecessor_submission_id"], ["submissions.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint(["guide_id"], ["project_guides.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["source_snapshot_id"], ["guide_source_snapshots.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["effective_policy_id"], - ["effective_project_submission_artifact_policies.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint( - ["pre_submit_policy_id"], ["pre_submit_checker_policies.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["identity_link_id", "actor_profile_id"], - ["actor_identity_links.id", "actor_identity_links.actor_profile_id"], - name="fk_pre_submit_evidence_identity_actor", - ), - sa.ForeignKeyConstraint( - ["assignment_id", "task_id", "actor_profile_id"], - ["task_assignments.id", "task_assignments.task_id", "task_assignments.contributor_id"], - name="fk_pre_submit_evidence_assignment", - ), - sa.ForeignKeyConstraint( - ["task_id", "project_id"], - ["workstream_tasks.id", "workstream_tasks.project_id"], - name="fk_pre_submit_evidence_task_project", - ), - sa.ForeignKeyConstraint( - ["task_id", "guide_version"], - ["workstream_tasks.id", "workstream_tasks.locked_guide_version"], - name="fk_pre_submit_evidence_task_guide", - ), - sa.ForeignKeyConstraint( - ["guide_id", "project_id", "guide_version"], - ["project_guides.id", "project_guides.project_id", "project_guides.version"], - name="fk_pre_submit_evidence_guide_lineage", - ), - sa.ForeignKeyConstraint( - ["task_id", "source_snapshot_id", "source_snapshot_sha256"], - [ - "workstream_tasks.id", - "workstream_tasks.locked_guide_source_snapshot_id", - "workstream_tasks.locked_guide_source_snapshot_hash", - ], - name="fk_pre_submit_evidence_task_source_snapshot", - ), - sa.ForeignKeyConstraint( - ["predecessor_submission_id", "task_id", "predecessor_submission_version"], - ["submissions.id", "submissions.task_id", "submissions.version"], - name="fk_pre_submit_evidence_predecessor", - ), - sa.ForeignKeyConstraint( - ["task_id", "effective_policy_id", "locked_artifact_policy_sha256"], - [ - "workstream_tasks.id", - "workstream_tasks.locked_effective_project_submission_artifact_policy_id", - "workstream_tasks.locked_effective_project_submission_artifact_policy_hash", - ], - name="fk_pre_submit_evidence_task_artifact_policy", - ), - sa.ForeignKeyConstraint( - ["task_id", "pre_submit_policy_id", "locked_checker_policy_sha256"], - [ - "workstream_tasks.id", - "workstream_tasks.locked_pre_submit_checker_policy_id", - "workstream_tasks.locked_pre_submit_checker_bundle_hash", - ], - name="fk_pre_submit_evidence_task_checker_policy", - ), - ) - op.create_index( - "ix_pre_submit_evidence_sets_actor_profile_id", - "pre_submit_evidence_sets", - ["actor_profile_id"], - ) - op.create_index( - "ix_pre_submit_evidence_sets_project_id", "pre_submit_evidence_sets", ["project_id"] - ) - op.create_index("ix_pre_submit_evidence_sets_task_id", "pre_submit_evidence_sets", ["task_id"]) - op.create_table( - "pre_submit_evidence_results", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("evidence_set_id", sa.String(36), nullable=False), - sa.Column("result_order", sa.Integer(), nullable=False), - sa.Column("schema_version", sa.String(80), nullable=False), - sa.Column("dispatch_authority", sa.String(160), nullable=False), - sa.Column("definition_id", sa.String(160), nullable=False), - sa.Column("definition_version", sa.String(40), nullable=False), - sa.Column("public_name", sa.String(160), nullable=False), - sa.Column("source", sa.String(160), nullable=False), - sa.Column("phase", sa.String(40), nullable=False), - sa.Column("classification", sa.String(40), nullable=False), - sa.Column("severity", sa.String(16), nullable=False), - sa.Column("status", sa.String(40), nullable=False), - sa.Column("failure_code", sa.String(160)), - sa.Column("message_code", sa.String(160), nullable=False), - sa.Column("effective_plan_sha256", sa.String(71), nullable=False), - sa.Column("rule_instance_id", sa.String(71)), - sa.Column("locked_policy_sha256", sa.String(71), nullable=False), - sa.Column( - "created_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.func.now() - ), - sa.UniqueConstraint("evidence_set_id", "result_order", name="uq_pre_submit_result_order"), - sa.UniqueConstraint( - "evidence_set_id", "definition_id", name="uq_pre_submit_result_definition" - ), - sa.CheckConstraint("result_order >= 0", name="ck_pre_submit_result_order"), - sa.CheckConstraint( - "status in ('passed','warning','advisory_disabled','dependency_not_run','failed')", - name="ck_pre_submit_result_status", - ), - sa.CheckConstraint( - "(status='failed' and failure_code is not null) or " - "(status<>'failed' and failure_code is null)", - name="result_failure_shape", - ), - sa.CheckConstraint( - "phase in ('custody','identity','materialization','default_policy','project_policy')", - name="ck_pre_submit_result_phase", - ), - sa.CheckConstraint( - "classification in ('mandatory_security','mandatory_integrity'," - "'mandatory_accountability','advisory')", - name="ck_pre_submit_result_classification", - ), - sa.CheckConstraint( - "severity in ('blocking','warning')", name="ck_pre_submit_result_severity" - ), - sa.CheckConstraint( - "(classification='advisory' and severity='warning') or " - "(classification<>'advisory' and severity='blocking')", - name="ck_pre_submit_result_classification_severity", - ), - sa.CheckConstraint( - f"effective_plan_sha256 ~ '{_SHA256}'", name="ck_pre_submit_result_plan_sha256" - ), - sa.CheckConstraint( - f"locked_policy_sha256 ~ '{_SHA256}'", name="ck_pre_submit_result_policy_sha256" - ), - sa.CheckConstraint( - "(phase='project_policy' and rule_instance_id is not null and " - f"rule_instance_id ~ '{_SHA256}') or " - "(phase<>'project_policy' and rule_instance_id is null)", - name="ck_pre_submit_result_rule_instance_shape", - ), - sa.ForeignKeyConstraint( - ["evidence_set_id"], ["pre_submit_evidence_sets.id"], ondelete="RESTRICT" - ), - ) - op.create_index( - "ix_pre_submit_evidence_results_evidence_set_id", - "pre_submit_evidence_results", - ["evidence_set_id"], - ) - op.execute( - """ - create function guard_pre_submit_evidence_set_creation() returns trigger - language plpgsql as $$ - begin - if new.created_at is distinct from transaction_timestamp() then - raise exception 'pre-submit evidence creation timestamp is invalid' - using errcode='55000'; - end if; - return new; - end; - $$ - """ - ) - op.execute( - "create trigger pre_submit_evidence_sets_creation before insert " - "on pre_submit_evidence_sets for each row execute function " - "guard_pre_submit_evidence_set_creation()" - ) - op.execute( - """ - create function guard_pre_submit_evidence_result_membership() returns trigger - language plpgsql as $$ - declare parent_created_at timestamptz; expected_count integer; current_count integer; - begin - select created_at, result_count into parent_created_at, expected_count - from pre_submit_evidence_sets where id=new.evidence_set_id for key share; - select count(*) into current_count from pre_submit_evidence_results - where evidence_set_id=new.evidence_set_id; - if parent_created_at is null - or parent_created_at <> transaction_timestamp() - or current_count >= expected_count then - raise exception 'pre-submit evidence result membership is closed' - using errcode='55000'; - end if; - return new; - end; - $$ - """ - ) - op.execute( - "create trigger pre_submit_evidence_results_membership before insert " - "on pre_submit_evidence_results for each row execute function " - "guard_pre_submit_evidence_result_membership()" - ) - _immutable_guard("pre_submit_evidence_results") - _immutable_guard("pre_submit_evidence_sets") - - -def downgrade() -> None: - bind = op.get_bind() - if bind.execute(sa.text("select count(*) from pre_submit_evidence_sets")).scalar_one(): - raise RuntimeError("cannot downgrade populated immutable pre-submit evidence") - op.execute("drop trigger pre_submit_evidence_results_membership on pre_submit_evidence_results") - op.execute("drop function guard_pre_submit_evidence_result_membership()") - op.execute("drop trigger pre_submit_evidence_sets_creation on pre_submit_evidence_sets") - op.execute("drop function guard_pre_submit_evidence_set_creation()") - for table in ("pre_submit_evidence_sets", "pre_submit_evidence_results"): - op.execute(f"drop trigger {table}_no_truncate on {table}") - op.execute(f"drop trigger {table}_immutable on {table}") - op.execute(f"drop function guard_{table}_immutable()") - op.drop_index( - "ix_pre_submit_evidence_results_evidence_set_id", - table_name="pre_submit_evidence_results", - ) - op.drop_table("pre_submit_evidence_results") - for name in ( - "ix_pre_submit_evidence_sets_task_id", - "ix_pre_submit_evidence_sets_project_id", - "ix_pre_submit_evidence_sets_actor_profile_id", - ): - op.drop_index(name, table_name="pre_submit_evidence_sets") - op.drop_table("pre_submit_evidence_sets") - op.drop_constraint( - "uq_project_guides_id_project_version", "project_guides", type_="unique" - ) - op.drop_constraint( - "uq_task_assignments_id_task_contributor", "task_assignments", type_="unique" - ) - op.drop_constraint("uq_workstream_tasks_id_project", "workstream_tasks", type_="unique") - op.drop_constraint("uq_actor_identity_links_id_profile", "actor_identity_links", type_="unique") diff --git a/backend/alembic/versions/0059_submission_policy_execution_claim.py b/backend/alembic/versions/0059_submission_policy_execution_claim.py deleted file mode 100644 index 3bc9dd63e..000000000 --- a/backend/alembic/versions/0059_submission_policy_execution_claim.py +++ /dev/null @@ -1,169 +0,0 @@ -"""add durable submission-policy derivation execution claims - -Revision ID: 0059_policy_execution_claim -Revises: 0058_pre_submit_evidence -Create Date: 2026-08-07 -""" - -from __future__ import annotations - -from alembic import op - - -revision = "0059_policy_execution_claim" -down_revision = "0058_pre_submit_evidence" -branch_labels = depends_on = None - - -def _install_guard(*, allow_reserved: bool) -> None: - reserved_transition = """ - if old.status = 'reserved' and new.status = 'pending' - and old.service_identity = 'workstream.project.setup' - and old.action_id = 'project.submission_artifact_policy.derive' - and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, - new.action_id,new.idempotency_key,new.operation_id,new.project_id, - new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, - new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, - new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, - new.committed_pre_submit_policy_id,new.committed_at) - is not distinct from - (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, - old.action_id,old.idempotency_key,old.operation_id,old.project_id, - old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, - old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, - old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, - old.committed_pre_submit_policy_id,old.committed_at) - then - return new; - end if; - """ if allow_reserved else "" - op.execute("drop function if exists reject_submission_policy_replay_mutation() cascade") - op.execute( - f""" - create function reject_submission_policy_replay_mutation() returns trigger - language plpgsql as $$ - begin - if tg_op = 'DELETE' then - raise exception 'submission-policy replay rows cannot be deleted'; - end if; -{reserved_transition} - if old.status <> 'pending' or new.status <> 'committed' - or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, - new.action_id,new.idempotency_key,new.request_digest, - new.resource_context_digest,new.resource_context_json::text,new.operation_id, - new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, - new.setup_run_id,new.setup_generation,new.setup_task_id, - new.correlation_id,new.created_at) - is distinct from - (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, - old.action_id,old.idempotency_key,old.request_digest, - old.resource_context_digest,old.resource_context_json::text,old.operation_id, - old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, - old.setup_run_id,old.setup_generation,old.setup_task_id, - old.correlation_id,old.created_at) - then - raise exception 'invalid submission-policy replay mutation'; - end if; - return new; - end $$ - """ - ) - op.execute( - "create trigger trg_submission_policy_replay_immutable before update or delete " - "on submission_policy_mutation_idempotency_records for each row " - "execute function reject_submission_policy_replay_mutation()" - ) - - -def upgrade() -> None: - op.execute( - "drop trigger submission_policy_replay_custody " - "on submission_policy_mutation_idempotency_records" - ) - op.execute( - "create constraint trigger submission_policy_replay_custody after insert or update " - "on submission_policy_mutation_idempotency_records deferrable initially deferred " - "for each row when (new.status='committed') " - "execute function validate_submission_policy_authority_custody()" - ) - op.drop_constraint( - "ck_submission_policy_replay_status", - "submission_policy_mutation_idempotency_records", - type_="check", - ) - op.drop_constraint( - "ck_submission_policy_replay_state_shape", - "submission_policy_mutation_idempotency_records", - type_="check", - ) - op.create_check_constraint( - "ck_submission_policy_replay_status", - "submission_policy_mutation_idempotency_records", - "status in ('reserved','pending','committed')", - ) - op.create_check_constraint( - "ck_submission_policy_replay_state_shape", - "submission_policy_mutation_idempotency_records", - "(status in ('reserved','pending') and response_json is null and committed_at is null " - "and committed_policy_id is null and committed_effective_policy_id is null " - "and committed_pre_submit_policy_id is null) or " - "(status='committed' and response_json is not null and committed_at is not null " - "and committed_policy_id is not null and " - "((action_id='project.submission_artifact_policy.approve' " - "and committed_effective_policy_id is not null " - "and committed_pre_submit_policy_id is not null) or " - "(action_id<>'project.submission_artifact_policy.approve' " - "and committed_effective_policy_id is null " - "and committed_pre_submit_policy_id is null)))", - ) - _install_guard(allow_reserved=True) - - -def downgrade() -> None: - op.execute("drop function reject_submission_policy_replay_mutation() cascade") - op.execute( - "do $$ begin if exists (select 1 from " - "submission_policy_mutation_idempotency_records where status='reserved') then " - "raise exception 'cannot downgrade submission-policy execution claims with reservations'; " - "end if; end $$" - ) - op.drop_constraint( - "ck_submission_policy_replay_status", - "submission_policy_mutation_idempotency_records", - type_="check", - ) - op.drop_constraint( - "ck_submission_policy_replay_state_shape", - "submission_policy_mutation_idempotency_records", - type_="check", - ) - op.create_check_constraint( - "ck_submission_policy_replay_status", - "submission_policy_mutation_idempotency_records", - "status in ('pending','committed')", - ) - op.create_check_constraint( - "ck_submission_policy_replay_state_shape", - "submission_policy_mutation_idempotency_records", - "(status='pending' and response_json is null and committed_at is null " - "and committed_policy_id is null and committed_effective_policy_id is null " - "and committed_pre_submit_policy_id is null) or " - "(status='committed' and response_json is not null and committed_at is not null " - "and committed_policy_id is not null and " - "((action_id='project.submission_artifact_policy.approve' " - "and committed_effective_policy_id is not null " - "and committed_pre_submit_policy_id is not null) or " - "(action_id<>'project.submission_artifact_policy.approve' " - "and committed_effective_policy_id is null " - "and committed_pre_submit_policy_id is null)))", - ) - _install_guard(allow_reserved=False) - op.execute( - "drop trigger submission_policy_replay_custody " - "on submission_policy_mutation_idempotency_records" - ) - op.execute( - "create constraint trigger submission_policy_replay_custody after insert or update " - "on submission_policy_mutation_idempotency_records deferrable initially deferred " - "for each row execute function validate_submission_policy_authority_custody()" - ) diff --git a/backend/alembic/versions/0060_submission_bundle_durable_intent.py b/backend/alembic/versions/0060_submission_bundle_durable_intent.py deleted file mode 100644 index 87d241014..000000000 --- a/backend/alembic/versions/0060_submission_bundle_durable_intent.py +++ /dev/null @@ -1,251 +0,0 @@ -"""Install submission-bundle durable put intent. - -Revision ID: 0060_submission_bundle_intent -Revises: 0059_policy_execution_claim -Create Date: 2026-08-07 -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0060_submission_bundle_intent" -down_revision = "0059_policy_execution_claim" -branch_labels = depends_on = None - -_UUID = ( - r"^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-" - r"[89ab][0-9a-f]{3}-[0-9a-f]{12}$" -) -_CURRENT_REQUEST_TYPES = "producer_request_type in ('guide', 'checker_output')" -_SUBMISSION_REQUEST_TYPES = ( - "producer_request_type in ('guide', 'checker_output', 'submission_bundle')" -) -_CURRENT_PRODUCER_IDENTITY = ( - "((producer_request_type = 'guide' and producer_type = 'actor_profile' " - f"and producer_ref ~ '{_UUID}') or " - "(producer_request_type = 'checker_output' and producer_type = 'service_identity' " - "and producer_ref = 'workstream.artifact.checker_output'))" -) -_SUBMISSION_PRODUCER_IDENTITY = ( - "((producer_request_type = 'guide' and producer_type = 'actor_profile' " - f"and producer_ref ~ '{_UUID}') or " - "(producer_request_type = 'checker_output' and producer_type = 'service_identity' " - "and producer_ref = 'workstream.artifact.checker_output') or " - "(producer_request_type = 'submission_bundle' and producer_type = 'actor_profile' " - f"and producer_ref ~ '{_UUID}'))" -) -_CURRENT_PRODUCER_REFERENCE = ( - "(producer_request_type = 'guide' and guide_source_item_id is not null " - "and checker_run_id is null and task_id is null and logical_role is null) or " - "(producer_request_type = 'checker_output' and guide_source_item_id is null " - "and checker_run_id is not null and task_id is not null " - "and octet_length(logical_role) between 1 and 100)" -) -_SUBMISSION_PRODUCER_REFERENCE = ( - f"{_CURRENT_PRODUCER_REFERENCE} or " - "(producer_request_type = 'submission_bundle' and guide_source_item_id is null " - "and checker_run_id is null and task_id is not null and logical_role is null)" -) -_CURRENT_RECEIPT_REFERENCE = ( - "contract_version = 2 and put_attempt_id is not null and " - "((guide_source_item_id is not null)::int + " - "(checker_run_id is not null)::int) = 1" -) -_SUBMISSION_RECEIPT_REFERENCE = ( - "contract_version = 2 and put_attempt_id is not null and " - "((guide_source_item_id is not null and checker_run_id is null " - "and logical_role is null) or " - "(guide_source_item_id is null and checker_run_id is not null " - "and octet_length(logical_role) between 1 and 100) or " - "(guide_source_item_id is null and checker_run_id is null " - "and logical_role is null))" -) - - -def _replace_put_constraint(name: str, expression: str) -> None: - op.drop_constraint(name, "artifact_put_attempts", type_="check") - op.create_check_constraint(name, "artifact_put_attempts", expression) - - -def upgrade() -> None: - _replace_put_constraint("producer_request_type", _SUBMISSION_REQUEST_TYPES) - _replace_put_constraint("producer_identity", _SUBMISSION_PRODUCER_IDENTITY) - _replace_put_constraint("producer_reference", _SUBMISSION_PRODUCER_REFERENCE) - op.drop_constraint( - "contract_producer_reference", - "artifact_operation_receipts", - type_="check", - ) - op.create_check_constraint( - "contract_producer_reference", - "artifact_operation_receipts", - _SUBMISSION_RECEIPT_REFERENCE, - ) - op.execute( - """ - create function guard_artifact_receipt_producer_reference() - returns trigger language plpgsql as $$ - declare request_type text; - begin - select producer_request_type into request_type - from artifact_put_attempts where id = new.put_attempt_id; - if request_type is null - or (request_type = 'guide' and not ( - new.guide_source_item_id is not null and new.checker_run_id is null - and new.logical_role is null)) - or (request_type = 'checker_output' and not ( - new.guide_source_item_id is null and new.checker_run_id is not null - and octet_length(new.logical_role) between 1 and 100)) - or (request_type = 'submission_bundle' and not ( - new.guide_source_item_id is null and new.checker_run_id is null - and new.logical_role is null)) - then - raise exception 'artifact receipt producer reference mismatch' - using errcode='23514'; - end if; - return new; - end; - $$ - """ - ) - op.execute( - "create trigger artifact_receipt_producer_reference " - "before insert or update of put_attempt_id, guide_source_item_id, " - "checker_run_id, logical_role on artifact_operation_receipts " - "for each row execute function guard_artifact_receipt_producer_reference()" - ) - op.create_table( - "submission_bundle_durable_intents", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("pre_submit_evidence_set_id", sa.String(36), nullable=False), - sa.Column("put_attempt_id", sa.String(36), nullable=False), - sa.Column( - "created_at", - sa.DateTime(timezone=True), - nullable=False, - server_default=sa.func.now(), - ), - sa.UniqueConstraint( - "pre_submit_evidence_set_id", - name="uq_submission_bundle_intent_evidence", - ), - sa.UniqueConstraint( - "put_attempt_id", - name="uq_submission_bundle_intent_put_attempt", - ), - sa.ForeignKeyConstraint( - ["pre_submit_evidence_set_id"], - ["pre_submit_evidence_sets.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint( - ["put_attempt_id"], - ["artifact_put_attempts.id"], - ondelete="RESTRICT", - ), - ) - op.create_index( - "ix_submission_bundle_durable_intents_pre_submit_evidence_set_id", - "submission_bundle_durable_intents", - ["pre_submit_evidence_set_id"], - ) - op.create_index( - "ix_submission_bundle_durable_intents_put_attempt_id", - "submission_bundle_durable_intents", - ["put_attempt_id"], - ) - op.execute( - """ - create function guard_submission_bundle_durable_intent_put_attempt() - returns trigger language plpgsql as $$ - declare request_type text; - begin - select producer_request_type into request_type - from artifact_put_attempts - where id = new.put_attempt_id - for share; - if request_type is distinct from 'submission_bundle' then - raise exception 'submission bundle durable intent requires submission_bundle put attempt' - using errcode='23514'; - end if; - return new; - end; - $$ - """ - ) - op.execute( - "create trigger submission_bundle_durable_intent_put_attempt " - "before insert on submission_bundle_durable_intents " - "for each row execute function " - "guard_submission_bundle_durable_intent_put_attempt()" - ) - op.execute( - """ - create function guard_submission_bundle_durable_intents_immutable() - returns trigger language plpgsql as $$ - begin - raise exception 'submission_bundle_durable_intents rows are immutable' - using errcode='55000'; - end; - $$ - """ - ) - op.execute( - "create trigger submission_bundle_durable_intents_immutable " - "before update or delete on submission_bundle_durable_intents " - "for each row execute function " - "guard_submission_bundle_durable_intents_immutable()" - ) - op.execute( - "create trigger submission_bundle_durable_intents_no_truncate " - "before truncate on submission_bundle_durable_intents " - "for each statement execute function " - "guard_submission_bundle_durable_intents_immutable()" - ) - - -def downgrade() -> None: - bind = op.get_bind() - if bind.execute(sa.text("select count(*) from submission_bundle_durable_intents")).scalar_one(): - raise RuntimeError("cannot remove populated submission-bundle durable intents") - op.execute("drop trigger artifact_receipt_producer_reference on artifact_operation_receipts") - op.execute("drop function guard_artifact_receipt_producer_reference()") - op.execute( - "drop trigger submission_bundle_durable_intents_no_truncate " - "on submission_bundle_durable_intents" - ) - op.execute( - "drop trigger submission_bundle_durable_intents_immutable " - "on submission_bundle_durable_intents" - ) - op.execute("drop function guard_submission_bundle_durable_intents_immutable()") - op.execute( - "drop trigger submission_bundle_durable_intent_put_attempt " - "on submission_bundle_durable_intents" - ) - op.execute("drop function guard_submission_bundle_durable_intent_put_attempt()") - op.drop_index( - "ix_submission_bundle_durable_intents_put_attempt_id", - table_name="submission_bundle_durable_intents", - ) - op.drop_index( - "ix_submission_bundle_durable_intents_pre_submit_evidence_set_id", - table_name="submission_bundle_durable_intents", - ) - op.drop_table("submission_bundle_durable_intents") - op.drop_constraint( - "contract_producer_reference", - "artifact_operation_receipts", - type_="check", - ) - op.create_check_constraint( - "contract_producer_reference", - "artifact_operation_receipts", - _CURRENT_RECEIPT_REFERENCE, - ) - _replace_put_constraint("producer_reference", _CURRENT_PRODUCER_REFERENCE) - _replace_put_constraint("producer_identity", _CURRENT_PRODUCER_IDENTITY) - _replace_put_constraint("producer_request_type", _CURRENT_REQUEST_TYPES) diff --git a/backend/alembic/versions/0061_submission_bundle_admission.py b/backend/alembic/versions/0061_submission_bundle_admission.py deleted file mode 100644 index c9b033848..000000000 --- a/backend/alembic/versions/0061_submission_bundle_admission.py +++ /dev/null @@ -1,328 +0,0 @@ -"""Install verified submission-bundle ready admissions. - -Revision ID: 0061_submission_admission -Revises: 0060_submission_bundle_intent -Create Date: 2026-08-08 -""" - -from __future__ import annotations - -import hashlib -import json - -from alembic import op -import sqlalchemy as sa - - -revision = "0061_submission_admission" -down_revision = "0060_submission_bundle_intent" -branch_labels = depends_on = None - - -def upgrade() -> None: - op.add_column( - "pre_submit_evidence_sets", - sa.Column("locked_policy_context_hash", sa.String(71), nullable=True), - ) - bind = op.get_bind() - rows = list( - bind.execute( - sa.text( - "select id,guide_id,guide_version,source_snapshot_id,source_snapshot_sha256," - "locked_guide_sha256,effective_policy_id,locked_artifact_policy_sha256," - "pre_submit_policy_id,locked_checker_policy_sha256,effective_plan_sha256 " - "from pre_submit_evidence_sets" - ) - ).mappings() - ) - # 0058 made evidence rows immutable. This reviewed migration is the sole - # bounded exception: add one deterministic derived column, then restore the - # guard before installing any admission surface. - op.execute( - "alter table pre_submit_evidence_sets disable trigger pre_submit_evidence_sets_immutable" - ) - for row in rows: - value = {key: row[key] for key in row if key != "id"} - encoded = json.dumps( - value, sort_keys=True, separators=(",", ":"), ensure_ascii=False - ).encode("utf-8") - digest = f"sha256:{hashlib.sha256(encoded).hexdigest()}" - bind.execute( - sa.text( - "update pre_submit_evidence_sets set locked_policy_context_hash=:digest " - "where id=:id" - ), - {"id": row["id"], "digest": digest}, - ) - op.execute( - "alter table pre_submit_evidence_sets enable trigger pre_submit_evidence_sets_immutable" - ) - op.alter_column("pre_submit_evidence_sets", "locked_policy_context_hash", nullable=False) - op.create_check_constraint( - "policy_context_sha256", - "pre_submit_evidence_sets", - "locked_policy_context_hash ~ '^sha256:[0-9a-f]{64}$'", - ) - op.create_table( - "submission_bundle_admissions", - sa.Column("id", sa.String(36), primary_key=True), - sa.Column("durable_intent_id", sa.String(36), nullable=False), - sa.Column("pre_submit_evidence_set_id", sa.String(36), nullable=False), - sa.Column("put_attempt_id", sa.String(36), nullable=False), - sa.Column("artifact_content_id", sa.String(36), nullable=False), - sa.Column("verified_replica_id", sa.String(36), nullable=False), - sa.Column("verification_receipt_id", sa.String(36), nullable=False), - sa.Column("put_operation_receipt_id", sa.String(36)), - sa.Column("put_observation_receipt_id", sa.String(36)), - sa.Column("actor_profile_id", sa.String(36), nullable=False), - sa.Column("identity_link_id", sa.String(36), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("task_id", sa.String(36), nullable=False), - sa.Column("assignment_id", sa.String(36), nullable=False), - sa.Column("predecessor_submission_id", sa.String(36)), - sa.Column("predecessor_submission_version", sa.Integer()), - sa.Column("locked_policy_context_hash", sa.String(71), nullable=False), - sa.Column("semantic_manifest_id", sa.String(36), nullable=False), - sa.Column("semantic_manifest_sha256", sa.String(71), nullable=False), - sa.Column("archive_sha256", sa.String(71), nullable=False), - sa.Column("archive_byte_count", sa.BigInteger(), nullable=False), - sa.Column("status", sa.String(16), nullable=False, server_default="ready"), - sa.Column("ready_at", sa.DateTime(timezone=True), nullable=False), - sa.Column("consumed_at", sa.DateTime(timezone=True)), - sa.Column("consumed_by_submission_id", sa.String(36)), - sa.Column("stale_at", sa.DateTime(timezone=True)), - sa.Column("stale_reason", sa.String(500)), - sa.Column( - "created_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.func.now() - ), - sa.ForeignKeyConstraint( - ["durable_intent_id"], ["submission_bundle_durable_intents.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["pre_submit_evidence_set_id"], ["pre_submit_evidence_sets.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["put_attempt_id"], ["artifact_put_attempts.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["artifact_content_id"], ["artifact_contents.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["verified_replica_id"], ["artifact_replicas.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["verification_receipt_id"], ["artifact_verification_receipts.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["put_operation_receipt_id"], ["artifact_operation_receipts.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["put_observation_receipt_id"], - ["artifact_put_observation_receipts.id"], - ondelete="RESTRICT", - ), - sa.ForeignKeyConstraint(["actor_profile_id"], ["actor_profiles.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["identity_link_id"], ["actor_identity_links.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["task_id"], ["workstream_tasks.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint(["assignment_id"], ["task_assignments.id"], ondelete="RESTRICT"), - sa.ForeignKeyConstraint( - ["predecessor_submission_id"], ["submissions.id"], ondelete="RESTRICT" - ), - sa.ForeignKeyConstraint( - ["consumed_by_submission_id"], ["submissions.id"], ondelete="RESTRICT" - ), - sa.UniqueConstraint("durable_intent_id", name="uq_submission_bundle_admission_intent"), - sa.UniqueConstraint( - "pre_submit_evidence_set_id", name="uq_submission_bundle_admission_evidence" - ), - sa.UniqueConstraint( - "verification_receipt_id", name="uq_submission_bundle_admission_verification" - ), - sa.CheckConstraint("status in ('ready','consumed','stale')", name="status"), - sa.CheckConstraint( - "locked_policy_context_hash ~ '^sha256:[0-9a-f]{64}$'", name="policy_context_hash" - ), - sa.CheckConstraint( - "semantic_manifest_sha256 ~ '^sha256:[0-9a-f]{64}$'", name="manifest_sha256" - ), - sa.CheckConstraint("archive_sha256 ~ '^sha256:[0-9a-f]{64}$'", name="archive_sha256"), - sa.CheckConstraint("archive_byte_count >= 0", name="archive_size"), - sa.CheckConstraint( - "((put_operation_receipt_id is not null)::int + (put_observation_receipt_id is not null)::int) = 1", - name="write_receipt_shape", - ), - sa.CheckConstraint( - "(predecessor_submission_id is null) = (predecessor_submission_version is null)", - name="predecessor_shape", - ), - sa.CheckConstraint( - "(status='ready' and consumed_at is null and consumed_by_submission_id is null and stale_at is null and stale_reason is null) or " - "(status='consumed' and consumed_at is not null and consumed_by_submission_id is not null and stale_at is null and stale_reason is null) or " - "(status='stale' and consumed_at is null and consumed_by_submission_id is null and stale_at is not null and octet_length(stale_reason) between 1 and 500)", - name="terminal_shape", - ), - ) - for column in ( - "pre_submit_evidence_set_id", - "artifact_content_id", - "actor_profile_id", - "project_id", - "task_id", - "status", - ): - op.create_index( - f"ix_submission_bundle_admissions_{column}", "submission_bundle_admissions", [column] - ) - op.create_index( - "uq_submission_bundle_admission_consumer", - "submission_bundle_admissions", - ["consumed_by_submission_id"], - unique=True, - postgresql_where=sa.text("consumed_by_submission_id is not null"), - ) - op.execute( - """ - create function guard_submission_bundle_admission_verified_lineage() - returns trigger language plpgsql as $$ - declare matches integer; - begin - select count(*) into matches - from submission_bundle_durable_intents intent - join pre_submit_evidence_sets evidence - on evidence.id=intent.pre_submit_evidence_set_id - join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id - join artifact_replicas replica on replica.id=attempt.replica_id - join artifact_contents content on content.id=replica.content_id - join artifact_verification_jobs job - on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id - join artifact_verification_receipts verification - on verification.verification_job_id=job.id - where intent.id=new.durable_intent_id - and evidence.id=new.pre_submit_evidence_set_id - and attempt.id=new.put_attempt_id - and content.id=new.artifact_content_id - and replica.id=new.verified_replica_id - and verification.id=new.verification_receipt_id - and attempt.producer_request_type='submission_bundle' - and attempt.producer_type='actor_profile' - and attempt.producer_ref=evidence.actor_profile_id - and attempt.project_id=evidence.project_id - and attempt.task_id=evidence.task_id - and attempt.media_type='application/zip' - and content.media_type='application/zip' - and attempt.status='object_confirmed' - and evidence.terminal_status='passed' and evidence.eligible - and replica.verification_state='verified' - and replica.availability_state='available' - and replica.integrity_state='valid' - and verification.outcome='verified' - and verification.execution_generation=job.execution_generation - and verification.observed_sha256=attempt.sha256 - and verification.observed_sha256=content.sha256 - and verification.observed_sha256=evidence.archive_sha256 - and verification.observed_byte_count=attempt.byte_count - and verification.observed_byte_count=content.byte_count - and verification.observed_byte_count=evidence.archive_byte_count - and new.actor_profile_id=evidence.actor_profile_id - and new.identity_link_id=evidence.identity_link_id - and new.project_id=evidence.project_id and new.task_id=evidence.task_id - and new.assignment_id=evidence.assignment_id - and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id - and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version - and new.locked_policy_context_hash=evidence.locked_policy_context_hash - and new.semantic_manifest_id=evidence.semantic_manifest_id - and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 - and new.archive_sha256=evidence.archive_sha256 - and new.archive_byte_count=evidence.archive_byte_count - and ((new.put_operation_receipt_id is not null and exists ( - select 1 from artifact_operation_receipts receipt - where receipt.id=new.put_operation_receipt_id - and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id - and receipt.outcome='stored_pending_verification')) - or (new.put_observation_receipt_id is not null and exists ( - select 1 from artifact_put_observation_receipts observation - where observation.id=new.put_observation_receipt_id - and observation.put_attempt_id=attempt.id - and observation.outcome='observed_confirmed' - and observation.observed_sha256=attempt.sha256 - and observation.observed_byte_count=attempt.byte_count))); - if matches <> 1 then - raise exception 'submission bundle admission verified lineage mismatch' - using errcode='23514'; - end if; - return new; - end; - $$ - """ - ) - op.execute( - "create trigger submission_bundle_admission_verified_lineage before insert on submission_bundle_admissions for each row execute function guard_submission_bundle_admission_verified_lineage()" - ) - op.execute( - """ - create function guard_submission_bundle_admission_lineage() - returns trigger language plpgsql as $$ - begin - if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, - old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, - old.put_operation_receipt_id, old.put_observation_receipt_id, - old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, - old.assignment_id, old.predecessor_submission_id, - old.predecessor_submission_version, - old.locked_policy_context_hash, - old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, - old.archive_byte_count, old.ready_at, old.created_at) - is distinct from - row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, - new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, - new.put_operation_receipt_id, new.put_observation_receipt_id, - new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, - new.assignment_id, new.predecessor_submission_id, - new.predecessor_submission_version, - new.locked_policy_context_hash, - new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, - new.archive_byte_count, new.ready_at, new.created_at) - then - raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; - end if; - if old.status <> 'ready' or new.status not in ('consumed','stale') then - raise exception 'invalid submission bundle admission transition' using errcode='23514'; - end if; - return new; - end; - $$ - """ - ) - op.execute( - "create trigger submission_bundle_admission_lineage before update on submission_bundle_admissions for each row execute function guard_submission_bundle_admission_lineage()" - ) - op.execute( - "create function guard_submission_bundle_admission_delete() returns trigger language plpgsql as $$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $$" - ) - op.execute( - "create trigger submission_bundle_admission_delete before delete or truncate on submission_bundle_admissions for each statement execute function guard_submission_bundle_admission_delete()" - ) - - -def downgrade() -> None: - bind = op.get_bind() - if bind.execute(sa.text("select count(*) from submission_bundle_admissions")).scalar_one(): - raise RuntimeError("cannot remove populated submission-bundle admissions") - op.execute("drop trigger submission_bundle_admission_delete on submission_bundle_admissions") - op.execute("drop function guard_submission_bundle_admission_delete()") - op.execute("drop trigger submission_bundle_admission_lineage on submission_bundle_admissions") - op.execute("drop function guard_submission_bundle_admission_lineage()") - op.execute( - "drop trigger submission_bundle_admission_verified_lineage on submission_bundle_admissions" - ) - op.execute("drop function guard_submission_bundle_admission_verified_lineage()") - op.drop_table("submission_bundle_admissions") - op.drop_constraint( - "policy_context_sha256", - "pre_submit_evidence_sets", - type_="check", - ) - op.drop_column("pre_submit_evidence_sets", "locked_policy_context_hash") diff --git a/backend/alembic/versions/0062_project_guide_compilation_foundation.py b/backend/alembic/versions/0062_project_guide_compilation_foundation.py deleted file mode 100644 index 371063645..000000000 --- a/backend/alembic/versions/0062_project_guide_compilation_foundation.py +++ /dev/null @@ -1,484 +0,0 @@ -"""Install hidden unified guide-compilation persistence. - -Revision ID: 0062_guide_compilation -Revises: 0061_submission_admission -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - -revision = "0062_guide_compilation" -down_revision = "0061_submission_admission" -branch_labels = depends_on = None - -_HASH = r"^sha256:[0-9a-f]{64}$" -_ACTION = "project.guide_compilation.execute" -_PERMISSION = "project.guide_compilation.execute" -_RESOURCE_MARKER = ( - "('project_submission_artifact_policy_mutation'::character varying)::text" -) -_RESOURCE_ADDITION = ( - ", ('project_guide_compilation_attempt'::character varying)::text" -) -_PERMISSION_MARKER = "('review.queue.override'::character varying)::text" -_PERMISSION_ADDITION = ( - ", ('project.guide_compilation.execute'::character varying)::text" -) - - -def _rewrite_permission_registry(*, add: bool) -> None: - connection = op.get_bind() - definition = connection.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_registries'" - ) - ).scalar_one() - expanded = _PERMISSION_MARKER + _PERMISSION_ADDITION - source, target = ( - (_PERMISSION_MARKER, expanded) - if add - else (expanded, _PERMISSION_MARKER) - ) - if definition.count(source) != 1 or (add and expanded in definition): - raise RuntimeError("unexpected compilation permission registry") - op.drop_constraint("authority_registries", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authority_registries {definition.replace(source, target, 1)}" - ) - - -def _rewrite_audit_resource(*, add: bool) -> None: - connection = op.get_bind() - definition = connection.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_privacy_bounds'" - ) - ).scalar_one() - expanded = _RESOURCE_MARKER + _RESOURCE_ADDITION - source, target = ( - (_RESOURCE_MARKER, expanded) - if add - else (expanded, _RESOURCE_MARKER) - ) - if definition.count(source) != 1 or (add and expanded in definition): - raise RuntimeError("unexpected compilation audit-resource registry") - op.drop_constraint("authority_privacy_bounds", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authority_privacy_bounds {definition.replace(source, target, 1)}" - ) - - -def _action_pair_token() -> str: - return ( - f"(((action_id)::text = '{_ACTION}'::text) AND " - f"((permission_id)::text = '{_PERMISSION}'::text))" - ) - - -def _rewrite_action_evidence(*, add: bool) -> None: - connection = op.get_bind() - definition = connection.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authorization_action_evidence'" - ) - ).scalar_one() - marker = ( - "(((action_id)::text = 'project.guide_sufficiency.run'::text) AND " - "((permission_id)::text = 'project.guide.manage'::text))" - ) - addition = " OR " + _action_pair_token() - if add: - if definition.count(marker) != 2 or _action_pair_token() in definition: - raise RuntimeError("unexpected compilation action-evidence registry") - definition = definition.replace(marker, marker + addition) - else: - if definition.count(addition) != 2: - raise RuntimeError("unexpected compilation action-evidence registry") - definition = definition.replace(addition, "") - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authorization_action_evidence {definition}" - ) - - -def upgrade() -> None: - """Create the attempt fence and append-only compilation graph.""" - op.execute("lock table audit_events in access exclusive mode") - _rewrite_audit_resource(add=True) - _rewrite_permission_registry(add=True) - _rewrite_action_evidence(add=True) - op.create_table( - "project_guide_compilation_attempts", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("guide_id", sa.String(36), nullable=False), - sa.Column("guide_version", sa.String(50), nullable=False), - sa.Column("source_snapshot_id", sa.String(36), nullable=False), - sa.Column("source_snapshot_hash", sa.String(71), nullable=False), - sa.Column("setup_run_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("canonical_input_hash", sa.String(71), nullable=False), - sa.Column("guide_material_hash", sa.String(71), nullable=False), - sa.Column("pre_catalogue_id", sa.String(160), nullable=False), - sa.Column("pre_catalogue_version", sa.String(100), nullable=False), - sa.Column("pre_catalogue_schema_version", sa.String(160), nullable=False), - sa.Column("pre_catalogue_manifest_hash", sa.String(71), nullable=False), - sa.Column("post_catalogue_id", sa.String(160), nullable=False), - sa.Column("post_catalogue_version", sa.String(100), nullable=False), - sa.Column("post_catalogue_schema_version", sa.String(160), nullable=False), - sa.Column("post_catalogue_manifest_hash", sa.String(71), nullable=False), - sa.Column("agent_identity", sa.String(100), nullable=False), - sa.Column("agent_version", sa.String(100), nullable=False), - sa.Column("instruction_version", sa.String(100), nullable=False), - sa.Column("provider_idempotency_key", sa.Uuid(), nullable=False), - sa.Column("status", sa.String(32), nullable=False), - sa.Column("canonical_result", sa.JSON()), - sa.Column("result_hash", sa.String(71)), - sa.Column("component_hashes", sa.JSON()), - sa.Column("failure_code", sa.String(100)), - sa.Column("persisted_compilation_id", sa.Uuid()), - sa.Column("reserved_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.func.now()), - sa.Column("provider_uncertain_at", sa.DateTime(timezone=True)), - sa.Column("accepted_at", sa.DateTime(timezone=True)), - sa.Column("terminal_at", sa.DateTime(timezone=True)), - sa.Column("persisted_at", sa.DateTime(timezone=True)), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"]), - sa.ForeignKeyConstraint(["guide_id"], ["project_guides.id"]), - sa.ForeignKeyConstraint( - ["source_snapshot_id", "source_snapshot_hash"], - ["guide_source_snapshots.id", "guide_source_snapshots.bundle_hash"], - name="fk_compilation_attempt_snapshot_hash", - ), - sa.ForeignKeyConstraint( - ["setup_run_id", "project_id", "guide_id", "source_snapshot_id", "setup_generation"], - ["project_setup_runs.id", "project_setup_runs.project_id", "project_setup_runs.guide_id", "project_setup_runs.source_snapshot_id", "project_setup_runs.setup_generation"], - name="fk_compilation_attempt_exact_setup", - ), - sa.UniqueConstraint("setup_run_id", "setup_generation", name="uq_compilation_attempt_setup_generation"), - sa.UniqueConstraint("provider_idempotency_key", name="uq_compilation_attempt_provider_key"), - sa.CheckConstraint("setup_generation > 0", name="ck_compilation_attempt_generation"), - sa.CheckConstraint( - "status in ('compilation_reserved','compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal','compilation_persisted')", - name="ck_compilation_attempt_status", - ), - sa.CheckConstraint( - f"source_snapshot_hash ~ '{_HASH}' and canonical_input_hash ~ '{_HASH}' and guide_material_hash ~ '{_HASH}' and " - f"pre_catalogue_manifest_hash ~ '{_HASH}' and post_catalogue_manifest_hash ~ '{_HASH}'", - name="ck_compilation_attempt_identity_hashes", - ), - sa.CheckConstraint(f"result_hash is null or result_hash ~ '{_HASH}'", name="ck_compilation_attempt_result_hash"), - sa.CheckConstraint("canonical_result is null or octet_length(canonical_result::text) <= 4194304", name="ck_compilation_attempt_result_size"), - sa.CheckConstraint( - "component_hashes is null or (json_typeof(component_hashes)='object' and " - "component_hashes::jsonb=jsonb_build_object(" - "'sufficiency_hash',component_hashes->>'sufficiency_hash'," - "'artifact_policy_hash',component_hashes->>'artifact_policy_hash'," - "'requirement_inventory_hash',component_hashes->>'requirement_inventory_hash'," - "'pre_submit_hash',component_hashes->>'pre_submit_hash'," - "'post_submit_hash',component_hashes->>'post_submit_hash'," - "'capability_suggestions_hash',component_hashes->>'capability_suggestions_hash'," - "'setup_notes_hash',component_hashes->>'setup_notes_hash') and " - + " and ".join( - f"coalesce((component_hashes->>'{name}') ~ '{_HASH}',false)" - for name in ( - "sufficiency_hash", "artifact_policy_hash", "requirement_inventory_hash", - "pre_submit_hash", "post_submit_hash", "capability_suggestions_hash", - "setup_notes_hash", - ) - ) - + ")", - name="ck_compilation_attempt_component_hashes", - ), - sa.CheckConstraint( - "(status='compilation_reserved' and provider_uncertain_at is null and accepted_at is null and terminal_at is null and persisted_at is null and canonical_result is null and result_hash is null and component_hashes is null and failure_code is null and persisted_compilation_id is null) or " - "(status='compilation_provider_uncertain' and provider_uncertain_at is not null and accepted_at is null and terminal_at is null and persisted_at is null and canonical_result is null and result_hash is null and component_hashes is null and failure_code is null and persisted_compilation_id is null) or " - "(status='provider_result_accepted' and accepted_at is not null and terminal_at is null and persisted_at is null and canonical_result is not null and result_hash is not null and component_hashes is not null and failure_code is null and persisted_compilation_id is null) or " - "(status='compilation_persisted' and accepted_at is not null and persisted_at is not null and terminal_at is null and canonical_result is not null and result_hash is not null and component_hashes is not null and failure_code is null and persisted_compilation_id is not null) or " - "(status='compilation_invalid_terminal' and terminal_at is not null and accepted_at is null and persisted_at is null and canonical_result is null and result_hash is null and component_hashes is null and persisted_compilation_id is null and failure_code in ('schema_invalid','unsafe_text','hash_mismatch','context_mismatch'))", - name="ck_compilation_attempt_state_shape", - ), - ) - for column in ("project_id", "guide_id", "source_snapshot_id", "setup_run_id"): - op.create_index(f"ix_project_guide_compilation_attempts_{column}", "project_guide_compilation_attempts", [column]) - - op.create_table( - "project_guide_compilations", - sa.Column("id", sa.Uuid(), primary_key=True), - sa.Column("attempt_id", sa.Uuid(), nullable=False), - sa.Column("project_id", sa.String(36), nullable=False), - sa.Column("guide_id", sa.String(36), nullable=False), - sa.Column("guide_version", sa.String(50), nullable=False), - sa.Column("source_snapshot_id", sa.String(36), nullable=False), - sa.Column("source_snapshot_hash", sa.String(71), nullable=False), - sa.Column("setup_run_id", sa.String(36), nullable=False), - sa.Column("setup_generation", sa.BigInteger(), nullable=False), - sa.Column("canonical_input_hash", sa.String(71), nullable=False), - sa.Column("guide_material_hash", sa.String(71), nullable=False), - sa.Column("pre_catalogue_manifest_hash", sa.String(71), nullable=False), - sa.Column("post_catalogue_manifest_hash", sa.String(71), nullable=False), - sa.Column("agent_identity", sa.String(100), nullable=False), - sa.Column("agent_version", sa.String(100), nullable=False), - sa.Column("instruction_version", sa.String(100), nullable=False), - sa.Column("canonical_result", sa.JSON(), nullable=False), - sa.Column("result_hash", sa.String(71), nullable=False), - sa.Column("component_hashes", sa.JSON(), nullable=False), - sa.Column("supersedes_compilation_id", sa.Uuid()), - sa.Column("created_by_actor_profile_id", sa.String(36), nullable=False), - sa.Column("created_via_identity_link_id", sa.String(36), nullable=False), - sa.Column("created_by_service_identity", sa.String(160), nullable=False), - sa.Column("creation_action_id", sa.String(160), nullable=False), - sa.Column("authorization_decision_event_id", sa.String(36), nullable=False), - sa.Column("authorization_resource_context_digest", sa.String(71), nullable=False), - sa.Column("created_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.func.now()), - sa.ForeignKeyConstraint(["attempt_id"], ["project_guide_compilation_attempts.id"]), - sa.ForeignKeyConstraint(["project_id"], ["projects.id"]), - sa.ForeignKeyConstraint(["guide_id"], ["project_guides.id"]), - sa.ForeignKeyConstraint(["source_snapshot_id"], ["guide_source_snapshots.id"]), - sa.ForeignKeyConstraint(["setup_run_id"], ["project_setup_runs.id"]), - sa.ForeignKeyConstraint(["created_by_actor_profile_id"], ["actor_profiles.id"]), - sa.ForeignKeyConstraint(["created_via_identity_link_id"], ["actor_identity_links.id"]), - sa.ForeignKeyConstraint(["authorization_decision_event_id"], ["audit_events.id"]), - sa.UniqueConstraint("attempt_id", name="uq_project_guide_compilation_attempt"), - sa.UniqueConstraint("id", "attempt_id", name="uq_project_guide_compilation_id_attempt"), - sa.UniqueConstraint("supersedes_compilation_id", name="uq_project_guide_compilation_predecessor"), - sa.UniqueConstraint("id", "project_id", "guide_id", name="uq_project_guide_compilation_scope"), - sa.ForeignKeyConstraint( - ["supersedes_compilation_id", "project_id", "guide_id"], - ["project_guide_compilations.id", "project_guide_compilations.project_id", "project_guide_compilations.guide_id"], - name="fk_project_guide_compilation_predecessor", - ), - sa.CheckConstraint( - f"source_snapshot_hash ~ '{_HASH}' and canonical_input_hash ~ '{_HASH}' and guide_material_hash ~ '{_HASH}' and pre_catalogue_manifest_hash ~ '{_HASH}' and post_catalogue_manifest_hash ~ '{_HASH}' and result_hash ~ '{_HASH}'", - name="ck_project_guide_compilation_hashes", - ), - sa.CheckConstraint( - "octet_length(canonical_result::text) <= 4194304 and " - "json_typeof(component_hashes)='object' and " - "component_hashes::jsonb=jsonb_build_object(" - "'sufficiency_hash',component_hashes->>'sufficiency_hash'," - "'artifact_policy_hash',component_hashes->>'artifact_policy_hash'," - "'requirement_inventory_hash',component_hashes->>'requirement_inventory_hash'," - "'pre_submit_hash',component_hashes->>'pre_submit_hash'," - "'post_submit_hash',component_hashes->>'post_submit_hash'," - "'capability_suggestions_hash',component_hashes->>'capability_suggestions_hash'," - "'setup_notes_hash',component_hashes->>'setup_notes_hash') and " - + " and ".join( - f"coalesce((component_hashes->>'{name}') ~ '{_HASH}',false)" - for name in ( - "sufficiency_hash", "artifact_policy_hash", "requirement_inventory_hash", - "pre_submit_hash", "post_submit_hash", "capability_suggestions_hash", - "setup_notes_hash", - ) - ), - name="ck_project_guide_compilation_result_shape", - ), - sa.CheckConstraint( - "setup_generation > 0 and created_by_service_identity='workstream.project.setup' and creation_action_id='project.guide_compilation.execute'", - name="ck_project_guide_compilation_custody", - ), - sa.CheckConstraint( - f"authorization_resource_context_digest ~ '{_HASH}'", - name="ck_project_guide_compilation_authorization_digest", - ), - ) - op.create_index( - "uq_project_guide_compilation_root", - "project_guide_compilations", - ["project_id", "guide_id"], - unique=True, - postgresql_where=sa.text("supersedes_compilation_id is null"), - ) - for column in ("project_id", "guide_id", "source_snapshot_id", "setup_run_id"): - op.create_index(f"ix_project_guide_compilations_{column}", "project_guide_compilations", [column]) - op.create_foreign_key( - "fk_compilation_attempt_exact_persisted_compilation", - "project_guide_compilation_attempts", - "project_guide_compilations", - ["persisted_compilation_id", "id"], - ["id", "attempt_id"], - ) - _install_guards() - - -def _install_guards() -> None: - statements = ( - """ - create function guard_project_guide_compilation_attempt_update() - returns trigger language plpgsql as $$ - begin - if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, - new.source_snapshot_hash,new.setup_run_id,new.setup_generation, - new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, - new.pre_catalogue_version,new.pre_catalogue_schema_version, - new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, - new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, - new.agent_identity,new.agent_version,new.instruction_version, - new.provider_idempotency_key) - is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, - old.source_snapshot_hash,old.setup_run_id,old.setup_generation, - old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, - old.pre_catalogue_version,old.pre_catalogue_schema_version, - old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, - old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, - old.agent_identity,old.agent_version,old.instruction_version, - old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; - if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; - if new.reserved_at is distinct from old.reserved_at then - raise exception 'compilation reservation timestamp is immutable'; - end if; - if new.provider_uncertain_at is distinct from old.provider_uncertain_at and - not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then - raise exception 'provider uncertainty timestamp is immutable'; - end if; - if new.accepted_at is distinct from old.accepted_at and - not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then - raise exception 'accepted timestamp is immutable'; - end if; - if new.terminal_at is distinct from old.terminal_at and - not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then - raise exception 'terminal timestamp is immutable'; - end if; - if row(new.persisted_at,new.persisted_compilation_id) is distinct from - row(old.persisted_at,old.persisted_compilation_id) and - not (old.status='provider_result_accepted' and new.status='compilation_persisted') then - raise exception 'persisted custody is immutable'; - end if; - if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) - is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then - raise exception 'accepted compilation result is immutable'; - end if; - if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or - (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or - (old.status='provider_result_accepted' and new.status='compilation_persisted')) then - raise exception 'invalid compilation attempt transition'; - end if; - return new; - end $$ - """, - """ - create trigger trg_compilation_attempt_update before update on project_guide_compilation_attempts - for each row execute function guard_project_guide_compilation_attempt_update() - """, - """ - create function reject_project_guide_compilation_mutation() - returns trigger language plpgsql as $$ begin raise exception 'compilation custody is append-only'; end $$ - """, - """ - create trigger trg_compilation_attempt_delete before delete or truncate on project_guide_compilation_attempts - for each statement execute function reject_project_guide_compilation_mutation() - """, - """ - create function guard_project_guide_compilation_insert() - returns trigger language plpgsql as $$ - declare predecessor_generation bigint; - declare source_attempt project_guide_compilation_attempts%rowtype; - begin - select * into source_attempt from project_guide_compilation_attempts - where id=new.attempt_id for update; - if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or - row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, - new.source_snapshot_hash,new.setup_run_id,new.setup_generation, - new.canonical_input_hash,new.guide_material_hash, - new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, - new.agent_identity,new.agent_version,new.instruction_version, - new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) - is distinct from - row(source_attempt.project_id,source_attempt.guide_id, - source_attempt.guide_version,source_attempt.source_snapshot_id, - source_attempt.source_snapshot_hash,source_attempt.setup_run_id, - source_attempt.setup_generation,source_attempt.canonical_input_hash, - source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, - source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, - source_attempt.agent_version,source_attempt.instruction_version, - source_attempt.canonical_result::jsonb,source_attempt.result_hash, - source_attempt.component_hashes::jsonb) then - raise exception 'compilation does not match its accepted attempt'; - end if; - if not exists( - select 1 from audit_events event - join actor_profiles profile on profile.id=new.created_by_actor_profile_id - join actor_identity_links link on link.id=new.created_via_identity_link_id - and link.actor_profile_id=profile.id - where event.id=new.authorization_decision_event_id - and event.event_domain='authority' - and event.event_type='SensitiveAuthorizationAllowed' - and event.denial_code is null - and event.actor_id=new.created_by_actor_profile_id - and event.permission_id='project.guide_compilation.execute' - and event.action_id='project.guide_compilation.execute' - and event.project_id=new.project_id - and event.resource_type='project_guide_compilation_attempt' - and event.resource_id=new.attempt_id::text - and event.after_facts->>'allowed'='true' - and event.after_facts->>'resource_context_digest'= - new.authorization_resource_context_digest - and profile.actor_kind='service' and profile.status='active' - and profile.service_identity='workstream.project.setup' - and link.subject_kind='service' and link.status='active' - and link.issuer='workstream-internal' - and link.subject='workstream.project.setup' - ) then - raise exception 'compilation authorization evidence is invalid'; - end if; - if new.supersedes_compilation_id is null then return new; end if; - select setup_generation into predecessor_generation - from project_guide_compilations - where id=new.supersedes_compilation_id - and project_id=new.project_id and guide_id=new.guide_id; - if predecessor_generation is null or predecessor_generation >= new.setup_generation then - raise exception 'compilation generation must strictly advance'; - end if; - return new; - end $$ - """, - """ - create trigger trg_compilation_insert before insert on project_guide_compilations - for each row execute function guard_project_guide_compilation_insert() - """, - """ - create trigger trg_compilation_mutation before update or delete or truncate on project_guide_compilations - for each statement execute function reject_project_guide_compilation_mutation() - """ - ) - for statement in statements: - op.execute(statement) - - -def downgrade() -> None: - """Remove only the hidden compilation foundation.""" - connection = op.get_bind() - connection.execute(sa.text("lock table audit_events in access exclusive mode")) - retained = connection.execute( - sa.text( - "select exists(select 1 from project_guide_compilation_attempts) or " - "exists(select 1 from project_guide_compilations) or " - "exists(select 1 from audit_events where action_id=:action)" - ), - {"action": _ACTION}, - ).scalar_one() - if retained: - raise RuntimeError("cannot downgrade non-empty guide-compilation custody") - op.execute("drop trigger if exists trg_compilation_mutation on project_guide_compilations") - op.execute("drop trigger if exists trg_compilation_insert on project_guide_compilations") - op.execute("drop trigger if exists trg_compilation_attempt_delete on project_guide_compilation_attempts") - op.execute("drop trigger if exists trg_compilation_attempt_update on project_guide_compilation_attempts") - op.execute("drop function if exists reject_project_guide_compilation_mutation()") - op.execute("drop function if exists guard_project_guide_compilation_insert()") - op.execute("drop function if exists guard_project_guide_compilation_attempt_update()") - op.drop_constraint("fk_compilation_attempt_exact_persisted_compilation", "project_guide_compilation_attempts", type_="foreignkey") - op.drop_table("project_guide_compilations") - op.drop_table("project_guide_compilation_attempts") - _rewrite_action_evidence(add=False) - _rewrite_permission_registry(add=False) - _rewrite_audit_resource(add=False) diff --git a/backend/alembic/versions/0063_guide_compilation_authority.py b/backend/alembic/versions/0063_guide_compilation_authority.py deleted file mode 100644 index df340cdbf..000000000 --- a/backend/alembic/versions/0063_guide_compilation_authority.py +++ /dev/null @@ -1,198 +0,0 @@ -"""Activate exact unified guide-compilation authorization vocabulary. - -Revision ID: 0063_compilation_authority -Revises: 0062_guide_compilation -""" - -from __future__ import annotations - -from alembic import op -import sqlalchemy as sa - - -revision = "0063_compilation_authority" -down_revision = "0062_guide_compilation" -branch_labels = depends_on = None - -_ACTION = "project.guide_compilation.request" -_EXECUTE_ACTION = "project.guide_compilation.execute" -_PERMISSION = _ACTION -_RESOURCE = "project_guide_compilation_request" - - -def _lock_audit_events() -> None: - op.execute("lock table audit_events in access exclusive mode") - - -def _refuse_permission_only_execute_evidence() -> None: - retained = ( - op.get_bind() - .execute( - sa.text( - "select exists(select 1 from audit_events " - "where permission_id=:execute_permission and action_id is null)" - ), - {"execute_permission": _EXECUTE_ACTION}, - ) - .scalar_one() - ) - if retained: - raise RuntimeError( - "cannot activate compilation authority over permission-only execute evidence" - ) - - -def _rewrite_constraint(name: str, marker: str, addition: str, *, add: bool) -> None: - connection = op.get_bind() - definition = connection.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass and conname=:name" - ), - {"name": f"ck_audit_events_{name}"}, - ).scalar_one() - expanded = marker + addition - source, target = (marker, expanded) if add else (expanded, marker) - if definition.count(source) != 1 or (add and expanded in definition): - raise RuntimeError(f"unexpected compilation authority {name} registry") - op.drop_constraint(name, "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_{name} {definition.replace(source, target, 1)}" - ) - - -def _rewrite_privacy_permission_registry(*, add: bool) -> None: - definition = ( - op.get_bind() - .execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_privacy_bounds'" - ) - ) - .scalar_one() - ) - marker = "('review.queue.override'::character varying)::text" - addition = ( - ", ('project.guide_compilation.request'::character varying)::text" - ", ('project.guide_compilation.execute'::character varying)::text" - ) - expanded = marker + addition - source, target = (marker, expanded) if add else (expanded, marker) - if definition.count(source) != 2 or (add and expanded in definition): - raise RuntimeError("unexpected compilation privacy permission registry") - op.drop_constraint("authority_privacy_bounds", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authority_privacy_bounds {definition.replace(source, target)}" - ) - - -def _rewrite_action_evidence(*, add: bool) -> None: - connection = op.get_bind() - definition = connection.execute( - sa.text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authorization_action_evidence'" - ) - ).scalar_one() - marker = ( - "(((action_id)::text = 'project.guide_compilation.execute'::text) AND " - "((permission_id)::text = 'project.guide_compilation.execute'::text))" - ) - token = ( - " OR (((action_id)::text = 'project.guide_compilation.request'::text) AND " - "((permission_id)::text = 'project.guide_compilation.request'::text))" - ) - permission_marker = "('project.effective_policy.read'::character varying)::text" - permission_tokens = ( - ", ('project.guide_compilation.request'::character varying)::text" - ", ('project.guide_compilation.execute'::character varying)::text" - ) - if add: - if ( - definition.count(marker) != 2 - or token in definition - or definition.count(permission_marker) != 1 - or permission_tokens in definition - ): - raise RuntimeError("unexpected compilation request action registry") - definition = definition.replace(marker, marker + token) - definition = definition.replace( - permission_marker, - permission_marker + permission_tokens, - 1, - ) - else: - if definition.count(token) != 2 or definition.count(permission_tokens) != 1: - raise RuntimeError("unexpected compilation request action registry") - definition = definition.replace(token, "") - definition = definition.replace(permission_tokens, "", 1) - op.drop_constraint("authorization_action_evidence", "audit_events", type_="check") - op.execute( - "alter table audit_events add constraint " - f"ck_audit_events_authorization_action_evidence {definition}" - ) - - -def upgrade() -> None: - _lock_audit_events() - _refuse_permission_only_execute_evidence() - _rewrite_constraint( - "authority_privacy_bounds", - "('project_guide_compilation_attempt'::character varying)::text", - ", ('project_guide_compilation_request'::character varying)::text", - add=True, - ) - _rewrite_privacy_permission_registry(add=True) - _rewrite_constraint( - "authority_registries", - "('project.guide_compilation.execute'::character varying)::text", - ", ('project.guide_compilation.request'::character varying)::text", - add=True, - ) - _rewrite_action_evidence(add=True) - - -def downgrade() -> None: - _lock_audit_events() - retained = ( - op.get_bind() - .execute( - sa.text( - "select exists(select 1 from audit_events " - "where action_id in (:request_action, :execute_action) " - "or permission_id=:request_action " - "or (target_ref_kind='permission_registry' " - "and target_ref_id in (:request_action, :execute_action)) " - "or (invalidation_target_kind='permission_registry' " - "and invalidation_target_ref in (:request_action, :execute_action)) " - "or resource_type=:request_resource)" - ), - { - "request_action": _ACTION, - "execute_action": _EXECUTE_ACTION, - "request_resource": _RESOURCE, - }, - ) - .scalar_one() - ) - if retained: - raise RuntimeError("cannot downgrade retained compilation authority") - _rewrite_action_evidence(add=False) - _rewrite_privacy_permission_registry(add=False) - _rewrite_constraint( - "authority_registries", - "('project.guide_compilation.execute'::character varying)::text", - ", ('project.guide_compilation.request'::character varying)::text", - add=False, - ) - _rewrite_constraint( - "authority_privacy_bounds", - "('project_guide_compilation_attempt'::character varying)::text", - ", ('project_guide_compilation_request'::character varying)::text", - add=False, - ) diff --git a/backend/app/modules/actors/service_identity_migration.py b/backend/app/modules/actors/service_identity_migration.py deleted file mode 100644 index 028edf2a7..000000000 --- a/backend/app/modules/actors/service_identity_migration.py +++ /dev/null @@ -1,589 +0,0 @@ -"""Confidential exact-set mapping for pre-AUTH-09 service ActorProfiles.""" - -from __future__ import annotations - -from collections.abc import Sequence -from datetime import UTC, datetime -import hashlib -import json -import os -from pathlib import Path -import re -import stat -from typing import Any, Literal -from urllib.parse import urlsplit -from uuid import UUID - -from pydantic import BaseModel, ConfigDict, Field, field_validator, model_validator -from sqlalchemy import text -from sqlalchemy.ext.asyncio import AsyncConnection, AsyncEngine - -from app.modules.actors.legacy_classification import database_binding_identifier -from migration_contracts.service_identity_0023 import SERVICE_IDENTITIES, ServiceIdentity - -MAPPING_FILE_ENV = "WORKSTREAM_SERVICE_ACTOR_IDENTITY_MAPPING_FILE" -MAX_MAPPING_FILE_BYTES = 64 * 1024 -MAX_MAPPINGS = len(SERVICE_IDENTITIES) -MAPPING_SCHEMA_VERSION = 1 -REPOSITORY_ROOT = Path(__file__).resolve().parents[4] -_DATABASE_BINDING_PATTERN = re.compile(r"postgres-v1:[0-9a-f]{64}") -_GENERATED_AT_PATTERN = re.compile(r"\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z") - - -class ServiceIdentityMappingError(RuntimeError): - """Privacy-bounded mapping failure safe for migration and CLI output.""" - - def __init__(self, code: str, *, count: int | None = None) -> None: - self.code = code - self.count = count - super().__init__(code) - - -def _canonical_bytes(value: Any) -> bytes: - return json.dumps( - value, - allow_nan=False, - ensure_ascii=True, - separators=(",", ":"), - sort_keys=True, - ).encode("utf-8") - - -def _sha256(value: bytes) -> str: - return hashlib.sha256(value).hexdigest() - - -def _canonical_uuid(value: str) -> str: - try: - parsed = UUID(value) - except (AttributeError, TypeError, ValueError) as exc: - raise ValueError("invalid actor profile id") from exc - if str(parsed) != value: - raise ValueError("invalid actor profile id") - return value - - -def _canonical_issuer(value: str) -> str: - if not value or len(value) > 200 or value.strip() != value: - raise ValueError("invalid issuer") - parsed = urlsplit(value) - try: - parsed.port - except ValueError: - raise ValueError("invalid issuer") from None - if ( - parsed.scheme != "https" - or not parsed.hostname - or parsed.username is not None - or parsed.password is not None - or parsed.query - or parsed.fragment - or any(character.isspace() or ord(character) < 0x20 for character in value) - ): - raise ValueError("invalid issuer") - return value - - -def _canonical_subject(value: str) -> str: - if not value or not value.strip() or len(value) > 200: - raise ValueError("invalid subject") - return value - - -class ServiceActorIdentityMapping(BaseModel): - """One operator-approved fixed identity for an exact existing service link.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - actor_profile_id: str - issuer: str - subject: str - service_identity: ServiceIdentity - - @field_validator("actor_profile_id") - @classmethod - def validate_actor_profile_id(cls, value: str) -> str: - return _canonical_uuid(value) - - @field_validator("issuer") - @classmethod - def validate_issuer(cls, value: str) -> str: - return _canonical_issuer(value) - - @field_validator("subject") - @classmethod - def validate_subject(cls, value: str) -> str: - return _canonical_subject(value) - - -class ServiceActorIdentityMappingDraft(BaseModel): - """Strict operator-authored choices before database binding.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - schema_version: Literal[1] - mappings: tuple[ServiceActorIdentityMapping, ...] = Field(max_length=MAX_MAPPINGS) - - @field_validator("schema_version", mode="before") - @classmethod - def validate_schema_version(cls, value: Any) -> int: - if type(value) is not int or value != MAPPING_SCHEMA_VERSION: - raise ValueError("invalid schema version") - return value - - @model_validator(mode="after") - def validate_uniqueness(self) -> ServiceActorIdentityMappingDraft: - actor_ids = [row.actor_profile_id for row in self.mappings] - external_ids = [(row.issuer, row.subject) for row in self.mappings] - identities = [row.service_identity for row in self.mappings] - if ( - len(actor_ids) != len(set(actor_ids)) - or len(external_ids) != len(set(external_ids)) - or len(identities) != len(set(identities)) - ): - raise ValueError("duplicate mapping") - return self - - -class ExistingServiceActorRow(BaseModel): - """Privacy-sensitive locked database projection used only during mapping.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - actor_profile_id: str - issuer: str - subject: str - - @field_validator("actor_profile_id") - @classmethod - def validate_actor_profile_id(cls, value: str) -> str: - return _canonical_uuid(value) - - @field_validator("issuer") - @classmethod - def validate_issuer(cls, value: str) -> str: - return _canonical_issuer(value) - - @field_validator("subject") - @classmethod - def validate_subject(cls, value: str) -> str: - return _canonical_subject(value) - - -class ServiceActorIdentityMappingEnvelope(BaseModel): - """Confidential exact mapping bound to one locked database snapshot.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - schema_version: Literal[1] - mappings: tuple[ServiceActorIdentityMapping, ...] = Field(max_length=MAX_MAPPINGS) - source_row_set_sha256: str - manifest_sha256: str - generated_at: str - database_binding: str - envelope_sha256: str - - @field_validator("schema_version", mode="before") - @classmethod - def validate_schema_version(cls, value: Any) -> int: - if type(value) is not int or value != MAPPING_SCHEMA_VERSION: - raise ValueError("invalid schema version") - return value - - @model_validator(mode="after") - def validate_mapping_uniqueness(self) -> ServiceActorIdentityMappingEnvelope: - ServiceActorIdentityMappingDraft(schema_version=1, mappings=self.mappings) - for digest in ( - self.source_row_set_sha256, - self.manifest_sha256, - self.envelope_sha256, - ): - if len(digest) != 64 or any(character not in "0123456789abcdef" for character in digest): - raise ValueError("invalid digest") - if _DATABASE_BINDING_PATTERN.fullmatch(self.database_binding) is None: - raise ValueError("invalid database binding") - if _GENERATED_AT_PATTERN.fullmatch(self.generated_at) is None: - raise ValueError("invalid generated_at") - try: - parsed = datetime.fromisoformat(self.generated_at.removesuffix("Z") + "+00:00") - except ValueError as exc: - raise ValueError("invalid generated_at") from exc - if parsed.tzinfo != UTC or parsed.microsecond: - raise ValueError("invalid generated_at") - return self - - -class ServiceActorIdentitySnapshot(BaseModel): - """Exact existing service rows plus a non-secret database binding.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - rows: tuple[ExistingServiceActorRow, ...] - database_binding: str - - -class ServiceActorIdentityMappingReport(BaseModel): - """Bounded CLI report without actor or external identity material.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - status: Literal["valid"] = "valid" - mapped_count: int - source_row_set_sha256: str - manifest_sha256: str - envelope_sha256: str | None = None - database_binding: str - envelope_written: bool = False - - -def _mapping_payload(rows: Sequence[ServiceActorIdentityMapping]) -> list[dict[str, str]]: - return [ - row.model_dump(mode="json") - for row in sorted(rows, key=lambda item: item.actor_profile_id) - ] - - -def _source_payload(rows: Sequence[ExistingServiceActorRow]) -> list[dict[str, str]]: - return [ - row.model_dump(mode="json") - for row in sorted(rows, key=lambda item: item.actor_profile_id) - ] - - -def source_row_set_sha256(rows: Sequence[ExistingServiceActorRow]) -> str: - """Digest the exact private source set without exposing it.""" - return _sha256(_canonical_bytes(_source_payload(rows))) - - -def canonical_draft_bytes(draft: ServiceActorIdentityMappingDraft) -> bytes: - """Serialize operator choices deterministically for review and hashing.""" - return _canonical_bytes( - {"schema_version": draft.schema_version, "mappings": _mapping_payload(draft.mappings)} - ) - - -def _envelope_payload(envelope: ServiceActorIdentityMappingEnvelope) -> dict[str, Any]: - return { - "schema_version": envelope.schema_version, - "mappings": _mapping_payload(envelope.mappings), - "source_row_set_sha256": envelope.source_row_set_sha256, - "manifest_sha256": envelope.manifest_sha256, - "generated_at": envelope.generated_at, - "database_binding": envelope.database_binding, - } - - -def canonical_envelope_bytes(envelope: ServiceActorIdentityMappingEnvelope) -> bytes: - """Serialize a complete envelope deterministically.""" - return _canonical_bytes(envelope.model_dump(mode="json")) - - -def validate_draft( - draft: ServiceActorIdentityMappingDraft, - rows: Sequence[ExistingServiceActorRow], -) -> ServiceActorIdentityMappingDraft: - """Require a one-to-one mapping for the exact existing service row set.""" - if len(rows) > MAX_MAPPINGS: - raise ServiceIdentityMappingError("service_inventory_exceeds_registry", count=len(rows)) - source = {(row.actor_profile_id, row.issuer, row.subject) for row in rows} - proposed = { - (row.actor_profile_id, row.issuer, row.subject) for row in draft.mappings - } - if source != proposed: - raise ServiceIdentityMappingError("service_mapping_source_mismatch", count=len(rows)) - return draft - - -def build_envelope( - draft: ServiceActorIdentityMappingDraft, - rows: Sequence[ExistingServiceActorRow], - *, - database_binding: str, - generated_at: str, -) -> ServiceActorIdentityMappingEnvelope: - """Bind validated operator choices to one exact database snapshot.""" - validate_draft(draft, rows) - provisional = ServiceActorIdentityMappingEnvelope( - schema_version=MAPPING_SCHEMA_VERSION, - mappings=tuple(sorted(draft.mappings, key=lambda row: row.actor_profile_id)), - source_row_set_sha256=source_row_set_sha256(rows), - manifest_sha256=_sha256(canonical_draft_bytes(draft)), - generated_at=generated_at, - database_binding=database_binding, - envelope_sha256="0" * 64, - ) - return provisional.model_copy( - update={"envelope_sha256": _sha256(_canonical_bytes(_envelope_payload(provisional)))} - ) - - -def verify_envelope( - envelope: ServiceActorIdentityMappingEnvelope, - rows: Sequence[ExistingServiceActorRow], - *, - database_binding: str, -) -> ServiceActorIdentityMappingEnvelope: - """Verify checksums, database binding, and the complete current source set.""" - draft = ServiceActorIdentityMappingDraft( - schema_version=MAPPING_SCHEMA_VERSION, - mappings=envelope.mappings, - ) - validate_draft(draft, rows) - expected = build_envelope( - draft, - rows, - database_binding=database_binding, - generated_at=envelope.generated_at, - ) - if expected != envelope: - raise ServiceIdentityMappingError("service_mapping_envelope_mismatch", count=len(rows)) - return envelope - - -def _reject_duplicate_pairs(pairs: list[tuple[str, Any]]) -> dict[str, Any]: - result: dict[str, Any] = {} - for key, value in pairs: - if key in result: - raise ValueError("duplicate key") - result[key] = value - return result - - -def _read_private_json_bytes(path: Path) -> bytes: - """Read one owner-only regular file without following symlinks.""" - try: - descriptor = os.open(path, os.O_RDONLY | getattr(os, "O_NOFOLLOW", 0)) - except OSError: - raise ServiceIdentityMappingError("service_mapping_file_unavailable") from None - try: - metadata = os.fstat(descriptor) - if ( - not stat.S_ISREG(metadata.st_mode) - or metadata.st_uid != os.geteuid() - or stat.S_IMODE(metadata.st_mode) & 0o077 - or metadata.st_size > MAX_MAPPING_FILE_BYTES - ): - raise ServiceIdentityMappingError("service_mapping_file_insecure") - chunks: list[bytes] = [] - remaining = MAX_MAPPING_FILE_BYTES + 1 - while remaining: - chunk = os.read(descriptor, remaining) - if not chunk: - break - chunks.append(chunk) - remaining -= len(chunk) - data = b"".join(chunks) - finally: - os.close(descriptor) - if len(data) > MAX_MAPPING_FILE_BYTES: - raise ServiceIdentityMappingError("service_mapping_file_too_large") - return data - - -def _parse_private_json(data: bytes) -> Any: - try: - return json.loads( - data.decode("utf-8"), - object_pairs_hook=_reject_duplicate_pairs, - parse_constant=lambda _value: (_ for _ in ()).throw(ValueError("nonfinite")), - ) - except (UnicodeDecodeError, ValueError, json.JSONDecodeError): - raise ServiceIdentityMappingError("service_mapping_file_invalid") from None - - -def _git_common_directory() -> Path | None: - marker = REPOSITORY_ROOT / ".git" - if marker.is_dir(): - return marker.resolve() - try: - value = marker.read_text(encoding="utf-8").strip() - except FileNotFoundError: - return None - except OSError: - raise ServiceIdentityMappingError("git_directory_unavailable") from None - prefix = "gitdir: " - if not value.startswith(prefix): - raise ServiceIdentityMappingError("git_directory_unavailable") - worktree_git = Path(value.removeprefix(prefix)) - if not worktree_git.is_absolute(): - worktree_git = marker.parent / worktree_git - resolved = worktree_git.resolve() - if resolved.parent.name != "worktrees": - raise ServiceIdentityMappingError("git_directory_unavailable") - return resolved.parent.parent - - -def protected_mapping_roots() -> tuple[Path, ...]: - """Return every linked worktree root plus shared Git metadata.""" - common = _git_common_directory() - roots = {REPOSITORY_ROOT.resolve()} - if common is None: - return tuple(roots) - roots.update({common, common.parent.resolve()}) - worktrees = common / "worktrees" - if worktrees.exists(): - try: - metadata_directories = tuple(worktrees.iterdir()) - except OSError: - raise ServiceIdentityMappingError("git_directory_unavailable") from None - for metadata in metadata_directories: - marker = metadata / "gitdir" - try: - git_file = Path(marker.read_text(encoding="utf-8").strip()) - except OSError: - raise ServiceIdentityMappingError("git_directory_unavailable") from None - if git_file.name != ".git" or not git_file.is_absolute(): - raise ServiceIdentityMappingError("git_directory_unavailable") - roots.add(git_file.parent.resolve()) - return tuple(sorted(roots, key=str)) - - -def validate_mapping_path(path: Path, *, output: bool = False) -> Path: - """Require an absolute path outside every repository and Git root.""" - if not path.is_absolute(): - raise ServiceIdentityMappingError("service_mapping_path_forbidden") - try: - resolved = path.parent.resolve(strict=True) / path.name - if not output and not resolved.exists(): - raise OSError("missing input") - except OSError: - raise ServiceIdentityMappingError("service_mapping_path_unavailable") from None - if any( - resolved == root or resolved.is_relative_to(root) - for root in protected_mapping_roots() - ): - raise ServiceIdentityMappingError("service_mapping_path_forbidden") - return resolved - - -def load_draft(path: Path) -> ServiceActorIdentityMappingDraft: - """Load one strict confidential operator draft.""" - try: - data = _read_private_json_bytes(path) - draft = ServiceActorIdentityMappingDraft.model_validate(_parse_private_json(data)) - if data != canonical_draft_bytes(draft) + b"\n": - raise ValueError("noncanonical draft") - return draft - except ServiceIdentityMappingError: - raise - except Exception: - raise ServiceIdentityMappingError("service_mapping_draft_invalid") from None - - -def load_envelope(path: Path) -> ServiceActorIdentityMappingEnvelope: - """Load one strict confidential database-bound envelope.""" - try: - data = _read_private_json_bytes(path) - envelope = ServiceActorIdentityMappingEnvelope.model_validate(_parse_private_json(data)) - if data != canonical_envelope_bytes(envelope) + b"\n": - raise ValueError("noncanonical envelope") - return envelope - except ServiceIdentityMappingError: - raise - except Exception: - raise ServiceIdentityMappingError("service_mapping_envelope_invalid") from None - - -def publish_envelope(path: Path, envelope: ServiceActorIdentityMappingEnvelope) -> None: - """Create one owner-only envelope without overwriting or following links.""" - flags = os.O_WRONLY | os.O_CREAT | os.O_EXCL | getattr(os, "O_NOFOLLOW", 0) - try: - descriptor = os.open(path, flags, 0o600) - except OSError: - raise ServiceIdentityMappingError("service_mapping_output_unavailable") from None - try: - remaining = memoryview(canonical_envelope_bytes(envelope) + b"\n") - while remaining: - written = os.write(descriptor, remaining) - if written <= 0: - raise OSError("short write") - remaining = remaining[written:] - os.fsync(descriptor) - except OSError: - try: - path.unlink() - except OSError: - pass - raise ServiceIdentityMappingError("service_mapping_output_failed") from None - finally: - os.close(descriptor) - - -async def read_existing_service_rows(connection: AsyncConnection) -> ServiceActorIdentitySnapshot: - """Read the exact existing service/link set and bind it to this database.""" - raw_rows = ( - await connection.execute( - text( - "select p.id, l.issuer, l.subject from actor_profiles p " - "join actor_identity_links l on l.actor_profile_id=p.id " - "where p.actor_kind='service' order by p.id" - ) - ) - ).all() - database_name, database_oid = ( - await connection.execute( - text( - "select current_database(), oid from pg_database " - "where datname=current_database()" - ) - ) - ).one() - try: - rows = tuple( - ExistingServiceActorRow( - actor_profile_id=row[0], - issuer=row[1], - subject=row[2], - ) - for row in raw_rows - ) - except Exception: - raise ServiceIdentityMappingError("service_mapping_source_invalid") from None - return ServiceActorIdentitySnapshot( - rows=rows, - database_binding=database_binding_identifier(database_name, database_oid), - ) - - -async def snapshot_existing_service_rows(engine: AsyncEngine) -> ServiceActorIdentitySnapshot: - """Read one non-mutating snapshot for the operator tool.""" - async with engine.connect() as connection: - return await read_existing_service_rows(connection) - - -def load_migration_mapping( - rows: Sequence[ExistingServiceActorRow], - *, - database_binding: str, -) -> ServiceActorIdentityMappingEnvelope | None: - """Load the required exact mapping from the migration-only environment.""" - raw_path = os.environ.get(MAPPING_FILE_ENV) - if not rows: - if raw_path: - raise ServiceIdentityMappingError("service_mapping_not_required", count=0) - return None - if not raw_path: - raise ServiceIdentityMappingError("service_mapping_required", count=len(rows)) - return verify_envelope( - load_envelope(validate_mapping_path(Path(raw_path))), - rows, - database_binding=database_binding, - ) - - -def build_report( - snapshot: ServiceActorIdentitySnapshot, - draft: ServiceActorIdentityMappingDraft, - *, - envelope: ServiceActorIdentityMappingEnvelope | None = None, - envelope_written: bool = False, -) -> ServiceActorIdentityMappingReport: - """Return only bounded counts, bindings, and non-secret digests.""" - return ServiceActorIdentityMappingReport( - mapped_count=len(draft.mappings), - source_row_set_sha256=source_row_set_sha256(snapshot.rows), - manifest_sha256=_sha256(canonical_draft_bytes(draft)), - envelope_sha256=envelope.envelope_sha256 if envelope else None, - database_binding=snapshot.database_binding, - envelope_written=envelope_written, - ) diff --git a/backend/migration_contracts/__init__.py b/backend/migration_contracts/__init__.py deleted file mode 100644 index 581c16d6c..000000000 --- a/backend/migration_contracts/__init__.py +++ /dev/null @@ -1 +0,0 @@ -"""Frozen data contracts used by historical Alembic revisions.""" diff --git a/backend/migration_contracts/service_identity_0023.py b/backend/migration_contracts/service_identity_0023.py deleted file mode 100644 index 3e7f8470e..000000000 --- a/backend/migration_contracts/service_identity_0023.py +++ /dev/null @@ -1,628 +0,0 @@ -"""Frozen confidential mapping contract for revision 0023.""" - -from __future__ import annotations - -from collections.abc import Sequence -from datetime import UTC, datetime -from enum import StrEnum, unique -import hashlib -import json -import os -from pathlib import Path -import re -import stat -from typing import Any, Literal -from urllib.parse import urlsplit -from uuid import UUID - -from pydantic import BaseModel, ConfigDict, Field, field_validator, model_validator -from sqlalchemy import text -from sqlalchemy.ext.asyncio import AsyncConnection, AsyncEngine - - - -@unique -class ServiceIdentity(StrEnum): - """Revision-0023 fixed service identity values.""" - - ARTIFACT_VERIFIER = "workstream.artifact.verifier" - ARTIFACT_PUT_RESOLVER = "workstream.artifact.put_resolver" - ARTIFACT_SCHEDULER = "workstream.artifact.scheduler" - ARTIFACT_BINDING = "workstream.artifact.binding" - ARTIFACT_GUIDE_READER = "workstream.artifact.guide_reader" - ARTIFACT_MATERIALIZER = "workstream.artifact.materializer" - ARTIFACT_CHECKER_OUTPUT = "workstream.artifact.checker_output" - - -SERVICE_IDENTITIES = frozenset(ServiceIdentity) -SERVICE_IDENTITY_VALUES = tuple(identity.value for identity in ServiceIdentity) - -MAPPING_FILE_ENV = "WORKSTREAM_SERVICE_ACTOR_IDENTITY_MAPPING_FILE" -MAX_MAPPING_FILE_BYTES = 64 * 1024 -MAX_MAPPINGS = len(SERVICE_IDENTITIES) -MAPPING_SCHEMA_VERSION = 1 -_DATABASE_BINDING_PATTERN = re.compile(r"postgres-v1:[0-9a-f]{64}") -_GENERATED_AT_PATTERN = re.compile(r"\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z") - - -class ServiceIdentityMappingError(RuntimeError): - """Privacy-bounded mapping failure safe for migration and CLI output.""" - - def __init__(self, code: str, *, count: int | None = None) -> None: - self.code = code - self.count = count - super().__init__(code) - - -def _canonical_bytes(value: Any) -> bytes: - return json.dumps( - value, - allow_nan=False, - ensure_ascii=True, - separators=(",", ":"), - sort_keys=True, - ).encode("utf-8") - - -def _sha256(value: bytes) -> str: - return hashlib.sha256(value).hexdigest() - - -def database_binding_identifier(database_name: str, database_oid: int) -> str: - """Build the revision-0023 same-database binding identifier.""" - if not database_name or database_oid <= 0: - raise ServiceIdentityMappingError("database_binding_unavailable") - digest = _sha256( - _canonical_bytes( - { - "database_name": database_name, - "database_oid": database_oid, - "schema_version": MAPPING_SCHEMA_VERSION, - } - ) - ) - return f"postgres-v1:{digest}" - - -def _canonical_uuid(value: str) -> str: - try: - parsed = UUID(value) - except (AttributeError, TypeError, ValueError) as exc: - raise ValueError("invalid actor profile id") from exc - if str(parsed) != value: - raise ValueError("invalid actor profile id") - return value - - -def _canonical_issuer(value: str) -> str: - if not value or len(value) > 200 or value.strip() != value: - raise ValueError("invalid issuer") - parsed = urlsplit(value) - try: - parsed.port - except ValueError: - raise ValueError("invalid issuer") from None - if ( - parsed.scheme != "https" - or not parsed.hostname - or parsed.username is not None - or parsed.password is not None - or parsed.query - or parsed.fragment - or any(character.isspace() or ord(character) < 0x20 for character in value) - ): - raise ValueError("invalid issuer") - return value - - -def _canonical_subject(value: str) -> str: - if not value or not value.strip() or len(value) > 200: - raise ValueError("invalid subject") - return value - - -class ServiceActorIdentityMapping(BaseModel): - """One operator-approved fixed identity for an exact existing service link.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - actor_profile_id: str - issuer: str - subject: str - service_identity: ServiceIdentity - - @field_validator("actor_profile_id") - @classmethod - def validate_actor_profile_id(cls, value: str) -> str: - return _canonical_uuid(value) - - @field_validator("issuer") - @classmethod - def validate_issuer(cls, value: str) -> str: - return _canonical_issuer(value) - - @field_validator("subject") - @classmethod - def validate_subject(cls, value: str) -> str: - return _canonical_subject(value) - - -class ServiceActorIdentityMappingDraft(BaseModel): - """Strict operator-authored choices before database binding.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - schema_version: Literal[1] - mappings: tuple[ServiceActorIdentityMapping, ...] = Field(max_length=MAX_MAPPINGS) - - @field_validator("schema_version", mode="before") - @classmethod - def validate_schema_version(cls, value: Any) -> int: - if type(value) is not int or value != MAPPING_SCHEMA_VERSION: - raise ValueError("invalid schema version") - return value - - @model_validator(mode="after") - def validate_uniqueness(self) -> ServiceActorIdentityMappingDraft: - actor_ids = [row.actor_profile_id for row in self.mappings] - external_ids = [(row.issuer, row.subject) for row in self.mappings] - identities = [row.service_identity for row in self.mappings] - if ( - len(actor_ids) != len(set(actor_ids)) - or len(external_ids) != len(set(external_ids)) - or len(identities) != len(set(identities)) - ): - raise ValueError("duplicate mapping") - return self - - -class ExistingServiceActorRow(BaseModel): - """Privacy-sensitive locked database projection used only during mapping.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - actor_profile_id: str - issuer: str - subject: str - - @field_validator("actor_profile_id") - @classmethod - def validate_actor_profile_id(cls, value: str) -> str: - return _canonical_uuid(value) - - @field_validator("issuer") - @classmethod - def validate_issuer(cls, value: str) -> str: - return _canonical_issuer(value) - - @field_validator("subject") - @classmethod - def validate_subject(cls, value: str) -> str: - return _canonical_subject(value) - - -class ServiceActorIdentityMappingEnvelope(BaseModel): - """Confidential exact mapping bound to one locked database snapshot.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - schema_version: Literal[1] - mappings: tuple[ServiceActorIdentityMapping, ...] = Field(max_length=MAX_MAPPINGS) - source_row_set_sha256: str - manifest_sha256: str - generated_at: str - database_binding: str - envelope_sha256: str - - @field_validator("schema_version", mode="before") - @classmethod - def validate_schema_version(cls, value: Any) -> int: - if type(value) is not int or value != MAPPING_SCHEMA_VERSION: - raise ValueError("invalid schema version") - return value - - @model_validator(mode="after") - def validate_mapping_uniqueness(self) -> ServiceActorIdentityMappingEnvelope: - ServiceActorIdentityMappingDraft(schema_version=1, mappings=self.mappings) - for digest in ( - self.source_row_set_sha256, - self.manifest_sha256, - self.envelope_sha256, - ): - if len(digest) != 64 or any(character not in "0123456789abcdef" for character in digest): - raise ValueError("invalid digest") - if _DATABASE_BINDING_PATTERN.fullmatch(self.database_binding) is None: - raise ValueError("invalid database binding") - if _GENERATED_AT_PATTERN.fullmatch(self.generated_at) is None: - raise ValueError("invalid generated_at") - try: - parsed = datetime.fromisoformat(self.generated_at.removesuffix("Z") + "+00:00") - except ValueError as exc: - raise ValueError("invalid generated_at") from exc - if parsed.tzinfo != UTC or parsed.microsecond: - raise ValueError("invalid generated_at") - return self - - -class ServiceActorIdentitySnapshot(BaseModel): - """Exact existing service rows plus a non-secret database binding.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - rows: tuple[ExistingServiceActorRow, ...] - database_binding: str - - -class ServiceActorIdentityMappingReport(BaseModel): - """Bounded CLI report without actor or external identity material.""" - - model_config = ConfigDict(extra="forbid", frozen=True) - - status: Literal["valid"] = "valid" - mapped_count: int - source_row_set_sha256: str - manifest_sha256: str - envelope_sha256: str | None = None - database_binding: str - envelope_written: bool = False - - -def _mapping_payload(rows: Sequence[ServiceActorIdentityMapping]) -> list[dict[str, str]]: - return [ - row.model_dump(mode="json") - for row in sorted(rows, key=lambda item: item.actor_profile_id) - ] - - -def _source_payload(rows: Sequence[ExistingServiceActorRow]) -> list[dict[str, str]]: - return [ - row.model_dump(mode="json") - for row in sorted(rows, key=lambda item: item.actor_profile_id) - ] - - -def source_row_set_sha256(rows: Sequence[ExistingServiceActorRow]) -> str: - """Digest the exact private source set without exposing it.""" - return _sha256(_canonical_bytes(_source_payload(rows))) - - -def canonical_draft_bytes(draft: ServiceActorIdentityMappingDraft) -> bytes: - """Serialize operator choices deterministically for review and hashing.""" - return _canonical_bytes( - {"schema_version": draft.schema_version, "mappings": _mapping_payload(draft.mappings)} - ) - - -def _envelope_payload(envelope: ServiceActorIdentityMappingEnvelope) -> dict[str, Any]: - return { - "schema_version": envelope.schema_version, - "mappings": _mapping_payload(envelope.mappings), - "source_row_set_sha256": envelope.source_row_set_sha256, - "manifest_sha256": envelope.manifest_sha256, - "generated_at": envelope.generated_at, - "database_binding": envelope.database_binding, - } - - -def canonical_envelope_bytes(envelope: ServiceActorIdentityMappingEnvelope) -> bytes: - """Serialize a complete envelope deterministically.""" - return _canonical_bytes(envelope.model_dump(mode="json")) - - -def validate_draft( - draft: ServiceActorIdentityMappingDraft, - rows: Sequence[ExistingServiceActorRow], -) -> ServiceActorIdentityMappingDraft: - """Require a one-to-one mapping for the exact existing service row set.""" - if len(rows) > MAX_MAPPINGS: - raise ServiceIdentityMappingError("service_inventory_exceeds_registry", count=len(rows)) - source = {(row.actor_profile_id, row.issuer, row.subject) for row in rows} - proposed = { - (row.actor_profile_id, row.issuer, row.subject) for row in draft.mappings - } - if source != proposed: - raise ServiceIdentityMappingError("service_mapping_source_mismatch", count=len(rows)) - return draft - - -def build_envelope( - draft: ServiceActorIdentityMappingDraft, - rows: Sequence[ExistingServiceActorRow], - *, - database_binding: str, - generated_at: str, -) -> ServiceActorIdentityMappingEnvelope: - """Bind validated operator choices to one exact database snapshot.""" - validate_draft(draft, rows) - provisional = ServiceActorIdentityMappingEnvelope( - schema_version=MAPPING_SCHEMA_VERSION, - mappings=tuple(sorted(draft.mappings, key=lambda row: row.actor_profile_id)), - source_row_set_sha256=source_row_set_sha256(rows), - manifest_sha256=_sha256(canonical_draft_bytes(draft)), - generated_at=generated_at, - database_binding=database_binding, - envelope_sha256="0" * 64, - ) - return provisional.model_copy( - update={"envelope_sha256": _sha256(_canonical_bytes(_envelope_payload(provisional)))} - ) - - -def verify_envelope( - envelope: ServiceActorIdentityMappingEnvelope, - rows: Sequence[ExistingServiceActorRow], - *, - database_binding: str, -) -> ServiceActorIdentityMappingEnvelope: - """Verify checksums, database binding, and the complete current source set.""" - draft = ServiceActorIdentityMappingDraft( - schema_version=MAPPING_SCHEMA_VERSION, - mappings=envelope.mappings, - ) - validate_draft(draft, rows) - expected = build_envelope( - draft, - rows, - database_binding=database_binding, - generated_at=envelope.generated_at, - ) - if expected != envelope: - raise ServiceIdentityMappingError("service_mapping_envelope_mismatch", count=len(rows)) - return envelope - - -def _reject_duplicate_pairs(pairs: list[tuple[str, Any]]) -> dict[str, Any]: - result: dict[str, Any] = {} - for key, value in pairs: - if key in result: - raise ValueError("duplicate key") - result[key] = value - return result - - -def _read_private_json_bytes(path: Path) -> bytes: - """Read one owner-only regular file without following symlinks.""" - try: - descriptor = os.open(path, os.O_RDONLY | getattr(os, "O_NOFOLLOW", 0)) - except OSError: - raise ServiceIdentityMappingError("service_mapping_file_unavailable") from None - try: - metadata = os.fstat(descriptor) - if ( - not stat.S_ISREG(metadata.st_mode) - or metadata.st_uid != os.geteuid() - or stat.S_IMODE(metadata.st_mode) & 0o077 - or metadata.st_size > MAX_MAPPING_FILE_BYTES - ): - raise ServiceIdentityMappingError("service_mapping_file_insecure") - chunks: list[bytes] = [] - remaining = MAX_MAPPING_FILE_BYTES + 1 - while remaining: - chunk = os.read(descriptor, remaining) - if not chunk: - break - chunks.append(chunk) - remaining -= len(chunk) - data = b"".join(chunks) - finally: - os.close(descriptor) - if len(data) > MAX_MAPPING_FILE_BYTES: - raise ServiceIdentityMappingError("service_mapping_file_too_large") - return data - - -def _parse_private_json(data: bytes) -> Any: - try: - return json.loads( - data.decode("utf-8"), - object_pairs_hook=_reject_duplicate_pairs, - parse_constant=lambda _value: (_ for _ in ()).throw(ValueError("nonfinite")), - ) - except (UnicodeDecodeError, ValueError, json.JSONDecodeError): - raise ServiceIdentityMappingError("service_mapping_file_invalid") from None - - -def _git_common_directory(repository_root: Path) -> Path | None: - marker = repository_root / ".git" - if marker.is_dir(): - return marker.resolve() - try: - value = marker.read_text(encoding="utf-8").strip() - except FileNotFoundError: - return None - except OSError: - raise ServiceIdentityMappingError("git_directory_unavailable") from None - prefix = "gitdir: " - if not value.startswith(prefix): - raise ServiceIdentityMappingError("git_directory_unavailable") - worktree_git = Path(value.removeprefix(prefix)) - if not worktree_git.is_absolute(): - worktree_git = marker.parent / worktree_git - resolved = worktree_git.resolve() - if resolved.parent.name != "worktrees": - raise ServiceIdentityMappingError("git_directory_unavailable") - return resolved.parent.parent - - -def protected_mapping_roots(repository_root: Path) -> tuple[Path, ...]: - """Return every linked worktree root plus shared Git metadata.""" - common = _git_common_directory(repository_root) - roots = {repository_root.resolve()} - if common is None: - return tuple(roots) - roots.update({common, common.parent.resolve()}) - worktrees = common / "worktrees" - if worktrees.exists(): - try: - metadata_directories = tuple(worktrees.iterdir()) - except OSError: - raise ServiceIdentityMappingError("git_directory_unavailable") from None - for metadata in metadata_directories: - marker = metadata / "gitdir" - try: - git_file = Path(marker.read_text(encoding="utf-8").strip()) - except OSError: - raise ServiceIdentityMappingError("git_directory_unavailable") from None - if git_file.name != ".git" or not git_file.is_absolute(): - raise ServiceIdentityMappingError("git_directory_unavailable") - roots.add(git_file.parent.resolve()) - return tuple(sorted(roots, key=str)) - - -def validate_mapping_path( - path: Path, - *, - repository_root: Path, - output: bool = False, -) -> Path: - """Require an absolute path outside every repository and Git root.""" - if not path.is_absolute(): - raise ServiceIdentityMappingError("service_mapping_path_forbidden") - try: - resolved = path.parent.resolve(strict=True) / path.name - if not output and not resolved.exists(): - raise OSError("missing input") - except OSError: - raise ServiceIdentityMappingError("service_mapping_path_unavailable") from None - if any( - resolved == root or resolved.is_relative_to(root) - for root in protected_mapping_roots(repository_root) - ): - raise ServiceIdentityMappingError("service_mapping_path_forbidden") - return resolved - - -def load_draft(path: Path) -> ServiceActorIdentityMappingDraft: - """Load one strict confidential operator draft.""" - try: - data = _read_private_json_bytes(path) - draft = ServiceActorIdentityMappingDraft.model_validate(_parse_private_json(data)) - if data != canonical_draft_bytes(draft) + b"\n": - raise ValueError("noncanonical draft") - return draft - except ServiceIdentityMappingError: - raise - except Exception: - raise ServiceIdentityMappingError("service_mapping_draft_invalid") from None - - -def load_envelope(path: Path) -> ServiceActorIdentityMappingEnvelope: - """Load one strict confidential database-bound envelope.""" - try: - data = _read_private_json_bytes(path) - envelope = ServiceActorIdentityMappingEnvelope.model_validate(_parse_private_json(data)) - if data != canonical_envelope_bytes(envelope) + b"\n": - raise ValueError("noncanonical envelope") - return envelope - except ServiceIdentityMappingError: - raise - except Exception: - raise ServiceIdentityMappingError("service_mapping_envelope_invalid") from None - - -def publish_envelope(path: Path, envelope: ServiceActorIdentityMappingEnvelope) -> None: - """Create one owner-only envelope without overwriting or following links.""" - flags = os.O_WRONLY | os.O_CREAT | os.O_EXCL | getattr(os, "O_NOFOLLOW", 0) - try: - descriptor = os.open(path, flags, 0o600) - except OSError: - raise ServiceIdentityMappingError("service_mapping_output_unavailable") from None - try: - remaining = memoryview(canonical_envelope_bytes(envelope) + b"\n") - while remaining: - written = os.write(descriptor, remaining) - if written <= 0: - raise OSError("short write") - remaining = remaining[written:] - os.fsync(descriptor) - except OSError: - try: - path.unlink() - except OSError: - pass - raise ServiceIdentityMappingError("service_mapping_output_failed") from None - finally: - os.close(descriptor) - - -async def read_existing_service_rows(connection: AsyncConnection) -> ServiceActorIdentitySnapshot: - """Read the exact existing service/link set and bind it to this database.""" - raw_rows = ( - await connection.execute( - text( - "select p.id, l.issuer, l.subject from actor_profiles p " - "join actor_identity_links l on l.actor_profile_id=p.id " - "where p.actor_kind='service' order by p.id" - ) - ) - ).all() - database_name, database_oid = ( - await connection.execute( - text( - "select current_database(), oid from pg_database " - "where datname=current_database()" - ) - ) - ).one() - try: - rows = tuple( - ExistingServiceActorRow( - actor_profile_id=row[0], - issuer=row[1], - subject=row[2], - ) - for row in raw_rows - ) - except Exception: - raise ServiceIdentityMappingError("service_mapping_source_invalid") from None - return ServiceActorIdentitySnapshot( - rows=rows, - database_binding=database_binding_identifier(database_name, database_oid), - ) - - -async def snapshot_existing_service_rows(engine: AsyncEngine) -> ServiceActorIdentitySnapshot: - """Read one non-mutating snapshot for the operator tool.""" - async with engine.connect() as connection: - return await read_existing_service_rows(connection) - - -def load_migration_mapping( - rows: Sequence[ExistingServiceActorRow], - *, - database_binding: str, - repository_root: Path, -) -> ServiceActorIdentityMappingEnvelope | None: - """Load the required exact mapping from the migration-only environment.""" - raw_path = os.environ.get(MAPPING_FILE_ENV) - if not rows: - if raw_path: - raise ServiceIdentityMappingError("service_mapping_not_required", count=0) - return None - if not raw_path: - raise ServiceIdentityMappingError("service_mapping_required", count=len(rows)) - return verify_envelope( - load_envelope( - validate_mapping_path(Path(raw_path), repository_root=repository_root) - ), - rows, - database_binding=database_binding, - ) - - -def build_report( - snapshot: ServiceActorIdentitySnapshot, - draft: ServiceActorIdentityMappingDraft, - *, - envelope: ServiceActorIdentityMappingEnvelope | None = None, - envelope_written: bool = False, -) -> ServiceActorIdentityMappingReport: - """Return only bounded counts, bindings, and non-secret digests.""" - return ServiceActorIdentityMappingReport( - mapped_count=len(draft.mappings), - source_row_set_sha256=source_row_set_sha256(snapshot.rows), - manifest_sha256=_sha256(canonical_draft_bytes(draft)), - envelope_sha256=envelope.envelope_sha256 if envelope else None, - database_binding=snapshot.database_binding, - envelope_written=envelope_written, - ) diff --git a/backend/pyproject.toml b/backend/pyproject.toml index 49fa4d586..72b7bd29b 100644 --- a/backend/pyproject.toml +++ b/backend/pyproject.toml @@ -28,7 +28,7 @@ requires = ["setuptools>=68"] build-backend = "setuptools.build_meta" [tool.setuptools.packages.find] -include = ["app*", "migration_contracts*"] +include = ["app*"] [project.optional-dependencies] agents = [ diff --git a/backend/scripts/run_test_lanes.py b/backend/scripts/run_test_lanes.py index 76d8fb07a..0240df6c1 100644 --- a/backend/scripts/run_test_lanes.py +++ b/backend/scripts/run_test_lanes.py @@ -87,7 +87,6 @@ class TestLane: SHARED_FOUNDATION_MODULES = ( "tests/test_actor_legacy_classification.py", - "tests/test_actor_migration_tools.py", "tests/test_agent_runtime.py", "tests/test_api_contract_e2e.py", "tests/test_api_controls.py", diff --git a/backend/scripts/schema_baseline_manifest.py b/backend/scripts/schema_baseline_manifest.py new file mode 100644 index 000000000..da0eab4f6 --- /dev/null +++ b/backend/scripts/schema_baseline_manifest.py @@ -0,0 +1,272 @@ +"""Emit the deterministic v0.1 PostgreSQL schema manifest.""" + +from __future__ import annotations + +import argparse +import asyncio +from datetime import date, datetime +from decimal import Decimal +import hashlib +import json +import os +from pathlib import Path +import re +from typing import Any +from urllib.parse import urlsplit, urlunsplit + +import asyncpg + +REFERENCE_TABLES = ( + "actor_profile_migration_state", + "authority_control", + "iso_4217_currency_codes", +) +APPLICATION_ACL_PRINCIPALS: dict[str, str] = {} +_SPACE = re.compile(r"\s+") +_ARRAY_EXPRESSION = re.compile(r"ARRAY\[(.*?)\](?:::(?:text|character varying)\[\])?", re.S) + + +def _asyncpg_url(url: str) -> str: + parsed = urlsplit(url) + if parsed.scheme != "postgresql+asyncpg": + raise ValueError("database URL must use postgresql+asyncpg") + return urlunsplit(("postgresql", parsed.netloc, parsed.path, parsed.query, parsed.fragment)) + + +def _json_value(value: Any) -> Any: + if isinstance(value, (datetime, date)): + return value.isoformat() + if isinstance(value, Decimal): + return str(value) + if isinstance(value, bytes): + return value.hex() + return value + + +def _normalize_definition(value: str | None) -> str: + """Normalize insignificant formatting while preserving expression structure.""" + compact = _SPACE.sub(" ", value or "").strip() + + def normalize_array(match: re.Match[str]) -> str: + body = re.sub(r"::(?:character varying|text)", "", match.group(1)) + body = re.sub(r"\(('(?:[^']|'')*')\)", r"\1", body) + return f"ARRAY[{body}]" + + normalized = _ARRAY_EXPRESSION.sub(normalize_array, compact) + return re.sub(r"\((ARRAY\[.*?\])\)::text\[\]", r"\1", normalized) + + +async def _records(connection: asyncpg.Connection, query: str) -> list[dict[str, Any]]: + return [ + {key: _json_value(value) for key, value in record.items()} + for record in await connection.fetch(query) + ] + + +def canonical_acl_principal(grantee: str, owner: str) -> str: + """Return the stable manifest principal or reject an unconfigured role.""" + if grantee == owner: + return "owner" + if grantee == "PUBLIC": + return "PUBLIC" + if grantee in APPLICATION_ACL_PRINCIPALS: + return grantee + raise RuntimeError(f"unknown ACL principal: {grantee}") + + +async def _acl_manifest(connection: asyncpg.Connection) -> list[dict[str, str]]: + rows = await connection.fetch( + "with objects(kind,name,owner_oid,acl,default_kind) as (" + "select case when c.relkind='S' then 'sequence' else 'relation' end, " + "c.relname,c.relowner,c.relacl,case when c.relkind='S' then 'S'::\"char\" else 'r'::\"char\" end " + "from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "where n.nspname='public' and c.relname <> 'alembic_version' " + "and c.relkind in ('r','p','S','v','m','f') union all " + "select 'routine',p.proname||'('||pg_get_function_identity_arguments(p.oid)||')'," + "p.proowner,p.proacl,'f'::\"char\" from pg_proc p join pg_namespace n " + "on n.oid=p.pronamespace where n.nspname='public' union all " + "select 'type',t.typname,t.typowner,t.typacl,'T'::\"char\" from pg_type t " + "join pg_namespace n on n.oid=t.typnamespace where n.nspname='public' " + "and t.typrelid=0 and t.typcategory <> 'A') " + "select o.kind,o.name,owner.rolname owner_name,coalesce(grantee.rolname,'PUBLIC') grantee_name," + "x.privilege_type,x.is_grantable from objects o join pg_roles owner " + "on owner.oid=o.owner_oid cross join lateral aclexplode(" + "coalesce(o.acl,acldefault(o.default_kind,o.owner_oid))) x " + "left join pg_roles grantee on grantee.oid=x.grantee order by 1,2,5,4" + ) + result: list[dict[str, str]] = [] + for row in rows: + principal = canonical_acl_principal(row["grantee_name"], row["owner_name"]) + result.append( + { + "kind": row["kind"], + "name": row["name"], + "principal": principal, + "privilege": row["privilege_type"], + "grantable": str(row["is_grantable"]).lower(), + } + ) + return result + + +async def build_manifest(database_url: str) -> dict[str, Any]: + """Collect the closed v0.1 schema and reference-data inventory.""" + connection = await asyncpg.connect(_asyncpg_url(database_url)) + try: + tables = await _records( + connection, + "select c.relname name,c.relkind::text kind,c.relpersistence::text persistence," + "c.relrowsecurity row_security,c.relforcerowsecurity force_row_security " + "from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "where n.nspname='public' and c.relkind in ('r','p','v','m','f') " + "and c.relname <> 'alembic_version' order by c.relname", + ) + columns = await _records( + connection, + "select c.relname table_name,row_number() over (partition by c.oid order by a.attnum) ordinal,a.attname name," + "format_type(a.atttypid,a.atttypmod) data_type,a.attnotnull not_null," + "a.attidentity identity_kind,a.attgenerated generated_kind," + "coalesce(pg_get_expr(d.adbin,d.adrelid),'') default_expression " + "from pg_attribute a join pg_class c on c.oid=a.attrelid " + "join pg_namespace n on n.oid=c.relnamespace left join pg_attrdef d " + "on d.adrelid=a.attrelid and d.adnum=a.attnum where n.nspname='public' " + "and c.relname <> 'alembic_version' and c.relkind in ('r','p','v','m','f') " + "and a.attnum>0 and not a.attisdropped order by c.relname,a.attnum", + ) + constraints = await _records( + connection, + "select coalesce(c.relname,'') table_name,q.conname name,q.contype::text kind," + "pg_get_constraintdef(q.oid,true) definition from pg_constraint q " + "left join pg_class c on c.oid=q.conrelid join pg_namespace n " + "on n.oid=q.connamespace where n.nspname='public' " + "and coalesce(c.relname,'') <> 'alembic_version' order by 1,2", + ) + indexes = await _records( + connection, + "select tablename table_name,indexname name,indexdef definition " + "from pg_indexes where schemaname='public' and tablename <> 'alembic_version' " + "order by tablename,indexname", + ) + sequences = await _records( + connection, + "select s.sequencename name,s.data_type,s.start_value,s.min_value,s.max_value," + "s.increment_by,s.cycle,s.cache_size,s.last_value " + "from pg_sequences s where s.schemaname='public' " + "order by s.sequencename", + ) + for sequence in sequences: + identifier = str(sequence["name"]).replace('"', '""') + state = await connection.fetchrow( + f'SELECT last_value,is_called FROM public."{identifier}"' + ) + sequence["last_value"] = state["last_value"] + sequence["is_called"] = state["is_called"] + types = await _records( + connection, + "select t.typname name,t.typtype::text kind,coalesce(array_to_json(array_agg(e.enumlabel " + "order by e.enumsortorder) filter (where e.enumlabel is not null))::text,'[]') labels " + "from pg_type t join pg_namespace n on n.oid=t.typnamespace left join pg_enum e " + "on e.enumtypid=t.oid where n.nspname='public' and t.typrelid=0 " + "and t.typcategory <> 'A' group by t.typname,t.typtype order by t.typname", + ) + routines = await _records( + connection, + "select p.proname name,pg_get_function_identity_arguments(p.oid) arguments," + "pg_get_functiondef(p.oid) definition from pg_proc p join pg_namespace n " + "on n.oid=p.pronamespace where n.nspname='public' order by p.proname,arguments", + ) + triggers = await _records( + connection, + "select c.relname table_name,t.tgname name,t.tgenabled::text enabled," + "pg_get_triggerdef(t.oid,true) definition from pg_trigger t join pg_class c " + "on c.oid=t.tgrelid join pg_namespace n on n.oid=c.relnamespace " + "where n.nspname='public' and not t.tgisinternal order by c.relname,t.tgname", + ) + policies = await _records( + connection, + "select c.relname table_name,p.polname name,p.polpermissive permissive,p.polcmd command," + "p.polroles::text roles,coalesce(pg_get_expr(p.polqual,p.polrelid),'') using_expression," + "coalesce(pg_get_expr(p.polwithcheck,p.polrelid),'') check_expression " + "from pg_policy p join pg_class c on c.oid=p.polrelid join pg_namespace n " + "on n.oid=c.relnamespace where n.nspname='public' order by c.relname,p.polname", + ) + auxiliary = await _records( + connection, + "select kind,name,definition from (" + "select 'extension' kind,e.extname name,e.extversion definition from pg_extension e " + "join pg_namespace n on n.oid=e.extnamespace where n.nspname='public' union all " + "select 'domain',t.typname,format_type(t.typbasetype,t.typtypmod) from pg_type t " + "join pg_namespace n on n.oid=t.typnamespace where n.nspname='public' and t.typtype='d' " + "union all select 'collation',c.collname,coalesce(c.collversion,'') from pg_collation c " + "join pg_namespace n on n.oid=c.collnamespace where n.nspname='public' union all " + "select 'operator_class',o.opcname,a.amname from pg_opclass o join pg_namespace n " + "on n.oid=o.opcnamespace join pg_am a on a.oid=o.opcmethod where n.nspname='public') x " + "order by kind,name", + ) + reference_rows: dict[str, list[dict[str, Any]]] = {} + for table in REFERENCE_TABLES: + records = await connection.fetch(f'SELECT * FROM public."{table}" ORDER BY 1') + reference_rows[table] = [ + {key: _json_value(value) for key, value in row.items()} for row in records + ] + for collection in (columns, constraints, indexes, routines, triggers, policies): + for row in collection: + for key in tuple(row): + if "definition" in key or "expression" in key: + row[key] = _normalize_definition(str(row[key])) + return { + "format": "workstream-v01-schema-manifest-1", + "tables": tables, + "columns": columns, + "constraints": constraints, + "indexes": indexes, + "sequences": sequences, + "types": types, + "routines": routines, + "triggers": triggers, + "policies": policies, + "auxiliary_objects": auxiliary, + "acl": await _acl_manifest(connection), + "reference_rows": reference_rows, + } + finally: + await connection.close() + + +def canonical_bytes(manifest: dict[str, Any]) -> bytes: + """Serialize a manifest deterministically.""" + return (json.dumps(manifest, indent=2, sort_keys=True) + "\n").encode() + + +async def _run(args: argparse.Namespace) -> None: + manifest = await build_manifest(args.database_url) + payload = canonical_bytes(manifest) + if args.compare: + expected = args.compare.read_bytes() + if payload != expected: + raise RuntimeError( + "schema manifest mismatch: " + f"expected={hashlib.sha256(expected).hexdigest()} " + f"actual={hashlib.sha256(payload).hexdigest()}" + ) + if args.output: + args.output.write_bytes(payload) + elif not args.compare: + print(payload.decode(), end="") + + +def main() -> None: + parser = argparse.ArgumentParser() + parser.add_argument( + "--database-url", default=os.environ.get("WORKSTREAM_DATABASE_URL"), required=False + ) + parser.add_argument("--output", type=Path) + parser.add_argument("--compare", type=Path) + args = parser.parse_args() + if not args.database_url: + parser.error("--database-url or WORKSTREAM_DATABASE_URL is required") + asyncio.run(_run(args)) + + +if __name__ == "__main__": + main() diff --git a/backend/scripts/schema_baseline_sql.py b/backend/scripts/schema_baseline_sql.py new file mode 100644 index 000000000..ca228e2ce --- /dev/null +++ b/backend/scripts/schema_baseline_sql.py @@ -0,0 +1,68 @@ +"""Split reviewed PostgreSQL baseline resources without parsing function bodies.""" + +from __future__ import annotations + + +def split_sql_statements(source: str) -> tuple[str, ...]: + """Split SQL on top-level semicolons, preserving quoted and dollar bodies.""" + statements: list[str] = [] + start = 0 + index = 0 + single_quoted = False + double_quoted = False + dollar_tag: str | None = None + + while index < len(source): + character = source[index] + if dollar_tag is not None: + if source.startswith(dollar_tag, index): + index += len(dollar_tag) + dollar_tag = None + continue + index += 1 + continue + if single_quoted: + if character == "'": + if index + 1 < len(source) and source[index + 1] == "'": + index += 2 + continue + single_quoted = False + index += 1 + continue + if double_quoted: + if character == '"': + if index + 1 < len(source) and source[index + 1] == '"': + index += 2 + continue + double_quoted = False + index += 1 + continue + if character == "'": + single_quoted = True + index += 1 + continue + if character == '"': + double_quoted = True + index += 1 + continue + if character == "$": + end = source.find("$", index + 1) + if end != -1: + candidate = source[index : end + 1] + if candidate == "$$" or candidate[1:-1].replace("_", "a").isalnum(): + dollar_tag = candidate + index = end + 1 + continue + if character == ";": + statement = source[start:index].strip() + if statement: + statements.append(statement) + start = index + 1 + index += 1 + + remainder = source[start:].strip() + if remainder: + statements.append(remainder) + if single_quoted or double_quoted or dollar_tag is not None: + raise ValueError("unterminated quoted value in baseline SQL") + return tuple(statements) diff --git a/backend/scripts/service_actor_identity_mapping.py b/backend/scripts/service_actor_identity_mapping.py deleted file mode 100644 index 1b5012810..000000000 --- a/backend/scripts/service_actor_identity_mapping.py +++ /dev/null @@ -1,145 +0,0 @@ -#!/usr/bin/env python3 -"""Validate and bind confidential existing-service identity mappings.""" - -from __future__ import annotations - -import argparse -import asyncio -from datetime import UTC, datetime -import json -from pathlib import Path -import sys - -from app.db.session import dispose_engine, get_engine -from app.modules.actors.service_identity_migration import ( - ServiceActorIdentityMappingDraft, - ServiceIdentityMappingError, - build_envelope, - build_report, - load_draft, - load_envelope, - publish_envelope, - snapshot_existing_service_rows, - validate_draft, - validate_mapping_path, - verify_envelope, -) - - -class DatabaseCleanupError(RuntimeError): - """The CLI workflow succeeded but its async engine cleanup failed.""" - - -class PrivacyBoundedParser(argparse.ArgumentParser): - """Argument parser that never reflects confidential paths or values.""" - - def error(self, _message: str) -> None: - raise ServiceIdentityMappingError("invalid_arguments") - - -def _parser() -> PrivacyBoundedParser: - parser = PrivacyBoundedParser( - description="Validate fixed service identities without changing database state." - ) - commands = parser.add_subparsers(dest="command", required=True) - validate = commands.add_parser("validate") - validate.add_argument("--draft", type=Path, required=True) - bind = commands.add_parser("bind") - bind.add_argument("--draft", type=Path, required=True) - bind.add_argument("--output", type=Path, required=True) - verify = commands.add_parser("verify") - verify.add_argument("--envelope", type=Path, required=True) - return parser - - -async def _execute(args: argparse.Namespace) -> dict: - snapshot = await snapshot_existing_service_rows(get_engine()) - if args.command == "verify": - envelope = load_envelope(validate_mapping_path(args.envelope)) - verify_envelope( - envelope, - snapshot.rows, - database_binding=snapshot.database_binding, - ) - draft = ServiceActorIdentityMappingDraft( - schema_version=1, - mappings=envelope.mappings, - ) - return build_report(snapshot, draft, envelope=envelope).model_dump(mode="json") - - draft = load_draft(validate_mapping_path(args.draft)) - validate_draft(draft, snapshot.rows) - if args.command == "validate": - return build_report(snapshot, draft).model_dump(mode="json") - - generated_at = datetime.now(UTC).replace(microsecond=0).isoformat().replace("+00:00", "Z") - envelope = build_envelope( - draft, - snapshot.rows, - database_binding=snapshot.database_binding, - generated_at=generated_at, - ) - publish_envelope(validate_mapping_path(args.output, output=True), envelope) - return build_report( - snapshot, - draft, - envelope=envelope, - envelope_written=True, - ).model_dump(mode="json") - - -async def _execute_and_dispose(args: argparse.Namespace) -> dict: - """Execute and dispose the pooled engine on the same event loop.""" - try: - report = await _execute(args) - except BaseException: - try: - await dispose_engine() - except BaseException: - pass - raise - try: - await dispose_engine() - except BaseException: - raise DatabaseCleanupError from None - return report - - -def main(argv: list[str] | None = None) -> int: - """Run the validate, bind, or verify workflow with bounded output.""" - result = 0 - stdout_message: str | None = None - stderr_message: str | None = None - try: - args = _parser().parse_args(argv) - report = asyncio.run(_execute_and_dispose(args)) - stdout_message = json.dumps( - report, - allow_nan=False, - separators=(",", ":"), - sort_keys=True, - ) - except ServiceIdentityMappingError as exc: - error = {"error": exc.code, "status": "error"} - if exc.count is not None: - error["count"] = exc.count - stderr_message = json.dumps(error, separators=(",", ":"), sort_keys=True) - result = 2 - except KeyboardInterrupt: - stderr_message = '{"error":"interrupted","status":"error"}' - result = 130 - except DatabaseCleanupError: - stderr_message = '{"error":"database_cleanup_failed","status":"error"}' - result = 2 - except Exception: - stderr_message = '{"error":"database_operation_failed","status":"error"}' - result = 2 - if stdout_message is not None: - print(stdout_message) - if stderr_message is not None: - print(stderr_message, file=sys.stderr) - return result - - -if __name__ == "__main__": - raise SystemExit(main()) diff --git a/backend/tests/authorization/guide_compilation/test_migration_contract.py b/backend/tests/authorization/guide_compilation/test_migration_contract.py index daea3a0a1..a09c49137 100644 --- a/backend/tests/authorization/guide_compilation/test_migration_contract.py +++ b/backend/tests/authorization/guide_compilation/test_migration_contract.py @@ -1,72 +1,40 @@ -"""PostgreSQL topology proof for AUTH compilation migration 0063.""" +"""Current-schema proof for AUTH guide-compilation authority.""" import asyncio -from pathlib import Path from uuid import uuid4 -from alembic import command -from alembic.config import Config import asyncpg import pytest pytestmark = pytest.mark.postgres_schema_contract -def _config() -> Config: - root = Path(__file__).resolve().parents[3] - config = Config(str(root / "alembic.ini")) - config.set_main_option("script_location", str(root / "alembic")) - return config - - async def _registry_state(database_url: str) -> tuple[str, int, int, int]: connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) try: - head = await connection.fetchval("select version_num from alembic_version") - action = await connection.fetchval( - "select count(*) from pg_constraint where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_registries' and " - "pg_get_constraintdef(oid) like '%project.guide_compilation.request%'" - ) - evidence = await connection.fetchval( - "select count(*) from pg_constraint where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authorization_action_evidence' and " - "pg_get_constraintdef(oid) like '%project.guide_compilation.request%'" - ) - resource = await connection.fetchval( - "select count(*) from pg_constraint where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_privacy_bounds' and " - "pg_get_constraintdef(oid) like '%project_guide_compilation_request%'" - ) - return head, action, evidence, resource - finally: - await connection.close() - - -async def _insert_authority_evidence(database_url: str, action: str) -> str: - event_id = str(uuid4()) - connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) - try: - await connection.execute( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version,actor_ref_kind," - "request_id,correlation_id,permission_id,action_id,reason,denial_code,after_facts) " - "values($1,'authorization_decision',$1,'SensitiveAuthorizationDenied'," - "'workstream:system:bootstrap','[]'::json,'{}'::json,'local_authority',false," - "'{}'::json,'authority',1,'system_principal',$2,$3,$4,$4," - "'authorization_evaluation','permission_not_granted','{\"allowed\": false}'::json)", - event_id, - str(uuid4()), - str(uuid4()), - action, + return ( + await connection.fetchval("select version_num from alembic_version"), + await connection.fetchval( + "select count(*) from pg_constraint where conrelid='audit_events'::regclass " + "and conname='ck_audit_events_authority_registries' and " + "pg_get_constraintdef(oid) like '%project.guide_compilation.request%'" + ), + await connection.fetchval( + "select count(*) from pg_constraint where conrelid='audit_events'::regclass " + "and conname='ck_audit_events_authorization_action_evidence' and " + "pg_get_constraintdef(oid) like '%project.guide_compilation.request%'" + ), + await connection.fetchval( + "select count(*) from pg_constraint where conrelid='audit_events'::regclass " + "and conname='ck_audit_events_authority_privacy_bounds' and " + "pg_get_constraintdef(oid) like '%project_guide_compilation_request%'" + ), ) - return event_id finally: await connection.close() -async def _insert_permission_without_action(database_url: str, permission: str) -> str: +async def _insert_permission_without_action(database_url: str, permission: str) -> None: event_id = str(uuid4()) connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) try: @@ -84,157 +52,28 @@ async def _insert_permission_without_action(database_url: str, permission: str) str(uuid4()), permission, ) - return event_id finally: await connection.close() -async def _insert_compilation_registry_reference( - database_url: str, permission: str -) -> str: - event_id = str(uuid4()) - connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) - try: - await connection.execute( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version,actor_ref_kind," - "request_id,correlation_id,permission_id,action_id,target_ref_kind,target_ref_id," - "reason,after_facts) values($1,'authorization_decision',$1," - "'SensitiveAuthorizationAllowed','workstream:system:bootstrap','[]'::json," - "'{}'::json,'local_authority',false,'{}'::json,'authority',1," - "'system_principal',$2,$3,'actor.profile.read_self','actor.profile.read_self'," - "'permission_registry',$4," - "'authorization_evaluation','{\"allowed\": true}'::json)", - event_id, - str(uuid4()), - str(uuid4()), - permission, - ) - return event_id - finally: - await connection.close() - - -async def _remove_authority_evidence(database_url: str, event_id: str) -> None: - connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) - try: - async with connection.transaction(): - await connection.execute("lock table audit_events in access exclusive mode") - await connection.execute( - "alter table audit_events disable trigger audit_events_reject_update_delete" - ) - await connection.execute("delete from audit_events where id=$1", event_id) - await connection.execute( - "alter table audit_events enable trigger audit_events_reject_update_delete" - ) - finally: - await connection.close() - - -def test_0063_empty_round_trip_preserves_exact_request_registries( - isolated_database_env: str, migration_lock +def test_v01_baseline_preserves_exact_compilation_registries( + isolated_database_env: str, ) -> None: - config = _config() - with migration_lock(): - try: - command.downgrade(config, "0062_guide_compilation") - assert asyncio.run(_registry_state(isolated_database_env)) == ( - "0062_guide_compilation", - 0, - 0, - 0, - ) - command.upgrade(config, "0063_compilation_authority") - assert asyncio.run(_registry_state(isolated_database_env)) == ( - "0063_compilation_authority", - 1, - 1, - 1, - ) - finally: - command.upgrade(config, "head") + assert asyncio.run(_registry_state(isolated_database_env)) == ( + "0001_v01_baseline", + 1, + 1, + 1, + ) @pytest.mark.parametrize( "permission", ["project.guide_compilation.request", "project.guide_compilation.execute"], ) -def test_0063_compilation_permissions_require_exact_action_evidence( - isolated_database_env: str, migration_lock, permission: str -) -> None: - with migration_lock(): - with pytest.raises(asyncpg.CheckViolationError): - asyncio.run( - _insert_permission_without_action(isolated_database_env, permission) - ) - - -def test_0063_refuses_historical_permission_only_execute_evidence( - isolated_database_env: str, migration_lock -) -> None: - config = _config() - event_id = "" - with migration_lock(): - try: - command.downgrade(config, "0062_guide_compilation") - event_id = asyncio.run( - _insert_permission_without_action( - isolated_database_env, - "project.guide_compilation.execute", - ) - ) - with pytest.raises( - RuntimeError, - match="permission-only execute evidence", - ): - command.upgrade(config, "0063_compilation_authority") - assert asyncio.run(_registry_state(isolated_database_env))[0] == ( - "0062_guide_compilation" - ) - finally: - if event_id: - asyncio.run(_remove_authority_evidence(isolated_database_env, event_id)) - command.upgrade(config, "head") - - -@pytest.mark.parametrize( - "permission", - ["project.guide_compilation.request", "project.guide_compilation.execute"], -) -def test_0063_downgrade_refuses_compilation_permission_registry_reference( - isolated_database_env: str, migration_lock, permission: str -) -> None: - config = _config() - event_id = "" - with migration_lock(): - try: - event_id = asyncio.run( - _insert_compilation_registry_reference( - isolated_database_env, - permission, - ) - ) - with pytest.raises(RuntimeError, match="cannot downgrade retained"): - command.downgrade(config, "0062_guide_compilation") - finally: - if event_id: - asyncio.run(_remove_authority_evidence(isolated_database_env, event_id)) - command.upgrade(config, "head") - - -@pytest.mark.parametrize( - "action", ["project.guide_compilation.request", "project.guide_compilation.execute"] -) -def test_0063_refuses_downgrade_after_retained_compilation_authority( - isolated_database_env: str, migration_lock, action: str +def test_compilation_permissions_require_exact_action_evidence( + isolated_database_env: str, + permission: str, ) -> None: - config = _config() - with migration_lock(): - try: - command.upgrade(config, "head") - asyncio.run(_insert_authority_evidence(isolated_database_env, action)) - with pytest.raises(RuntimeError, match="cannot downgrade retained"): - command.downgrade(config, "0062_guide_compilation") - finally: - command.upgrade(config, "head") + with pytest.raises(asyncpg.CheckViolationError): + asyncio.run(_insert_permission_without_action(isolated_database_env, permission)) diff --git a/backend/tests/conftest.py b/backend/tests/conftest.py index f2bcccb4f..1a7fb232d 100644 --- a/backend/tests/conftest.py +++ b/backend/tests/conftest.py @@ -21,7 +21,7 @@ from scripts.run_isolated_tests import LOOPBACK, NAME_RE, ROLE_RE DDL_LOCK_DIRECTORY = Path("/tmp") -EXPECTED_PUBLIC_SCHEMA_SHA256 = "d311629237dea2163a76fa474aa3873a9343f05255ccd85e63357b4a1eb0d75c" +EXPECTED_PUBLIC_SCHEMA_SHA256 = "a99c6b144fddbaa2ba2bbc6d0639b09bcc025088160f345f65e30fd4b0055e77" PROTECTED_TEST_TABLES = ( "actor_profile_migration_state", "alembic_version", diff --git a/backend/tests/projects/guide_compilation/test_migration_contract.py b/backend/tests/projects/guide_compilation/test_migration_contract.py index 37107c586..25be8c128 100644 --- a/backend/tests/projects/guide_compilation/test_migration_contract.py +++ b/backend/tests/projects/guide_compilation/test_migration_contract.py @@ -1,112 +1,57 @@ -"""Alembic topology and downgrade custody for compilation persistence.""" +"""Current-schema custody proof for guide-compilation persistence.""" from __future__ import annotations import asyncio -from pathlib import Path -from alembic import command -from alembic.config import Config import asyncpg import pytest -from sqlalchemy.ext.asyncio import async_sessionmaker, create_async_engine -from app.modules.projects.guide_compilation.repository import GuideCompilationRepository - -from .helpers import context, identity, seed_database - - -def _config() -> Config: - root = Path(__file__).resolve().parents[3] - config = Config(str(root / "alembic.ini")) - config.set_main_option("script_location", str(root / "alembic")) - return config +pytestmark = pytest.mark.postgres_schema_contract async def _schema_state(database_url: str) -> tuple[str, bool, int, int, int, int]: connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) try: - head = await connection.fetchval("select version_num from alembic_version") - tables = await connection.fetchval( - "select to_regclass('project_guide_compilation_attempts') is not null" - ) - triggers = await connection.fetchval( - "select count(*) from pg_trigger where not tgisinternal and tgrelid in " - "(select c.oid from pg_class c join pg_namespace n on n.oid=c.relnamespace " - "where n.nspname='public' and c.relname in " - "('project_guide_compilation_attempts','project_guide_compilations'))" - ) - action_pairs = await connection.fetchval( - "select count(*) from pg_constraint where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authorization_action_evidence' and " - "pg_get_constraintdef(oid) like " - "'%project.guide_compilation.execute%'" - ) - permission_pairs = await connection.fetchval( - "select count(*) from pg_constraint where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_registries' and " - "pg_get_constraintdef(oid) like '%project.guide_compilation.execute%'" + return ( + await connection.fetchval("select version_num from alembic_version"), + await connection.fetchval( + "select to_regclass('project_guide_compilation_attempts') is not null" + ), + await connection.fetchval( + "select count(*) from pg_trigger where not tgisinternal and tgrelid in " + "(select c.oid from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "where n.nspname='public' and c.relname in " + "('project_guide_compilation_attempts','project_guide_compilations'))" + ), + await connection.fetchval( + "select count(*) from pg_constraint where conrelid='audit_events'::regclass " + "and conname='ck_audit_events_authorization_action_evidence' and " + "pg_get_constraintdef(oid) like '%project.guide_compilation.execute%'" + ), + await connection.fetchval( + "select count(*) from pg_constraint where conrelid='audit_events'::regclass " + "and conname='ck_audit_events_authority_registries' and " + "pg_get_constraintdef(oid) like '%project.guide_compilation.execute%'" + ), + await connection.fetchval( + "select count(*) from pg_constraint where conrelid='audit_events'::regclass " + "and conname='ck_audit_events_authority_privacy_bounds' and " + "pg_get_constraintdef(oid) like '%project_guide_compilation_attempt%'" + ), ) - resource_types = await connection.fetchval( - "select count(*) from pg_constraint where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_privacy_bounds' and " - "pg_get_constraintdef(oid) like '%project_guide_compilation_attempt%'" - ) - return head, tables, triggers, action_pairs, permission_pairs, resource_types finally: await connection.close() -def test_0062_empty_round_trip_restores_exact_current_schema( - isolated_database_env: str, migration_lock +def test_v01_baseline_preserves_guide_compilation_schema( + isolated_database_env: str, ) -> None: - """An empty 0062 downgrade/re-upgrade restores the current schema head.""" - config = _config() - with migration_lock(): - try: - command.downgrade(config, "0061_submission_admission") - assert asyncio.run(_schema_state(isolated_database_env)) == ( - "0061_submission_admission", - False, - 0, - 0, - 0, - 0, - ) - command.upgrade(config, "0062_guide_compilation") - assert asyncio.run(_schema_state(isolated_database_env)) == ( - "0062_guide_compilation", - True, - 4, - 1, - 1, - 1, - ) - finally: - command.upgrade(config, "head") - - -def test_0062_nonempty_attempt_blocks_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """A consumed setup generation cannot disappear through downgrade.""" - async def seed_attempt() -> None: - values = await seed_database(isolated_database_env) - engine = create_async_engine(isolated_database_env) - factory = async_sessionmaker(engine, expire_on_commit=False) - try: - async with factory() as session, session.begin(): - await GuideCompilationRepository(session).reserve_attempt( - identity(context(values)) - ) - finally: - await engine.dispose() - - asyncio.run(seed_attempt()) - with migration_lock(), pytest.raises( - RuntimeError, match="cannot downgrade non-empty guide-compilation custody" - ): - command.downgrade(_config(), "0061_submission_admission") - assert asyncio.run(_schema_state(isolated_database_env))[0] == ( - "0063_compilation_authority" + assert asyncio.run(_schema_state(isolated_database_env)) == ( + "0001_v01_baseline", + True, + 4, + 1, + 1, + 1, ) diff --git a/backend/tests/test_actor_migration_tools.py b/backend/tests/test_actor_migration_tools.py deleted file mode 100644 index 60222861a..000000000 --- a/backend/tests/test_actor_migration_tools.py +++ /dev/null @@ -1,574 +0,0 @@ -"""Behavior tests for fixed service-identity migration evidence.""" - -from __future__ import annotations - -import argparse -import asyncio -import json -import os -from pathlib import Path -from uuid import uuid4 - -import pytest -from pydantic import ValidationError - -from app.modules.actors import service_identity_migration as identity_migration -from app.modules.actors.legacy_classification import database_binding_identifier -from app.modules.actors.service_identity_migration import ( - MAPPING_FILE_ENV, - MAX_MAPPINGS, - ExistingServiceActorRow, - ServiceActorIdentityMapping, - ServiceActorIdentityMappingDraft, - ServiceActorIdentityMappingEnvelope, - ServiceIdentityMappingError, - build_envelope, - build_report, - canonical_draft_bytes, - load_draft, - load_envelope, - load_migration_mapping, - publish_envelope, - protected_mapping_roots, - source_row_set_sha256, - validate_draft, - validate_mapping_path, - verify_envelope, -) -from migration_contracts.service_identity_0023 import ( - SERVICE_IDENTITY_VALUES, - ServiceIdentity, -) -from scripts import service_actor_identity_mapping as mapping_cli - -ISSUER = "https://identity.example.test" -SUBJECT = "Opaque-Service-Subject" -ACTOR_ID = "11111111-1111-4111-8111-111111111111" -DATABASE_BINDING = database_binding_identifier("workstream", 16_384) -GENERATED_AT = "2026-07-16T12:00:00Z" - - -def source_row( - *, - actor_profile_id: str = ACTOR_ID, - subject: str = SUBJECT, -) -> ExistingServiceActorRow: - return ExistingServiceActorRow( - actor_profile_id=actor_profile_id, - issuer=ISSUER, - subject=subject, - ) - - -def mapping( - *, - actor_profile_id: str = ACTOR_ID, - subject: str = SUBJECT, - service_identity: ServiceIdentity = ServiceIdentity.ARTIFACT_VERIFIER, -) -> ServiceActorIdentityMapping: - return ServiceActorIdentityMapping( - actor_profile_id=actor_profile_id, - issuer=ISSUER, - subject=subject, - service_identity=service_identity, - ) - - -def draft(*rows: ServiceActorIdentityMapping) -> ServiceActorIdentityMappingDraft: - return ServiceActorIdentityMappingDraft(schema_version=1, mappings=rows) - - -def envelope(): - return build_envelope( - draft(mapping()), - (source_row(),), - database_binding=DATABASE_BINDING, - generated_at=GENERATED_AT, - ) - - -def write_private_json(path: Path, value: object) -> None: - path.write_text( - json.dumps( - value, - allow_nan=False, - ensure_ascii=True, - separators=(",", ":"), - sort_keys=True, - ) - + "\n", - encoding="utf-8", - ) - os.chmod(path, 0o600) - - -def test_service_identity_migration_contract_registry_is_exact() -> None: - assert SERVICE_IDENTITY_VALUES == ( - "workstream.artifact.verifier", - "workstream.artifact.put_resolver", - "workstream.artifact.scheduler", - "workstream.artifact.binding", - "workstream.artifact.guide_reader", - "workstream.artifact.materializer", - "workstream.artifact.checker_output", - ) - - -@pytest.mark.parametrize( - "field,value", - [ - ("actor_profile_id", str(uuid4()).upper()), - ("actor_profile_id", "not-a-uuid"), - ("issuer", "http://identity.example.test"), - ("issuer", "https://user@identity.example.test"), - ("issuer", "https://identity.example.test?private=true"), - ("subject", ""), - ("subject", " "), - ("service_identity", "workstream.artifact.unknown"), - ], -) -def test_mapping_rejects_noncanonical_or_unknown_values(field: str, value: str) -> None: - payload = mapping().model_dump(mode="json") - payload[field] = value - with pytest.raises(ValidationError): - ServiceActorIdentityMapping.model_validate(payload) - - -@pytest.mark.parametrize( - "issuer", - [ - "", - " https://identity.example.test", - "https://identity.example.test:invalid", - "https://identity.example.test/path\nsegment", - ], -) -def test_mapping_rejects_ambiguous_issuer_bytes(issuer: str) -> None: - payload = mapping().model_dump(mode="json") - payload["issuer"] = issuer - with pytest.raises(ValidationError): - ServiceActorIdentityMapping.model_validate(payload) - - -def test_draft_rejects_duplicate_profile_external_identity_and_fixed_identity() -> None: - duplicate = mapping() - with pytest.raises(ValidationError): - draft(duplicate, duplicate) - with pytest.raises(ValidationError): - draft( - duplicate, - mapping( - actor_profile_id="22222222-2222-4222-8222-222222222222", - subject="Other-Subject", - ), - ) - - -def test_exact_mapping_accepts_zero_subset_and_all_seven_rows() -> None: - assert validate_draft(draft(), ()) == draft() - assert validate_draft(draft(mapping()), (source_row(),)) == draft(mapping()) - source_rows = tuple( - source_row( - actor_profile_id=f"00000000-0000-4000-8000-{index:012d}", - subject=f"subject-{index}", - ) - for index in range(1, 8) - ) - mapped_rows = tuple( - mapping( - actor_profile_id=row.actor_profile_id, - subject=row.subject, - service_identity=identity, - ) - for row, identity in zip(source_rows, ServiceIdentity, strict=True) - ) - assert validate_draft(draft(*mapped_rows), source_rows).mappings == mapped_rows - - -def test_exact_mapping_rejects_missing_extra_or_changed_private_source() -> None: - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_source_mismatch"): - validate_draft(draft(), (source_row(),)) - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_source_mismatch"): - validate_draft(draft(mapping()), ()) - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_source_mismatch"): - validate_draft(draft(mapping(subject=SUBJECT.lower())), (source_row(),)) - - -def test_exact_mapping_rejects_inventory_larger_than_closed_registry() -> None: - rows = tuple( - source_row( - actor_profile_id=f"00000000-0000-4000-8000-{index:012d}", - subject=f"subject-{index}", - ) - for index in range(1, MAX_MAPPINGS + 2) - ) - with pytest.raises( - ServiceIdentityMappingError, - match="service_inventory_exceeds_registry", - ) as captured: - validate_draft(draft(), rows) - assert captured.value.count == MAX_MAPPINGS + 1 - - -def test_envelope_has_stable_known_answer_and_detects_any_binding_drift() -> None: - built = envelope() - assert built.envelope_sha256 == "1ca678ece8ec42fbd119209b963e3d25b36fc9c60dc00e9788328d4ed517a2d8" - assert verify_envelope( - built, - (source_row(),), - database_binding=DATABASE_BINDING, - ) == built - with pytest.raises(ServiceIdentityMappingError, match="envelope_mismatch"): - verify_envelope( - built, - (source_row(),), - database_binding=database_binding_identifier("other", 16_384), - ) - - -@pytest.mark.parametrize( - "field,value", - [ - ("schema_version", True), - ("schema_version", 1.0), - ("source_row_set_sha256", "g" * 64), - ("manifest_sha256", "0" * 63), - ("database_binding", "postgres-v1:not-a-digest"), - ("generated_at", "2026-02-31T12:00:00Z"), - ("generated_at", "2026-07-16 12:00:00Z"), - ], -) -def test_envelope_rejects_noncanonical_or_impossible_metadata( - field: str, - value: object, -) -> None: - payload = envelope().model_dump(mode="json") - payload[field] = value - with pytest.raises(ValidationError): - ServiceActorIdentityMappingEnvelope.model_validate(payload) - - -def test_canonical_hashes_ignore_input_order() -> None: - first = source_row() - second = source_row( - actor_profile_id="22222222-2222-4222-8222-222222222222", - subject="Second", - ) - first_mapping = mapping() - second_mapping = mapping( - actor_profile_id=second.actor_profile_id, - subject=second.subject, - service_identity=ServiceIdentity.ARTIFACT_PUT_RESOLVER, - ) - assert source_row_set_sha256((first, second)) == source_row_set_sha256((second, first)) - assert canonical_draft_bytes(draft(first_mapping, second_mapping)) == canonical_draft_bytes( - draft(second_mapping, first_mapping) - ) - - -@pytest.mark.parametrize( - "payload", - [ - b'{"schema_version":1,"schema_version":1,"mappings":[]}', - b'{"schema_version":NaN,"mappings":[]}', - b"{not-json}", - ], -) -def test_private_loader_rejects_ambiguous_json_without_echo(tmp_path: Path, payload: bytes) -> None: - path = tmp_path / "draft.json" - path.write_bytes(payload) - os.chmod(path, 0o600) - with pytest.raises(ServiceIdentityMappingError) as captured: - load_draft(path) - assert SUBJECT not in str(captured.value) - assert ISSUER not in str(captured.value) - - -def test_private_loader_redacts_strict_schema_failures(tmp_path: Path) -> None: - draft_path = tmp_path / "invalid-draft.json" - write_private_json( - draft_path, - { - "schema_version": 1, - "mappings": [{"actor_profile_id": ACTOR_ID, "subject": SUBJECT}], - }, - ) - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_draft_invalid"): - load_draft(draft_path) - - envelope_path = tmp_path / "invalid-envelope.json" - payload = envelope().model_dump(mode="json") - payload["unexpected_private_field"] = SUBJECT - write_private_json(envelope_path, payload) - with pytest.raises( - ServiceIdentityMappingError, - match="service_mapping_envelope_invalid", - ) as captured: - load_envelope(envelope_path) - assert SUBJECT not in str(captured.value) - - -@pytest.mark.parametrize("schema_version", [True, 1.0]) -def test_private_loader_rejects_coerced_schema_versions( - tmp_path: Path, - schema_version: object, -) -> None: - path = tmp_path / "coerced-version.json" - payload = draft().model_dump(mode="json") - payload["schema_version"] = schema_version - write_private_json(path, payload) - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_draft_invalid"): - load_draft(path) - - -def test_private_loader_accepts_only_exact_canonical_draft(tmp_path: Path) -> None: - path = tmp_path / "canonical-draft.json" - write_private_json(path, draft(mapping()).model_dump(mode="json")) - assert load_draft(path) == draft(mapping()) - - -def test_private_loader_requires_exact_canonical_bytes(tmp_path: Path) -> None: - draft_path = tmp_path / "pretty-draft.json" - draft_path.write_text( - json.dumps(draft().model_dump(mode="json"), indent=2) + "\n", - encoding="utf-8", - ) - os.chmod(draft_path, 0o600) - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_draft_invalid"): - load_draft(draft_path) - - envelope_path = tmp_path / "whitespace-envelope.json" - envelope_path.write_bytes( - json.dumps(envelope().model_dump(mode="json"), sort_keys=True).encode() + b"\n" - ) - os.chmod(envelope_path, 0o600) - with pytest.raises( - ServiceIdentityMappingError, - match="service_mapping_envelope_invalid", - ): - load_envelope(envelope_path) - - -def test_private_loader_rejects_open_permissions_and_symlink(tmp_path: Path) -> None: - path = tmp_path / "draft.json" - write_private_json(path, draft().model_dump(mode="json")) - os.chmod(path, 0o644) - with pytest.raises(ServiceIdentityMappingError, match="file_insecure"): - load_draft(path) - os.chmod(path, 0o600) - link = tmp_path / "draft-link.json" - link.symlink_to(path) - with pytest.raises(ServiceIdentityMappingError, match="file_unavailable"): - load_draft(link) - - -def test_publish_envelope_is_owner_only_reloadable_and_never_overwrites(tmp_path: Path) -> None: - path = tmp_path / "envelope.json" - publish_envelope(path, envelope()) - assert os.stat(path).st_mode & 0o777 == 0o600 - assert load_envelope(path) == envelope() - with pytest.raises(ServiceIdentityMappingError, match="output_unavailable"): - publish_envelope(path, envelope()) - - -def test_publish_envelope_removes_partial_output_after_write_failure( - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, -) -> None: - path = tmp_path / "partial-envelope.json" - - def fail_write(_descriptor: int, _data: object) -> int: - raise OSError("simulated private-output failure") - - monkeypatch.setattr(os, "write", fail_write) - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_output_failed"): - publish_envelope(path, envelope()) - assert not path.exists() - - -def test_migration_environment_is_required_only_for_existing_services( - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, -) -> None: - monkeypatch.delenv(MAPPING_FILE_ENV, raising=False) - assert load_migration_mapping((), database_binding=DATABASE_BINDING) is None - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_required"): - load_migration_mapping((source_row(),), database_binding=DATABASE_BINDING) - path = tmp_path / "envelope.json" - publish_envelope(path, envelope()) - monkeypatch.setenv(MAPPING_FILE_ENV, str(path)) - assert load_migration_mapping( - (source_row(),), database_binding=DATABASE_BINDING - ) == envelope() - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_not_required"): - load_migration_mapping((), database_binding=DATABASE_BINDING) - - -def test_mapping_paths_reject_relative_and_every_linked_repository_root( - monkeypatch: pytest.MonkeyPatch, -) -> None: - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_path_forbidden"): - validate_mapping_path(Path("relative-private-mapping.json"), output=True) - roots = protected_mapping_roots() - assert Path(__file__).resolve().parents[2] in roots - for root in roots: - with pytest.raises( - ServiceIdentityMappingError, - match="service_mapping_path_forbidden", - ): - validate_mapping_path(root / "private-mapping.json", output=True) - - monkeypatch.setenv(MAPPING_FILE_ENV, str(Path(__file__).resolve())) - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_path_forbidden"): - load_migration_mapping((source_row(),), database_binding=DATABASE_BINDING) - - -def test_mapping_path_guard_supports_deployments_without_git_metadata( - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, -) -> None: - deployed_root = tmp_path / "deployed-workstream" - deployed_root.mkdir() - private_root = tmp_path / "private" - private_root.mkdir() - monkeypatch.setattr(identity_migration, "REPOSITORY_ROOT", deployed_root) - assert protected_mapping_roots() == (deployed_root,) - assert validate_mapping_path( - private_root / "mapping.json", - output=True, - ) == private_root / "mapping.json" - - -def test_mapping_path_guard_handles_main_and_linked_git_layouts( - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, -) -> None: - main_root = tmp_path / "main" - (main_root / ".git").mkdir(parents=True) - monkeypatch.setattr(identity_migration, "REPOSITORY_ROOT", main_root) - assert set(protected_mapping_roots()) == {main_root, main_root / ".git"} - - linked_root = tmp_path / "linked" - linked_root.mkdir() - common = tmp_path / "common" / ".git" - metadata = common / "worktrees" / "linked" - metadata.mkdir(parents=True) - (linked_root / ".git").write_text( - "gitdir: ../common/.git/worktrees/linked\n", - encoding="utf-8", - ) - (metadata / "gitdir").write_text( - str(linked_root / ".git") + "\n", - encoding="utf-8", - ) - monkeypatch.setattr(identity_migration, "REPOSITORY_ROOT", linked_root) - assert {linked_root, common, common.parent}.issubset(protected_mapping_roots()) - - -@pytest.mark.parametrize( - "git_marker", - [ - "invalid-marker", - "gitdir: /tmp/not-a-worktrees-entry", - ], -) -def test_mapping_path_guard_rejects_invalid_git_metadata( - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, - git_marker: str, -) -> None: - repository = tmp_path / "repository" - repository.mkdir() - (repository / ".git").write_text(git_marker + "\n", encoding="utf-8") - monkeypatch.setattr(identity_migration, "REPOSITORY_ROOT", repository) - with pytest.raises(ServiceIdentityMappingError, match="git_directory_unavailable"): - protected_mapping_roots() - - -def test_mapping_path_guard_rejects_missing_linked_worktree_metadata( - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, -) -> None: - linked_root = tmp_path / "linked" - linked_root.mkdir() - common = tmp_path / "common" / ".git" - (common / "worktrees" / "linked").mkdir(parents=True) - (linked_root / ".git").write_text( - f"gitdir: {common / 'worktrees' / 'linked'}\n", - encoding="utf-8", - ) - monkeypatch.setattr(identity_migration, "REPOSITORY_ROOT", linked_root) - with pytest.raises(ServiceIdentityMappingError, match="git_directory_unavailable"): - protected_mapping_roots() - - -def test_mapping_path_guard_rejects_missing_input( - tmp_path: Path, -) -> None: - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_path_unavailable"): - validate_mapping_path(tmp_path / "missing-envelope.json") - - -def test_envelope_loader_preserves_bounded_file_errors(tmp_path: Path) -> None: - with pytest.raises(ServiceIdentityMappingError, match="service_mapping_file_unavailable"): - load_envelope(tmp_path / "missing-envelope.json") - - -def test_report_contains_only_counts_and_non_secret_digests() -> None: - snapshot = type("Snapshot", (), {"rows": (source_row(),), "database_binding": DATABASE_BINDING}) - report = build_report(snapshot, draft(mapping()), envelope=envelope()) - serialized = report.model_dump_json() - assert report.mapped_count == 1 - assert ACTOR_ID not in serialized - assert SUBJECT not in serialized - assert ISSUER not in serialized - - -def test_cli_executes_and_disposes_engine_on_one_event_loop( - monkeypatch: pytest.MonkeyPatch, -) -> None: - loop_ids: list[int] = [] - - async def execute(_args: argparse.Namespace) -> dict[str, str]: - loop_ids.append(id(asyncio.get_running_loop())) - return {"status": "valid"} - - async def dispose() -> None: - loop_ids.append(id(asyncio.get_running_loop())) - - monkeypatch.setattr(mapping_cli, "_execute", execute) - monkeypatch.setattr(mapping_cli, "dispose_engine", dispose) - assert asyncio.run(mapping_cli._execute_and_dispose(argparse.Namespace())) == { - "status": "valid" - } - assert len(set(loop_ids)) == 1 - - -def test_cli_preserves_workflow_error_when_cleanup_also_fails( - monkeypatch: pytest.MonkeyPatch, -) -> None: - async def execute(_args: argparse.Namespace) -> dict: - raise ServiceIdentityMappingError("expected_mapping_failure") - - async def dispose() -> None: - raise asyncio.CancelledError - - monkeypatch.setattr(mapping_cli, "_execute", execute) - monkeypatch.setattr(mapping_cli, "dispose_engine", dispose) - with pytest.raises(ServiceIdentityMappingError, match="expected_mapping_failure"): - asyncio.run(mapping_cli._execute_and_dispose(argparse.Namespace())) - - -def test_cli_reports_cleanup_failure_only_after_success( - monkeypatch: pytest.MonkeyPatch, -) -> None: - async def execute(_args: argparse.Namespace) -> dict[str, str]: - return {"status": "valid"} - - async def dispose() -> None: - raise asyncio.CancelledError - - monkeypatch.setattr(mapping_cli, "_execute", execute) - monkeypatch.setattr(mapping_cli, "dispose_engine", dispose) - with pytest.raises(mapping_cli.DatabaseCleanupError): - asyncio.run(mapping_cli._execute_and_dispose(argparse.Namespace())) diff --git a/backend/tests/test_alembic.py b/backend/tests/test_alembic.py index d0d5cdd49..186f2e7e2 100644 --- a/backend/tests/test_alembic.py +++ b/backend/tests/test_alembic.py @@ -1,14088 +1,308 @@ from __future__ import annotations import asyncio -from concurrent.futures import ThreadPoolExecutor -from datetime import UTC, datetime +from copy import deepcopy import hashlib import json -import os from pathlib import Path -import re -import threading -import time -from uuid import NAMESPACE_URL, UUID, uuid4, uuid5 -import pytest from alembic import command from alembic.config import Config -from migration_contracts import service_identity_0023 as frozen_service_identity_contract -from migration_contracts.service_identity_0023 import ( - SERVICE_IDENTITY_VALUES as FROZEN_SERVICE_IDENTITY_VALUES, - ServiceIdentityMappingError as FrozenServiceIdentityMappingError, - protected_mapping_roots as frozen_protected_mapping_roots, - validate_mapping_path as validate_frozen_mapping_path, -) -from sqlalchemy import select, text -from sqlalchemy.exc import DBAPIError, IntegrityError -from sqlalchemy.ext.asyncio import AsyncConnection, async_sessionmaker, create_async_engine - -from app.adapters.auth.dev import actor_id_from_external_identity -from app.core.hashing import canonical_json_hash -from app.modules.audit.schemas import ( - ActorReferenceKind, - AuthorityAuditEventInput, - AuthorityEventType, -) -from app.modules.audit.service import AuditService -from app.modules.authorization.catalogue import ( - ACTION_DEFINITIONS, - HISTORICAL_PERMISSION_IDS, - NEW_PERMISSION_IDS, - ActionId, - ActionOwner, - PermissionId, -) -from app.modules.authorization.runtime import ( - ProjectGuideMutationResourceContext, - authorization_resource_digest, -) -from app.modules.projects.models import ( - GuideMutationIdempotencyRecord, - ProjectCreateIdempotencyRecord, - ProjectGuide, -) -from project_create_fixtures import insert_historical_project, seed_authorized_project +from alembic.script import ScriptDirectory +import asyncpg +import pytest -from app.modules.actors.legacy_classification import ( - CLASSIFICATION_FILE_ENV, - LegacyActorClassification, - LegacyActorClassificationManifest, - LegacyActorRow, - LegacyClassificationError, - build_envelope, - canonical_envelope_bytes, - database_binding_identifier, +from scripts.schema_baseline_manifest import ( + APPLICATION_ACL_PRINCIPALS, + build_manifest, + canonical_acl_principal, + canonical_bytes, ) -from app.modules.actors.service_identities import ServiceIdentity -from app.modules.actors.service_identity_migration import ( - MAPPING_FILE_ENV, - ServiceActorIdentityMapping, - ServiceActorIdentityMappingDraft, - build_envelope as build_service_identity_envelope, - publish_envelope as publish_service_identity_envelope, - snapshot_existing_service_rows, -) - -HEAD_REVISION = "0063_compilation_authority" +from scripts.schema_baseline_sql import split_sql_statements +HEAD_REVISION = "0001_v01_baseline" +RECREATE_GUIDANCE = "Workstream v0.1 requires a fresh database; recreate this database" pytestmark = pytest.mark.postgres_schema_contract -_OBSOLETE_ART_UPLOAD_IDS = tuple( - "artifact.upload_" + value - for value in ( - "session.create", - "session.read", - "item.write", - "session.seal", - "session.cancel", - "session.expire", - ) -) - -_PROJECT_MUTATION_OWNERS = { - ActionOwner.AUTH_12B2, - ActionOwner.AUTH_12C, - ActionOwner.AUTH_12D, - ActionOwner.XINT_003_02B, - ActionOwner.AUTH_12E, - ActionOwner.AUTH_12F, - ActionOwner.AUTH_12F2, - ActionOwner.AUTH_12F3, - ActionOwner.AUTH_12G, - ActionOwner.AUTH_12H, -} - - -async def _pre_submit_evidence_schema(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - tables = { - row - for row in ( - await connection.execute( - text( - "select table_name from information_schema.tables where " - "table_schema=current_schema() and table_name like " - "'pre_submit_evidence_%'" - ) - ) - ).scalars() - } - constraints = { - row - for row in ( - await connection.execute( - text( - "select conname from pg_constraint where conname like " - "'%pre_submit_evidence%' or conname in " - "('uq_actor_identity_links_id_profile'," - "'uq_workstream_tasks_id_project'," - "'uq_task_assignments_id_task_contributor'," - "'uq_project_guides_id_project_version')" - ) - ) - ).scalars() - } - triggers = { - row - for row in ( - await connection.execute( - text( - "select tgname from pg_trigger where not tgisinternal and " - "tgname like 'pre_submit_evidence_%'" - ) - ) - ).scalars() - } - return {"tables": tables, "constraints": constraints, "triggers": triggers} - finally: - await engine.dispose() +def _alembic_config() -> Config: + backend = Path(__file__).resolve().parents[1] + return Config(backend / "alembic.ini") -def test_0058_pre_submit_evidence_empty_round_trip( - isolated_database_env: str, - migration_lock, -) -> None: - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "0057_submission_policy_authority") - prior = asyncio.run(_pre_submit_evidence_schema(isolated_database_env)) - command.upgrade(config, HEAD_REVISION) - installed = asyncio.run(_pre_submit_evidence_schema(isolated_database_env)) - command.downgrade(config, "0057_submission_policy_authority") - restored = asyncio.run(_pre_submit_evidence_schema(isolated_database_env)) - command.upgrade(config, HEAD_REVISION) - repeated = asyncio.run(_pre_submit_evidence_schema(isolated_database_env)) - finally: - command.upgrade(config, "head") - assert prior == restored == {"tables": set(), "constraints": set(), "triggers": set()} - assert installed == repeated - assert installed["tables"] == { - "pre_submit_evidence_sets", - "pre_submit_evidence_results", - } - assert { - "uq_actor_identity_links_id_profile", - "uq_workstream_tasks_id_project", - "uq_task_assignments_id_task_contributor", - "uq_project_guides_id_project_version", - "fk_pre_submit_evidence_identity_actor", - "fk_pre_submit_evidence_assignment", - "fk_pre_submit_evidence_task_project", - "fk_pre_submit_evidence_guide_lineage", - "fk_pre_submit_evidence_task_source_snapshot", - "ck_pre_submit_evidence_results_result_failure_shape", - }.issubset(installed["constraints"]) - assert installed["triggers"] == { - "pre_submit_evidence_sets_immutable", - "pre_submit_evidence_sets_creation", - "pre_submit_evidence_sets_no_truncate", - "pre_submit_evidence_results_immutable", - "pre_submit_evidence_results_membership", - "pre_submit_evidence_results_no_truncate", - } +def _manifest_path() -> Path: + return Path(__file__).resolve().parents[1] / "alembic/baseline/v01_baseline_manifest.json" -async def _submission_bundle_intent_schema(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) +async def _database_snapshot(database_url: str) -> dict[str, object]: + connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) try: - async with engine.connect() as connection: - table_exists = bool( - await connection.scalar( - text("select to_regclass('submission_bundle_durable_intents') is not null") - ) - ) - request_type = await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='artifact_put_attempts'::regclass " - "and conname='ck_artifact_put_attempts_producer_request_type'" + objects = await connection.fetch( + "select c.relkind::text,c.relname from pg_class c join pg_namespace n " + "on n.oid=c.relnamespace where n.nspname='public' order by 1,2" + ) + versions: list[str] = [] + if await connection.fetchval("select to_regclass('public.alembic_version') is not null"): + versions = await connection.fetch("select version_num from alembic_version order by 1") + reference_rows: dict[str, list[str]] = {} + for table in ( + "actor_profile_migration_state", + "authority_control", + "iso_4217_currency_codes", + ): + if await connection.fetchval("select to_regclass($1) is not null", f"public.{table}"): + rows = await connection.fetch( + f'SELECT row_to_json(t)::text value FROM public."{table}" t ORDER BY 1' ) - ) - constraints = { - row - for row in ( - await connection.execute( - text( - "select conname from pg_constraint where conrelid=" - "to_regclass('submission_bundle_durable_intents')" - ) - ) - ).scalars() - } - triggers = { - row - for row in ( - await connection.execute( - text( - "select tgname from pg_trigger where not tgisinternal and " - "tgrelid=to_regclass('submission_bundle_durable_intents')" - ) - ) - ).scalars() - } - receipt_triggers = { - row - for row in ( - await connection.execute( - text( - "select tgname from pg_trigger where not tgisinternal and " - "tgrelid='artifact_operation_receipts'::regclass" - ) - ) - ).scalars() - } - return { - "table_exists": table_exists, - "request_type": request_type, - "constraints": constraints, - "triggers": triggers, - "receipt_triggers": receipt_triggers, - } + reference_rows[table] = [row["value"] for row in rows] + return { + "versions": [row["version_num"] for row in versions], + "objects": [tuple(row.values()) for row in objects], + "reference_rows": reference_rows, + } finally: - await engine.dispose() - - -def test_0060_submission_bundle_intent_empty_round_trip( - isolated_database_env: str, - migration_lock, -) -> None: - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "0059_policy_execution_claim") - prior = asyncio.run(_submission_bundle_intent_schema(isolated_database_env)) - command.upgrade(config, HEAD_REVISION) - installed = asyncio.run(_submission_bundle_intent_schema(isolated_database_env)) - command.downgrade(config, "0059_policy_execution_claim") - restored = asyncio.run(_submission_bundle_intent_schema(isolated_database_env)) - command.upgrade(config, HEAD_REVISION) - repeated = asyncio.run(_submission_bundle_intent_schema(isolated_database_env)) - finally: - command.upgrade(config, "head") - - assert prior == restored - assert prior["table_exists"] is False - assert "submission_bundle" not in str(prior["request_type"]) - assert installed == repeated - assert installed["table_exists"] is True - assert "submission_bundle" in str(installed["request_type"]) - assert { - "uq_submission_bundle_intent_evidence", - "uq_submission_bundle_intent_put_attempt", - }.issubset(installed["constraints"]) - assert installed["triggers"] == { - "submission_bundle_durable_intent_put_attempt", - "submission_bundle_durable_intents_immutable", - "submission_bundle_durable_intents_no_truncate", - } - assert "artifact_receipt_producer_reference" in installed["receipt_triggers"] + await connection.close() -async def _submission_bundle_admission_schema(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) +async def _execute(database_url: str, statement: str, *arguments: object) -> None: + connection = await asyncpg.connect(database_url.replace("+asyncpg", "")) try: - async with engine.connect() as connection: - table_exists = bool( - await connection.scalar( - text("select to_regclass('submission_bundle_admissions') is not null") - ) - ) - constraints = set( - ( - await connection.scalars( - text( - "select conname from pg_constraint where conrelid=" - "to_regclass('submission_bundle_admissions')" - ) - ) - ).all() - ) - triggers = set( - ( - await connection.scalars( - text( - "select tgname from pg_trigger where not tgisinternal and " - "tgrelid=to_regclass('submission_bundle_admissions')" - ) - ) - ).all() - ) - evidence_column = bool( - await connection.scalar( - text( - "select count(*) from information_schema.columns " - "where table_schema='public' and table_name='pre_submit_evidence_sets' " - "and column_name='locked_policy_context_hash'" - ) - ) - ) - evidence_constraints = set( - ( - await connection.scalars( - text( - "select conname from pg_constraint where conrelid=" - "to_regclass('pre_submit_evidence_sets') and " - "conname='ck_pre_submit_evidence_sets_policy_context_sha256'" - ) - ) - ).all() - ) - evidence_immutable_enabled = await connection.scalar( - text( - "select tgenabled from pg_trigger where not tgisinternal and " - "tgrelid=to_regclass('pre_submit_evidence_sets') and " - "tgname='pre_submit_evidence_sets_immutable'" - ) - ) - consumer_index = bool( - await connection.scalar( - text( - "select count(*) from pg_indexes where schemaname='public' and " - "tablename='submission_bundle_admissions' and " - "indexname='uq_submission_bundle_admission_consumer'" - ) - ) - ) - return { - "table_exists": table_exists, - "constraints": constraints, - "triggers": triggers, - "evidence_column": evidence_column, - "evidence_constraints": evidence_constraints, - "evidence_immutable_enabled": evidence_immutable_enabled, - "consumer_index": consumer_index, - } + await connection.execute(statement, *arguments) finally: - await engine.dispose() + await connection.close() -def test_0061_submission_bundle_admission_empty_round_trip( - isolated_database_env: str, - migration_lock, -) -> None: +def test_v01_graph_has_one_root_and_head() -> None: config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "0060_submission_bundle_intent") - prior = asyncio.run(_submission_bundle_admission_schema(isolated_database_env)) - command.upgrade(config, HEAD_REVISION) - installed = asyncio.run(_submission_bundle_admission_schema(isolated_database_env)) - command.downgrade(config, "0060_submission_bundle_intent") - restored = asyncio.run(_submission_bundle_admission_schema(isolated_database_env)) - command.upgrade(config, HEAD_REVISION) - repeated = asyncio.run(_submission_bundle_admission_schema(isolated_database_env)) - finally: - command.upgrade(config, "head") - - assert ( - prior - == restored - == { - "table_exists": False, - "constraints": set(), - "triggers": set(), - "evidence_column": False, - "evidence_constraints": set(), - "evidence_immutable_enabled": b"O", - "consumer_index": False, - } - ) - assert installed == repeated - assert { - "uq_submission_bundle_admission_intent", - "uq_submission_bundle_admission_evidence", - "uq_submission_bundle_admission_verification", - "ck_submission_bundle_admissions_terminal_shape", - "ck_submission_bundle_admissions_write_receipt_shape", - }.issubset(installed["constraints"]) - assert installed["triggers"] == { - "submission_bundle_admission_verified_lineage", - "submission_bundle_admission_lineage", - "submission_bundle_admission_delete", - } - assert installed["evidence_column"] is True - assert installed["evidence_constraints"] == { - "ck_pre_submit_evidence_sets_policy_context_sha256" - } - assert installed["evidence_immutable_enabled"] == b"O" - assert installed["consumer_index"] is True - - -async def _submission_policy_authority_shape(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - columns = int( - await connection.scalar( - text( - "select count(*) from information_schema.columns where " - "table_schema=current_schema() and " - "((table_name='submission_artifact_policies' and " - "column_name in ('created_by_actor_profile_id'," - "'approved_by_actor_profile_id')) or " - "(table_name in ('effective_project_submission_artifact_policies'," - "'pre_submit_checker_policies') and " - "column_name='created_by_actor_profile_id'))" - ) - ) - or 0 - ) - replay_table = bool( - await connection.scalar( - text( - "select to_regclass(current_schema() || " - "'.submission_policy_mutation_idempotency_records') is not null" - ) - ) - ) - provenance_triggers = int( - await connection.scalar( - text( - "select count(*) from pg_trigger where not tgisinternal and " - "tgname=any(:names)" - ), - { - "names": [ - "submission_policy_creation_provenance_immutable", - "submission_policy_approval_provenance_immutable", - "effective_submission_policy_provenance_immutable", - "pre_submit_policy_provenance_immutable", - ] - }, - ) - or 0 - ) - action_states = tuple( - ( - definition.action_id.value, - definition.availability.value, - ) - for definition in ACTION_DEFINITIONS - if definition.action_id - in { - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_CREATE, - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_DERIVE, - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_UPDATE, - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_APPROVE, - } - ) - return { - "columns": columns, - "replay_table": replay_table, - "provenance_triggers": provenance_triggers, - "action_states": action_states, - } - finally: - await engine.dispose() - - -async def _seed_historical_submission_policy(database_url: str, ids: dict[str, str]) -> None: - engine = create_async_engine(database_url) - digest = f"sha256:{'a' * 64}" - policy_digest = f"sha256:{'b' * 64}" - try: - async with engine.begin() as connection: - await insert_historical_project( - connection, - project_id=ids["project"], - name="0057 historical policy", - slug=f"submission-policy-{ids['project']}", - ) - for table, trigger in ( - ("project_guides", "guide_mutation_product_custody"), - ("guide_source_snapshots", "source_snapshot_product_custody"), - ): - await connection.execute(text(f"alter table {table} disable trigger {trigger}")) - await connection.execute( - text( - "insert into project_guides(id,project_id,version,status,content_markdown," - "created_by) values(:guide,:project,'v1','draft','# guide','migration-test')" - ), - ids, - ) - await connection.execute( - text( - "insert into guide_source_snapshots(id,project_id,guide_id,guide_version," - "manifest_schema_version,manifest_json,bundle_hash,captured_by) values(" - ":snapshot,:project,:guide,'v1','1','{}'::json,:digest,'migration-test')" - ), - {**ids, "digest": digest}, - ) - for table, trigger in ( - ("project_guides", "guide_mutation_product_custody"), - ("guide_source_snapshots", "source_snapshot_product_custody"), - ): - await connection.execute(text(f"alter table {table} enable trigger {trigger}")) - await connection.execute( - text( - "insert into submission_artifact_policies(" - "id,project_id,guide_id,guide_version,source_snapshot_id," - "source_snapshot_hash,policy_version,lifecycle_status,policy_body," - "policy_hash,derivation_source,source_material_refs,created_by) values(" - ":policy,:project,:guide,'v1',:snapshot,:digest,'v1','draft','{}'::json," - ":policy_digest,'migration-test','[]'::json,'migration-test')" - ), - {**ids, "digest": digest, "policy_digest": policy_digest}, - ) - finally: - await engine.dispose() + script = ScriptDirectory.from_config(config) + revisions = list(script.walk_revisions()) - -async def _historical_submission_policy_authority(database_url: str, policy_id: str): - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return tuple( - ( - await connection.execute( - text( - "select policy_hash,created_by_actor_profile_id," - "created_via_identity_link_id,creation_action_id," - "approved_by_actor_profile_id,approval_action_id " - "from submission_artifact_policies where id=:id" - ), - {"id": policy_id}, - ) - ).one() - ) - finally: - await engine.dispose() + assert [revision.revision for revision in revisions] == [HEAD_REVISION] + assert revisions[0].down_revision is None + assert script.get_heads() == [HEAD_REVISION] -def test_submission_policy_authority_safe_empty_roundtrip( - isolated_database_env: str, - migration_lock, +def test_fresh_database_matches_committed_manifest( + isolated_database_env: str, migration_lock ) -> None: - """0057 installs only inactive custody and is reversible while unused.""" config = _alembic_config() - ids = {name: str(uuid4()) for name in ("project", "guide", "snapshot", "policy")} with migration_lock(): - try: - command.downgrade(config, "0056_review_lease_preference") - prior = asyncio.run(_submission_policy_authority_shape(isolated_database_env)) - asyncio.run(_seed_historical_submission_policy(isolated_database_env, ids)) - command.upgrade(config, HEAD_REVISION) - upgraded = asyncio.run(_submission_policy_authority_shape(isolated_database_env)) - historical = asyncio.run( - _historical_submission_policy_authority(isolated_database_env, ids["policy"]) - ) - command.downgrade(config, "0056_review_lease_preference") - restored = asyncio.run(_submission_policy_authority_shape(isolated_database_env)) - command.upgrade(config, HEAD_REVISION) - repeated = asyncio.run(_submission_policy_authority_shape(isolated_database_env)) + asyncio.run( + _execute(isolated_database_env, "drop schema public cascade; create schema public") + ) + command.upgrade(config, HEAD_REVISION) + expected = _manifest_path().read_bytes() + actual = canonical_bytes(asyncio.run(build_manifest(isolated_database_env))) + + assert hashlib.sha256(actual).hexdigest() == hashlib.sha256(expected).hexdigest() + assert actual == expected + + +def test_manifest_covers_every_required_object_class() -> None: + manifest = json.loads(_manifest_path().read_text(encoding="utf-8")) + assert manifest["format"] == "workstream-v01-schema-manifest-1" + assert len(manifest["tables"]) == 75 + assert len(manifest["columns"]) >= 1_200 + assert len(manifest["constraints"]) >= 850 + assert len(manifest["indexes"]) >= 400 + assert len(manifest["sequences"]) == 2 + assert len(manifest["routines"]) == 81 + assert len(manifest["triggers"]) == 113 + assert sum(row["principal"] == "PUBLIC" for row in manifest["acl"]) == 81 + assert set(manifest["reference_rows"]) == { + "actor_profile_migration_state", + "authority_control", + "iso_4217_currency_codes", + } + assert all(row["principal"] in {"owner", "PUBLIC"} for row in manifest["acl"]) + assert manifest["types"] == [] + assert manifest["policies"] == [] + assert manifest["auxiliary_objects"] == [] + + +def test_source_to_baseline_delta_is_exactly_the_approved_sequence_repair() -> None: + baseline_dir = _manifest_path().parent + source = json.loads((baseline_dir / "v01_pre_reset_source_manifest.json").read_text()) + expected = json.loads(_manifest_path().read_text()) + delta = json.loads((baseline_dir / "v01_approved_manifest_delta.json").read_text()) + repaired = deepcopy(source) + changes = {entry["name"]: entry for entry in delta["sequence_state_changes"]} + assert set(changes) == { + "actor_profile_migration_state_id_seq", + "authority_control_id_seq", + } + for sequence in repaired["sequences"]: + if sequence["name"] in changes: + change = changes[sequence["name"]] + assert sequence[change["field"]] == change["from"] + sequence[change["field"]] = change["to"] + assert canonical_bytes(repaired) == canonical_bytes(expected) + + +def test_acl_principals_are_closed_and_owner_mapping_is_role_name_independent() -> None: + assert APPLICATION_ACL_PRINCIPALS == {} + assert canonical_acl_principal("database_owner", "database_owner") == "owner" + assert canonical_acl_principal("PUBLIC", "database_owner") == "PUBLIC" + with pytest.raises(RuntimeError, match="unknown ACL principal"): + canonical_acl_principal("unexpected_role", "database_owner") + + +def test_every_acl_principal_is_effective_on_the_installed_baseline( + isolated_database_env: str, +) -> None: + async def acl_results() -> tuple[int, int]: + connection = await asyncpg.connect(isolated_database_env.replace("+asyncpg", "")) + try: + row = await connection.fetchrow( + "with checks(ok) as (" + "select has_table_privilege(c.relowner,c.oid,x.privilege_type) " + "from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "cross join lateral aclexplode(coalesce(c.relacl,acldefault(" + "case when c.relkind='S' then 'S'::\"char\" else 'r'::\"char\" end,c.relowner))) x " + "where n.nspname='public' and c.relname <> 'alembic_version' " + "and c.relkind in ('r','p','v','m','f') and x.grantee=c.relowner " + "union all select has_sequence_privilege(c.relowner,c.oid,x.privilege_type) " + "from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "cross join lateral aclexplode(coalesce(c.relacl,acldefault('S',c.relowner))) x " + "where n.nspname='public' and c.relkind='S' and x.grantee=c.relowner " + "union all select has_function_privilege(p.proowner,p.oid,x.privilege_type) " + "from pg_proc p join pg_namespace n on n.oid=p.pronamespace " + "cross join lateral aclexplode(coalesce(p.proacl,acldefault('f',p.proowner))) x " + "where n.nspname='public' and x.grantee=p.proowner " + "union all select has_type_privilege(t.typowner,t.oid,x.privilege_type) " + "from pg_type t join pg_namespace n on n.oid=t.typnamespace " + "cross join lateral aclexplode(coalesce(t.typacl,acldefault('T',t.typowner))) x " + "where n.nspname='public' and t.typrelid=0 and t.typcategory <> 'A' " + "and x.grantee=t.typowner union all " + "select has_table_privilege('pg_monitor',c.oid,x.privilege_type) " + "from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "cross join lateral aclexplode(coalesce(c.relacl,acldefault(" + "case when c.relkind='S' then 'S'::\"char\" else 'r'::\"char\" end,c.relowner))) x " + "where n.nspname='public' and c.relname <> 'alembic_version' " + "and c.relkind in ('r','p','v','m','f') and x.grantee=0 " + "union all select has_sequence_privilege('pg_monitor',c.oid,x.privilege_type) " + "from pg_class c join pg_namespace n on n.oid=c.relnamespace " + "cross join lateral aclexplode(coalesce(c.relacl,acldefault('S',c.relowner))) x " + "where n.nspname='public' and c.relkind='S' and x.grantee=0 " + "union all select has_function_privilege('pg_monitor',p.oid,x.privilege_type) " + "from pg_proc p join pg_namespace n on n.oid=p.pronamespace " + "cross join lateral aclexplode(coalesce(p.proacl,acldefault('f',p.proowner))) x " + "where n.nspname='public' and x.grantee=0 " + "union all select has_type_privilege('pg_monitor',t.oid,x.privilege_type) " + "from pg_type t join pg_namespace n on n.oid=t.typnamespace " + "cross join lateral aclexplode(coalesce(t.typacl,acldefault('T',t.typowner))) x " + "where n.nspname='public' and t.typrelid=0 and t.typcategory <> 'A' " + "and x.grantee=0) select count(*) filter (where not ok) ineffective," + "count(*) total from checks" + ) + return row["ineffective"], row["total"] finally: - command.upgrade(config, "head") + await connection.close() - assert prior == restored - assert prior["columns"] == 0 - assert prior["replay_table"] is False - assert prior["provenance_triggers"] == 0 - assert upgraded == repeated - assert upgraded["columns"] == 4 - assert upgraded["replay_table"] is True - assert upgraded["provenance_triggers"] == 4 - assert dict(upgraded["action_states"]) == { - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_CREATE.value: "active", - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_DERIVE.value: "active", - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_UPDATE.value: "active", - ActionId.PROJECT_SUBMISSION_ARTIFACT_POLICY_APPROVE.value: "planned", - } - assert historical == (f"sha256:{'b' * 64}", None, None, None, None, None) + ineffective, total = asyncio.run(acl_results()) + manifest = json.loads(_manifest_path().read_text()) + assert ineffective == 0 + assert total == len(manifest["acl"]) -def test_submission_policy_authority_pending_replay_blocks_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Even an uncommitted replay reservation is durable authority custody.""" - config = _alembic_config() - ids = { - name: str(uuid4()) for name in ("profile", "link", "project", "guide", "snapshot", "policy") - } - replay_id, operation_id, idempotency_key = uuid4(), uuid4(), uuid4() - bootstrap_grant_id, grant_id = uuid4(), uuid4() - decision_id, null_scope_decision_id = str(uuid4()), str(uuid4()) - digest = f"sha256:{'c' * 64}" +def test_baseline_resources_are_deterministic_and_environment_free() -> None: + baseline = Path(__file__).resolve().parents[1] / "alembic/baseline" + schema = (baseline / "v01_schema.sql").read_text(encoding="utf-8") + references = (baseline / "v01_reference_data.sql").read_text(encoding="utf-8") + combined = schema + references - async def seed_pending() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - constraint_rows = ( - ( - await connection.execute( - text( - "select c.relname as table_name, pg_get_constraintdef(k.oid) as definition " - "from pg_constraint k join pg_class c on c.oid=k.conrelid " - "where k.contype='c' and c.relname in (" - "'submission_artifact_policies'," - "'submission_policy_mutation_idempotency_records'," - "'effective_project_submission_artifact_policies'," - "'pre_submit_checker_policies')" - ) - ) - ) - .mappings() - .all() - ) - definitions = { - table: " ".join( - row["definition"].lower() - for row in constraint_rows - if row["table_name"] == table - ) - for table in ( - "submission_artifact_policies", - "submission_policy_mutation_idempotency_records", - "effective_project_submission_artifact_policies", - "pre_submit_checker_policies", - ) - } - submission_definition = definitions["submission_artifact_policies"] - for fragment in ( - "creation_scope_type is not null", - "creation_scope_project_id is not null", - "creation_action_id is not null", - "approval_scope_type is not null", - "approval_scope_project_id is not null", - "approval_action_id is not null", - "created_by_service_identity is not null", - ): - assert fragment in submission_definition - assert ( - "service_identity is not null" - in definitions["submission_policy_mutation_idempotency_records"] - ) - for table in ( - "effective_project_submission_artifact_policies", - "pre_submit_checker_policies", - ): - for fragment in ( - "creation_scope_type is not null", - "creation_scope_project_id is not null", - "creation_action_id is not null", - ): - assert fragment in definitions[table] - await insert_historical_project( - connection, - project_id=ids["project"], - name="0057 pending replay", - slug=f"submission-replay-{ids['project']}", - ) - await connection.execute( - text( - "insert into actor_profiles(id,actor_kind,status,provisioning_method," - "created_by) values(:profile,'human','active','automatic_first_access'," - ":profile)" - ), - ids, - ) - await connection.execute( - text( - "insert into admin_role_grants(" - "id,target_actor_profile_id,role,scope_type,status,version," - "granted_by_system_principal,grant_reason) values(" - ":bootstrap_grant,:profile,'access_administrator','system','active',1," - "'workstream:system:bootstrap','0057 custody proof')" - ), - {**ids, "bootstrap_grant": bootstrap_grant_id}, - ) - await connection.execute( - text( - "update authority_control set bootstrap_completed=true," - "bootstrap_grant_id=:bootstrap_grant,version=1 where id=1" - ), - {"bootstrap_grant": bootstrap_grant_id}, - ) - await connection.execute( - text( - "insert into admin_role_grants(" - "id,target_actor_profile_id,role,scope_type,scope_project_id,status," - "version,granted_by_actor_profile_id,granted_by_admin_role_grant_id," - "grant_reason) values(:grant,:profile,'project_manager','project'," - ":project,'active',1,:profile,:bootstrap_grant,'0057 custody proof')" - ), - { - **ids, - "bootstrap_grant": bootstrap_grant_id, - "grant": grant_id, - }, - ) - await connection.execute( - text( - "insert into actor_identity_links(id,actor_profile_id,issuer,subject," - "subject_kind,status,linked_by,last_verified_at) values(:link,:profile," - "'https://identity.test',:profile,'human','active',:profile," - "clock_timestamp())" - ), - ids, - ) - for table, trigger in ( - ("project_guides", "guide_mutation_product_custody"), - ("guide_source_snapshots", "source_snapshot_product_custody"), - ): - await connection.execute(text(f"alter table {table} disable trigger {trigger}")) - await connection.execute( - text( - "insert into project_guides(id,project_id,version,status,content_markdown," - "created_by) values(:guide,:project,'v1','draft','# guide','migration-test')" - ), - ids, - ) - await connection.execute( - text( - "insert into guide_source_snapshots(id,project_id,guide_id,guide_version," - "manifest_schema_version,manifest_json,bundle_hash,captured_by) values(" - ":snapshot,:project,:guide,'v1','1','{}'::json,:digest,'migration-test')" - ), - {**ids, "digest": digest}, - ) - for table, trigger in ( - ("project_guides", "guide_mutation_product_custody"), - ("guide_source_snapshots", "source_snapshot_product_custody"), - ): - await connection.execute(text(f"alter table {table} enable trigger {trigger}")) - await connection.execute( - text( - "insert into submission_policy_mutation_idempotency_records(" - "id,actor_profile_id,identity_link_id,action_id,idempotency_key," - "request_digest,resource_context_digest,resource_context_json," - "operation_id,project_id,guide_id,source_snapshot_id,policy_id," - "setup_generation,status) values(:id,:profile,:link," - "'project.submission_artifact_policy.create',:key,:digest,:digest," - '\'{"guide_version":"v1"}\'::json,:operation,:project,:guide,' - ":snapshot,:policy,1,'pending')" - ), - { - **ids, - "id": replay_id, - "key": idempotency_key, - "operation": operation_id, - "digest": digest, - }, - ) - for scope_type, scope_project, action_id, grant, service in ( - ( - "project", - None, - "project.submission_artifact_policy.create", - grant_id, - None, - ), - ( - None, - ids["project"], - "project.submission_artifact_policy.create", - grant_id, - None, - ), - ("project", ids["project"], None, grant_id, None), - ( - "service", - ids["project"], - "project.submission_artifact_policy.derive", - None, - None, - ), - ): - with pytest.raises( - IntegrityError, - match="ck_submission_artifact_policies_ck_submission_policy_cr", - ): - async with connection.begin_nested(): - await connection.execute( - text( - "insert into audit_events(" - "id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id," - "matched_grant_id,permission_id,action_id,reason,denial_code," - "project_id,resource_type,resource_id,after_facts) values(" - ":decision,'authorization_decision',:decision," - "'SensitiveAuthorizationAllowed',:profile,'[]'::json,'{}'::json," - "'local_authority',false,'{}'::json,'authority',1,'actor_profile'," - ":request,:correlation,:grant_text," - "'project.effective_policy.manage'," - "'project.submission_artifact_policy.create'," - "'authorization_evaluation',null,:project," - "'project_submission_artifact_policy_mutation',:policy," - "cast(:after_facts as json))" - ), - { - **ids, - "decision": null_scope_decision_id, - "request": str(uuid4()), - "correlation": str(uuid4()), - "grant_text": str(grant_id), - "after_facts": json.dumps( - {"allowed": True, "resource_context_digest": digest} - ), - }, - ) - await connection.execute( - text( - "insert into submission_artifact_policies(" - "id,project_id,guide_id,guide_version,source_snapshot_id," - "source_snapshot_hash,policy_version,lifecycle_status,policy_body," - "policy_hash,derivation_source,source_material_refs,created_by," - "created_by_actor_profile_id,created_via_identity_link_id," - "created_by_admin_role_grant_id,created_by_service_identity," - "creation_scope_type," - "creation_scope_project_id,creation_action_id," - "creation_decision_event_id) values(:policy,:project,:guide,'v1'," - ":snapshot,:digest,'v1','draft','{}'::json,:digest,'test'," - "'[]'::json,'test',:profile,:link,:grant,:service,:scope_type," - ":scope_project,:action_id,:decision)" - ), - { - **ids, - "grant": grant, - "service": service, - "decision": null_scope_decision_id, - "digest": digest, - "scope_type": scope_type, - "scope_project": scope_project, - "action_id": action_id, - }, - ) - with pytest.raises(IntegrityError): - async with connection.begin_nested(): - await connection.execute( - text( - "insert into submission_policy_mutation_idempotency_records(" - "id,actor_profile_id,identity_link_id,service_identity,action_id," - "idempotency_key,request_digest,resource_context_digest," - "resource_context_json,operation_id,project_id,guide_id," - "source_snapshot_id,policy_id,setup_generation,status) values(" - ":id,null,null,null,'project.submission_artifact_policy.derive'," - 'null,:digest,:digest,\'{"guide_version":"v1"}\'::json,' - ":operation,:project,:guide,:snapshot,:policy,1,'pending')" - ), - { - **ids, - "id": uuid4(), - "operation": uuid4(), - "digest": digest, - }, - ) - with pytest.raises(IntegrityError): - async with connection.begin_nested(): - await connection.execute( - text( - "insert into submission_policy_mutation_idempotency_records(" - "id,actor_profile_id,identity_link_id,action_id,idempotency_key," - "request_digest,resource_context_digest,resource_context_json," - "operation_id,project_id,guide_id,source_snapshot_id,policy_id," - "setup_generation,status) values(:id,:profile,:link," - "'project.submission_artifact_policy.update',:key,:digest,:digest," - '\'{"guide_version":"v1"}\'::json,:operation,:project,' - ":guide,:snapshot,:policy,1,'pending')" - ), - { - **ids, - "id": uuid4(), - "key": idempotency_key, - "operation": uuid4(), - "digest": digest, - }, - ) - with pytest.raises(DBAPIError, match="invalid submission-policy replay mutation"): - async with connection.begin_nested(): - await connection.execute( - text( - "update submission_policy_mutation_idempotency_records " - "set setup_generation=2 where id=:id" - ), - {"id": replay_id}, - ) - with pytest.raises(DBAPIError, match="invalid submission-policy replay mutation"): - async with connection.begin_nested(): - await connection.execute( - text( - "update submission_policy_mutation_idempotency_records set " - 'resource_context_json=\'{"guide_version": "v1"}\'::json ' - "where id=:id" - ), - {"id": replay_id}, - ) - with pytest.raises(DBAPIError, match="cannot be deleted"): - async with connection.begin_nested(): - await connection.execute( - text( - "delete from submission_policy_mutation_idempotency_records " - "where id=:id" - ), - {"id": replay_id}, - ) - await connection.execute( - text("set constraints submission_policy_replay_custody immediate") - ) - with pytest.raises(DBAPIError, match="cannot be truncated"): - async with connection.begin_nested(): - await connection.execute( - text("truncate submission_policy_mutation_idempotency_records") - ) - await connection.execute( - text("set constraints submission_policy_replay_custody deferred") - ) - with pytest.raises( - DBAPIError, match="submission-policy creation evidence mismatch" - ): - async with connection.begin_nested(): - await connection.execute( - text( - "insert into audit_events(" - "id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id," - "matched_grant_id,permission_id,action_id,reason,denial_code," - "project_id,resource_type,resource_id,after_facts) values(" - ":decision,'authorization_decision',:decision," - "'SensitiveAuthorizationAllowed',:profile,'[]'::json,'{}'::json," - "'local_authority',false,'{}'::json,'authority',1,'actor_profile'," - ":request,:correlation,:grant_text," - "'project.effective_policy.manage'," - "'project.submission_artifact_policy.create'," - "'authorization_evaluation',null,:project," - "'project_submission_artifact_policy_mutation',:policy," - "cast(:after_facts as json))" - ), - { - **ids, - "decision": decision_id, - "request": str(uuid4()), - "correlation": str(uuid4()), - "grant_text": str(grant_id), - "after_facts": json.dumps( - {"allowed": True, "resource_context_digest": digest} - ), - }, - ) - await connection.execute( - text( - "insert into submission_artifact_policies(" - "id,project_id,guide_id,guide_version,source_snapshot_id," - "source_snapshot_hash,policy_version,lifecycle_status,policy_body," - "policy_hash,derivation_source,source_material_refs,created_by," - "created_by_actor_profile_id,created_via_identity_link_id," - "created_by_admin_role_grant_id,creation_scope_type," - "creation_scope_project_id,creation_action_id," - "creation_decision_event_id) values(:policy,:project,:guide,'v1'," - ":snapshot,:digest,'v1','draft','{}'::json,:digest,'test'," - "'[]'::json,'test',:profile,:link,:grant,'project',:project," - "'project.submission_artifact_policy.create',:decision)" - ), - { - **ids, - "grant": grant_id, - "decision": decision_id, - "digest": digest, - }, - ) - await connection.execute( - text( - "update submission_policy_mutation_idempotency_records set " - "status='committed',response_json='{}'::json," - "committed_policy_id=:policy,committed_at=now() where id=:id" - ), - {**ids, "id": replay_id}, - ) - await connection.execute( - text("set constraints submission_policy_creation_custody immediate") - ) - finally: - await engine.dispose() + prohibited = ( + "ALTER OWNER", + "SESSION AUTHORIZATION", + "CREATE DATABASE", + "\\connect", + "SET ROLE", + "workstream_baseline_source", + "workstream_baseline_target", + ) + assert not any(token in combined for token in prohibited) + assert "CREATE TABLE public.alembic_version" not in schema + assert "$workstream_baseline_batch$" not in combined + assert "CREATE TRIGGER" in schema + assert "INSERT INTO public.iso_4217_currency_codes" in references - async def reset_schema() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text("drop schema public cascade")) - await connection.execute(text("create schema public")) - finally: - await engine.dispose() - with migration_lock(): - try: - command.upgrade(config, HEAD_REVISION) - asyncio.run(seed_pending()) - with pytest.raises( - RuntimeError, - match="cannot downgrade submission-policy authority with evidence", - ): - command.downgrade(config, "0056_review_lease_preference") - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - finally: - asyncio.run(reset_schema()) - command.upgrade(config, "head") +def test_baseline_sql_splitter_preserves_function_bodies() -> None: + source = "CREATE FUNCTION f() RETURNS void AS $$ BEGIN PERFORM ';'; END $$ LANGUAGE plpgsql; SELECT 'a;''b';" + assert split_sql_statements(source) == ( + "CREATE FUNCTION f() RETURNS void AS $$ BEGIN PERFORM ';'; END $$ LANGUAGE plpgsql", + "SELECT 'a;''b'", + ) + with pytest.raises(ValueError, match="unterminated"): + split_sql_statements("SELECT $$broken") -def test_submission_policy_authority_audit_evidence_blocks_downgrade( +def test_unknown_old_stamp_refuses_before_mutation( isolated_database_env: str, migration_lock, ) -> None: - """Exact submission-policy AUTH evidence independently prevents vocabulary loss.""" config = _alembic_config() - event_id, policy_id, project_id = str(uuid4()), str(uuid4()), str(uuid4()) - - async def seed_evidence() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into audit_events(" - "id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version," - "actor_ref_kind,request_id,correlation_id,permission_id,action_id,reason," - "denial_code,project_id,resource_type,resource_id,after_facts) values(" - ":id,'authorization_decision',:id,'SensitiveAuthorizationDenied'," - "'workstream:system:bootstrap','[]'::json,'{}'::json,'local_authority'," - "false,'{}'::json,'authority',1,'system_principal',:request,:correlation," - "'project.effective_policy.manage'," - "'project.submission_artifact_policy.create'," - "'authorization_evaluation','permission_not_granted',:project," - "'project_submission_artifact_policy_mutation',:policy," - "'{\"allowed\": false}'::json)" - ), - { - "id": event_id, - "request": str(uuid4()), - "correlation": str(uuid4()), - "project": project_id, - "policy": policy_id, - }, - ) - finally: - await engine.dispose() - - async def reset_schema() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text("drop schema public cascade")) - await connection.execute(text("create schema public")) - finally: - await engine.dispose() - with migration_lock(): - try: - command.upgrade(config, HEAD_REVISION) - asyncio.run(seed_evidence()) - with pytest.raises( - RuntimeError, - match="cannot downgrade submission-policy authority with evidence", - ): - command.downgrade(config, "0056_review_lease_preference") - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - finally: - asyncio.run(reset_schema()) + asyncio.run( + _execute( + isolated_database_env, + "drop schema public cascade; create schema public; " + "create table sentinel(id integer primary key, value text not null); " + "insert into sentinel values (1,'preserve-me'); " + "create table alembic_version(version_num varchar(32) primary key); " + "insert into alembic_version values ('0063_compilation_authority')", + ) + ) + before = asyncio.run(_database_snapshot(isolated_database_env)) + with pytest.raises(RuntimeError, match=RECREATE_GUIDANCE): command.upgrade(config, "head") + after = asyncio.run(_database_snapshot(isolated_database_env)) - -def test_0054_guide_sufficiency_authority_safe_empty_downgrade_and_reupgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Remove and restore 12E only while no authorization evidence exists.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "0049_rev_auth_readiness") - assert asyncio.run(_current_revision(isolated_database_env)) == ( - "0049_rev_auth_readiness" - ) - command.upgrade(config, HEAD_REVISION) - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - finally: - command.upgrade(config, HEAD_REVISION) + assert before == after -def test_0050_replay_is_append_only_and_blocks_populated_downgrade( +def test_root_upgrade_refuses_nonempty_unstamped_schema_before_product_ddl( isolated_database_env: str, migration_lock, ) -> None: - """Prove replay constraint closure, sole completion, and downgrade refusal.""" config = _alembic_config() - ids = { - name: str(uuid4()) - for name in ("profile", "link", "project", "guide", "snapshot", "setup", "report") - } - ids["slug"] = f"replay-{ids['project']}" - replay_id, operation_id, key = uuid4(), uuid4(), uuid4() - digest = f"sha256:{'a' * 64}" - final_digest = f"sha256:{'b' * 64}" - - async def exercise() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await insert_historical_project( - connection, - project_id=ids["project"], - name="0050 replay", - slug=ids["slug"], - ) - custody_triggers = ( - ("project_guides", "guide_mutation_product_custody"), - ("guide_source_snapshots", "source_snapshot_product_custody"), - ("project_setup_runs", "source_setup_run_custody"), - ) - for table, trigger in custody_triggers: - await connection.execute(text(f"alter table {table} disable trigger {trigger}")) - statements = ( - "insert into actor_profiles(id,actor_kind,status,provisioning_method," - "service_identity,created_by) values(:profile,'service','active'," - "'manual_service_provisioning','workstream.project.setup',:profile)", - "insert into actor_identity_links(id,actor_profile_id,issuer,subject," - "subject_kind,status,linked_by) values(:link,:profile,'https://identity.test'," - "'workstream.project.setup','service','active',:profile)", - "insert into project_guides(id,project_id,version,status,content_markdown," - "created_by) values(:guide,:project,'v1','draft','# guide','migration-test')", - "insert into guide_source_snapshots(id,project_id,guide_id,guide_version," - "manifest_schema_version,manifest_json,bundle_hash,captured_by) values(" - ":snapshot,:project,:guide,'v1','1','{}'::json,:digest,'migration-test')", - "insert into project_setup_runs(id,project_id,guide_id,guide_version," - "source_snapshot_id,source_snapshot_hash,setup_generation,status,current_step," - "created_by) values(:setup,:project,:guide,'v1',:snapshot,:digest,1," - "'running_sufficiency_agent','guide_sufficiency','migration-test')", - "insert into guide_sufficiency_reports(id,project_id,guide_id,guide_version," - "source_snapshot_id,source_snapshot_hash,status,findings,summary,created_by) " - "values(:report,:project,:guide,'v1',:snapshot,:digest,'passed','[]'::json," - "'ready','migration-test')", - ) - for statement in statements: - await connection.execute(text(statement), {**ids, "digest": digest}) - for table, trigger in custody_triggers: - await connection.execute(text(f"alter table {table} enable trigger {trigger}")) - values = { - "id": replay_id, - "profile": ids["profile"], - "link": ids["link"], - "key": key, - "request": digest, - "resource": final_digest, - "operation": operation_id, - **ids, - } - await connection.execute( - text( - "insert into guide_sufficiency_mutation_idempotency_records(" - "id,actor_profile_id,identity_link_id,action_id,idempotency_key," - "request_digest,resource_context_digest,operation_id,project_id,guide_id," - "source_snapshot_id,setup_run_id,setup_generation,status) values(" - ":id,:profile,:link,'project.guide_sufficiency.run',:key,:request,:resource," - ":operation,:project,:guide,:snapshot,:setup,1,'pending')" - ), - values, - ) - with pytest.raises(DBAPIError, match="invalid guide sufficiency replay mutation"): - async with connection.begin_nested(): - await connection.execute( - text( - "update guide_sufficiency_mutation_idempotency_records " - "set setup_generation=2 where id=:id" - ), - {"id": replay_id}, - ) - async with engine.begin() as connection: - await connection.execute( - text( - "update guide_sufficiency_mutation_idempotency_records set " - "status='committed',response_json='{}'::json,report_id=:report," - "committed_at=now() where id=:id" - ), - {"id": replay_id, "report": ids["report"]}, - ) - async with engine.begin() as connection: - with pytest.raises(DBAPIError, match="invalid guide sufficiency replay mutation"): - async with connection.begin_nested(): - await connection.execute( - text( - "update guide_sufficiency_mutation_idempotency_records " - "set response_json=cast(:response as json) where id=:id" - ), - {"id": replay_id, "response": json.dumps({"changed": True})}, - ) - with pytest.raises( - DBAPIError, match="guide sufficiency replay rows are append-only" - ): - async with connection.begin_nested(): - await connection.execute( - text("truncate guide_sufficiency_mutation_idempotency_records") - ) - finally: - await engine.dispose() - - async def clear_replay() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "alter table guide_sufficiency_mutation_idempotency_records " - "disable trigger trg_sufficiency_replay_immutable" - ) - ) - await connection.execute( - text( - "alter table guide_sufficiency_mutation_idempotency_records " - "disable trigger trg_sufficiency_replay_no_truncate" - ) - ) - await connection.execute( - text("truncate guide_sufficiency_mutation_idempotency_records") - ) - await connection.execute( - text( - "alter table guide_sufficiency_mutation_idempotency_records " - "enable trigger trg_sufficiency_replay_immutable" - ) - ) - await connection.execute( - text( - "alter table guide_sufficiency_mutation_idempotency_records " - "enable trigger trg_sufficiency_replay_no_truncate" - ) - ) - finally: - await engine.dispose() - - async def install_provenance_only() -> None: - decision_id = str(uuid4()) - await _insert_authority_audit_fixture(isolated_database_env, decision_id) - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "update guide_sufficiency_reports set " - "project_setup_run_id=:setup,setup_generation=1," - "agent_material_sha256=:digest,agent_material_byte_count=1," - "created_by_actor_profile_id=:profile,created_via_identity_link_id=:link," - "created_by_service_identity='workstream.project.setup'," - "creation_scope_type='service',creation_scope_project_id=:project," - "creation_action_id='project.guide_sufficiency.run'," - "authorization_decision_event_id=:decision where id=:report" - ), - {"decision": decision_id, "digest": digest, **ids}, - ) - finally: - await engine.dispose() - - async def clear_product_evidence() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text("delete from guide_sufficiency_reports where id=:report"), - {"report": ids["report"]}, - ) - finally: - await engine.dispose() - - with migration_lock(): - try: - asyncio.run(exercise()) - with pytest.raises( - RuntimeError, - match="cannot downgrade guide sufficiency authority with evidence", - ): - command.downgrade(config, "0049_rev_auth_readiness") - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - asyncio.run(clear_replay()) - asyncio.run(install_provenance_only()) - with pytest.raises( - RuntimeError, - match="cannot downgrade guide sufficiency authority with evidence", - ): - command.downgrade(config, "0049_rev_auth_readiness") - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - finally: - asyncio.run(clear_replay()) - asyncio.run(clear_product_evidence()) - command.upgrade(config, HEAD_REVISION) - - -def _alembic_config() -> Config: - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - return config - - -async def _review_queue_foundation_state(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - revision = await connection.scalar(text("select version_num from alembic_version")) - queue_count = await connection.scalar(text("select count(*) from review_queue_entries")) - admission_count = await connection.scalar( - text("select count(*) from review_admission_idempotency_records") - ) - triggers = set( - ( - await connection.execute( - text( - "select tgname from pg_trigger where tgrelid in " - "('review_queue_entries'::regclass, " - "'review_admission_idempotency_records'::regclass) " - "and not tgisinternal" - ) - ) - ).scalars() - ) - return { - "revision": str(revision), - "queue_count": int(queue_count or 0), - "admission_count": int(admission_count or 0), - "queue_guard": "review_queue_entries_guard" in triggers, - "admission_guard": "review_admission_records_guard" in triggers, - "queue_truncate_guard": "review_queue_entries_reject_truncate" in triggers, - "admission_truncate_guard": ( - "review_admission_idempotency_records_reject_truncate" in triggers - ), - } - finally: - await engine.dispose() - - -async def _review_lease_preference_state(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - revision = await connection.scalar(text("select version_num from alembic_version")) - lease_count = await connection.scalar(text("select count(*) from review_leases")) - queue_columns = set( - ( - await connection.scalars( - text( - "select column_name from information_schema.columns " - "where table_schema=current_schema() " - "and table_name='review_queue_entries'" - ) - ) - ).all() - ) - triggers = set( - ( - await connection.scalars( - text( - "select tgname from pg_trigger where tgrelid in " - "('review_queue_entries'::regclass,'review_leases'::regclass) " - "and not tgisinternal" - ) - ) - ).all() - ) - return { - "revision": str(revision), - "lease_count": int(lease_count or 0), - "active_lease_column": "active_lease_id" in queue_columns, - "lease_guard": "review_leases_guard" in triggers, - "queue_graph_guard": "review_queue_entries_active_lease_guard" in triggers, - "lease_graph_guard": "review_leases_active_lease_guard" in triggers, - "truncate_guard": "review_leases_reject_truncate" in triggers, - } - finally: - await engine.dispose() - - -def test_service_identity_migration_contract_is_frozen_from_application_modules() -> None: - backend_root = Path(__file__).resolve().parents[1] - revision_source = (backend_root / "alembic/versions/0023_service_actor_identity.py").read_text( - encoding="utf-8" - ) - contract_source = (backend_root / "migration_contracts/service_identity_0023.py").read_text( - encoding="utf-8" - ) - assert "from migration_contracts.service_identity_0023 import" in revision_source - assert "app.modules" not in revision_source - assert "app.modules" not in contract_source - assert "repository_root=MIGRATION_REPOSITORY_ROOT" in revision_source - assert "REPOSITORY_ROOT" not in contract_source - assert FROZEN_SERVICE_IDENTITY_VALUES == ( - "workstream.artifact.verifier", - "workstream.artifact.put_resolver", - "workstream.artifact.scheduler", - "workstream.artifact.binding", - "workstream.artifact.guide_reader", - "workstream.artifact.materializer", - "workstream.artifact.checker_output", - ) - assert tuple(identity.value for identity in ServiceIdentity) == ( - *FROZEN_SERVICE_IDENTITY_VALUES, - "workstream.project.setup", - "workstream.review.preference_expiry", - "workstream.review.lease_expiry", - "workstream.review.authority_invalidation_reconciliation", - "workstream.review.reconciliation", - "workstream.review.artifact_reference_reconciliation", - "workstream.review.projection", - ) - - -def test_frozen_mapping_path_custody_is_independent_of_install_location( - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, -) -> None: - repository_root = Path(__file__).resolve().parents[2] - monkeypatch.setattr( - frozen_service_identity_contract, - "__file__", - "/installed/site-packages/migration_contracts/service_identity_0023.py", - ) - roots = frozen_protected_mapping_roots(repository_root) - assert repository_root in roots - for root in roots: - with pytest.raises( - FrozenServiceIdentityMappingError, - match="service_mapping_path_forbidden", - ): - validate_frozen_mapping_path( - root / "private-envelope.json", - repository_root=repository_root, - output=True, - ) - - deployment_root = tmp_path / "deployed" - private_root = tmp_path / "private" - deployment_root.mkdir() - private_root.mkdir() - assert ( - validate_frozen_mapping_path( - private_root / "private-envelope.json", - repository_root=deployment_root, - output=True, + asyncio.run( + _execute( + isolated_database_env, + "drop schema public cascade; create schema public; create table sentinel(id integer)", ) - == private_root / "private-envelope.json" ) - -def test_alembic_upgrade_and_downgrade(isolated_database_env: str, migration_lock) -> None: - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - with migration_lock(): - command.downgrade(config, "base") + with migration_lock(), pytest.raises(RuntimeError, match=RECREATE_GUIDANCE): command.upgrade(config, "head") - constraint_names = asyncio.run( - _project_setup_run_check_constraint_names(isolated_database_env) - ) - assert "ck_project_setup_runs_ck_project_setup_runs_status" in constraint_names - command.downgrade(config, "base") - - -def test_0051_legacy_intake_safe_empty_round_trip( - isolated_database_env: str, migration_lock -) -> None: - """The clean cut removes the namespace and recreates only an empty legacy shape.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0050_guide_source_v2") - legacy = asyncio.run(_legacy_intake_shape(isolated_database_env)) - assert legacy["revision"] == "0050_guide_source_v2" - assert legacy["tables"] == (True, True) - assert legacy["upload_columns"] == (True, True) - - command.upgrade(config, HEAD_REVISION) - removed = asyncio.run(_legacy_intake_shape(isolated_database_env)) - assert removed["revision"] == HEAD_REVISION - assert removed["tables"] == (False, False) - assert removed["upload_columns"] == (False, False) - assert removed["contributor_constraints"] == () - command.downgrade(config, "0050_guide_source_v2") - restored = asyncio.run(_legacy_intake_shape(isolated_database_env)) - assert restored == legacy - command.upgrade(config, HEAD_REVISION) - finally: - command.downgrade(config, "base") + snapshot = asyncio.run(_database_snapshot(isolated_database_env)) + assert snapshot["versions"] == [] + assert ("r", "sentinel") in snapshot["objects"] + assert ("r", "projects") not in snapshot["objects"] -@pytest.mark.parametrize( - "blocker", - ( - "upload_session", - "upload_item", - "contributor_attempt", - "attempt_upload_item", - "v1_receipt", - "receipt_upload_item", - ), -) -def test_0051_legacy_intake_refuses_each_populated_condition_atomically( - isolated_database_env: str, migration_lock, blocker: str +def test_root_downgrade_refuses_without_mutation( + isolated_database_env: str, + migration_lock, ) -> None: - """Every historical row class preserves the entire predecessor schema on refusal.""" config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0050_guide_source_v2") - asyncio.run(_seed_0051_legacy_blocker(isolated_database_env, blocker)) - before = asyncio.run(_legacy_intake_shape(isolated_database_env)) - with pytest.raises( - RuntimeError, match="legacy contributor artifact intake is populated" - ): - command.upgrade(config, HEAD_REVISION) - assert asyncio.run(_legacy_intake_shape(isolated_database_env)) == before - finally: - asyncio.run(_reset_0051_test_schema(isolated_database_env)) - - -async def _reset_0051_test_schema(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("drop schema public cascade")) - await connection.execute(text("create schema public")) - finally: - await engine.dispose() + before = asyncio.run(_database_snapshot(isolated_database_env)) + with migration_lock(), pytest.raises(RuntimeError, match="cannot be downgraded"): + command.downgrade(config, "base") + after = asyncio.run(_database_snapshot(isolated_database_env)) + assert before == after -async def _legacy_intake_shape(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - has_legacy_tables = bool( - await connection.scalar( - text("select to_regclass('artifact_upload_sessions') is not null") - ) - ) - physical_schema = tuple( - tuple(row) - for row in ( - await connection.execute( - text( - "select 'column',table_name,column_name,data_type,udt_name," - "is_nullable,coalesce(column_default,'')," - "coalesce(character_maximum_length::text,'') " - "from information_schema.columns where table_schema='public' and " - "table_name in ('artifact_upload_sessions','artifact_upload_items'," - "'artifact_put_attempts','artifact_operation_receipts') union all " - "select 'constraint',c.relname,q.conname,q.contype::text," - "pg_get_constraintdef(q.oid,true),'','','' from pg_constraint q " - "join pg_class c on c.oid=q.conrelid join pg_namespace n " - "on n.oid=c.relnamespace where n.nspname='public' and c.relname in " - "('artifact_upload_sessions','artifact_upload_items'," - "'artifact_put_attempts','artifact_operation_receipts') union all " - "select 'index',tablename,indexname,indexdef,'','','','' " - "from pg_indexes where schemaname='public' and tablename in " - "('artifact_upload_sessions','artifact_upload_items'," - "'artifact_put_attempts','artifact_operation_receipts') " - "order by 1,2,3,4" - ) - ) - ).all() - ) - constraints = tuple( - await connection.scalars( - text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='artifact_put_attempts'::regclass and contype='c' " - "and pg_get_constraintdef(oid) ilike '%contributor%' order by conname" - ) - ) +def test_seeded_sequences_advance_past_singleton_rows(isolated_database_env: str) -> None: + async def read_next_values() -> tuple[int, int]: + connection = await asyncpg.connect(isolated_database_env.replace("+asyncpg", "")) + try: + return ( + await connection.fetchval("select nextval('actor_profile_migration_state_id_seq')"), + await connection.fetchval("select nextval('authority_control_id_seq')"), ) - return { - "revision": str( - await connection.scalar(text("select version_num from alembic_version")) - ), - "tables": ( - bool( - await connection.scalar( - text("select to_regclass('artifact_upload_sessions') is not null") - ) - ), - bool( - await connection.scalar( - text("select to_regclass('artifact_upload_items') is not null") - ) - ), - ), - "upload_columns": ( - bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns where table_name='artifact_put_attempts' and column_name='upload_item_id')" - ) - ) - ), - bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns where table_name='artifact_operation_receipts' and column_name='upload_item_id')" - ) - ) - ), - ), - "contributor_constraints": constraints, - "physical_schema": physical_schema, - "legacy_rows": tuple( - tuple(row) - for row in ( - await connection.execute( - text( - "select 'session',id,state from artifact_upload_sessions " - "union all select 'item',id,state from artifact_upload_items " - "union all select 'attempt',id,producer_request_type " - "from artifact_put_attempts union all " - "select 'receipt',id,contract_version::text " - "from artifact_operation_receipts order by 1,2" - ) - ) - ).all() - ) - if has_legacy_tables - else (), - "row_counts": tuple( - ( - await connection.execute( - text( - "select (select count(*) from artifact_put_attempts)," - "(select count(*) from artifact_operation_receipts)," - "(select count(*) from artifact_upload_sessions)," - "(select count(*) from artifact_upload_items)" - ) - ) - ).one() - ) - if has_legacy_tables - else (), - } - finally: - await engine.dispose() - + finally: + await connection.close() -async def _seed_0051_legacy_blocker(database_url: str, blocker: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - table = { - "upload_session": "artifact_upload_sessions", - "upload_item": "artifact_upload_items", - "contributor_attempt": "artifact_put_attempts", - "attempt_upload_item": "artifact_put_attempts", - "v1_receipt": "artifact_operation_receipts", - "receipt_upload_item": "artifact_operation_receipts", - }[blocker] - constraint_names = tuple( - await connection.scalars( - text( - "select conname from pg_constraint where conrelid=cast(:table as regclass) " - "and contype in ('c','f') order by conname" - ), - {"table": table}, - ) - ) - for name in constraint_names: - await connection.execute(text(f'alter table {table} drop constraint "{name}"')) - identifier = str(uuid4()) - if blocker == "upload_session": - await connection.execute( - text( - "insert into artifact_upload_sessions (id,actor_id,project_id,permitted_roles,state,maximum_bytes,current_bytes,reserved_bytes,maximum_items,current_items,reserved_items,expires_at,cas_version) values (:id,'actor','project','[]'::json,'open',1,0,0,1,0,0,now(),0)" - ), - {"id": identifier}, - ) - elif blocker == "upload_item": - await connection.execute( - text( - "insert into artifact_upload_items (id,session_id,logical_role,display_name,reserved_bytes,idempotency_key,request_digest,state,cas_version) values (:id,'session','result','result.zip',1,'key',:digest,'reserved',0)" - ), - {"id": identifier, "digest": "sha256:" + "1" * 64}, - ) - elif blocker in {"contributor_attempt", "attempt_upload_item"}: - await connection.execute( - text( - "insert into artifact_put_attempts (id,producer_request_type,producer_type,producer_ref,project_id,task_id,upload_item_id,sha256,byte_count,media_type,storage_namespace_id,namespace_fingerprint,canonical_target,operation_identity,request_digest,status,execution_generation,observation_count,maximum_observations,cas_version) values (:id,:request_type,'actor_profile',:actor,'project',:task,:item,:digest,1,'application/zip','primary',:digest,'sha256/11/' || repeat('1',62),:digest,:digest,'prepared',0,0,5,0)" - ), - { - "id": identifier, - "request_type": "contributor" - if blocker == "contributor_attempt" - else "guide", - "actor": str(uuid4()), - "task": "task" if blocker == "contributor_attempt" else None, - "item": None if blocker == "contributor_attempt" else "item", - "digest": "sha256:" + "1" * 64, - }, - ) - else: - await connection.execute( - text( - "insert into artifact_operation_receipts (id,contract_version,put_attempt_id,upload_item_id,replica_id,operation,idempotency_key,request_digest,provider_object_ref,replayed,outcome,attempt_number,correlation_id,details) values (:id,:version,:attempt,:item,'replica','put','key',:digest,'object',false,'stored_pending_verification',1,'correlation','[]'::json)" - ), - { - "id": identifier, - "version": 1 if blocker == "v1_receipt" else 2, - "attempt": None if blocker == "v1_receipt" else "attempt", - "item": "item", - "digest": "sha256:" + "1" * 64, - }, - ) - finally: - await engine.dispose() - - -async def _project_setup_run_check_constraint_names(database_url: str) -> set[str]: - """Return physical check-constraint names for the setup-run table.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - rows = await connection.scalars( - text( - "select constraint_name from information_schema.table_constraints " - "where table_schema = current_schema() " - "and table_name = 'project_setup_runs' " - "and constraint_type = 'CHECK'" - ) - ) - return set(rows.all()) - finally: - await engine.dispose() - - -def test_0051_review_queue_foundation_empty_round_trip( - isolated_database_env: str, - migration_lock, -) -> None: - """0051 creates no queue history and reverses only while still unused.""" - config = _alembic_config() - with migration_lock(): - command.downgrade(config, "0050_guide_source_v2") - command.upgrade(config, "0051_review_queue_foundation") - state = asyncio.run(_review_queue_foundation_state(isolated_database_env)) - assert state == { - "revision": "0051_review_queue_foundation", - "queue_count": 0, - "admission_count": 0, - "queue_guard": True, - "admission_guard": True, - "queue_truncate_guard": True, - "admission_truncate_guard": True, - } - command.downgrade(config, "0050_guide_source_v2") - command.upgrade(config, "head") - - -def test_0056_review_lease_preference_empty_round_trip( - isolated_database_env: str, - migration_lock, -) -> None: - """0056 installs no attempts and reverses exactly while unused.""" - config = _alembic_config() - with migration_lock(): - command.downgrade(config, "0055_contribution_policy") - command.upgrade(config, "0056_review_lease_preference") - assert asyncio.run(_review_lease_preference_state(isolated_database_env)) == { - "revision": "0056_review_lease_preference", - "lease_count": 0, - "active_lease_column": True, - "lease_guard": True, - "queue_graph_guard": True, - "lease_graph_guard": True, - "truncate_guard": True, - } - command.downgrade(config, "0055_contribution_policy") - command.upgrade(config, "head") - - -def test_0034_project_role_issue_evidence_exact_safe_round_trip( - isolated_database_env: str, - migration_lock, -) -> None: - """0034 changes only its frozen functions and privacy registry, reversibly.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0033_authorization_read_rate") - asyncio.run(_insert_empty_pending_0034_issue(isolated_database_env)) - predecessor = asyncio.run( - _project_role_issue_evidence_0034_state(isolated_database_env) - ) - - command.upgrade(config, "0034_project_role_issue_evidence") - forward = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - assert forward["revision"] == "0034_project_role_issue_evidence" - assert forward["rows"] == predecessor["rows"] == (1, 0) - assert forward["triggers"] == predecessor["triggers"] - assert forward["fact_constraint"] == predecessor["fact_constraint"] - assert forward["privacy_constraint"] != predecessor["privacy_constraint"] - assert forward["functions"] != predecessor["functions"] - - command.downgrade(config, "0033_authorization_read_rate") - restored = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - assert restored == predecessor - - command.upgrade(config, "0034_project_role_issue_evidence") - assert ( - asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - == forward - ) - finally: - asyncio.run(_clear_pending_0034_issues(isolated_database_env)) - command.downgrade(config, "base") - - -@pytest.mark.parametrize("drift", ["changed", "missing", "unvalidated", "wrong_table"]) -def test_0034_project_role_issue_evidence_refuses_fact_constraint_drift( - isolated_database_env: str, - migration_lock, - drift: str, -) -> None: - """A detached or changed fact gate cannot be silently accepted by 0034.""" - config = _alembic_config() - definition = None - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0033_authorization_read_rate") - before = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - definition = before["fact_constraint"][2] - asyncio.run(_replace_0034_fact_constraint_with_drift(isolated_database_env, drift)) - drifted = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - with pytest.raises(RuntimeError, match="unexpected authority fact constraint"): - command.upgrade(config, "0034_project_role_issue_evidence") - refused = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - assert refused == drifted - assert refused["revision"] == before["revision"] - assert refused["functions"] == before["functions"] - assert refused["triggers"] == before["triggers"] - assert refused["privacy_constraint"] == before["privacy_constraint"] - assert refused["rows"] == before["rows"] - finally: - asyncio.run(_restore_0034_fact_constraint(isolated_database_env, definition)) - command.downgrade(config, "base") - - -def test_0034_project_role_issue_evidence_fact_shape_is_closed( - isolated_database_env: str, - migration_lock, -) -> None: - """The richer revoke projection is exact and preserves legacy two-key facts.""" - config = _alembic_config() - project_id = str(uuid4()) - mappings = { - "submitter": "auth13_assignment", - "reviewer": "rev_reviewer_obligation", - "adjudicator": "none", - } - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - for role, obligation in mappings.items(): - before = { - "effective": True, - "role": role, - "scope_type": "project", - "scope_id": project_id, - "future_obligation": obligation, - } - after = {**before, "effective": False} - mismatched_role = "reviewer" if role != "reviewer" else "submitter" - assert asyncio.run( - _facts_are_safe_0034(isolated_database_env, before, after, project_id) - ) - invalid = ( - ({key: value for key, value in before.items() if key != "role"}, after), - ({**before, "extra": "no"}, {**after, "extra": "no"}), - ({**before, "effective": "true"}, after), - ({**before, "scope_id": str(uuid4())}, after), - ({**before, "future_obligation": "wrong"}, after), - (before, {**after, "role": mismatched_role}), - ) - for invalid_before, invalid_after in invalid: - assert ( - asyncio.run( - _facts_are_safe_0034( - isolated_database_env, - invalid_before, - invalid_after, - project_id, - ) - ) - is False - ) - for null_before, null_after in ((None, after), (before, None)): - assert ( - asyncio.run( - _facts_are_safe_0034( - isolated_database_env, - null_before, - null_after, - project_id, - ) - ) - is False - ) - assert asyncio.run( - _facts_are_safe_0034( - isolated_database_env, - {"effective": True}, - {"effective": False}, - project_id, - ) - ) - finally: - command.downgrade(config, "base") - - -def test_0034_project_role_issue_evidence_rejects_false_invalidation_at_insert( - isolated_database_env: str, - migration_lock, -) -> None: - """An issue reservation cannot accept an invalidation even before completion.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - fixture = asyncio.run(_seed_pending_issue_cause_0034(isolated_database_env)) - with pytest.raises(IntegrityError) as rejected: - asyncio.run( - _insert_false_issue_invalidation_0034( - isolated_database_env, - fixture, - ) - ) - assert getattr(rejected.value.orig, "sqlstate", None) == "23514" - assert ( - asyncio.run(_count_linked_events_0034(isolated_database_env, fixture["record"])) - == 1 - ) - finally: - asyncio.run(_clear_0034_issue_fixture(isolated_database_env)) - command.downgrade(config, "base") - - -def test_0034_five_key_revoke_invalidation_requires_exact_linkage( - isolated_database_env: str, - migration_lock, -) -> None: - """Five-key obligation facts are admitted only for one linked revoke pair.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - for invalid_form in ( - "non_revoke", - "orphan", - "mixed_facts", - "cross_record", - "null_target_kind", - "null_target_id", - "wrong_target_kind", - "wrong_target_id", - ): - records: list[str] = [] - try: - if invalid_form == "non_revoke": - fixture = asyncio.run(_seed_pending_issue_cause_0034(isolated_database_env)) - records.append(fixture["record"]) - cause = fixture - else: - fixture = asyncio.run( - _seed_pending_revoke_cause_0034(isolated_database_env) - ) - records.append(fixture["record"]) - cause = fixture - if invalid_form == "orphan": - cause = {**fixture, "cause": str(uuid4())} - elif invalid_form == "cross_record": - cause = asyncio.run( - _seed_pending_revoke_cause_0034( - isolated_database_env, - envelope=fixture, - ) - ) - records.append(cause["record"]) - - before_facts = _five_key_revoke_facts_0034(fixture, effective=True) - after_facts = _five_key_revoke_facts_0034(fixture, effective=False) - if invalid_form == "mixed_facts": - after_facts = {"effective": False} - target_ref_kind: str | None = "project_role_grant" - target_ref_id: str | None = cause["grant"] - if invalid_form == "null_target_kind": - target_ref_kind = None - elif invalid_form == "null_target_id": - target_ref_id = None - elif invalid_form == "wrong_target_kind": - target_ref_kind = "actor_profile" - elif invalid_form == "wrong_target_id": - target_ref_id = str(uuid4()) - before = asyncio.run( - _linked_revoke_fixture_state_0034(isolated_database_env, records) - ) - - with pytest.raises(IntegrityError) as rejected: - asyncio.run( - _insert_revoke_invalidation_0034( - isolated_database_env, - fixture, - cause=cause, - before_facts=before_facts, - after_facts=after_facts, - target_ref_kind=target_ref_kind, - target_ref_id=target_ref_id, - ) - ) - expected_sqlstate = "23503" if invalid_form == "orphan" else "23514" - assert getattr(rejected.value.orig, "sqlstate", None) == expected_sqlstate - assert ( - asyncio.run( - _linked_revoke_fixture_state_0034(isolated_database_env, records) - ) - == before - ) - finally: - asyncio.run(_clear_linked_revoke_fixtures_0034(isolated_database_env, records)) - finally: - command.downgrade(config, "base") - - -def test_0034_downgrade_refuses_five_key_revoke_evidence_without_mutation( - isolated_database_env: str, - migration_lock, -) -> None: - """A linked five-key revoke pair remains intact when 0034 refuses downgrade.""" - config = _alembic_config() - records: list[str] = [] - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - fixture = asyncio.run(_seed_pending_revoke_cause_0034(isolated_database_env)) - records.append(fixture["record"]) - before_insert = asyncio.run( - _linked_revoke_fixture_state_0034(isolated_database_env, records) - ) - invalidation_id = asyncio.run( - _insert_revoke_invalidation_0034( - isolated_database_env, - fixture, - cause=fixture, - before_facts=_five_key_revoke_facts_0034(fixture, effective=True), - after_facts=_five_key_revoke_facts_0034(fixture, effective=False), - target_ref_kind="project_role_grant", - target_ref_id=fixture["grant"], - ) - ) - admitted = asyncio.run( - _linked_revoke_fixture_state_0034(isolated_database_env, records) - ) - assert admitted != before_insert - assert admitted["event_ids"] == tuple(sorted((fixture["cause"], invalidation_id))) - assert admitted["event_count"] == 2 - - before_downgrade = { - "migration": asyncio.run( - _project_role_issue_evidence_0034_state(isolated_database_env) - ), - "fixture": admitted, - } - with pytest.raises( - RuntimeError, - match="incompatible project-role issue evidence", - ): - command.downgrade(config, "0033_authorization_read_rate") - after_refusal = { - "migration": asyncio.run( - _project_role_issue_evidence_0034_state(isolated_database_env) - ), - "fixture": asyncio.run( - _linked_revoke_fixture_state_0034(isolated_database_env, records) - ), - } - assert after_refusal == before_downgrade - finally: - asyncio.run(_clear_linked_revoke_fixtures_0034(isolated_database_env, records)) - command.downgrade(config, "base") - - -@pytest.mark.parametrize( - "drift", - [ - "guard_function", - "linked_function", - "facts_function", - "trigger_disabled", - "privacy_constraint", - ], -) -def test_0034_project_role_issue_evidence_refuses_frozen_definition_drift( - isolated_database_env: str, - migration_lock, - drift: str, -) -> None: - """Frozen predecessor function and privacy definitions are mandatory.""" - config = _alembic_config() - definitions = None - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0033_authorization_read_rate") - definitions = asyncio.run( - _project_role_issue_evidence_0034_definitions(isolated_database_env) - ) - before = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - asyncio.run(_install_definition_drift_0034(isolated_database_env, drift)) - drifted = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - if drift in {"guard_function", "linked_function", "facts_function"}: - message = "unexpected predecessor authority evidence definition" - elif drift == "trigger_disabled": - message = "unexpected authority evidence trigger binding" - else: - message = "unexpected authority privacy constraint" - with pytest.raises(RuntimeError, match=message): - command.upgrade(config, "0034_project_role_issue_evidence") - assert ( - asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - == drifted - ) - assert drifted["revision"] == before["revision"] - assert drifted["rows"] == before["rows"] - if drift == "trigger_disabled": - assert drifted["triggers"] != before["triggers"] - else: - assert drifted["triggers"] == before["triggers"] - finally: - if definitions is not None: - asyncio.run( - _restore_project_role_issue_evidence_0034_definitions( - isolated_database_env, - definitions, - ) - ) - assert ( - asyncio.run( - _project_role_issue_evidence_0034_definitions(isolated_database_env) - ) - == definitions - ) - command.downgrade(config, "base") - - -@pytest.mark.parametrize("incompatible", ["response", "linked_event"]) -def test_0034_project_role_issue_evidence_refuses_incompatible_pending_state( - isolated_database_env: str, - migration_lock, - incompatible: str, -) -> None: - """Pending issue state is admitted only with null response and zero evidence.""" - config = _alembic_config() - fixture = None - state_shape_constraint = None - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0033_authorization_read_rate") - if incompatible == "linked_event": - fixture = asyncio.run(_seed_pending_issue_cause_0034(isolated_database_env)) - else: - state_shape_constraint = asyncio.run( - _authority_idempotency_state_shape_0034(isolated_database_env) - ) - assert state_shape_constraint is not None - asyncio.run(_insert_empty_pending_0034_issue(isolated_database_env)) - fixture = None - asyncio.run( - _add_pending_issue_response_0034( - isolated_database_env, - state_shape_constraint, - ) - ) - incompatible_constraint = asyncio.run( - _authority_idempotency_state_shape_0034(isolated_database_env) - ) - assert incompatible_constraint is not None - assert incompatible_constraint[:2] == ( - state_shape_constraint[0], - False, - ) - assert incompatible_constraint[2].removesuffix( - " NOT VALID" - ) == state_shape_constraint[2].removesuffix(" NOT VALID") - before = asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - with pytest.raises(RuntimeError, match="incompatible project-role issue evidence"): - command.upgrade(config, "0034_project_role_issue_evidence") - assert ( - asyncio.run(_project_role_issue_evidence_0034_state(isolated_database_env)) - == before - ) - finally: - if fixture is not None: - asyncio.run(_clear_0034_issue_fixture(isolated_database_env)) - else: - asyncio.run( - _clear_pending_0034_issues( - isolated_database_env, - state_shape_constraint, - ) - ) - if state_shape_constraint is not None: - assert ( - asyncio.run(_authority_idempotency_state_shape_0034(isolated_database_env)) - == state_shape_constraint - ) - command.downgrade(config, "base") - - -async def _project_role_issue_evidence_0034_state(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - function_rows = ( - await connection.execute( - text( - "select proname,pg_get_functiondef(oid) from pg_proc where oid in " - "('guard_authority_idempotency_record'::regproc," - "'validate_linked_authority_event'::regproc," - "'authority_event_facts_are_safe'::regproc) order by proname" - ) - ) - ).all() - constraint_rows = { - row.conname: (row.table_name, row.convalidated, row.definition) - for row in ( - await connection.execute( - text( - "select conname,conrelid::regclass::text table_name,convalidated," - "pg_get_constraintdef(oid) definition from pg_constraint " - "where conname in ('ck_audit_events_fact_bounds'," - "'ck_audit_events_authority_privacy_bounds'," - "'ck_authority_idempotency_records_state_shape')" - ) - ) - ).all() - } - triggers = tuple( - ( - await connection.execute( - text( - "select tgname,pg_get_triggerdef(oid,true),tgenabled from pg_trigger " - "where tgname in ('authority_idempotency_guard'," - "'audit_events_validate_idempotency') order by tgname" - ) - ) - ).all() - ) - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "functions": tuple( - (name, hashlib.sha256(definition.encode()).hexdigest()) - for name, definition in function_rows - ), - "fact_constraint": constraint_rows.get("ck_audit_events_fact_bounds"), - "privacy_constraint": constraint_rows["ck_audit_events_authority_privacy_bounds"], - "idempotency_state_constraint": constraint_rows.get( - "ck_authority_idempotency_records_state_shape" - ), - "triggers": triggers, - "rows": ( - int( - await connection.scalar( - text("select count(*) from authority_idempotency_records") - ) - ), - int(await connection.scalar(text("select count(*) from audit_events"))), - ), - } - finally: - await engine.dispose() - - -async def _install_definition_drift_0034(database_url: str, drift: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - if drift == "guard_function": - await connection.execute( - text( - "create or replace function guard_authority_idempotency_record() " - "returns trigger language plpgsql as $$ begin return new; end $$" - ) - ) - elif drift == "linked_function": - await connection.execute( - text( - "create or replace function validate_linked_authority_event() " - "returns trigger language plpgsql as $$ begin return new; end $$" - ) - ) - elif drift == "facts_function": - await connection.execute( - text( - "create or replace function authority_event_facts_are_safe(" - "event_name text,before_state json,after_state json," - "envelope_project_id text) returns boolean language sql immutable " - "as $$ select true $$" - ) - ) - elif drift == "trigger_disabled": - await connection.execute( - text( - "alter table audit_events disable trigger audit_events_validate_idempotency" - ) - ) - else: - await connection.execute( - text( - "alter table audit_events drop constraint " - "ck_audit_events_authority_privacy_bounds" - ) - ) - await connection.execute( - text( - "alter table audit_events add constraint " - "ck_audit_events_authority_privacy_bounds check (true)" - ) - ) - finally: - await engine.dispose() - - -async def _project_role_issue_evidence_0034_definitions( - database_url: str, -) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - functions = dict( - ( - await connection.execute( - text( - "select proname,pg_get_functiondef(oid) from pg_proc where oid in " - "('guard_authority_idempotency_record'::regproc," - "'validate_linked_authority_event'::regproc," - "'authority_event_facts_are_safe'::regproc)" - ) - ) - ).all() - ) - privacy_row = ( - await connection.execute( - text( - "select conrelid::regclass::text,convalidated," - "pg_get_constraintdef(oid) from pg_constraint where conname=" - "'ck_audit_events_authority_privacy_bounds' and " - "conrelid='audit_events'::regclass" - ) - ) - ).one() - trigger_rows = ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled from pg_trigger " - "where tgname in ('authority_idempotency_guard'," - "'audit_events_validate_idempotency') order by tgname" - ) - ) - ).all() - return { - "functions": functions, - "privacy": tuple(privacy_row), - "triggers": tuple(tuple(row) for row in trigger_rows), - } - finally: - await engine.dispose() - - -async def _restore_project_role_issue_evidence_0034_definitions( - database_url: str, - definitions: dict[str, object], -) -> None: - functions = definitions["functions"] - assert isinstance(functions, dict) - privacy = definitions["privacy"] - assert isinstance(privacy, tuple) - privacy_table, privacy_validated, privacy_definition = privacy - assert privacy_table == "audit_events" - assert isinstance(privacy_validated, bool) - assert isinstance(privacy_definition, str) - triggers = definitions["triggers"] - assert isinstance(triggers, tuple) - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - for definition in functions.values(): - assert isinstance(definition, str) - await connection.exec_driver_sql(definition) - current_privacy = tuple( - ( - await connection.execute( - text( - "select conrelid::regclass::text,convalidated," - "pg_get_constraintdef(oid) from pg_constraint where conname=" - "'ck_audit_events_authority_privacy_bounds' and " - "conrelid='audit_events'::regclass" - ) - ) - ).one() - ) - if current_privacy != privacy: - await _restore_0034_privacy_constraint( - connection, - privacy_definition, - privacy_validated, - ) - await _restore_0034_trigger_states(connection, triggers) - finally: - await engine.dispose() - - -async def _restore_0034_privacy_constraint( - connection, - predecessor_definition: str, - validated: bool, -) -> None: - resource_markers = ( - ( - "'project'::character varying, 'project_role_grant'::character varying", - "'project'::character varying, 'qualification_snapshot'::character varying, " - "'project_role_grant'::character varying", - ), - ( - "('project'::character varying)::text, ('project_role_grant'::character varying)::text", - "('project'::character varying)::text, " - "('qualification_snapshot'::character varying)::text, " - "('project_role_grant'::character varying)::text", - ), - ) - predecessor_definition = predecessor_definition.removesuffix(" NOT VALID") - matches = [ - (old, new) - for old, new in resource_markers - if old in predecessor_definition and new not in predecessor_definition - ] - assert matches - old, new = max(matches, key=lambda item: len(item[1])) - forward_source = predecessor_definition.replace(old, new) - validation_clause = "" if validated else " not valid" - await connection.execute( - text( - "alter table audit_events drop constraint if exists " - "ck_audit_events_authority_privacy_bounds" - ) - ) - await connection.exec_driver_sql( - "alter table audit_events add constraint " - "ck_audit_events_authority_privacy_bounds " - f"{forward_source}{validation_clause}" - ) - forward_definition = await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint where conname=" - "'ck_audit_events_authority_privacy_bounds' and " - "conrelid='audit_events'::regclass" - ) - ) - assert isinstance(forward_definition, str) - backward_matches = [ - (candidate_old, candidate_new) - for candidate_old, candidate_new in resource_markers - if candidate_new in forward_definition - ] - assert backward_matches - old, new = max(backward_matches, key=lambda item: len(item[1])) - predecessor_source = forward_definition.removesuffix(" NOT VALID").replace(new, old) - # Keep this normalization independent of the migration under test. Sharing its - # implementation would let the repair helper reproduce the same defect and mask drift. - predecessor_source = re.sub( - r"\('([^']+)'::character varying\)::text", - r"'\1'", - predecessor_source, - ) - predecessor_source = re.sub( - r"\(\((\w+)\)::text = ANY \(ARRAY\[([^]]+)\]\)\)", - r"\1 in (\2)", - predecessor_source, - ) - predecessor_source = re.sub( - r"\(\((\w+)\)::text <> ALL \(ARRAY\[([^]]+)\]\)\)", - r"\1 not in (\2)", - predecessor_source, - ) - await connection.execute( - text("alter table audit_events drop constraint ck_audit_events_authority_privacy_bounds") - ) - await connection.exec_driver_sql( - "alter table audit_events add constraint " - "ck_audit_events_authority_privacy_bounds " - f"{predecessor_source}{validation_clause}" - ) - - -async def _restore_0034_trigger_states( - connection, - triggers: tuple[tuple[object, ...], ...], -) -> None: - allowed_triggers = { - ("audit_events", "audit_events_reject_truncate"), - ("audit_events", "audit_events_reject_update_delete"), - ("audit_events", "audit_events_set_authority_time"), - ("audit_events", "audit_events_validate_idempotency"), - ("authority_idempotency_records", "authority_idempotency_guard"), - ( - "authority_idempotency_records", - "authority_idempotency_pending_guard", - ), - ( - "authority_idempotency_records", - "authority_idempotency_reject_truncate", - ), - } - operations = { - "O": "enable trigger", - "D": "disable trigger", - "R": "enable replica trigger", - "A": "enable always trigger", - } - for trigger in triggers: - assert len(trigger) == 3 - table_name, trigger_name, enabled_state = trigger - assert (table_name, trigger_name) in allowed_triggers - if isinstance(enabled_state, bytes): - enabled_state = enabled_state.decode("ascii") - assert enabled_state in operations - await connection.exec_driver_sql( - f"alter table {table_name} {operations[enabled_state]} {trigger_name}" - ) - - -async def _facts_are_safe_0034( - database_url: str, - before: dict[str, object] | None, - after: dict[str, object] | None, - project_id: str, -) -> bool | None: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return await connection.scalar( - text( - "select authority_event_facts_are_safe(" - "'AuthorityInvalidationRequested',cast(:before as json)," - "cast(:after as json),:project)" - ), - { - "before": None if before is None else json.dumps(before), - "after": None if after is None else json.dumps(after), - "project": project_id, - }, - ) - finally: - await engine.dispose() - - -async def _seed_pending_issue_cause_0034(database_url: str) -> dict[str, str]: - values = { - "record": str(uuid4()), - "key": str(uuid4()), - "actor": str(uuid4()), - "target": str(uuid4()), - "project": str(uuid4()), - "grant": str(uuid4()), - "manager": str(uuid4()), - "request": str(uuid4()), - "correlation": str(uuid4()), - } - engine = create_async_engine(database_url) - trigger_states = None - try: - async with engine.begin() as connection: - trigger_states = tuple( - tuple(row) - for row in ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled " - "from pg_trigger where " - "(tgrelid='authority_idempotency_records'::regclass and " - "tgname='authority_idempotency_pending_guard') or " - "(tgrelid='audit_events'::regclass and " - "tgname='audit_events_validate_idempotency') " - "order by tgrelid::regclass::text,tgname" - ) - ) - ).all() - ) - assert len(trigger_states) == 2 - await connection.execute( - text( - "alter table authority_idempotency_records disable trigger " - "authority_idempotency_pending_guard" - ) - ) - await connection.execute( - text("alter table audit_events disable trigger audit_events_validate_idempotency") - ) - async with engine.begin() as connection: - await connection.execute( - text( - "insert into authority_idempotency_records " - "(id,idempotency_key,actor_ref_kind,actor_ref,operation,request_digest,status) " - "values (:record,:key,'actor_profile',:actor," - "'project_role_grant.issue',:digest,'pending')" - ), - values | {"digest": f"sha256:{'1' * 64}"}, - ) - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version," - "actor_ref_kind,request_id,correlation_id,target_actor_ref_kind," - "target_actor_ref,matched_grant_id,permission_id,project_id,resource_type," - "resource_id,target_ref_kind,target_ref_id,reason,idempotency_reference," - "after_facts) values (:grant,'project_role_grant',:grant," - "'ProjectRoleGrantIssued',:actor,'[]','{}','local_authority',false,'{}'," - "'authority',1,'actor_profile',:request,:correlation,'actor_profile'," - ":target,:manager,'project.role_grant.manage',:project," - "'project_role_grant',:grant,'project_role_grant',:grant," - "'authority_assignment',:record,cast(:facts as json))" - ), - values - | { - "facts": json.dumps( - { - "status": "active", - "role": "submitter", - "scope_type": "project", - "scope_id": values["project"], - "effective": True, - } - ) - }, - ) - return values - finally: - if trigger_states is not None: - async with engine.begin() as connection: - await _restore_0034_trigger_states(connection, trigger_states) - await engine.dispose() - - -async def _insert_false_issue_invalidation_0034( - database_url: str, - values: dict[str, str], -) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version," - "actor_ref_kind,request_id,correlation_id,permission_id,project_id," - "resource_type,resource_id,reason,idempotency_reference," - "invalidation_cause_event_id,invalidation_target_kind," - "invalidation_target_ref,before_facts,after_facts) values " - "(:id,'authority_invalidation',:id,'AuthorityInvalidationRequested'," - ":actor,'[]','{}','local_authority',false,'{}','authority',1," - "'actor_profile',:request,:correlation,'project.role_grant.manage'," - ":project,'project_role_grant',:grant,'authority_state_changed',:record," - ":grant,'project_role_grant',:grant,cast(:before as json)," - "cast(:after as json))" - ), - values - | { - "id": str(uuid4()), - "before": json.dumps({"effective": True}), - "after": json.dumps({"effective": False}), - }, - ) - finally: - await engine.dispose() - - -async def _count_linked_events_0034(database_url: str, record_id: str) -> int: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return int( - await connection.scalar( - text("select count(*) from audit_events where idempotency_reference=:record"), - {"record": record_id}, - ) - ) - finally: - await engine.dispose() - - -def _five_key_revoke_facts_0034( - values: dict[str, str], - *, - effective: bool, -) -> dict[str, object]: - return { - "effective": effective, - "role": "submitter", - "scope_type": "project", - "scope_id": values["project"], - "future_obligation": "auth13_assignment", - } - - -async def _seed_pending_revoke_cause_0034( - database_url: str, - *, - envelope: dict[str, str] | None = None, -) -> dict[str, str]: - values = { - "record": str(uuid4()), - "key": str(uuid4()), - "cause": str(uuid4()), - "actor": envelope["actor"] if envelope else str(uuid4()), - "target": envelope["target"] if envelope else str(uuid4()), - "project": envelope["project"] if envelope else str(uuid4()), - "grant": envelope["grant"] if envelope else str(uuid4()), - "manager": envelope["manager"] if envelope else str(uuid4()), - "request": envelope["request"] if envelope else str(uuid4()), - "correlation": envelope["correlation"] if envelope else str(uuid4()), - } - before_facts = { - "status": "active", - "role": "submitter", - "scope_type": "project", - "scope_id": values["project"], - "effective": True, - } - after_facts = {**before_facts, "status": "revoked", "effective": False} - engine = create_async_engine(database_url) - pending_guard = None - try: - async with engine.begin() as connection: - pending_guard = tuple( - ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled " - "from pg_trigger where tgrelid=" - "'authority_idempotency_records'::regclass and tgname=" - "'authority_idempotency_pending_guard'" - ) - ) - ).one() - ) - await connection.execute( - text( - "alter table authority_idempotency_records disable trigger " - "authority_idempotency_pending_guard" - ) - ) - async with engine.begin() as connection: - await connection.execute( - text( - "insert into authority_idempotency_records " - "(id,idempotency_key,actor_ref_kind,actor_ref,operation," - "request_digest,status) values " - "(:record,:key,'actor_profile',:actor," - "'project_role_grant.revoke',:digest,'pending')" - ), - values | {"digest": f"sha256:{'2' * 64}"}, - ) - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id," - "target_actor_ref_kind,target_actor_ref,matched_grant_id,permission_id," - "project_id,resource_type,resource_id,target_ref_kind,target_ref_id," - "reason,idempotency_reference,before_facts,after_facts) values " - "(:cause,'project_role_grant',:grant,'ProjectRoleGrantRevoked'," - ":actor,'[]','{}','local_authority',false,'{}','authority',1," - "'actor_profile',:request,:correlation,'actor_profile',:target," - ":manager,'project.role_grant.manage',:project,'project_role_grant'," - ":grant,'project_role_grant',:grant,'authority_revocation',:record," - "cast(:before as json),cast(:after as json))" - ), - values - | { - "before": json.dumps(before_facts), - "after": json.dumps(after_facts), - }, - ) - return values - finally: - if pending_guard is not None: - async with engine.begin() as connection: - await _restore_0034_trigger_states(connection, (pending_guard,)) - await engine.dispose() - - -async def _insert_revoke_invalidation_0034( - database_url: str, - record: dict[str, str], - *, - cause: dict[str, str], - before_facts: dict[str, object], - after_facts: dict[str, object], - target_ref_kind: str | None, - target_ref_id: str | None, -) -> str: - invalidation_id = str(uuid4()) - values = { - **cause, - "cause": cause.get("cause", cause["grant"]), - "id": invalidation_id, - "record": record["record"], - "actor": record["actor"], - "before": json.dumps(before_facts), - "after": json.dumps(after_facts), - "target_ref_kind": target_ref_kind, - "target_ref_id": target_ref_id, - } - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id," - "target_actor_ref_kind,target_actor_ref,permission_id,project_id," - "resource_type,resource_id,target_ref_kind,target_ref_id,reason," - "idempotency_reference," - "invalidation_cause_event_id,invalidation_target_kind," - "invalidation_target_ref,before_facts,after_facts) values " - "(:id,'authority_invalidation',:id,'AuthorityInvalidationRequested'," - ":actor,'[]','{}','local_authority',false,'{}','authority',1," - "'actor_profile',:request,:correlation,'actor_profile',:target," - "'project.role_grant.manage',:project,'project_role_grant',:grant," - ":target_ref_kind,:target_ref_id,'authority_state_changed',:record," - ":cause,'project_role_grant'," - ":grant,cast(:before as json),cast(:after as json))" - ), - values, - ) - return invalidation_id - finally: - await engine.dispose() - - -async def _linked_revoke_fixture_state_0034( - database_url: str, - records: list[str], -) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - parameters = {"records": records} - record_rows = tuple( - ( - await connection.execute( - text( - "select to_jsonb(r)::text from authority_idempotency_records r " - "where r.id::text=any(cast(:records as text[])) " - "order by r.id::text" - ), - parameters, - ) - ).scalars() - ) - event_rows = tuple( - ( - await connection.execute( - text( - "select to_jsonb(e)::text from audit_events e " - "where e.idempotency_reference::text=any(cast(:records as text[])) " - "order by e.id::text" - ), - parameters, - ) - ).scalars() - ) - event_ids = tuple( - ( - await connection.execute( - text( - "select e.id::text from audit_events e " - "where e.idempotency_reference::text=any(cast(:records as text[])) " - "order by e.id::text" - ), - parameters, - ) - ).scalars() - ) - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "records": record_rows, - "events": event_rows, - "event_ids": event_ids, - "event_count": len(event_rows), - } - finally: - await engine.dispose() - - -async def _clear_linked_revoke_fixtures_0034( - database_url: str, - records: list[str], -) -> None: - if not records: - return - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - if not await connection.scalar( - text("select to_regclass('authority_idempotency_records') is not null") - ): - return - trigger_rows = ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled from pg_trigger " - "where tgrelid in ('audit_events'::regclass," - "'authority_idempotency_records'::regclass) and not tgisinternal " - "order by tgrelid::regclass::text,tgname" - ) - ) - ).all() - await connection.execute(text("alter table audit_events disable trigger user")) - await connection.execute( - text("alter table authority_idempotency_records disable trigger user") - ) - parameters = {"records": records} - await connection.execute( - text( - "delete from audit_events where " - "idempotency_reference::text=any(cast(:records as text[]))" - ), - parameters, - ) - await connection.execute( - text( - "delete from authority_idempotency_records where " - "id::text=any(cast(:records as text[]))" - ), - parameters, - ) - await _restore_0034_trigger_states( - connection, - tuple(tuple(row) for row in trigger_rows), - ) - finally: - await engine.dispose() - - -async def _clear_0034_issue_fixture(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - if not await connection.scalar( - text("select to_regclass('authority_idempotency_records') is not null") - ): - return - await connection.execute(text("alter table audit_events disable trigger user")) - await connection.execute( - text("alter table authority_idempotency_records disable trigger user") - ) - await connection.execute( - text( - "delete from audit_events where idempotency_reference in " - "(select id from authority_idempotency_records " - "where operation='project_role_grant.issue' and status='pending')" - ) - ) - await connection.execute( - text( - "delete from authority_idempotency_records " - "where operation='project_role_grant.issue' and status='pending'" - ) - ) - await connection.execute( - text("alter table authority_idempotency_records enable trigger user") - ) - await connection.execute(text("alter table audit_events enable trigger user")) - finally: - await engine.dispose() - - -async def _insert_empty_pending_0034_issue(database_url: str) -> None: - engine = create_async_engine(database_url) - pending_guard = None - try: - async with engine.begin() as connection: - pending_guard = tuple( - ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled " - "from pg_trigger where tgrelid=" - "'authority_idempotency_records'::regclass and tgname=" - "'authority_idempotency_pending_guard'" - ) - ) - ).one() - ) - await connection.execute( - text( - "alter table authority_idempotency_records disable trigger " - "authority_idempotency_pending_guard" - ) - ) - async with engine.begin() as connection: - await connection.execute( - text( - "insert into authority_idempotency_records " - "(id,idempotency_key,actor_ref_kind,actor_ref,operation,request_digest,status) " - "values (:id,:key,'actor_profile',:actor,'project_role_grant.issue'," - ":digest,'pending')" - ), - { - "id": str(uuid4()), - "key": str(uuid4()), - "actor": str(uuid4()), - "digest": f"sha256:{'0' * 64}", - }, - ) - finally: - if pending_guard is not None: - async with engine.begin() as connection: - await _restore_0034_trigger_states(connection, (pending_guard,)) - await engine.dispose() - - -async def _authority_idempotency_state_shape_0034( - database_url: str, -) -> tuple[str, bool, str] | None: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - row = ( - await connection.execute( - text( - "select conrelid::regclass::text,convalidated," - "pg_get_constraintdef(oid) from pg_constraint where conname=" - "'ck_authority_idempotency_records_state_shape' and " - "conrelid='authority_idempotency_records'::regclass" - ) - ) - ).one_or_none() - return None if row is None else tuple(row) - finally: - await engine.dispose() - - -async def _add_pending_issue_response_0034( - database_url: str, - state_shape_constraint: tuple[str, bool, str], -) -> None: - table_name, validated, definition = state_shape_constraint - assert table_name == "authority_idempotency_records" - assert isinstance(validated, bool) - assert isinstance(definition, str) - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - current_row = ( - await connection.execute( - text( - "select conrelid::regclass::text,convalidated," - "pg_get_constraintdef(oid) from pg_constraint where conname=" - "'ck_authority_idempotency_records_state_shape' and " - "conrelid='authority_idempotency_records'::regclass" - ) - ) - ).one() - assert tuple(current_row) == state_shape_constraint - trigger_rows = ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled from pg_trigger " - "where tgrelid='authority_idempotency_records'::regclass and " - "not tgisinternal order by tgname" - ) - ) - ).all() - assert {row.tgname for row in trigger_rows} == { - "authority_idempotency_guard", - "authority_idempotency_pending_guard", - "authority_idempotency_reject_truncate", - } - await connection.execute( - text( - "alter table authority_idempotency_records drop constraint " - "ck_authority_idempotency_records_state_shape" - ) - ) - await connection.execute( - text("alter table authority_idempotency_records disable trigger user") - ) - await connection.execute( - text( - "update authority_idempotency_records set " - "response_resource_type='project_role_grant'," - "response_resource_id=:resource,response_resource_version=1," - "response_http_status=201 where operation='project_role_grant.issue'" - ), - {"resource": str(uuid4())}, - ) - await connection.exec_driver_sql( - "alter table authority_idempotency_records add constraint " - "ck_authority_idempotency_records_state_shape " - f"{definition.removesuffix(' NOT VALID')} not valid" - ) - await _restore_0034_trigger_states( - connection, - tuple(tuple(row) for row in trigger_rows), - ) - finally: - await engine.dispose() - - -async def _clear_pending_0034_issues( - database_url: str, - state_shape_constraint: tuple[str, bool, str] | None = None, -) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - exists = await connection.scalar( - text("select to_regclass('authority_idempotency_records') is not null") - ) - if exists: - trigger_rows = ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled from pg_trigger " - "where tgrelid='authority_idempotency_records'::regclass " - "and not tgisinternal order by tgname" - ) - ) - ).all() - await connection.execute( - text("alter table authority_idempotency_records disable trigger user") - ) - await connection.execute( - text( - "delete from authority_idempotency_records " - "where operation='project_role_grant.issue' and status='pending'" - ) - ) - if state_shape_constraint is not None: - table_name, validated, definition = state_shape_constraint - assert table_name == "authority_idempotency_records" - assert isinstance(validated, bool) - assert isinstance(definition, str) - await connection.execute( - text( - "alter table authority_idempotency_records drop constraint " - "if exists ck_authority_idempotency_records_state_shape" - ) - ) - await connection.exec_driver_sql( - "alter table authority_idempotency_records add constraint " - "ck_authority_idempotency_records_state_shape " - f"{definition.removesuffix(' NOT VALID')}" - f"{' not valid' if not validated else ''}" - ) - await _restore_0034_trigger_states( - connection, - tuple(tuple(row) for row in trigger_rows), - ) - finally: - await engine.dispose() - - -async def _replace_0034_fact_constraint_with_drift( - database_url: str, - drift: str, -) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text("alter table audit_events drop constraint ck_audit_events_fact_bounds") - ) - if drift == "changed": - await connection.execute( - text( - "alter table audit_events add constraint ck_audit_events_fact_bounds " - "check (event_domain <> 'authority' or true)" - ) - ) - elif drift == "unvalidated": - await connection.execute( - text( - "alter table audit_events add constraint ck_audit_events_fact_bounds " - "check (event_domain <> 'authority' or true) not valid" - ) - ) - elif drift == "wrong_table": - await connection.execute( - text( - "alter table projects add constraint ck_audit_events_fact_bounds " - "check (true)" - ) - ) - finally: - await engine.dispose() - - -async def _restore_0034_fact_constraint( - database_url: str, - definition: str | None, -) -> None: - if definition is None: - return - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - rows = ( - ( - await connection.execute( - text( - "select conrelid::regclass::text table_name from pg_constraint " - "where conname='ck_audit_events_fact_bounds'" - ) - ) - ) - .scalars() - .all() - ) - for table_name in rows: - await connection.execute( - text(f"alter table {table_name} drop constraint ck_audit_events_fact_bounds") - ) - await connection.execute( - text( - "alter table audit_events add constraint " - f"ck_audit_events_fact_bounds {definition}" - ) - ) - finally: - await engine.dispose() - - -def test_artifact_recovery_schema_and_empty_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """Prove 0032 lineage indexes, custody triggers, and reversible empty state.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - assert asyncio.run(_artifact_recovery_schema(isolated_database_env)) == { - "revision": HEAD_REVISION, - "constraints": { - "artifact_recovery_attempt_custody", - "artifact_verification_lineage_custody", - "uq_artifact_recovery_idempotency", - "uq_artifact_recovery_retry_job", - "uq_artifact_recovery_source_job", - "uq_artifact_verification_initial_origin", - "uq_artifact_verification_parent", - }, - } - command.downgrade(config, "0031_project_role_grants") - assert "artifact_recovery_attempts" not in asyncio.run( - _fetch_table_names(isolated_database_env) - ) - finally: - command.downgrade(config, "base") - - -def test_guide_source_artifact_ingest_schema_and_replay( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0038 installs one linear server-owned guide-ingest staging table.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0038_guide_source_ingest") - assert "guide_source_artifact_ingests" in asyncio.run( - _fetch_table_names(isolated_database_env) - ) - asyncio.run(_seed_populated_guide_source_ingest(isolated_database_env)) - with pytest.raises( - RuntimeError, - match="cannot downgrade populated guide source artifact ingests", - ): - command.downgrade(config, "0037_art_auth_context_evidence") - asyncio.run(_clear_populated_guide_source_ingest(isolated_database_env)) - command.downgrade(config, "0037_art_auth_context_evidence") - assert "guide_source_artifact_ingests" not in asyncio.run( - _fetch_table_names(isolated_database_env) - ) - command.upgrade(config, "0038_guide_source_ingest") - assert "guide_source_artifact_ingests" in asyncio.run( - _fetch_table_names(isolated_database_env) - ) - finally: - command.downgrade(config, "base") - - -def test_0039_backfills_setup_generations_per_guide( - isolated_database_env: str, - migration_lock, -) -> None: - """Existing setup runs receive deterministic guide-local generations.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0038_guide_source_ingest") - expected = asyncio.run(_seed_setup_runs_before_0039(isolated_database_env)) - - command.upgrade(config, "0039_guide_source_bindings") - actual = asyncio.run(_setup_generations_after_0039(isolated_database_env)) - assert actual == expected - assert "guide_source_artifact_bindings" in asyncio.run( - _fetch_table_names(isolated_database_env) - ) - - command.downgrade(config, "0038_guide_source_ingest") - assert "guide_source_artifact_bindings" not in asyncio.run( - _fetch_table_names(isolated_database_env) - ) - finally: - command.downgrade(config, "base") - - -async def _seed_setup_runs_before_0039(database_url: str) -> list[tuple[str, int]]: - engine = create_async_engine(database_url) - project_ids = (str(uuid4()), str(uuid4())) - guide_ids = (str(uuid4()), str(uuid4())) - snapshot_ids = (str(uuid4()), str(uuid4())) - run_ids = (str(uuid4()), str(uuid4()), str(uuid4())) - digest = "sha256:" + "b" * 64 - try: - async with engine.begin() as connection: - for index in range(2): - parameters = { - "project": project_ids[index], - "guide": guide_ids[index], - "snapshot": snapshot_ids[index], - "slug": f"generation-{project_ids[index]}", - "digest": digest, - } - await connection.execute( - text( - "insert into projects (id, name, slug, status) " - "values (:project, 'Generation project', :slug, 'draft')" - ), - parameters, - ) - await connection.execute( - text( - "insert into project_guides " - "(id, project_id, version, status, content_markdown, created_by) " - "values (:guide, :project, 'v1', 'draft', '# Guide', 'migration-test')" - ), - parameters, - ) - await connection.execute( - text( - "insert into guide_source_snapshots " - "(id, project_id, guide_id, guide_version, manifest_schema_version, " - "manifest_json, bundle_hash, captured_by) values " - "(:snapshot, :project, :guide, 'v1', '1', '{}'::json, :digest, " - "'migration-test')" - ), - parameters, - ) - - for run_id, guide_index, created_at in ( - (run_ids[1], 0, datetime(2026, 1, 2, tzinfo=UTC)), - (run_ids[0], 0, datetime(2026, 1, 1, tzinfo=UTC)), - (run_ids[2], 1, datetime(2026, 1, 1, tzinfo=UTC)), - ): - await connection.execute( - text( - "insert into project_setup_runs " - "(id, project_id, guide_id, guide_version, source_snapshot_id, " - "source_snapshot_hash, status, current_step, created_by, created_at) " - "values (:run, :project, :guide, 'v1', :snapshot, :digest, " - "'queued', 'queued', 'migration-test', :created_at)" - ), - { - "run": run_id, - "project": project_ids[guide_index], - "guide": guide_ids[guide_index], - "snapshot": snapshot_ids[guide_index], - "digest": digest, - "created_at": created_at, - }, - ) - return sorted([(run_ids[0], 1), (run_ids[1], 2), (run_ids[2], 1)]) - finally: - await engine.dispose() - - -async def _setup_generations_after_0039(database_url: str) -> list[tuple[str, int]]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - rows = await connection.execute( - text("select id, setup_generation from project_setup_runs order by id") - ) - return sorted((str(row.id), int(row.setup_generation)) for row in rows) - finally: - await engine.dispose() - - -async def _seed_populated_guide_source_ingest(database_url: str) -> None: - engine = create_async_engine(database_url) - ids = { - name: str(uuid4()) - for name in ("actor", "identity_link", "project", "guide", "snapshot", "item") - } - try: - async with engine.begin() as connection: - parameters = { - **ids, - "ingest": str(uuid4()), - "slug": f"migration-{ids['project']}", - "sha256": "sha256:" + "a" * 64, - } - await insert_historical_project( - connection, - project_id=ids["project"], - name="Migration project", - slug=parameters["slug"], - ) - statements = ( - ( - "insert into actor_profiles " - "(id, actor_kind, status, provisioning_method, created_by) " - "values (:actor, 'human', 'active', 'automatic_first_access', 'migration-test')" - ), - ( - "insert into actor_identity_links " - "(id, actor_profile_id, issuer, subject, subject_kind, status, " - "linked_by, last_verified_at) values " - "(:identity_link, :actor, 'https://identity.test', :actor, 'human', " - "'active', 'migration-test', clock_timestamp())" - ), - ( - "insert into project_guides " - "(id, project_id, version, status, content_markdown, created_by) " - "values (:guide, :project, 'v1', 'draft', '# Guide', 'migration-test')" - ), - ( - "insert into guide_source_snapshots " - "(id, project_id, guide_id, guide_version, manifest_schema_version, " - "manifest_json, bundle_hash, captured_by) values " - "(:snapshot, :project, :guide, 'v1', '1', '{}'::json, :sha256, 'migration-test')" - ), - ( - "insert into guide_source_snapshot_items " - "(id, source_snapshot_id, item_order, source_kind, durable_ref, " - "ingestion_adapter, content_hash, media_type) values " - "(:item, :snapshot, 0, 'upload', 'migration-test', 'upload', :sha256, " - "'application/octet-stream')" - ), - ( - "insert into guide_source_artifact_ingests " - "(id, source_item_id, actor_profile_id, sha256, byte_count, media_type) " - "values (:ingest, :item, :actor, :sha256, 1, 'application/octet-stream')" - ), - ) - for statement in statements: - await connection.execute(text(statement), parameters) - finally: - await engine.dispose() - - -async def _clear_populated_guide_source_ingest(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("delete from guide_source_artifact_ingests")) - finally: - await engine.dispose() - - -async def _artifact_recovery_schema(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - revision = await connection.scalar(text("select version_num from alembic_version")) - names = set( - ( - await connection.execute( - text( - "select conname from pg_constraint where conrelid in " - "('artifact_recovery_attempts'::regclass, " - "'artifact_verification_jobs'::regclass) " - "union select tgname from pg_trigger where tgrelid in " - "('artifact_recovery_attempts'::regclass, " - "'artifact_verification_jobs'::regclass) and not tgisinternal " - "union select indexname from pg_indexes where indexname = " - "'uq_artifact_verification_initial_origin'" - ) - ) - ).scalars() - ) - expected = { - "artifact_recovery_attempt_custody", - "artifact_verification_lineage_custody", - "uq_artifact_recovery_idempotency", - "uq_artifact_recovery_retry_job", - "uq_artifact_recovery_source_job", - "uq_artifact_verification_initial_origin", - "uq_artifact_verification_parent", - } - return {"revision": revision, "constraints": names & expected} - finally: - await engine.dispose() - - -def test_0035_project_read_action_evidence_round_trip( - isolated_database_env: str, migration_lock -) -> None: - """Prove all eleven planned pairs and both permissions round-trip exactly.""" - config = _alembic_config() - definitions = tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner in {ActionOwner.AUTH_11B, ActionOwner.AUTH_11C1, ActionOwner.AUTH_11C2} - ) - assert len(definitions) == 11 - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, definitions=definitions - ) - ) - asyncio.run(_assert_removed_art_authority_rejected(isolated_database_env)) - command.downgrade(config, "0034_project_role_issue_evidence") - command.upgrade(config, "head") - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, definitions=definitions - ) - ) - asyncio.run(_assert_removed_art_authority_rejected(isolated_database_env)) - finally: - command.downgrade(config, "base") - - -def test_0035_project_read_action_evidence_refuses_nonempty_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """A committed 11A audit row must block removal of its frozen vocabulary.""" - config = _alembic_config() - definition = next(item for item in ACTION_DEFINITIONS if item.owner is ActionOwner.AUTH_11B) - event_id = "" - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - event_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, - definition.action_id.value, - definition.permission_id.value, - ) - ) - with pytest.raises( - RuntimeError, match="cannot downgrade non-empty project-read action evidence" - ): - command.downgrade(config, "0034_project_role_issue_evidence") - assert asyncio.run(_current_revision(isolated_database_env)) == (HEAD_REVISION) - finally: - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, event_id=event_id)) - command.downgrade(config, "base") - - -def test_0041_project_mutation_action_evidence_round_trip( - isolated_database_env: str, migration_lock -) -> None: - """Prove all eighteen planned action pairs round-trip without new permissions.""" - config = _alembic_config() - definitions = tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner in _PROJECT_MUTATION_OWNERS - ) - assert len(definitions) == 18 - assert {definition.permission_id for definition in definitions} == { - PermissionId.PROJECT_CREATE, - PermissionId.PROJECT_GUIDE_MANAGE, - PermissionId.PROJECT_REVIEW_POLICY_MANAGE, - PermissionId.PROJECT_EFFECTIVE_POLICY_MANAGE, - } - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, definitions=definitions - ) - ) - command.downgrade(config, "0040_guide_materialization") - command.upgrade(config, "head") - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, definitions=definitions - ) - ) - finally: - command.downgrade(config, "base") - - -def test_0041_project_mutation_action_evidence_refuses_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """Committed direct and idempotency-linked evidence must preserve vocabulary.""" - config = _alembic_config() - definitions = tuple( - item for item in ACTION_DEFINITIONS if item.owner in _PROJECT_MUTATION_OWNERS - ) - assert len(definitions) == 18 - event_id = "" - linked_event_id = "" - record_id = str(uuid4()) - actor_id = str(uuid4()) - target_id = str(uuid4()) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - definition = definitions[0] - event_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, - definition.action_id.value, - definition.permission_id.value, - ) - ) - with pytest.raises( - RuntimeError, - match="cannot downgrade non-empty project-mutation action evidence", - ): - command.downgrade(config, "0040_guide_materialization") - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, event_id=event_id)) - event_id = "" - - definition = definitions[-1] - asyncio.run( - _insert_committed_authority_idempotency( - isolated_database_env, record_id, actor_id, target_id - ) - ) - linked_event_id = asyncio.run( - _insert_linked_authorization_action_event( - isolated_database_env, - record_id=record_id, - actor_id=actor_id, - action_id=definition.action_id.value, - permission_id=definition.permission_id.value, - ) - ) - with pytest.raises( - RuntimeError, - match="cannot downgrade non-empty project-mutation action evidence", - ): - command.downgrade(config, "0040_guide_materialization") - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - finally: - if event_id: - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - if linked_event_id: - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=linked_event_id) - ) - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=None - ) - ) - command.downgrade(config, "base") - - -def test_0043_project_setup_service_round_trip_and_seeds_no_authority( - isolated_database_env: str, migration_lock -) -> None: - """0043 alone admits the eighth identity without creating actor authority.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0042_guide_extraction") - prior = asyncio.run(_project_setup_service_state(isolated_database_env)) - assert not prior["constraint_admits_identity"] - assert prior["authority_rows"] == (0, 0, 0, 0) - - command.upgrade(config, "head") - upgraded = asyncio.run(_project_setup_service_state(isolated_database_env)) - assert upgraded["constraint_admits_identity"] - assert upgraded["authority_rows"] == (0, 0, 0, 0) - - command.downgrade(config, "0042_guide_extraction") - restored = asyncio.run(_project_setup_service_state(isolated_database_env)) - assert not restored["constraint_admits_identity"] - assert restored["authority_rows"] == (0, 0, 0, 0) - - command.upgrade(config, "head") - assert asyncio.run(_project_setup_service_state(isolated_database_env)) == upgraded - finally: - command.downgrade(config, "base") - - -def test_0043_project_setup_service_refuses_in_use_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """An exact project-setup profile prevents removal of its closed identity.""" - config = _alembic_config() - actor_profile_id = str(uuid4()) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run( - _insert_project_setup_service_actor( - isolated_database_env, - actor_profile_id=actor_profile_id, - ) - ) - with pytest.raises( - RuntimeError, - match="cannot downgrade project setup service identity", - ): - command.downgrade(config, "0042_guide_extraction") - assert asyncio.run(_current_revision(isolated_database_env)) == (HEAD_REVISION) - asyncio.run(_remove_fixed_service_actor(isolated_database_env, actor_profile_id)) - actor_profile_id = "" - command.downgrade(config, "0042_guide_extraction") - finally: - if actor_profile_id: - asyncio.run(_remove_fixed_service_actor(isolated_database_env, actor_profile_id)) - command.downgrade(config, "base") - - -async def _project_create_authority_schema_state(database_url: str) -> tuple[bool, bool, bool]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - table_exists = bool( - await connection.scalar( - text( - "select to_regclass('public.project_create_idempotency_records') " - "is not null" - ) - ) - ) - provenance_exists = bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='projects' " - "and column_name='authorization_decision_event_id')" - ) - ) - ) - privacy = ( - await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass " - "and conname='ck_audit_events_authority_privacy_bounds'" - ) - ) - or "" - ) - return ( - table_exists, - provenance_exists, - "project_create_operation" in privacy and "target_ref_kind" in privacy, - ) - finally: - await engine.dispose() - - -def test_0044_project_create_authority_round_trip( - isolated_database_env: str, migration_lock -) -> None: - """0044 alone installs and exactly removes project-create persistence.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0043_project_setup_service") - assert asyncio.run(_project_create_authority_schema_state(isolated_database_env)) == ( - False, - False, - False, - ) - command.upgrade(config, "head") - assert asyncio.run(_project_create_authority_schema_state(isolated_database_env)) == ( - True, - True, - True, - ) - command.downgrade(config, "0043_project_setup_service") - assert asyncio.run(_project_create_authority_schema_state(isolated_database_env)) == ( - False, - False, - False, - ) - command.upgrade(config, "head") - finally: - command.downgrade(config, "base") - - -async def _assert_0044_rejects_new_unattributed_project(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute( - text( - "insert into projects (id,name,slug,status) " - "values (:id,'Unattributed','unattributed','draft')" - ), - {"id": str(uuid4())}, - ) - with pytest.raises(IntegrityError): - await transaction.commit() - if transaction.is_active: - await transaction.rollback() - finally: - await engine.dispose() - - -def test_0044_rejects_new_unattributed_project(isolated_database_env: str, migration_lock) -> None: - """Historical null provenance survives, but new null-provenance rows deny.""" - config = _alembic_config() - historical_id = str(uuid4()) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0043_project_setup_service") - - async def seed_historical() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into projects (id,name,slug,status) " - "values (:id,'Historical','historical','draft')" - ), - {"id": historical_id}, - ) - finally: - await engine.dispose() - - asyncio.run(seed_historical()) - command.upgrade(config, "head") - asyncio.run(_assert_0044_rejects_new_unattributed_project(isolated_database_env)) - - async def remove_historical() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text("delete from projects where id=:id"), {"id": historical_id} - ) - finally: - await engine.dispose() - - asyncio.run(remove_historical()) - finally: - command.downgrade(config, "base") - - -def test_0044_refuses_populated_project_create_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """A committed project custody chain prevents destructive downgrade.""" - config = _alembic_config() - - async def seed() -> None: - engine = create_async_engine(isolated_database_env) - try: - factory = async_sessionmaker(engine, expire_on_commit=False) - async with factory() as session: - await seed_authorized_project( - session, - project_id=str(uuid4()), - name="Downgrade custody", - slug=f"downgrade-custody-{uuid4()}", - ) - await session.commit() - finally: - await engine.dispose() - - async def reset_schema() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text("drop schema public cascade")) - await connection.execute(text("create schema public")) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run(seed()) - with pytest.raises( - RuntimeError, match="cannot downgrade non-empty project creation authority" - ): - command.downgrade(config, "0043_project_setup_service") - finally: - asyncio.run(reset_schema()) - - -async def _guide_metadata_authority_schema_state( - database_url: str, -) -> tuple[bool, bool, bool, bool]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return ( - bool( - await connection.scalar( - text( - "select to_regclass('public.guide_mutation_idempotency_records') " - "is not null" - ) - ) - ), - bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='project_guides' " - "and column_name='mutation_generation')" - ) - ) - ), - bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='guide_source_snapshots' " - "and column_name='creation_generation')" - ) - ) - ), - bool( - await connection.scalar( - text( - "select exists(select 1 from pg_trigger " - "where tgname='guide_mutation_reservation_custody')" - ) - ) - ), - ) - finally: - await engine.dispose() - - -def test_0045_guide_source_metadata_authority_round_trip( - isolated_database_env: str, migration_lock -) -> None: - """0045 installs and exactly removes the guide-mutation custody seam.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0044_project_create_authority") - assert asyncio.run(_guide_metadata_authority_schema_state(isolated_database_env)) == ( - False, - False, - False, - False, - ) - command.upgrade(config, "head") - assert asyncio.run(_guide_metadata_authority_schema_state(isolated_database_env)) == ( - True, - True, - True, - True, - ) - command.downgrade(config, "0044_project_create_authority") - assert asyncio.run(_guide_metadata_authority_schema_state(isolated_database_env)) == ( - False, - False, - False, - False, - ) - command.upgrade(config, "head") - finally: - command.downgrade(config, "base") - - -def test_0045_preserves_historical_guide_rows(isolated_database_env: str, migration_lock) -> None: - """0045 preserves historical rows while the later v2 clean cut refuses them.""" - config = _alembic_config() - project_id, guide_id, snapshot_id, setup_run_id = (str(uuid4()) for _ in range(4)) - snapshot_hash = "sha256:" + "0" * 64 - - async def seed_and_read(*, seed: bool) -> tuple | None: - engine = create_async_engine(isolated_database_env) - try: - if seed: - factory = async_sessionmaker(engine, expire_on_commit=False) - async with factory() as session: - await insert_historical_project( - session, - project_id=project_id, - name="Historical guide project", - slug=f"historical-guide-{uuid4()}", - ) - await session.execute( - text( - "insert into project_guides " - "(id,project_id,version,status,content_markdown,created_by) " - "values (:id,:project_id,'v1','draft','# Historical','legacy')" - ), - {"id": guide_id, "project_id": project_id}, - ) - await session.execute( - text( - "insert into guide_source_snapshots " - "(id,project_id,guide_id,guide_version,manifest_schema_version," - "manifest_json,bundle_hash,captured_by) values " - "(:id,:project_id,:guide_id,'v1','guide_source_snapshot.v1'," - "cast(:manifest as jsonb),:hash,'legacy')" - ), - { - "id": snapshot_id, - "project_id": project_id, - "guide_id": guide_id, - "manifest": '{"schema_version":"guide_source_snapshot.v1","items":[]}', - "hash": snapshot_hash, - }, - ) - await session.execute( - text( - "insert into project_setup_runs " - "(id,project_id,guide_id,guide_version,source_snapshot_id," - "source_snapshot_hash,setup_generation,status,current_step,created_by) " - "values (:id,:project_id,:guide_id,'v1',:snapshot_id,:hash,1," - "'queued','queued','legacy')" - ), - { - "id": setup_run_id, - "project_id": project_id, - "guide_id": guide_id, - "snapshot_id": snapshot_id, - "hash": snapshot_hash, - }, - ) - await session.commit() - return None - async with engine.connect() as connection: - guide_result = await connection.execute( - text( - "select mutation_generation,last_mutated_by_actor_profile_id," - "last_authorization_decision_event_id from project_guides where id=:id" - ), - {"id": guide_id}, - ) - snapshot_result = await connection.execute( - text( - "select creation_generation,created_by_actor_profile_id," - "authorization_decision_event_id from guide_source_snapshots where id=:id" - ), - {"id": snapshot_id}, - ) - setup_result = await connection.execute( - text( - "select authorized_by_actor_profile_id,authorized_via_identity_link_id," - "authorization_decision_event_id from project_setup_runs where id=:id" - ), - {"id": setup_run_id}, - ) - return (*guide_result.one(), *snapshot_result.one(), *setup_result.one()) - finally: - await engine.dispose() - - async def reset_schema() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text("drop schema public cascade")) - await connection.execute(text("create schema public")) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0044_project_create_authority") - asyncio.run(seed_and_read(seed=True)) - command.upgrade(config, "0045_guide_metadata_authority") - assert asyncio.run(seed_and_read(seed=False)) == (None,) * 9 - command.downgrade(config, "0044_project_create_authority") - command.upgrade(config, "0045_guide_metadata_authority") - assert asyncio.run(seed_and_read(seed=False)) == (None,) * 9 - with pytest.raises( - RuntimeError, - match="guide source v2 requires an empty guide-source namespace", - ): - command.upgrade(config, "0050_guide_source_v2") - finally: - asyncio.run(reset_schema()) - - -def test_0045_refuses_populated_guide_authority_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """Committed 12D custody prevents destructive downgrade.""" - config = _alembic_config() - - async def seed() -> None: - engine = create_async_engine(isolated_database_env) - try: - factory = async_sessionmaker(engine, expire_on_commit=False) - async with factory() as session: - project_id, guide_id = str(uuid4()), str(uuid4()) - await seed_authorized_project( - session, - project_id=project_id, - name="Guide downgrade custody", - slug=f"guide-downgrade-{uuid4()}", - ) - project_record = await session.scalar( - select(ProjectCreateIdempotencyRecord).where( - ProjectCreateIdempotencyRecord.project_id == project_id - ) - ) - assert project_record is not None - operation_id, decision_id = uuid4(), uuid4() - resource = ProjectGuideMutationResourceContext( - resource_type="project_guide_mutation", - resource_id=UUID(guide_id), - operation_id=operation_id, - scope_project_id=UUID(project_id), - guide_id=UUID(guide_id), - target_kind="create", - guide_exists=False, - operation_generation=1, - ) - resource_digest = authorization_resource_digest(resource) - audit_row = ( - await session.execute( - text( - "select id,matched_grant_id::uuid from audit_events " - "where action_id='project.create' and target_ref_id=:project_id" - ), - {"project_id": project_id}, - ) - ).one() - grant_id = audit_row[1] - assert grant_id is not None - await AuditService(session).add_authority_event( - AuthorityAuditEventInput( - event_id=decision_id, - event_type=AuthorityEventType.SENSITIVE_AUTHORIZATION_ALLOWED, - entity_type="authorization_decision", - entity_id=str(decision_id), - actor_ref_kind=ActorReferenceKind.ACTOR_PROFILE, - actor_ref=project_record.actor_profile_id, - request_id=uuid4(), - correlation_id=uuid4(), - matched_grant_id=str(grant_id), - permission_id=PermissionId.PROJECT_GUIDE_MANAGE, - action_id=ActionId.PROJECT_GUIDE_CREATE, - project_id=project_id, - resource_type="project", - resource_id=project_id, - target_ref_kind="project", - target_ref_id=project_id, - reason="authorization_evaluation", - after_facts={ - "allowed": True, - "resource_context_digest": resource_digest, - }, - ) - ) - reservation = GuideMutationIdempotencyRecord( - id=uuid4(), - actor_profile_id=project_record.actor_profile_id, - identity_link_id=project_record.identity_link_id, - action_id=ActionId.PROJECT_GUIDE_CREATE.value, - idempotency_key=uuid4(), - request_digest=canonical_json_hash( - {"domain": "workstream.test.guide_create", "guide_id": guide_id} - ), - resource_context_digest=resource_digest, - operation_id=operation_id, - project_id=project_id, - resource_id=guide_id, - operation_generation=1, - status="pending", - ) - session.add(reservation) - session.add( - ProjectGuide( - id=guide_id, - project_id=project_id, - version="v1", - status="draft", - content_markdown="# Custodied", - created_by=project_record.actor_profile_id, - mutation_generation=1, - last_mutated_by_actor_profile_id=project_record.actor_profile_id, - last_mutated_via_identity_link_id=project_record.identity_link_id, - last_mutated_by_admin_role_grant_id=grant_id, - last_mutation_scope_type="system", - last_mutation_action_id=ActionId.PROJECT_GUIDE_CREATE.value, - last_authorization_decision_event_id=str(decision_id), - ) - ) - await session.flush() - reservation.status = "committed" - reservation.response_json = {"id": guide_id} - reservation.committed_at = datetime.now(UTC) - await session.commit() - with pytest.raises(DBAPIError, match="activation authority"): - await session.execute( - text("update project_guides set status='active' where id=:id"), - {"id": guide_id}, - ) - await session.commit() - await session.rollback() - finally: - await engine.dispose() - - async def reset_schema() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text("drop schema public cascade")) - await connection.execute(text("create schema public")) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run(seed()) - with pytest.raises( - RuntimeError, match="cannot downgrade used guide source-metadata authority" - ): - command.downgrade(config, "0044_project_create_authority") - finally: - asyncio.run(reset_schema()) - - -def test_0036_art_auth_catalogue_round_trip(isolated_database_env: str, migration_lock) -> None: - """Prove the three replacement pairs and review permission round-trip exactly.""" - config = _alembic_config() - definitions = tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner in {ActionOwner.XINT_002_05A, ActionOwner.XINT_002_07} - ) - assert len(definitions) == 3 - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, definitions=definitions - ) - ) - asyncio.run(_assert_removed_art_authority_rejected(isolated_database_env)) - command.downgrade(config, "0033_authorization_read_rate") - command.upgrade(config, "head") - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, definitions=definitions - ) - ) - asyncio.run(_assert_removed_art_authority_rejected(isolated_database_env)) - finally: - command.downgrade(config, "base") - - -def test_0036_art_auth_catalogue_refuses_obsolete_evidence( - isolated_database_env: str, migration_lock -) -> None: - """Obsolete upload evidence must block catalogue deletion without mutation.""" - config = _alembic_config() - event_ids: list[str] = [] - record_id = str(uuid4()) - actor_id = str(uuid4()) - target_id = str(uuid4()) - obsolete = _OBSOLETE_ART_UPLOAD_IDS - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0035_project_read_evidence") - event_ids.extend( - asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, identifier, identifier - ) - ) - for identifier in obsolete - ) - event_ids.append( - asyncio.run( - _insert_forward_permission_reference( - isolated_database_env, - event_ids[0], - reference_field="target", - permission=obsolete[0], - ) - ) - ) - event_ids.append( - asyncio.run( - _insert_forward_permission_reference( - isolated_database_env, - event_ids[1], - reference_field="invalidation", - permission=obsolete[1], - ) - ) - ) - asyncio.run( - _insert_committed_authority_idempotency( - isolated_database_env, record_id, actor_id, target_id - ) - ) - event_ids.append( - asyncio.run( - _insert_linked_authorization_action_event( - isolated_database_env, - record_id=record_id, - actor_id=actor_id, - action_id=obsolete[2], - permission_id=obsolete[2], - ) - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, actions=obsolete, permissions=obsolete - ) - ) - with pytest.raises( - RuntimeError, - match="cannot remove non-empty obsolete artifact authority evidence", - ): - command.upgrade(config, "head") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, actions=obsolete, permissions=obsolete - ) - ) - == before - ) - for event_id in reversed(event_ids): - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - event_ids.clear() - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=None - ) - ) - record_id = "" - command.upgrade(config, "head") - assert asyncio.run(_current_revision(isolated_database_env)) == (HEAD_REVISION) - finally: - for event_id in reversed(event_ids): - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - if record_id: - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=None - ) - ) - command.downgrade(config, "base") - - -def test_0036_art_auth_catalogue_refuses_new_evidence_downgrade( - isolated_database_env: str, migration_lock -) -> None: - """Committed replacement-action evidence must block restoration of old authority.""" - config = _alembic_config() - definitions = tuple( - item - for item in ACTION_DEFINITIONS - if item.owner in {ActionOwner.XINT_002_05A, ActionOwner.XINT_002_07} - ) - event_ids: list[str] = [] - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - event_ids.extend( - asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, - definition.action_id.value, - definition.permission_id.value, - ) - ) - for definition in definitions - ) - review_permission = PermissionId.ARTIFACT_REVIEW_PACKET_MATERIALIZE.value - event_ids.append( - asyncio.run( - _insert_forward_permission_reference( - isolated_database_env, - event_ids[0], - reference_field="target", - permission=review_permission, - ) - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=tuple(item.action_id.value for item in definitions), - permissions=(review_permission,), - ) - ) - with pytest.raises( - RuntimeError, match="cannot downgrade non-empty ART authorization evidence" - ): - command.downgrade(config, "0035_project_read_evidence") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=tuple(item.action_id.value for item in definitions), - permissions=(review_permission,), - ) - ) - == before - ) - finally: - for event_id in reversed(event_ids): - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - command.downgrade(config, "base") - - -def test_0036_art_auth_catalogue_refuses_each_obsolete_evidence_shape( - isolated_database_env: str, migration_lock -) -> None: - """Prove every removal predicate independently blocks the clean-cut upgrade.""" - config = _alembic_config() - obsolete = _OBSOLETE_ART_UPLOAD_IDS - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0035_project_read_evidence") - for identifier in obsolete: - event_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, identifier, identifier - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(identifier,), - permissions=(identifier,), - ) - ) - with pytest.raises( - RuntimeError, - match="cannot remove non-empty obsolete artifact authority evidence", - ): - command.upgrade(config, "head") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(identifier,), - permissions=(identifier,), - ) - ) - == before - ) - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - - cause_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, - "actor.profile.read_self", - "actor.profile.read_self", - ) - ) - for reference_field, permission in ( - ("target", obsolete[0]), - ("invalidation", obsolete[1]), - ): - event_id = asyncio.run( - _insert_forward_permission_reference( - isolated_database_env, - cause_id, - reference_field=reference_field, - permission=permission, - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, actions=(), permissions=(permission,) - ) - ) - with pytest.raises( - RuntimeError, - match="cannot remove non-empty obsolete artifact authority evidence", - ): - command.upgrade(config, "head") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, actions=(), permissions=(permission,) - ) - ) - == before - ) - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, event_id=cause_id)) - - record_id, actor_id, target_id = str(uuid4()), str(uuid4()), str(uuid4()) - asyncio.run( - _insert_committed_authority_idempotency( - isolated_database_env, record_id, actor_id, target_id - ) - ) - event_id = asyncio.run( - _insert_linked_authorization_action_event( - isolated_database_env, - record_id=record_id, - actor_id=actor_id, - action_id=obsolete[2], - permission_id=obsolete[2], - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(obsolete[2],), - permissions=(obsolete[2],), - ) - ) - with pytest.raises( - RuntimeError, - match="cannot remove non-empty obsolete artifact authority evidence", - ): - command.upgrade(config, "head") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(obsolete[2],), - permissions=(obsolete[2],), - ) - ) - == before - ) - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, event_id=event_id)) - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=None - ) - ) - - orphan_event_id = asyncio.run( - _insert_orphan_linked_authorization_action_event( - isolated_database_env, - action_id=obsolete[3], - permission_id=obsolete[3], - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(obsolete[3],), - permissions=(obsolete[3],), - ) - ) - with pytest.raises( - RuntimeError, - match="cannot remove non-empty obsolete artifact authority evidence", - ): - command.upgrade(config, "head") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(obsolete[3],), - permissions=(obsolete[3],), - ) - ) - == before - ) - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=orphan_event_id) - ) - finally: - command.downgrade(config, "base") - - -def test_0036_art_auth_catalogue_refuses_each_new_evidence_shape( - isolated_database_env: str, migration_lock -) -> None: - """Prove each added action and permission independently blocks downgrade.""" - config = _alembic_config() - definitions = tuple( - item - for item in ACTION_DEFINITIONS - if item.owner in {ActionOwner.XINT_002_05A, ActionOwner.XINT_002_07} - ) - review_permission = PermissionId.ARTIFACT_REVIEW_PACKET_MATERIALIZE.value - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - for definition in definitions: - event_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, - definition.action_id.value, - definition.permission_id.value, - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(definition.action_id.value,), - permissions=(definition.permission_id.value,), - ) - ) - with pytest.raises( - RuntimeError, - match="cannot downgrade non-empty ART authorization evidence", - ): - command.downgrade(config, "0035_project_read_evidence") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(definition.action_id.value,), - permissions=(definition.permission_id.value,), - ) - ) - == before - ) - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - - cause_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, - "actor.profile.read_self", - "actor.profile.read_self", - ) - ) - for reference_field in ("target", "invalidation"): - event_id = asyncio.run( - _insert_forward_permission_reference( - isolated_database_env, - cause_id, - reference_field=reference_field, - permission=review_permission, - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(), - permissions=(review_permission,), - ) - ) - with pytest.raises( - RuntimeError, - match="cannot downgrade non-empty ART authorization evidence", - ): - command.downgrade(config, "0035_project_read_evidence") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(), - permissions=(review_permission,), - ) - ) - == before - ) - asyncio.run( - _remove_authority_audit_fixture(isolated_database_env, event_id=event_id) - ) - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, event_id=cause_id)) - - record_id, actor_id, target_id = str(uuid4()), str(uuid4()), str(uuid4()) - asyncio.run( - _insert_committed_authority_idempotency( - isolated_database_env, record_id, actor_id, target_id - ) - ) - linked_definition = definitions[0] - event_id = asyncio.run( - _insert_linked_authorization_action_event( - isolated_database_env, - record_id=record_id, - actor_id=actor_id, - action_id=linked_definition.action_id.value, - permission_id=linked_definition.permission_id.value, - ) - ) - before = asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(linked_definition.action_id.value,), - permissions=(linked_definition.permission_id.value,), - ) - ) - with pytest.raises( - RuntimeError, - match="cannot downgrade non-empty ART authorization evidence", - ): - command.downgrade(config, "0035_project_read_evidence") - assert ( - asyncio.run( - _art_catalogue_migration_state( - isolated_database_env, - actions=(linked_definition.action_id.value,), - permissions=(linked_definition.permission_id.value,), - ) - ) - == before - ) - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, event_id=event_id)) - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=None - ) - ) - finally: - command.downgrade(config, "base") - - -def test_project_role_migration_constraints_and_immutable_history( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0031 exact-role coexistence, evidence bounds, and lifecycle custody.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - result = asyncio.run(_exercise_project_role_migration(isolated_database_env)) - assert result == { - "revision": HEAD_REVISION, - "role_count": 3, - "invalid_availability": "23514", - "duplicate_role": "23505", - "snapshot_update": "55000", - "snapshot_delete": "55000", - "snapshot_truncate": "55000", - "issuance_update": "23514", - "grant_delete": "55000", - "grant_truncate": "55000", - "database_timestamps": True, - "snapshot_constraint_rejections": { - "extra_key": "23514", - "available_empty": "23514", - "unavailable_with_reference": "23514", - "url_reference": "23514", - "too_many_references": "23514", - "invalid_prior_uuid": "23514", - }, - "grant_constraint_rejections": { - "automated_method": "23514", - "combined_role": "23514", - "leading_space_reason": "23514", - "control_reason": "23514", - "oversize_reason": "23514", - "snapshot_mismatch": "23503", - "invalid_active_version": "23514", - }, - "valid_revoke": ("revoked", 2), - "second_revoke": "23514", - } - project_definitions = tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner in {ActionOwner.AUTH_10B, ActionOwner.AUTH_10C} - ) - assert len(project_definitions) == 5 - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, definitions=project_definitions - ) - ) - asyncio.run(_assert_project_role_denial_sql(isolated_database_env)) - finally: - command.downgrade(config, "base") - - -def test_project_role_upgrade_refuses_each_legacy_predicate_before_ddl( - isolated_database_env: str, - migration_lock, -) -> None: - """Every obsolete storage predicate leaves 0030 and its schema untouched.""" - config = _alembic_config() - cases = ( - {"before_facts": {"role": "both"}}, - {"after_facts": {"role": "both"}}, - {"before_facts": {"replaced_grant_id": str(uuid4())}}, - {"after_facts": {"replaced_grant_id": str(uuid4())}}, - {"event_type": "ProjectRoleGrantReplaced"}, - {"reason": "authority_replacement"}, - { - "before_facts": {"role": "both", "replaced_grant_id": str(uuid4())}, - "after_facts": {"role": "both", "replaced_grant_id": str(uuid4())}, - "event_type": "ProjectRoleGrantReplaced", - "reason": "authority_replacement", - }, - ) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0030_artifact_verification") - for patch in cases: - event_id, constraints, triggers = asyncio.run( - _install_legacy_project_role_blocker( - isolated_database_env, patch, bypass_constraints=True - ) - ) - before_event = asyncio.run(_project_role_audit_row(isolated_database_env, event_id)) - with pytest.raises( - RuntimeError, - match="cannot safely upgrade replacement-era project-role evidence", - ): - command.upgrade(config, "head") - assert asyncio.run(_project_role_refusal_state(isolated_database_env)) == ( - "0030_artifact_verification", - False, - False, - 1, - ) - assert ( - asyncio.run(_project_role_audit_row(isolated_database_env, event_id)) - == before_event - ) - asyncio.run( - _remove_legacy_project_role_blocker( - isolated_database_env, event_id, constraints, triggers - ) - ) - - for operation in ("project_role_grant.issue", "project_role_grant.revoke"): - record_id = asyncio.run( - _insert_project_role_idempotency_blocker(isolated_database_env, operation) - ) - before_record = asyncio.run( - _project_role_idempotency_row(isolated_database_env, record_id) - ) - with pytest.raises( - RuntimeError, - match="cannot safely upgrade replacement-era project-role evidence", - ): - command.upgrade(config, "head") - assert asyncio.run(_project_role_refusal_state(isolated_database_env))[:3] == ( - "0030_artifact_verification", - False, - False, - ) - assert ( - asyncio.run(_project_role_idempotency_row(isolated_database_env, record_id)) - == before_record - ) - asyncio.run( - _remove_project_role_idempotency_blocker(isolated_database_env, record_id) - ) - - event_id, constraints, triggers = asyncio.run( - _install_legacy_project_role_blocker( - isolated_database_env, - {"after_facts": {"role": "both"}}, - bypass_constraints=True, - ) - ) - record_id = asyncio.run( - _insert_project_role_idempotency_blocker( - isolated_database_env, "project_role_grant.revoke" - ) - ) - before_record = asyncio.run( - _project_role_idempotency_row(isolated_database_env, record_id) - ) - with pytest.raises( - RuntimeError, - match="cannot safely upgrade replacement-era project-role evidence", - ): - command.upgrade(config, "head") - assert ( - asyncio.run(_project_role_idempotency_row(isolated_database_env, record_id)) - == before_record - ) - asyncio.run(_remove_project_role_idempotency_blocker(isolated_database_env, record_id)) - asyncio.run( - _remove_legacy_project_role_blocker( - isolated_database_env, event_id, constraints, triggers - ) - ) - unrelated_event_id = asyncio.run( - _insert_authorization_action_event(isolated_database_env) - ) - unrelated_before = asyncio.run( - _project_role_audit_row(isolated_database_env, unrelated_event_id) - ) - command.upgrade(config, "head") - assert ( - asyncio.run(_project_role_audit_row(isolated_database_env, unrelated_event_id)) - == unrelated_before - ) - asyncio.run( - _remove_authorization_action_events(isolated_database_env, [unrelated_event_id]) - ) - finally: - command.downgrade(config, "base") - - -def test_project_role_downgrade_refuses_each_reserved_evidence_predicate( - isolated_database_env: str, - migration_lock, -) -> None: - """Every representable 10A audit predicate leaves head and row untouched.""" - config = _alembic_config() - cases = ( - *( - {"action_id": action} - for action in ( - "project.contributor_candidate.list", - "project_role_grant.list", - "project_role_grant.read", - "project_role_grant.issue", - "project_role_grant.revoke", - ) - ), - {"denial_code": "project_role_grant_already_revoked"}, - {"denial_code": "project_role_grant_replay_state_changed"}, - { - "action_id": "project_role_grant.issue", - "denial_code": "project_role_grant_replay_state_changed", - }, - ) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - for patch in cases: - event_id, constraints, triggers = asyncio.run( - _install_legacy_project_role_blocker( - isolated_database_env, patch, bypass_constraints=False - ) - ) - before_event = asyncio.run(_project_role_audit_row(isolated_database_env, event_id)) - with pytest.raises( - RuntimeError, match="cannot downgrade project-role grant evidence" - ): - command.downgrade(config, "0030_artifact_verification") - assert asyncio.run(_project_role_refusal_state(isolated_database_env))[:3] == ( - HEAD_REVISION, - True, - True, - ) - assert ( - asyncio.run(_project_role_audit_row(isolated_database_env, event_id)) - == before_event - ) - asyncio.run( - _remove_legacy_project_role_blocker( - isolated_database_env, event_id, constraints, triggers - ) - ) - for include_grant in (False, True): - table_ids = asyncio.run( - _install_project_role_table_blockers( - isolated_database_env, include_grant=include_grant - ) - ) - before_tables = asyncio.run( - _project_role_table_rows(isolated_database_env, table_ids) - ) - with pytest.raises( - RuntimeError, match="cannot downgrade project-role grant evidence" - ): - command.downgrade(config, "0030_artifact_verification") - assert asyncio.run(_project_role_refusal_state(isolated_database_env))[:3] == ( - HEAD_REVISION, - True, - True, - ) - assert ( - asyncio.run(_project_role_table_rows(isolated_database_env, table_ids)) - == before_tables - ) - asyncio.run(_remove_project_role_table_blockers(isolated_database_env, table_ids)) - command.downgrade(config, "0030_artifact_verification") - finally: - command.downgrade(config, "base") - - -def test_outbox_migration_schema_and_downgrade_writer_guard( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove exact 0029 schema plus ACCESS EXCLUSIVE commit/rollback behavior.""" - config = _alembic_config() - committed_project_id = str(uuid4()) - rolled_back_project_id = str(uuid4()) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - schema = asyncio.run(_outbox_schema(isolated_database_env)) - assert schema == { - "revision": HEAD_REVISION, - "columns": { - "aggregate_id", - "aggregate_type", - "archived_at", - "attempt_count", - "causation_event_id", - "claim_expires_at", - "claim_generation", - "claim_owner", - "claimed_at", - "correlation_id", - "delivery_state", - "event_id", - "event_type", - "event_version", - "finalized_at", - "idempotency_key", - "last_attempt_at", - "last_error_code", - "next_attempt_at", - "occurred_at", - "payload", - "payload_digest", - "producer", - "project_id", - }, - "nullable": { - "next_attempt_at", - "causation_event_id", - "claim_owner", - "claimed_at", - "claim_expires_at", - "last_attempt_at", - "last_error_code", - "finalized_at", - "archived_at", - }, - "indexes": { - "ix_outbox_events_aggregate", - "ix_outbox_events_eligible", - "ix_outbox_events_expired_claims", - "ix_outbox_events_project_drain", - "ix_outbox_events_retention", - "pk_outbox_events", - "uq_outbox_events_idempotency_key", - }, - "triggers": {"outbox_events_custody", "outbox_events_reject_truncate"}, - } - - committed = asyncio.run( - _outbox_downgrade_writer_race( - isolated_database_env, - config, - project_id=committed_project_id, - commit_writer=True, - ) - ) - assert committed == "refused_after_commit" - assert asyncio.run(_current_revision(isolated_database_env)) == (HEAD_REVISION) - asyncio.run(_remove_outbox_migration_row(isolated_database_env, committed_project_id)) - command.downgrade(config, "0028_artifact_admission") - assert "outbox_events" not in asyncio.run(_fetch_table_names(isolated_database_env)) - - command.upgrade(config, "head") - rolled_back = asyncio.run( - _outbox_downgrade_writer_race( - isolated_database_env, - config, - project_id=rolled_back_project_id, - commit_writer=False, - ) - ) - assert rolled_back == "succeeded_after_rollback" - assert asyncio.run(_current_revision(isolated_database_env)) == ( - "0028_artifact_admission" - ) - finally: - command.upgrade(config, "head") - asyncio.run(_remove_outbox_migration_row(isolated_database_env, committed_project_id)) - asyncio.run(_remove_outbox_migration_row(isolated_database_env, rolled_back_project_id)) - command.downgrade(config, "base") - - -def test_current_schema_uses_project_policy_contract( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove current schema stores guide prose and policy records separately.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - columns = asyncio.run(_fetch_columns(isolated_database_env)) - finally: - command.downgrade(config, "base") - - assert { - "projects.id", - "projects.name", - "projects.slug", - "projects.status", - "project_guides.content_markdown", - "project_guides.approved_by", - "project_guides.effective_at", - "submission_artifact_policies.policy_body", - "effective_project_submission_artifact_policies.effective_policy", - "pre_submit_checker_policies.compiled_bundle", - "checker_policies.source_snapshot_id", - "checker_policies.source_snapshot_hash", - "checker_policies.effective_policy_id", - "checker_policies.effective_policy_hash", - "checker_policies.pre_submit_checker_policy_id", - "checker_policies.pre_submit_checker_bundle_hash", - "payment_policies.base_amount", - "payment_policies.currency", - "artifact_contents.sha256", - "artifact_bindings.scope_version", - "artifact_storage_namespaces.namespace_fingerprint", - "artifact_replicas.provider_object_ref", - "artifact_replicas.storage_namespace_id", - "artifact_operation_receipts.request_digest", - "outbox_events.event_id", - "outbox_events.payload_digest", - "outbox_events.delivery_state", - }.issubset(columns) - discarded_columns = { - "projects.base_amount", - "projects.currency", - "project_guides.required_task_fields", - "project_guides.required_submission_fields", - "project_guides.task_instructions", - "project_guides.output_requirements", - "project_guides.acceptance_criteria", - "project_guides.rejection_criteria", - "project_guides.reviewer_rubric", - "project_guides.forbidden_actions", - "project_guides.required_skills", - "project_guides.difficulty_scale", - "project_guides.estimated_time_policy", - "project_guides.common_rejection_reasons", - "project_guides.evidence_policy", - "project_guides.unacceptable_work_policy", - "workstream_tasks.required_files", - "workstream_tasks.required_evidence", - "workstream_tasks.locked_checker_policy_version", - "submissions.locked_checker_policy_version", - "checker_runs.locked_checker_policy_version", - "artifact_upload_sessions.id", - "artifact_upload_items.id", - "artifact_replicas.provider_artifact_id", - "artifact_replicas.provider_manifest_id", - "artifact_replicas.retention_state", - "artifact_operation_receipts.provider_receipt_id", - "artifact_operation_receipts.retention_reference", - } - assert columns.isdisjoint(discarded_columns) - - -def test_post_submit_policy_upgrade_leaves_pre_provenance_rows_fail_closed( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0008 does not create fake post-submit authority for pre-provenance rows.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - pre_provenance_project_id = str(uuid4()) - pre_provenance_guide_id = str(uuid4()) - pre_provenance_policy_id = str(uuid4()) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0007_task_locked_context") - asyncio.run( - _seed_pre_provenance_post_submit_policy( - isolated_database_env, - pre_provenance_project_id, - pre_provenance_guide_id, - pre_provenance_policy_id, - ) - ) - command.upgrade(config, "0008_post_submit_checker_policy") - policy_hash = asyncio.run( - _fetch_pre_provenance_post_submit_policy_hash( - isolated_database_env, - pre_provenance_policy_id, - ) - ) - finally: - command.downgrade(config, "base") - - assert policy_hash is None - - -def test_post_submit_policy_upgrade_blocks_pre_provenance_runtime_rows( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0008 fails clearly when runtime rows cannot gain trusted provenance.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - ids = { - name: str(uuid4()) for name in ("project", "guide", "policy", "task", "submission", "run") - } - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0007_task_locked_context") - asyncio.run(_seed_pre_provenance_runtime_rows(isolated_database_env, ids)) - - with pytest.raises(RuntimeError, match="cannot infer locked post-submit"): - command.upgrade(config, "0008_post_submit_checker_policy") - - columns_exist = asyncio.run( - _post_submit_lock_columns_exist(isolated_database_env, "submissions") - ) - finally: - command.downgrade(config, "base") - - assert columns_exist is False - - -def test_canonical_actor_registry_separates_authority_from_legacy_workflow_metadata( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove obsolete profile tables are removed from the current schema.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0021_auth_action_evidence") - table_names = asyncio.run(_fetch_table_names(isolated_database_env)) - finally: - command.downgrade(config, "base") - - assert "actor_profiles" in table_names - assert "actor_identity_links" in table_names - assert "legacy_actor_identities" in table_names - assert "legacy_workflow_eligibility" in table_names - assert "actor_identities" not in table_names - assert "worker_profiles" not in table_names - assert "reviewer_profiles" not in table_names - - -def test_canonical_actor_upgrade_rejects_unclassified_legacy_rows( - isolated_database_env: str, - migration_lock, - monkeypatch: pytest.MonkeyPatch, -) -> None: - """Fail closed before changing tables when non-empty legacy data is ambiguous.""" - config = _alembic_config() - actor_id = actor_id_from_external_identity( - "https://identity.test", - "unclassified-human", - ) - monkeypatch.delenv(CLASSIFICATION_FILE_ENV, raising=False) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0019_authority_idempotency") - asyncio.run( - _seed_pre_0020_actor( - isolated_database_env, - actor_id=actor_id, - subject="unclassified-human", - ) - ) - - with pytest.raises( - LegacyClassificationError, - match="^classification_file_not_configured$", - ): - command.upgrade(config, "0020_canonical_actor_profile") - - state = asyncio.run(_pre_0020_actor_state(isolated_database_env, actor_id)) - finally: - command.downgrade(config, "base") - - assert state == {"revision": "0019_authority_idempotency", "legacy_rows": 1} - - -def test_canonical_actor_upgrade_redacts_invalid_legacy_row_values( - isolated_database_env: str, - migration_lock, - monkeypatch: pytest.MonkeyPatch, -) -> None: - """Keep invalid source identity values out of migration diagnostics.""" - config = _alembic_config() - raw_actor_id = "raw-private-invalid-actor-id" - monkeypatch.delenv(CLASSIFICATION_FILE_ENV, raising=False) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0019_authority_idempotency") - asyncio.run( - _seed_pre_0020_actor( - isolated_database_env, - actor_id=raw_actor_id, - subject="raw-private-subject", - ) - ) - with pytest.raises(LegacyClassificationError) as captured: - command.upgrade(config, "0020_canonical_actor_profile") - assert str(captured.value) == "invalid_source_rows" - assert raw_actor_id not in str(captured.value) - state = asyncio.run(_pre_0020_actor_state(isolated_database_env, raw_actor_id)) - finally: - command.downgrade(config, "base") - - assert state == {"revision": "0019_authority_idempotency", "legacy_rows": 1} - - -def test_canonical_actor_classified_upgrade_preserves_identity_and_attribution( - isolated_database_env: str, - migration_lock, - monkeypatch: pytest.MonkeyPatch, - tmp_path: Path, -) -> None: - """Consume bound evidence once and downgrade later without the external file.""" - config = _alembic_config() - issuer = "https://identity.test" - subject = "classified-human" - actor_id = actor_id_from_external_identity(issuer, subject) - audit_event_id = str(uuid4()) - envelope_path = tmp_path / "classification-envelope.json" - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0019_authority_idempotency") - asyncio.run( - _seed_pre_0020_actor( - isolated_database_env, - actor_id=actor_id, - subject=subject, - audit_event_id=audit_event_id, - ) - ) - binding = asyncio.run(_legacy_database_binding(isolated_database_env)) - row = LegacyActorRow(actor_id=actor_id, issuer=issuer, subject=subject) - envelope = build_envelope( - LegacyActorClassificationManifest( - schema_version=1, - classifications=( - LegacyActorClassification( - actor_id=actor_id, - issuer=issuer, - subject=subject, - subject_kind="human", - ), - ), - ), - (row,), - database_binding=binding, - generated_at="2026-07-15T12:00:00Z", - ) - envelope_path.write_bytes(canonical_envelope_bytes(envelope)) - os.chmod(envelope_path, 0o600) - monkeypatch.setenv(CLASSIFICATION_FILE_ENV, str(envelope_path)) - - command.upgrade(config, "0020_canonical_actor_profile") - upgraded = asyncio.run( - _canonical_actor_migration_state( - isolated_database_env, - actor_id, - audit_event_id, - ) - ) - asyncio.run( - _update_canonical_actor_display_fields( - isolated_database_env, - actor_id, - display_name="Canonical Human", - contact_email=None, - ) - ) - envelope_path.unlink() - monkeypatch.delenv(CLASSIFICATION_FILE_ENV, raising=False) - command.downgrade(config, "0019_authority_idempotency") - restored = asyncio.run(_pre_0020_actor_state(isolated_database_env, actor_id)) - restored_display = asyncio.run( - _pre_0020_actor_display_fields(isolated_database_env, actor_id) - ) - with pytest.raises( - LegacyClassificationError, - match="^classification_file_not_configured$", - ): - command.upgrade(config, "0020_canonical_actor_profile") - reupgrade_rejected = asyncio.run(_pre_0020_actor_state(isolated_database_env, actor_id)) - finally: - command.downgrade(config, "base") - - assert upgraded == { - "profile_id": actor_id, - "actor_kind": "human", - "display_name": None, - "contact_email": None, - "identity_link_id": str(uuid5(NAMESPACE_URL, f"workstream:identity-link:{actor_id}")), - "identity_subject": subject, - "legacy_profile_type": "worker", - "audit_actor_id": actor_id, - "classified_count": 1, - "source_checksum": envelope.source_row_set_sha256, - } - assert restored == {"revision": "0019_authority_idempotency", "legacy_rows": 1} - assert restored_display == { - "display_name": "Canonical Human", - "email": None, - } - assert reupgrade_rejected == restored - - -def test_actor_profile_registry_unique_constraints_are_enforced( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove actor registry uniqueness is enforced by Postgres.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run(_assert_actor_registry_unique_constraints(isolated_database_env)) - finally: - command.downgrade(config, "base") - - -def test_canonical_actor_downgrade_refuses_nonactive_authority_state( - isolated_database_env: str, - migration_lock, -) -> None: - """Prevent rollback from silently restoring revoked or inactive actors.""" - config = _alembic_config() - actor_id = actor_id_from_external_identity("https://identity.test", "rollback-guard") - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - retained_revision = asyncio.run(_current_revision(isolated_database_env)) - asyncio.run(_seed_canonical_actor_for_downgrade_guard(isolated_database_env, actor_id)) - for state in ("revoked", "suspended", "deactivated"): - asyncio.run( - _set_canonical_actor_guard_state(isolated_database_env, actor_id, state) - ) - with pytest.raises( - RuntimeError, - match="^canonical actor downgrade refused: inactive authority state$", - ): - command.downgrade(config, "0019_authority_idempotency") - assert asyncio.run(_current_revision(isolated_database_env)) == retained_revision - asyncio.run( - _reset_canonical_actor_guard_state( - isolated_database_env, - actor_id, - ) - ) - command.downgrade(config, "0019_authority_idempotency") - finally: - command.downgrade(config, "base") - - -def test_authorization_action_evidence_constraints_and_guarded_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove exact action parity, rollback custody, and downgrade locking.""" - config = _alembic_config() - historical_event = str(uuid4()) - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0020_canonical_actor_profile") - asyncio.run(_insert_authority_audit_fixture(isolated_database_env, historical_event)) - historical_before = asyncio.run( - _authorization_action_row(isolated_database_env, historical_event) - ) - command.upgrade(config, "0021_auth_action_evidence") - schema = asyncio.run(_authorization_action_schema(isolated_database_env)) - historical_upgraded = asyncio.run( - _authorization_action_row(isolated_database_env, historical_event) - ) - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, - definitions=tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner - not in { - ActionOwner.AUTH_08, - ActionOwner.AUTH_09B, - ActionOwner.AUTH_09C, - ActionOwner.AUTH_09D_A, - ActionOwner.AUTH_09D_B, - ActionOwner.AUTH_10B, - ActionOwner.AUTH_10C, - ActionOwner.AUTH_11B, - ActionOwner.AUTH_11C1, - ActionOwner.AUTH_11C2, - *_PROJECT_MUTATION_OWNERS, - ActionOwner.XINT_002_05A, - ActionOwner.XINT_002_07, - ActionOwner.XINT_003_08A, - ActionOwner.XINT_003_08B, - ActionOwner.AUTH_12I, - } - ), - ) - ) - action_event = asyncio.run(_insert_authorization_action_event(isolated_database_env)) - with pytest.raises( - RuntimeError, - match="^cannot downgrade non-empty authorization action evidence$", - ): - command.downgrade(config, "0020_canonical_actor_profile") - asyncio.run(_remove_authorization_action_events(isolated_database_env, [action_event])) - permission_event = asyncio.run( - _insert_authorization_action_event(isolated_database_env) - ) - asyncio.run( - _convert_to_permission_only_forward_evidence( - isolated_database_env, permission_event - ) - ) - with pytest.raises( - RuntimeError, - match="^cannot downgrade non-empty authorization action evidence$", - ): - command.downgrade(config, "0020_canonical_actor_profile") - asyncio.run( - _remove_authorization_action_events(isolated_database_env, [permission_event]) - ) - - target_reference_event = asyncio.run( - _insert_forward_permission_reference( - isolated_database_env, - historical_event, - reference_field="target", - ) - ) - with pytest.raises( - RuntimeError, - match="^cannot downgrade non-empty authorization action evidence$", - ): - command.downgrade(config, "0020_canonical_actor_profile") - asyncio.run( - _remove_authorization_action_events(isolated_database_env, [target_reference_event]) - ) - - invalidation_reference_event = asyncio.run( - _insert_forward_permission_reference( - isolated_database_env, - historical_event, - reference_field="invalidation", - ) - ) - with pytest.raises( - RuntimeError, - match="^cannot downgrade non-empty authorization action evidence$", - ): - command.downgrade(config, "0020_canonical_actor_profile") - asyncio.run( - _remove_authorization_action_events( - isolated_database_env, [invalidation_reference_event] - ) - ) - - command.downgrade(config, "0020_canonical_actor_profile") - downgraded = asyncio.run(_authorization_action_schema(isolated_database_env)) - historical_downgraded = asyncio.run( - _authorization_action_row(isolated_database_env, historical_event) - ) - asyncio.run(_assert_historical_permission_registry(isolated_database_env)) - asyncio.run( - _remove_authorization_action_events(isolated_database_env, [historical_event]) - ) - command.upgrade(config, "0021_auth_action_evidence") - - lock_observed, raced_event = _action_downgrade_waits_for_insert( - config, isolated_database_env - ) - asyncio.run(_remove_authorization_action_events(isolated_database_env, [raced_event])) - command.downgrade(config, "0020_canonical_actor_profile") - command.upgrade(config, "0021_auth_action_evidence") - finally: - command.downgrade(config, "base") - - assert schema == { - "revision": "0021_auth_action_evidence", - "action_column": True, - "action_constraint": True, - } - assert downgraded == { - "revision": "0020_canonical_actor_profile", - "action_column": False, - "action_constraint": False, - } - expected_historical = { - "event_type": "SensitiveAuthorizationAllowed", - "permission_id": "actor.profile.read_any", - "action_id": None, - } - assert historical_before == expected_historical - assert historical_upgraded == expected_historical - assert historical_downgraded == expected_historical - assert lock_observed is True - - -def test_bootstrap_admin_grant_schema_is_immutable_and_guarded( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove clean migration reversibility and irreversible grant history guards.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0021_auth_action_evidence") - for event_type in ( - "InitialAccessAdministratorBootstrapped", - "AdminRoleGrantIssueDenied", - "LastAccessAdministratorOperationDenied", - ): - asyncio.run(_insert_orphan_admin_evidence(isolated_database_env, event_type)) - with pytest.raises( - RuntimeError, - match="^cannot adopt orphan administrative grant evidence$", - ): - command.upgrade(config, "0022_bootstrap_admin_grants") - asyncio.run(_clear_orphan_admin_state(isolated_database_env)) - asyncio.run(_insert_orphan_admin_idempotency(isolated_database_env)) - with pytest.raises( - RuntimeError, - match="^cannot adopt orphan administrative idempotency$", - ): - command.upgrade(config, "0022_bootstrap_admin_grants") - asyncio.run(_clear_orphan_admin_state(isolated_database_env)) - command.upgrade(config, "0022_bootstrap_admin_grants") - assert asyncio.run(_admin_authority_schema(isolated_database_env)) == { - "revision": "0022_bootstrap_admin_grants", - "grant_table": True, - "control": (False, None, 0), - } - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, - definitions=tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner - not in { - ActionOwner.AUTH_09B, - ActionOwner.AUTH_09C, - ActionOwner.AUTH_09D_A, - ActionOwner.AUTH_09D_B, - ActionOwner.AUTH_10B, - ActionOwner.AUTH_10C, - ActionOwner.AUTH_11B, - ActionOwner.AUTH_11C1, - ActionOwner.AUTH_11C2, - *_PROJECT_MUTATION_OWNERS, - ActionOwner.XINT_002_05A, - ActionOwner.XINT_002_07, - ActionOwner.XINT_003_08A, - ActionOwner.XINT_003_08B, - ActionOwner.AUTH_12I, - } - ), - ) - ) - command.downgrade(config, "0021_auth_action_evidence") - command.upgrade(config, "0022_bootstrap_admin_grants") - proof = asyncio.run(_exercise_admin_authority_guards(isolated_database_env)) - assert proof == { - "service_target_rejected": True, - "missing_authorizer_rejected": True, - "mixed_bootstrap_attribution_rejected": True, - "orphan_bootstrap_commit_rejected": True, - "mismatched_bootstrap_control_rejected": True, - "second_bootstrap_rejected": True, - "immutable_provenance_rejected": True, - "incomplete_revocation_rejected": True, - "immutable_provenance_preserved": True, - "immutable_reason_rejected": True, - "delete_rejected": True, - "truncate_rejected": True, - "control_reset_rejected": True, - "revoked_status": "revoked", - "revoked_version": 2, - "grant_reason": "Operations assignment", - "revoked_reason": "Rotation ended", - "bootstrap_completed": True, - } - with pytest.raises( - RuntimeError, - match="^cannot downgrade non-empty administrative authority$", - ): - command.downgrade(config, "0021_auth_action_evidence") - asyncio.run(_clear_admin_authority_guard_fixtures(isolated_database_env)) - command.downgrade(config, "0021_auth_action_evidence") - command.upgrade(config, "0022_bootstrap_admin_grants") - finally: - command.downgrade(config, "base") - - -def test_fixed_service_identity_schema_mapping_and_guarded_downgrade( - isolated_database_env: str, - migration_lock, - tmp_path: Path, - monkeypatch: pytest.MonkeyPatch, -) -> None: - """Prove exact legacy mapping, static action parity, and destructive rollback guards.""" - config = _alembic_config() - service_id = actor_id_from_external_identity("https://identity.test", "auth09-legacy-service") - envelope_path = tmp_path / "service-identity-envelope.json" - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0022_bootstrap_admin_grants") - command.upgrade(config, "0023_service_actor_identity") - assert asyncio.run(_service_identity_schema(isolated_database_env)) == { - "revision": "0023_service_actor_identity", - "service_identity_column": True, - "mapped_count": 0, - "manifest_digest": None, - "envelope_digest": None, - } - asyncio.run( - _assert_authorization_action_sql_pairs( - isolated_database_env, - definitions=tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner - in { - ActionOwner.AUTH_09B, - ActionOwner.AUTH_09C, - ActionOwner.AUTH_09D_A, - ActionOwner.AUTH_09D_B, - } - ), - ) - ) - command.downgrade(config, "0022_bootstrap_admin_grants") - - asyncio.run( - _insert_service_actor_before_fixed_identity( - isolated_database_env, - service_id, - "auth09-legacy-service", - ) - ) - monkeypatch.delenv(MAPPING_FILE_ENV, raising=False) - with pytest.raises( - FrozenServiceIdentityMappingError, - match="^service_mapping_required$", - ): - command.upgrade(config, "0023_service_actor_identity") - assert asyncio.run(_current_revision(isolated_database_env)) == ( - "0022_bootstrap_admin_grants" - ) - - asyncio.run( - _write_service_identity_envelope( - isolated_database_env, - envelope_path, - ) - ) - monkeypatch.setenv(MAPPING_FILE_ENV, str(envelope_path)) - command.upgrade(config, "0023_service_actor_identity") - mapped = asyncio.run(_service_identity_schema(isolated_database_env)) - assert mapped["revision"] == "0023_service_actor_identity" - assert mapped["service_identity"] == "workstream.artifact.verifier" - assert mapped["mapped_count"] == 1 - for digest_key in ("source_digest", "manifest_digest", "envelope_digest"): - digest = mapped[digest_key] - assert isinstance(digest, str) - assert len(digest) == 64 - assert mapped["private_evidence_columns"] is False - assert asyncio.run(_service_identity_guards(isolated_database_env, service_id)) == { - "identity_update_rejected": True, - "kind_update_rejected": True, - "human_identity_rejected": True, - "unknown_identity_rejected": True, - "duplicate_identity_rejected": True, - } - assert asyncio.run(_service_identity_evidence_guards(isolated_database_env)) == { - "update_rejected": True, - "delete_rejected": True, - "truncate_rejected": True, - "invalid_count_rejected": True, - "invalid_source_digest_rejected": True, - "invalid_manifest_digest_rejected": True, - "invalid_database_binding_rejected": True, - } - with pytest.raises( - RuntimeError, - match="^cannot downgrade fixed service identity authority$", - ): - command.downgrade(config, "0022_bootstrap_admin_grants") - asyncio.run(_remove_fixed_service_actor(isolated_database_env, service_id)) - command.downgrade(config, "0022_bootstrap_admin_grants") - monkeypatch.delenv(MAPPING_FILE_ENV, raising=False) - command.upgrade(config, "0023_service_actor_identity") - - auth09_definitions = tuple( - definition - for definition in ACTION_DEFINITIONS - if definition.owner - in { - ActionOwner.AUTH_09B, - ActionOwner.AUTH_09C, - ActionOwner.AUTH_09D_A, - ActionOwner.AUTH_09D_B, - } - ) - assert len(auth09_definitions) == 8 - for definition in auth09_definitions: - event_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, - definition.action_id.value, - definition.permission_id.value, - ) - ) - with pytest.raises( - RuntimeError, - match="^cannot downgrade fixed service identity authority$", - ): - command.downgrade(config, "0022_bootstrap_admin_grants") - asyncio.run(_remove_authorization_action_events(isolated_database_env, [event_id])) - command.downgrade(config, "0022_bootstrap_admin_grants") - command.upgrade(config, "0023_service_actor_identity") - finally: - monkeypatch.delenv(MAPPING_FILE_ENV, raising=False) - command.downgrade(config, "base") - - -def test_service_link_verification_timestamp_schema_and_guarded_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Allow null verification only for services and refuse proof-losing rollback.""" - config = _alembic_config() - human_id, human_link_id = str(uuid4()), str(uuid4()) - rejected_human_id, rejected_human_link_id = str(uuid4()), str(uuid4()) - service_id, service_link_id = str(uuid4()), str(uuid4()) - - async def seed_human_before_upgrade() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:id,'human','active','automatic_first_access',:id)" - ), - {"id": human_id}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by) " - "values (:link,:actor,'issuer-0024','human-0024','human','active',:actor)" - ), - {"link": human_link_id, "actor": human_id}, - ) - finally: - await engine.dispose() - - async def schema_state() -> dict[str, object]: - engine = create_async_engine(isolated_database_env) - try: - async with engine.connect() as connection: - column = ( - ( - await connection.execute( - text( - "select is_nullable,column_default from information_schema.columns " - "where table_schema='public' and table_name='actor_identity_links' " - "and column_name='last_verified_at'" - ) - ) - ) - .mappings() - .one() - ) - human_verified = await connection.scalar( - text( - "select last_verified_at is not null from actor_identity_links where id=:id" - ), - {"id": human_link_id}, - ) - constraint = await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint where " - "conrelid='actor_identity_links'::regclass and " - "conname='ck_actor_identity_links_human_verified'" - ) - ) - return { - "nullable": column["is_nullable"], - "default": column["column_default"], - "human_verified": human_verified, - "constraint": constraint, - } - finally: - await engine.dispose() - - async def insert_service_and_reject_null_human() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,service_identity,created_by) " - "values (:id,'service','active','manual_service_provisioning'," - "'workstream.artifact.verifier',:id)" - ), - {"id": service_id}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by," - "last_verified_at) values (:link,:actor,'issuer-0024','service-0024'," - "'service','active',:actor,null)" - ), - {"link": service_link_id, "actor": service_id}, - ) - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:id,'human','active','automatic_first_access',:id)" - ), - {"id": rejected_human_id}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by," - "last_verified_at) values (:link,:actor,'issuer-0024'," - "'rejected-human-0024','human','active',:actor,null)" - ), - {"link": rejected_human_link_id, "actor": rejected_human_id}, - ) - finally: - await engine.dispose() - - async def make_service_downgrade_safe() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_identity_links set last_verified_at=clock_timestamp() " - "where id=:id" - ), - {"id": service_link_id}, - ) - finally: - await engine.dispose() - - async def cleanup() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text("alter table actor_identity_links disable trigger user") - ) - await connection.execute(text("alter table actor_profiles disable trigger user")) - await connection.execute( - text( - "delete from actor_identity_links where id in (:human_link,:service_link)" - ), - {"human_link": human_link_id, "service_link": service_link_id}, - ) - await connection.execute( - text( - "delete from actor_profiles where id in (:human,:rejected_human,:service)" - ), - { - "human": human_id, - "rejected_human": rejected_human_id, - "service": service_id, - }, - ) - await connection.execute(text("alter table actor_profiles enable trigger user")) - await connection.execute( - text("alter table actor_identity_links enable trigger user") - ) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0023_service_actor_identity") - asyncio.run(seed_human_before_upgrade()) - command.upgrade(config, "0024_service_link_verification") - state = asyncio.run(schema_state()) - assert state["nullable"] == "YES" - assert state["default"] is None - assert state["human_verified"] is True - assert "subject_kind" in str(state["constraint"]) - assert "last_verified_at IS NOT NULL" in str(state["constraint"]) - asyncio.run(insert_service_and_reject_null_human()) - with pytest.raises( - RuntimeError, - match="^cannot downgrade with unverified service identity links$", - ): - command.downgrade(config, "0023_service_actor_identity") - assert asyncio.run(_current_revision(isolated_database_env)) == ( - "0024_service_link_verification" - ) - asyncio.run(make_service_downgrade_safe()) - command.downgrade(config, "0023_service_actor_identity") - historical = asyncio.run(schema_state()) - assert historical["nullable"] == "NO" - assert "now()" in str(historical["default"]) - assert historical["constraint"] is None - command.upgrade(config, "0024_service_link_verification") - asyncio.run(cleanup()) - finally: - try: - asyncio.run(make_service_downgrade_safe()) - asyncio.run(cleanup()) - except DBAPIError: - pass - command.downgrade(config, "base") - - -def test_artifact_foundation_upgrade_preserves_prior_head_and_promotes_nothing( - isolated_database_env: str, - migration_lock, -) -> None: - """Upgrade populated 0015 data without interpreting legacy declarations.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - project_id = str(uuid4()) - runtime_ids = { - name: str(uuid4()) - for name in ( - "project", - "guide", - "snapshot", - "submission_policy", - "effective_policy", - "pre_submit_policy", - "policy", - "review_policy", - "revision_policy", - "payment_policy", - "task", - "submission", - "run", - ) - } - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0015_post_submit_correction") - asyncio.run(_seed_artifact_prior_head(isolated_database_env, project_id)) - asyncio.run(_seed_artifact_prior_head_runtime_rows(isolated_database_env, runtime_ids)) - before = asyncio.run(_artifact_prior_head_project(isolated_database_env, project_id)) - runtime_before = asyncio.run( - _artifact_prior_head_runtime_rows(isolated_database_env, runtime_ids) - ) - command.upgrade(config, "0016_artifact_domain") - after = asyncio.run(_artifact_prior_head_project(isolated_database_env, project_id)) - runtime_after = asyncio.run( - _artifact_prior_head_runtime_rows(isolated_database_env, runtime_ids) - ) - artifact_counts = asyncio.run(_artifact_table_counts(isolated_database_env)) - finally: - command.downgrade(config, "base") - - assert after == before - assert runtime_after == runtime_before - assert artifact_counts == {name: 0 for name in artifact_counts} - - -def test_artifact_foundation_enforces_immutable_facts_and_guarded_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove PostgreSQL rejects malformed/mutable facts and non-empty downgrade.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - ids = { - name: str(uuid4()) - for name in ( - "project", - "content", - "session", - "item", - "replica", - "receipt", - "binding", - "binding_v2", - ) - } - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0016_artifact_domain") - asyncio.run(_assert_artifact_fact_guards(isolated_database_env, ids)) - with pytest.raises(RuntimeError, match="non-empty artifact foundation"): - command.downgrade(config, "0015_post_submit_correction") - asyncio.run(_truncate_artifact_foundation(isolated_database_env)) - command.downgrade(config, "0015_post_submit_correction") - command.upgrade(config, "0016_artifact_domain") - assert all( - count == 0 - for count in asyncio.run(_artifact_table_counts(isolated_database_env)).values() - ) - finally: - command.downgrade(config, "base") - - -def test_artifact_store_v2_empty_clean_cut_and_reversible_shape( - isolated_database_env: str, - migration_lock, -) -> None: - """Migrate only empty v1 tables and restore their empty shape on downgrade.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0023_service_actor_identity") - command.upgrade(config, "0025_artifact_store_v2") - v2_columns = asyncio.run(_fetch_columns(isolated_database_env)) - command.downgrade(config, "0023_service_actor_identity") - v1_columns = asyncio.run(_fetch_columns(isolated_database_env)) - command.upgrade(config, "0025_artifact_store_v2") - finally: - command.downgrade(config, "base") - - assert { - "artifact_storage_namespaces.namespace_fingerprint", - "artifact_upload_items.provider_object_ref", - "artifact_replicas.storage_namespace_id", - "artifact_replicas.namespace_fingerprint", - "artifact_replicas.provider_profile", - "artifact_replicas.provider_object_ref", - "artifact_operation_receipts.replayed", - }.issubset(v2_columns) - assert { - "artifact_upload_items.provider_operation_reference", - "artifact_replicas.provider_artifact_id", - "artifact_replicas.provider_manifest_id", - "artifact_replicas.retention_state", - "artifact_operation_receipts.provider_receipt_id", - "artifact_operation_receipts.retention_reference", - }.issubset(v1_columns) - assert { - "artifact_upload_items.provider_object_ref", - "artifact_replicas.storage_namespace_id", - "artifact_replicas.namespace_fingerprint", - "artifact_replicas.provider_profile", - "artifact_replicas.provider_object_ref", - "artifact_operation_receipts.provider_object_ref", - "artifact_operation_receipts.replayed", - }.isdisjoint(v1_columns) - assert "artifact_storage_namespaces.id" not in v1_columns - - -def test_artifact_store_v2_refuses_populated_v1_before_ddl( - isolated_database_env: str, - migration_lock, -) -> None: - """Never fabricate namespace or verification provenance for a v1 row.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0023_service_actor_identity") - asyncio.run(_seed_artifact_content(isolated_database_env)) - with pytest.raises( - RuntimeError, - match="artifact storage clean cut requires empty pre-production tables", - ): - command.upgrade(config, "0025_artifact_store_v2") - refused = asyncio.run(_artifact_v2_refusal_state(isolated_database_env)) - asyncio.run(_truncate_artifact_foundation(isolated_database_env)) - command.upgrade(config, "0025_artifact_store_v2") - finally: - command.downgrade(config, "base") - - assert refused == { - "revision": "0023_service_actor_identity", - "namespace_table_exists": False, - "v1_content_count": 1, - } - - -def test_artifact_store_v2_refuses_populated_v2_downgrade_before_ddl( - isolated_database_env: str, - migration_lock, -) -> None: - """Never drop a namespace-only v2 deployment fence during downgrade.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0025_artifact_store_v2") - asyncio.run(_seed_v2_artifact_namespace(isolated_database_env)) - with pytest.raises( - RuntimeError, - match="artifact storage clean cut requires empty pre-production tables", - ): - command.downgrade(config, "0023_service_actor_identity") - refused_revision = asyncio.run(_current_revision(isolated_database_env)) - refused_columns = asyncio.run(_fetch_columns(isolated_database_env)) - refused_namespace_count = asyncio.run(_artifact_namespace_count(isolated_database_env)) - asyncio.run(_truncate_v2_artifact_namespace(isolated_database_env)) - command.downgrade(config, "0023_service_actor_identity") - finally: - asyncio.run(_truncate_v2_artifact_namespace(isolated_database_env)) - command.downgrade(config, "base") - - assert refused_revision == "0025_artifact_store_v2" - assert refused_namespace_count == 1 - assert "artifact_replicas.provider_object_ref" in refused_columns - - -def test_artifact_store_v2_waits_for_concurrent_v1_writer_and_refuses( - isolated_database_env: str, - migration_lock, -) -> None: - """Serialize the clean-cut emptiness check against every v1 writer.""" - config = _alembic_config() - inserted = threading.Event() - release_insert = threading.Event() - upgrade_started = threading.Event() - - def guarded_upgrade() -> None: - upgrade_started.set() - command.upgrade(config, "0025_artifact_store_v2") - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0023_service_actor_identity") - with ThreadPoolExecutor(max_workers=2) as pool: - insert_future = pool.submit( - asyncio.run, - _insert_v1_artifact_content_until_released( - isolated_database_env, - inserted, - release_insert, - ), - ) - assert inserted.wait(timeout=5) - upgrade_future = pool.submit(guarded_upgrade) - assert upgrade_started.wait(timeout=5) - time.sleep(0.2) - assert upgrade_future.done() is False - release_insert.set() - insert_future.result(timeout=5) - with pytest.raises( - RuntimeError, - match="artifact storage clean cut requires empty pre-production tables", - ): - upgrade_future.result(timeout=5) - - refused = asyncio.run(_artifact_v2_refusal_state(isolated_database_env)) - asyncio.run(_truncate_artifact_foundation(isolated_database_env)) - command.upgrade(config, "0025_artifact_store_v2") - finally: - release_insert.set() - asyncio.run(_truncate_artifact_foundation(isolated_database_env)) - command.downgrade(config, "base") - - assert refused == { - "revision": "0023_service_actor_identity", - "namespace_table_exists": False, - "v1_content_count": 1, - } - - -def test_actor_profile_lifecycle_fresh_and_prior_head_upgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Install 0026 from the exact prior head and preserve reversible shape.""" - config = _alembic_config() - - async def shape() -> tuple[str, bool, bool]: - engine = create_async_engine(isolated_database_env) - try: - async with engine.connect() as connection: - return ( - str(await connection.scalar(text("select version_num from alembic_version"))), - bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_name='actor_profiles' and column_name='reactivated_at')" - ) - ) - ), - bool( - await connection.scalar( - text( - "select exists(select 1 from pg_constraint where " - "conname='ck_actor_identity_links_reactivation_fields')" - ) - ) - ), - ) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0025_artifact_store_v2") - prior_shape = ("0025_artifact_store_v2", False, False) - lifecycle_shape = ("0026_actor_profile_lifecycle", True, True) - assert asyncio.run(shape()) == prior_shape - command.upgrade(config, "0026_actor_profile_lifecycle") - assert asyncio.run(shape()) == lifecycle_shape - command.downgrade(config, "0025_artifact_store_v2") - assert asyncio.run(shape()) == prior_shape - command.upgrade(config, "0026_actor_profile_lifecycle") - assert asyncio.run(shape()) == lifecycle_shape - finally: - command.downgrade(config, "base") - - -def test_actor_profile_lifecycle_constraint_and_trigger_parity( - isolated_database_env: str, - migration_lock, -) -> None: - """Enforce normalized attribution and only legal profile lifecycle transitions.""" - config = _alembic_config() - actor_id = str(uuid4()) - - async def prove_guards() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await _insert_canonical_actor(connection, actor_id, "lifecycle-parity", "human") - await connection.execute( - text( - "update actor_profiles set status='suspended',suspended_by=:actor," - "suspended_at=clock_timestamp(),suspension_reason='investigate' where id=:actor" - ), - {"actor": actor_id}, - ) - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_profiles set status='active',suspended_by=null," - "suspended_at=null,suspension_reason=null where id=:actor" - ), - {"actor": actor_id}, - ) - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_profiles set status='active',suspended_by=null," - "suspended_at=null,suspension_reason=null,reactivated_by=:actor," - "reactivated_at=clock_timestamp(),reactivation_reason='restored' where id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute( - text( - "update actor_profiles set status='suspended',suspended_by=:actor," - "suspended_at=clock_timestamp(),suspension_reason='second review' " - "where id=:actor" - ), - {"actor": actor_id}, - ) - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_profiles set status='active',suspended_by=null," - "suspended_at=null,suspension_reason=null where id=:actor" - ), - {"actor": actor_id}, - ) - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_profiles set status='active',suspended_by=null," - "suspended_at=null,suspension_reason=null,reactivated_by=:actor," - "reactivated_at=clock_timestamp(),reactivation_reason='restored again' " - "where id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute( - text( - "update actor_identity_links set status='revoked',revoked_by=:actor," - "revoked_at=clock_timestamp(),revoked_reason='link review' " - "where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_identity_links set status='active',revoked_by=null," - "revoked_at=null,revoked_reason=null where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_identity_links set status='active',revoked_by=null," - "revoked_at=null,revoked_reason=null,reactivated_by=:actor," - "reactivated_at=clock_timestamp(),reactivation_reason='link restored' " - "where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute( - text( - "update actor_identity_links set status='revoked',revoked_by=:actor," - "revoked_at=clock_timestamp(),revoked_reason='second link review' " - "where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_identity_links set status='active',revoked_by=null," - "revoked_at=null,revoked_reason=null where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - invalid = ( - "update actor_profiles set reactivation_reason='rewritten' where id=:actor", - "update actor_profiles set status='suspended',suspended_by=:actor," - "suspended_at=clock_timestamp(),suspension_reason=' padded ' where id=:actor", - "update actor_identity_links set reactivation_reason='rewritten' " - "where actor_profile_id=:actor", - ) - for statement in invalid: - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute(text(statement), {"actor": actor_id}) - invalid_reason_updates = ( - ( - "actor_profiles", - "update actor_profiles set status='suspended',suspended_by=:actor," - "suspended_at=clock_timestamp(),suspension_reason=chr(9)||'hold' " - "where id=:actor", - ), - ( - "actor_profiles", - "update actor_profiles set reactivation_reason='restored'||chr(10) " - "where id=:actor", - ), - ( - "actor_profiles", - "update actor_profiles set status='deactivated',deactivated_by=:actor," - "deactivated_at=clock_timestamp(),deactivation_reason=chr(13)||'terminal' " - "where id=:actor", - ), - ( - "actor_identity_links", - "update actor_identity_links set revoked_reason=chr(12)||'link review' " - "where actor_profile_id=:actor", - ), - ( - "actor_identity_links", - "update actor_identity_links set reactivation_reason='link restored'||chr(11) " - "where actor_profile_id=:actor", - ), - ) - for table, statement in invalid_reason_updates: - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute(text(f"alter table {table} disable trigger user")) - await connection.execute(text(statement), {"actor": actor_id}) - python_strip_code_points = ( - 9, - 10, - 11, - 12, - 13, - 28, - 29, - 30, - 31, - 32, - 133, - 160, - 5760, - 8192, - 8193, - 8194, - 8195, - 8196, - 8197, - 8198, - 8199, - 8200, - 8201, - 8202, - 8232, - 8233, - 8239, - 8287, - 12288, - ) - assert python_strip_code_points == tuple( - code_point for code_point in range(0x110000) if chr(code_point).isspace() - ) - for code_point in python_strip_code_points: - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute( - text("alter table actor_profiles disable trigger user") - ) - await connection.execute( - text( - "update actor_profiles set status='suspended'," - "suspended_by=:actor,suspended_at=clock_timestamp()," - "suspension_reason=chr(:code_point)||'hold' where id=:actor" - ), - {"actor": actor_id, "code_point": code_point}, - ) - async with engine.begin() as connection: - await connection.execute(text("alter table actor_profiles disable trigger user")) - await connection.execute( - text( - "update actor_profiles set reactivated_by=null,reactivated_at=null," - "reactivation_reason=null where id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute(text("alter table actor_profiles enable trigger user")) - await connection.execute( - text("alter table actor_identity_links disable trigger user") - ) - await connection.execute( - text( - "update actor_identity_links set status='active',revoked_by=null," - "revoked_at=null,revoked_reason=null,reactivated_by=null," - "reactivated_at=null,reactivation_reason=null " - "where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute( - text("alter table actor_identity_links enable trigger user") - ) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "head") - asyncio.run(prove_guards()) - finally: - command.downgrade(config, "base") - - -def test_actor_profile_lifecycle_upgrade_refuses_dirty_rows( - isolated_database_env: str, - migration_lock, -) -> None: - """Refuse partial provenance and non-normalized reasons before 0026 DDL.""" - config = _alembic_config() - cases = ( - ( - str(uuid4()), - "partial-link-reactivation", - "update actor_identity_links set reactivated_by=:actor where actor_profile_id=:actor", - "update actor_identity_links set reactivated_by=null where actor_profile_id=:actor", - ), - ( - str(uuid4()), - "padded-profile-suspension", - "update actor_profiles set status='suspended',suspended_by=:actor," - "suspended_at=clock_timestamp(),suspension_reason=' padded ' where id=:actor", - "update actor_profiles set suspension_reason='valid suspension' where id=:actor", - ), - ( - str(uuid4()), - "tab-padded-profile-suspension", - "update actor_profiles set status='suspended',suspended_by=:actor," - "suspended_at=clock_timestamp(),suspension_reason=chr(9)||'padded' " - "where id=:actor", - "update actor_profiles set suspension_reason='valid suspension' where id=:actor", - ), - ( - str(uuid4()), - "multibyte-profile-deactivation", - "update actor_profiles set status='deactivated',deactivated_by=:actor," - "deactivated_at=clock_timestamp(),deactivation_reason=repeat(chr(233),251) " - "where id=:actor", - "update actor_profiles set deactivation_reason='valid deactivation' where id=:actor", - ), - ( - str(uuid4()), - "nbsp-profile-deactivation", - "update actor_profiles set status='deactivated',deactivated_by=:actor," - "deactivated_at=clock_timestamp(),deactivation_reason=chr(160)||'padded' " - "where id=:actor", - "update actor_profiles set deactivation_reason='valid deactivation' where id=:actor", - ), - ( - str(uuid4()), - "padded-link-revocation", - "update actor_identity_links set status='revoked',revoked_by=:actor," - "revoked_at=clock_timestamp(),revoked_reason=' padded ' " - "where actor_profile_id=:actor", - "update actor_identity_links set revoked_reason='valid revocation' " - "where actor_profile_id=:actor", - ), - ( - str(uuid4()), - "newline-padded-link-revocation", - "update actor_identity_links set status='revoked',revoked_by=:actor," - "revoked_at=clock_timestamp(),revoked_reason='padded'||chr(10) " - "where actor_profile_id=:actor", - "update actor_identity_links set revoked_reason='valid revocation' " - "where actor_profile_id=:actor", - ), - ( - str(uuid4()), - "multibyte-link-reactivation", - "update actor_identity_links set reactivated_by=:actor," - "reactivated_at=clock_timestamp(),reactivation_reason=repeat(chr(233),251) " - "where actor_profile_id=:actor", - "update actor_identity_links set reactivation_reason='valid reactivation' " - "where actor_profile_id=:actor", - ), - ) - - async def seed_actors() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - for actor_id, subject, _, _ in cases: - await _insert_canonical_actor(connection, actor_id, subject, "human") - finally: - await engine.dispose() - - async def execute(statement: str, actor_id: str) -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text(statement), {"actor": actor_id}) - finally: - await engine.dispose() - - async def prior_head_state(actor_id: str) -> tuple[object, ...]: - engine = create_async_engine(isolated_database_env) - try: - async with engine.connect() as connection: - columns = await connection.execute( - text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='actor_profiles' " - "and column_name='reactivated_by')" - ) - ) - profile = await connection.execute( - text( - "select status,suspension_reason,deactivation_reason " - "from actor_profiles where id=:actor" - ), - {"actor": actor_id}, - ) - link = await connection.execute( - text( - "select status,revoked_reason,reactivated_by,reactivation_reason " - "from actor_identity_links where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - audit_count = await connection.scalar(text("select count(*) from audit_events")) - return ( - columns.scalar_one(), - tuple(profile.one()), - tuple(link.one()), - audit_count, - ) - finally: - await engine.dispose() - - async def restore_active_fixtures() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text("alter table actor_profiles disable trigger user")) - await connection.execute( - text( - "update actor_profiles set status='active',suspended_by=null," - "suspended_at=null,suspension_reason=null,deactivated_by=null," - "deactivated_at=null,deactivation_reason=null,reactivated_by=null," - "reactivated_at=null,reactivation_reason=null where id=any(:actors)" - ), - {"actors": [case[0] for case in cases]}, - ) - await connection.execute(text("alter table actor_profiles enable trigger user")) - await connection.execute( - text("alter table actor_identity_links disable trigger user") - ) - await connection.execute( - text( - "update actor_identity_links set status='active',revoked_by=null," - "revoked_at=null,revoked_reason=null,reactivated_by=null," - "reactivated_at=null,reactivation_reason=null " - "where actor_profile_id=any(:actors)" - ), - {"actors": [case[0] for case in cases]}, - ) - await connection.execute( - text("alter table actor_identity_links enable trigger user") - ) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0025_artifact_store_v2") - asyncio.run(seed_actors()) - for actor_id, _, dirty_statement, clean_statement in cases: - asyncio.run(execute(dirty_statement, actor_id)) - before = asyncio.run(prior_head_state(actor_id)) - with pytest.raises(RuntimeError, match="dirty actor lifecycle rows"): - command.upgrade(config, "head") - assert asyncio.run(_current_revision(isolated_database_env)) == ( - "0025_artifact_store_v2" - ) - assert asyncio.run(prior_head_state(actor_id)) == before - asyncio.run(execute(clean_statement, actor_id)) - command.upgrade(config, "head") - asyncio.run(restore_active_fixtures()) - finally: - command.downgrade(config, "base") - - -def test_actor_profile_lifecycle_safe_downgrade_and_reupgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Restore the exact prior schema when no forward evidence exists.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0026_actor_profile_lifecycle") - command.downgrade(config, "0025_artifact_store_v2") - assert asyncio.run(_current_revision(isolated_database_env)) == "0025_artifact_store_v2" - command.upgrade(config, "0026_actor_profile_lifecycle") - assert ( - asyncio.run(_current_revision(isolated_database_env)) - == "0026_actor_profile_lifecycle" - ) - finally: - command.downgrade(config, "base") - - -def test_actor_profile_lifecycle_downgrade_refuses_forward_evidence( - isolated_database_env: str, - migration_lock, -) -> None: - """Keep the full head intact for every lifecycle-evidence branch.""" - config = _alembic_config() - actor_id = str(uuid4()) - - async def seed_actor() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await _insert_canonical_actor(connection, actor_id, "forward-lifecycle", "human") - finally: - await engine.dispose() - - async def write_profile_reactivation(*, clear: bool = False) -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - if clear: - await connection.execute( - text("alter table actor_profiles disable trigger user") - ) - await connection.execute( - text( - "update actor_profiles set reactivated_by=null,reactivated_at=null," - "reactivation_reason=null where id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute(text("alter table actor_profiles enable trigger user")) - return - await connection.execute( - text( - "update actor_profiles set status='suspended',suspended_by=:actor," - "suspended_at=clock_timestamp(),suspension_reason='hold' where id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute( - text( - "update actor_profiles set status='active',suspended_by=null," - "suspended_at=null,suspension_reason=null,reactivated_by=:actor," - "reactivated_at=clock_timestamp(),reactivation_reason='restored' where id=:actor" - ), - {"actor": actor_id}, - ) - finally: - await engine.dispose() - - async def insert_audit_blocker(blocker: str) -> str: - engine = create_async_engine(isolated_database_env) - event_id = str(uuid4()) - try: - async with engine.begin() as connection: - link_id = await connection.scalar( - text("select id from actor_identity_links where actor_profile_id=:actor"), - {"actor": actor_id}, - ) - if blocker in {"ActorProfileReactivated", "ActorIdentityLinkReactivated"}: - is_profile = blocker == "ActorProfileReactivated" - resource_type = "actor_profile" if is_profile else "actor_identity_link" - resource_id = actor_id if is_profile else link_id - permission_id = ( - "actor.profile.reactivate" - if is_profile - else "actor.identity_link.reactivate" - ) - reason = ( - "administrative_correction" if is_profile else "identity_lifecycle_change" - ) - before_facts = ( - '{"status":"suspended"}' if is_profile else '{"status":"revoked"}' - ) - await connection.execute( - text( - "alter table audit_events disable trigger " - "audit_events_validate_idempotency" - ) - ) - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id," - "target_actor_ref_kind,target_actor_ref,permission_id," - "resource_type,resource_id,target_ref_kind,target_ref_id,reason," - "before_facts,after_facts) values " - "(:id,:resource_type,:resource_id,:event_type,:actor,'[]'::json," - "'{}'::json,'local_authority',false,'{}'::json,'authority',1," - "'actor_profile',:request_id,:correlation_id,'actor_profile',:actor," - ":permission_id,:resource_type,:resource_id," - ":resource_type,:resource_id,:reason,cast(:before_facts as json)," - '\'{"status":"active"}\'::json)' - ), - { - "id": event_id, - "resource_type": resource_type, - "resource_id": resource_id, - "event_type": blocker, - "actor": actor_id, - "request_id": str(uuid4()), - "correlation_id": str(uuid4()), - "permission_id": permission_id, - "reason": reason, - "before_facts": before_facts, - }, - ) - await connection.execute( - text( - "alter table audit_events enable trigger " - "audit_events_validate_idempotency" - ) - ) - else: - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id," - "target_actor_ref_kind,target_actor_ref,permission_id,action_id," - "resource_type,resource_id,target_ref_kind,target_ref_id,reason," - "denial_code,after_facts) values " - "(:id,'authorization_decision',:id,'SensitiveAuthorizationDenied'," - ":actor,'[]'::json,'{}'::json,'local_authority',false,'{}'::json," - "'authority',1,'actor_profile',:request_id,:correlation_id," - "'actor_profile',:actor,'actor.identity_link.revoke'," - "'actor.identity_link.revoke','actor_identity_link',:link_id," - "'actor_identity_link',:link_id,'authorization_evaluation'," - ":denial_code,cast(:after_facts as json))" - ), - { - "id": event_id, - "actor": actor_id, - "request_id": str(uuid4()), - "correlation_id": str(uuid4()), - "link_id": link_id, - "denial_code": blocker, - "after_facts": '{"allowed": false}', - }, - ) - return event_id - finally: - await engine.dispose() - - async def remove_audit_blocker(event_id: str) -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "alter table audit_events disable trigger audit_events_reject_update_delete" - ) - ) - await connection.execute( - text("delete from audit_events where id=:id"), {"id": event_id} - ) - await connection.execute( - text( - "alter table audit_events enable trigger audit_events_reject_update_delete" - ) - ) - finally: - await engine.dispose() - - async def forward_state() -> tuple[object, ...]: - engine = create_async_engine(isolated_database_env) - try: - async with engine.connect() as connection: - profile = await connection.execute( - text( - "select reactivated_by,reactivated_at,reactivation_reason " - "from actor_profiles where id=:actor" - ), - {"actor": actor_id}, - ) - events = await connection.execute( - text( - "select id,event_type,denial_code from audit_events " - "where event_domain='authority' order by id" - ) - ) - column_exists = await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='actor_profiles' " - "and column_name='reactivated_by')" - ) - ) - return column_exists, tuple(profile.one()), tuple(events.all()) - finally: - await engine.dispose() - - def refuse_downgrade_without_change() -> None: - before = asyncio.run(forward_state()) - with pytest.raises(RuntimeError, match="cannot downgrade actor lifecycle evidence"): - command.downgrade(config, "0025_artifact_store_v2") - assert asyncio.run(_current_revision(isolated_database_env)) == ( - "0026_actor_profile_lifecycle" - ) - assert asyncio.run(forward_state()) == before - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0026_actor_profile_lifecycle") - asyncio.run(seed_actor()) - asyncio.run(write_profile_reactivation()) - refuse_downgrade_without_change() - asyncio.run(write_profile_reactivation(clear=True)) - for blocker in ( - "ActorProfileReactivated", - "ActorIdentityLinkReactivated", - "identity_link_already_revoked", - "identity_link_not_revoked", - ): - event_id = asyncio.run(insert_audit_blocker(blocker)) - refuse_downgrade_without_change() - asyncio.run(remove_audit_blocker(event_id)) - command.downgrade(config, "0025_artifact_store_v2") - finally: - command.downgrade(config, "base") - - -def test_contributor_foundation_upgrade_guards_and_reversible_preservation( - isolated_database_env: str, - migration_lock, -) -> None: - """Preserve valid attribution and enforce canonical-human lineage in PostgreSQL.""" - config = _alembic_config() - human_id = str(uuid4()) - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0026_actor_profile_lifecycle") - fixture = asyncio.run( - _seed_contributor_prior_head( - isolated_database_env, - assignment_values=(human_id,), - submission_values=(human_id,), - human_ids=(human_id,), - ) - ) - before = asyncio.run(_contributor_foundation_shape(isolated_database_env)) - worker_column = ("worker_id", 100) - contributor_column = ("contributor_id", 36) - assert before["revision"] == "0026_actor_profile_lifecycle" - assert before["assignment_column"] == worker_column - assert before["submission_column"] == worker_column - - command.upgrade(config, "0027_contributor_foundation") - upgraded = asyncio.run(_contributor_foundation_shape(isolated_database_env)) - expected_upgraded = { - "revision": "0027_contributor_foundation", - "assignment_column": contributor_column, - "submission_column": contributor_column, - "assignment_index": "ix_task_assignments_contributor_id", - "submission_index": "ix_submissions_contributor_id", - "foreign_keys": ( - "fk_submissions_contributor_id_actor_profiles", - "fk_task_assignments_contributor_id_actor_profiles", - ), - "function": True, - "triggers": ( - "submissions_contributor_human", - "task_assignments_contributor_human", - ), - "assignment_values": (human_id,), - "submission_values": (human_id,), - } - assert upgraded == expected_upgraded - direct_sql = asyncio.run( - _exercise_contributor_lineage_guards( - isolated_database_env, - fixture=fixture, - human_id=human_id, - ) - ) - assert direct_sql == { - "missing_assignment": "23503", - "service_assignment": "23514", - "missing_assignment_update": "23503", - "service_assignment_update": "23514", - "missing_submission": "23503", - "service_submission": "23514", - "missing_submission_update": "23503", - "service_submission_update": "23514", - "suspended_human_inserted": True, - "deactivated_human_inserted": True, - "unrelated_update_preserved": True, - } - assert asyncio.run( - _exercise_contributor_lineage_function_contract(isolated_database_env) - ) == { - "zero_arguments": "55000", - "extra_arguments": "55000", - "absent_field": "55000", - "nullable_field_accepted": True, - } - - asyncio.run(_add_contributor_function_dependency(isolated_database_env)) - intact = asyncio.run(_contributor_foundation_shape(isolated_database_env)) - with pytest.raises(RuntimeError, match='"total":1'): - command.downgrade(config, "0026_actor_profile_lifecycle") - assert asyncio.run(_contributor_foundation_shape(isolated_database_env)) == intact - asyncio.run(_drop_contributor_function_dependency(isolated_database_env)) - - command.downgrade(config, "0026_actor_profile_lifecycle") - restored = asyncio.run(_contributor_foundation_shape(isolated_database_env)) - assert restored["revision"] == "0026_actor_profile_lifecycle" - assert restored["assignment_column"] == worker_column - assert restored["submission_column"] == worker_column - assert restored["assignment_index"] == "ix_task_assignments_worker_id" - assert restored["submission_index"] == "ix_submissions_worker_id" - assignment_values = restored["assignment_values"] - assert isinstance(assignment_values, tuple) - assert human_id in assignment_values - expected_submission_values = (human_id,) - assert restored["submission_values"] == expected_submission_values - - command.upgrade(config, "0027_contributor_foundation") - assert asyncio.run(_current_revision(isolated_database_env)) == ( - "0027_contributor_foundation" - ) - finally: - command.downgrade(config, "0023_service_actor_identity") - asyncio.run(_clear_contributor_migration_fixtures(isolated_database_env)) - command.downgrade(config, "base") - - -def test_contributor_foundation_preflight_refuses_all_unsafe_classes_atomically( - isolated_database_env: str, - migration_lock, -) -> None: - """Classify both source tables without guessing or partially changing schema.""" - config = _alembic_config() - missing_ids = (str(uuid4()), str(uuid4())) - assignment_malformed = tuple(f"private.person.{index}@example.test" for index in range(22)) - submission_malformed = tuple( - f"eyJhbGciOiJSUzI1NiJ9.secret-token-material-{index}" for index in range(22) - ) - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0026_actor_profile_lifecycle") - fixture = asyncio.run( - _seed_contributor_prior_head( - isolated_database_env, - assignment_values=assignment_malformed + (missing_ids[0], "service"), - submission_values=submission_malformed + (missing_ids[1], "service"), - ) - ) - service_id = str(fixture["service_id"]) - before = asyncio.run(_contributor_foundation_shape(isolated_database_env)) - - with pytest.raises(RuntimeError, match="contributor foundation preflight") as failure: - command.upgrade(config, "0027_contributor_foundation") - - message = str(failure.value) - assert "malformed" in message - assert "missing" in message - assert "service" in message - assert service_id in message - assert all(missing_id in message for missing_id in missing_ids) - diagnostic = json.loads(message.split("preflight failed: ", 1)[1]) - for table in ("task_assignments", "submissions"): - malformed = diagnostic[table]["malformed"] - assert malformed["total"] == 22 - assert len(malformed["rows"]) == 20 - assert [row[0] for row in malformed["rows"]] == sorted( - row[0] for row in malformed["rows"] - ) - assert all(row[1] == "" for row in malformed["rows"]) - assert all( - value not in message for value in assignment_malformed + submission_malformed - ) - assert all( - row_id in message - for row_id in ( - tuple(fixture["assignment_ids"])[-2:] + tuple(fixture["submission_ids"])[-2:] - ) - ) - assert "issuer" not in message - assert "subject" not in message - assert asyncio.run(_contributor_foundation_shape(isolated_database_env)) == before - finally: - command.downgrade(config, "0023_service_actor_identity") - asyncio.run(_clear_contributor_migration_fixtures(isolated_database_env)) - command.downgrade(config, "base") - - -def test_api_rate_control_schema_preserves_domain_and_guards_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0017 schema guards, preservation, and transactional downgrade refusal.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - project_id = str(uuid4()) - artifact_id = str(uuid4()) - digest = bytes(range(32)) - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0015_post_submit_correction") - asyncio.run(_seed_artifact_prior_head(isolated_database_env, project_id)) - command.upgrade(config, "0016_artifact_domain") - before = asyncio.run(_artifact_prior_head_project(isolated_database_env, project_id)) - artifact_before = asyncio.run( - _seed_and_fetch_0016_artifact(isolated_database_env, artifact_id) - ) - - command.upgrade(config, "0017_api_controls") - after = asyncio.run(_artifact_prior_head_project(isolated_database_env, project_id)) - artifact_after = asyncio.run(_fetch_0016_artifact(isolated_database_env, artifact_id)) - schema = asyncio.run(_api_rate_control_schema(isolated_database_env)) - asyncio.run(_assert_api_rate_control_guards(isolated_database_env, digest)) - - with pytest.raises(RuntimeError, match="non-empty API rate controls"): - command.downgrade(config, "0016_artifact_domain") - - asyncio.run(_clear_api_rate_controls(isolated_database_env)) - inserted = threading.Event() - release_insert = threading.Event() - downgrade_started = threading.Event() - - def guarded_downgrade() -> None: - downgrade_started.set() - command.downgrade(config, "0016_artifact_domain") - - with ThreadPoolExecutor(max_workers=2) as pool: - insert_future = pool.submit( - asyncio.run, - _insert_rate_control_until_released( - isolated_database_env, - digest, - inserted, - release_insert, - ), - ) - assert inserted.wait(timeout=5) - downgrade_future = pool.submit(guarded_downgrade) - assert downgrade_started.wait(timeout=5) - time.sleep(0.2) - assert downgrade_future.done() is False - release_insert.set() - insert_future.result(timeout=5) - with pytest.raises(RuntimeError, match="non-empty API rate controls"): - downgrade_future.result(timeout=5) - - refused_state = asyncio.run(_api_rate_control_state(isolated_database_env)) - asyncio.run(_clear_api_rate_controls(isolated_database_env)) - command.downgrade(config, "0016_artifact_domain") - downgraded_state = asyncio.run(_api_rate_control_state(isolated_database_env)) - command.upgrade(config, "0017_api_controls") - finally: - asyncio.run(_clear_api_rate_controls(isolated_database_env)) - asyncio.run(_truncate_artifact_foundation(isolated_database_env)) - command.downgrade(config, "base") - command.upgrade(config, "head") - - assert after == before - assert artifact_after == artifact_before - assert schema == { - "columns": { - "control_scope:character varying:NO", - "key_digest:bytea:NO", - "window_started_at:timestamp with time zone:NO", - "window_expires_at:timestamp with time zone:NO", - "request_count:bigint:NO", - "updated_at:timestamp with time zone:NO", - }, - "constraints": { - "pk_api_rate_control_counters", - "ck_api_rate_control_counters_scope_token", - "ck_api_rate_control_counters_digest_length", - "ck_api_rate_control_counters_request_count", - "ck_api_rate_control_counters_window_order", - }, - "indexes": { - "pk_api_rate_control_counters", - "ix_api_rate_control_counters_window_expires_at", - }, - } - assert refused_state == { - "revision": "0017_api_controls", - "table_exists": True, - "row_count": 1, - } - assert downgraded_state == { - "revision": "0016_artifact_domain", - "table_exists": False, - "row_count": None, - } - - -def test_authorization_read_rate_scope_upgrade_and_downgrade_refusal( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0033 preserves counters and refuses a live new-scope downgrade.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - async def insert(scope: str, marker: int) -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into api_rate_control_counters " - "(control_scope,key_digest,window_started_at,window_expires_at," - "request_count,updated_at) values " - "(:scope,:digest,statement_timestamp()," - "statement_timestamp()+interval '1 minute',1,statement_timestamp())" - ), - {"scope": scope, "digest": bytes([marker]) * 32}, - ) - finally: - await engine.dispose() - - async def scopes() -> list[str]: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - return list( - ( - await connection.execute( - text( - "select control_scope from api_rate_control_counters " - "order by control_scope" - ) - ) - ).scalars() - ) - finally: - await engine.dispose() - - async def clear_new_scope() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "delete from api_rate_control_counters " - "where control_scope='authorization_read'" - ) - ) - finally: - await engine.dispose() - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0032_artifact_recovery") - asyncio.run(insert("first_access", 41)) - asyncio.run(insert("admin_mutation", 42)) - command.upgrade(config, "0033_authorization_read_rate") - assert asyncio.run(scopes()) == ["admin_mutation", "first_access"] - asyncio.run(insert("authorization_read", 43)) - with pytest.raises( - RuntimeError, - match="cannot downgrade live authorization-read rate controls", - ): - command.downgrade(config, "0032_artifact_recovery") - assert asyncio.run(scopes()) == [ - "admin_mutation", - "authorization_read", - "first_access", - ] - asyncio.run(clear_new_scope()) - - inserted = threading.Event() - release_insert = threading.Event() - with ThreadPoolExecutor(max_workers=2) as pool: - insert_future = pool.submit( - asyncio.run, - _insert_rate_control_until_released( - isolated_database_env, - bytes([45]) * 32, - inserted, - release_insert, - scope="authorization_read", - ), - ) - assert inserted.wait(timeout=5) - downgrade_future = pool.submit( - command.downgrade, - config, - "0032_artifact_recovery", - ) - asyncio.run(_wait_for_rate_control_table_lock(isolated_database_env)) - release_insert.set() - insert_future.result(timeout=5) - with pytest.raises( - RuntimeError, - match="cannot downgrade live authorization-read rate controls", - ): - downgrade_future.result(timeout=5) - - asyncio.run(clear_new_scope()) - command.downgrade(config, "0032_artifact_recovery") - assert asyncio.run(scopes()) == ["admin_mutation", "first_access"] - with pytest.raises(IntegrityError): - asyncio.run(insert("authorization_read", 43)) - command.upgrade(config, "0033_authorization_read_rate") - asyncio.run(insert("authorization_read", 44)) - finally: - asyncio.run(_clear_api_rate_controls(isolated_database_env)) - command.upgrade(config, "head") - - -def test_authorization_read_rate_scope_migration_refuses_constraint_drift( - isolated_database_env: str, - migration_lock, -) -> None: - """Keep revision and counter state unchanged when the known constraint drifted.""" - config = _alembic_config() - - async def replace_constraint(definition: str) -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "alter table api_rate_control_counters drop constraint " - "ck_api_rate_control_counters_scope_token" - ) - ) - await connection.execute( - text( - "alter table api_rate_control_counters add constraint " - "ck_api_rate_control_counters_scope_token check " - f"({definition})" - ) - ) - finally: - await engine.dispose() - - async def state() -> tuple[str, str, int]: - engine = create_async_engine(isolated_database_env) - try: - async with engine.connect() as connection: - revision = str( - await connection.scalar(text("select version_num from alembic_version")) - ) - definition = str( - await connection.scalar( - text( - "select pg_get_expr(conbin,conrelid) from pg_constraint " - "where conrelid='api_rate_control_counters'::regclass " - "and conname='ck_api_rate_control_counters_scope_token'" - ) - ) - ) - rows = int( - await connection.scalar(text("select count(*) from api_rate_control_counters")) - ) - return revision, definition, rows - finally: - await engine.dispose() - - old_definition = "control_scope in ('first_access', 'admin_mutation')" - new_definition = "control_scope in ('first_access', 'admin_mutation', 'authorization_read')" - drifted_definition = "control_scope in ('first_access')" - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0032_artifact_recovery") - asyncio.run(replace_constraint(drifted_definition)) - before_upgrade = asyncio.run(state()) - with pytest.raises(RuntimeError, match="unexpected API rate-control scope constraint"): - command.upgrade(config, "0033_authorization_read_rate") - assert asyncio.run(state()) == before_upgrade - - asyncio.run(replace_constraint(old_definition)) - command.upgrade(config, "0033_authorization_read_rate") - asyncio.run(replace_constraint(drifted_definition)) - before_downgrade = asyncio.run(state()) - with pytest.raises(RuntimeError, match="unexpected API rate-control scope constraint"): - command.downgrade(config, "0032_artifact_recovery") - assert asyncio.run(state()) == before_downgrade - - asyncio.run(replace_constraint(new_definition)) - finally: - command.upgrade(config, "head") - - -def test_authority_audit_schema_preserves_legacy_and_guards_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0018 preserves legacy evidence and refuses destructive downgrade.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - legacy_id = str(uuid4()) - authority_id = str(uuid4()) - - with migration_lock(): - try: - command.downgrade(config, "base") - command.upgrade(config, "0017_api_controls") - before = asyncio.run(_seed_and_fetch_legacy_audit(isolated_database_env, legacy_id)) - - command.upgrade(config, "0018_authority_audit_evidence") - after = asyncio.run(_fetch_audit_row(isolated_database_env, legacy_id)) - schema = asyncio.run(_authority_audit_schema(isolated_database_env)) - occurred_at = asyncio.run( - _insert_authority_audit_fixture(isolated_database_env, authority_id) - ) - - with pytest.raises(RuntimeError, match="non-empty authority audit"): - command.downgrade(config, "0017_api_controls") - refused = asyncio.run(_authority_audit_state(isolated_database_env)) - - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, authority_id)) - command.downgrade(config, "0017_api_controls") - downgraded = asyncio.run(_fetch_audit_row(isolated_database_env, legacy_id)) - command.upgrade(config, "0018_authority_audit_evidence") - restored_schema = asyncio.run(_authority_audit_schema(isolated_database_env)) - finally: - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, authority_id)) - command.downgrade(config, "base") - command.upgrade(config, "head") - - assert after == {**before, "event_domain": "legacy_lifecycle"} - assert downgraded == before - assert occurred_at.year >= 2026 - assert refused == { - "revision": "0018_authority_audit_evidence", - "authority_rows": 1, - } - assert schema == restored_schema - assert schema == { - "columns": { - "actor_ref_kind:varchar:YES", - "after_facts:json:YES", - "before_facts:json:YES", - "correlation_id:uuid:YES", - "denial_code:varchar:YES", - "event_domain:varchar:NO", - "event_version:int4:YES", - "idempotency_reference:uuid:YES", - "invalidation_cause_event_id:varchar:YES", - "invalidation_target_kind:varchar:YES", - "invalidation_target_ref:varchar:YES", - "matched_grant_id:varchar:YES", - "occurred_at:timestamptz:YES", - "permission_id:varchar:YES", - "project_id:varchar:YES", - "request_id:uuid:YES", - "resource_id:varchar:YES", - "resource_type:varchar:YES", - "target_actor_ref:varchar:YES", - "target_actor_ref_kind:varchar:YES", - "target_ref_id:varchar:YES", - "target_ref_kind:varchar:YES", - }, - "constraints": { - "ck_audit_events_authority_privacy_bounds", - "ck_audit_events_authority_registries", - "ck_audit_events_authority_tokens", - "ck_audit_events_domain_shape", - "ck_audit_events_fact_bounds", - "ck_audit_events_foundation_shapes", - "ck_audit_events_reference_pairs", - "fk_audit_events_invalidation_cause", - }, - "indexes": { - "ix_audit_events_actor_ref", - "ix_audit_events_correlation_id", - "ix_audit_events_occurred_at", - "ix_audit_events_project_id", - "ix_audit_events_request_id", - }, - "triggers": { - "audit_events_reject_truncate", - "audit_events_reject_update_delete", - "audit_events_set_authority_time", - }, - "functions": { - "authority_facts_are_safe", - "authority_grant_facts_are_safe", - "authority_event_facts_are_safe", - "reject_audit_event_mutation", - "set_authority_audit_database_time", - }, - "legacy_default": True, - "external_identity_nullable": True, - } - - -def test_authority_idempotency_schema_preserves_audit_and_guards_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0019 state, linkage, forward compatibility, and downgrade custody.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - orphan_event, orphan_ref = str(uuid4()), str(uuid4()) - record_id, actor_id, target_id = str(uuid4()), str(uuid4()), str(uuid4()) - - with migration_lock(): - try: - command.downgrade(config, "0018_authority_audit_evidence") - asyncio.run( - _insert_pre_0019_forward_reference(isolated_database_env, orphan_event, orphan_ref) - ) - command.upgrade(config, "0019_authority_idempotency") - schema = asyncio.run(_authority_idempotency_schema(isolated_database_env)) - invalid = asyncio.run(_authority_idempotency_invalid_writes(isolated_database_env)) - asyncio.run( - _insert_committed_authority_idempotency( - isolated_database_env, record_id, actor_id, target_id - ) - ) - immutable = asyncio.run( - _authority_idempotency_immutable_writes(isolated_database_env, record_id) - ) - with pytest.raises(RuntimeError, match="non-empty authority idempotency"): - command.downgrade(config, "0018_authority_audit_evidence") - refused = asyncio.run(_authority_idempotency_state(isolated_database_env, orphan_event)) - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=None - ) - ) - downgrade_lock_observed = _authority_downgrade_waits_for_writer( - config, isolated_database_env - ) - preserved = asyncio.run( - _authority_idempotency_state(isolated_database_env, orphan_event) - ) - command.upgrade(config, "0019_authority_idempotency") - restored = asyncio.run(_authority_idempotency_schema(isolated_database_env)) - finally: - command.upgrade(config, "head") - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=orphan_event - ) - ) - - assert schema == restored - assert schema == { - "columns": { - "actor_ref:varchar:NO", - "actor_ref_kind:varchar:NO", - "committed_at:timestamptz:YES", - "created_at:timestamptz:NO", - "id:uuid:NO", - "idempotency_key:uuid:NO", - "operation:varchar:NO", - "request_digest:varchar:NO", - "response_http_status:int2:YES", - "response_resource_id:uuid:YES", - "response_resource_type:varchar:YES", - "response_resource_version:int8:YES", - "status:varchar:NO", - }, - "constraints": { - "authority_idempotency_pending_guard", - "ck_authority_idempotency_records_actor_kind", - "ck_authority_idempotency_records_actor_reference", - "ck_authority_idempotency_records_operation", - "ck_authority_idempotency_records_request_digest", - "ck_authority_idempotency_records_response_status", - "ck_authority_idempotency_records_response_type", - "ck_authority_idempotency_records_response_version", - "ck_authority_idempotency_records_state_shape", - "ck_authority_idempotency_records_status", - "pk_authority_idempotency_records", - "uq_authority_idempotency_records_actor_reference", - "uq_authority_idempotency_records_replay_namespace", - }, - "triggers": { - "authority_idempotency_guard", - "authority_idempotency_pending_guard", - "authority_idempotency_reject_truncate", - }, - "audit_fk_validated": False, - "audit_trigger": True, - } - assert invalid == {"initial_committed": True, "pending_commit": True, "new_orphan": True} - assert immutable == { - "update": True, - "delete": True, - "truncate": True, - "database_timestamps": True, - } - assert downgrade_lock_observed is True - assert refused == {"revision": "0019_authority_idempotency", "records": 1, "orphan": 1} - assert preserved == {"revision": "0018_authority_audit_evidence", "records": None, "orphan": 1} - - -async def _outbox_schema(database_url: str) -> dict[str, object]: - """Return the exact shared-outbox migration surface.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - column_rows = ( - await connection.execute( - text( - "select column_name, is_nullable from information_schema.columns " - "where table_schema='public' and table_name='outbox_events'" - ) - ) - ).all() - indexes = set( - ( - await connection.scalars( - text( - "select indexname from pg_indexes " - "where schemaname='public' and tablename='outbox_events'" - ) - ) - ).all() - ) - triggers = set( - ( - await connection.scalars( - text( - "select tgname from pg_trigger " - "where tgrelid='outbox_events'::regclass and not tgisinternal" - ) - ) - ).all() - ) - return { - "revision": str( - await connection.scalar(text("select version_num from alembic_version")) - ), - "columns": {row.column_name for row in column_rows}, - "nullable": {row.column_name for row in column_rows if row.is_nullable == "YES"}, - "indexes": indexes, - "triggers": triggers, - } - finally: - await engine.dispose() - - -async def _outbox_downgrade_writer_race( - database_url: str, - config: Config, - *, - project_id: str, - commit_writer: bool, -) -> str: - """Hold one append open while downgrade waits, then commit or roll it back.""" - engine = create_async_engine(database_url) - event_id = str(uuid4()) - try: - async with engine.begin() as setup_connection: - await insert_historical_project( - setup_connection, - project_id=project_id, - name="Outbox migration", - slug=f"outbox-migration-{project_id}", - status="active", - ) - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute( - text( - "insert into outbox_events " - "(event_id,event_type,event_version,aggregate_type,aggregate_id,project_id," - "correlation_id,idempotency_key,payload,payload_digest) values " - "(:event_id,'MigrationProbe',1,'migration_probe',:aggregate_id,:project_id," - ":correlation_id,:idempotency_key,'{}'::jsonb,:digest)" - ), - { - "event_id": event_id, - "aggregate_id": str(uuid4()), - "project_id": project_id, - "correlation_id": f"migration:{event_id}", - "idempotency_key": f"migration:{event_id}:v1", - "digest": "sha256:" + ("0" * 64), - }, - ) - downgrade = asyncio.create_task( - asyncio.to_thread( - command.downgrade, - config, - "0028_artifact_admission", - ) - ) - await asyncio.sleep(0.1) - assert not downgrade.done() - if commit_writer: - await transaction.commit() - with pytest.raises( - RuntimeError, match="cannot downgrade with shared outbox events" - ): - await asyncio.wait_for(downgrade, timeout=5) - return "refused_after_commit" - await transaction.rollback() - await asyncio.wait_for(downgrade, timeout=5) - return "succeeded_after_rollback" - finally: - await engine.dispose() - - -async def _remove_outbox_migration_row(database_url: str, project_id: str) -> None: - """Remove only migration-test truth under explicit disabled trigger custody.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - table_exists = await connection.scalar( - text("select to_regclass('public.outbox_events') is not null") - ) - if table_exists: - await connection.execute(text("alter table outbox_events disable trigger user")) - await connection.execute( - text("delete from outbox_events where project_id=:project_id"), - {"project_id": project_id}, - ) - await connection.execute(text("alter table outbox_events enable trigger user")) - project_exists = await connection.scalar( - text("select to_regclass('public.projects') is not null") - ) - if project_exists: - await connection.execute( - text("delete from projects where id=:project_id"), - {"project_id": project_id}, - ) - finally: - await engine.dispose() - - -async def _fetch_columns(database_url: str) -> set[str]: - """Return current public table columns as table.column names.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - rows = ( - await connection.execute( - text( - """ - select table_name, column_name - from information_schema.columns - where table_schema = 'public' - """ - ) - ) - ).all() - return {f"{row.table_name}.{row.column_name}" for row in rows} - finally: - await engine.dispose() - - -async def _fetch_table_names(database_url: str) -> set[str]: - """Return current public table names.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - rows = ( - await connection.execute( - text( - """ - select table_name - from information_schema.tables - where table_schema = 'public' - """ - ) - ) - ).all() - return {row.table_name for row in rows} - finally: - await engine.dispose() - - -async def _seed_pre_0020_actor( - database_url: str, - *, - actor_id: str, - subject: str, - audit_event_id: str | None = None, -) -> None: - """Seed one valid legacy identity, typed profile, and optional attribution.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into actor_identities " - "(actor_id,external_subject,external_issuer,display_name,email," - "last_seen_roles,last_claim_snapshot,auth_source,is_dev_auth) values " - "(:actor,:subject,'https://identity.test','Legacy Human'," - "'legacy@example.test','[\"worker\"]'::json,'{}'::json,'flow',false)" - ), - {"actor": actor_id, "subject": subject}, - ) - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_id,profile_type,status,skill_tags,scope_type,scope_id," - "profile_metadata) values " - "(:id,:actor,'worker','active','[\"stem\"]'::json,'global','global'," - '\'{"source":"legacy"}\'::json)' - ), - {"id": str(uuid4()), "actor": actor_id}, - ) - if audit_event_id is not None: - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,external_subject," - "external_issuer,actor_roles,claim_snapshot,auth_source,is_dev_auth," - "reason,event_payload) values " - "(:id,'task','legacy-task','task_created',:actor,:subject," - "'https://identity.test','[\"worker\"]'::json,'{}'::json,'flow'," - "false,'migration attribution proof','{}'::json)" - ), - {"id": audit_event_id, "actor": actor_id, "subject": subject}, - ) - finally: - await engine.dispose() - - -async def _legacy_database_binding(database_url: str) -> str: - """Return the classification binding for the current isolated database.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - database_name, database_oid = ( - await connection.execute( - text( - "select current_database(), oid from pg_database " - "where datname=current_database()" - ) - ) - ).one() - return database_binding_identifier(database_name, database_oid) - finally: - await engine.dispose() - - -async def _pre_0020_actor_state(database_url: str, actor_id: str) -> dict[str, object]: - """Return prior-head revision and retained legacy actor count.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "legacy_rows": await connection.scalar( - text("select count(*) from actor_identities where actor_id=:actor"), - {"actor": actor_id}, - ), - } - finally: - await engine.dispose() - - -async def _pre_0020_actor_display_fields( - database_url: str, - actor_id: str, -) -> dict[str, str | None]: - """Return restored legacy display fields after canonical downgrade.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - row = ( - await connection.execute( - text("select display_name,email from actor_identities where actor_id=:actor"), - {"actor": actor_id}, - ) - ).one() - return {"display_name": row.display_name, "email": row.email} - finally: - await engine.dispose() - - -async def _update_canonical_actor_display_fields( - database_url: str, - actor_id: str, - *, - display_name: str | None, - contact_email: str | None, -) -> None: - """Apply canonical self-service fields before downgrade proof.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_profiles set display_name=:display_name, " - "contact_email=:contact_email,updated_at=now() where id=:actor" - ), - { - "actor": actor_id, - "display_name": display_name, - "contact_email": contact_email, - }, - ) - finally: - await engine.dispose() - - -async def _canonical_actor_migration_state( - database_url: str, - actor_id: str, - audit_event_id: str, -) -> dict[str, object]: - """Return canonical, compatibility, evidence, and attribution migration facts.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - profile = ( - await connection.execute( - text( - "select id,actor_kind,display_name,contact_email " - "from actor_profiles where id=:actor" - ), - {"actor": actor_id}, - ) - ).one() - identity_link = ( - await connection.execute( - text( - "select id,subject from actor_identity_links where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - ).one() - legacy_profile_type = await connection.scalar( - text("select profile_type from legacy_workflow_eligibility where actor_id=:actor"), - {"actor": actor_id}, - ) - audit_actor_id = await connection.scalar( - text("select actor_id from audit_events where id=:event"), - {"event": audit_event_id}, - ) - migration_state = ( - await connection.execute( - text( - "select classified_count,source_row_set_sha256 " - "from actor_profile_migration_state where id=1" - ) - ) - ).one() - return { - "profile_id": profile.id, - "actor_kind": profile.actor_kind, - "display_name": profile.display_name, - "contact_email": profile.contact_email, - "identity_link_id": identity_link.id, - "identity_subject": identity_link.subject, - "legacy_profile_type": legacy_profile_type, - "audit_actor_id": audit_actor_id, - "classified_count": migration_state.classified_count, - "source_checksum": migration_state.source_row_set_sha256, - } - finally: - await engine.dispose() - - -async def _current_revision(database_url: str) -> str: - """Return the exact current Alembic revision.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return str(await connection.scalar(text("select version_num from alembic_version"))) - finally: - await engine.dispose() - - -async def _seed_canonical_actor_for_downgrade_guard( - database_url: str, - actor_id: str, -) -> None: - """Seed one complete active canonical actor for rollback guard tests.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await _insert_canonical_actor(connection, actor_id, "rollback-guard", "human") - finally: - await engine.dispose() - - -async def _set_canonical_actor_guard_state( - database_url: str, - actor_id: str, - state: str, -) -> None: - """Put one actor in a reviewed rollback stop state.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - if state == "revoked": - await connection.execute( - text( - "update actor_identity_links set status='revoked', " - "revoked_by=:actor, revoked_at=now(), revoked_reason='test guard' " - "where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - elif state == "suspended": - await connection.execute( - text( - "update actor_profiles set status='suspended', suspended_by=:actor, " - "suspended_at=now(), suspension_reason='test guard' where id=:actor" - ), - {"actor": actor_id}, - ) - elif state == "deactivated": - await connection.execute( - text( - "update actor_profiles set status='deactivated', deactivated_by=:actor, " - "deactivated_at=now(), deactivation_reason='test guard' where id=:actor" - ), - {"actor": actor_id}, - ) - else: - raise AssertionError(f"unknown test state: {state}") - finally: - await engine.dispose() - - -async def _reset_canonical_actor_guard_state( - database_url: str, - actor_id: str, -) -> None: - """Restore test-owned state after proving the migration refuses it.""" - engine = create_async_engine(database_url) - history_guards_disabled = False - try: - try: - async with engine.begin() as connection: - await connection.execute( - text("alter table actor_profiles disable trigger actor_profile_history_guard") - ) - await connection.execute( - text( - "alter table actor_identity_links disable trigger " - "actor_identity_link_history_guard" - ) - ) - history_guards_disabled = True - async with engine.begin() as connection: - await connection.execute( - text( - "update actor_profiles set status='active', suspended_by=null, " - "suspended_at=null, suspension_reason=null, deactivated_by=null, " - "deactivated_at=null, deactivation_reason=null, reactivated_by=null, " - "reactivated_at=null, reactivation_reason=null where id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute( - text( - "update actor_identity_links set status='active', revoked_by=null, " - "revoked_at=null, revoked_reason=null, reactivated_by=null, " - "reactivated_at=null, reactivation_reason=null " - "where actor_profile_id=:actor" - ), - {"actor": actor_id}, - ) - finally: - if history_guards_disabled: - async with engine.begin() as connection: - await connection.execute( - text( - "alter table actor_profiles enable trigger actor_profile_history_guard" - ) - ) - await connection.execute( - text( - "alter table actor_identity_links enable trigger " - "actor_identity_link_history_guard" - ) - ) - finally: - await engine.dispose() - - -async def _assert_actor_registry_unique_constraints(database_url: str) -> None: - """Prove canonical indexes, constraints, timestamps, and history guards.""" - engine = create_async_engine(database_url) - actor_id = actor_id_from_external_identity("https://identity.test", "unique-actor") - try: - async with engine.begin() as connection: - await _insert_canonical_actor(connection, actor_id, "unique-actor", "human") - index_rows = ( - await connection.execute( - text( - "select indexname,indexdef from pg_indexes " - "where schemaname=current_schema() and " - "tablename in ('actor_profiles','actor_identity_links')" - ) - ) - ).all() - indexes = {row.indexname: row.indexdef for row in index_rows} - assert "(status, actor_kind)" in indexes["ix_actor_profiles_status_actor_kind"] - assert "(last_seen_at)" in indexes["ix_actor_profiles_last_seen_at"] - assert ( - "(issuer, subject, status)" - in indexes["ix_actor_identity_links_issuer_subject_status"] - ) - assert "ix_actor_profiles_actor_kind" not in indexes - assert "ix_actor_profiles_status" not in indexes - assert "ix_actor_identity_links_status" not in indexes - timestamps = ( - await connection.execute( - text( - "select p.created_at,p.updated_at,l.linked_at,l.last_verified_at " - "from actor_profiles p join actor_identity_links l " - "on l.actor_profile_id=p.id where p.id=:actor" - ), - {"actor": actor_id}, - ) - ).one() - assert all(value is not None and value.tzinfo is not None for value in timestamps) - - await _expect_integrity_error( - engine, - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:actor,'human','active','automatic_first_access',:actor)" - ), - {"actor": actor_id}, - ) - await _expect_integrity_error( - engine, - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by," - "last_verified_at) values (:id,:actor,'https://identity.test'," - "'second-link','human','active',:actor,clock_timestamp())" - ), - {"id": str(uuid4()), "actor": actor_id}, - ) - - invalid_profiles = ( - ("not-a-uuid", "human", "active", "automatic_first_access", {}), - (str(uuid4()), "agent", "active", "automatic_first_access", {}), - (str(uuid4()), "human", "unknown", "automatic_first_access", {}), - (str(uuid4()), "human", "active", "manual_service_provisioning", {}), - ( - str(uuid4()), - "human", - "suspended", - "automatic_first_access", - {}, - ), - ) - for invalid_id, kind, status, method, lifecycle in invalid_profiles: - await _expect_integrity_error( - engine, - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:id,:kind,:status,:method,:id)" - ), - { - "id": invalid_id, - "kind": kind, - "status": status, - "method": method, - **lifecycle, - }, - ) - - invalid_links = ( - {"link_id": "not-a-uuid"}, - {"issuer": " "}, - {"link_subject": " "}, - {"subject_kind": "agent"}, - {"status": "unknown"}, - {"status": "revoked"}, - ) - for position, overrides in enumerate(invalid_links): - await _expect_invalid_canonical_pair( - engine, - subject=f"invalid-link-{position}", - **overrides, - ) - - await _expect_dbapi_error( - engine, - text("update actor_profiles set actor_kind='service' where id=:actor"), - {"actor": actor_id}, - ) - await _expect_dbapi_error( - engine, - text("update actor_identity_links set subject='changed' where actor_profile_id=:actor"), - {"actor": actor_id}, - ) - await _expect_dbapi_error( - engine, - text("delete from actor_profiles where id=:actor"), - {"actor": actor_id}, - ) - await _expect_dbapi_error( - engine, - text("delete from actor_identity_links where actor_profile_id=:actor"), - {"actor": actor_id}, - ) - orphan_id = actor_id_from_external_identity("https://identity.test", "orphan-profile") - await _expect_integrity_error( - engine, - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:actor,'human','active','automatic_first_access',:actor)" - ), - {"actor": orphan_id}, - ) - - connection = await engine.connect() - transaction = await connection.begin() - try: - await connection.execute( - text( - "update actor_profiles set status='deactivated', " - "deactivated_by=:actor,deactivated_at=now()," - "deactivation_reason='terminal proof' where id=:actor" - ), - {"actor": actor_id}, - ) - with pytest.raises(DBAPIError): - await connection.execute( - text( - "update actor_profiles set status='active',deactivated_by=null," - "deactivated_at=null,deactivation_reason=null where id=:actor" - ), - {"actor": actor_id}, - ) - finally: - await transaction.rollback() - await connection.close() - - width_actor_id = actor_id_from_external_identity("https://identity.test", "s" * 200) - async with engine.begin() as connection: - await _insert_canonical_actor(connection, width_actor_id, "s" * 200, "human") - oversized_actor_id = actor_id_from_external_identity("https://identity.test", "s" * 201) - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await _insert_canonical_actor(connection, oversized_actor_id, "s" * 201, "human") - - other_actor_id = actor_id_from_external_identity( - "https://identity.test", "other-unique-actor" - ) - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await _insert_canonical_actor( - connection, - other_actor_id, - "unique-actor", - "human", - ) - - mismatched_actor_id = actor_id_from_external_identity( - "https://identity.test", "kind-mismatch" - ) - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await _insert_canonical_actor( - connection, - mismatched_actor_id, - "kind-mismatch", - "service", - link_kind="human", - ) - finally: - await engine.dispose() - - -async def _insert_canonical_actor( - connection, - actor_id: str, - subject: str, - actor_kind: str, - *, - link_kind: str | None = None, -) -> None: - """Insert a complete profile-link pair in one deferred-constraint transaction.""" - provisioning = ( - "automatic_first_access" if actor_kind == "human" else "manual_service_provisioning" - ) - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:actor,:kind,'active',:provisioning,:actor)" - ), - {"actor": actor_id, "kind": actor_kind, "provisioning": provisioning}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by," - "last_verified_at) values (:id,:actor,'https://identity.test',:subject," - ":kind,'active',:actor,clock_timestamp())" - ), - { - "id": str(uuid4()), - "actor": actor_id, - "subject": subject, - "kind": link_kind or actor_kind, - }, - ) - - -async def _expect_invalid_canonical_pair( - engine, - *, - subject: str, - link_id: str | None = None, - issuer: str = "https://identity.test", - link_subject: str | None = None, - subject_kind: str = "human", - status: str = "active", -) -> None: - """Assert that a malformed identity link cannot commit with its profile.""" - actor_id = actor_id_from_external_identity("https://identity.test", subject) - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:actor,'human','active','automatic_first_access',:actor)" - ), - {"actor": actor_id}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by," - "last_verified_at) values (:id,:actor,:issuer,:subject,:kind,:status," - ":actor,clock_timestamp())" - ), - { - "id": link_id or str(uuid4()), - "actor": actor_id, - "issuer": issuer, - "subject": subject if link_subject is None else link_subject, - "kind": subject_kind, - "status": status, - }, - ) - - -async def _expect_integrity_error(engine, statement, params: dict) -> None: - """Assert that one SQL statement raises a database integrity error.""" - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await connection.execute(statement, params) - - -async def _expect_dbapi_error(engine, statement, params: dict) -> None: - """Assert that one statement is rejected by a database trigger or constraint.""" - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute(statement, params) - - -async def _seed_pre_provenance_post_submit_policy( - database_url: str, - project_id: str, - guide_id: str, - policy_id: str, -) -> None: - """Seed a valid 0007 checker policy row before post-submit hashes exist.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into projects ( - id, - name, - slug, - status - ) - values ( - :project_id, - 'Pre-provenance policy project', - 'pre-provenance-policy-project', - 'draft' - ) - """ - ), - {"project_id": project_id}, - ) - await connection.execute( - text( - """ - insert into project_guides ( - id, - project_id, - version, - status, - content_markdown, - created_by - ) - values ( - :guide_id, - :project_id, - 'v1', - 'draft', - '# Pre-provenance guide', - 'pre-provenance-test' - ) - """ - ), - {"guide_id": guide_id, "project_id": project_id}, - ) - await connection.execute( - text( - """ - insert into checker_policies ( - id, - project_id, - guide_version, - required_checkers, - warning_checkers, - blocking_severities - ) - values ( - :policy_id, - :project_id, - 'v1', - '["check_policy_context_present"]'::json, - '[]'::json, - '["high"]'::json - ) - """ - ), - {"policy_id": policy_id, "project_id": project_id}, - ) - finally: - await engine.dispose() - - -async def _seed_pre_provenance_runtime_rows(database_url: str, ids: dict[str, str]) -> None: - """Seed 0007 runtime rows that cannot be trusted under 0008 provenance.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into projects ( - id, - name, - slug, - status - ) - values ( - :project_id, - 'Pre-provenance runtime project', - 'pre-provenance-runtime-project', - 'draft' - ) - """ - ), - {"project_id": ids["project"]}, - ) - await connection.execute( - text( - """ - insert into project_guides ( - id, - project_id, - version, - status, - content_markdown, - created_by - ) - values ( - :guide_id, - :project_id, - 'v1', - 'active', - '# Pre-provenance runtime guide', - 'pre-provenance-test' - ) - """ - ), - {"guide_id": ids["guide"], "project_id": ids["project"]}, - ) - await _seed_pre_provenance_policies(connection, ids["project"], ids["policy"]) - await connection.execute( - text( - """ - insert into workstream_tasks ( - id, - project_id, - locked_guide_version, - locked_review_policy_version, - locked_revision_policy_version, - locked_payment_policy_version, - source_type, - title, - description, - skill_tags, - status, - created_by - ) - values ( - :task_id, - :project_id, - 'v1', - 'v1', - 'v1', - 'v1', - 'manual', - 'Pre-provenance runtime task', - 'Already in progress before 0008.', - '[]'::json, - 'in_progress', - 'pre-provenance-test' - ) - """ - ), - {"task_id": ids["task"], "project_id": ids["project"]}, - ) - await connection.execute( - text( - """ - insert into submissions ( - id, - task_id, - worker_id, - version, - status, - summary, - package_hash, - artifact_hash_manifest, - worker_attestation, - locked_guide_version, - locked_review_policy_version, - locked_revision_policy_version, - locked_payment_policy_version - ) - values ( - :submission_id, - :task_id, - 'pre-provenance-worker', - 1, - 'submitted', - 'Pre-provenance submitted packet', - 'sha256:pre-provenance-package', - '[]'::json, - 'pre-provenance attestation', - 'v1', - 'v1', - 'v1', - 'v1' - ) - """ - ), - {"submission_id": ids["submission"], "task_id": ids["task"]}, - ) - await connection.execute( - text( - """ - insert into checker_runs ( - id, - task_id, - submission_id, - submission_version, - trigger_source, - status, - routing_recommendation, - outcome_source, - triggered_by, - triggered_by_subject, - triggered_by_issuer, - trigger_auth_source, - attempt_number, - is_current_for_submission, - locked_guide_version, - locked_review_policy_version, - locked_revision_policy_version, - locked_payment_policy_version, - package_hash, - artifact_hash_manifest, - artifact_manifest_hash, - passed_count, - warning_count, - failed_count, - blocking_count - ) - values ( - :run_id, - :task_id, - :submission_id, - 1, - 'submission_lock', - 'completed', - 'allow_review', - 'auto_checker', - 'pre-provenance-test', - 'pre-provenance-test', - 'flow-pre-provenance', - 'flow', - 1, - true, - 'v1', - 'v1', - 'v1', - 'v1', - 'sha256:pre-provenance-package', - '[]'::json, - 'sha256:pre-provenance-manifest', - 1, - 0, - 0, - 0 - ) - """ - ), - { - "run_id": ids["run"], - "task_id": ids["task"], - "submission_id": ids["submission"], - }, - ) - finally: - await engine.dispose() - - -async def _seed_pre_provenance_policies( - connection, project_id: str, checker_policy_id: str -) -> None: - """Seed v0.1 guide policies required by locked task foreign keys.""" - await connection.execute( - text( - """ - insert into checker_policies ( - id, - project_id, - guide_version, - required_checkers, - warning_checkers, - blocking_severities - ) - values ( - :checker_policy_id, - :project_id, - 'v1', - '["check_policy_context_present"]'::json, - '[]'::json, - '["high"]'::json - ) - """ - ), - {"checker_policy_id": checker_policy_id, "project_id": project_id}, - ) - await connection.execute( - text( - """ - insert into review_policies ( - id, - project_id, - guide_version, - requires_second_review, - allowed_decisions, - minimum_finding_fields - ) - values ( - :review_policy_id, - :project_id, - 'v1', - false, - '["accept", "needs_revision", "reject"]'::json, - '[]'::json - ) - """ - ), - {"review_policy_id": str(uuid4()), "project_id": project_id}, - ) - await connection.execute( - text( - """ - insert into revision_policies ( - id, - project_id, - guide_version, - max_revision_rounds, - revision_deadline_hours, - auto_reject_after_limit, - allowed_resubmission_states - ) - values ( - :revision_policy_id, - :project_id, - 'v1', - 7, - 48, - true, - '["needs_revision"]'::json - ) - """ - ), - {"revision_policy_id": str(uuid4()), "project_id": project_id}, - ) - await connection.execute( - text( - """ - insert into payment_policies ( - id, - project_id, - guide_version, - base_amount, - currency, - payout_type - ) - values ( - :payment_policy_id, - :project_id, - 'v1', - 25.00, - 'USD', - 'fixed' - ) - """ - ), - {"payment_policy_id": str(uuid4()), "project_id": project_id}, - ) - - -async def _post_submit_lock_columns_exist(database_url: str, table_name: str) -> bool: - """Return whether a post-submit lock column was added to a table.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - count = await connection.scalar( - text( - """ - select count(*) - from information_schema.columns - where table_name = :table_name - and column_name = 'locked_post_submit_checker_policy_id' - """ - ), - {"table_name": table_name}, - ) - return bool(count) - finally: - await engine.dispose() - - -async def _fetch_pre_provenance_post_submit_policy_hash( - database_url: str, - policy_id: str, -) -> str | None: - """Return the post-submit policy hash created by the 0008 migration, if any.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - return await connection.scalar( - text("select policy_hash from checker_policies where id = :policy_id"), - {"policy_id": policy_id}, - ) - finally: - await engine.dispose() - - -async def _seed_artifact_prior_head(database_url: str, project_id: str) -> None: - """Seed one representative legacy row at the previous migration head.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into projects (id, name, slug, status) - values (:id, 'Prior artifact project', :slug, 'draft') - """ - ), - {"id": project_id, "slug": f"prior-artifact-{project_id}"}, - ) - finally: - await engine.dispose() - - -async def _seed_artifact_prior_head_runtime_rows( - database_url: str, - ids: dict[str, str], -) -> None: - """Seed representative runtime rows valid at the 0015 migration head.""" - snapshot_id = ids["snapshot"] - submission_policy_id = ids["submission_policy"] - effective_policy_id = ids["effective_policy"] - pre_submit_policy_id = ids["pre_submit_policy"] - review_policy_id = ids["review_policy"] - revision_policy_id = ids["revision_policy"] - payment_policy_id = ids["payment_policy"] - snapshot_hash = f"sha256:{'a' * 64}" - submission_policy_hash = f"sha256:{'b' * 64}" - effective_policy_hash = f"sha256:{'c' * 64}" - pre_submit_bundle_hash = f"sha256:{'d' * 64}" - post_submit_policy_hash = f"sha256:{'e' * 64}" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into projects (id, name, slug, status) - values (:id, 'Artifact runtime project', :slug, 'active') - """ - ), - {"id": ids["project"], "slug": f"artifact-runtime-{ids['project']}"}, - ) - await connection.execute( - text( - """ - insert into project_guides ( - id, project_id, version, status, content_markdown, - created_by, approved_by - ) - values ( - :id, :project_id, 'v1', 'active', '# Artifact runtime guide', - 'artifact-migration-test', 'artifact-migration-test' - ) - """ - ), - {"id": ids["guide"], "project_id": ids["project"]}, - ) - await connection.execute( - text( - """ - insert into guide_source_snapshots ( - id, project_id, guide_id, guide_version, - manifest_schema_version, manifest_json, bundle_hash, captured_by - ) - values ( - :id, :project_id, :guide_id, 'v1', '1', '{}'::json, - :bundle_hash, 'artifact-migration-test' - ) - """ - ), - { - "id": snapshot_id, - "project_id": ids["project"], - "guide_id": ids["guide"], - "bundle_hash": snapshot_hash, - }, - ) - await connection.execute( - text( - """ - insert into submission_artifact_policies ( - id, project_id, guide_id, guide_version, - source_snapshot_id, source_snapshot_hash, policy_version, - lifecycle_status, policy_body, policy_hash, derivation_source, - source_material_refs, created_by, approved_by_role, - approved_by_actor, approved_at - ) - values ( - :id, :project_id, :guide_id, 'v1', :snapshot_id, - :snapshot_hash, 'v1', 'approved', '{}'::json, :policy_hash, - 'migration_test', '[]'::json, 'artifact-migration-test', - 'admin', 'artifact-migration-test', now() - ) - """ - ), - { - "id": submission_policy_id, - "project_id": ids["project"], - "guide_id": ids["guide"], - "snapshot_id": snapshot_id, - "snapshot_hash": snapshot_hash, - "policy_hash": submission_policy_hash, - }, - ) - await connection.execute( - text( - """ - insert into effective_project_submission_artifact_policies ( - id, project_id, guide_id, guide_version, - source_snapshot_id, source_snapshot_hash, - submission_artifact_policy_id, submission_artifact_policy_hash, - lifecycle_status, merge_algorithm_version, effective_policy, - effective_policy_hash, created_by - ) - values ( - :id, :project_id, :guide_id, 'v1', :snapshot_id, - :snapshot_hash, :submission_policy_id, :submission_policy_hash, - 'approved', '1', '{}'::json, :effective_policy_hash, - 'artifact-migration-test' - ) - """ - ), - { - "id": effective_policy_id, - "project_id": ids["project"], - "guide_id": ids["guide"], - "snapshot_id": snapshot_id, - "snapshot_hash": snapshot_hash, - "submission_policy_id": submission_policy_id, - "submission_policy_hash": submission_policy_hash, - "effective_policy_hash": effective_policy_hash, - }, - ) - await connection.execute( - text( - """ - insert into pre_submit_checker_policies ( - id, project_id, guide_id, guide_version, - source_snapshot_id, source_snapshot_hash, effective_policy_id, - effective_policy_hash, lifecycle_status, compiler_version, - compiled_bundle, compiled_bundle_hash, checker_names, - checker_configs, created_by - ) - values ( - :id, :project_id, :guide_id, 'v1', :snapshot_id, - :snapshot_hash, :effective_policy_id, :effective_policy_hash, - 'compiled', '1', '{}'::json, :bundle_hash, '[]'::json, - '{}'::json, 'artifact-migration-test' - ) - """ - ), - { - "id": pre_submit_policy_id, - "project_id": ids["project"], - "guide_id": ids["guide"], - "snapshot_id": snapshot_id, - "snapshot_hash": snapshot_hash, - "effective_policy_id": effective_policy_id, - "effective_policy_hash": effective_policy_hash, - "bundle_hash": pre_submit_bundle_hash, - }, - ) - await connection.execute( - text( - """ - insert into checker_policies ( - id, project_id, guide_id, guide_version, - source_snapshot_id, source_snapshot_hash, effective_policy_id, - effective_policy_hash, pre_submit_checker_policy_id, - pre_submit_checker_bundle_hash, required_checkers, - warning_checkers, blocking_severities, policy_hash, policy_body, - lifecycle_status, approved_by_role, approved_by_actor, - approved_at, created_by - ) - values ( - :id, :project_id, :guide_id, 'v1', :snapshot_id, - :snapshot_hash, :effective_policy_id, :effective_policy_hash, - :pre_submit_policy_id, :pre_submit_bundle_hash, - '["artifact_integrity"]'::json, '[]'::json, '["high"]'::json, - :policy_hash, '{}'::json, 'approved', 'admin', - 'artifact-migration-test', now(), 'artifact-migration-test' - ) - """ - ), - { - "id": ids["policy"], - "project_id": ids["project"], - "guide_id": ids["guide"], - "snapshot_id": snapshot_id, - "snapshot_hash": snapshot_hash, - "effective_policy_id": effective_policy_id, - "effective_policy_hash": effective_policy_hash, - "pre_submit_policy_id": pre_submit_policy_id, - "pre_submit_bundle_hash": pre_submit_bundle_hash, - "policy_hash": post_submit_policy_hash, - }, - ) - await _seed_pre_provenance_policies_without_checker( - connection, - ids["project"], - review_policy_id, - revision_policy_id, - payment_policy_id, - ) - lock_params = { - "project_id": ids["project"], - "post_policy_id": ids["policy"], - "post_policy_hash": post_submit_policy_hash, - "snapshot_id": snapshot_id, - "snapshot_hash": snapshot_hash, - "effective_policy_id": effective_policy_id, - "effective_policy_hash": effective_policy_hash, - "pre_submit_policy_id": pre_submit_policy_id, - "pre_submit_bundle_hash": pre_submit_bundle_hash, - } - await connection.execute( - text( - """ - insert into workstream_tasks ( - id, project_id, locked_guide_version, - locked_post_submit_checker_policy_id, - locked_post_submit_checker_policy_version, - locked_post_submit_checker_policy_hash, - locked_post_submit_checker_policy_body, - locked_review_policy_version, locked_revision_policy_version, - locked_payment_policy_version, locked_guide_source_snapshot_id, - locked_guide_source_snapshot_hash, - locked_effective_project_submission_artifact_policy_id, - locked_effective_project_submission_artifact_policy_hash, - locked_pre_submit_checker_policy_id, - locked_pre_submit_checker_bundle_hash, source_type, title, - description, skill_tags, status, created_by - ) - values ( - :id, :project_id, 'v1', :post_policy_id, 'v1', - :post_policy_hash, '{}'::json, 'v1', 'v1', 'v1', - :snapshot_id, :snapshot_hash, :effective_policy_id, - :effective_policy_hash, :pre_submit_policy_id, - :pre_submit_bundle_hash, 'manual', 'Artifact runtime task', - 'Representative task at migration 0015.', '[]'::json, - 'in_progress', 'artifact-migration-test' - ) - """ - ), - {"id": ids["task"], **lock_params}, - ) - await connection.execute( - text( - """ - insert into submissions ( - id, task_id, worker_id, version, status, summary, - package_hash, artifact_hash_manifest, worker_attestation, - locked_guide_version, locked_post_submit_checker_policy_id, - locked_post_submit_checker_policy_version, - locked_post_submit_checker_policy_hash, - locked_post_submit_checker_policy_body, - locked_review_policy_version, locked_revision_policy_version, - locked_payment_policy_version, locked_guide_source_snapshot_id, - locked_guide_source_snapshot_hash, - locked_effective_project_submission_artifact_policy_id, - locked_effective_project_submission_artifact_policy_hash, - locked_pre_submit_checker_policy_id, - locked_pre_submit_checker_bundle_hash - ) - values ( - :id, :task_id, 'artifact-worker', 1, 'submitted', - 'Representative submission at migration 0015.', - 'sha256:artifact-package', '[]'::json, - 'artifact migration attestation', 'v1', :post_policy_id, - 'v1', :post_policy_hash, '{}'::json, 'v1', 'v1', 'v1', - :snapshot_id, :snapshot_hash, :effective_policy_id, - :effective_policy_hash, :pre_submit_policy_id, - :pre_submit_bundle_hash - ) - """ - ), - {"id": ids["submission"], "task_id": ids["task"], **lock_params}, - ) - await connection.execute( - text( - """ - insert into checker_runs ( - id, task_id, submission_id, submission_version, - trigger_source, status, routing_recommendation, outcome_source, - triggered_by, triggered_by_subject, triggered_by_issuer, - trigger_auth_source, attempt_number, is_current_for_submission, - locked_guide_version, locked_post_submit_checker_policy_id, - locked_post_submit_checker_policy_version, - locked_post_submit_checker_policy_hash, - locked_post_submit_checker_policy_body, - locked_review_policy_version, locked_revision_policy_version, - locked_payment_policy_version, package_hash, - artifact_hash_manifest, artifact_manifest_hash, passed_count, - warning_count, failed_count, blocking_count - ) - values ( - :id, :task_id, :submission_id, 1, 'submission_lock', - 'completed', 'allow_review', 'auto_checker', - 'artifact-migration-test', 'artifact-migration-test', - 'flow-test', 'flow', 1, true, 'v1', :post_policy_id, 'v1', - :post_policy_hash, '{}'::json, 'v1', 'v1', 'v1', - 'sha256:artifact-package', '[]'::json, - 'sha256:artifact-manifest', 1, 0, 0, 0 - ) - """ - ), - { - "id": ids["run"], - "task_id": ids["task"], - "submission_id": ids["submission"], - **lock_params, - }, - ) - finally: - await engine.dispose() - - -async def _seed_pre_provenance_policies_without_checker( - connection, - project_id: str, - review_policy_id: str, - revision_policy_id: str, - payment_policy_id: str, -) -> None: - """Seed the non-checker guide policies needed by a locked task.""" - await connection.execute( - text( - """ - insert into review_policies ( - id, project_id, guide_version, requires_second_review, - allowed_decisions, minimum_finding_fields - ) values ( - :id, :project_id, 'v1', false, - '["accept", "needs_revision", "reject"]'::json, '[]'::json - ) - """ - ), - {"id": review_policy_id, "project_id": project_id}, - ) - await connection.execute( - text( - """ - insert into revision_policies ( - id, project_id, guide_version, max_revision_rounds, - revision_deadline_hours, auto_reject_after_limit, - allowed_resubmission_states - ) values ( - :id, :project_id, 'v1', 7, 48, true, '["needs_revision"]'::json - ) - """ - ), - {"id": revision_policy_id, "project_id": project_id}, - ) - await connection.execute( - text( - """ - insert into payment_policies ( - id, project_id, guide_version, base_amount, currency, payout_type - ) values (:id, :project_id, 'v1', 25.00, 'USD', 'fixed') - """ - ), - {"id": payment_policy_id, "project_id": project_id}, - ) - - -async def _artifact_prior_head_project(database_url: str, project_id: str) -> dict[str, str]: - """Return exact prior-head project values for migration comparison.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - row = ( - ( - await connection.execute( - text("select id, name, slug, status from projects where id = :id"), - {"id": project_id}, - ) - ) - .mappings() - .one() - ) - return dict(row) - finally: - await engine.dispose() - - -async def _artifact_prior_head_runtime_rows( - database_url: str, ids: dict[str, str] -) -> dict[str, dict]: - """Return every column from representative populated 0015 domain rows.""" - table_ids = { - "projects": ids["project"], - "project_guides": ids["guide"], - "guide_source_snapshots": ids["snapshot"], - "submission_artifact_policies": ids["submission_policy"], - "effective_project_submission_artifact_policies": ids["effective_policy"], - "pre_submit_checker_policies": ids["pre_submit_policy"], - "checker_policies": ids["policy"], - "review_policies": ids["review_policy"], - "revision_policies": ids["revision_policy"], - "payment_policies": ids["payment_policy"], - "workstream_tasks": ids["task"], - "submissions": ids["submission"], - "checker_runs": ids["run"], - } - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - rows: dict[str, dict] = {} - for table_name, row_id in table_ids.items(): - value = await connection.scalar( - text( - f"select row_to_json(selected) from " - f"(select * from {table_name} where id = :id) selected" - ), - {"id": row_id}, - ) - assert isinstance(value, dict) - rows[table_name] = value - return rows - finally: - await engine.dispose() - - -async def _artifact_table_counts(database_url: str) -> dict[str, int]: - """Return row counts for every additive artifact table.""" - tables = ( - "artifact_upload_sessions", - "artifact_upload_items", - "artifact_contents", - "artifact_bindings", - "artifact_replicas", - "artifact_operation_receipts", - ) - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - counts: dict[str, int] = {} - for table in tables: - count = await connection.scalar(text(f"select count(*) from {table}")) - counts[table] = int(count or 0) - return counts - finally: - await engine.dispose() - - -async def _seed_artifact_content(database_url: str) -> None: - """Insert one content fact that a clean-cut migration must refuse.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into artifact_contents " - "(id, sha256, byte_count, media_type, normalized_display_name) " - "values (:id, :sha256, 1, 'application/octet-stream', 'legacy.bin')" - ), - {"id": str(uuid4()), "sha256": "sha256:" + "1" * 64}, - ) - finally: - await engine.dispose() - - -async def _seed_v2_artifact_namespace(database_url: str) -> None: - """Insert the v2-only namespace fact that downgrade must preserve.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into artifact_storage_namespaces " - "(id, backend, adapter, provider_profile, namespace_descriptor, " - "namespace_fingerprint) values " - "('primary', 'local', 'local', 'local-v2', '{}'::json, :fingerprint)" - ), - {"fingerprint": "sha256:" + "3" * 64}, - ) - finally: - await engine.dispose() - - -async def _artifact_namespace_count(database_url: str) -> int: - """Return the current v2 deployment-namespace fact count.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - count = await connection.scalar( - text("select count(*) from artifact_storage_namespaces") - ) - return int(count or 0) - finally: - await engine.dispose() - - -async def _truncate_v2_artifact_namespace(database_url: str) -> None: - """Clear the v2 namespace when its table exists during test cleanup.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - exists = await connection.scalar( - text("select to_regclass('public.artifact_storage_namespaces') is not null") - ) - if exists: - await connection.execute(text("truncate table artifact_storage_namespaces cascade")) - finally: - await engine.dispose() - - -async def _insert_v1_artifact_content_until_released( - database_url: str, - inserted: threading.Event, - release: threading.Event, -) -> None: - """Hold one uncommitted v1 writer while the clean-cut upgrade requests locks.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into artifact_contents " - "(id, sha256, byte_count, media_type, normalized_display_name) " - "values (:id, :sha256, 1, 'application/octet-stream', 'raced.bin')" - ), - {"id": str(uuid4()), "sha256": "sha256:" + "2" * 64}, - ) - inserted.set() - assert await asyncio.to_thread(release.wait, 5) - finally: - await engine.dispose() - - -async def _artifact_v2_refusal_state(database_url: str) -> dict[str, object]: - """Return transactional proof that refusal changed no v1 schema or data.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - revision = await connection.scalar(text("select version_num from alembic_version")) - namespace_table = await connection.scalar( - text("select to_regclass('public.artifact_storage_namespaces') is not null") - ) - content_count = await connection.scalar(text("select count(*) from artifact_contents")) - return { - "revision": revision, - "namespace_table_exists": namespace_table, - "v1_content_count": content_count, - } - finally: - await engine.dispose() - - -async def _assert_artifact_fact_guards(database_url: str, ids: dict[str, str]) -> None: - """Exercise digest and immutable-row guards directly in PostgreSQL.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into projects (id, name, slug, status) - values (:project_id, 'Artifact guards', :slug, 'draft') - """ - ), - {"project_id": ids["project"], "slug": f"guards-{ids['project']}"}, - ) - await connection.execute( - text( - """ - insert into artifact_contents (id, sha256, byte_count) - values (:content_id, :sha256, 0) - """ - ), - {"content_id": ids["content"], "sha256": "sha256:" + "0" * 64}, - ) - await connection.execute( - text( - """ - insert into artifact_upload_sessions ( - id, actor_id, project_id, permitted_roles, state, - maximum_bytes, current_bytes, reserved_bytes, - maximum_items, current_items, reserved_items, expires_at, cas_version - ) values ( - :id, 'actor', :project, '[]'::json, 'open', - 8, 0, 4, 1, 0, 1, now() + interval '1 hour', 0 - ) - """ - ), - {"id": ids["session"], "project": ids["project"]}, - ) - await connection.execute( - text( - """ - insert into artifact_upload_items ( - id, session_id, logical_role, display_name, reserved_bytes, - idempotency_key, request_digest, state, cas_version - ) values ( - :id, :session, 'packet', 'packet.bin', 4, - 'idem', :digest, 'reserved', 0 - ) - """ - ), - {"id": ids["item"], "session": ids["session"], "digest": "sha256:" + "1" * 64}, - ) - await connection.execute( - text( - """ - insert into artifact_replicas ( - id, content_id, adapter, provider_artifact_id, - verification_state, retention_state, availability_state, integrity_state - ) values ( - :id, :content, 'local', 'artifact-provider-id', - 'pending', 'unretained', 'available', 'valid' - ) - """ - ), - {"id": ids["replica"], "content": ids["content"]}, - ) - await connection.execute( - text( - """ - insert into artifact_operation_receipts ( - id, upload_item_id, replica_id, adapter, service_principal, - operation, idempotency_key, request_digest, response_digest, - provider_receipt_id, provider_operation_reference, outcome, attempt_number, - correlation_id, provider_recorded_at, details - ) values ( - :id, :item, :replica, 'local', 'workstream.artifact', - 'store', 'idem', :request_digest, :response_digest, - 'provider-receipt', 'provider-operation', 'stored', 1, - 'correlation', now(), '{}'::json - ) - """ - ), - { - "id": ids["receipt"], - "item": ids["item"], - "replica": ids["replica"], - "request_digest": "sha256:" + "1" * 64, - "response_digest": "sha256:" + "2" * 64, - }, - ) - await connection.execute( - text( - """ - insert into artifact_bindings ( - id, content_id, project_id, resource_type, resource_id, - logical_role, scope_version, actor_id, attribution_type - ) values ( - :id, :content, :project, 'submission', 'submission-1', - 'packet', 1, 'actor', 'submitted_by' - ) - """ - ), - {"id": ids["binding"], "content": ids["content"], "project": ids["project"]}, - ) - await connection.execute( - text( - """ - insert into artifact_bindings ( - id, content_id, project_id, resource_type, resource_id, - logical_role, scope_version, actor_id, attribution_type, - supersedes_binding_id - ) values ( - :id, :content, :project, 'submission', 'submission-1', - 'packet', 2, 'actor', 'submitted_by', :predecessor - ) - """ - ), - { - "id": ids["binding_v2"], - "content": ids["content"], - "project": ids["project"], - "predecessor": ids["binding"], - }, - ) - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute( - text("update artifact_contents set byte_count = 1 where id = :id"), - {"id": ids["content"]}, - ) - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into artifact_contents (id, sha256, byte_count) - values (:id, 'SHA256:INVALID', 1) - """ - ), - {"id": str(uuid4())}, - ) - failing_statements = ( - ( - "update artifact_upload_sessions set state = 'unknown' where id = :id", - {"id": ids["session"]}, - ), - ( - "update artifact_upload_sessions set current_bytes = -1 where id = :id", - {"id": ids["session"]}, - ), - ( - "update artifact_upload_sessions set state = 'sealed' where id = :id", - {"id": ids["session"]}, - ), - ( - "update artifact_upload_sessions set reserved_bytes = 9 where id = :id", - {"id": ids["session"]}, - ), - ( - "update artifact_upload_items set state = 'unknown' where id = :id", - {"id": ids["item"]}, - ), - ( - "update artifact_upload_items set reserved_bytes = -1 where id = :id", - {"id": ids["item"]}, - ), - ( - "update artifact_upload_items set cas_version = -1 where id = :id", - {"id": ids["item"]}, - ), - ( - "update artifact_upload_items set content_id = :content, " - "provider_operation_reference = 'op' where id = :id", - {"id": ids["item"], "content": ids["content"]}, - ), - ( - "update artifact_upload_items set state = 'ready' where id = :id", - {"id": ids["item"]}, - ), - ( - "update artifact_replicas set verification_state = 'trusted' where id = :id", - {"id": ids["replica"]}, - ), - ( - "update artifact_replicas set retention_state = 'held' where id = :id", - {"id": ids["replica"]}, - ), - ( - "update artifact_replicas set availability_state = 'online' where id = :id", - {"id": ids["replica"]}, - ), - ( - "update artifact_replicas set integrity_state = 'trusted' where id = :id", - {"id": ids["replica"]}, - ), - ( - "update artifact_operation_receipts set operation = 'copy' where id = :id", - {"id": ids["receipt"]}, - ), - ( - "update artifact_operation_receipts set attempt_number = 0 where id = :id", - {"id": ids["receipt"]}, - ), - ( - "update artifact_operation_receipts set outcome = 'verified' where id = :id", - {"id": ids["receipt"]}, - ), - ( - "delete from artifact_operation_receipts where id = :id", - {"id": ids["receipt"]}, - ), - ( - "update artifact_bindings set logical_role = 'other' where id = :id", - {"id": ids["binding"]}, - ), - ( - "delete from artifact_bindings where id = :id", - {"id": ids["binding_v2"]}, - ), - ) - for statement, parameters in failing_statements: - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute(text(statement), parameters) - - duplicate_statements = ( - ( - "insert into artifact_contents (id, sha256, byte_count) " - "select :new_id, sha256, byte_count from artifact_contents where id = :id", - {"new_id": str(uuid4()), "id": ids["content"]}, - ), - ( - "insert into artifact_upload_items " - "(id, session_id, logical_role, display_name, reserved_bytes, " - "idempotency_key, request_digest, state, cas_version) " - "select :new_id, session_id, logical_role, display_name, reserved_bytes, " - "idempotency_key, request_digest, state, cas_version " - "from artifact_upload_items where id = :id", - {"new_id": str(uuid4()), "id": ids["item"]}, - ), - ( - "insert into artifact_replicas " - "(id, content_id, adapter, provider_artifact_id, verification_state, " - "retention_state, availability_state, integrity_state) " - "select :new_id, content_id, adapter, provider_artifact_id, " - "verification_state, retention_state, availability_state, integrity_state " - "from artifact_replicas where id = :id", - {"new_id": str(uuid4()), "id": ids["replica"]}, - ), - ( - "insert into artifact_operation_receipts " - "(id, upload_item_id, replica_id, adapter, service_principal, operation, " - "idempotency_key, request_digest, response_digest, provider_receipt_id, " - "provider_operation_reference, outcome, attempt_number, correlation_id, " - "provider_recorded_at, details) " - "select :new_id, upload_item_id, replica_id, adapter, service_principal, " - "operation, idempotency_key, request_digest, response_digest, " - "provider_receipt_id || '-duplicate', provider_operation_reference, outcome, " - "attempt_number, correlation_id || '-duplicate', provider_recorded_at, details " - "from artifact_operation_receipts where id = :id", - {"new_id": str(uuid4()), "id": ids["receipt"]}, - ), - ) - for statement, parameters in duplicate_statements: - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await connection.execute(text(statement), parameters) - - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into artifact_operation_receipts ( - id, replica_id, adapter, service_principal, operation, - idempotency_key, request_digest, response_digest, - provider_receipt_id, provider_operation_reference, outcome, attempt_number, - correlation_id, retention_reference, retention_class, - provider_recorded_at, details - ) values ( - :id, :replica, 'local', 'workstream.artifact', 'retain', - 'retain-without-owner', :request_digest, :response_digest, - 'provider-receipt-retain', 'provider-retain', 'retained', 1, - 'correlation-retain', - 'reference', 'standard', now(), '{}'::json - ) - """ - ), - { - "id": str(uuid4()), - "replica": ids["replica"], - "request_digest": "sha256:" + "3" * 64, - "response_digest": "sha256:" + "4" * 64, - }, - ) - with pytest.raises(DBAPIError): - async with engine.begin() as connection: - await connection.execute( - text( - """ - insert into artifact_bindings ( - id, content_id, project_id, resource_type, resource_id, - logical_role, scope_version, actor_id, attribution_type, - supersedes_binding_id - ) values ( - :id, :content, :project, 'submission', 'submission-1', - 'packet', 3, 'actor', 'submitted_by', :wrong_predecessor - ) - """ - ), - { - "id": str(uuid4()), - "content": ids["content"], - "project": ids["project"], - "wrong_predecessor": ids["binding"], - }, - ) - finally: - await engine.dispose() - - -async def _truncate_artifact_foundation(database_url: str) -> None: - """Clear artifact rows after guarded-downgrade assertions.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - """ - truncate table - artifact_operation_receipts, - artifact_replicas, - artifact_bindings, - artifact_upload_items, - artifact_contents, - artifact_upload_sessions - cascade - """ - ) - ) - finally: - await engine.dispose() - - -async def _api_rate_control_schema(database_url: str) -> dict[str, set[str]]: - """Return the exact public schema contract for the rate table.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - columns = ( - await connection.execute( - text( - "select column_name, data_type, is_nullable " - "from information_schema.columns " - "where table_schema = 'public' " - "and table_name = 'api_rate_control_counters'" - ) - ) - ).all() - constraints = ( - await connection.execute( - text( - "select conname from pg_constraint " - "where conrelid = 'api_rate_control_counters'::regclass" - ) - ) - ).scalars() - indexes = ( - await connection.execute( - text( - "select indexname from pg_indexes " - "where schemaname = 'public' " - "and tablename = 'api_rate_control_counters'" - ) - ) - ).scalars() - return { - "columns": { - f"{row.column_name}:{row.data_type}:{row.is_nullable}" for row in columns - }, - "constraints": set(constraints), - "indexes": set(indexes), - } - finally: - await engine.dispose() - - -async def _seed_and_fetch_0016_artifact(database_url: str, artifact_id: str) -> dict[str, object]: - """Seed one representative 0016 row and return its exact persisted value.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into artifact_contents " - "(id, sha256, byte_count, media_type, normalized_display_name) " - "values (:id, :sha256, 17, 'text/plain', 'rate-migration.txt')" - ), - {"id": artifact_id, "sha256": "sha256:" + "7" * 64}, - ) - finally: - await engine.dispose() - return await _fetch_0016_artifact(database_url, artifact_id) - - -async def _fetch_0016_artifact(database_url: str, artifact_id: str) -> dict[str, object]: - """Fetch the representative 0016 artifact-domain row.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - row = ( - ( - await connection.execute( - text( - "select id, sha256, byte_count, media_type, " - "normalized_display_name from artifact_contents where id = :id" - ), - {"id": artifact_id}, - ) - ) - .mappings() - .one() - ) - return dict(row) - finally: - await engine.dispose() - - -async def _insert_rate_control_until_released( - database_url: str, - digest: bytes, - inserted: threading.Event, - release: threading.Event, - *, - scope: str = "first_access", -) -> None: - """Hold an uncommitted writer until the downgrade is waiting on its lock.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into api_rate_control_counters " - "(control_scope, key_digest, window_started_at, window_expires_at, " - "request_count, updated_at) values " - "(:scope, :digest, statement_timestamp(), " - "statement_timestamp() + interval '1 minute', 1, statement_timestamp())" - ), - {"scope": scope, "digest": digest}, - ) - inserted.set() - assert await asyncio.to_thread(release.wait, 5) - finally: - await engine.dispose() - - -async def _wait_for_rate_control_table_lock(database_url: str) -> None: - """Wait until downgrade is queued for the table's access-exclusive lock.""" - engine = create_async_engine(database_url) - try: - deadline = time.monotonic() + 5 - while time.monotonic() < deadline: - async with engine.connect() as connection: - waiting = await connection.scalar( - text( - "select exists(select 1 from pg_locks " - "where relation='api_rate_control_counters'::regclass " - "and mode='AccessExclusiveLock' and not granted)" - ) - ) - if waiting: - return - await asyncio.sleep(0.01) - raise AssertionError("downgrade did not request the table lock") - finally: - await engine.dispose() - - -async def _assert_api_rate_control_guards(database_url: str, digest: bytes) -> None: - """Insert one valid counter and reject every malformed direct variant.""" - engine = create_async_engine(database_url) - insert_sql = text( - "insert into api_rate_control_counters " - "(control_scope, key_digest, window_started_at, window_expires_at, " - "request_count, updated_at) values " - "(:scope, :digest, statement_timestamp(), " - "statement_timestamp() + make_interval(secs => :seconds), " - ":count, statement_timestamp())" - ) - valid = { - "scope": "first_access", - "digest": digest, - "seconds": 60, - "count": 1, - } - try: - async with engine.begin() as connection: - await connection.execute(insert_sql, valid) - - invalid = [ - {**valid, "scope": "caller_supplied", "digest": bytes([1]) * 32}, - {**valid, "digest": bytes(31)}, - {**valid, "digest": bytes([2]) * 32, "count": 0}, - {**valid, "digest": bytes([3]) * 32, "seconds": 0}, - valid, - ] - for values in invalid: - with pytest.raises(IntegrityError): - async with engine.begin() as connection: - await connection.execute(insert_sql, values) - finally: - await engine.dispose() - - -async def _api_rate_control_state(database_url: str) -> dict[str, object]: - """Return revision, table existence, and row count after migration actions.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - revision = await connection.scalar(text("select version_num from alembic_version")) - exists = await connection.scalar( - text("select to_regclass('public.api_rate_control_counters') is not null") - ) - count = None - if exists: - count = await connection.scalar( - text("select count(*) from api_rate_control_counters") - ) - return { - "revision": revision, - "table_exists": exists, - "row_count": count, - } - finally: - await engine.dispose() - - -async def _clear_api_rate_controls(database_url: str) -> None: - """Clear rate rows only when the migration table exists.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - exists = await connection.scalar( - text("select to_regclass('public.api_rate_control_counters') is not null") - ) - if exists: - await connection.execute(text("delete from api_rate_control_counters")) - finally: - await engine.dispose() - - -async def _seed_and_fetch_legacy_audit(database_url: str, event_id: str) -> dict[str, object]: - """Insert one prior-head lifecycle event and return its legacy fields.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, from_status, to_status, " - "actor_id, external_subject, external_issuer, actor_roles, " - "claim_snapshot, auth_source, is_dev_auth, reason, event_payload) " - "values (:id, 'task', :entity_id, 'task_created', null, 'draft', " - "'legacy-actor', 'opaque-subject', 'https://issuer.example.test', " - "'[\"project_manager\"]'::json, '{\"bounded\": true}'::json, " - "'verified_token', false, 'created', '{\"source\": \"manual\"}'::json)" - ), - {"id": event_id, "entity_id": str(uuid4())}, - ) - finally: - await engine.dispose() - return await _fetch_audit_row(database_url, event_id) - - -async def _fetch_audit_row(database_url: str, event_id: str) -> dict[str, object]: - """Fetch stable legacy fields and the authority domain when it exists.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - has_domain = await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_name = 'audit_events' and column_name = 'event_domain')" - ) - ) - domain = ", event_domain" if has_domain else "" - row = ( - ( - await connection.execute( - text( - "select id, entity_type, entity_id, event_type, from_status, " - "to_status, actor_id, external_subject, external_issuer, " - "actor_roles, claim_snapshot, auth_source, is_dev_auth, reason, " - f"event_payload{domain} from audit_events where id = :id" - ), - {"id": event_id}, - ) - ) - .mappings() - .one() - ) - return dict(row) - finally: - await engine.dispose() - - -async def _authority_audit_schema(database_url: str) -> dict[str, object]: - """Return the exact 0018 authority-audit schema surface.""" - new_columns = { - "event_domain", - "event_version", - "occurred_at", - "actor_ref_kind", - "request_id", - "correlation_id", - "target_actor_ref_kind", - "target_actor_ref", - "matched_grant_id", - "permission_id", - "project_id", - "resource_type", - "resource_id", - "target_ref_kind", - "target_ref_id", - "denial_code", - "idempotency_reference", - "invalidation_cause_event_id", - "invalidation_target_kind", - "invalidation_target_ref", - "before_facts", - "after_facts", - } - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - columns = ( - ( - await connection.execute( - text( - "select column_name, udt_name, is_nullable, column_default " - "from information_schema.columns where table_schema = 'public' " - "and table_name = 'audit_events'" - ) - ) - ) - .mappings() - .all() - ) - by_name = {row["column_name"]: row for row in columns} - constraints = set( - ( - await connection.execute( - text( - "select conname from pg_constraint where " - "conrelid = 'audit_events'::regclass " - "and (conname like 'ck_audit_events_%' or " - "conname = 'fk_audit_events_invalidation_cause')" - ) - ) - ).scalars() - ) - indexes = set( - ( - await connection.execute( - text( - "select indexname from pg_indexes where schemaname = 'public' " - "and tablename = 'audit_events' and indexname in " - "('ix_audit_events_request_id', 'ix_audit_events_correlation_id', " - "'ix_audit_events_occurred_at', 'ix_audit_events_project_id', " - "'ix_audit_events_actor_ref')" - ) - ) - ).scalars() - ) - triggers = set( - ( - await connection.execute( - text( - "select tgname from pg_trigger where " - "tgrelid = 'audit_events'::regclass and not tgisinternal" - ) - ) - ).scalars() - ) - functions = set( - ( - await connection.execute( - text( - "select proname from pg_proc where proname in " - "('authority_facts_are_safe', 'authority_grant_facts_are_safe', " - "'authority_event_facts_are_safe', 'reject_audit_event_mutation', " - "'set_authority_audit_database_time')" - ) - ) - ).scalars() - ) - return { - "columns": { - f"{name}:{by_name[name]['udt_name']}:{by_name[name]['is_nullable']}" - for name in new_columns - }, - "constraints": constraints, - "indexes": indexes, - "triggers": triggers, - "functions": functions, - "legacy_default": "legacy_lifecycle" - in (by_name["event_domain"]["column_default"] or ""), - "external_identity_nullable": all( - by_name[name]["is_nullable"] == "YES" - for name in ("external_subject", "external_issuer") - ), - } - finally: - await engine.dispose() - - -async def _insert_authority_audit_fixture(database_url: str, event_id: str): - """Insert valid authority evidence while proving database-owned time.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - return await connection.scalar( - text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, actor_id, actor_roles, " - "claim_snapshot, auth_source, is_dev_auth, event_payload, event_domain, " - "event_version, occurred_at, actor_ref_kind, request_id, correlation_id, " - "permission_id, reason, after_facts) values (:id, " - "'authorization_decision', :id, 'SensitiveAuthorizationAllowed', " - "'workstream:system:bootstrap', '[]'::json, " - "'{}'::json, 'local_authority', false, '{}'::json, 'authority', 1, " - "'2000-01-01T00:00:00Z', 'system_principal', :request_id, " - ":correlation_id, 'actor.profile.read_any', " - "'authorization_evaluation', '{\"allowed\": true}') returning occurred_at" - ), - { - "id": event_id, - "request_id": str(uuid4()), - "correlation_id": str(uuid4()), - }, - ) - finally: - await engine.dispose() - - -async def _authority_audit_state(database_url: str) -> dict[str, object]: - """Return migration revision and retained authority evidence count.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "authority_rows": await connection.scalar( - text("select count(*) from audit_events where event_domain = 'authority'") - ), - } - finally: - await engine.dispose() - - -async def _remove_authority_audit_fixture(database_url: str, event_id: str) -> None: - """Perform explicit owner-only fixture cleanup under the documented lock.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - has_domain = await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_name = 'audit_events' and column_name = 'event_domain')" - ) - ) - if not has_domain: - return - await connection.execute(text("lock table audit_events in access exclusive mode")) - await connection.execute( - text("alter table audit_events disable trigger audit_events_reject_update_delete") - ) - await connection.execute( - text("delete from audit_events where id = :id and event_domain = 'authority'"), - {"id": event_id}, - ) - await connection.execute( - text("alter table audit_events enable trigger audit_events_reject_update_delete") - ) - finally: - await engine.dispose() - - -async def _insert_pre_0019_forward_reference( - database_url: str, event_id: str, reference: str -) -> None: - """Seed the forward reference that 0019's NOT VALID FK must preserve.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into audit_events (id, entity_type, entity_id, event_type, actor_id, " - "actor_roles, claim_snapshot, auth_source, is_dev_auth, event_payload, " - "event_domain, event_version, actor_ref_kind, request_id, correlation_id, " - "permission_id, reason, idempotency_reference, after_facts) values " - "(:id, 'authorization_decision', :id, 'SensitiveAuthorizationAllowed', " - ":actor, '[]'::json, '{}'::json, 'local_authority', false, '{}'::json, " - "'authority', 1, 'actor_profile', :request, :correlation, " - "'actor.profile.read_any', 'authorization_evaluation', :reference, " - "'{\"allowed\": true}'::json)" - ), - { - "id": event_id, - "actor": str(uuid4()), - "request": str(uuid4()), - "correlation": str(uuid4()), - "reference": reference, - }, - ) - finally: - await engine.dispose() - - -async def _authority_idempotency_schema(database_url: str) -> dict[str, object]: - """Return the exact 0019 schema and audit-link surface.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - columns = set( - ( - await connection.execute( - text( - "select column_name || ':' || udt_name || ':' || is_nullable " - "from information_schema.columns where table_schema='public' " - "and table_name='authority_idempotency_records'" - ) - ) - ).scalars() - ) - constraints = set( - ( - await connection.execute( - text( - "select conname from pg_constraint where " - "conrelid='authority_idempotency_records'::regclass" - ) - ) - ).scalars() - ) - triggers = set( - ( - await connection.execute( - text( - "select tgname from pg_trigger where " - "tgrelid='authority_idempotency_records'::regclass and not tgisinternal" - ) - ) - ).scalars() - ) - return { - "columns": columns, - "constraints": constraints, - "triggers": triggers, - "audit_fk_validated": await connection.scalar( - text( - "select convalidated from pg_constraint where " - "conname='fk_audit_events_authority_idempotency'" - ) - ), - "audit_trigger": bool( - await connection.scalar( - text( - "select exists(select 1 from pg_trigger where " - "tgname='audit_events_validate_idempotency' and not tgisinternal)" - ) - ) - ), - } - finally: - await engine.dispose() - - -async def _authority_idempotency_invalid_writes(database_url: str) -> dict[str, bool]: - """Prove invalid initial state, durable pending, and new orphan fail closed.""" - engine = create_async_engine(database_url) - results: dict[str, bool] = {} - try: - for name, statement, values in ( - ( - "initial_committed", - "insert into authority_idempotency_records (id,idempotency_key,actor_ref_kind," - "actor_ref,operation,request_digest,status,response_resource_type," - "response_resource_id,response_http_status,committed_at) values " - "(:id,:key,'actor_profile',:actor,'actor_profile.suspend',:digest,'committed'," - "'actor_profile',:resource,200,statement_timestamp())", - { - "id": str(uuid4()), - "key": str(uuid4()), - "actor": str(uuid4()), - "resource": str(uuid4()), - "digest": "sha256:" + "a" * 64, - }, - ), - ( - "pending_commit", - "insert into authority_idempotency_records (id,idempotency_key,actor_ref_kind," - "actor_ref,operation,request_digest,status) values " - "(:id,:key,'actor_profile',:actor,'actor_profile.suspend',:digest,'pending')", - { - "id": str(uuid4()), - "key": str(uuid4()), - "actor": str(uuid4()), - "digest": "sha256:" + "a" * 64, - }, - ), - ( - "new_orphan", - "insert into audit_events (id,entity_type,entity_id,event_type,actor_id," - "actor_roles,claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id,permission_id,reason," - "idempotency_reference,after_facts) values (:id,'authorization_decision',:id," - "'SensitiveAuthorizationAllowed',:actor,'[]','{}','local_authority',false,'{}'," - "'authority',1,'actor_profile',:request,:correlation,'actor.profile.read_any'," - "'authorization_evaluation',:reference,cast(:facts as json))", - { - "id": str(uuid4()), - "actor": str(uuid4()), - "request": str(uuid4()), - "correlation": str(uuid4()), - "reference": str(uuid4()), - "facts": json.dumps({"allowed": True}), - }, - ), - ): - try: - async with engine.begin() as connection: - await connection.execute(text(statement), values) - except DBAPIError: - results[name] = True - else: - results[name] = False - return results - finally: - await engine.dispose() - - -async def _insert_committed_authority_idempotency( - database_url: str, record_id: str, actor_id: str, target_id: str -) -> None: - """Insert one complete actor-suspension reservation and evidence pair.""" - engine = create_async_engine(database_url) - success_id, invalidation_id = str(uuid4()), str(uuid4()) - request_id, correlation_id = str(uuid4()), str(uuid4()) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into authority_idempotency_records (id,idempotency_key,actor_ref_kind," - "actor_ref,operation,request_digest,status) values " - "(:id,:key,'actor_profile',:actor,'actor_profile.suspend',:digest,'pending')" - ), - { - "id": record_id, - "key": str(uuid4()), - "actor": actor_id, - "digest": "sha256:" + "a" * 64, - }, - ) - common = ( - "actor_roles,claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id,permission_id," - "resource_type,resource_id,reason,idempotency_reference" - ) - await connection.execute( - text( - f"insert into audit_events (id,entity_type,entity_id,event_type,actor_id,{common}," - "target_ref_kind,target_ref_id,before_facts,after_facts) values " - "(:id,'actor_profile',:target," - "'ActorProfileSuspended',:actor,'[]','{}','local_authority',false,'{}'," - "'authority',1,'actor_profile',:request,:correlation,'actor.profile.suspend'," - "'actor_profile',:target,'security_response',:record," - "'actor_profile',:target,cast(:before_facts as json),cast(:after_facts as json))" - ), - { - "id": success_id, - "target": target_id, - "actor": actor_id, - "request": request_id, - "correlation": correlation_id, - "record": record_id, - "before_facts": json.dumps({"status": "active"}), - "after_facts": json.dumps({"status": "suspended"}), - }, - ) - await connection.execute( - text( - f"insert into audit_events (id,entity_type,entity_id,event_type,actor_id,{common}," - "invalidation_cause_event_id,invalidation_target_kind,invalidation_target_ref," - "before_facts,after_facts) values (:id,'authority_invalidation',:id," - "'AuthorityInvalidationRequested',:actor,'[]','{}','local_authority',false,'{}'," - "'authority',1,'actor_profile',:request,:correlation,'actor.profile.suspend'," - "'actor_profile',:target,'authority_state_changed',:record,:cause,'actor_profile'," - ":target,cast(:before_facts as json),cast(:after_facts as json))" - ), - { - "id": invalidation_id, - "target": target_id, - "actor": actor_id, - "request": request_id, - "correlation": correlation_id, - "record": record_id, - "cause": success_id, - "before_facts": json.dumps({"effective": True}), - "after_facts": json.dumps({"effective": False}), - }, - ) - await connection.execute( - text( - "update authority_idempotency_records set status='committed'," - "response_resource_type='actor_profile',response_resource_id=:target," - "response_resource_version=1,response_http_status=200 where id=:id" - ), - {"id": record_id, "target": target_id}, - ) - finally: - await engine.dispose() - - -async def _authority_idempotency_state(database_url: str, orphan_event: str) -> dict[str, object]: - """Return revision, optional record count, and preserved orphan count.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - exists = await connection.scalar( - text( - "select exists(select 1 from information_schema.tables where " - "table_name='authority_idempotency_records')" - ) - ) - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "records": await connection.scalar( - text("select count(*) from authority_idempotency_records") - ) - if exists - else None, - "orphan": await connection.scalar( - text("select count(*) from audit_events where id=:id"), {"id": orphan_event} - ), - } - finally: - await engine.dispose() - - -async def _authority_idempotency_immutable_writes( - database_url: str, record_id: str -) -> dict[str, bool]: - """Prove committed rows are immutable and carry database-owned timestamps.""" - engine = create_async_engine(database_url) - results: dict[str, bool] = {} - try: - statements = { - "update": "update authority_idempotency_records set response_http_status=200 where id=:id", - "delete": "delete from authority_idempotency_records where id=:id", - "truncate": "truncate authority_idempotency_records", - } - for name, statement in statements.items(): - try: - async with engine.begin() as connection: - await connection.execute(text(statement), {"id": record_id}) - except DBAPIError: - results[name] = True - else: - results[name] = False - async with engine.connect() as connection: - results["database_timestamps"] = bool( - await connection.scalar( - text( - "select created_at is not null and committed_at is not null " - "and committed_at >= created_at from authority_idempotency_records " - "where id=:id" - ), - {"id": record_id}, - ) - ) - return results - finally: - await engine.dispose() - - -def _authority_downgrade_waits_for_writer(config: Config, database_url: str) -> bool: - """Observe downgrade waiting for the deterministic writer-blocking table lock.""" - writer_ready = threading.Event() - release_writer = threading.Event() - - async def hold_writer_lock() -> None: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute( - text("lock table authority_idempotency_records in row exclusive mode") - ) - writer_ready.set() - await asyncio.to_thread(release_writer.wait) - await transaction.rollback() - finally: - await engine.dispose() - - async def observe_downgrade_lock() -> bool: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - for _ in range(5000): - waiting = await connection.scalar( - text( - "select exists(select 1 from pg_locks locks " - "join pg_class relation on relation.oid=locks.relation " - "where relation.relname='authority_idempotency_records' " - "and locks.mode='AccessExclusiveLock' and not locks.granted)" - ) - ) - if waiting: - return True - await asyncio.sleep(0) - return False - finally: - await engine.dispose() - - with ThreadPoolExecutor(max_workers=2) as executor: - writer = executor.submit(asyncio.run, hold_writer_lock()) - if not writer_ready.wait(timeout=5): - release_writer.set() - writer.result(timeout=5) - return False - downgrade = executor.submit(command.downgrade, config, "0018_authority_audit_evidence") - try: - observed = asyncio.run(observe_downgrade_lock()) - finally: - release_writer.set() - writer.result(timeout=10) - downgrade.result(timeout=10) - return observed - - -async def _remove_authority_idempotency_fixture( - database_url: str, record_id: str, *, orphan_event: str | None -) -> None: - """Owner-only cleanup for immutable 0019 fixtures.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - exists = await connection.scalar( - text( - "select exists(select 1 from information_schema.tables where " - "table_name='authority_idempotency_records')" - ) - ) - if exists: - await connection.execute( - text("lock table authority_idempotency_records in access exclusive mode") - ) - await connection.execute(text("lock table audit_events in access exclusive mode")) - await connection.execute( - text("alter table audit_events disable trigger audit_events_reject_update_delete") - ) - await connection.execute( - text("delete from audit_events where idempotency_reference=:record"), - {"record": record_id}, - ) - if orphan_event: - await connection.execute( - text("delete from audit_events where id=:id"), {"id": orphan_event} - ) - await connection.execute( - text("alter table audit_events enable trigger audit_events_reject_update_delete") - ) - if exists: - await connection.execute( - text( - "alter table authority_idempotency_records disable trigger " - "authority_idempotency_guard" - ) - ) - await connection.execute( - text("delete from authority_idempotency_records where id=:id"), - {"id": record_id}, - ) - await connection.execute( - text( - "alter table authority_idempotency_records enable trigger " - "authority_idempotency_guard" - ) - ) - finally: - await engine.dispose() - - -_ACTION_EVIDENCE_INSERT = text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, actor_id, actor_roles, claim_snapshot, " - "auth_source, is_dev_auth, event_payload, event_domain, event_version, actor_ref_kind, " - "request_id, correlation_id, permission_id, action_id, reason, denial_code, after_facts) " - "values (:id, 'authorization_decision', :id, 'SensitiveAuthorizationDenied', " - "'workstream:system:bootstrap', '[]'::json, '{}'::json, 'local_authority', false, " - "'{}'::json, 'authority', 1, 'system_principal', :request_id, :correlation_id, " - ":permission_id, :action_id, 'authorization_evaluation', 'permission_not_granted', " - "'{\"allowed\": false}'::json)" -) - -_ALLOWED_ACTION_EVIDENCE_INSERT = text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, actor_id, actor_roles, claim_snapshot, " - "auth_source, is_dev_auth, event_payload, event_domain, event_version, actor_ref_kind, " - "request_id, correlation_id, permission_id, action_id, reason, after_facts) " - "values (:id, 'authorization_decision', :id, 'SensitiveAuthorizationAllowed', " - "'workstream:system:bootstrap', '[]'::json, '{}'::json, 'local_authority', false, " - "'{}'::json, 'authority', 1, 'system_principal', :request_id, :correlation_id, " - ":permission_id, :action_id, 'authorization_evaluation', " - "'{\"allowed\": true}'::json)" -) - - -def _action_evidence_values(action_id: str | None, permission_id: str) -> dict[str, str | None]: - event_id = str(uuid4()) - return { - "id": event_id, - "request_id": str(uuid4()), - "correlation_id": str(uuid4()), - "permission_id": permission_id, - "action_id": action_id, - } - - -async def _authorization_action_schema(database_url: str) -> dict[str, object]: - """Return the migration revision and action-evidence schema markers.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "action_column": bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='audit_events' " - "and column_name='action_id')" - ) - ) - ), - "action_constraint": bool( - await connection.scalar( - text( - "select exists(select 1 from pg_constraint where " - "conrelid='audit_events'::regclass and " - "conname='ck_audit_events_authorization_action_evidence')" - ) - ) - ), - } - finally: - await engine.dispose() - - -async def _authorization_action_row(database_url: str, event_id: str) -> dict[str, object]: - """Fetch stable action evidence across both sides of migration 0021.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - has_action = await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='audit_events' " - "and column_name='action_id')" - ) - ) - action_column = ", action_id" if has_action else "" - row = ( - ( - await connection.execute( - text( - "select event_type, permission_id" - f"{action_column} from audit_events where id=:id" - ), - {"id": event_id}, - ) - ) - .mappings() - .one() - ) - result = dict(row) - result.setdefault("action_id", None) - return result - finally: - await engine.dispose() - - -async def _assert_authorization_action_sql_pairs( - database_url: str, - *, - definitions: tuple = ACTION_DEFINITIONS, -) -> None: - """Prove exact pair closure without freezing typed availability in SQL.""" - engine = create_async_engine(database_url) - try: - for definition in definitions: - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute( - _ACTION_EVIDENCE_INSERT, - _action_evidence_values( - definition.action_id.value, definition.permission_id.value - ), - ) - await transaction.rollback() - - for definition in definitions: - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute( - _ALLOWED_ACTION_EVIDENCE_INSERT, - _action_evidence_values( - definition.action_id.value, definition.permission_id.value - ), - ) - await transaction.rollback() - - unknown_action = _action_evidence_values("unknown.action", "actor.profile.read_self") - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute(_ACTION_EVIDENCE_INSERT, unknown_action) - await transaction.rollback() - - for definition in definitions: - wrong_permission_id = ( - "actor.profile.read_self" - if definition.permission_id.value != "actor.profile.read_self" - else "actor.profile.read_any" - ) - wrong_permission = _action_evidence_values( - definition.action_id.value, wrong_permission_id - ) - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute(_ACTION_EVIDENCE_INSERT, wrong_permission) - await transaction.rollback() - - for permission in NEW_PERMISSION_IDS: - missing_action = _action_evidence_values(None, permission.value) - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute(_ACTION_EVIDENCE_INSERT, missing_action) - await transaction.rollback() - - nondecision = text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, actor_id, actor_roles, claim_snapshot, " - "auth_source, is_dev_auth, event_payload, event_domain, event_version, " - "actor_ref_kind, request_id, correlation_id, permission_id, action_id, reason, " - "denial_code) values (:id, 'admin_role_grant', :entity_id, " - "'AdminRoleGrantIssueDenied', 'workstream:system:bootstrap', '[]'::json, " - "'{}'::json, 'local_authority', false, '{}'::json, 'authority', 1, " - "'system_principal', :request_id, :correlation_id, 'actor.profile.read_self', " - "'actor.profile.read_self', 'authorization_policy_denial', " - "'permission_not_granted')" - ) - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute( - nondecision, - { - "id": str(uuid4()), - "entity_id": str(uuid4()), - "request_id": str(uuid4()), - "correlation_id": str(uuid4()), - }, - ) - await transaction.rollback() - finally: - await engine.dispose() - - -async def _assert_removed_art_authority_rejected(database_url: str) -> None: - """Prove current SQL rejects every deleted pair and permission reference.""" - removed = _OBSOLETE_ART_UPLOAD_IDS - engine = create_async_engine(database_url) - try: - for identifier in removed: - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute( - _ACTION_EVIDENCE_INSERT, - _action_evidence_values(identifier, identifier), - ) - await transaction.rollback() - - async with engine.connect() as connection: - transaction = await connection.begin() - values = { - "id": str(uuid4()), - "request": str(uuid4()), - "correlation": str(uuid4()), - "permission": identifier, - } - with pytest.raises(IntegrityError): - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id,permission_id," - "target_ref_kind,target_ref_id,reason,after_facts) values " - "(:id,'authorization_decision',:id,'SensitiveAuthorizationAllowed'," - "'workstream:system:bootstrap','[]'::json,'{}'::json," - "'local_authority',false,'{}'::json,'authority',1," - "'system_principal',:request,:correlation,'actor.profile.read_any'," - "'permission_registry',:permission,'authorization_evaluation'," - "'{\"allowed\": true}'::json)" - ), - values, - ) - await transaction.rollback() - - async with engine.connect() as connection: - transaction = await connection.begin() - cause = _action_evidence_values( - "actor.profile.read_self", "actor.profile.read_self" - ) - await connection.execute(_ACTION_EVIDENCE_INSERT, cause) - await connection.execute( - text( - "alter table audit_events disable trigger audit_events_validate_idempotency" - ) - ) - with pytest.raises(IntegrityError): - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles," - "claim_snapshot,auth_source,is_dev_auth,event_payload,event_domain," - "event_version,actor_ref_kind,request_id,correlation_id," - "invalidation_cause_event_id,invalidation_target_kind," - "invalidation_target_ref,reason,before_facts,after_facts) values " - "(:id,'authority_invalidation',:id," - "'AuthorityInvalidationRequested','workstream:system:bootstrap'," - "'[]'::json,'{}'::json,'local_authority',false,'{}'::json," - "'authority',1,'system_principal',:request,:correlation,:cause," - "'permission_registry',:permission,'authority_state_changed'," - "'{\"effective\": true}'::json," - "'{\"effective\": false}'::json)" - ), - { - "id": str(uuid4()), - "request": str(uuid4()), - "correlation": str(uuid4()), - "cause": cause["id"], - "permission": identifier, - }, - ) - await transaction.rollback() - finally: - await engine.dispose() - - -async def _insert_authorization_action_event(database_url: str) -> str: - """Commit one valid planned-action denial fixture.""" - values = _action_evidence_values("artifact.binding.read", "artifact.binding.read") - event_id = values["id"] - assert event_id is not None - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(_ACTION_EVIDENCE_INSERT, values) - return event_id - finally: - await engine.dispose() - - -async def _convert_to_permission_only_forward_evidence(database_url: str, event_id: str) -> None: - """Simulate a pre-guard forward row to exercise the second rollback predicate.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("lock table audit_events in access exclusive mode")) - await connection.execute( - text("alter table audit_events disable trigger audit_events_reject_update_delete") - ) - await connection.execute( - text( - "alter table audit_events drop constraint " - "ck_audit_events_authorization_action_evidence" - ) - ) - await connection.execute( - text("update audit_events set action_id=null where id=:id"), - {"id": event_id}, - ) - await connection.execute( - text( - "alter table audit_events add constraint " - "ck_audit_events_authorization_action_evidence " - "check (action_id is null) not valid" - ) - ) - await connection.execute( - text("alter table audit_events enable trigger audit_events_reject_update_delete") - ) - finally: - await engine.dispose() - - -async def _insert_forward_permission_reference( - database_url: str, - cause_event_id: str, - *, - reference_field: str, - permission: str = "artifact.binding.read", -) -> str: - """Commit one new permission-registry reference without an action ID.""" - event_id = str(uuid4()) - values = { - "id": event_id, - "request_id": str(uuid4()), - "correlation_id": str(uuid4()), - "permission": permission, - "cause_id": cause_event_id, - } - if reference_field == "target": - statement = text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, actor_id, actor_roles, " - "claim_snapshot, auth_source, is_dev_auth, event_payload, event_domain, " - "event_version, actor_ref_kind, request_id, correlation_id, permission_id, " - "target_ref_kind, target_ref_id, reason, after_facts) values " - "(:id, 'authorization_decision', :id, 'SensitiveAuthorizationAllowed', " - "'workstream:system:bootstrap', '[]'::json, '{}'::json, 'local_authority', " - "false, '{}'::json, 'authority', 1, 'system_principal', :request_id, " - ":correlation_id, 'actor.profile.read_any', 'permission_registry', " - ":permission, 'authorization_evaluation', '{\"allowed\": true}'::json)" - ) - elif reference_field == "invalidation": - statement = text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, actor_id, actor_roles, " - "claim_snapshot, auth_source, is_dev_auth, event_payload, event_domain, " - "event_version, actor_ref_kind, request_id, correlation_id, " - "invalidation_cause_event_id, invalidation_target_kind, " - "invalidation_target_ref, reason, before_facts, after_facts) values " - "(:id, 'authority_invalidation', :id, 'AuthorityInvalidationRequested', " - "'workstream:system:bootstrap', '[]'::json, '{}'::json, 'local_authority', " - "false, '{}'::json, 'authority', 1, 'system_principal', :request_id, " - ":correlation_id, :cause_id, 'permission_registry', :permission, " - "'authority_state_changed', '{\"effective\": true}'::json, " - "'{\"effective\": false}'::json)" - ) - else: - raise ValueError(f"unsupported reference field: {reference_field}") - - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - if reference_field == "invalidation": - await connection.execute( - text( - "alter table audit_events disable trigger audit_events_validate_idempotency" - ) - ) - await connection.execute(statement, values) - if reference_field == "invalidation": - await connection.execute( - text( - "alter table audit_events enable trigger audit_events_validate_idempotency" - ) - ) - return event_id - finally: - await engine.dispose() - - -async def _assert_historical_permission_registry(database_url: str) -> None: - """Prove downgrade restores every historical permission and rejects every new one.""" - statement = text( - "insert into audit_events " - "(id, entity_type, entity_id, event_type, actor_id, actor_roles, claim_snapshot, " - "auth_source, is_dev_auth, event_payload, event_domain, event_version, " - "actor_ref_kind, request_id, correlation_id, permission_id, reason, after_facts) " - "values (:id, 'authorization_decision', :id, 'SensitiveAuthorizationAllowed', " - "'workstream:system:bootstrap', '[]'::json, '{}'::json, 'local_authority', false, " - "'{}'::json, 'authority', 1, 'system_principal', :request_id, :correlation_id, " - ":permission_id, 'authorization_evaluation', '{\"allowed\": true}'::json)" - ) - engine = create_async_engine(database_url) - try: - for permission in HISTORICAL_PERMISSION_IDS: - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute(statement, _action_evidence_values(None, permission.value)) - await transaction.rollback() - - for permission in NEW_PERMISSION_IDS: - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute( - statement, _action_evidence_values(None, permission.value) - ) - await transaction.rollback() - finally: - await engine.dispose() - - -async def _remove_authorization_action_events(database_url: str, event_ids: list[str]) -> None: - """Owner-only cleanup for immutable action-evidence test fixtures.""" - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("lock table audit_events in access exclusive mode")) - await connection.execute( - text("alter table audit_events disable trigger audit_events_reject_update_delete") - ) - await connection.execute( - text("delete from audit_events where id = any(:ids)"), - {"ids": event_ids}, - ) - await connection.execute( - text("alter table audit_events enable trigger audit_events_reject_update_delete") - ) - finally: - await engine.dispose() - - -def _action_downgrade_waits_for_insert(config: Config, database_url: str) -> tuple[bool, str]: - """Prove an insert cannot pass between the downgrade check and destructive DDL.""" - writer_ready = threading.Event() - release_writer = threading.Event() - values = _action_evidence_values("artifact.binding.read", "artifact.binding.read") - event_id = values["id"] - assert event_id is not None - - async def hold_uncommitted_insert() -> None: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute(_ACTION_EVIDENCE_INSERT, values) - writer_ready.set() - await asyncio.to_thread(release_writer.wait) - await transaction.commit() - finally: - await engine.dispose() - - async def observe_downgrade_lock() -> bool: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - for _ in range(5000): - waiting = await connection.scalar( - text( - "select exists(select 1 from pg_locks locks " - "join pg_class relation on relation.oid=locks.relation " - "where relation.relname='audit_events' " - "and locks.mode='AccessExclusiveLock' and not locks.granted)" - ) - ) - if waiting: - return True - await asyncio.sleep(0) - return False - finally: - await engine.dispose() - - with ThreadPoolExecutor(max_workers=2) as executor: - writer = executor.submit(asyncio.run, hold_uncommitted_insert()) - if not writer_ready.wait(timeout=5): - release_writer.set() - writer.result(timeout=5) - return False, event_id - downgrade = executor.submit(command.downgrade, config, "0020_canonical_actor_profile") - try: - observed = asyncio.run(observe_downgrade_lock()) - finally: - release_writer.set() - writer.result(timeout=10) - with pytest.raises( - RuntimeError, - match="^cannot downgrade non-empty authorization action evidence$", - ): - downgrade.result(timeout=10) - return observed, event_id - - -async def _insert_orphan_admin_evidence(database_url: str, event_type: str) -> None: - engine = create_async_engine(database_url) - event_id, target_id = str(uuid4()), str(uuid4()) - denied = event_type != "InitialAccessAdministratorBootstrapped" - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version," - "actor_ref_kind,request_id,correlation_id,target_actor_ref_kind," - "target_actor_ref,resource_type,resource_id,target_ref_kind,target_ref_id," - "reason,denial_code,after_facts) values " - "(:id,'admin_role_grant',:id,:event_type," - "'workstream:system:bootstrap','[]','{}','local_authority',false,'{}'," - "'authority',1,'system_principal',:request,:correlation,'actor_profile'," - ":target,'admin_role_grant',:id,'admin_role_grant',:id," - ":reason,:denial_code,cast(:facts as json))" - ), - { - "id": event_id, - "event_type": event_type, - "target": target_id, - "request": str(uuid4()), - "correlation": str(uuid4()), - "reason": "authorization_policy_denial" - if denied - else "initial_access_bootstrap", - "denial_code": "permission_not_granted" if denied else None, - "facts": None - if denied - else json.dumps( - { - "status": "active", - "role": "access_administrator", - "scope_type": "system", - "effective": True, - } - ), - }, - ) - finally: - await engine.dispose() - - -async def _insert_orphan_admin_idempotency(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text("alter table authority_idempotency_records disable trigger user") - ) - await connection.execute( - text( - "insert into authority_idempotency_records " - "(id,idempotency_key,actor_ref_kind,actor_ref,operation,request_digest,status) " - "values (:id,:key,'actor_profile',:actor,'admin_role_grant.issue'," - ":digest,'pending')" - ), - { - "id": str(uuid4()), - "key": str(uuid4()), - "actor": str(uuid4()), - "digest": "sha256:" + "a" * 64, - }, - ) - await connection.execute( - text("alter table authority_idempotency_records enable trigger user") - ) - finally: - await engine.dispose() - - -async def _clear_orphan_admin_state(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("alter table audit_events disable trigger user")) - await connection.execute( - text("alter table authority_idempotency_records disable trigger user") - ) - await connection.execute( - text( - "delete from audit_events where event_type in " - "('InitialAccessAdministratorBootstrapped','AdminRoleGrantIssued'," - "'AdminRoleGrantRevoked','AdminRoleGrantIssueDenied'," - "'LastAccessAdministratorOperationDenied')" - ) - ) - await connection.execute( - text( - "delete from authority_idempotency_records " - "where operation like 'admin_role_grant.%'" - ) - ) - await connection.execute( - text("alter table authority_idempotency_records enable trigger user") - ) - await connection.execute(text("alter table audit_events enable trigger user")) - finally: - await engine.dispose() - - -async def _admin_authority_schema(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - control = ( - await connection.execute( - text( - "select bootstrap_completed,bootstrap_grant_id,version " - "from authority_control where id=1" - ) - ) - ).one() - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "grant_table": bool( - await connection.scalar( - text("select to_regclass('public.admin_role_grants') is not null") - ) - ), - "control": tuple(control), - } - finally: - await engine.dispose() - - -async def _exercise_admin_authority_guards(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - admin_id = actor_id_from_external_identity("https://identity.test", "auth08-admin") - target_id = actor_id_from_external_identity("https://identity.test", "auth08-target") - service_id = actor_id_from_external_identity("https://identity.test", "auth08-service") - bootstrap_id, grant_id = str(uuid4()), str(uuid4()) - results: dict[str, object] = {} - try: - async with engine.begin() as connection: - await _insert_canonical_actor(connection, admin_id, "auth08-admin", "human") - await _insert_canonical_actor(connection, target_id, "auth08-target", "human") - await _insert_canonical_actor(connection, service_id, "auth08-service", "service") - - insert_grant = ( - "insert into admin_role_grants " - "(id,target_actor_profile_id,role,scope_type,status,version," - "granted_by_actor_profile_id,granted_by_system_principal," - "granted_by_admin_role_grant_id,grant_reason) values " - "(:id,:target,:role,:scope,'active',1,:actor,:principal,:authorizer,:reason)" - ) - invalid_cases = ( - ( - "service_target_rejected", - { - "id": str(uuid4()), - "target": service_id, - "role": "access_administrator", - "scope": "system", - "actor": None, - "principal": "workstream:system:bootstrap", - "authorizer": None, - "reason": "Invalid service target", - }, - ), - ( - "missing_authorizer_rejected", - { - "id": str(uuid4()), - "target": target_id, - "role": "operator", - "scope": "system", - "actor": admin_id, - "principal": None, - "authorizer": None, - "reason": "Missing authorizer", - }, - ), - ( - "mixed_bootstrap_attribution_rejected", - { - "id": str(uuid4()), - "target": admin_id, - "role": "access_administrator", - "scope": "system", - "actor": admin_id, - "principal": "workstream:system:bootstrap", - "authorizer": None, - "reason": "Mixed attribution", - }, - ), - ) - for name, values in invalid_cases: - try: - async with engine.begin() as connection: - await connection.execute(text(insert_grant), values) - except DBAPIError: - results[name] = True - else: - results[name] = False - - try: - async with engine.begin() as connection: - await connection.execute( - text(insert_grant), - { - "id": str(uuid4()), - "target": admin_id, - "role": "access_administrator", - "scope": "system", - "actor": None, - "principal": "workstream:system:bootstrap", - "authorizer": None, - "reason": "Orphan bootstrap", - }, - ) - except DBAPIError: - results["orphan_bootstrap_commit_rejected"] = True - else: - results["orphan_bootstrap_commit_rejected"] = False - - mismatched_bootstrap_id, mismatched_grant_id = str(uuid4()), str(uuid4()) - try: - async with engine.begin() as connection: - await connection.execute( - text(insert_grant), - { - "id": mismatched_bootstrap_id, - "target": admin_id, - "role": "access_administrator", - "scope": "system", - "actor": None, - "principal": "workstream:system:bootstrap", - "authorizer": None, - "reason": "Mismatched bootstrap", - }, - ) - await connection.execute( - text(insert_grant), - { - "id": mismatched_grant_id, - "target": target_id, - "role": "operator", - "scope": "system", - "actor": admin_id, - "principal": None, - "authorizer": mismatched_bootstrap_id, - "reason": "Mismatched control target", - }, - ) - await connection.execute( - text( - "update authority_control set bootstrap_completed=true," - "bootstrap_grant_id=:grant,version=1 where id=1" - ), - {"grant": mismatched_grant_id}, - ) - except DBAPIError: - results["mismatched_bootstrap_control_rejected"] = True - else: - results["mismatched_bootstrap_control_rejected"] = False - - async with engine.begin() as connection: - await connection.execute( - text(insert_grant), - { - "id": bootstrap_id, - "target": admin_id, - "role": "access_administrator", - "scope": "system", - "actor": None, - "principal": "workstream:system:bootstrap", - "authorizer": None, - "reason": "Initial Access Administrator bootstrap", - }, - ) - await connection.execute( - text( - "update authority_control set bootstrap_completed=true," - "bootstrap_grant_id=:grant,version=1 where id=1" - ), - {"grant": bootstrap_id}, - ) - - try: - async with engine.begin() as connection: - await connection.execute( - text(insert_grant), - { - "id": str(uuid4()), - "target": target_id, - "role": "access_administrator", - "scope": "system", - "actor": None, - "principal": "workstream:system:bootstrap", - "authorizer": None, - "reason": "Second bootstrap", - }, - ) - except DBAPIError: - results["second_bootstrap_rejected"] = True - else: - results["second_bootstrap_rejected"] = False - - async with engine.begin() as connection: - await connection.execute( - text(insert_grant), - { - "id": grant_id, - "target": target_id, - "role": "operator", - "scope": "system", - "actor": admin_id, - "principal": None, - "authorizer": bootstrap_id, - "reason": "Operations assignment", - }, - ) - - immutable_columns = ( - "id,target_actor_profile_id,role,scope_type,scope_project_id," - "granted_by_actor_profile_id,granted_by_system_principal," - "granted_by_admin_role_grant_id,grant_reason,granted_at" - ) - async with engine.connect() as connection: - immutable_before = tuple( - ( - await connection.execute( - text(f"select {immutable_columns} from admin_role_grants where id=:id"), - {"id": grant_id}, - ) - ).one() - ) - - guarded_writes = ( - ( - "immutable_reason_rejected", - "update admin_role_grants set grant_reason='Changed' where id=:id", - {"id": grant_id}, - ), - ( - "delete_rejected", - "delete from admin_role_grants where id=:id", - {"id": grant_id}, - ), - ( - "truncate_rejected", - "truncate table admin_role_grants", - {}, - ), - ( - "control_reset_rejected", - "update authority_control set bootstrap_completed=false," - "bootstrap_grant_id=null,version=0 where id=1", - {}, - ), - ) - immutable_updates = ( - ("id", str(uuid4())), - ("target_actor_profile_id", admin_id), - ("role", "finance_authority"), - ("scope_type", "project"), - ("scope_project_id", str(uuid4())), - ("granted_by_actor_profile_id", target_id), - ("granted_by_system_principal", "workstream:system:bootstrap"), - ("granted_by_admin_role_grant_id", grant_id), - ("grant_reason", "Changed provenance"), - ) - immutable_rejected = True - for column, value in immutable_updates: - try: - async with engine.begin() as connection: - await connection.execute( - text(f"update admin_role_grants set {column}=:value where id=:id"), - {"id": grant_id, "value": value}, - ) - except DBAPIError: - continue - immutable_rejected = False - try: - async with engine.begin() as connection: - await connection.execute( - text( - "update admin_role_grants set granted_at=granted_at + interval '1 second' " - "where id=:id" - ), - {"id": grant_id}, - ) - except DBAPIError: - pass - else: - immutable_rejected = False - results["immutable_provenance_rejected"] = immutable_rejected - try: - async with engine.begin() as connection: - await connection.execute( - text("update admin_role_grants set status='revoked',version=2 where id=:id"), - {"id": grant_id}, - ) - except DBAPIError: - results["incomplete_revocation_rejected"] = True - else: - results["incomplete_revocation_rejected"] = False - - async with engine.begin() as connection: - await connection.execute( - text( - "update admin_role_grants set status='revoked',version=2," - "revoked_by_actor_profile_id=:actor," - "revoked_by_admin_role_grant_id=:authorizer," - "revoked_reason='Rotation ended',revoked_at=clock_timestamp() where id=:id" - ), - {"id": grant_id, "actor": admin_id, "authorizer": bootstrap_id}, - ) - for name, statement, values in guarded_writes: - try: - async with engine.begin() as connection: - await connection.execute(text(statement), values) - except DBAPIError: - results[name] = True - else: - results[name] = False - - async with engine.connect() as connection: - row = ( - await connection.execute( - text( - f"select {immutable_columns},status,version,revoked_reason " - "from admin_role_grants where id=:id" - ), - {"id": grant_id}, - ) - ).one() - immutable_after = tuple(row)[: len(immutable_before)] - results.update( - immutable_provenance_preserved=immutable_after == immutable_before, - revoked_status=row.status, - revoked_version=row.version, - grant_reason=row.grant_reason, - revoked_reason=row.revoked_reason, - bootstrap_completed=bool( - await connection.scalar( - text("select bootstrap_completed from authority_control where id=1") - ) - ), - ) - return results - finally: - await engine.dispose() - - -async def _clear_admin_authority_guard_fixtures(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("alter table authority_control disable trigger user")) - await connection.execute(text("alter table admin_role_grants disable trigger user")) - await connection.execute( - text( - "update authority_control set bootstrap_completed=false," - "bootstrap_grant_id=null,version=0 where id=1" - ) - ) - await connection.execute(text("delete from admin_role_grants")) - await connection.execute(text("alter table admin_role_grants enable trigger user")) - await connection.execute(text("alter table authority_control enable trigger user")) - finally: - await engine.dispose() - - -async def _insert_service_actor_before_fixed_identity( - database_url: str, - actor_profile_id: str, - subject: str, -) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await _insert_canonical_actor(connection, actor_profile_id, subject, "service") - finally: - await engine.dispose() - - -async def _write_service_identity_envelope(database_url: str, path: Path) -> None: - engine = create_async_engine(database_url) - try: - snapshot = await snapshot_existing_service_rows(engine) - row = snapshot.rows[0] - draft = ServiceActorIdentityMappingDraft( - schema_version=1, - mappings=( - ServiceActorIdentityMapping( - actor_profile_id=row.actor_profile_id, - issuer=row.issuer, - subject=row.subject, - service_identity=ServiceIdentity.ARTIFACT_VERIFIER, - ), - ), - ) - envelope = build_service_identity_envelope( - draft, - snapshot.rows, - database_binding=snapshot.database_binding, - generated_at="2026-07-16T12:00:00Z", - ) - publish_service_identity_envelope(path, envelope) - finally: - await engine.dispose() - - -async def _service_identity_schema(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - state = ( - await connection.execute( - text( - "select service_identity_mapped_count," - "service_identity_source_row_set_sha256," - "service_identity_manifest_sha256," - "service_identity_envelope_sha256 " - "from actor_profile_migration_state where id=1" - ) - ) - ).one() - result: dict[str, object] = { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "service_identity_column": bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_name='actor_profiles' and " - "column_name='service_identity')" - ) - ) - ), - "mapped_count": state.service_identity_mapped_count, - "source_digest": state.service_identity_source_row_set_sha256, - "manifest_digest": state.service_identity_manifest_sha256, - "envelope_digest": state.service_identity_envelope_sha256, - "private_evidence_columns": bool( - await connection.scalar( - text( - "select exists(select 1 from information_schema.columns " - "where table_name='actor_profile_migration_state' and " - "column_name in ('actor_profile_id','issuer','subject','file_path'))" - ) - ) - ), - } - service_identity = await connection.scalar( - text( - "select service_identity from actor_profiles where actor_kind='service' limit 1" - ) - ) - if service_identity is not None: - result["service_identity"] = service_identity - if state.service_identity_mapped_count == 0: - result.pop("source_digest") - result.pop("private_evidence_columns") - return result - finally: - await engine.dispose() - - -async def _service_identity_guards( - database_url: str, - actor_profile_id: str, -) -> dict[str, bool]: - engine = create_async_engine(database_url) - results: dict[str, bool] = {} - cases = ( - ( - "identity_update_rejected", - "update actor_profiles set service_identity='workstream.artifact.scheduler' " - "where id=:actor_id", - {"actor_id": actor_profile_id}, - ), - ( - "kind_update_rejected", - "update actor_profiles set actor_kind='human'," - "provisioning_method='automatic_first_access',service_identity=null " - "where id=:actor_id", - {"actor_id": actor_profile_id}, - ), - ( - "human_identity_rejected", - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,service_identity,created_by) " - "values (:id,'human','active','automatic_first_access'," - "'workstream.artifact.scheduler',:id)", - {"id": str(uuid4())}, - ), - ( - "unknown_identity_rejected", - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,service_identity,created_by) " - "values (:id,'service','active','manual_service_provisioning'," - "'workstream.artifact.unknown',:id)", - {"id": str(uuid4())}, - ), - ( - "duplicate_identity_rejected", - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,service_identity,created_by) " - "values (:id,'service','active','manual_service_provisioning'," - "'workstream.artifact.verifier',:id)", - {"id": str(uuid4())}, - ), - ) - try: - for name, statement, values in cases: - try: - async with engine.begin() as connection: - await connection.execute(text(statement), values) - except DBAPIError: - results[name] = True - else: - results[name] = False - return results - finally: - await engine.dispose() - - -async def _service_identity_evidence_guards(database_url: str) -> dict[str, bool]: - engine = create_async_engine(database_url) - results: dict[str, bool] = {} - immutable_cases = { - "update_rejected": ( - "update actor_profile_migration_state set " - "service_identity_mapped_count=service_identity_mapped_count where id=1" - ), - "delete_rejected": "delete from actor_profile_migration_state where id=1", - "truncate_rejected": "truncate actor_profile_migration_state", - } - constraint_cases = { - "invalid_count_rejected": ( - "update actor_profile_migration_state set service_identity_mapped_count=8 where id=1" - ), - "invalid_source_digest_rejected": ( - "update actor_profile_migration_state set " - "service_identity_source_row_set_sha256='not-a-digest' where id=1" - ), - "invalid_manifest_digest_rejected": ( - "update actor_profile_migration_state set " - "service_identity_manifest_sha256='not-a-digest' where id=1" - ), - "invalid_database_binding_rejected": ( - "update actor_profile_migration_state set " - "service_identity_database_binding='postgres-v1:not-a-digest' where id=1" - ), - } - try: - for name, statement in immutable_cases.items(): - try: - async with engine.begin() as connection: - await connection.execute(text(statement)) - except DBAPIError: - results[name] = True - else: - results[name] = False - for name, statement in constraint_cases.items(): - try: - async with engine.begin() as connection: - await connection.execute( - text("alter table actor_profile_migration_state disable trigger user") - ) - await connection.execute(text(statement)) - except DBAPIError: - results[name] = True - else: - results[name] = False - return results - finally: - await engine.dispose() - - -async def _remove_fixed_service_actor(database_url: str, actor_profile_id: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("alter table actor_identity_links disable trigger user")) - await connection.execute(text("alter table actor_profiles disable trigger user")) - await connection.execute( - text("delete from actor_identity_links where actor_profile_id=:actor_id"), - {"actor_id": actor_profile_id}, - ) - await connection.execute( - text("delete from actor_profiles where id=:actor_id"), - {"actor_id": actor_profile_id}, - ) - await connection.execute(text("alter table actor_profiles enable trigger user")) - await connection.execute(text("alter table actor_identity_links enable trigger user")) - finally: - await engine.dispose() - - -async def _project_setup_service_state(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - definition = await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='actor_profiles'::regclass " - "and conname='ck_actor_profiles_kind_service_identity'" - ) - ) - counts = tuple( - ( - await connection.execute( - text( - "select " - "(select count(*) from actor_profiles where service_identity=:identity)," - "(select count(*) from actor_identity_links as links join " - "actor_profiles as profiles on profiles.id=links.actor_profile_id " - "where profiles.service_identity=:identity)," - "(select count(*) from admin_role_grants as grants join " - "actor_profiles as profiles on profiles.id=grants.target_actor_profile_id " - "where profiles.service_identity=:identity)," - "(select count(*) from project_role_grants as grants join " - "actor_profiles as profiles on profiles.id=grants.actor_profile_id " - "where profiles.service_identity=:identity)" - ), - {"identity": ServiceIdentity.PROJECT_SETUP.value}, - ) - ).one() - ) - return { - "constraint_admits_identity": ( - ServiceIdentity.PROJECT_SETUP.value in str(definition) - ), - "authority_rows": counts, - } - finally: - await engine.dispose() - - -async def _insert_project_setup_service_actor( - database_url: str, - *, - actor_profile_id: str, -) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,service_identity,created_by) " - "values (:id,'service','active','manual_service_provisioning'," - ":identity,:id)" - ), - { - "id": actor_profile_id, - "identity": ServiceIdentity.PROJECT_SETUP.value, - }, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by) " - "values (:link,:actor,'https://identity.test',:subject,'service'," - "'active',:actor)" - ), - { - "link": str(uuid4()), - "actor": actor_profile_id, - "subject": ServiceIdentity.PROJECT_SETUP.value, - }, - ) - finally: - await engine.dispose() - - -async def _seed_contributor_prior_head( - database_url: str, - *, - assignment_values: tuple[str, ...], - submission_values: tuple[str, ...], - human_ids: tuple[str, ...] = (), -) -> dict[str, tuple[str, ...] | str]: - engine = create_async_engine(database_url) - assignment_ids = tuple(str(uuid4()) for _ in assignment_values) - runtime_ids = { - name: str(uuid4()) - for name in ( - "project", - "guide", - "snapshot", - "submission_policy", - "effective_policy", - "pre_submit_policy", - "policy", - "review_policy", - "revision_policy", - "payment_policy", - "task", - "submission", - "run", - ) - } - submission_ids = (runtime_ids["submission"],) + tuple( - str(uuid4()) for _ in submission_values[1:] - ) - service_id = str(uuid4()) - try: - await _seed_artifact_prior_head_runtime_rows(database_url, runtime_ids) - async with engine.begin() as connection: - for human_id in human_ids: - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:id,'human','active','automatic_first_access',:id)" - ), - {"id": human_id}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status," - "linked_by,last_verified_at) values " - "(:link,:actor,'https://identity.test',:subject,'human'," - "'active',:actor,clock_timestamp())" - ), - { - "link": str(uuid4()), - "actor": human_id, - "subject": f"contributor-{human_id}", - }, - ) - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,service_identity,created_by) " - "values (:id,'service','active','manual_service_provisioning'," - ":identity,:id)" - ), - { - "id": service_id, - "identity": ServiceIdentity.ARTIFACT_VERIFIER.value, - }, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by," - "last_verified_at) values " - "(:link,:actor,'workstream-local',:subject,'service','active'," - ":actor,clock_timestamp())" - ), - { - "link": str(uuid4()), - "actor": service_id, - "subject": ServiceIdentity.ARTIFACT_VERIFIER.value, - }, - ) - resolved_assignment_values = tuple( - service_id if value == "service" else value for value in assignment_values - ) - for index, value in enumerate(assignment_values): - await connection.execute( - text( - "insert into task_assignments " - "(id,task_id,worker_id,assigned_by,status) values " - "(:id,:task,:actor,'migration-test',:status)" - ), - { - "id": assignment_ids[index], - "task": runtime_ids["task"], - "actor": resolved_assignment_values[index], - "status": "active" if index == 0 else "released", - }, - ) - resolved_submission_values = tuple( - service_id if value == "service" else value for value in submission_values - ) - await connection.execute( - text("update submissions set worker_id=:actor where id=:id"), - { - "id": submission_ids[0], - "actor": resolved_submission_values[0], - }, - ) - for index, value in enumerate(resolved_submission_values[1:], start=1): - await connection.execute( - text( - "insert into submissions " - "(id,task_id,worker_id,version,status,summary,package_uri," - "package_hash,artifact_hash_manifest,worker_attestation," - "locked_guide_version,locked_post_submit_checker_policy_id," - "locked_post_submit_checker_policy_version," - "locked_post_submit_checker_policy_hash," - "locked_post_submit_checker_policy_body," - "locked_review_policy_version,locked_revision_policy_version," - "locked_payment_policy_version,locked_guide_source_snapshot_id," - "locked_guide_source_snapshot_hash," - "locked_effective_project_submission_artifact_policy_id," - "locked_effective_project_submission_artifact_policy_hash," - "locked_pre_submit_checker_policy_id," - "locked_pre_submit_checker_bundle_hash,submitted_at,locked_at," - "supersedes_submission_id) " - "select :id,task_id,:actor,:version," - "status,summary,package_uri,package_hash,artifact_hash_manifest," - "worker_attestation,locked_guide_version," - "locked_post_submit_checker_policy_id," - "locked_post_submit_checker_policy_version," - "locked_post_submit_checker_policy_hash," - "locked_post_submit_checker_policy_body," - "locked_review_policy_version,locked_revision_policy_version," - "locked_payment_policy_version,locked_guide_source_snapshot_id," - "locked_guide_source_snapshot_hash," - "locked_effective_project_submission_artifact_policy_id," - "locked_effective_project_submission_artifact_policy_hash," - "locked_pre_submit_checker_policy_id," - "locked_pre_submit_checker_bundle_hash,submitted_at,locked_at,null " - "from submissions where id=:source" - ), - { - "id": submission_ids[index], - "actor": value, - "version": index + 1, - "source": submission_ids[0], - }, - ) - return { - "assignment_ids": assignment_ids, - "submission_ids": submission_ids, - "assignment_task": runtime_ids["task"], - "submission_task": runtime_ids["task"], - "service_id": service_id, - } - finally: - await engine.dispose() - - -async def _clear_contributor_migration_fixtures(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(text("alter table actor_identity_links disable trigger user")) - await connection.execute(text("alter table actor_profiles disable trigger user")) - await connection.execute(text("delete from actor_identity_links")) - await connection.execute(text("delete from actor_profiles")) - await connection.execute(text("alter table actor_profiles enable trigger user")) - await connection.execute(text("alter table actor_identity_links enable trigger user")) - finally: - await engine.dispose() - - -async def _contributor_foundation_shape(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - - async def column(table: str) -> tuple[str, int]: - row = ( - await connection.execute( - text( - "select column_name,character_maximum_length " - "from information_schema.columns where table_schema='public' " - "and table_name=:table and column_name in " - "('worker_id','contributor_id')" - ), - {"table": table}, - ) - ).one() - return str(row[0]), int(row[1]) - - async def index(table: str) -> str: - value = await connection.scalar( - text( - "select indexname from pg_indexes where schemaname='public' " - "and tablename=:table and indexname like " - "'ix_%_worker_id' or schemaname='public' and tablename=:table " - "and indexname like 'ix_%_contributor_id'" - ), - {"table": table}, - ) - assert value is not None - return str(value) - - function_exists = bool( - await connection.scalar( - text( - "select to_regprocedure(" - "'public.require_human_actor_profile_reference()') is not null" - ) - ) - ) - foreign_keys = tuple( - str(row) - for row in ( - await connection.execute( - text( - "select conname from pg_constraint where conname in " - "('fk_task_assignments_contributor_id_actor_profiles'," - "'fk_submissions_contributor_id_actor_profiles') order by conname" - ) - ) - ).scalars() - ) - triggers = tuple( - str(row) - for row in ( - await connection.execute( - text( - "select tgname from pg_trigger where not tgisinternal and tgname in " - "('task_assignments_contributor_human'," - "'submissions_contributor_human') order by tgname" - ) - ) - ).scalars() - ) - assignment_field = "contributor_id" if function_exists else "worker_id" - submission_field = "contributor_id" if function_exists else "worker_id" - assignment_values = tuple( - str(row) - for row in ( - await connection.execute( - text(f"select {assignment_field} from task_assignments order by id") - ) - ).scalars() - ) - submission_values = tuple( - str(row) - for row in ( - await connection.execute( - text(f"select {submission_field} from submissions order by id") - ) - ).scalars() - ) - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "assignment_column": await column("task_assignments"), - "submission_column": await column("submissions"), - "assignment_index": await index("task_assignments"), - "submission_index": await index("submissions"), - "foreign_keys": foreign_keys, - "function": function_exists, - "triggers": triggers, - "assignment_values": assignment_values, - "submission_values": submission_values, - } - finally: - await engine.dispose() - - -def _database_error_sqlstate(error: DBAPIError) -> str | None: - return getattr(error.orig, "sqlstate", None) - - -async def _exercise_contributor_lineage_guards( - database_url: str, - *, - fixture: dict[str, tuple[str, ...] | str], - human_id: str, -) -> dict[str, object]: - engine = create_async_engine(database_url) - service_id = str(fixture["service_id"]) - assignment_task = str(fixture["assignment_task"]) - submission_task = str(fixture["submission_task"]) - assignment_id = str(tuple(fixture["assignment_ids"])[0]) - submission_id = str(tuple(fixture["submission_ids"])[0]) - missing_id = str(uuid4()) - suspended_id = str(uuid4()) - deactivated_id = str(uuid4()) - results: dict[str, object] = {} - try: - for name, statement, values in ( - ( - "missing_assignment", - "insert into task_assignments " - "(id,task_id,contributor_id,assigned_by,status) values " - "(:id,:task,:actor,'test','released')", - {"id": str(uuid4()), "task": assignment_task, "actor": missing_id}, - ), - ( - "service_assignment", - "insert into task_assignments " - "(id,task_id,contributor_id,assigned_by,status) values " - "(:id,:task,:actor,'test','released')", - {"id": str(uuid4()), "task": assignment_task, "actor": service_id}, - ), - ( - "missing_assignment_update", - "update task_assignments set contributor_id=:actor where id=:id", - {"id": assignment_id, "actor": missing_id}, - ), - ( - "service_assignment_update", - "update task_assignments set contributor_id=:actor where id=:id", - {"id": assignment_id, "actor": service_id}, - ), - ( - "missing_submission", - "insert into submissions " - "(id,task_id,contributor_id,version,status,summary,package_uri," - "package_hash,artifact_hash_manifest,worker_attestation," - "locked_guide_version,locked_post_submit_checker_policy_id," - "locked_post_submit_checker_policy_version," - "locked_post_submit_checker_policy_hash," - "locked_post_submit_checker_policy_body," - "locked_review_policy_version,locked_revision_policy_version," - "locked_payment_policy_version,locked_guide_source_snapshot_id," - "locked_guide_source_snapshot_hash," - "locked_effective_project_submission_artifact_policy_id," - "locked_effective_project_submission_artifact_policy_hash," - "locked_pre_submit_checker_policy_id," - "locked_pre_submit_checker_bundle_hash,submitted_at,locked_at," - "supersedes_submission_id) " - "select :id,task_id,:actor,2,status,summary," - "package_uri,package_hash,artifact_hash_manifest,worker_attestation," - "locked_guide_version,locked_post_submit_checker_policy_id," - "locked_post_submit_checker_policy_version," - "locked_post_submit_checker_policy_hash," - "locked_post_submit_checker_policy_body,locked_review_policy_version," - "locked_revision_policy_version,locked_payment_policy_version," - "locked_guide_source_snapshot_id,locked_guide_source_snapshot_hash," - "locked_effective_project_submission_artifact_policy_id," - "locked_effective_project_submission_artifact_policy_hash," - "locked_pre_submit_checker_policy_id,locked_pre_submit_checker_bundle_hash," - "submitted_at,locked_at,null from submissions where task_id=:task", - {"id": str(uuid4()), "task": submission_task, "actor": missing_id}, - ), - ( - "service_submission", - "insert into submissions " - "(id,task_id,contributor_id,version,status,summary,package_uri," - "package_hash,artifact_hash_manifest,worker_attestation," - "locked_guide_version,locked_post_submit_checker_policy_id," - "locked_post_submit_checker_policy_version," - "locked_post_submit_checker_policy_hash," - "locked_post_submit_checker_policy_body," - "locked_review_policy_version,locked_revision_policy_version," - "locked_payment_policy_version,locked_guide_source_snapshot_id," - "locked_guide_source_snapshot_hash," - "locked_effective_project_submission_artifact_policy_id," - "locked_effective_project_submission_artifact_policy_hash," - "locked_pre_submit_checker_policy_id," - "locked_pre_submit_checker_bundle_hash,submitted_at,locked_at," - "supersedes_submission_id) " - "select :id,task_id,:actor,3,status,summary," - "package_uri,package_hash,artifact_hash_manifest,worker_attestation," - "locked_guide_version,locked_post_submit_checker_policy_id," - "locked_post_submit_checker_policy_version," - "locked_post_submit_checker_policy_hash," - "locked_post_submit_checker_policy_body,locked_review_policy_version," - "locked_revision_policy_version,locked_payment_policy_version," - "locked_guide_source_snapshot_id,locked_guide_source_snapshot_hash," - "locked_effective_project_submission_artifact_policy_id," - "locked_effective_project_submission_artifact_policy_hash," - "locked_pre_submit_checker_policy_id,locked_pre_submit_checker_bundle_hash," - "submitted_at,locked_at,null from submissions where task_id=:task", - {"id": str(uuid4()), "task": submission_task, "actor": service_id}, - ), - ( - "missing_submission_update", - "update submissions set contributor_id=:actor where id=:id", - {"id": submission_id, "actor": missing_id}, - ), - ( - "service_submission_update", - "update submissions set contributor_id=:actor where id=:id", - {"id": submission_id, "actor": service_id}, - ), - ): - try: - async with engine.begin() as connection: - await connection.execute(text(statement), values) - except DBAPIError as error: - results[name] = _database_error_sqlstate(error) - else: - results[name] = None - - async with engine.begin() as connection: - await connection.execute( - text("update task_assignments set assigned_by='updated' where id=:id"), - {"id": assignment_id}, - ) - results["unrelated_update_preserved"] = ( - await connection.scalar( - text("select contributor_id=:actor from task_assignments where id=:id"), - {"id": assignment_id, "actor": human_id}, - ) - is True - ) - for actor_id, status in ( - (suspended_id, "suspended"), - (deactivated_id, "deactivated"), - ): - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,created_by) values " - "(:id,'human','active','automatic_first_access',:id)" - ), - {"id": actor_id}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status," - "linked_by,last_verified_at) values " - "(:link,:actor,'https://identity.test',:subject,'human'," - "'active',:actor,clock_timestamp())" - ), - { - "link": str(uuid4()), - "actor": actor_id, - "subject": f"historical-{actor_id}", - }, - ) - if status == "suspended": - await connection.execute( - text( - "update actor_profiles set status='suspended'," - "suspended_by=:actor,suspended_at=clock_timestamp()," - "suspension_reason='migration test' where id=:actor" - ), - {"actor": actor_id}, - ) - else: - await connection.execute( - text( - "update actor_profiles set status='deactivated'," - "deactivated_by=:actor,deactivated_at=clock_timestamp()," - "deactivation_reason='migration test' where id=:actor" - ), - {"actor": actor_id}, - ) - await connection.execute( - text( - "insert into task_assignments " - "(id,task_id,contributor_id,assigned_by,status) values " - "(:id,:task,:actor,'test','released')" - ), - {"id": str(uuid4()), "task": assignment_task, "actor": actor_id}, - ) - results[f"{status}_human_inserted"] = True - return results - finally: - await engine.dispose() - - -async def _exercise_contributor_lineage_function_contract( - database_url: str, -) -> dict[str, object]: - """Prove closed trigger arguments and nullable-field delegation.""" - engine = create_async_engine(database_url) - results: dict[str, object] = {} - try: - for name, arguments in ( - ("zero_arguments", ""), - ("extra_arguments", "'contributor_id','extra'"), - ("absent_field", "'missing_field'"), - ): - try: - async with engine.begin() as connection: - await connection.execute( - text("create temporary table lineage_probe (contributor_id text)") - ) - await connection.execute( - text( - "create trigger lineage_probe_guard before insert on " - "lineage_probe for each row execute function public." - f"require_human_actor_profile_reference({arguments})" - ) - ) - await connection.execute( - text( - "insert into lineage_probe (contributor_id) values " - "('not-a-canonical-id')" - ) - ) - except DBAPIError as error: - results[name] = _database_error_sqlstate(error) - else: - results[name] = None - - async with engine.begin() as connection: - await connection.execute( - text("create temporary table lineage_nullable (contributor_id text)") - ) - await connection.execute( - text( - "create trigger lineage_nullable_guard before insert on " - "lineage_nullable for each row execute function public." - "require_human_actor_profile_reference('contributor_id')" - ) - ) - await connection.execute( - text("insert into lineage_nullable (contributor_id) values (null)") - ) - results["nullable_field_accepted"] = ( - await connection.scalar(text("select count(*) from lineage_nullable")) == 1 - ) - return results - finally: - await engine.dispose() - - -async def _add_contributor_function_dependency(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "create trigger task_assignments_contributor_dependency " - "before update of contributor_id on task_assignments for each row " - "execute function require_human_actor_profile_reference('contributor_id')" - ) - ) - finally: - await engine.dispose() - - -async def _drop_contributor_function_dependency(database_url: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text("drop trigger task_assignments_contributor_dependency on task_assignments") - ) - finally: - await engine.dispose() - - -async def _insert_authorization_action_event_for( - database_url: str, - action_id: str, - permission_id: str, -) -> str: - values = _action_evidence_values(action_id, permission_id) - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute(_ACTION_EVIDENCE_INSERT, values) - return str(values["id"]) - finally: - await engine.dispose() - - -async def _insert_linked_authorization_action_event( - database_url: str, - *, - record_id: str, - actor_id: str, - action_id: str, - permission_id: str, -) -> str: - """Seed one constraint-valid linked denial while bypassing only link policy.""" - event_id = str(uuid4()) - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text("alter table audit_events disable trigger audit_events_validate_idempotency") - ) - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version," - "actor_ref_kind,request_id,correlation_id,permission_id,action_id,reason," - "idempotency_reference,after_facts) values " - "(:id,'authorization_decision',:id,'SensitiveAuthorizationAllowed'," - ":actor,'[]'::json,'{}'::json,'local_authority',false,'{}'::json," - "'authority',1,'actor_profile',:request,:correlation,:permission,:action," - "'authorization_evaluation',:record,'{\"allowed\": true}'::json)" - ), - { - "id": event_id, - "actor": actor_id, - "request": str(uuid4()), - "correlation": str(uuid4()), - "permission": permission_id, - "action": action_id, - "record": record_id, - }, - ) - await connection.execute( - text("alter table audit_events enable trigger audit_events_validate_idempotency") - ) - return event_id - finally: - await engine.dispose() - - -async def _insert_orphan_linked_authorization_action_event( - database_url: str, - *, - action_id: str, - permission_id: str, -) -> str: - """Seed historical action evidence whose non-null idempotency link is orphaned.""" - event_id = str(uuid4()) - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "alter table audit_events drop constraint fk_audit_events_authority_idempotency" - ) - ) - await connection.execute( - text("alter table audit_events disable trigger audit_events_validate_idempotency") - ) - await connection.execute( - text( - "insert into audit_events " - "(id,entity_type,entity_id,event_type,actor_id,actor_roles,claim_snapshot," - "auth_source,is_dev_auth,event_payload,event_domain,event_version," - "actor_ref_kind,request_id,correlation_id,permission_id,action_id,reason," - "idempotency_reference,after_facts) values " - "(:id,'authorization_decision',:id,'SensitiveAuthorizationAllowed'," - ":actor,'[]'::json,'{}'::json,'local_authority',false,'{}'::json," - "'authority',1,'actor_profile',:request,:correlation,:permission,:action," - "'authorization_evaluation',:record,'{\"allowed\": true}'::json)" - ), - { - "id": event_id, - "actor": str(uuid4()), - "request": str(uuid4()), - "correlation": str(uuid4()), - "permission": permission_id, - "action": action_id, - "record": str(uuid4()), - }, - ) - await connection.execute( - text( - "alter table audit_events add constraint " - "fk_audit_events_authority_idempotency foreign key " - "(idempotency_reference,actor_ref_kind,actor_id) references " - "authority_idempotency_records (id,actor_ref_kind,actor_ref) not valid" - ) - ) - await connection.execute( - text("alter table audit_events enable trigger audit_events_validate_idempotency") - ) - return event_id - finally: - await engine.dispose() - - -async def _art_catalogue_migration_state( - database_url: str, - *, - actions: tuple[str, ...], - permissions: tuple[str, ...], -) -> dict[str, object]: - """Snapshot revision, rewritten constraints, and all protected evidence counts.""" - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - constraints = dict( - ( - await connection.execute( - text( - "select conname,pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass and conname in " - "('ck_audit_events_authority_registries'," - "'ck_audit_events_authority_privacy_bounds'," - "'ck_audit_events_authorization_action_evidence') order by conname" - ) - ) - ).all() - ) - direct_count = await connection.scalar( - text( - "select count(*) from audit_events where action_id=any(:actions) or " - "permission_id=any(:permissions) or " - "(target_ref_kind='permission_registry' and target_ref_id=any(:permissions)) " - "or (invalidation_target_kind='permission_registry' and " - "invalidation_target_ref=any(:permissions))" - ), - {"actions": list(actions), "permissions": list(permissions)}, - ) - linked_count = await connection.scalar( - text( - "select count(*) from authority_idempotency_records record join " - "audit_events event on event.idempotency_reference=record.id where " - "event.action_id=any(:actions) or event.permission_id=any(:permissions)" - ), - {"actions": list(actions), "permissions": list(permissions)}, - ) - return { - "revision": await connection.scalar( - text("select version_num from alembic_version") - ), - "constraints": constraints, - "direct_count": direct_count, - "linked_count": linked_count, - } - finally: - await engine.dispose() - - -async def _exercise_project_role_migration(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - actor_id = actor_id_from_external_identity("https://identity.test", "auth10a-actor") - project_id, admin_grant_id = str(uuid4()), str(uuid4()) - snapshot_ids = [str(uuid4()) for _ in range(3)] - grant_ids = [str(uuid4()) for _ in range(3)] - results: dict[str, object] = {} - supplied_at = datetime(2000, 1, 1, tzinfo=UTC) - - async def rejected(connection, statement: str, values: dict[str, object]) -> str | None: - try: - async with connection.begin_nested(): - await connection.execute(text(statement), values) - except DBAPIError as error: - return _database_error_sqlstate(error) - return None - - try: - async with engine.connect() as connection: - transaction = await connection.begin() - try: - await _insert_canonical_actor(connection, actor_id, "auth10a-actor", "human") - await connection.execute( - text( - "insert into projects(id,name,slug,status) values (:id,'AUTH 10A',:slug,'active')" - ), - {"id": project_id, "slug": f"auth-10a-{project_id}"}, - ) - await connection.execute( - text( - "insert into admin_role_grants " - "(id,target_actor_profile_id,role,scope_type,status,version," - "granted_by_system_principal,grant_reason) values " - "(:id,:actor,'access_administrator','system','active',1," - "'workstream:system:bootstrap','AUTH 10A migration proof')" - ), - {"id": admin_grant_id, "actor": actor_id}, - ) - await connection.execute( - text( - "update authority_control set bootstrap_completed=true," - "bootstrap_grant_id=:grant,version=1 where id=1" - ), - {"grant": admin_grant_id}, - ) - snapshot_insert = text( - "insert into project_role_qualification_snapshots " - "(id,project_id,actor_profile_id,requested_role,skills_snapshot," - "reputation_snapshot,prior_project_work_refs,external_expertise_refs," - "captured_by_actor_profile_id,captured_by_admin_role_grant_id,captured_at) values " - "(:id,:project,:actor,:role,cast(:skills as jsonb),cast(:reputation as jsonb)," - "cast(:prior as jsonb),cast(:external as jsonb),:actor,:admin," - "cast(:supplied_at as timestamptz))" - ) - available = json.dumps( - { - "availability": "available", - "reference_ids": ["opaque:1"], - "unavailable_reason": None, - } - ) - unavailable = json.dumps( - { - "availability": "unavailable", - "reference_ids": [], - "unavailable_reason": "no_record", - } - ) - for role, snapshot_id in zip( - ("submitter", "reviewer", "adjudicator"), snapshot_ids, strict=True - ): - await connection.execute( - snapshot_insert, - { - "id": snapshot_id, - "project": project_id, - "actor": actor_id, - "role": role, - "skills": available, - "reputation": unavailable, - "prior": "[]", - "external": "[]", - "admin": admin_grant_id, - "supplied_at": supplied_at, - }, - ) - results["invalid_availability"] = await rejected( - connection, - str(snapshot_insert), - { - "id": str(uuid4()), - "project": project_id, - "actor": actor_id, - "role": "submitter", - "skills": json.dumps( - { - "availability": "available", - "reference_ids": [], - "unavailable_reason": None, - } - ), - "reputation": unavailable, - "prior": "[]", - "external": "[]", - "admin": admin_grant_id, - "supplied_at": supplied_at, - }, - ) - snapshot_rejections: dict[str, str | None] = {} - snapshot_variants = { - "extra_key": { - "availability": "available", - "reference_ids": ["opaque:1"], - "unavailable_reason": None, - "extra": True, - }, - "available_empty": { - "availability": "available", - "reference_ids": [], - "unavailable_reason": None, - }, - "unavailable_with_reference": { - "availability": "unavailable", - "reference_ids": ["opaque:1"], - "unavailable_reason": "no_record", - }, - "url_reference": { - "availability": "available", - "reference_ids": ["https://unsafe.example"], - "unavailable_reason": None, - }, - "too_many_references": { - "availability": "available", - "reference_ids": [f"opaque:{index}" for index in range(21)], - "unavailable_reason": None, - }, - } - for name, skills in snapshot_variants.items(): - snapshot_rejections[name] = await rejected( - connection, - str(snapshot_insert), - { - "id": str(uuid4()), - "project": project_id, - "actor": actor_id, - "role": "submitter", - "skills": json.dumps(skills), - "reputation": unavailable, - "prior": "[]", - "external": "[]", - "admin": admin_grant_id, - "supplied_at": supplied_at, - }, - ) - snapshot_rejections["invalid_prior_uuid"] = await rejected( - connection, - str(snapshot_insert), - { - "id": str(uuid4()), - "project": project_id, - "actor": actor_id, - "role": "submitter", - "skills": available, - "reputation": unavailable, - "prior": json.dumps(["not-a-uuid"]), - "external": "[]", - "admin": admin_grant_id, - "supplied_at": supplied_at, - }, - ) - results["snapshot_constraint_rejections"] = snapshot_rejections - results["snapshot_truncate"] = await rejected( - connection, - "truncate project_role_qualification_snapshots, project_role_grants", - {}, - ) - raw_grant_insert = ( - "insert into project_role_grants " - "(id,project_id,actor_profile_id,role,status,version,grant_method," - "qualification_snapshot_id,granted_by_actor_profile_id," - "granted_by_admin_role_grant_id,grant_reason) values " - "(:id,:project,:actor,:role,:status,:version,:method,:snapshot,:actor,:admin,:reason)" - ) - base_grant = { - "project": project_id, - "actor": actor_id, - "role": "submitter", - "status": "active", - "version": 1, - "method": "manual", - "snapshot": snapshot_ids[0], - "admin": admin_grant_id, - "reason": "Qualified", - } - grant_variants = { - "automated_method": {"method": "automated"}, - "combined_role": {"role": "both"}, - "leading_space_reason": {"reason": " Qualified"}, - "control_reason": {"reason": "bad\u200bcontrol"}, - "oversize_reason": {"reason": "é" * 251}, - "snapshot_mismatch": {"snapshot": snapshot_ids[1]}, - "invalid_active_version": {"version": 2}, - } - results["grant_constraint_rejections"] = { - name: await rejected( - connection, raw_grant_insert, base_grant | patch | {"id": str(uuid4())} - ) - for name, patch in grant_variants.items() - } - grant_insert = text( - "insert into project_role_grants " - "(id,project_id,actor_profile_id,role,qualification_snapshot_id," - "granted_by_actor_profile_id,granted_by_admin_role_grant_id,grant_reason,granted_at) " - "values (:id,:project,:actor,:role,:snapshot,:actor,:admin," - "'Qualified manually',cast(:supplied_at as timestamptz))" - ) - for role, snapshot_id, grant_id in zip( - ("submitter", "reviewer", "adjudicator"), snapshot_ids, grant_ids, strict=True - ): - await connection.execute( - grant_insert, - { - "id": grant_id, - "project": project_id, - "actor": actor_id, - "role": role, - "snapshot": snapshot_id, - "admin": admin_grant_id, - "supplied_at": supplied_at, - }, - ) - results["revision"] = await connection.scalar( - text("select version_num from alembic_version") - ) - results["role_count"] = await connection.scalar( - text("select count(*) from project_role_grants where project_id=:project"), - {"project": project_id}, - ) - results["duplicate_role"] = await rejected( - connection, - str(grant_insert), - { - "id": str(uuid4()), - "project": project_id, - "actor": actor_id, - "role": "submitter", - "snapshot": snapshot_ids[0], - "admin": admin_grant_id, - "supplied_at": supplied_at, - }, - ) - results["snapshot_update"] = await rejected( - connection, - "update project_role_qualification_snapshots set external_expertise_refs='[]'::jsonb where id=:id", - {"id": snapshot_ids[0]}, - ) - results["snapshot_delete"] = await rejected( - connection, - "delete from project_role_qualification_snapshots where id=:id", - {"id": snapshot_ids[0]}, - ) - results["issuance_update"] = await rejected( - connection, - "update project_role_grants set grant_reason='Changed' where id=:id", - {"id": grant_ids[0]}, - ) - results["grant_delete"] = await rejected( - connection, "delete from project_role_grants where id=:id", {"id": grant_ids[0]} - ) - results["grant_truncate"] = await rejected( - connection, "truncate project_role_grants", {} - ) - await connection.execute( - text( - "update project_role_grants set status='revoked',version=2," - "revoked_by_actor_profile_id=:actor,revoked_by_admin_role_grant_id=:admin," - "revoked_reason='No longer assigned',revoked_at='2000-01-01T00:00:00+00:00' where id=:id" - ), - {"id": grant_ids[0], "actor": actor_id, "admin": admin_grant_id}, - ) - results["valid_revoke"] = tuple( - ( - await connection.execute( - text("select status,version from project_role_grants where id=:id"), - {"id": grant_ids[0]}, - ) - ).one() - ) - results["database_timestamps"] = bool( - await connection.scalar( - text( - "select captured_at > '2026-01-01'::timestamptz from " - "project_role_qualification_snapshots where id=:id" - ), - {"id": snapshot_ids[0]}, - ) - ) and bool( - await connection.scalar( - text( - "select granted_at > '2026-01-01'::timestamptz and " - "revoked_at > '2026-01-01'::timestamptz from project_role_grants where id=:id" - ), - {"id": grant_ids[0]}, - ) - ) - results["second_revoke"] = await rejected( - connection, - "update project_role_grants set revoked_reason='Again' where id=:id", - {"id": grant_ids[0]}, - ) - finally: - await transaction.rollback() - return results - finally: - await engine.dispose() - - -async def _install_legacy_project_role_blocker( - database_url: str, - patch: dict[str, object], - *, - bypass_constraints: bool, -) -> tuple[str, list[tuple[str, str]], tuple[tuple[object, ...], ...]]: - event_id = await _insert_authorization_action_event(database_url) - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - triggers = tuple( - tuple(row) - for row in ( - await connection.execute( - text( - "select tgrelid::regclass::text,tgname,tgenabled " - "from pg_trigger where tgrelid='audit_events'::regclass " - "and not tgisinternal order by tgname" - ) - ) - ).all() - ) - constraints: list[tuple[str, str]] = [] - if bypass_constraints: - constraints = [ - tuple(row) - for row in ( - await connection.execute( - text( - "select conname,pg_get_constraintdef(oid) from pg_constraint " - "where conrelid='audit_events'::regclass and contype='c' " - "order by conname" - ) - ) - ).all() - ] - await connection.execute(text("alter table audit_events disable trigger user")) - for name, _definition in constraints: - await connection.execute( - text(f'alter table audit_events drop constraint "{name}"') - ) - else: - await connection.execute( - text( - "alter table audit_events disable trigger audit_events_reject_update_delete" - ) - ) - assignments = [] - values: dict[str, object] = {"id": event_id} - for key, value in patch.items(): - if key == "action_id": - definition = next( - item for item in ACTION_DEFINITIONS if item.action_id.value == value - ) - assignments.append("permission_id=:permission_id") - values["permission_id"] = definition.permission_id.value - if key in {"before_facts", "after_facts"}: - assignments.append(f"{key}=cast(:{key} as json)") - values[key] = json.dumps(value) - else: - assignments.append(f"{key}=:{key}") - values[key] = value - await connection.execute( - text(f"update audit_events set {','.join(assignments)} where id=:id"), values - ) - if not bypass_constraints: - await _restore_0034_trigger_states(connection, triggers) - return event_id, constraints, triggers - finally: - await engine.dispose() - - -async def _remove_legacy_project_role_blocker( - database_url: str, - event_id: str, - constraints: list[tuple[str, str]], - triggers: tuple[tuple[object, ...], ...], -) -> None: - engine = create_async_engine(database_url) - try: - try: - async with engine.begin() as connection: - await connection.execute( - text( - "alter table audit_events disable trigger audit_events_reject_update_delete" - ) - ) - await connection.execute( - text("delete from audit_events where id=:id"), {"id": event_id} - ) - for name, definition in constraints: - if name == "ck_audit_events_authority_privacy_bounds": - await _restore_0034_privacy_constraint( - connection, - definition, - not definition.endswith(" NOT VALID"), - ) - else: - await connection.execute( - text(f'alter table audit_events add constraint "{name}" {definition}') - ) - finally: - async with engine.begin() as connection: - await _restore_0034_trigger_states(connection, triggers) - finally: - await engine.dispose() - - -async def _project_role_refusal_state(database_url: str) -> tuple[str, bool, bool, int]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return ( - str(await connection.scalar(text("select version_num from alembic_version"))), - bool( - await connection.scalar( - text("select to_regclass('project_role_grants') is not null") - ) - ), - bool( - await connection.scalar( - text( - "select to_regclass('project_role_qualification_snapshots') is not null" - ) - ) - ), - int( - await connection.scalar( - text( - "select count(*) from audit_events where event_domain='authority' and " - "(before_facts->>'role'='both' or after_facts->>'role'='both' or " - "before_facts::jsonb ? 'replaced_grant_id' or " - "after_facts::jsonb ? 'replaced_grant_id' or " - "event_type='ProjectRoleGrantReplaced' or reason='authority_replacement')" - ) - ) - ), - ) - finally: - await engine.dispose() - - -async def _project_role_audit_row(database_url: str, event_id: str) -> tuple: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return tuple( - ( - await connection.execute( - text( - "select id,event_type,reason,action_id,denial_code,before_facts," - "after_facts from audit_events where id=:id" - ), - {"id": event_id}, - ) - ).one() - ) - finally: - await engine.dispose() - - -async def _insert_project_role_idempotency_blocker(database_url: str, operation: str) -> str: - record_id = str(uuid4()) - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text("alter table authority_idempotency_records disable trigger user") - ) - await connection.execute( - text( - "insert into authority_idempotency_records " - "(id,idempotency_key,actor_ref_kind,actor_ref,operation,request_digest,status) " - "values (:id,:key,'system_principal','workstream:system:bootstrap'," - ":operation,:digest,'pending')" - ), - { - "id": record_id, - "key": str(uuid4()), - "operation": operation, - "digest": "sha256:" + "0" * 64, - }, - ) - return record_id - finally: - await engine.dispose() - - -async def _project_role_idempotency_row(database_url: str, record_id: str) -> tuple: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - return tuple( - ( - await connection.execute( - text( - "select id,idempotency_key,actor_ref_kind,actor_ref,operation," - "request_digest,status from authority_idempotency_records where id=:id" - ), - {"id": record_id}, - ) - ).one() - ) - finally: - await engine.dispose() - - -async def _remove_project_role_idempotency_blocker(database_url: str, record_id: str) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text("delete from authority_idempotency_records where id=:id"), {"id": record_id} - ) - await connection.execute( - text("alter table authority_idempotency_records enable trigger user") - ) - finally: - await engine.dispose() - - -async def _assert_project_role_denial_sql(database_url: str) -> None: - engine = create_async_engine(database_url) - insert = text(str(_ACTION_EVIDENCE_INSERT).replace("'permission_not_granted'", ":denial_code")) - try: - for denial_code in ( - "project_role_grant_already_revoked", - "project_role_grant_replay_state_changed", - ): - values = _action_evidence_values("project_role_grant.read", "project.role_grant.read") - values["denial_code"] = denial_code - async with engine.connect() as connection: - transaction = await connection.begin() - await connection.execute(insert, values) - await transaction.rollback() - invalid = _action_evidence_values("project_role_grant.read", "project.role_grant.read") - invalid["denial_code"] = "project_role_grant_neighboring_unknown" - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute(insert, invalid) - await transaction.rollback() - finally: - await engine.dispose() - - -async def _install_project_role_table_blockers( - database_url: str, *, include_grant: bool -) -> dict[str, str]: - ids = { - "actor": actor_id_from_external_identity("https://identity.test", "auth10a-blocker"), - "project": str(uuid4()), - "admin": str(uuid4()), - "snapshot": str(uuid4()), - "grant": str(uuid4()), - } - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await _insert_canonical_actor(connection, ids["actor"], "auth10a-blocker", "human") - await insert_historical_project( - connection, - project_id=ids["project"], - name="AUTH 10A blocker", - slug=f"auth-10a-blocker-{ids['project']}", - status="active", - ) - await connection.execute( - text( - "insert into admin_role_grants " - "(id,target_actor_profile_id,role,scope_type,status,version," - "granted_by_system_principal,grant_reason) values " - "(:admin,:actor,'access_administrator','system','active',1," - "'workstream:system:bootstrap','AUTH 10A downgrade blocker')" - ), - ids, - ) - await connection.execute( - text( - "update authority_control set bootstrap_completed=true," - "bootstrap_grant_id=:admin,version=1 where id=1" - ), - ids, - ) - availability = json.dumps( - { - "availability": "available", - "reference_ids": ["opaque:1"], - "unavailable_reason": None, - } - ) - unavailable = json.dumps( - { - "availability": "unavailable", - "reference_ids": [], - "unavailable_reason": "no_record", - } - ) - await connection.execute( - text( - "insert into project_role_qualification_snapshots " - "(id,project_id,actor_profile_id,requested_role,skills_snapshot," - "reputation_snapshot,prior_project_work_refs,external_expertise_refs," - "captured_by_actor_profile_id,captured_by_admin_role_grant_id) values " - "(:snapshot,:project,:actor,'submitter',cast(:available as jsonb)," - "cast(:unavailable as jsonb),'[]'::jsonb,'[]'::jsonb,:actor,:admin)" - ), - ids | {"available": availability, "unavailable": unavailable}, - ) - if include_grant: - await connection.execute( - text( - "insert into project_role_grants " - "(id,project_id,actor_profile_id,role,qualification_snapshot_id," - "granted_by_actor_profile_id,granted_by_admin_role_grant_id,grant_reason) " - "values (:grant,:project,:actor,'submitter',:snapshot,:actor,:admin,'Qualified')" - ), - ids, - ) - return ids - finally: - await engine.dispose() - - -async def _project_role_table_rows( - database_url: str, ids: dict[str, str] -) -> tuple[tuple | None, tuple | None]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - snapshot = ( - await connection.execute( - text( - "select id,project_id,actor_profile_id,requested_role,skills_snapshot," - "reputation_snapshot,prior_project_work_refs,external_expertise_refs," - "captured_by_actor_profile_id,captured_by_admin_role_grant_id,captured_at " - "from project_role_qualification_snapshots where id=:snapshot" - ), - ids, - ) - ).one_or_none() - grant = ( - await connection.execute( - text( - "select id,project_id,actor_profile_id,role,status,version,grant_method," - "qualification_snapshot_id,granted_by_actor_profile_id," - "granted_by_admin_role_grant_id,grant_reason,granted_at from " - "project_role_grants where id=:grant" - ), - ids, - ) - ).one_or_none() - return ( - tuple(snapshot) if snapshot is not None else None, - tuple(grant) if grant is not None else None, - ) - finally: - await engine.dispose() - - -async def _remove_project_role_table_blockers(database_url: str, ids: dict[str, str]) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - for table in ( - "project_role_grants", - "project_role_qualification_snapshots", - "admin_role_grants", - "authority_control", - "actor_identity_links", - "actor_profiles", - ): - await connection.execute(text(f"alter table {table} disable trigger user")) - await connection.execute(text("delete from project_role_grants where id=:grant"), ids) - await connection.execute( - text("delete from project_role_qualification_snapshots where id=:snapshot"), - ids, - ) - await connection.execute( - text( - "update authority_control set bootstrap_completed=false," - "bootstrap_grant_id=null,version=0 where id=1" - ) - ) - await connection.execute(text("delete from admin_role_grants where id=:admin"), ids) - await connection.execute( - text("delete from actor_identity_links where actor_profile_id=:actor"), ids - ) - await connection.execute(text("delete from actor_profiles where id=:actor"), ids) - await connection.execute(text("delete from projects where id=:project"), ids) - for table in reversed( - ( - "project_role_grants", - "project_role_qualification_snapshots", - "admin_role_grants", - "authority_control", - "actor_identity_links", - "actor_profiles", - ) - ): - await connection.execute(text(f"alter table {table} enable trigger user")) - finally: - await engine.dispose() - - -def test_xint003_02a_policy_lineage_backfill_immutability_and_roundtrip( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove historical policies get exact identity without invented semantics.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - ids = { - "project": str(uuid4()), - "guide": str(uuid4()), - "review": str(uuid4()), - "revision": str(uuid4()), - } - - with migration_lock(): - try: - command.downgrade(config, "0045_guide_metadata_authority") - asyncio.run(_seed_xint003_02a_legacy_policies(isolated_database_env, ids)) - command.upgrade(config, "0047_policy_identity_lineage") - state = asyncio.run(_xint003_02a_policy_state(isolated_database_env, ids)) - immutable = asyncio.run( - _xint003_02a_policy_immutable_writes(isolated_database_env, ids) - ) - with pytest.raises( - RuntimeError, match="cannot downgrade populated immutable policy lineage" - ): - command.downgrade(config, "0045_guide_metadata_authority") - refused_state = asyncio.run(_xint003_02a_policy_state(isolated_database_env, ids)) - finally: - asyncio.run(_remove_xint003_02a_immutable_policies(isolated_database_env, ids)) - command.downgrade(config, "0045_guide_metadata_authority") - command.upgrade(config, "head") - - assert state["review"][0:3] == (ids["review"], 1, "legacy_incomplete") - assert state["revision"][0:3] == (ids["revision"], 1, "legacy_incomplete") - assert state["review"][3].startswith("sha256:") - assert state["revision"][3].startswith("sha256:") - assert state["guide"] == ( - ids["review"], - 1, - state["review"][3], - ids["revision"], - 1, - state["revision"][3], - ) - assert immutable == { - "partial_selection", - "active_selection_change", - "review_update", - "review_delete", - "review_truncate", - "revision_update", - "revision_delete", - "revision_truncate", - } - assert refused_state == state - - -def test_xint003_02b_policy_authority_schema_and_roundtrip( - isolated_database_env: str, - migration_lock, -) -> None: - """Prove 0048 installs only the closed policy mutation custody boundary.""" - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - - with migration_lock(): - try: - command.downgrade(config, "0047_policy_identity_lineage") - command.upgrade(config, "0048_policy_authority") - shape = asyncio.run(_xint003_02b_authority_shape(isolated_database_env)) - command.downgrade(config, "0047_policy_identity_lineage") - absent = asyncio.run(_xint003_02b_authority_shape(isolated_database_env)) - finally: - command.upgrade(config, "head") - - assert shape == { - "ledger": True, - "review_provenance": 8, - "revision_provenance": 8, - "custody_triggers": 3, - "selector_constraint": True, - "review_only_selector": True, - "revision_only_selector": True, - "partial_review_selector": False, - "partial_revision_selector": False, - "selector_custody": True, - "predecessor_custody": True, - } - assert absent == { - "ledger": False, - "review_provenance": 0, - "revision_provenance": 0, - "custody_triggers": 0, - "selector_constraint": True, - "review_only_selector": False, - "revision_only_selector": False, - "partial_review_selector": False, - "partial_revision_selector": False, - "selector_custody": False, - "predecessor_custody": False, - } - - -_XINT003_02C_ACTIONS = ( - ("review.revision_context.repair", "project.task.manage"), - ("review.revision_obligation.close", "project.task.manage"), - ("review.revision_context.legacy_close", "operations.reconcile.run"), ("review.lifecycle.activation.manage", "operations.reconcile.run"), -) -_XINT003_02C_IDENTITIES = tuple( - identity.value - for identity in ( - ServiceIdentity.REVIEW_PREFERENCE_EXPIRY, ServiceIdentity.REVIEW_LEASE_EXPIRY, - ServiceIdentity.REVIEW_AUTHORITY_INVALIDATION_RECONCILIATION, ServiceIdentity.REVIEW_RECONCILIATION, - ServiceIdentity.REVIEW_ARTIFACT_REFERENCE_RECONCILIATION, ServiceIdentity.REVIEW_PROJECTION, - ) -) - - -def test_xint003_02c_rev_auth_readiness_schema_and_roundtrip( - isolated_database_env: str, migration_lock) -> None: - """0049 admits exact planned evidence and principals without seeding authority.""" - config = _alembic_config() - with migration_lock(): - try: - command.downgrade(config, "0048_policy_authority") - prior = asyncio.run(_xint003_02c_readiness_state(isolated_database_env)) - command.upgrade(config, "head") - upgraded = asyncio.run(_xint003_02c_readiness_state(isolated_database_env)) - command.downgrade(config, "0048_policy_authority") - restored = asyncio.run(_xint003_02c_readiness_state(isolated_database_env)) - command.upgrade(config, "head") - repeated = asyncio.run(_xint003_02c_readiness_state(isolated_database_env)) - finally: - command.upgrade(config, "head") - additions = " OR " + " OR ".join(_xint003_02c_pair_token(*pair) for pair in _XINT003_02C_ACTIONS) - assert prior["profiles"] == upgraded["profiles"] == 0 - assert upgraded["action_definition"].count(additions) == 2 - without_later_actions = upgraded["action_definition"].replace(additions, "") - for action in ("project.guide_compilation.execute", "project.guide_compilation.request"): - assert upgraded["action_definition"].count(" OR " + _xint003_02c_pair_token(action, action)) == 2 - without_later_actions = without_later_actions.replace(" OR " + _xint003_02c_pair_token(action, action), "").replace(f", ('{action}'::character varying)::text", "") - assert without_later_actions == prior["action_definition"] - historical_identities = (*FROZEN_SERVICE_IDENTITY_VALUES, ServiceIdentity.PROJECT_SETUP.value) - assert prior["identity_values"] == historical_identities - assert upgraded["identity_values"] == (*historical_identities, *_XINT003_02C_IDENTITIES) - assert restored == prior - assert repeated == upgraded - - -@pytest.mark.parametrize(("action_id", "permission_id"), _XINT003_02C_ACTIONS) -@pytest.mark.parametrize("evidence_shape", ("direct", "idempotency_linked")) -def test_xint003_02c_rev_auth_readiness_guarded_action_evidence_downgrade( - isolated_database_env: str, - migration_lock, - action_id: str, - permission_id: str, - evidence_shape: str, -) -> None: - """Every newly admitted action pair blocks vocabulary removal once used.""" - config = _alembic_config() - event_id = "" - record_id = str(uuid4()) - with migration_lock(): - try: - command.upgrade(config, "head") - if evidence_shape == "direct": - event_id = asyncio.run( - _insert_authorization_action_event_for( - isolated_database_env, action_id, permission_id - ) - ) - else: - actor_id, target_id = str(uuid4()), str(uuid4()) - asyncio.run( - _insert_committed_authority_idempotency( - isolated_database_env, record_id, actor_id, target_id - ) - ) - event_id = asyncio.run( - _insert_linked_authorization_action_event( - isolated_database_env, - record_id=record_id, - actor_id=actor_id, - action_id=action_id, - permission_id=permission_id, - ) - ) - with pytest.raises( - RuntimeError, - match="cannot downgrade non-empty REV authorization action evidence", - ): - command.downgrade(config, "0048_policy_authority") - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - finally: - asyncio.run(_remove_authority_audit_fixture(isolated_database_env, event_id=event_id)) - if evidence_shape == "idempotency_linked": - asyncio.run( - _remove_authority_idempotency_fixture( - isolated_database_env, record_id, orphan_event=None - ) - ) - command.upgrade(config, "head") - - -@pytest.mark.parametrize("service_identity", _XINT003_02C_IDENTITIES) -def test_xint003_02c_rev_auth_readiness_guarded_identity_downgrade( - isolated_database_env: str, migration_lock, service_identity: str -) -> None: - """Every newly admitted fixed principal blocks removal while in use.""" - config = _alembic_config() - actor_id = str(uuid4()) - with migration_lock(): - try: - command.upgrade(config, "head") - asyncio.run( - _insert_rev_service_actor( - isolated_database_env, - actor_id=actor_id, - service_identity=service_identity, - ) - ) - with pytest.raises( - RuntimeError, match="cannot downgrade in-use REV service identities" - ): - command.downgrade(config, "0048_policy_authority") - assert asyncio.run(_current_revision(isolated_database_env)) == HEAD_REVISION - finally: - asyncio.run(_remove_fixed_service_actor(isolated_database_env, actor_id)) - command.upgrade(config, "head") - - -async def _xint003_02c_readiness_state(database_url: str) -> dict[str, object]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - action_definition = str( - await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint where " - "conname='ck_audit_events_authorization_action_evidence'" - ) - ) - ) - identity_definition = str( - await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint where " - "conname='ck_actor_profiles_kind_service_identity'" - ) - ) - ) - profiles = int( - await connection.scalar( - text( - "select count(*) from actor_profiles where " - "service_identity=any(:identities)" - ), - {"identities": list(_XINT003_02C_IDENTITIES)}, - ) - or 0 - ) - return { - "action_definition": action_definition, - "identity_values": tuple( - re.findall(r"'([^']+)'::character varying", identity_definition) - ), - "profiles": profiles, - } - finally: - await engine.dispose() - - -def _xint003_02c_pair_token(action: str, permission: str) -> str: - return ( - f"(((action_id)::text = '{action}'::text) AND " - f"((permission_id)::text = '{permission}'::text))" - ) - - -async def _insert_rev_service_actor( - database_url: str, *, actor_id: str, service_identity: str -) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into actor_profiles " - "(id,actor_kind,status,provisioning_method,service_identity,created_by) " - "values (:id,'service','active','manual_service_provisioning'," - ":identity,:id)" - ), - {"id": actor_id, "identity": service_identity}, - ) - await connection.execute( - text( - "insert into actor_identity_links " - "(id,actor_profile_id,issuer,subject,subject_kind,status,linked_by) " - "values (:id,:actor,'https://identity.test',:subject,'service'," - "'active',:actor)" - ), - { - "id": str(uuid4()), - "actor": actor_id, - "subject": service_identity, - }, - ) - finally: - await engine.dispose() - - -async def _xint003_02b_authority_shape(database_url: str) -> dict[str, int | bool]: - engine = create_async_engine(database_url) - provenance = { - "predecessor_policy_hash", - "created_by_actor_profile_id", - "created_via_identity_link_id", - "created_by_admin_role_grant_id", - "creation_scope_type", - "creation_scope_project_id", - "creation_action_id", - "authorization_decision_event_id", - } - try: - async with engine.connect() as connection: - tables = set( - ( - await connection.execute( - text( - "select table_name from information_schema.tables " - "where table_schema='public'" - ) - ) - ).scalars() - ) - columns = {} - for table in ("review_policies", "revision_policies"): - columns[table] = set( - ( - await connection.execute( - text( - "select column_name from information_schema.columns " - "where table_schema='public' and table_name=:table" - ), - {"table": table}, - ) - ).scalars() - ) - triggers = int( - await connection.scalar( - text( - "select count(*) from pg_trigger where not tgisinternal and tgname in " - "('review_policy_mutation_custody'," - "'revision_policy_mutation_custody'," - "'policy_mutation_replay_custody')" - ) - ) - or 0 - ) - selector = bool( - await connection.scalar( - text( - "select exists(select 1 from pg_constraint where " - "conname='ck_project_guides_policy_selection_shape')" - ) - ) - ) - selector_definition = str( - await connection.scalar( - text( - "select pg_get_constraintdef(oid) from pg_constraint " - "where conname='ck_project_guides_policy_selection_shape'" - ) - ) - or "" - ) - selector_behavior = await _policy_selector_constraint_behavior( - connection, selector_definition - ) - custody_definition = str( - await connection.scalar( - text( - "select pg_get_functiondef(p.oid) from pg_proc p " - "where p.proname='validate_policy_mutation_custody'" - ) - ) - or "" - ) - return { - "ledger": "policy_mutation_idempotency_records" in tables, - "review_provenance": len(columns["review_policies"] & provenance), - "revision_provenance": len(columns["revision_policies"] & provenance), - "custody_triggers": triggers, - "selector_constraint": selector, - **selector_behavior, - "selector_custody": "selected_review_policy_id" in custody_definition - and "selected_revision_policy_id" in custody_definition, - "predecessor_custody": "prior.policy_generation=product_generation-1" - in custody_definition, - } - finally: - await engine.dispose() - - -async def _policy_selector_constraint_behavior( - connection: AsyncConnection, definition: str -) -> dict[str, bool]: - """Exercise the installed selector expression without product trigger noise.""" - await connection.execute( - text( - "create temporary table policy_selector_probe (" - "selected_review_policy_id text, selected_review_policy_generation integer, " - "selected_review_policy_hash text, selected_revision_policy_id text, " - "selected_revision_policy_generation integer, " - "selected_revision_policy_hash text, constraint selector_probe " - f"{definition}) on commit drop" - ) - ) - cases = { - "review_only_selector": ("review", 1, "sha256:" + "1" * 64, None, None, None), - "revision_only_selector": (None, None, None, "revision", 1, "sha256:" + "2" * 64), - "partial_review_selector": ("review", None, None, None, None, None), - "partial_revision_selector": (None, None, None, "revision", None, None), - } - accepted: dict[str, bool] = {} - for name, values in cases.items(): - savepoint = await connection.begin_nested() - try: - await connection.execute( - text( - "insert into policy_selector_probe values " - "(:r_id,:r_generation,:r_hash,:v_id,:v_generation,:v_hash)" - ), - dict( - zip( - ("r_id", "r_generation", "r_hash", "v_id", "v_generation", "v_hash"), - values, - strict=True, - ) - ), - ) - accepted[name] = True - except IntegrityError: - accepted[name] = False - finally: - await savepoint.rollback() - return accepted - - -async def _seed_xint003_02a_legacy_policies(database_url: str, ids: dict[str, str]) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - for table in ("projects", "project_guides"): - await connection.execute(text(f"alter table {table} disable trigger user")) - await connection.execute( - text( - "insert into projects (id,name,slug,status) values " - "(:project,'XINT 003 02A','xint-003-02a','draft')" - ), - ids, - ) - await connection.execute( - text( - "insert into project_guides " - "(id,project_id,version,status,content_markdown,created_by) values " - "(:guide,:project,'v1','draft','# Legacy guide','migration-test')" - ), - ids, - ) - for table in reversed(("projects", "project_guides")): - await connection.execute(text(f"alter table {table} enable trigger user")) - await connection.execute( - text( - "insert into review_policies " - "(id,project_id,guide_version,requires_second_review,allowed_decisions," - "minimum_finding_fields,sla_hours) values " - '(:review,:project,\'v1\',false,\'["accept","needs_revision",' - "\"reject\"]'::json,'[]'::json,24)" - ), - ids, - ) - await connection.execute( - text( - "insert into revision_policies " - "(id,project_id,guide_version,max_revision_rounds,revision_deadline_hours," - "auto_reject_after_limit,allowed_resubmission_states) values " - "(:revision,:project,'v1',3,48,false,'[\"needs_revision\"]'::json)" - ), - ids, - ) - finally: - await engine.dispose() - - -async def _xint003_02a_policy_state(database_url: str, ids: dict[str, str]) -> dict[str, tuple]: - engine = create_async_engine(database_url) - try: - async with engine.connect() as connection: - review = tuple( - ( - await connection.execute( - text( - "select id,policy_generation,semantics_status,policy_hash " - "from review_policies where id=:review" - ), - ids, - ) - ).one() - ) - revision = tuple( - ( - await connection.execute( - text( - "select id,policy_generation,semantics_status,policy_hash " - "from revision_policies where id=:revision" - ), - ids, - ) - ).one() - ) - guide = tuple( - ( - await connection.execute( - text( - "select selected_review_policy_id,selected_review_policy_generation," - "selected_review_policy_hash,selected_revision_policy_id," - "selected_revision_policy_generation,selected_revision_policy_hash " - "from project_guides where id=:guide" - ), - ids, - ) - ).one() - ) - return {"review": review, "revision": revision, "guide": guide} - finally: - await engine.dispose() - - -async def _xint003_02a_policy_immutable_writes(database_url: str, ids: dict[str, str]) -> set[str]: - engine = create_async_engine(database_url) - refused: set[str] = set() - try: - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(IntegrityError): - await connection.execute( - text( - "update project_guides set selected_review_policy_hash=null where id=:guide" - ), - ids, - ) - refused.add("partial_selection") - await transaction.rollback() - async with engine.begin() as connection: - await connection.execute( - text("alter table project_guides disable trigger guide_mutation_product_custody") - ) - await connection.execute( - text("alter table project_guides disable trigger guide_lineage_lifecycle_guard") - ) - await connection.execute( - text("update project_guides set status='active' where id=:guide"), ids - ) - await connection.execute( - text("alter table project_guides enable trigger guide_mutation_product_custody") - ) - await connection.execute( - text("alter table project_guides enable trigger guide_lineage_lifecycle_guard") - ) - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(DBAPIError): - await connection.execute( - text( - "update project_guides set selected_review_policy_hash=:hash " - "where id=:guide" - ), - ids | {"hash": "sha256:" + "f" * 64}, - ) - refused.add("active_selection_change") - await transaction.rollback() - statements = { - "review_update": ( - "update review_policies set requires_second_review=true where id=:review", - ids, - ), - "review_delete": ("delete from review_policies where id=:review", ids), - "review_truncate": ("truncate review_policies", {}), - "revision_update": ( - "update revision_policies set max_revision_rounds=4 where id=:revision", - ids, - ), - "revision_delete": ("delete from revision_policies where id=:revision", ids), - "revision_truncate": ("truncate revision_policies", {}), - } - for operation, (sql, params) in statements.items(): - async with engine.connect() as connection: - transaction = await connection.begin() - with pytest.raises(DBAPIError): - await connection.execute(text(sql), params) - refused.add(operation) - await transaction.rollback() - return refused - finally: - await engine.dispose() - - -async def _remove_xint003_02a_immutable_policies(database_url: str, ids: dict[str, str]) -> None: - engine = create_async_engine(database_url) - try: - async with engine.begin() as connection: - lineage_query = text( - "select exists(select 1 from information_schema.columns " - "where table_schema='public' and table_name='project_guides' " - "and column_name='selected_review_policy_id')" - ) - has_lineage = bool(await connection.scalar(lineage_query)) - for table in ( - "projects", - "project_guides", - "review_policies", - "revision_policies", - ): - await connection.execute(text(f"alter table {table} disable trigger user")) - if has_lineage: - await connection.execute( - text( - "update project_guides set status='draft',selected_review_policy_id=null,selected_review_policy_generation=null,selected_review_policy_hash=null," - "selected_revision_policy_id=null," - "selected_revision_policy_generation=null," - "selected_revision_policy_hash=null where id=:guide" - ), - ids, - ) - await connection.execute(text("delete from review_policies where id=:review"), ids) - await connection.execute(text("delete from revision_policies where id=:revision"), ids) - await connection.execute(text("delete from project_guides where id=:guide"), ids) - await connection.execute(text("delete from projects where id=:project"), ids) - for table in reversed( - ( - "projects", - "project_guides", - "review_policies", - "revision_policies", - ) - ): - await connection.execute(text(f"alter table {table} enable trigger user")) - finally: - await engine.dispose() + assert asyncio.run(read_next_values()) == (2, 2) diff --git a/backend/tests/test_artifact_admission.py b/backend/tests/test_artifact_admission.py index e8e69f493..6f6ea0b2e 100644 --- a/backend/tests/test_artifact_admission.py +++ b/backend/tests/test_artifact_admission.py @@ -12,7 +12,6 @@ from unittest.mock import AsyncMock from uuid import UUID, uuid4 -from alembic import command from alembic.config import Config import pytest from sqlalchemy import func, select, text @@ -3292,196 +3291,3 @@ async def test_invalid_checker_role_precedes_namespace_drift( assert await _count(session, ArtifactPutAttempt) == 0 finally: await engine.dispose() - - -@pytest.mark.postgres_schema_contract -def test_artifact_admission_migration_preserves_prior_rows_and_round_trips_empty( - isolated_database_env: str, - migration_lock, -) -> None: - config = _alembic_config() - namespace_fingerprint = "sha256:" + "a" * 64 - - async def seed_prior_namespace() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "insert into artifact_storage_namespaces " - "(id,backend,adapter,provider_profile,namespace_descriptor," - "namespace_fingerprint) values " - "('primary','local','local','local-v2','{}',:fingerprint)" - ), - {"fingerprint": namespace_fingerprint}, - ) - finally: - await engine.dispose() - - async def state() -> tuple[int, bool]: - engine = create_async_engine(isolated_database_env) - try: - async with engine.connect() as connection: - count = await connection.scalar( - text("select count(*) from artifact_storage_namespaces") - ) - table_exists = await connection.scalar( - text("select to_regclass('artifact_put_attempts') is not null") - ) - return int(count or 0), bool(table_exists) - finally: - await engine.dispose() - - async def cleanup() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute(text("truncate table artifact_storage_namespaces cascade")) - finally: - await engine.dispose() - - with migration_lock(): - try: - asyncio.run(_reset_admission_test_schema(isolated_database_env)) - command.upgrade(config, "0026_actor_profile_lifecycle") - asyncio.run(seed_prior_namespace()) - command.upgrade(config, "0028_artifact_admission") - assert list(asyncio.run(state())) == [1, True] - command.downgrade(config, "0026_actor_profile_lifecycle") - assert list(asyncio.run(state())) == [1, False] - command.upgrade(config, "0028_artifact_admission") - assert list(asyncio.run(state())) == [1, True] - asyncio.run(cleanup()) - finally: - asyncio.run(_reset_admission_test_schema(isolated_database_env)) - command.upgrade(config, "head") - - -@pytest.mark.postgres_schema_contract -def test_artifact_admission_migration_refuses_populated_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - config = _alembic_config() - - async def seed_attempt_only() -> None: - engine = create_async_engine(isolated_database_env) - try: - factory = async_sessionmaker(engine, expire_on_commit=False) - async with factory() as session: - context = _context() - await _seed_human_actor(session, context) - project_id, guide_id, snapshot_id, item_id = (str(uuid4()) for _ in range(4)) - await session.execute( - text( - "insert into projects (id,name,slug,status) values " - "(:id,'Admission migration',:slug,'draft')" - ), - {"id": project_id, "slug": f"admission-migration-{project_id}"}, - ) - await session.execute( - text( - "insert into project_guides " - "(id,project_id,version,status,content_markdown,created_by) values " - "(:id,:project_id,'v1','draft','# Guide','test')" - ), - {"id": guide_id, "project_id": project_id}, - ) - await session.execute( - text( - "insert into guide_source_snapshots " - "(id,project_id,guide_id,guide_version,manifest_schema_version," - "manifest_json,bundle_hash,captured_by) values " - "(:id,:project_id,:guide_id,'v1','v1',:manifest,:bundle_hash,:actor)" - ), - { - "id": snapshot_id, - "project_id": project_id, - "guide_id": guide_id, - "manifest": '{"items": []}', - "bundle_hash": canonical_json_hash({"items": []}), - "actor": str(context.actor_profile_id), - }, - ) - await session.execute( - text( - "insert into guide_source_snapshot_items " - "(id,source_snapshot_id,item_order,source_kind,durable_ref," - "ingestion_adapter,content_hash,media_type) values " - "(:id,:snapshot_id,0,'inline','guide.md','inline'," - ":content_hash,'text/markdown')" - ), - { - "id": item_id, - "snapshot_id": snapshot_id, - "content_hash": "sha256:" + "a" * 64, - }, - ) - namespace_fingerprint = "sha256:" + "c" * 64 - await session.execute( - text( - "insert into artifact_storage_namespaces " - "(id,backend,adapter,provider_profile,namespace_descriptor," - "namespace_fingerprint) values " - "('primary','local','local','local-v2','{}',:fingerprint)" - ), - {"fingerprint": namespace_fingerprint}, - ) - await session.execute( - text( - "insert into artifact_put_attempts " - "(id,producer_request_type,producer_type,producer_ref," - "project_id,guide_source_item_id,sha256,byte_count,media_type," - "storage_namespace_id,namespace_fingerprint,canonical_target," - "operation_identity,request_digest,status," - "execution_generation,cas_version,prepared_at) values " - "(:id,'guide','actor_profile',:producer_ref,:project_id," - ":item_id,:sha256,1,'text/markdown','primary',:fingerprint," - ":target,:operation_identity,:request_digest,'prepared'," - "0,0,now())" - ), - { - "id": str(uuid4()), - "producer_ref": str(context.actor_profile_id), - "project_id": project_id, - "item_id": item_id, - "sha256": "sha256:" + "b" * 64, - "fingerprint": namespace_fingerprint, - "target": "sha256/bb/" + "b" * 62, - "operation_identity": "sha256:" + "d" * 64, - "request_digest": "sha256:" + "e" * 64, - }, - ) - await session.commit() - finally: - await engine.dispose() - - async def cleanup() -> None: - engine = create_async_engine(isolated_database_env) - try: - async with engine.begin() as connection: - await connection.execute( - text( - "truncate table artifact_put_attempt_charges, " - "artifact_put_attempts, artifact_admission_charges, " - "artifact_admission_scopes cascade" - ) - ) - finally: - await engine.dispose() - - with migration_lock(): - try: - asyncio.run(_reset_admission_test_schema(isolated_database_env)) - command.upgrade(config, "0028_artifact_admission") - asyncio.run(seed_attempt_only()) - with pytest.raises( - RuntimeError, - match="cannot downgrade populated artifact admission ledger", - ): - command.downgrade(config, "0026_actor_profile_lifecycle") - asyncio.run(cleanup()) - command.downgrade(config, "0026_actor_profile_lifecycle") - finally: - asyncio.run(_reset_admission_test_schema(isolated_database_env)) - command.upgrade(config, "head") diff --git a/backend/tests/test_authorization.py b/backend/tests/test_authorization.py index a9e15113a..d3a27e91e 100644 --- a/backend/tests/test_authorization.py +++ b/backend/tests/test_authorization.py @@ -2667,10 +2667,6 @@ def test_obsolete_artifact_upload_authority_is_historical_only() -> None: ".agent-loop/initiatives/WS-XINT-001-lifecycle-boundary-reconciliation/AUTH_ART_HANDOFF.md" ) allowed = { - "backend/alembic/versions/0021_authorization_action_evidence.py", - "backend/alembic/versions/0022_bootstrap_admin_grants.py", - "backend/alembic/versions/0023_service_actor_identity.py", - "backend/alembic/versions/0036_art_auth_catalogue_reconciliation.py", ".agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-07A-closed-permission-action-catalogue.md", ".agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-09-actor-state-service-actors.md", ".agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-09A-service-identity-foundation.md", diff --git a/backend/tests/test_compensation.py b/backend/tests/test_compensation.py index 16352a5fd..9a77aab0d 100644 --- a/backend/tests/test_compensation.py +++ b/backend/tests/test_compensation.py @@ -5,16 +5,12 @@ import asyncio from collections.abc import Iterator from datetime import UTC, datetime -from pathlib import Path from uuid import uuid4 -from alembic import command -from alembic.config import Config from pydantic import ValidationError import pytest -from sqlalchemy import inspect, select, update +from sqlalchemy import select, update from sqlalchemy.exc import DBAPIError, IntegrityError -from sqlalchemy.ext.asyncio import create_async_engine from app.core.config import get_settings from app.db import session as db_session @@ -301,53 +297,3 @@ async def create(route_key: str) -> str: async with db_session.get_session_factory()() as session: rows = (await session.scalars(select(ProjectCompensationAdapterBinding))).all() assert len(rows) == 1 - - -@pytest.mark.postgres_schema_contract -def test_0053_binding_migration_round_trip( - compensation_database_env: str, -) -> None: - config = Config(str(Path(__file__).resolve().parents[1] / "alembic.ini")) - config.set_main_option( - "script_location", - str(Path(__file__).resolve().parents[1] / "alembic"), - ) - command.downgrade(config, "0052_legacy_intake_removal") - - async def table_names() -> set[str]: - engine = create_async_engine(compensation_database_env) - try: - async with engine.connect() as connection: - return set(await connection.run_sync(lambda sync: inspect(sync).get_table_names())) - finally: - await engine.dispose() - - async def binding_columns() -> set[str]: - engine = create_async_engine(compensation_database_env) - try: - async with engine.connect() as connection: - columns = await connection.run_sync( - lambda sync: inspect(sync).get_columns("project_compensation_adapter_bindings") - ) - return {column["name"] for column in columns} - finally: - await engine.dispose() - - assert "project_compensation_adapter_bindings" not in asyncio.run(table_names()) - command.upgrade(config, "0053_compensation_bindings") - assert "project_compensation_adapter_bindings" in asyncio.run(table_names()) - assert asyncio.run(binding_columns()) == { - "id", - "project_id", - "instrument_type", - "adapter_actor_id", - "route_key", - "status", - "binding_lifecycle_version", - "created_by", - "created_at", - "suspended_by", - "suspended_at", - "retired_by", - "retired_at", - } diff --git a/backend/tests/test_guide_bindings.py b/backend/tests/test_guide_bindings.py index c4c8fbecb..0020a0d2e 100644 --- a/backend/tests/test_guide_bindings.py +++ b/backend/tests/test_guide_bindings.py @@ -7,7 +7,6 @@ from dataclasses import replace from datetime import UTC, datetime import hashlib -import importlib.util from io import BytesIO from pathlib import Path from types import SimpleNamespace @@ -18,8 +17,6 @@ import pytest from PIL import Image from pypdf import PdfWriter -from alembic import command -from alembic.config import Config from sqlalchemy import func, select, text from sqlalchemy.exc import DBAPIError, IntegrityError, SQLAlchemyError from sqlalchemy.ext.asyncio import async_sessionmaker, create_async_engine @@ -111,42 +108,6 @@ from project_create_fixtures import seed_historical_project, suspend_historical_product_custody -@pytest.mark.parametrize( - ("revision_file", "expected_guard"), - [ - ( - "0039_guide_source_bindings.py", - "cannot downgrade populated guide source artifact bindings", - ), - ( - "0040_guide_materialization.py", - "cannot downgrade populated guide materialization evidence", - ), - ( - "0042_guide_extraction.py", - "cannot downgrade populated guide extraction evidence", - ), - ], -) -def test_superseded_guide_migration_populated_guards_remain_enforced( - monkeypatch: pytest.MonkeyPatch, - revision_file: str, - expected_guard: str, -) -> None: - """Keep each older guard covered even though 0049 now refuses first.""" - revision_path = Path(__file__).resolve().parents[1] / "alembic/versions" / revision_file - spec = importlib.util.spec_from_file_location(f"guard_{revision_file}", revision_path) - assert spec is not None and spec.loader is not None - revision = importlib.util.module_from_spec(spec) - spec.loader.exec_module(revision) - populated_result = SimpleNamespace(scalar_one=lambda: True) - bind = SimpleNamespace(execute=lambda _statement: populated_result) - monkeypatch.setattr(revision.op, "get_bind", lambda: bind) - - with pytest.raises(RuntimeError, match=expected_guard): - revision.downgrade() - - def test_sufficiency_material_limit_accepts_exact_boundary_and_rejects_one_over() -> None: base = GuideSourceMaterial( project_id="p", @@ -170,67 +131,6 @@ def test_sufficiency_material_limit_accepts_exact_boundary_and_rejects_one_over( assert exc_info.value.code == "guide_source_limit_exceeded" -@pytest.mark.asyncio -@pytest.mark.postgres_schema_contract -async def test_guide_sufficiency_provenance_migration_round_trip( - isolated_database_env: str, - migration_lock, -) -> None: - project_root = Path(__file__).resolve().parents[1] - config = Config(str(project_root / "alembic.ini")) - config.set_main_option("script_location", str(project_root / "alembic")) - with migration_lock(): - engine = None - try: - await asyncio.to_thread(command.downgrade, config, "0045_guide_metadata_authority") - engine = create_async_engine(isolated_database_env) - async with engine.connect() as connection: - absent = await connection.scalar( - text("select to_regclass('guide_sufficiency_report_source_usages')") - ) - assert absent is None - # Do not reuse a connection pool established against the downgraded - # schema when asserting the freshly upgraded constraint catalogue. - await engine.dispose() - await asyncio.to_thread(command.upgrade, config, "head") - engine = create_async_engine(isolated_database_env) - async with engine.connect() as connection: - present = await connection.scalar( - text("select to_regclass('guide_sufficiency_report_source_usages')") - ) - columns = set( - ( - await connection.execute( - text( - "select column_name from information_schema.columns " - "where table_name='guide_sufficiency_reports'" - ) - ) - ).scalars() - ) - assert present == "guide_sufficiency_report_source_usages" - assert { - "project_setup_run_id", - "setup_generation", - "agent_material_sha256", - "agent_material_byte_count", - }.issubset(columns) - async with engine.connect() as connection: - setup_columns = set( - ( - await connection.execute( - text( - "select column_name from information_schema.columns " - "where table_name='project_setup_runs'" - ) - ) - ).scalars() - ) - assert "error_artifact_incident_id" in setup_columns - finally: - await asyncio.to_thread(command.upgrade, config, "head") - if engine is not None: - await engine.dispose() @pytest.mark.asyncio @@ -1227,11 +1127,6 @@ async def test_extraction_publishes_deterministic_content_and_exact_usage( expected_output: str, expected_omissions: dict[str, bool], ) -> None: - config = Config(str(Path(__file__).resolve().parents[1] / "alembic.ini")) - config.set_main_option("script_location", str(Path(__file__).resolve().parents[1] / "alembic")) - with migration_lock(): - await asyncio.to_thread(command.downgrade, config, "0042_guide_extraction") - await asyncio.to_thread(command.upgrade, config, "head") digest = "sha256:" + hashlib.sha256(payload).hexdigest() engine = create_async_engine(isolated_database_env) factory = async_sessionmaker(engine, expire_on_commit=False) @@ -1301,20 +1196,6 @@ async def test_extraction_publishes_deterministic_content_and_exact_usage( ), {"usage_id": str(result.usage_id)}, ) - with ( - migration_lock(), - pytest.raises( - RuntimeError, - # The v2 clean-cut is the first downgrade boundary and must - # refuse this populated lineage before older evidence guards. - match="guide source v2 downgrade requires empty guide-source tables", - ), - ): - await asyncio.to_thread( - command.downgrade, - config, - "0041_project_mutation_evidence", - ) finally: if prepared is not None: await prepared.close() @@ -2436,27 +2317,6 @@ async def test_next_generation_explicitly_supersedes_prior_binding( await engine.dispose() -@pytest.mark.postgres_schema_contract -def test_0039_refuses_populated_binding_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - config = Config(str(Path(__file__).resolve().parents[1] / "alembic.ini")) - config.set_main_option( - "script_location", - str(Path(__file__).resolve().parents[1] / "alembic"), - ) - asyncio.run(_create_populated_binding(isolated_database_env)) - with ( - migration_lock(), - pytest.raises( - RuntimeError, - # The v2 clean-cut supersedes the older binding guard whenever - # authoritative guide-source lineage exists. - match="guide source v2 downgrade requires empty guide-source tables", - ), - ): - command.downgrade(config, "0038_guide_source_ingest") async def _create_populated_binding(database_url: str) -> None: @@ -2474,27 +2334,6 @@ async def _create_populated_binding(database_url: str) -> None: await engine.dispose() -@pytest.mark.postgres_schema_contract -def test_0040_refuses_populated_classification_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - config = Config(str(Path(__file__).resolve().parents[1] / "alembic.ini")) - config.set_main_option( - "script_location", - str(Path(__file__).resolve().parents[1] / "alembic"), - ) - asyncio.run(_create_populated_classification(isolated_database_env)) - with ( - migration_lock(), - pytest.raises( - RuntimeError, - # Classification evidence is anchored to populated v2 source - # lineage, so the outer clean-cut guard must fire first. - match="guide source v2 downgrade requires empty guide-source tables", - ), - ): - command.downgrade(config, "0039_guide_source_bindings") async def _create_populated_classification(database_url: str) -> None: @@ -2526,27 +2365,6 @@ async def _create_populated_classification(database_url: str) -> None: await engine.dispose() -@pytest.mark.postgres_schema_contract -def test_0040_refuses_incident_only_downgrade( - isolated_database_env: str, - migration_lock, -) -> None: - config = Config(str(Path(__file__).resolve().parents[1] / "alembic.ini")) - config.set_main_option( - "script_location", - str(Path(__file__).resolve().parents[1] / "alembic"), - ) - asyncio.run(_create_populated_incident(isolated_database_env)) - with ( - migration_lock(), - pytest.raises( - RuntimeError, - # Incident evidence is anchored to populated v2 source lineage, - # so the outer clean-cut guard must fire first. - match="guide source v2 downgrade requires empty guide-source tables", - ), - ): - command.downgrade(config, "0039_guide_source_bindings") async def _create_populated_incident(database_url: str) -> None: diff --git a/backend/tests/test_review_lease_persistence.py b/backend/tests/test_review_lease_persistence.py index 23c24b011..638ea60a0 100644 --- a/backend/tests/test_review_lease_persistence.py +++ b/backend/tests/test_review_lease_persistence.py @@ -5,11 +5,8 @@ import asyncio from collections.abc import AsyncIterator, Iterator from datetime import UTC, datetime, timedelta -from pathlib import Path from uuid import UUID, uuid4 -from alembic import command -from alembic.config import Config from httpx import ASGITransport, AsyncClient import pytest from sqlalchemy import text, update @@ -507,84 +504,3 @@ async def test_terminal_attempt_is_immutable_and_cannot_reopen( text("update review_leases set status='active' where id=:id"), {"id": value.id}, ) - - -@pytest.mark.postgres_schema_contract -@pytest.mark.asyncio -async def test_populated_lease_persistence_refuses_downgrade( - review_lease_client: AsyncClient, - monkeypatch: pytest.MonkeyPatch, - migration_lock, -) -> None: - _, queue, reviewer_id, version_id = await _seed_queue_and_policy( - review_lease_client, monkeypatch - ) - value = _lease_input(queue, reviewer_id, version_id) - async with db_session.get_session_factory()() as session: - await ReviewQueueRepository(session).add_lease(value) - await session.execute( - update(ReviewQueueEntry) - .where(ReviewQueueEntry.id == queue.id) - .values(queue_state="leased", active_lease_id=value.id, lifecycle_generation=2) - ) - await session.commit() - starting_revision = await session.scalar(text("select version_num from alembic_version")) - await db_session.dispose_engine() - - backend_root = Path(__file__).resolve().parents[1] - config = Config(str(backend_root / "alembic.ini")) - config.set_main_option("script_location", str(backend_root / "alembic")) - - def downgrade() -> None: - with migration_lock(): - command.downgrade(config, "0055_contribution_policy") - - # The newest irreversible authority boundary must stop the multi-revision - # downgrade before Alembic reaches the older review-lease guard. - with pytest.raises( - RuntimeError, match="cannot downgrade submission-policy authority with evidence" - ): - await asyncio.to_thread(downgrade) - - async with db_session.get_session_factory()() as session: - assert ( - await session.scalar(text("select version_num from alembic_version")) - == starting_revision - ) - assert await session.get(ReviewLease, value.id) is not None - - -@pytest.mark.postgres_schema_contract -@pytest.mark.asyncio -async def test_newer_submission_policy_authority_precedes_preference_downgrade( - review_lease_client: AsyncClient, - monkeypatch: pytest.MonkeyPatch, - migration_lock, -) -> None: - _, queue, _, _ = await _seed_queue_and_policy(review_lease_client, monkeypatch) - async with db_session.get_session_factory()() as session: - service_id = await _service_actor(session) - await session.commit() - starting_revision = await session.scalar(text("select version_num from alembic_version")) - await db_session.dispose_engine() - - backend_root = Path(__file__).resolve().parents[1] - config = Config(str(backend_root / "alembic.ini")) - config.set_main_option("script_location", str(backend_root / "alembic")) - - def downgrade() -> None: - with migration_lock(): - command.downgrade(config, "0055_contribution_policy") - - with pytest.raises( - RuntimeError, match="cannot downgrade submission-policy authority with evidence" - ): - await asyncio.to_thread(downgrade) - - async with db_session.get_session_factory()() as session: - assert ( - await session.scalar(text("select version_num from alembic_version")) - == starting_revision - ) - assert await session.get(ActorProfile, service_id) is not None - assert await session.get(ReviewQueueEntry, queue.id) is not None diff --git a/backend/tests/test_review_queue_persistence.py b/backend/tests/test_review_queue_persistence.py index 54acfeb7d..30fba5a26 100644 --- a/backend/tests/test_review_queue_persistence.py +++ b/backend/tests/test_review_queue_persistence.py @@ -2,14 +2,10 @@ from __future__ import annotations -import asyncio from collections.abc import AsyncIterator, Iterator from datetime import UTC, datetime, timedelta -from pathlib import Path from uuid import uuid4 -from alembic import command -from alembic.config import Config from httpx import ASGITransport, AsyncClient import pytest from sqlalchemy import select, text @@ -555,86 +551,3 @@ async def test_preferred_shape_is_storage_only_and_lease_shape_is_impossible( {"id": preferred.id}, ) await session.rollback() - - -@pytest.mark.postgres_schema_contract -@pytest.mark.asyncio -async def test_later_authority_preserves_populated_review_admission_on_downgrade( - review_client: AsyncClient, - monkeypatch: pytest.MonkeyPatch, - migration_lock, -) -> None: - project, task, submission = await _reviewable_lineage(review_client, monkeypatch) - reservation_value = _reservation_input(project, task, submission) - async with db_session.get_session_factory()() as session: - await ReviewQueueRepository(session).reserve_admission(reservation_value) - await session.commit() - initial_revision = await session.scalar(text("select version_num from alembic_version")) - await db_session.dispose_engine() - - backend_root = Path(__file__).resolve().parents[1] - config = Config(str(backend_root / "alembic.ini")) - config.set_main_option("script_location", str(backend_root / "alembic")) - - def downgrade() -> None: - with migration_lock(): - command.downgrade(config, "0050_guide_source_v2") - - # Downgrades are newest-first; submission-policy evidence is the first - # irreversible boundary and must preserve the older review admission too. - with pytest.raises( - RuntimeError, match="cannot downgrade submission-policy authority with evidence" - ): - await asyncio.to_thread(downgrade) - - async with db_session.get_session_factory()() as session: - assert ( - await session.scalar(text("select version_num from alembic_version")) - == initial_revision - ) - assert ( - await session.scalar( - select(ReviewAdmissionIdempotencyRecord.id).where( - ReviewAdmissionIdempotencyRecord.id == reservation_value.id - ) - ) - == reservation_value.id - ) - - -@pytest.mark.postgres_schema_contract -@pytest.mark.asyncio -async def test_later_authority_preserves_populated_review_queue_on_downgrade( - review_client: AsyncClient, - monkeypatch: pytest.MonkeyPatch, - migration_lock, -) -> None: - project, task, submission = await _reviewable_lineage(review_client, monkeypatch) - queue_value = _queue_input(project, task, submission) - async with db_session.get_session_factory()() as session: - await ReviewQueueRepository(session).add_queue_entry(queue_value) - await session.commit() - initial_revision = await session.scalar(text("select version_num from alembic_version")) - await db_session.dispose_engine() - - backend_root = Path(__file__).resolve().parents[1] - config = Config(str(backend_root / "alembic.ini")) - config.set_main_option("script_location", str(backend_root / "alembic")) - - def downgrade() -> None: - with migration_lock(): - command.downgrade(config, "0050_guide_source_v2") - - # Downgrades are newest-first; submission-policy evidence is the first - # irreversible boundary and must preserve the older queue entry too. - with pytest.raises( - RuntimeError, match="cannot downgrade submission-policy authority with evidence" - ): - await asyncio.to_thread(downgrade) - - async with db_session.get_session_factory()() as session: - assert ( - await session.scalar(text("select version_num from alembic_version")) - == initial_revision - ) - assert await session.get(ReviewQueueEntry, queue_value.id) is not None diff --git a/backend/tests/test_tasks.py b/backend/tests/test_tasks.py index 30f73f7e5..9e4b7f5aa 100644 --- a/backend/tests/test_tasks.py +++ b/backend/tests/test_tasks.py @@ -14,7 +14,6 @@ from uuid import UUID, uuid4 import pytest # type: ignore[import-not-found] -from alembic import command # type: ignore[attr-defined] from alembic.config import Config from httpx import ASGITransport, AsyncClient from sqlalchemy import func, inspect, select, text, update @@ -2424,33 +2423,6 @@ async def test_chunk4_migration_creates_expected_tables(task_database_env: str) }.issubset(table_names) -@pytest.mark.postgres_schema_contract -def test_chunk4_migration_downgrade_removes_task_tables(task_database_env: str) -> None: - config = alembic_config() - asyncio.run(db_session.dispose_engine()) - command.downgrade(config, "0002_project_guide_foundation") - - async def inspect_tables() -> set[str]: - async with db_session.get_engine().connect() as connection: - return await connection.run_sync( - lambda sync_connection: set(inspect(sync_connection).get_table_names()) - ) - - table_names = asyncio.run(inspect_tables()) - - assert "projects" in table_names - assert { - "actor_identities", - "actor_profiles", - "workstream_tasks", - "task_assignments", - "submissions", - "evidence_items", - "audit_events", - }.isdisjoint(table_names) - - asyncio.run(db_session.dispose_engine()) - command.upgrade(config, "head") def test_task_assignment_partial_unique_index_metadata_compiles() -> None: diff --git a/docs/architecture_data_model.md b/docs/architecture_data_model.md index edada8523..71e5aaa36 100644 --- a/docs/architecture_data_model.md +++ b/docs/architecture_data_model.md @@ -81,7 +81,7 @@ Fields include: - permitted display/profile metadata - database-time creation/update fields - bounded suspension and reactivation attribution plus immutable terminal - deactivation attribution after AUTH-09D-A migration `0026` + deactivation attribution in the v0.1 baseline Profile status is a guard, not a role or project grant. Lifecycle invalidation effectiveness is component-scoped. Reactivating a @@ -93,7 +93,7 @@ make the whole actor effective. An identity link binds one canonical external issuer and opaque subject to one ActorProfile. It has active/revoked state plus state-transition-guarded current -revocation and reactivation attribution. AUTH-09D-A migration `0026` enforces +revocation and reactivation attribution. The v0.1 baseline enforces complete attribution and bounded lifecycle reasons. AUTH-09D-B activates exact link revoke/reactivate mutations. Append-only audit evidence preserves immutable transition history; the current row carries only the latest state-compatible attribution. @@ -1004,26 +1004,19 @@ Example: Post-submit checker policy governs durable internal checker runs after a submission is finalized. It does not replace the generated project pre-submit checker policy. -Migration note: the `0008_post_submit_checker_policy` migration adds explicit -post-submit policy hash, body, and lock columns. Existing local v0.1 checker -policy rows without policy hashes are intentionally not backfilled into -authority. They must be recreated or repaired through the project setup -lifecycle. Existing non-draft task, submission, or checker-run rows from the -construction database block the migration with an explicit preflight error -because Workstream cannot truthfully infer which post-submit policy body and -hash governed those runtime records. After the migration, runtime records fail +Baseline invariant: post-submit policy hash, body, and lock columns are +explicit. Pre-v0.1 development rows without policy hashes are not backfilled +into authority; recreate the database and use the project setup lifecycle. +Runtime records fail closed when a task, submission, or checker run lacks valid `locked_post_submit_checker_policy_*` context. -Migration note: the `0014_post_submit_setup` migration adds required -post-submit policy provenance fields that bind a compiled policy to guide, -source snapshot, effective project policy, and pre-submit checker bundle -context. Existing construction-era `checker_policies` rows cannot be truthfully -backfilled into that provenance, so the migration fails closed until those local -draft-era rows are reset and recreated through project setup. +Baseline invariant: required post-submit policy provenance binds a compiled +policy to guide, source snapshot, effective project policy, and pre-submit +checker bundle context. Construction-era rows are not an upgrade source. -Migration note: the `0015_post_submit_correction` migration replaces the -single-row project/guide-version uniqueness rule with uniqueness for current +Baseline invariant: the single-row project/guide-version uniqueness rule is +replaced by uniqueness for current `compiled` or `approved` rows. Superseded rows remain append-only and retain their policy body/hash, supersession kind/reason, actor/role/time provenance, and any same-context correction replacement link. Correction lookup is scoped @@ -1312,7 +1305,7 @@ Fields: - `released_at` - `status` -Migration `0027_contributor_foundation` clean-cuts the retired persisted human +The v0.1 baseline excludes the retired persisted human owner to `contributor_id`. The non-null `varchar(36)` value is protected by foreign key `fk_task_assignments_contributor_id_actor_profiles`, index `ix_task_assignments_contributor_id`, and trigger diff --git a/docs/operations_artifact_storage.md b/docs/operations_artifact_storage.md index f5ab8085d..c719bde33 100644 --- a/docs/operations_artifact_storage.md +++ b/docs/operations_artifact_storage.md @@ -72,10 +72,9 @@ expected, confirm that its parent scopes have capacity, and compare the configured limit with the persisted scope limit. Do not delete admission charges or edit counters in PostgreSQL. -Migration `0061_submission_admission` installs immutable ready-admission -custody. Downgrade is intentionally refused once admission rows exist; rollback -planning must preserve those facts and move forward with a corrective migration -rather than deleting or bypassing them. +The v0.1 baseline installs immutable ready-admission custody. Recovery planning +must preserve those facts and move forward with a corrective migration rather +than deleting or bypassing them; the baseline cannot be downgraded. ## Quota expansion and rollback @@ -98,15 +97,10 @@ These routes do not delete, retain, release, or mutate provider objects; change admission configuration; activate AWS; or cut over any guide, task, submission, checker, review, contribution, payment, or reputation lifecycle. -## Legacy contributor-intake migration +## Contributor-intake baseline invariant -Migration `0051_legacy_intake_removal` is a safe-empty cut. Before deploying, -confirm that the legacy upload-session/item tables contain no rows and that no -put attempt or operation receipt carries contributor/upload-item lineage or a -version-1 receipt contract. The migration takes exclusive locks and refuses -before changing schema when any such evidence exists. - -Do not delete, detach, or rewrite those rows to force deployment. Preserve the -database at revision `0050_guide_source_v2` and escalate for a separately -approved maintenance and audit migration. A refusal is an expected evidence- -preservation outcome, not permission to bypass the preflight. +The v0.1 baseline contains only the current contributor-intake schema. The +retired upload-session/item shape and version-1 receipt contract are not an +upgrade source. Recreate pre-v0.1 development databases; for production data, +use a separately reviewed evidence-preserving maintenance migration rather +than deleting, detaching, rewriting, or restamping rows. diff --git a/docs/operations_authorization_service.md b/docs/operations_authorization_service.md index 4b8d61652..f0e4ef3cc 100644 --- a/docs/operations_authorization_service.md +++ b/docs/operations_authorization_service.md @@ -17,11 +17,11 @@ owning implementation chunks. | JWKS endpoint, cache, and rotation | Platform security/on-call | Rotation drill, cache bounds, outage behavior, alerts. | | Introspection/revocation policy | Platform security | Approved mode, endpoint trust policy, timeout/failure proof. | | First Access Administrator bootstrap | Restricted deployment operator | Dry-run, target verification, one-time result, authority event. | -| Legacy actor classification | Data migration owner plus security reviewer | Versioned manifest, live-row digest, checksum, dry-run report. | +| Pre-v0.1 production remediation | Data owner plus security reviewer | Separately approved forward migration and evidence-preservation proof. | | Actor/grant administration | Access Administrator | Supported API/command, reason, idempotency, evidence. | | Project contributor grants | Covered Project Manager | Exact-project target and privacy-bounded candidate lookup. | | Recovery operations | Operator or covered Project Manager as specified | Matched permission, reason, resource scope, immutable evidence. | -| Rollout and rollback | Release owner | Migration round trip, compatibility inventory, rollback stop conditions. | +| Rollout and recovery | Release owner | Fresh-baseline proof, compatibility inventory, and forward-recovery stop conditions. | | Live authorization proof | Release owner plus security/QA | API-visible drill with redacted committed evidence. | ## Required Configuration @@ -197,48 +197,15 @@ unavailable until merged feature behavior exists and the dedicated AUTH activation custodian integrates its evaluator and changes only that action's availability. -### Existing Service Identity Mapping Custody +### Existing Service Identity Custody -This procedure applies only when service ActorProfiles already exist before -migration `0023`. The data-migration owner prepares a private draft containing -the exact existing ActorProfile ID, issuer, opaque subject, and proposed fixed -service identity for every row. A security reviewer verifies each choice from -authoritative ownership records. Neither the tool nor an operator may infer a -value from subject syntax, email, display name, token role, or adapter -provenance. - -Run the supported tool against the exact target database. Draft and envelope -files must be regular, non-symlink, owner-only mode `0600` files in a controlled -directory outside the checkout, every linked worktree, and shared Git metadata. -Zero existing service rows require no file; otherwise the envelope must cover -the complete locked service projection and select unique values from the seven -closed identities. - -```bash -chmod 600 /secure/workstream/service-identity-draft-v1.json -.venv/bin/python scripts/service_actor_identity_mapping.py validate \ - --draft /secure/workstream/service-identity-draft-v1.json -.venv/bin/python scripts/service_actor_identity_mapping.py bind \ - --draft /secure/workstream/service-identity-draft-v1.json \ - --output /secure/workstream/service-identity-envelope-v1.json -chmod 600 /secure/workstream/service-identity-envelope-v1.json -.venv/bin/python scripts/service_actor_identity_mapping.py verify \ - --envelope /secure/workstream/service-identity-envelope-v1.json -``` - -`validate` and `verify` never modify PostgreSQL. `bind` refuses an existing -output path. The tool prints only stable codes, bounded counts, and non-secret -digests. Inject `WORKSTREAM_SERVICE_ACTOR_IDENTITY_MAPPING_FILE` only into the -migration process immediately before `alembic upgrade head`; never commit or -log the path or confidential contents. - -Migration `0023` consumes the packaged versioned contract, locks the complete -actor/link source projection, and refuses missing, extra, stale, duplicate, or -ambiguous mappings atomically. It retains only bounded counts and non-secret -source, manifest, envelope, and database-binding digests. After database -verification and the approved rollback window, securely delete the draft and -envelope. If any row cannot truthfully map, remain on `0022` and open a reviewed -data-remediation decision; never guess, delete history, or use manual SQL. +The v0.1 baseline and runtime fixed-service registry are the only current +service-identity installation paths. The former pre-v0.1 mapping utility and +revision-specific mapping procedure are historical and have been removed. +Existing development databases are not upgraded or mapped forward: recreate +the database and install `0001_v01_baseline`. Operators must never infer a +service identity from subject syntax, email, display name, token role, or +adapter provenance. The [approved AUTH-06 chunk contract](../.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-06-canonical-actor-profile.md) records the exact deprecated compatibility identifier. That temporary, @@ -249,25 +216,19 @@ intake. Operator start override does not use the bridge. AUTH-13 removes the claim and start consumers; AUTH-14 removes the final submission consumer, compatibility route, and adapter. -## Contributor Attribution Migration And Runtime Guard +## Contributor Attribution Runtime Guard -Migration `0027_contributor_foundation` clean-cuts the retired assignment and -submission human-owner columns to `contributor_id`. Before any DDL, it locks -`actor_profiles`, `task_assignments`, and `submissions` and independently -classifies every old value as malformed UUID, missing ActorProfile, or service -ActorProfile. Failure reports only bounded row/profile ID pairs and counts. It -redacts malformed source values completely while retaining safe row IDs and -well-formed missing/service profile IDs. It does not inspect issuer, subject, -email, token claims, current assignment, or another table to infer a -replacement. +The v0.1 baseline uses canonical `contributor_id` attribution. It does not +inspect issuer, subject, email, token claims, current assignment, or another +table to infer a replacement for invalid attribution. Remediate a refusal only from authoritative canonical-actor evidence. Create or repair the canonical human ActorProfile through its owning reviewed process, or correct a demonstrably wrong attribution through a separately reviewed data repair. Do not map by email or display name, select a latest profile, convert a service identity, fabricate an ActorProfile, or edit immutable audit history. -Rerun from exact head `0026_actor_profile_lifecycle` and retain the bounded -preflight result with the deployment evidence. +Pre-v0.1 transition preflights are historical only. Current deployments install +the canonical contributor shape from `0001_v01_baseline`. The reusable primitive is `public.require_human_actor_profile_reference()`. Exact triggers @@ -278,12 +239,10 @@ human lineage. Exact foreign keys indexes `ix_task_assignments_contributor_id` and `ix_submissions_contributor_id` preserve lookup behavior. -After upgrade, both columns are non-null `varchar(36)` foreign keys. PostgreSQL +Both columns are non-null `varchar(36)` foreign keys. PostgreSQL rejects a missing profile with SQLSTATE `23503` and a service profile with `23514`. Suspended and deactivated human profiles remain valid historical -references. Downgrade first locks the same tables and refuses before DDL when -any non-owned dependency uses the shared lineage function; remove or migrate -that dependent schema through its owning release before retrying. +references. The v0.1 baseline has no downgrade path. Claim and submission also revalidate current identity inside their mutation transaction in lock order ActorProfile, exact issuer/subject identity link, @@ -317,11 +276,9 @@ an authentication or pagination-cursor key. Missing key or database access returns the same retryable 503 when a later route attaches the dependency. Exhaustion returns 429 with `Retry-After`. -Before upgrading to `0033_authorization_read_rate`, confirm migration -`0032_artifact_recovery` is current and that no unreviewed constraint changes -exist. This migration requires PostgreSQL major version 16, matching the -CI-pinned database used to freeze the exact `pg_get_expr` rendering. Confirm -the target before either direction: +The current authorization-read constraint requires PostgreSQL major version +16, matching the CI-pinned database used to freeze the exact `pg_get_expr` +rendering. Confirm the target before deployment: ```sql SELECT current_setting('server_version_num')::integer / 10000 @@ -330,7 +287,7 @@ SELECT current_setting('server_version_num')::integer / 10000 Stop if the result is not `16`; validate a different major version through a reviewed forward migration change rather than bypassing the drift check. -Inspect the exact database-owned expression before either direction: +Inspect the exact current database-owned expression: ```sql SELECT pg_get_expr(conbin, conrelid) AS scope_constraint @@ -339,24 +296,14 @@ WHERE conrelid = 'api_rate_control_counters'::regclass AND conname = 'ck_api_rate_control_counters_scope_token'; ``` -Before upgrade, the returned scope set must be exactly `first_access` and -`admin_mutation`. Before downgrade, it must be exactly `first_access`, -`admin_mutation`, and `authorization_read`. PostgreSQL may render these as an +The returned scope set must be exactly `first_access`, `admin_mutation`, and +`authorization_read`. PostgreSQL may render these as an `ANY (ARRAY[...])` expression with text casts; compare the complete expression -and values, not a substring. Upgrade takes an access-exclusive lock on -`api_rate_control_counters`, replaces only its closed scope constraint, and -preserves every existing counter. The dependency remains deliberately -unattached after this migration. +and values, not a substring. -If either direction reports `unexpected API rate-control scope constraint`, it -leaves the Alembic revision, constraint, and counter rows unchanged. Do not -drop, bypass, or force the constraint. Compare the live definition with the -reviewed migrations that actually ran, reconcile it to the canonical expected -definition through a reviewed forward repair, and then retry the migration. -Prefer forward recovery when the provenance of the drift is uncertain. - -Downgrade also takes the table lock before preflight and refuses while any live -or expired `authorization_read` row exists: +If validation reports `unexpected API rate-control scope constraint`, do not +drop, bypass, or force the constraint. Reconcile it to the canonical expected +definition through a reviewed forward repair. Diagnose current rows with: ```sql SELECT count(*) AS authorization_read_rows @@ -364,11 +311,7 @@ FROM api_rate_control_counters WHERE control_scope = 'authorization_read'; ``` -Do not delete an unexpired row merely to force rollback. Prefer forward -recovery. If rollback is required before AUTH-10B2 attaches the dependency, -verify the count is zero, quiesce deployments that could run the new scope, -then downgrade. After 10B2, wait for the largest configured window to expire, -quiesce every reader, delete only expired rows using PostgreSQL time, and retry. +Do not delete an unexpired row. Recover forward. Generate the secret outside the repository and store it in the deployment secret manager: @@ -400,10 +343,7 @@ WHERE window_expires_at <= statement_timestamp(); Runtime consumption opportunistically deletes at most 100 expired other rows. On idle systems, operators may run the same expired-only SQL cleanup. Never -delete active rows to recover capacity, and never downgrade migration `0017` -while the table is nonempty; the guarded downgrade takes an exclusive table -lock, refuses, and rolls back. Quiesce every protected write before attempting -the downgrade so waiting writers cannot resume against a removed table. +delete active rows to recover capacity. The v0.1 baseline is not downgradable. ## JWKS Rotation And Outage @@ -487,172 +427,16 @@ fabricated human/system role. ## Legacy Actor Classification -Non-empty legacy registries require the supported classification tool and a -versioned JSON manifest. Each entry binds the exact legacy actor ID, issuer, -opaque subject, and subject kind. - -Platform security owns the manifest and envelope. Both files contain -confidential identity-linking evidence even though the command report is -redacted. Store them in an environment-specific owner-only directory outside -the repository, every linked worktree, and the Git common directory. Do not -attach either file to tickets, CI logs, PRs, or engineering-loop evidence. - -Manifest schema version 1 has exactly this shape: - -```json -{ - "schema_version": 1, - "classifications": [ - { - "actor_id": "00000000-0000-5000-8000-000000000000", - "issuer": "https://issuer.example.invalid", - "subject": "opaque-subject-from-the-legacy-row", - "subject_kind": "human" - } - ] -} -``` - -`subject_kind` is only `human` or `service`. The actor ID must be the canonical -UUIDv5 derived by the existing registry from the byte-exact HTTPS issuer and -case-sensitive opaque subject. Operators must classify from authoritative -issuer records; email, subject syntax, token roles, profile rows, and manual SQL -are not classification evidence. - -The tool must: - -- support dry-run; -- reject unknown fields/kinds, duplicates, missing rows, extra rows, stale - rows, mismatched issuer/subject, invalid UUIDs, and ambiguous classification; -- compute a complete live-row digest and manifest checksum; -- bind evidence to a non-secret database/environment identifier; -- write no grants; -- emit a bounded remediation report. - -Prepare a restricted directory and validate without writing an envelope: - -```bash -cd backend -WORKSTREAM_DATABASE_URL='' \ - .venv/bin/python scripts/legacy_actor_classification.py \ - --manifest /secure/workstream/prod/legacy-actor-manifest-v1.json -``` - -Dry-run is the default. An empty registry needs no manifest and returns an -explicit empty proof. A non-empty registry without a manifest fails closed. The -JSON report contains only row count, mode, empty status, checksums, and the -non-secret database binding; stderr uses stable error codes and does not render -identity values, paths, database names, or connection URLs. - -After the dry-run report is reviewed, export one write-once envelope: - -```bash -cd backend -WORKSTREAM_DATABASE_URL='' \ - .venv/bin/python scripts/legacy_actor_classification.py \ - --manifest /secure/workstream/prod/legacy-actor-manifest-v1.json \ - --output /secure/workstream/prod/legacy-actor-classification-v1.json \ - --generated-at 2026-07-13T12:30:00Z -``` - -`--generated-at` is an explicit UTC RFC3339 second so the same reviewed inputs -produce byte-identical evidence. Export writes mode `0600` through a -crash-safe, atomic no-overwrite publish. Repeating the exact command is -idempotent only when the existing regular file has identical bytes and private -permissions. A different existing file, symlink, relative path, repository -path, or Git-directory path fails closed. - -The envelope contains schema version, sorted classifications, live source-row -digest, canonical manifest digest, generated-at, database binding, and a digest -over the complete envelope. The binding hashes PostgreSQL database name and -database OID. It is a non-secret same-cluster wrong-database guard, not a -globally unique deployment identity. A clone, restore, or database recreation -requires a fresh dry run and envelope even when the human environment label is -unchanged. +The former AUTH-06 classification migration and private envelope workflow are +historical and must not be run against v0.1. Recreate development databases +from the baseline; production remediation requires a separately reviewed +forward migration. -The canonical actor-schema migration locates this envelope only through: - -```bash -export WORKSTREAM_LEGACY_ACTOR_CLASSIFICATION_FILE=/secure/workstream/prod/legacy-actor-classification-v1.json -``` - -Set the variable only on the reviewed AUTH-06 migration runner. The migration -loads the strict envelope, recomputes the complete live row-set digest and -database binding inside its transaction, and aborts on checksum, TOCTOU, -missing/extra row, identity, or binding mismatch. The envelope never creates -grants and is not a supported ad hoc migration path. - -On validation failure, correct the authoritative manifest or target database, -rerun dry-run, and export to a new secure path when the evidence bytes change. -Never edit an envelope or bypass the failure with SQL. - -Deploy AUTH-06 only in a quiesced maintenance window after the dry-run report -and envelope have been reviewed: - -1. Drain in-flight API requests and jobs. -2. Stop every old-version API replica and asynchronous writer. -3. Run the migration from the reviewed AUTH-06 release artifact. -4. Start only replicas and jobs containing the matching AUTH-06 code. -5. Complete the checks below before resuming traffic. - -```bash -cd backend -export WORKSTREAM_LEGACY_ACTOR_CLASSIFICATION_FILE=/secure/workstream/prod/legacy-actor-classification-v1.json -.venv/bin/alembic upgrade 0020_canonical_actor_profile -``` - -Verify one durable migration-state row before serving traffic. Record only the -schema version, classified count, and checksums; do not export identity rows: - -```sql -select schema_version, classified_count, source_row_set_sha256, - manifest_sha256, envelope_sha256, migrated_at -from actor_profile_migration_state where id = 1; - -select - (select count(*) from actor_profiles) as profile_count, - (select count(*) from actor_identity_links) as identity_link_count, - not exists ( - select 1 from actor_profiles p - full join actor_identity_links l on l.actor_profile_id = p.id - where p.id is null or l.id is null - ) as exact_one_link_per_profile, - to_regclass('public.admin_role_grants') is null as no_admin_grant_table, - to_regclass('public.project_role_grants') is null as no_project_grant_table; -``` - -Confirm every canonical profile has exactly one identity link, the classified -count matches the reviewed report, and no grants were created by the migration. -Retain the manifest and envelope only through verification and the approved -rollback window. Then delete both identity-bearing files from operator storage -and retain only the bounded report and durable checksum record. - -Rollback to `0019_authority_idempotency` uses the same quiescence sequence: drain -requests and jobs, stop all AUTH-06 writers, run the downgrade, deploy only the -matching pre-AUTH-06 code, verify, and then resume traffic. The downgrade is -envelope-independent because its required state is in PostgreSQL. It refuses -while any profile is suspended or any identity link is revoked; those states -may be repaired only through their reviewed lifecycle operations, never direct -SQL. Deactivation is terminal: if any actor is deactivated, downgrade is -unavailable and operators must recover forward on AUTH-06. A non-empty registry -restored to 0019 cannot be upgraded again from deleted evidence: run the -classification tool against the exact restored rows and obtain a newly reviewed -envelope. The migration never guesses a subject kind or bypasses this -fresh-evidence requirement. - -Run the exact rollback only after those checks pass: - -```bash -cd backend -.venv/bin/alembic downgrade 0019_authority_idempotency -``` - -Rollback restores every canonical identity to legacy identity storage and -copies the current canonical `display_name` and `contact_email`, including -`null`, into the restored row. This prevents a cleared canonical contact email -from being resurrected by pre-AUTH-06 code. Because canonical migration does -not import legacy display fields, rollback intentionally scrubs retained legacy -display data unless it was set through `PATCH /api/v1/actors/me` after AUTH-06. +Rollback across the removed pre-v0.1 revision graph is unsupported. Production +recovery must move forward through a reviewed corrective migration that +preserves actor and authorization evidence. Non-production databases may be +recreated from `0001_v01_baseline`. Never rewrite the Alembic stamp, delete +authority evidence, or restore the retired identity-storage shape. ## Staged Rollout @@ -661,7 +445,7 @@ For each chunk: 1. Confirm allowed files and stop conditions. 2. Run focused tests plus the full backend suite/API drill required by the contract. -3. Run migration upgrade, downgrade-one, and re-upgrade where applicable. +3. Run the current migration's forward and refusal tests where applicable. 4. Confirm the obsolete-path allowlist only shrinks and no compatibility path was added or restored. 5. Run required internal reviewers and repair valid findings. @@ -694,12 +478,8 @@ availability. The REV owner cardinalities are `2/5/3/1/1/5/2` for authority; all 23 REV actions remain planned and unavailable. WS-XINT-003-02C registers the four additional actions and six closed service identities but adds no evaluator, route, job, principal row, or lifecycle behavior. -Migration `0049_rev_auth_readiness` takes protected locks on authority -idempotency evidence, audit evidence, and actor profiles before replacing the -closed constraints. It seeds no ActorProfile, identity link, grant, route, or -job. Downgrade refuses after any new action has direct or idempotency-linked -audit evidence, or while any new REV service identity is in use; otherwise it -restores the exact `0048` constraints. +The v0.1 baseline seeds no ActorProfile, identity link, grant, route, or job for +REV readiness. Its closed catalogue constraints are installed directly. Their owning feature must publish the approved principal/resource/guard/surface/ transaction contract before activation, but those foreign facts do not become free-form catalogue fields. Startup validation failure is a release @@ -709,8 +489,8 @@ PR #139 historically required availability-neutral transfer of 25 ART and 19 REV owner rows before feature activation. Both transfers completed; WS-XINT-002-01 then reconciles the live ART set to 22 planned rows by deleting six obsolete upload actions and adding three bundle/review actions. The ART -transfer adds no migration; the later WS-XINT-002-01 catalogue -reconciliation uses migration `0036`. +transfer and later WS-XINT-002-01 catalogue reconciliation are included in the +v0.1 baseline. The REV transfer adds no migration. The ART transfer does not grant Operator authority; its `OPERATOR` suffix denotes only future activation custody, and verification retry remains independently gated from read/status actions. @@ -722,7 +502,7 @@ route mapping is in `docs/spec_authorization_service.md`. WS-XINT-002-04A activates Project Manager guide-source ingest, and WS-XINT-002-04B activates only the fixed-service guide binding and read actions. The other 16 ART actions remain planned, including every Operator artifact action. -Migration `0037` keeps each allowed or denied internal ART decision bound to +The v0.1 schema keeps each allowed or denied internal ART decision bound to the exact privacy-bounded resource-context digest in append-only audit facts. AUTH-11A adds read-only `project.setup_diagnostic.read` and @@ -741,11 +521,11 @@ review-evidence binding. v0.1 reviewer findings/notes and contributor responses are REV-owned records with no artifact upload. Any future uploaded evidence requires separate approved REV-owned intent plus exact ART and AUTH owner work. -Migration `0021` preserves historical audit rows with null `action_id`. Inspect +The v0.1 schema permits historical audit rows with null `action_id`. Inspect non-null action evidence only by bounded ActionId, request/correlation IDs, and resource references; do not export event payloads or actor identity-link data for routine diagnosis. Every action must carry its catalogue-mapped PermissionId, -and every permission added after migration `0018` must carry one of its mapped +and every current permission must carry one of its mapped actions. Planned actions can record bounded denial evidence but cannot record an allowed decision through the typed writer. @@ -836,59 +616,19 @@ Still-planned fixed-service actions produce no handle. ProjectRoleGrant preparation is unsupported until AUTH-10 supplies and proves its canonical lock path. -Downgrade is allowed only while every action ID remains null and no permission -outside migration `0018`'s historical 49-value set exists in the decision, -target-reference, or invalidation-reference fields. The migration takes an -exclusive audit-table lock before these checks and keeps it through destructive -DDL. If any forward evidence exists, stop and recover forward rather than -discarding it. +The pre-v0.1 downgrade path is removed. Preserve action evidence and recover +forward rather than discarding it. Canonical actor self-read/self-update, the seven AUTH-08 administrative actions, AUTH-09B controlled service provisioning, and the two AUTH-09C actor-registry reads are active. Project capability context waits for AUTH-10 exact-project grants and canonical project composition. -AUTH-10 is a clean cut to independent `submitter`, `reviewer`, and -`adjudicator` grants. Before rollout, scan current typed schemas, audit facts, -idempotency records, and PostgreSQL validators for `both`, replacement fields, -replacement events, and replacement reasons. Migration `0031` must stop on any -incompatible evidence; operators must remediate through a separately approved -data decision, never an automatic conversion. A safe downgrade also refuses -rather than deleting adjudicator or new exact-role evidence. - -Before upgrading to `0031`, run the following read-only preflight against the -same database. Both counts must be zero: - -```sql -select count(*) from audit_events where event_domain='authority' and ( - before_facts->>'role'='both' or after_facts->>'role'='both' or - before_facts::jsonb ? 'replaced_grant_id' or - after_facts::jsonb ? 'replaced_grant_id' or - event_type='ProjectRoleGrantReplaced' or reason='authority_replacement'); -select count(*) from authority_idempotency_records where operation in - ('project_role_grant.issue','project_role_grant.revoke'); -``` - -Before downgrading from `0031`, both new tables must be empty and this count -must be zero: - -```sql -select count(*) from project_role_grants; -select count(*) from project_role_qualification_snapshots; -select count(*) from audit_events where event_domain='authority' and ( - before_facts->>'role'='adjudicator' or after_facts->>'role'='adjudicator' or - action_id in ('project.contributor_candidate.list','project_role_grant.list', - 'project_role_grant.read','project_role_grant.issue','project_role_grant.revoke') or - denial_code in ('project_role_grant_already_revoked', - 'project_role_grant_replay_state_changed')); -``` - -The migration repeats these checks while holding `ACCESS EXCLUSIVE` locks on -the affected authority tables, so schedule a maintenance window that prevents -authority writes. A refusal occurs before schema mutation. Keep the database at -its current revision, investigate the exact nonzero predicate, and recover -forward through a separately reviewed data decision; never delete or convert -authority evidence merely to make the migration proceed. +AUTH-10 uses independent `submitter`, `reviewer`, and `adjudicator` grants. The +retired `both` role and replacement-event migration states are not accepted by +the v0.1 baseline. Recreate pre-v0.1 development databases. Production +remediation requires a separately approved evidence-preserving data decision; +never automatically convert or delete authority evidence. Project-role revocation is routed by exact role. Submitter invalidation may reach task assignment; reviewer invalidation reaches only REV; adjudicator @@ -917,11 +657,8 @@ planned and unavailable. Each active action can be resolved for this fixed service only by an internal command carrying exact setup-run, expected-step, task/correlation, project, guide, snapshot, generation, stale output, and material custody. It is not admitted through the public HTTP route, -and it never receives a fabricated human grant. Migration -`0043_project_setup_service` seeds no profile, link, AdminRoleGrant, or -ProjectRoleGrant. It takes an `ACCESS EXCLUSIVE` lock on `actor_profiles` while -replacing the closed service-identity constraint, and downgrade refuses once a -`workstream.project.setup` ActorProfile exists. An Access Administrator may use the existing controlled +and it never receives a fabricated human grant. The baseline seeds no profile, +link, AdminRoleGrant, or ProjectRoleGrant. An Access Administrator may use the existing controlled service-actor provisioning route only when the deployment supplies the exact issuer and opaque subject; that actor still has no executable setup action until each owning activation chunk merges. @@ -1228,7 +965,7 @@ log the key, a cursor, or distinctions hidden by the shared 404. Authorization read exhaustion returns 429 with `Retry-After`, and unavailable rate/evidence persistence returns retryable 503 before private row lookup. -AUTH-10C adds migration `0034_project_role_issue_evidence`. It performs no +AUTH-10C adds project-role issue evidence. It performs no product-row rewrite: it replaces only the three frozen authority evidence function bodies, adds `qualification_snapshot` to the existing privacy resource registry, and leaves the existing fact constraint and trigger identities in @@ -1269,8 +1006,7 @@ database owner must: 6. retain redacted change evidence and return credentials to controlled storage. Do not use owner maintenance to revise authority history, erase a denial, or -fabricate evidence. Normal migration downgrade refuses while authority rows -exist; destructive cleanup requires a separately reviewed retention or legal +fabricate evidence. Destructive cleanup requires a separately reviewed retention or legal procedure and is not an application operation. ## Incident Response @@ -1349,43 +1085,34 @@ still be updated. Embedded review, revision, retired payout/economic, and contribution-record configuration fields correctly return 422; do not reintroduce a compatibility payload or direct product-service authorization path. -Migration `0045_guide_metadata_authority` leaves pre-existing guide, source -snapshot, and setup-run rows readable with null authorization provenance; it -does not invent or backfill historical custody. Every new covered mutation must -commit its complete replay, decision, and row provenance atomically. Once any -12D custody or attributed mutation exists, downgrade is intentionally refused; -operators must not delete authority evidence merely to force rollback. +The v0.1 guide-metadata schema does not invent or backfill historical custody. +Every new covered mutation must +commit its complete replay, decision, and row provenance atomically. Operators +must preserve authority evidence and recover forward. -Migration `0054_guide_sufficiency_authority` leaves historical sufficiency -reports readable with null authorization provenance. New 12E mutations record +The v0.1 schema leaves historical sufficiency reports readable with null +authorization provenance. New 12E mutations record complete creation or acknowledgement provenance and use the append-only -`guide_sufficiency_mutation_idempotency_records` replay ledger. Downgrade is -refused after any 12E replay or attributed sufficiency provenance exists; do -not delete replay, product, or authority evidence to force rollback. - -Migration `0057_submission_policy_authority` installs submission-policy -PREP, replay, and nullable provenance custody. Migration -`0059_policy_execution_claim` adds the fixed-service derivation execution claim. -Existing submission, -effective, and pre-submit policy rows remain readable with all authority fields -null; do not backfill invented authority. Human replay custody permits only +`guide_sufficiency_mutation_idempotency_records` replay ledger. Do not delete +replay, product, or authority evidence; recover forward. + +The v0.1 baseline installs submission-policy PREP, replay, nullable provenance +custody, and the fixed-service derivation execution claim. Human replay custody permits only `pending -> committed`. Fixed-service derivation commits `reserved` before material or agent I/O, then uses fresh final PREP and atomically advances `reserved -> pending -> committed` with the protected product mutation. A -reserved or pending row is durable custody and intentionally blocks downgrade. +reserved or pending row is durable custody. Any audit event using the submission-policy mutation resource type, -including denied evidence, blocks downgrade independently. 12F2 activates only +including denied evidence, must be preserved. 12F2 activates only manual human create/update. Each update appends a separately authorized successor and supersedes its exact hash-selected predecessor atomically. 12F3 activates derive only for the fixed `workstream.project.setup` service; approve remains planned. Operators must not treat the shared schema as wider activation. -Migration `0063_compilation_authority` admits the request action, permission, -and resource while preserving the earlier execute vocabulary. Empty downgrade -to `0062_guide_compilation` is supported, but any allowed or denied audit -evidence for either compilation action intentionally blocks downgrade. Do not -delete authority evidence to force rollback; retain revision 0063 or apply an -explicitly reviewed evidence-retention migration. +The v0.1 baseline admits the guide-compilation request action, permission, and +resource while preserving the execute vocabulary. The baseline cannot be +downgraded. Recreate a development database instead of deleting authority +evidence or attempting revision-specific rollback. ## Draft review and revision policy authorization @@ -1403,8 +1130,8 @@ only the corresponding draft-guide selector in the same transaction. The two policies may be attached in either order. Never repair an active guide by changing these selectors: active and superseded guide selections remain frozen. -Migration `0048_policy_authority` adds nullable historical provenance columns -and the `policy_mutation_idempotency_records` custody ledger. Historical +The v0.1 baseline includes nullable historical provenance columns and the +`policy_mutation_idempotency_records` custody ledger. Historical `legacy_incomplete` rows remain grandfathered and are not attributed. Downgrade is refused after any 02B mutation/replay custody exists; do not delete policy or authorization evidence to force rollback. A populated rollback requires an diff --git a/docs/operations_backend_testing.md b/docs/operations_backend_testing.md index 1b5edcb23..5150be060 100644 --- a/docs/operations_backend_testing.md +++ b/docs/operations_backend_testing.md @@ -93,8 +93,8 @@ lane ownership remains repository-defined and exact. The lanes are balanced by measured dependency ownership: `project_lifecycle` owns project tests, `task_lifecycle` owns task and checker tests, `schema_contracts_a`, `schema_contracts_b`, and `schema_contracts_c` -deterministically partition exact -node IDs from the measured 12-minute `test_alembic.py` hotspot; +deterministically partition exact node IDs from the baseline and PostgreSQL +schema-contract suites; `schema_contracts_a` also owns reset and isolated-runner contracts. The `shared_foundations_a` and `shared_foundations_b` lanes deterministically partition exact node IDs from the remaining authorization, artifact, API, and diff --git a/docs/spec_artifact_storage_service.md b/docs/spec_artifact_storage_service.md index 01bc5b67f..042161cd5 100644 --- a/docs/spec_artifact_storage_service.md +++ b/docs/spec_artifact_storage_service.md @@ -1218,7 +1218,7 @@ database uniqueness constraint permits one set for that identity. Exact replay returns the existing durable evidence set but never returns a new pass capability; the caller must re-prepare the exact bundle before a later submission attempt. Changed facts or changed deterministic results conflict. -Migration `0058_pre_submit_evidence` installs the normalized set and +The v0.1 baseline installs the normalized set and result tables plus composite identity-link, assignment, task/project, locked guide/policy and predecessor lineage constraints. Set and result rows reject update, delete and truncate; result membership closes with the creating @@ -1260,7 +1260,7 @@ execution, which produces a new prepared generation, evidence identity, and single-use pass capability. If the process dies after intent commit, the existing generic put-attempt observation and recovery machinery owns the technical obligation without another submission-specific recovery aggregate. -Migration `0060_submission_bundle_intent` installs the immutable join +The v0.1 baseline installs the immutable join and extends only the existing generic put-attempt and receipt producer shapes needed for submission bundles. @@ -1710,51 +1710,35 @@ Implementation is a clean cut: normal submission creation still enters evaluation automatically; - no dual write, nullable shadow field, fake verified backfill, fallback adapter, compatibility constructor, or second factory remains; -- migration `0025` refuses every populated v1 artifact table before DDL and - leaves the prior schema and rows unchanged. It performs no automated rebuild - or fabricated backfill. Because this is a pre-production clean cut, the - Operator must reprovision an empty database/storage namespace out of band and - reingest authoritative bytes through v2; records whose authoritative bytes - are unavailable are not migrated. -- migration `0028_artifact_admission` installs the durable admission ledger and prepared - put-attempt tables. Its downgrade locks every owned table and refuses to - remove the foundation when any admission scope, charge, attempt, or - attempt-charge link exists; downgrade is permitted only while all four - tables are empty. -- migration `0030_artifact_verification` adds polymorphic contract-v2 operation +- the v0.1 baseline contains no v1 artifact schema or fabricated backfill; + pre-v0.1 development databases/storage namespaces are reprovisioned and + authoritative bytes are reingested through v2; +- the v0.1 baseline installs the durable admission ledger and prepared + put-attempt tables; +- the v0.1 baseline includes polymorphic contract-v2 operation receipts, typed put-observation receipts, verification jobs and receipts, and - execution-mode/observation fencing. Existing contributor receipt rows remain - readable as contract v1. Downgrade refuses when verification evidence or a - non-contributor receipt cannot be represented by the prior schema. -- migration `0039_guide_source_bindings` deterministically backfills positive, - guide-local setup generations ordered by creation time and stable row ID, + execution-mode/observation fencing; +- the v0.1 baseline installs positive guide-local setup generations, installs exact guide/snapshot/item/setup-run/content/replica lineage - constraints, and creates immutable guide-source bindings. Downgrade is - permitted only while the binding table is empty; populated binding evidence - is never discarded. -- migration `0040_guide_materialization` adds immutable exact-binding format + constraints, and creates immutable guide-source bindings; +- the v0.1 baseline adds immutable exact-binding format classifications and bounded ART custody incidents. Composite foreign keys prevent either table from naming different binding/content/replica/generation - facts, and closed status/code checks reject unknown outcomes. Downgrade locks - both tables and refuses while either contains evidence. This hidden chunk + facts, and closed status/code checks reject unknown outcomes. This hidden chunk adds no Operator route or generic artifact-read API; future authorized operational visibility must project these bounded records without exposing provider references or document content. -- migration `0042_guide_extraction` adds bounded extraction attempts, +- the v0.1 baseline adds bounded extraction attempts, successful canonical content, exact usage provenance, and a durable exact-lineage two-slot materialization budget. Composite constraints prevent cross-binding/classification/content/generation usage and require usage to - reference an `extracted` attempt. Downgrade locks the four tables and refuses - while any extraction or retry-budget evidence exists. -- migration `0050_guide_source_v2` requires an empty guide-source snapshot - namespace, renames the non-authoritative declaration field to `source_label`, + reference an `extracted` attempt; +- the v0.1 baseline uses `source_label` for the non-authoritative declaration, removes caller-owned hash/content-id fields, installs the exact v2 manifest - trigger, and refuses downgrade when guide-source rows exist rather than - fabricating legacy byte identity. + trigger, and never fabricates legacy byte identity. -Every migration proves fresh upgrade, prior-head upgrade, populated-state -preservation or explicit refusal, empty downgrade/re-upgrade, and no artifact -bytes in PostgreSQL. +The baseline proves fresh installation, fail-closed refusal of old/nonempty +databases, and no artifact bytes in PostgreSQL. It is not downgradable. ## Verification Strategy diff --git a/docs/spec_authorization_service.md b/docs/spec_authorization_service.md index fce7c98c5..8fb62748b 100644 --- a/docs/spec_authorization_service.md +++ b/docs/spec_authorization_service.md @@ -127,7 +127,7 @@ The active model has no `both`, replacement field, replacement event, or replacement reason. Qualification evidence is bound to the same actor, project, and exact requested role. One active row is permitted per actor/project/role. Issue idempotency includes the requested role; revoke derives -the role from the locked grant. Migration `0031` refuses upgrade when obsolete +the role from the locked grant. The v0.1 baseline excludes obsolete combined or replacement evidence exists and never converts or deletes those rows. It replaces current typed and PostgreSQL validators without changing historical migrations. @@ -292,7 +292,7 @@ AUTH-07B activates `actor.profile.read_self` and `actor.profile.update_self`. AUTH-08 activates exactly seven administrative actions through migration `0022`; all other registered actions remain planned. -AUTH-09A registers these exact planned actions through migration `0023`: +AUTH-09A registers these exact planned actions in the v0.1 baseline: | ActionId | PermissionId | Activation owner | |---|---|---| @@ -407,7 +407,7 @@ Artifact verification recovery remains the existing registered. Shared outbox dispatch/retry remains owned by the shared-outbox subsystem and is not represented as a REV-owned projection action. -Migration `0021` is availability-neutral. PostgreSQL enforces the closed +The v0.1 baseline is availability-neutral for this surface. PostgreSQL enforces the closed ActionId set, authorization-decision event shape, exact ActionId-to-PermissionId mapping, and the requirement that every post-`0018` permission carry a mapped action. Typed catalogue validation separately rejects allowed evidence until the @@ -501,12 +501,12 @@ Operator grant or entitlement. WS-XINT-002-03 activates the three internal service actions, WS-XINT-002-04A activates guide-source ingest, and WS-XINT-002-04B activates the two fixed-service guide binding/read actions; the other 16 ART actions remain planned and unavailable. -Migration `0037` admits the exact privacy-bounded ART resource-context digest +The v0.1 baseline admits the exact privacy-bounded ART resource-context digest in append-only authorization decision facts; it adds no table or column. `artifact.verification_job.retry` requires its own later evaluator, guards, and independent activation proof; read/status proof cannot activate retry. The historical ART transfer added no migration; WS-XINT-002-01 reconciles the -closed catalogue through migration `0036`. The separately started REV custody +closed catalogue in the v0.1 baseline. The separately started REV custody transfer is also complete: all 19 REV rows now name exact AUTH custodians, remain planned and unavailable, and add no migration. @@ -581,7 +581,7 @@ project-setup actions and all six REV rows remain planned and unavailable. Registration makes the identity selectable by the existing controlled provisioning route but creates no ActorProfile, ActorIdentityLink, role, grant, or executable authority by -itself; migration `0043_project_setup_service` only expands the closed database +itself; the v0.1 baseline only expands the closed database identity constraint. AUTH-09B lets a system Access Administrator bind an exact configured-issuer @@ -1131,12 +1131,11 @@ execution task, calls no provider, and does not make the hidden POL workflow liv | `project.setup_run.update` | `project.guide.manage` | `WS-AUTH-001-12B2` | | `project.guide.activate` | `project.guide.manage` | `WS-AUTH-001-12H` | -Migration `0054_guide_sufficiency_authority` preserves historical sufficiency +The v0.1 baseline preserves historical sufficiency rows as readable, unattributed records while requiring complete creation or acknowledgement authority provenance for new 12E mutations. Its replay ledger -is append-only, and downgrade is refused after any 12E replay or provenance -exists. Operators must not delete authority or product evidence to force a -rollback. +is append-only. Operators must preserve authority and product evidence and +recover forward. `WS-AUTH-001-12F` is a planning-only parent and activates nothing. 12F1 owns the zero-activation PREP/replay/provenance foundation; 12F2 owns explicitly @@ -1156,7 +1155,7 @@ idempotency from fixed setup-service task custody. Manual mutations permit only `reserved -> pending -> committed` state machine: `reserved` is committed before material or agent I/O, while the final two transitions commit atomically with the derived policy, final AUTH evidence, and setup output. -Migration `0057_submission_policy_authority` preserves existing product rows in +The v0.1 baseline preserves existing product rows in the all-null unattributed shape until their owning route cutovers. 12F2 now activates only manual human create/update. Manual update appends a separately authorized successor, binds predecessor hash and successor identity through @@ -1165,14 +1164,12 @@ Diagnostic sufficiency, legacy role strings, services, contributors, and agent-derived rows cannot authorize this exception. Fixed-service derive is active under 12F3; human approval remains planned for 12F4. Any durable execution claim or replay row—including reserved or pending—or attributed -provenance blocks downgrade. Any submission-policy -authorization audit event, including denied evidence, also blocks downgrade so -the admitted evidence vocabulary is never removed while referenced. +provenance must be preserved. Submission-policy authorization audit events, +including denied evidence, must also be preserved. -Migration `0041_project_mutation_evidence` extends only the closed audit -action-to-permission evidence constraint. It follows ART migration -`0040_guide_materialization`, adds no permission, and refuses downgrade after -direct or idempotency-linked evidence uses any new action. +The v0.1 baseline extends only the closed audit action-to-permission evidence +constraint. It includes the verified guide-materialization schema, adds no +permission, and requires direct or idempotency-linked evidence to be preserved. The two collection routes return and transactionally bind at most the newest 100 canonical rows in deterministic newest-first order. Older retained records @@ -1243,7 +1240,7 @@ where existence itself is sensitive. First access and administrative mutations are rate-controlled through Postgres-backed fail-closed controls before their public APIs become available. -Migration `0033_authorization_read_rate` extends that same durable +The v0.1 baseline extends that same durable counter with the closed `authorization_read` scope. Its dependency remains unattached and activates no action until AUTH-10B2. The dedicated default is 120 requests per 60 seconds per verified issuer/subject digest, independently From 401beb70b7daa77313dfd82c510e0d3c0ac5b2ae Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Tue, 11 Aug 2026 12:05:35 +0100 Subject: [PATCH 2/4] reconcile baseline behavior ownership --- .ci/behavior-ownership/partition.v1.json | 12 ++++++------ backend/scripts/behavior_ownership.py | 21 ++++++++++++++++++++- backend/tests/test_behavior_ownership.py | 15 +++++++++++++++ 3 files changed, 41 insertions(+), 7 deletions(-) diff --git a/.ci/behavior-ownership/partition.v1.json b/.ci/behavior-ownership/partition.v1.json index f9cc155da..31b1e19b0 100644 --- a/.ci/behavior-ownership/partition.v1.json +++ b/.ci/behavior-ownership/partition.v1.json @@ -156,10 +156,6 @@ "group": "shared", "target": "backend/app/modules/actors/service_identities.py" }, - { - "group": "shared", - "target": "backend/app/modules/actors/service_identity_migration.py" - }, { "group": "shared", "target": "backend/app/modules/api_controls/models.py" @@ -774,7 +770,11 @@ }, { "group": "shared", - "target": "backend/scripts/service_actor_identity_mapping.py" + "target": "backend/scripts/schema_baseline_manifest.py" + }, + { + "group": "shared", + "target": "backend/scripts/schema_baseline_sql.py" }, { "group": "shared", @@ -789,7 +789,7 @@ "target": "backend/scripts/week2_api_e2e.py" } ], - "authority_digest": "980703d737c30d6579d96d01bb348116af9bfbc772a1d74ad15131d9e2388597", + "authority_digest": "a26548020ee449fb68a72c86e17bd1f98a6d47804e55d09a5f1a9f3b4c5fb095", "protected_base_commit": "7676ce4347db0c9694962a9b587a20765e16eac6", "schema": "workstream.behavior-ownership-partition.v1" } diff --git a/backend/scripts/behavior_ownership.py b/backend/scripts/behavior_ownership.py index 8a45c9c9f..9f3992db5 100644 --- a/backend/scripts/behavior_ownership.py +++ b/backend/scripts/behavior_ownership.py @@ -99,6 +99,18 @@ "backend/app/modules/authorization/guide_compilation.py", } ) +V01_BASELINE_REMOVED_TARGETS = frozenset( + { + "backend/app/modules/actors/service_identity_migration.py", + "backend/scripts/service_actor_identity_mapping.py", + } +) +V01_BASELINE_ADDED_TARGETS = frozenset( + { + "backend/scripts/schema_baseline_manifest.py", + "backend/scripts/schema_baseline_sql.py", + } +) class BehaviorOwnershipError(RuntimeError): @@ -233,9 +245,15 @@ def _validate_additive_partition_transition( raise BehaviorOwnershipError("invalid_trusted_partition") current_assignments = current["assignments"] current_by_target = {item["target"]: item for item in current_assignments} + removed = set(trusted_targets) - set(current_by_target) + retained_trusted = [ + item for item in trusted_assignments if item["target"] not in removed + ] if ( trusted_targets != sorted(trusted_targets) - or [current_by_target.get(target) for target in trusted_targets] != trusted_assignments + or removed - V01_BASELINE_REMOVED_TARGETS + or [current_by_target[item["target"]] for item in retained_trusted] + != retained_trusted ): raise BehaviorOwnershipError("untrusted_partition_change") additions = set(current_by_target) - set(trusted_targets) @@ -245,6 +263,7 @@ def _validate_additive_partition_transition( | TASK_BOUNDARY_FOUNDATION_TARGETS | POL_03A_CALLABLE_TARGETS | AUTH_12I_TARGETS + | V01_BASELINE_ADDED_TARGETS ) expected_additions = (approved_additions & additions) - set(trusted_targets) if POL_03A_DECLARATIVE_MODEL_TARGET in additions: diff --git a/backend/tests/test_behavior_ownership.py b/backend/tests/test_behavior_ownership.py index 4e28bbe06..af89c2633 100644 --- a/backend/tests/test_behavior_ownership.py +++ b/backend/tests/test_behavior_ownership.py @@ -192,6 +192,21 @@ def test_partition_accepts_only_the_approved_additive_foundation_transition( } +def test_partition_accepts_only_the_v01_migration_tool_removals() -> None: + retained = "backend/app/core/config.py" + removed = sorted(ownership.V01_BASELINE_REMOVED_TARGETS) + trusted = _partition(sorted([retained, *removed])) + current = _partition([retained]) + + ownership._validate_additive_partition_transition(current, trusted) + + with pytest.raises(ownership.BehaviorOwnershipError, match="untrusted_partition_change"): + ownership._validate_additive_partition_transition( + current, + _partition(sorted([retained, *removed, "backend/scripts/extra.py"])), + ) + + def test_partition_rejects_reordered_trusted_assignments( tmp_path: Path, monkeypatch: pytest.MonkeyPatch ) -> None: From 399dd1f7ad863fed18ab9c5417ab3d52276586d9 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Tue, 11 Aug 2026 13:48:36 +0100 Subject: [PATCH 3/4] fix baseline documentation contract --- .../TEST_STRUCTURE_DEBT.json | 70 +++++++++---------- .../WS-DB-001-01-external-review-response.md | 33 +++++++++ .../reviews/WS-DB-001-01-pr-trust-bundle.md | 44 ++++++++++++ backend/tests/test_authorization.py | 3 +- 4 files changed, 113 insertions(+), 37 deletions(-) create mode 100644 .agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md create mode 100644 .agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md diff --git a/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json b/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json index cd050f10f..083a8e7eb 100644 --- a/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json +++ b/.agent-loop/initiatives/WS-AUTH-003-module-boundary-recovery/TEST_STRUCTURE_DEBT.json @@ -218,11 +218,11 @@ }, { "capability": "unassigned_legacy_auth", - "content_sha256": "5ef6aaa93c09a9625196c0d1fc8f6e9c6e22b13f68b4d95253fad97616e21871", - "end_line": 13435, + "content_sha256": "6c02f75335bb5ad6bb023b7d80b0c8801c849feae308fa4f5446d38d6058b1ed", + "end_line": 13434, "hard_limit": 1200, "kind": "test_file", - "observed_lines": 13435, + "observed_lines": 13434, "path": "backend/tests/test_authorization.py", "qualified_symbol": null, "removal_chunk": "WS-AUTH-003-CLOSE", @@ -531,50 +531,50 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "951b44cc07e36002118fe93b7974e8d65851b0e2c3cec89a3031cbe42b014e2d", - "end_line": 8535, + "end_line": 8534, "hard_limit": 120, "kind": "test_function", "observed_lines": 140, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_actor_lifecycle_service_applies_success_and_guards_conflicts", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8396 + "start_line": 8395 }, { "capability": "unassigned_legacy_auth", "content_sha256": "569084d6de89ff9eae71d526fc6c157aea7638f55ca93ad128b721fbda339be6", - "end_line": 9025, + "end_line": 9024, "hard_limit": 120, "kind": "test_function", "observed_lines": 122, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_admin_resource_digest_alone_rejects_substituted_role_and_disposition", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8904 + "start_line": 8903 }, { "capability": "unassigned_legacy_auth", "content_sha256": "90b8b670b4d277209617cc1aa794188b4fb3cd9d894b69d5dc3d0adfc885f6ed", - "end_line": 9253, + "end_line": 9252, "hard_limit": 120, "kind": "test_function", "observed_lines": 132, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_admin_revoke_stages_complete_state_and_evidence", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 9122 + "start_line": 9121 }, { "capability": "unassigned_legacy_auth", "content_sha256": "78d9bf3df08e5633e9a75720b1e4bf5b7d7b24019bc392b4cb7496a9ac5e5e8e", - "end_line": 11087, + "end_line": 11086, "hard_limit": 120, "kind": "test_function", "observed_lines": 122, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_authorization_locks_refresh_cached_actor_lifecycle_state", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 10966 + "start_line": 10965 }, { "capability": "unassigned_legacy_auth", @@ -591,86 +591,86 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "df1df6ec2ba6aa55445e21cfcf4e4e3ad9664c9504313484a495b6a6df1e9047", - "end_line": 3482, + "end_line": 3481, "hard_limit": 120, "kind": "test_function", "observed_lines": 126, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_identity_link_lifecycle_route_preserves_outcome_transaction_contract", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 3357 + "start_line": 3356 }, { "capability": "unassigned_legacy_auth", "content_sha256": "05d1b020ecff0f9bc0a0567adc07f5b31a2f9dfb7828ae3ad34d4e1e7757797c", - "end_line": 8688, + "end_line": 8687, "hard_limit": 120, "kind": "test_function", "observed_lines": 151, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_identity_link_lifecycle_service_applies_success_and_guards_conflicts", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 8538 + "start_line": 8537 }, { "capability": "unassigned_legacy_auth", "content_sha256": "a45270573154ce2f298221169a3d55530059598bc976263feafc349c77c6ea46", - "end_line": 6340, + "end_line": 6339, "hard_limit": 120, "kind": "test_function", "observed_lines": 121, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_pre_submit_materializer_adapter_binds_every_fact_and_service", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6220 + "start_line": 6219 }, { "capability": "unassigned_legacy_auth", "content_sha256": "c5d6d0d480ced964354915614f15202c0159bfbb281658da0d44186dffd17848", - "end_line": 7483, + "end_line": 7482, "hard_limit": 120, "kind": "test_function", "observed_lines": 142, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_prepared_actor_authority_crossed_mutations_complete_in_both_orders", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 7342 + "start_line": 7341 }, { "capability": "unassigned_legacy_auth", "content_sha256": "ebb76e63671195aa4d806ac602bfe58cb22bf82d00c8a70ab186785f3acd7f9b", - "end_line": 7824, + "end_line": 7823, "hard_limit": 120, "kind": "test_function", "observed_lines": 336, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_prepared_crosses_real_lifecycle_service_transactions", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 7489 + "start_line": 7488 }, { "capability": "unassigned_legacy_auth", "content_sha256": "9ea4fc0ddbab4c7262a43bc3f498ee1afea3318e9a0b6c93c87763f9f22aae9c", - "end_line": 7314, + "end_line": 7313, "hard_limit": 120, "kind": "test_function", "observed_lines": 518, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_prepared_postgresql_failure_and_cancellation_are_atomic", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 6797 + "start_line": 6796 }, { "capability": "unassigned_legacy_auth", "content_sha256": "46e0b031394da6fee856e48615732a17ff8d2276d9cedfb0ecaa3a6879410adb", - "end_line": 4687, + "end_line": 4686, "hard_limit": 120, "kind": "test_function", "observed_lines": 157, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_11c2_reads_require_exact_admin_context_and_role_allowlist", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 4531 + "start_line": 4530 }, { "capability": "unassigned_legacy_auth", @@ -687,38 +687,38 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "105667302ed6e8f2fd16ea7e95d642e72e41514673e1152503536e0520f9c362", - "end_line": 10962, + "end_line": 10961, "hard_limit": 120, "kind": "test_function", "observed_lines": 204, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_read_permissions_have_postgresql_role_scope_matrix", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 10759 + "start_line": 10758 }, { "capability": "unassigned_legacy_auth", "content_sha256": "756b7f99f9a743284934b4d85ce263617710d9b8119792ccb4526a1de04070a1", - "end_line": 12464, + "end_line": 12463, "hard_limit": 120, "kind": "test_function", "observed_lines": 233, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_role_and_all_operation_mappings_commit_one_linked_pair", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 12232 + "start_line": 12231 }, { "capability": "unassigned_legacy_auth", "content_sha256": "2e1d7db74ddb955b90a0ee12e4fb72b651a0f85d2746c76e09079c05b0b85252", - "end_line": 13435, + "end_line": 13434, "hard_limit": 120, "kind": "test_function", "observed_lines": 681, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_project_role_issue_postgresql_prep_binds_target_role_and_scope", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 12755 + "start_line": 12754 }, { "capability": "unassigned_legacy_auth", @@ -747,14 +747,14 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "05621e885ed2f88d0ba1a072c1f263fc923939f7ce755a514e9872112aa830a1", - "end_line": 11981, + "end_line": 11980, "hard_limit": 120, "kind": "test_function", "observed_lines": 163, "path": "backend/tests/test_authorization.py", "qualified_symbol": "test_service_actor_replay_fails_closed_on_committed_state_drift", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 11819 + "start_line": 11818 }, { "capability": "unassigned_legacy_auth", @@ -1035,14 +1035,14 @@ { "capability": "unassigned_legacy_auth", "content_sha256": "1a0a9f3e2be6965e29f76aa74272ccfa2fe4b99e4e0c3bde5ec8ba2c374b369b", - "end_line": 11295, + "end_line": 11294, "hard_limit": 100, "kind": "test_helper", "observed_lines": 169, "path": "backend/tests/test_authorization.py", "qualified_symbol": "_operation_success", "removal_chunk": "WS-AUTH-003-CLOSE", - "start_line": 11127 + "start_line": 11126 }, { "capability": "unassigned_legacy_auth", diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md new file mode 100644 index 000000000..7e6a0e150 --- /dev/null +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md @@ -0,0 +1,33 @@ +# WS-DB-001-01 External Review Response + +## Comments addressed + +- GitHub Backend `shared_foundations_a` exposed one stale documentation assertion + that still required the removed revision-specific ART catalogue wording. The + test now proves that the catalogue reconciliation is part of the v0.1 + baseline, matching the current operations runbook. +- The frozen test-structure ledger was regenerated after a one-line reduction + in the existing oversized authorization test file. Structural enforcement was + not bypassed or relaxed. + +## Comments deferred + +- None. + +## Human decisions needed + +- None. CodeRabbit produced no actionable review thread. Its review was skipped + because the clean-cut removal of the historical migration graph exceeds the + service's 100-file limit; splitting the atomic baseline reset would violate + the approved chunk contract. + +## Commands rerun + +- Focused authorization documentation contract test. +- Frozen test-structure debt validation. +- Ruff on the corrected test file. +- Git diff whitespace validation. + +## Remaining risks + +- Hosted exact-head CI remains the final full-suite and coverage proof. diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md new file mode 100644 index 000000000..6fb8834b9 --- /dev/null +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md @@ -0,0 +1,44 @@ +# WS-DB-001-01 PR Trust Bundle + +## Intent and scope + +Reset the unreleased v0.1 development migration graph to one authoritative +Alembic baseline while preserving the exact current schema, reference data, +security behavior, and application contracts. Historical revisions and their +migration-only tooling are removed; existing databases are not upgraded through +the deleted graph. + +## Design + +- One root/head revision installs deterministic schema and reference-data SQL. +- Canonical manifests prove the baseline against the pre-reset schema, with one + explicit sequence-state delta. +- Fresh empty databases are supported; old stamps and nonempty schemas fail + closed; downgrade is unsupported. +- Product behavior, authorization, module-boundary, and coverage tests remain in + the parallel hosted lanes. + +## Verification and review + +- Alembic reports exactly one root/head. +- Focused baseline, reset, behavior-ownership, authorization documentation, and + test-structure tests pass locally. +- Ruff, boundary checks, stale-wording scan, markdown-link checks, and diff + whitespace checks pass locally. +- Required architecture, security, QA, test-delta, CI-integrity, reuse, senior, + and documentation reviews have no unresolved valid finding. +- CodeRabbit has no actionable thread; its automated review is service-limited + by the atomic clean-cut file count. + +## Human review focus + +- Confirm the clean-cut policy: recreate development databases and require a + separately reviewed forward remediation for any pre-v0.1 production data. +- Confirm the deterministic schema/reference manifests and approved sequence + delta represent the intended v0.1 database. +- Confirm no removed migration-only workflow remains presented as current. + +## Remaining gate + +All exact-head GitHub Actions lanes and the aggregate coverage job must pass +before merge. diff --git a/backend/tests/test_authorization.py b/backend/tests/test_authorization.py index d3a27e91e..9093a29fb 100644 --- a/backend/tests/test_authorization.py +++ b/backend/tests/test_authorization.py @@ -2904,14 +2904,13 @@ def test_art_custody_documentation_matches_the_independent_activation_fixture() ) assert "all 22 ART rows to ten exact activation custodians" in operations assert "the original 19 REV\nrows to seven exact AUTH custodians" in operations - assert "transfer adds no migration; the later WS-XINT-002-01" in operations + assert "v0.1 baseline.\nThe REV transfer adds no migration." in operations assert "does not grant Operator" in operations assert "verification retry remains independently gated" in operations assert ( "73 PermissionIds, 102 ActionIds, 54 active actions, and\n48 planned actions" in operations ) - def test_rev_custody_documentation_matches_the_independent_catalogue_fixture() -> None: repository_root = Path(__file__).resolve().parents[2] custody_documents = ( From 466e43c7617f6e7540d86bde03165c935b3abe2f Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Tue, 11 Aug 2026 14:22:01 +0100 Subject: [PATCH 4/4] compact baseline schema evidence --- .../WS-DB-001-01-external-review-response.md | 6 + .../reviews/WS-DB-001-01-pr-trust-bundle.md | 6 +- .../baseline/v01_baseline_manifest.json | 26924 +--------------- .../v01_pre_reset_source_manifest.json | 26924 +--------------- backend/scripts/schema_baseline_manifest.py | 4 +- backend/tests/test_alembic.py | 10 + 6 files changed, 24 insertions(+), 53850 deletions(-) diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md index 7e6a0e150..b83f49bd1 100644 --- a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-external-review-response.md @@ -2,6 +2,11 @@ ## Comments addressed +- Human review identified that pretty-printing the two generated schema + manifests inflated the PR by 53,844 presentation-only lines. The canonical + serializer and committed manifests now use compact, sorted JSON, with a + regression test requiring exact compact bytes. Manifest content and schema + parity proof are unchanged. - GitHub Backend `shared_foundations_a` exposed one stale documentation assertion that still required the removed revision-specific ART catalogue wording. The test now proves that the catalogue reconciliation is part of the v0.1 @@ -24,6 +29,7 @@ ## Commands rerun - Focused authorization documentation contract test. +- Compact-manifest canonicalization and approved-delta tests. - Frozen test-structure debt validation. - Ruff on the corrected test file. - Git diff whitespace validation. diff --git a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md index 6fb8834b9..bb4efde23 100644 --- a/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md +++ b/.agent-loop/initiatives/WS-DB-001-v01-schema-baseline/reviews/WS-DB-001-01-pr-trust-bundle.md @@ -12,7 +12,8 @@ the deleted graph. - One root/head revision installs deterministic schema and reference-data SQL. - Canonical manifests prove the baseline against the pre-reset schema, with one - explicit sequence-state delta. + explicit sequence-state delta. They are compact sorted JSON machine evidence + so generated formatting does not obscure the human-reviewable SQL and delta. - Fresh empty databases are supported; old stamps and nonempty schemas fail closed; downgrade is unsupported. - Product behavior, authorization, module-boundary, and coverage tests remain in @@ -22,7 +23,8 @@ the deleted graph. - Alembic reports exactly one root/head. - Focused baseline, reset, behavior-ownership, authorization documentation, and - test-structure tests pass locally. + test-structure tests pass locally. Compact-manifest tests also prove exact + deterministic serialization and unchanged approved-delta semantics. - Ruff, boundary checks, stale-wording scan, markdown-link checks, and diff whitespace checks pass locally. - Required architecture, security, QA, test-delta, CI-integrity, reuse, senior, diff --git a/backend/alembic/baseline/v01_baseline_manifest.json b/backend/alembic/baseline/v01_baseline_manifest.json index 362ea8889..6041e90b6 100644 --- a/backend/alembic/baseline/v01_baseline_manifest.json +++ b/backend/alembic/baseline/v01_baseline_manifest.json @@ -1,26923 +1 @@ -{ - "acl": [ - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_event_facts_are_safe(event_name text, before_state js", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_event_facts_are_safe(event_name text, before_state js", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_facts_are_safe(facts json)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_facts_are_safe(facts json)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "enforce_compensation_binding_lifecycle()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "enforce_compensation_binding_lifecycle()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_identity_link_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_identity_link_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_profile_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_profile_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_admin_role_grant()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_admin_role_grant()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_artifact_receipt_producer_reference()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_artifact_receipt_producer_reference()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_control()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_control()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_idempotency_record()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_idempotency_record()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_children()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_children()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_version_content()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_version_content()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_lineage_and_lifecycle()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_lineage_and_lifecycle()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_mutation_idempotency()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_mutation_idempotency()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_iso_4217_currency_codes()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_iso_4217_currency_codes()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_outbox_event()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_outbox_event()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_policy_mutation_replay()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_policy_mutation_replay()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_result_membership()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_result_membership()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_results_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_results_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_set_creation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_set_creation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_sets_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_sets_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_compensation_units()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_compensation_units()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_create_idempotency()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_create_idempotency()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_attempt_update()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_attempt_update()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_insert()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_insert()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_policy_selection()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_policy_selection()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_grant_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_grant_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_snapshot_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_snapshot_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_admission_record()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_admission_record()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_lease()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_lease()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_policies_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_policies_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_queue_entry()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_queue_entry()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_revision_policies_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_revision_policies_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_service_identity_migration_evidence()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_service_identity_migration_evidence()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_delete()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_delete()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_lineage()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_lineage()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_verified_lineage()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_verified_lineage()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intent_put_attempt()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intent_put_attempt()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intents_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intents_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_availability_is_safe(value jsonb)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_availability_is_safe(value jsonb)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reason_is_safe(value text)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reason_is_safe(value text)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_token_is_safe(value text)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_token_is_safe(value text)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_approval_provenance()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_approval_provenance()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_creation_provenance()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_creation_provenance()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_output_provenance()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_output_provenance()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_admin_role_grant_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_admin_role_grant_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_artifact_fact_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_artifact_fact_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_audit_event_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_audit_event_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_control_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_control_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_idempotency_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_idempotency_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_contribution_policy_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_contribution_policy_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_mutation_idempotency_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_mutation_idempotency_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_source_snapshot_item_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_source_snapshot_item_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_pending_authority_idempotency()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_pending_authority_idempotency()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_policy_mutation_replay_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_policy_mutation_replay_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_create_idempotency_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_create_idempotency_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_guide_compilation_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_guide_compilation_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_role_history_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_role_history_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_lease_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_lease_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_queue_foundation_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_queue_foundation_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "require_human_actor_profile_reference()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "require_human_actor_profile_reference()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "set_authority_audit_database_time()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "set_authority_audit_database_time()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_binding_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_binding_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_recovery_attempt()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_recovery_attempt()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_verification_lineage()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_verification_lineage()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_bootstrap_authority_state()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_bootstrap_authority_state()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_canonical_actor_link()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_canonical_actor_link()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_contribution_policy_graph()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_contribution_policy_graph()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_mutation_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_mutation_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_source_snapshot_items()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_source_snapshot_items()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_linked_authority_event()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_linked_authority_event()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_policy_mutation_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_policy_mutation_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_project_create_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_project_create_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_review_active_lease()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_review_active_lease()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_authority_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_authority_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_creation_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_creation_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "sequence", - "name": "actor_profile_migration_state_id_seq", - "principal": "owner", - "privilege": "USAGE" - }, - { - "grantable": "false", - "kind": "sequence", - "name": "authority_control_id_seq", - "principal": "owner", - "privilege": "USAGE" - } - ], - "auxiliary_objects": [], - "columns": [ - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "issuer", - "not_null": true, - "ordinal": 3, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "subject", - "not_null": true, - "ordinal": 4, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "subject_kind", - "not_null": true, - "ordinal": 5, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "linked_by", - "not_null": true, - "ordinal": 7, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "linked_at", - "not_null": true, - "ordinal": 8, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_verified_at", - "not_null": false, - "ordinal": 9, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by", - "not_null": false, - "ordinal": 10, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_at", - "not_null": false, - "ordinal": 11, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_reason", - "not_null": false, - "ordinal": 12, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_by", - "not_null": false, - "ordinal": 13, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_at", - "not_null": false, - "ordinal": 14, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivation_reason", - "not_null": false, - "ordinal": 15, - "table_name": "actor_identity_links" - }, - { - "data_type": "integer", - "default_expression": "nextval('actor_profile_migration_state_id_seq'::regclass)", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "schema_version", - "not_null": true, - "ordinal": 2, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classified_count", - "not_null": true, - "ordinal": 3, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_row_set_sha256", - "not_null": true, - "ordinal": 4, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "manifest_sha256", - "not_null": false, - "ordinal": 5, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "envelope_sha256", - "not_null": false, - "ordinal": 6, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "migrated_at", - "not_null": true, - "ordinal": 7, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_mapped_count", - "not_null": true, - "ordinal": 8, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_source_row_set_sha256", - "not_null": true, - "ordinal": 9, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_manifest_sha256", - "not_null": false, - "ordinal": 10, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_envelope_sha256", - "not_null": false, - "ordinal": 11, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(76)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_database_binding", - "not_null": true, - "ordinal": 12, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_kind", - "not_null": true, - "ordinal": 2, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 3, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provisioning_method", - "not_null": true, - "ordinal": 4, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "display_name", - "not_null": false, - "ordinal": 5, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(320)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contact_email", - "not_null": false, - "ordinal": 6, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 7, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 8, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 9, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_seen_at", - "not_null": false, - "ordinal": 10, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_by", - "not_null": false, - "ordinal": 11, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_at", - "not_null": false, - "ordinal": 12, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspension_reason", - "not_null": false, - "ordinal": 13, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deactivated_by", - "not_null": false, - "ordinal": 14, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deactivated_at", - "not_null": false, - "ordinal": 15, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deactivation_reason", - "not_null": false, - "ordinal": 16, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity", - "not_null": false, - "ordinal": 17, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_by", - "not_null": false, - "ordinal": 18, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_at", - "not_null": false, - "ordinal": 19, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivation_reason", - "not_null": false, - "ordinal": 20, - "table_name": "actor_profiles" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "role", - "not_null": true, - "ordinal": 3, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 4, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_project_id", - "not_null": false, - "ordinal": 5, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "admin_role_grants" - }, - { - "data_type": "smallint", - "default_expression": "'1'::smallint", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 7, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_actor_profile_id", - "not_null": false, - "ordinal": 8, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_system_principal", - "not_null": false, - "ordinal": 9, - "table_name": "admin_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_admin_role_grant_id", - "not_null": false, - "ordinal": 10, - "table_name": "admin_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "grant_reason", - "not_null": true, - "ordinal": 11, - "table_name": "admin_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "clock_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_at", - "not_null": true, - "ordinal": 12, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_actor_profile_id", - "not_null": false, - "ordinal": 13, - "table_name": "admin_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_admin_role_grant_id", - "not_null": false, - "ordinal": 14, - "table_name": "admin_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_reason", - "not_null": false, - "ordinal": 15, - "table_name": "admin_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_at", - "not_null": false, - "ordinal": 16, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "control_scope", - "not_null": true, - "ordinal": 1, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "bytea", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "key_digest", - "not_null": true, - "ordinal": 2, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "window_started_at", - "not_null": true, - "ordinal": 3, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "window_expires_at", - "not_null": true, - "ordinal": 4, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_count", - "not_null": true, - "ordinal": 5, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 6, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_type", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_ref", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creating_operation_identity", - "not_null": true, - "ordinal": 8, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(20)", - "default_expression": "'provisional'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "state", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "reserved_at", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "completed_at", - "not_null": false, - "ordinal": 12, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "released_at", - "not_null": false, - "ordinal": 13, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 15, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "limit_bytes", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "counted_bytes", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_type", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_id", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_bindings" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_version", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 8, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attribution_type", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_binding_id", - "not_null": false, - "ordinal": 10, - "table_name": "artifact_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_contents" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": false, - "ordinal": 4, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "normalized_display_name", - "not_null": false, - "ordinal": 5, - "table_name": "artifact_contents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replica_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(1024)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_object_ref", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replayed", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome", - "not_null": true, - "ordinal": 8, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_number", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "details", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "contract_version", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_source_item_id", - "not_null": false, - "ordinal": 15, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_run_id", - "not_null": false, - "ordinal": 16, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": false, - "ordinal": 17, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_put_attempt_charges" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "charge_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_put_attempt_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_put_attempt_charges" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_request_type", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_type", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_ref", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": false, - "ordinal": 6, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_source_item_id", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_run_id", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": false, - "ordinal": 9, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(255)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "storage_namespace_id", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_fingerprint", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(1024)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_target", - "not_null": true, - "ordinal": 15, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_identity", - "not_null": true, - "ordinal": 16, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 17, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "'prepared'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 18, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "next_run_at", - "not_null": false, - "ordinal": 19, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "executor_id", - "not_null": false, - "ordinal": 20, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lease_expires_at", - "not_null": false, - "ordinal": 21, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 22, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_result_code", - "not_null": false, - "ordinal": 23, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replica_id", - "not_null": false, - "ordinal": 24, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "receipt_id", - "not_null": false, - "ordinal": 25, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 26, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "prepared_at", - "not_null": true, - "ordinal": 27, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 28, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 29, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 30, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_mode", - "not_null": false, - "ordinal": 31, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "observation_count", - "not_null": true, - "ordinal": 32, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'5'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "maximum_observations", - "not_null": true, - "ordinal": 33, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "expected_sha256", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "expected_byte_count", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_sha256", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_byte_count", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 9, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requester_actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requester_identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_request_id", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_correlation_id", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_verification_job_id", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retry_verification_job_id", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "parent_recovery_attempt_id", - "not_null": false, - "ordinal": 11, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "recovery_class", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(1000)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reason", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "client_idempotency_key", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 15, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(20)", - "default_expression": "'requested'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 16, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_result_code", - "not_null": false, - "ordinal": 17, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "initiation_audit_event_id", - "not_null": true, - "ordinal": 18, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_audit_event_id", - "not_null": false, - "ordinal": 19, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 20, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 21, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 22, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": false, - "ordinal": 23, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(1024)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_object_ref", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verification_state", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "availability_state", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "integrity_state", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_replicas" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_reconciled_at", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_replicas" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_replicas" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "storage_namespace_id", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_fingerprint", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_profile", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "backend", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_profile", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_descriptor", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_fingerprint", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "originating_put_attempt_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replica_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(40)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "integer", - "default_expression": "0", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_count", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "maximum_attempts", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "next_run_at", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "executor_id", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lease_expires_at", - "not_null": false, - "ordinal": 9, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_result_code", - "not_null": false, - "ordinal": 12, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 13, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 14, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": false, - "ordinal": 15, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "parent_verification_job_id", - "not_null": false, - "ordinal": 16, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verification_job_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_sha256", - "not_null": false, - "ordinal": 5, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_byte_count", - "not_null": false, - "ordinal": 6, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "audit_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "entity_type", - "not_null": true, - "ordinal": 2, - "table_name": "audit_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "entity_id", - "not_null": true, - "ordinal": 3, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_type", - "not_null": true, - "ordinal": 4, - "table_name": "audit_events" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "from_status", - "not_null": false, - "ordinal": 5, - "table_name": "audit_events" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "to_status", - "not_null": false, - "ordinal": 6, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 7, - "table_name": "audit_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_subject", - "not_null": false, - "ordinal": 8, - "table_name": "audit_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_issuer", - "not_null": false, - "ordinal": 9, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_roles", - "not_null": true, - "ordinal": 10, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_snapshot", - "not_null": true, - "ordinal": 11, - "table_name": "audit_events" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "auth_source", - "not_null": true, - "ordinal": 12, - "table_name": "audit_events" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "is_dev_auth", - "not_null": true, - "ordinal": 13, - "table_name": "audit_events" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reason", - "not_null": false, - "ordinal": 14, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_payload", - "not_null": true, - "ordinal": 15, - "table_name": "audit_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "audit_events" - }, - { - "data_type": "character varying(24)", - "default_expression": "'legacy_lifecycle'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_domain", - "not_null": true, - "ordinal": 17, - "table_name": "audit_events" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_version", - "not_null": false, - "ordinal": 18, - "table_name": "audit_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "occurred_at", - "not_null": false, - "ordinal": 19, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_ref_kind", - "not_null": false, - "ordinal": 20, - "table_name": "audit_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_id", - "not_null": false, - "ordinal": 21, - "table_name": "audit_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": false, - "ordinal": 22, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_actor_ref_kind", - "not_null": false, - "ordinal": 23, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_actor_ref", - "not_null": false, - "ordinal": 24, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "matched_grant_id", - "not_null": false, - "ordinal": 25, - "table_name": "audit_events" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "permission_id", - "not_null": false, - "ordinal": 26, - "table_name": "audit_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": false, - "ordinal": 27, - "table_name": "audit_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_type", - "not_null": false, - "ordinal": 28, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_id", - "not_null": false, - "ordinal": 29, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_ref_kind", - "not_null": false, - "ordinal": 30, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_ref_id", - "not_null": false, - "ordinal": 31, - "table_name": "audit_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "denial_code", - "not_null": false, - "ordinal": 32, - "table_name": "audit_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_reference", - "not_null": false, - "ordinal": 33, - "table_name": "audit_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "invalidation_cause_event_id", - "not_null": false, - "ordinal": 34, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "invalidation_target_kind", - "not_null": false, - "ordinal": 35, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "invalidation_target_ref", - "not_null": false, - "ordinal": 36, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "before_facts", - "not_null": false, - "ordinal": 37, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "after_facts", - "not_null": false, - "ordinal": 38, - "table_name": "audit_events" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": false, - "ordinal": 39, - "table_name": "audit_events" - }, - { - "data_type": "smallint", - "default_expression": "nextval('authority_control_id_seq'::regclass)", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "authority_control" - }, - { - "data_type": "boolean", - "default_expression": "false", - "generated_kind": "00", - "identity_kind": "00", - "name": "bootstrap_completed", - "not_null": true, - "ordinal": 2, - "table_name": "authority_control" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bootstrap_grant_id", - "not_null": false, - "ordinal": 3, - "table_name": "authority_control" - }, - { - "data_type": "smallint", - "default_expression": "'0'::smallint", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 4, - "table_name": "authority_control" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "clock_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 5, - "table_name": "authority_control" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "clock_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 6, - "table_name": "authority_control" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 2, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_ref_kind", - "not_null": true, - "ordinal": 3, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_ref", - "not_null": true, - "ordinal": 4, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(48)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation", - "not_null": true, - "ordinal": 5, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 7, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_resource_type", - "not_null": false, - "ordinal": 8, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_resource_id", - "not_null": false, - "ordinal": 9, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_resource_version", - "not_null": false, - "ordinal": 10, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "smallint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_http_status", - "not_null": false, - "ordinal": 11, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 12, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 13, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "required_checkers", - "not_null": true, - "ordinal": 4, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_checkers", - "not_null": true, - "ordinal": 5, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "blocking_severities", - "not_null": true, - "ordinal": 6, - "table_name": "checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": false, - "ordinal": 8, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_body", - "not_null": false, - "ordinal": 9, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 10, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 11, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 12, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_id", - "not_null": true, - "ordinal": 13, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_hash", - "not_null": true, - "ordinal": 14, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_checker_policy_id", - "not_null": true, - "ordinal": 15, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_checker_bundle_hash", - "not_null": true, - "ordinal": 16, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 17, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_role", - "not_null": false, - "ordinal": 18, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_actor", - "not_null": false, - "ordinal": 19, - "table_name": "checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_at", - "not_null": false, - "ordinal": 20, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 21, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 22, - "table_name": "checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 23, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_by_role", - "not_null": false, - "ordinal": 24, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_by_actor", - "not_null": false, - "ordinal": 25, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersession_kind", - "not_null": false, - "ordinal": 26, - "table_name": "checker_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersession_reason", - "not_null": false, - "ordinal": 27, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_run_id", - "not_null": true, - "ordinal": 2, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 3, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 4, - "table_name": "checker_results" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_name", - "not_null": true, - "ordinal": 5, - "table_name": "checker_results" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "checker_results" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "severity", - "not_null": true, - "ordinal": 7, - "table_name": "checker_results" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "blocks_review", - "not_null": true, - "ordinal": 8, - "table_name": "checker_results" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "message", - "not_null": true, - "ordinal": 9, - "table_name": "checker_results" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_message", - "not_null": false, - "ordinal": 10, - "table_name": "checker_results" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_suggested_fix", - "not_null": false, - "ordinal": 11, - "table_name": "checker_results" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_evidence_refs", - "not_null": true, - "ordinal": 12, - "table_name": "checker_results" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_visible", - "not_null": true, - "ordinal": 13, - "table_name": "checker_results" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "metadata", - "not_null": true, - "ordinal": 14, - "table_name": "checker_results" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 15, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 2, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 3, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 4, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "trigger_source", - "not_null": true, - "ordinal": 5, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_recommendation", - "not_null": true, - "ordinal": 7, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome_source", - "not_null": true, - "ordinal": 8, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "triggered_by", - "not_null": true, - "ordinal": 9, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "triggered_by_subject", - "not_null": true, - "ordinal": 10, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "triggered_by_issuer", - "not_null": true, - "ordinal": 11, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "trigger_auth_source", - "not_null": true, - "ordinal": 12, - "table_name": "checker_runs" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "trigger_reason", - "not_null": false, - "ordinal": 13, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "audit_event_id", - "not_null": false, - "ordinal": 14, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_number", - "not_null": true, - "ordinal": 15, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_checker_run_id", - "not_null": false, - "ordinal": 16, - "table_name": "checker_runs" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "is_current_for_submission", - "not_null": true, - "ordinal": 17, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_version", - "not_null": true, - "ordinal": 18, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_payment_policy_version", - "not_null": true, - "ordinal": 19, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "package_hash", - "not_null": true, - "ordinal": 20, - "table_name": "checker_runs" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_hash_manifest", - "not_null": true, - "ordinal": 21, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_manifest_hash", - "not_null": true, - "ordinal": 22, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "passed_count", - "not_null": true, - "ordinal": 23, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_count", - "not_null": true, - "ordinal": 24, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failed_count", - "not_null": true, - "ordinal": 25, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "blocking_count", - "not_null": true, - "ordinal": 26, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "queued_at", - "not_null": true, - "ordinal": 27, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "started_at", - "not_null": false, - "ordinal": 28, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "completed_at", - "not_null": false, - "ordinal": 29, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_code", - "not_null": false, - "ordinal": 30, - "table_name": "checker_runs" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_message", - "not_null": false, - "ordinal": 31, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 32, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 33, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_version", - "not_null": false, - "ordinal": 34, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_hash", - "not_null": false, - "ordinal": 35, - "table_name": "checker_runs" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_body", - "not_null": false, - "ordinal": 36, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_id", - "not_null": true, - "ordinal": 37, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_generation", - "not_null": true, - "ordinal": 38, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_hash", - "not_null": true, - "ordinal": 39, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_id", - "not_null": true, - "ordinal": 40, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_generation", - "not_null": true, - "ordinal": 41, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_hash", - "not_null": true, - "ordinal": 42, - "table_name": "checker_runs" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_rule_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_policy_version_id", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_type", - "not_null": true, - "ordinal": 5, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instrument_type", - "not_null": true, - "ordinal": 6, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "unit_code", - "not_null": true, - "ordinal": 7, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "numeric", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "quantity", - "not_null": true, - "ordinal": 8, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter_binding_id", - "not_null": true, - "ordinal": 9, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "name", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "'draft'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "current_published_version_id", - "not_null": false, - "ordinal": 5, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 6, - "table_name": "contribution_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 8, - "table_name": "contribution_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 9, - "table_name": "contribution_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_policy_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "version_number", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(16)", - "default_expression": "'draft'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 6, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "published_by", - "not_null": false, - "ordinal": 8, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "published_at", - "not_null": false, - "ordinal": 9, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 10, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 11, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_rules" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_policy_version_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_type", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compensation_mode", - "not_null": true, - "ordinal": 5, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_artifact_policy_id", - "not_null": true, - "ordinal": 7, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_artifact_policy_hash", - "not_null": true, - "ordinal": 8, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 9, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "merge_algorithm_version", - "not_null": true, - "ordinal": 10, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy", - "not_null": true, - "ordinal": 11, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_hash", - "not_null": true, - "ordinal": 12, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 13, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_effective_policy_id", - "not_null": false, - "ordinal": 15, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 16, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 17, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 18, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 19, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 20, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 21, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 22, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_decision_event_id", - "not_null": false, - "ordinal": 23, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 2, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "type", - "not_null": true, - "ordinal": 3, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "label", - "not_null": true, - "ordinal": 4, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(1000)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "uri", - "not_null": false, - "ordinal": 5, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "hash", - "not_null": false, - "ordinal": 6, - "table_name": "evidence_items" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "size_bytes", - "not_null": false, - "ordinal": 7, - "table_name": "evidence_items" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_at", - "not_null": false, - "ordinal": 8, - "table_name": "evidence_items" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "metadata", - "not_null": true, - "ordinal": 9, - "table_name": "evidence_items" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "evidence_items" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 7, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_id", - "not_null": true, - "ordinal": 10, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_generation", - "not_null": true, - "ordinal": 11, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 12, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 13, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": false, - "ordinal": 14, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 15, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 16, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_binding_id", - "not_null": false, - "ordinal": 11, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service", - "not_null": true, - "ordinal": 12, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "code", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_sha256", - "not_null": false, - "ordinal": 7, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_byte_count", - "not_null": false, - "ordinal": 8, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bounded_facts", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(255)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detected_format", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_name", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_version", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_sha256", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_byte_count", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_sha256", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_output", - "not_null": true, - "ordinal": 11, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "omission_facts", - "not_null": true, - "ordinal": 12, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detected_format", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_name", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_version", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_number", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 11, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_code", - "not_null": false, - "ordinal": 12, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bounded_facts", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claimed_slots", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extracted_content_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extraction_attempt_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_status", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(255)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detected_format", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detector_name", - "not_null": true, - "ordinal": 11, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detector_version", - "not_null": true, - "ordinal": 12, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification_facts", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "item_order", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_kind", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_label", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "ingestion_adapter", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": false, - "ordinal": 7, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "manifest_schema_version", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "manifest_json", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bundle_hash", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_by", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_at", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 10, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 11, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 12, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 13, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 14, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 15, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 16, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_generation", - "not_null": false, - "ordinal": 17, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 7, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 10, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 11, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "report_id", - "not_null": false, - "ordinal": 12, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": false, - "ordinal": 13, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 14, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 15, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 16, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 17, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 18, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "report_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "item_order", - "not_null": true, - "ordinal": 3, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 6, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extraction_usage_id", - "not_null": true, - "ordinal": 7, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extraction_attempt_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extracted_content_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": true, - "ordinal": 10, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 11, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_output_sha256", - "not_null": true, - "ordinal": 12, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 7, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "findings", - "not_null": true, - "ordinal": 8, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "summary", - "not_null": false, - "ordinal": 9, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_name", - "not_null": false, - "ordinal": 10, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_version", - "not_null": false, - "ordinal": 11, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 12, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 13, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_role", - "not_null": false, - "ordinal": 14, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_actor", - "not_null": false, - "ordinal": 15, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_at", - "not_null": false, - "ordinal": 16, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "acknowledgement_note", - "not_null": false, - "ordinal": 17, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": false, - "ordinal": 18, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": false, - "ordinal": 19, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_material_sha256", - "not_null": false, - "ordinal": 20, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_material_byte_count", - "not_null": false, - "ordinal": 21, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 22, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 23, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 24, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service_identity", - "not_null": false, - "ordinal": 25, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 26, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 27, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 28, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 29, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_actor_profile_id", - "not_null": false, - "ordinal": 30, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_via_identity_link_id", - "not_null": false, - "ordinal": 31, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_admin_role_grant_id", - "not_null": false, - "ordinal": 32, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_scope_type", - "not_null": false, - "ordinal": 33, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_scope_project_id", - "not_null": false, - "ordinal": 34, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_action_id", - "not_null": false, - "ordinal": 35, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_decision_event_id", - "not_null": false, - "ordinal": 36, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(3)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "code", - "not_null": true, - "ordinal": 1, - "table_name": "iso_4217_currency_codes" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 1, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_subject", - "not_null": true, - "ordinal": 2, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_issuer", - "not_null": true, - "ordinal": 3, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "display_name", - "not_null": false, - "ordinal": 4, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(320)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "email", - "not_null": false, - "ordinal": 5, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_seen_roles", - "not_null": true, - "ordinal": 6, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_claim_snapshot", - "not_null": true, - "ordinal": 7, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "auth_source", - "not_null": true, - "ordinal": 8, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "is_dev_auth", - "not_null": true, - "ordinal": 9, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "first_seen_at", - "not_null": true, - "ordinal": 10, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_seen_at", - "not_null": true, - "ordinal": 11, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 12, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 2, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "profile_type", - "not_null": true, - "ordinal": 3, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "skill_tags", - "not_null": true, - "ordinal": 5, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 6, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_id", - "not_null": true, - "ordinal": 7, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "profile_metadata", - "not_null": true, - "ordinal": 8, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 9, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 10, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_id", - "not_null": true, - "ordinal": 1, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_type", - "not_null": true, - "ordinal": 2, - "table_name": "outbox_events" - }, - { - "data_type": "smallint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_version", - "not_null": true, - "ordinal": 3, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "'workstream'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer", - "not_null": true, - "ordinal": 4, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "aggregate_type", - "not_null": true, - "ordinal": 5, - "table_name": "outbox_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "aggregate_id", - "not_null": true, - "ordinal": 6, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 7, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": true, - "ordinal": 8, - "table_name": "outbox_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "causation_event_id", - "not_null": false, - "ordinal": 9, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 10, - "table_name": "outbox_events" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payload", - "not_null": true, - "ordinal": 11, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payload_digest", - "not_null": true, - "ordinal": 12, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "occurred_at", - "not_null": true, - "ordinal": 13, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(16)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "delivery_state", - "not_null": true, - "ordinal": 14, - "table_name": "outbox_events" - }, - { - "data_type": "integer", - "default_expression": "0", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_count", - "not_null": true, - "ordinal": 15, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "next_attempt_at", - "not_null": false, - "ordinal": 16, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_owner", - "not_null": false, - "ordinal": 17, - "table_name": "outbox_events" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_generation", - "not_null": true, - "ordinal": 18, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claimed_at", - "not_null": false, - "ordinal": 19, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_expires_at", - "not_null": false, - "ordinal": 20, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_attempt_at", - "not_null": false, - "ordinal": 21, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_error_code", - "not_null": false, - "ordinal": 22, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "finalized_at", - "not_null": false, - "ordinal": 23, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archived_at", - "not_null": false, - "ordinal": 24, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "payment_policies" - }, - { - "data_type": "numeric(12,2)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "base_amount", - "not_null": false, - "ordinal": 4, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "currency", - "not_null": false, - "ordinal": 5, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payout_type", - "not_null": false, - "ordinal": 6, - "table_name": "payment_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revision_payment_rule", - "not_null": false, - "ordinal": 7, - "table_name": "payment_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "rejection_payment_rule", - "not_null": false, - "ordinal": 8, - "table_name": "payment_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "accepted_payment_rule", - "not_null": false, - "ordinal": 9, - "table_name": "payment_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "payment_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 7, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 8, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 9, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 10, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 11, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_id", - "not_null": true, - "ordinal": 12, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_generation", - "not_null": true, - "ordinal": 13, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 14, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 15, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 17, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_id", - "not_null": true, - "ordinal": 7, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_hash", - "not_null": true, - "ordinal": 8, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 9, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compiler_version", - "not_null": false, - "ordinal": 10, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compiled_bundle", - "not_null": false, - "ordinal": 11, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compiled_bundle_hash", - "not_null": false, - "ordinal": 12, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_names", - "not_null": true, - "ordinal": 13, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_configs", - "not_null": true, - "ordinal": 14, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 15, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_pre_submit_checker_policy_id", - "not_null": false, - "ordinal": 17, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 18, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 19, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 20, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 21, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 22, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 23, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 24, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_decision_event_id", - "not_null": false, - "ordinal": 25, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "evidence_set_id", - "not_null": true, - "ordinal": 2, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_order", - "not_null": true, - "ordinal": 3, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "schema_version", - "not_null": true, - "ordinal": 4, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "dispatch_authority", - "not_null": true, - "ordinal": 5, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "definition_id", - "not_null": true, - "ordinal": 6, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "definition_version", - "not_null": true, - "ordinal": 7, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "public_name", - "not_null": true, - "ordinal": 8, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source", - "not_null": true, - "ordinal": 9, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "phase", - "not_null": true, - "ordinal": 10, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification", - "not_null": true, - "ordinal": 11, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "severity", - "not_null": true, - "ordinal": 12, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 13, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_code", - "not_null": false, - "ordinal": 14, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "message_code", - "not_null": true, - "ordinal": 15, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_plan_sha256", - "not_null": true, - "ordinal": 16, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "rule_instance_id", - "not_null": false, - "ordinal": 17, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_policy_sha256", - "not_null": true, - "ordinal": 18, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 19, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_identity", - "not_null": true, - "ordinal": 2, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 4, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 5, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 6, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assignment_id", - "not_null": true, - "ordinal": 7, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_id", - "not_null": false, - "ordinal": 8, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_version", - "not_null": false, - "ordinal": 9, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "prepared_generation_id", - "not_null": true, - "ordinal": 10, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_sha256", - "not_null": true, - "ordinal": 11, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_byte_count", - "not_null": true, - "ordinal": 12, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_id", - "not_null": true, - "ordinal": 13, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_sha256", - "not_null": true, - "ordinal": 14, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 15, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 16, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 17, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_sha256", - "not_null": true, - "ordinal": 18, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_sha256", - "not_null": true, - "ordinal": 19, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_id", - "not_null": true, - "ordinal": 20, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_artifact_policy_sha256", - "not_null": true, - "ordinal": 21, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_policy_id", - "not_null": true, - "ordinal": 22, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_checker_policy_sha256", - "not_null": true, - "ordinal": 23, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_plan_sha256", - "not_null": true, - "ordinal": 24, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "catalogue_id", - "not_null": true, - "ordinal": 25, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "catalogue_version", - "not_null": true, - "ordinal": 26, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "catalogue_manifest_sha256", - "not_null": true, - "ordinal": 27, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "storage_scheme", - "not_null": true, - "ordinal": 28, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_status", - "not_null": true, - "ordinal": 29, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "eligible", - "not_null": true, - "ordinal": 30, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_count", - "not_null": true, - "ordinal": 31, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_manifest_sha256", - "not_null": true, - "ordinal": 32, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 33, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_policy_context_hash", - "not_null": true, - "ordinal": 34, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instrument_type", - "not_null": true, - "ordinal": 3, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter_actor_id", - "not_null": true, - "ordinal": 4, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "route_key", - "not_null": true, - "ordinal": 5, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_lifecycle_version", - "not_null": true, - "ordinal": 7, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 8, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 9, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_by", - "not_null": false, - "ordinal": 10, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_at", - "not_null": false, - "ordinal": 11, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 12, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 13, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 1, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instrument_type", - "not_null": true, - "ordinal": 2, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "unit_code", - "not_null": true, - "ordinal": 3, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(3)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "iso_currency_code", - "not_null": false, - "ordinal": 4, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 6, - "table_name": "project_compensation_units" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 8, - "table_name": "project_compensation_units" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 9, - "table_name": "project_compensation_units" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 7, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 8, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_generation", - "not_null": true, - "ordinal": 9, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 11, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 12, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": true, - "ordinal": 7, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 8, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_input_hash", - "not_null": true, - "ordinal": 9, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_material_hash", - "not_null": true, - "ordinal": 10, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_id", - "not_null": true, - "ordinal": 11, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_version", - "not_null": true, - "ordinal": 12, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_schema_version", - "not_null": true, - "ordinal": 13, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_manifest_hash", - "not_null": true, - "ordinal": 14, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_id", - "not_null": true, - "ordinal": 15, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_version", - "not_null": true, - "ordinal": 16, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_schema_version", - "not_null": true, - "ordinal": 17, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_manifest_hash", - "not_null": true, - "ordinal": 18, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_identity", - "not_null": true, - "ordinal": 19, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_version", - "not_null": true, - "ordinal": 20, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instruction_version", - "not_null": true, - "ordinal": 21, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_idempotency_key", - "not_null": true, - "ordinal": 22, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 23, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_result", - "not_null": false, - "ordinal": 24, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_hash", - "not_null": false, - "ordinal": 25, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "component_hashes", - "not_null": false, - "ordinal": 26, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_code", - "not_null": false, - "ordinal": 27, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "persisted_compilation_id", - "not_null": false, - "ordinal": 28, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "reserved_at", - "not_null": true, - "ordinal": 29, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_uncertain_at", - "not_null": false, - "ordinal": 30, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "accepted_at", - "not_null": false, - "ordinal": 31, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 32, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "persisted_at", - "not_null": false, - "ordinal": 33, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_guide_compilations" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 4, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 5, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 6, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 7, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": true, - "ordinal": 8, - "table_name": "project_guide_compilations" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 9, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_input_hash", - "not_null": true, - "ordinal": 10, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_material_hash", - "not_null": true, - "ordinal": 11, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_manifest_hash", - "not_null": true, - "ordinal": 12, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_manifest_hash", - "not_null": true, - "ordinal": 13, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_identity", - "not_null": true, - "ordinal": 14, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_version", - "not_null": true, - "ordinal": 15, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instruction_version", - "not_null": true, - "ordinal": 16, - "table_name": "project_guide_compilations" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_result", - "not_null": true, - "ordinal": 17, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_hash", - "not_null": true, - "ordinal": 18, - "table_name": "project_guide_compilations" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "component_hashes", - "not_null": true, - "ordinal": 19, - "table_name": "project_guide_compilations" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_compilation_id", - "not_null": false, - "ordinal": 20, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": true, - "ordinal": 21, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": true, - "ordinal": 22, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service_identity", - "not_null": true, - "ordinal": 23, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": true, - "ordinal": 24, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": true, - "ordinal": 25, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_resource_context_digest", - "not_null": true, - "ordinal": 26, - "table_name": "project_guide_compilations" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 27, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_guides" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 3, - "table_name": "project_guides" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "project_guides" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_markdown", - "not_null": true, - "ordinal": 5, - "table_name": "project_guides" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by", - "not_null": false, - "ordinal": 6, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_at", - "not_null": false, - "ordinal": 7, - "table_name": "project_guides" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "change_summary", - "not_null": false, - "ordinal": 8, - "table_name": "project_guides" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 9, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 11, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 12, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutated_by_actor_profile_id", - "not_null": false, - "ordinal": 13, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutated_via_identity_link_id", - "not_null": false, - "ordinal": 14, - "table_name": "project_guides" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutated_by_admin_role_grant_id", - "not_null": false, - "ordinal": 15, - "table_name": "project_guides" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutation_scope_type", - "not_null": false, - "ordinal": 16, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutation_scope_project_id", - "not_null": false, - "ordinal": 17, - "table_name": "project_guides" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutation_action_id", - "not_null": false, - "ordinal": 18, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_authorization_decision_event_id", - "not_null": false, - "ordinal": 19, - "table_name": "project_guides" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "mutation_generation", - "not_null": false, - "ordinal": 20, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_review_policy_id", - "not_null": false, - "ordinal": 21, - "table_name": "project_guides" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_review_policy_hash", - "not_null": false, - "ordinal": 22, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_revision_policy_id", - "not_null": false, - "ordinal": 23, - "table_name": "project_guides" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_revision_policy_hash", - "not_null": false, - "ordinal": 24, - "table_name": "project_guides" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_review_policy_generation", - "not_null": false, - "ordinal": 25, - "table_name": "project_guides" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_revision_policy_generation", - "not_null": false, - "ordinal": 26, - "table_name": "project_guides" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "role", - "not_null": true, - "ordinal": 4, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "project_role_grants" - }, - { - "data_type": "smallint", - "default_expression": "'1'::smallint", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 6, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "'manual'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "grant_method", - "not_null": true, - "ordinal": 7, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "qualification_snapshot_id", - "not_null": true, - "ordinal": 8, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_actor_profile_id", - "not_null": true, - "ordinal": 9, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_admin_role_grant_id", - "not_null": true, - "ordinal": 10, - "table_name": "project_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "grant_reason", - "not_null": true, - "ordinal": 11, - "table_name": "project_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_at", - "not_null": true, - "ordinal": 12, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_actor_profile_id", - "not_null": false, - "ordinal": 13, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_admin_role_grant_id", - "not_null": false, - "ordinal": 14, - "table_name": "project_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_reason", - "not_null": false, - "ordinal": 15, - "table_name": "project_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_at", - "not_null": false, - "ordinal": 16, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requested_role", - "not_null": true, - "ordinal": 4, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "skills_snapshot", - "not_null": true, - "ordinal": 5, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reputation_snapshot", - "not_null": true, - "ordinal": 6, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "prior_project_work_refs", - "not_null": true, - "ordinal": 7, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_expertise_refs", - "not_null": true, - "ordinal": 8, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_by_actor_profile_id", - "not_null": true, - "ordinal": 9, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_by_admin_role_grant_id", - "not_null": true, - "ordinal": 10, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_at", - "not_null": true, - "ordinal": 11, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(155)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "celery_task_id", - "not_null": false, - "ordinal": 7, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 8, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "current_step", - "not_null": true, - "ordinal": 9, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_sufficiency_report_id", - "not_null": false, - "ordinal": 10, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_submission_artifact_policy_id", - "not_null": false, - "ordinal": 11, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_code", - "not_null": false, - "ordinal": 12, - "table_name": "project_setup_runs" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_summary", - "not_null": false, - "ordinal": 13, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 14, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 15, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 16, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "started_at", - "not_null": false, - "ordinal": 17, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "finished_at", - "not_null": false, - "ordinal": 18, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 19, - "table_name": "project_setup_runs" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_submit_derivation_summary", - "not_null": false, - "ordinal": 20, - "table_name": "project_setup_runs" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 21, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorized_by_actor_profile_id", - "not_null": false, - "ordinal": 22, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorized_via_identity_link_id", - "not_null": false, - "ordinal": 23, - "table_name": "project_setup_runs" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorized_by_admin_role_grant_id", - "not_null": false, - "ordinal": 24, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_scope_type", - "not_null": false, - "ordinal": 25, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_scope_project_id", - "not_null": false, - "ordinal": 26, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_action_id", - "not_null": false, - "ordinal": 27, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 28, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_artifact_incident_id", - "not_null": false, - "ordinal": 29, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "continuation_verification_job_id", - "not_null": false, - "ordinal": 30, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "continuation_started_at", - "not_null": false, - "ordinal": 31, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "projects" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "name", - "not_null": true, - "ordinal": 2, - "table_name": "projects" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "slug", - "not_null": true, - "ordinal": 3, - "table_name": "projects" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "description", - "not_null": false, - "ordinal": 4, - "table_name": "projects" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "projects" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 6, - "table_name": "projects" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 7, - "table_name": "projects" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 8, - "table_name": "projects" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 9, - "table_name": "projects" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 10, - "table_name": "projects" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 11, - "table_name": "projects" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 12, - "table_name": "projects" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 13, - "table_name": "projects" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 2, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 3, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 4, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 5, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 6, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 7, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 8, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "admitting_checker_run_id", - "not_null": true, - "ordinal": 9, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_queue_entry_id", - "not_null": false, - "ordinal": 11, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 12, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 13, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_leases" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_queue_entry_id", - "not_null": true, - "ordinal": 2, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 4, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 5, - "table_name": "review_leases" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 6, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reviewer_id", - "not_null": true, - "ordinal": 7, - "table_name": "review_leases" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reviewer_contribution_policy_version_id", - "not_null": true, - "ordinal": 8, - "table_name": "review_leases" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_generation", - "not_null": true, - "ordinal": 9, - "table_name": "review_leases" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "review_leases" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "claimed_at", - "not_null": true, - "ordinal": 11, - "table_name": "review_leases" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "expires_at", - "not_null": true, - "ordinal": 12, - "table_name": "review_leases" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "closed_at", - "not_null": false, - "ordinal": 13, - "table_name": "review_leases" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "close_reason", - "not_null": false, - "ordinal": 14, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "review_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "review_policies" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requires_second_review", - "not_null": true, - "ordinal": 4, - "table_name": "review_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "allowed_decisions", - "not_null": true, - "ordinal": 5, - "table_name": "review_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "minimum_finding_fields", - "not_null": true, - "ordinal": 6, - "table_name": "review_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_generation", - "not_null": true, - "ordinal": 8, - "table_name": "review_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 9, - "table_name": "review_policies" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantics_status", - "not_null": true, - "ordinal": 10, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 11, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_preference_window_seconds", - "not_null": false, - "ordinal": 12, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_lease_duration_seconds", - "not_null": false, - "ordinal": 13, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "max_active_review_leases_per_reviewer", - "not_null": false, - "ordinal": 14, - "table_name": "review_policies" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "self_review_allowed", - "not_null": false, - "ordinal": 15, - "table_name": "review_policies" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reject_policy", - "not_null": false, - "ordinal": 16, - "table_name": "review_policies" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "finding_evidence_requirement", - "not_null": false, - "ordinal": 17, - "table_name": "review_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_policy_hash", - "not_null": false, - "ordinal": 18, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 19, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 20, - "table_name": "review_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 21, - "table_name": "review_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 22, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 23, - "table_name": "review_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 24, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 25, - "table_name": "review_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 3, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 4, - "table_name": "review_queue_entries" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 5, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "admitting_checker_run_id", - "not_null": true, - "ordinal": 6, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(16)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "queue_state", - "not_null": true, - "ordinal": 7, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_mode", - "not_null": true, - "ordinal": 8, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_reason", - "not_null": true, - "ordinal": 9, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "first_queued_at", - "not_null": true, - "ordinal": 10, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "available_since", - "not_null": true, - "ordinal": 11, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "preferred_reviewer_id", - "not_null": false, - "ordinal": 12, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "preference_expires_at", - "not_null": false, - "ordinal": 13, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "closed_at", - "not_null": false, - "ordinal": 14, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "closed_reason", - "not_null": false, - "ordinal": 15, - "table_name": "review_queue_entries" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_generation", - "not_null": true, - "ordinal": 16, - "table_name": "review_queue_entries" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_generation", - "not_null": true, - "ordinal": 17, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 18, - "table_name": "review_queue_entries" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "active_lease_id", - "not_null": false, - "ordinal": 19, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "revision_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "max_revision_rounds", - "not_null": true, - "ordinal": 4, - "table_name": "revision_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revision_deadline_hours", - "not_null": true, - "ordinal": 5, - "table_name": "revision_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "allowed_resubmission_states", - "not_null": true, - "ordinal": 6, - "table_name": "revision_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reviewer_reassignment_rule", - "not_null": false, - "ordinal": 7, - "table_name": "revision_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 8, - "table_name": "revision_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_generation", - "not_null": true, - "ordinal": 9, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 10, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantics_status", - "not_null": true, - "ordinal": 11, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 12, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_policy_hash", - "not_null": false, - "ordinal": 13, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 14, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 15, - "table_name": "revision_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 16, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 17, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 18, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 19, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 20, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 7, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 8, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_body", - "not_null": true, - "ordinal": 9, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 10, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "derivation_source", - "not_null": true, - "ordinal": 11, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_material_refs", - "not_null": true, - "ordinal": 12, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "derivation_agent_name", - "not_null": false, - "ordinal": 13, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "derivation_agent_version", - "not_null": false, - "ordinal": 14, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 15, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 17, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_role", - "not_null": false, - "ordinal": 18, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_actor", - "not_null": false, - "ordinal": 19, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_at", - "not_null": false, - "ordinal": 20, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 21, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 22, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "change_summary", - "not_null": false, - "ordinal": 23, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 24, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 25, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 26, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service_identity", - "not_null": false, - "ordinal": 27, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 28, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 29, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 30, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_decision_event_id", - "not_null": false, - "ordinal": 31, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_actor_profile_id", - "not_null": false, - "ordinal": 32, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_via_identity_link_id", - "not_null": false, - "ordinal": 33, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_admin_role_grant_id", - "not_null": false, - "ordinal": 34, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_scope_type", - "not_null": false, - "ordinal": 35, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_scope_project_id", - "not_null": false, - "ordinal": 36, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_action_id", - "not_null": false, - "ordinal": 37, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_decision_event_id", - "not_null": false, - "ordinal": 38, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "durable_intent_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_evidence_set_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 4, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_content_id", - "not_null": true, - "ordinal": 5, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 6, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verification_receipt_id", - "not_null": true, - "ordinal": 7, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_operation_receipt_id", - "not_null": false, - "ordinal": 8, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_observation_receipt_id", - "not_null": false, - "ordinal": 9, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 10, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 11, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 12, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 13, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assignment_id", - "not_null": true, - "ordinal": 14, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_id", - "not_null": false, - "ordinal": 15, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_version", - "not_null": false, - "ordinal": 16, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_policy_context_hash", - "not_null": true, - "ordinal": 17, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_id", - "not_null": true, - "ordinal": 18, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_sha256", - "not_null": true, - "ordinal": 19, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_sha256", - "not_null": true, - "ordinal": 20, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_byte_count", - "not_null": true, - "ordinal": 21, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(16)", - "default_expression": "'ready'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 22, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "ready_at", - "not_null": true, - "ordinal": 23, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "consumed_at", - "not_null": false, - "ordinal": 24, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "consumed_by_submission_id", - "not_null": false, - "ordinal": 25, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "stale_at", - "not_null": false, - "ordinal": 26, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "stale_reason", - "not_null": false, - "ordinal": 27, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 28, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_evidence_set_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 4, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity", - "not_null": false, - "ordinal": 4, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 5, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": false, - "ordinal": 6, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 7, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 8, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_json", - "not_null": true, - "ordinal": 9, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 10, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 11, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 12, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 13, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_id", - "not_null": true, - "ordinal": 14, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": false, - "ordinal": 15, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 16, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_task_id", - "not_null": false, - "ordinal": 17, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": false, - "ordinal": 18, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 19, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 20, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_policy_id", - "not_null": false, - "ordinal": 21, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_effective_policy_id", - "not_null": false, - "ordinal": 22, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_pre_submit_policy_id", - "not_null": false, - "ordinal": 23, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 24, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 25, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 2, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contributor_id", - "not_null": true, - "ordinal": 3, - "table_name": "submissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 4, - "table_name": "submissions" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "submissions" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "summary", - "not_null": true, - "ordinal": 6, - "table_name": "submissions" - }, - { - "data_type": "character varying(1000)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "package_uri", - "not_null": false, - "ordinal": 7, - "table_name": "submissions" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "package_hash", - "not_null": true, - "ordinal": 8, - "table_name": "submissions" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_hash_manifest", - "not_null": true, - "ordinal": 9, - "table_name": "submissions" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_attestation", - "not_null": true, - "ordinal": 10, - "table_name": "submissions" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_version", - "not_null": true, - "ordinal": 11, - "table_name": "submissions" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_payment_policy_version", - "not_null": true, - "ordinal": 12, - "table_name": "submissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "submitted_at", - "not_null": true, - "ordinal": 13, - "table_name": "submissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_at", - "not_null": false, - "ordinal": 14, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_submission_id", - "not_null": false, - "ordinal": 15, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_id", - "not_null": false, - "ordinal": 16, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_hash", - "not_null": false, - "ordinal": 17, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_id", - "not_null": false, - "ordinal": 18, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_hash", - "not_null": false, - "ordinal": 19, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_policy_id", - "not_null": false, - "ordinal": 20, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_bundle_hash", - "not_null": false, - "ordinal": 21, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 22, - "table_name": "submissions" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_version", - "not_null": false, - "ordinal": 23, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_hash", - "not_null": false, - "ordinal": 24, - "table_name": "submissions" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_body", - "not_null": false, - "ordinal": 25, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_id", - "not_null": true, - "ordinal": 26, - "table_name": "submissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_generation", - "not_null": true, - "ordinal": 27, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_hash", - "not_null": true, - "ordinal": 28, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_id", - "not_null": true, - "ordinal": 29, - "table_name": "submissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_generation", - "not_null": true, - "ordinal": 30, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_hash", - "not_null": true, - "ordinal": 31, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 2, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contributor_id", - "not_null": true, - "ordinal": 3, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assigned_by", - "not_null": true, - "ordinal": 4, - "table_name": "task_assignments" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "assigned_at", - "not_null": true, - "ordinal": 5, - "table_name": "task_assignments" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "accepted_at", - "not_null": false, - "ordinal": 6, - "table_name": "task_assignments" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "released_at", - "not_null": false, - "ordinal": 7, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 8, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_version", - "not_null": false, - "ordinal": 3, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_payment_policy_version", - "not_null": false, - "ordinal": 4, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_type", - "not_null": true, - "ordinal": 5, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_ref", - "not_null": false, - "ordinal": 6, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_payload_hash", - "not_null": false, - "ordinal": 7, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "import_batch_id", - "not_null": false, - "ordinal": 8, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_task_id", - "not_null": false, - "ordinal": 9, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(300)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "title", - "not_null": true, - "ordinal": 10, - "table_name": "workstream_tasks" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "description", - "not_null": true, - "ordinal": 11, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_type", - "not_null": false, - "ordinal": 12, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "difficulty", - "not_null": false, - "ordinal": 13, - "table_name": "workstream_tasks" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "skill_tags", - "not_null": true, - "ordinal": 14, - "table_name": "workstream_tasks" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "estimated_time_minutes", - "not_null": false, - "ordinal": 15, - "table_name": "workstream_tasks" - }, - { - "data_type": "numeric(12,2)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "base_amount", - "not_null": false, - "ordinal": 16, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "currency", - "not_null": false, - "ordinal": 17, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payout_type", - "not_null": false, - "ordinal": 18, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 19, - "table_name": "workstream_tasks" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "acceptance_criteria", - "not_null": false, - "ordinal": 20, - "table_name": "workstream_tasks" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "rejection_criteria", - "not_null": false, - "ordinal": 21, - "table_name": "workstream_tasks" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deadline_at", - "not_null": false, - "ordinal": 22, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 23, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assigned_to", - "not_null": false, - "ordinal": 24, - "table_name": "workstream_tasks" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 25, - "table_name": "workstream_tasks" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 26, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_id", - "not_null": false, - "ordinal": 27, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_hash", - "not_null": false, - "ordinal": 28, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_id", - "not_null": false, - "ordinal": 29, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_hash", - "not_null": false, - "ordinal": 30, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_policy_id", - "not_null": false, - "ordinal": 31, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_bundle_hash", - "not_null": false, - "ordinal": 32, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 33, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_version", - "not_null": false, - "ordinal": 34, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_hash", - "not_null": false, - "ordinal": 35, - "table_name": "workstream_tasks" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_body", - "not_null": false, - "ordinal": 36, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_id", - "not_null": false, - "ordinal": 37, - "table_name": "workstream_tasks" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_generation", - "not_null": false, - "ordinal": 38, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_hash", - "not_null": false, - "ordinal": 39, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_id", - "not_null": false, - "ordinal": 40, - "table_name": "workstream_tasks" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_generation", - "not_null": false, - "ordinal": 41, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_hash", - "not_null": false, - "ordinal": 42, - "table_name": "workstream_tasks" - } - ], - "constraints": [ - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "actor_identity_link_profile_guard", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (subject_kind::text = 'service'::text OR last_verified_at IS NOT NULL)", - "kind": "c", - "name": "ck_actor_identity_links_human_verified", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_actor_identity_links_id_uuid", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (length(btrim(issuer::text)) >= 1 AND length(btrim(issuer::text)) <= 200)", - "kind": "c", - "name": "ck_actor_identity_links_issuer", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK ((revoked_reason IS NULL OR revoked_reason::text = btrim(revoked_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(revoked_reason::text) >= 1 AND octet_length(revoked_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500))", - "kind": "c", - "name": "ck_actor_identity_links_lifecycle_reason_bounds", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_identity_links_reactivation_fields", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (status::text = 'active'::text AND revoked_by IS NULL AND revoked_at IS NULL AND revoked_reason IS NULL OR status::text = 'revoked'::text AND revoked_by IS NOT NULL AND revoked_at IS NOT NULL AND revoked_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_identity_links_revocation_fields", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'revoked']))", - "kind": "c", - "name": "ck_actor_identity_links_status", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (length(btrim(subject::text)) >= 1 AND length(btrim(subject::text)) <= 200)", - "kind": "c", - "name": "ck_actor_identity_links_subject", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (subject_kind::text = ANY (ARRAY['human', 'service']))", - "kind": "c", - "name": "ck_actor_identity_links_subject_kind", - "table_name": "actor_identity_links" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_actor_identity_links_actor_profile_id_actor_profiles", - "table_name": "actor_identity_links" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_actor_identity_links", - "table_name": "actor_identity_links" - }, - { - "definition": "UNIQUE (actor_profile_id)", - "kind": "u", - "name": "uq_actor_identity_links_actor_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "UNIQUE (issuer, subject)", - "kind": "u", - "name": "uq_actor_identity_links_external_identity", - "table_name": "actor_identity_links" - }, - { - "definition": "UNIQUE (id, actor_profile_id)", - "kind": "u", - "name": "uq_actor_identity_links_id_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (classified_count = 0 AND manifest_sha256 IS NULL AND envelope_sha256 IS NULL OR classified_count > 0 AND manifest_sha256 IS NOT NULL AND envelope_sha256 IS NOT NULL)", - "kind": "c", - "name": "ck_actor_profile_migration_state_evidence", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CHECK (service_identity_mapped_count >= 0 AND service_identity_mapped_count <= 7 AND service_identity_source_row_set_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_database_binding::text ~ '^postgres-v1:[0-9a-f]{64}$'::text AND (service_identity_mapped_count = 0 AND service_identity_manifest_sha256 IS NULL AND service_identity_envelope_sha256 IS NULL OR service_identity_mapped_count >= 1 AND service_identity_mapped_count <= 7 AND service_identity_manifest_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_envelope_sha256::text ~ '^[0-9a-f]{64}$'::text))", - "kind": "c", - "name": "ck_actor_profile_migration_state_service_identity_evidence", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CHECK (id = 1 AND schema_version = 1 AND classified_count >= 0)", - "kind": "c", - "name": "ck_actor_profile_migration_state_singleton", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_actor_profile_migration_state", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "actor_profile_link_guard", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (actor_kind::text = ANY (ARRAY['human', 'service']))", - "kind": "c", - "name": "ck_actor_profiles_actor_kind", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_actor_profiles_id_uuid", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (actor_kind::text = 'human'::text AND provisioning_method::text = 'automatic_first_access'::text OR actor_kind::text = 'service'::text AND provisioning_method::text = 'manual_service_provisioning'::text)", - "kind": "c", - "name": "ck_actor_profiles_kind_provisioning", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (actor_kind::text = 'human'::text AND service_identity IS NULL OR actor_kind::text = 'service'::text AND (service_identity::text = ANY (ARRAY['workstream.artifact.verifier', 'workstream.artifact.put_resolver', 'workstream.artifact.scheduler', 'workstream.artifact.binding', 'workstream.artifact.guide_reader', 'workstream.artifact.materializer', 'workstream.artifact.checker_output', 'workstream.project.setup', 'workstream.review.preference_expiry', 'workstream.review.lease_expiry', 'workstream.review.authority_invalidation_reconciliation', 'workstream.review.reconciliation', 'workstream.review.artifact_reference_reconciliation', 'workstream.review.projection'])))", - "kind": "c", - "name": "ck_actor_profiles_kind_service_identity", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (status::text = 'active'::text AND suspended_by IS NULL AND suspended_at IS NULL AND suspension_reason IS NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'suspended'::text AND suspended_by IS NOT NULL AND suspended_at IS NOT NULL AND suspension_reason IS NOT NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'deactivated'::text AND deactivated_by IS NOT NULL AND deactivated_at IS NOT NULL AND deactivation_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_profiles_lifecycle_fields", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK ((suspension_reason IS NULL OR suspension_reason::text = btrim(suspension_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(suspension_reason::text) >= 1 AND octet_length(suspension_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500) AND (deactivation_reason IS NULL OR deactivation_reason::text = btrim(deactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(deactivation_reason::text) >= 1 AND octet_length(deactivation_reason::text) <= 500))", - "kind": "c", - "name": "ck_actor_profiles_lifecycle_reason_bounds", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (provisioning_method::text = ANY (ARRAY['automatic_first_access', 'manual_service_provisioning']))", - "kind": "c", - "name": "ck_actor_profiles_provisioning_method", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_profiles_reactivation_fields", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'deactivated']))", - "kind": "c", - "name": "ck_actor_profiles_status", - "table_name": "actor_profiles" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_actor_profiles", - "table_name": "actor_profiles" - }, - { - "definition": "UNIQUE (service_identity)", - "kind": "u", - "name": "service_identity", - "table_name": "actor_profiles" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "admin_role_grants_bootstrap_invariant", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (granted_by_system_principal::text = 'workstream:system:bootstrap'::text AND granted_by_actor_profile_id IS NULL AND granted_by_admin_role_grant_id IS NULL OR granted_by_system_principal IS NULL AND granted_by_actor_profile_id IS NOT NULL AND granted_by_admin_role_grant_id IS NOT NULL)", - "kind": "c", - "name": "ck_admin_role_grants_grant_attribution", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (octet_length(grant_reason) >= 1 AND octet_length(grant_reason) <= 500)", - "kind": "c", - "name": "ck_admin_role_grants_grant_reason", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND octet_length(revoked_reason) >= 1 AND octet_length(revoked_reason) <= 500 AND revoked_at IS NOT NULL)", - "kind": "c", - "name": "ck_admin_role_grants_lifecycle", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (role::text = ANY (ARRAY['access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority']))", - "kind": "c", - "name": "ck_admin_role_grants_role", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (scope_type::text = 'system'::text AND scope_project_id IS NULL OR scope_type::text = 'project'::text AND scope_project_id IS NOT NULL AND (role::text <> ALL (ARRAY['access_administrator', 'operator'])))", - "kind": "c", - "name": "ck_admin_role_grants_role_scope", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (scope_type::text = ANY (ARRAY['system', 'project']))", - "kind": "c", - "name": "ck_admin_role_grants_scope_type", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_admin_role_grants_granted_by_admin_role_grant_id_adm_81e0", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_admin_role_grants_revoked_by_admin_role_grant_id_adm_78b5", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_admin_role_grants_scope_project_id_projects", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (target_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_admin_role_grants_target_actor_profile_id_actor_profiles", - "table_name": "admin_role_grants" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_admin_role_grants", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (octet_length(key_digest) = 32)", - "kind": "c", - "name": "ck_api_rate_control_counters_digest_length", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (request_count >= 1 AND request_count <= '9223372036854775807'::bigint)", - "kind": "c", - "name": "ck_api_rate_control_counters_request_count", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (control_scope::text = ANY (ARRAY['first_access', 'admin_mutation', 'authorization_read']))", - "kind": "c", - "name": "ck_api_rate_control_counters_scope_token", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (window_started_at < window_expires_at)", - "kind": "c", - "name": "ck_api_rate_control_counters_window_order", - "table_name": "api_rate_control_counters" - }, - { - "definition": "PRIMARY KEY (control_scope, key_digest)", - "kind": "p", - "name": "pk_api_rate_control_counters", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_admission_charges_byte_count_nonnegative", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_admission_charges_cas_nonnegative", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK ((state::text = 'completed'::text) = (completed_at IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_admission_charges_completed_timestamp", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (creating_operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_admission_charges_operation_identity_shape", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", - "kind": "c", - "name": "ck_artifact_admission_charges_producer_type", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK ((state::text = 'released'::text) = (released_at IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_admission_charges_released_timestamp", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_admission_charges_sha256_shape", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (state::text = ANY (ARRAY['provisional', 'completed', 'released']))", - "kind": "c", - "name": "ck_artifact_admission_charges_state", - "table_name": "artifact_admission_charges" - }, - { - "definition": "FOREIGN KEY (scope_type, scope_id) REFERENCES artifact_admission_scopes(scope_type, scope_id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_admission_charges_scope", - "table_name": "artifact_admission_charges" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_admission_charges", - "table_name": "artifact_admission_charges" - }, - { - "definition": "UNIQUE (scope_type, scope_id, sha256, byte_count)", - "kind": "u", - "name": "uq_artifact_admission_charge_scope_content", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_admission_scopes_cas_nonnegative", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (counted_bytes >= 0 AND counted_bytes <= limit_bytes)", - "kind": "c", - "name": "ck_artifact_admission_scopes_counted_bytes_within_limit", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (limit_bytes > 0)", - "kind": "c", - "name": "ck_artifact_admission_scopes_limit_positive", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (octet_length(scope_id::text) >= 1 AND octet_length(scope_id::text) <= 120)", - "kind": "c", - "name": "ck_artifact_admission_scopes_scope_id_bounds", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (scope_type::text = ANY (ARRAY['deployment', 'project', 'producer', 'task']))", - "kind": "c", - "name": "ck_artifact_admission_scopes_scope_type", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "PRIMARY KEY (scope_type, scope_id)", - "kind": "p", - "name": "pk_artifact_admission_scopes", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (scope_version > 0)", - "kind": "c", - "name": "ck_artifact_bindings_scope_version_positive", - "table_name": "artifact_bindings" - }, - { - "definition": "CHECK (scope_version = 1 AND supersedes_binding_id IS NULL OR scope_version > 1 AND supersedes_binding_id IS NOT NULL)", - "kind": "c", - "name": "ck_artifact_bindings_scope_version_predecessor", - "table_name": "artifact_bindings" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_bindings_content_id_artifact_contents", - "table_name": "artifact_bindings" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_bindings_project_id_projects", - "table_name": "artifact_bindings" - }, - { - "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES artifact_bindings(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_bindings_supersedes_binding_id_artifact_bindings", - "table_name": "artifact_bindings" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_bindings", - "table_name": "artifact_bindings" - }, - { - "definition": "TRIGGER DEFERRABLE", - "kind": "t", - "name": "trg_artifact_binding_history", - "table_name": "artifact_bindings" - }, - { - "definition": "UNIQUE (project_id, resource_type, resource_id, logical_role, scope_version)", - "kind": "u", - "name": "uq_artifact_binding_scope_version", - "table_name": "artifact_bindings" - }, - { - "definition": "UNIQUE (supersedes_binding_id)", - "kind": "u", - "name": "uq_artifact_binding_supersedes", - "table_name": "artifact_bindings" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_contents_byte_count_nonnegative", - "table_name": "artifact_contents" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_contents_sha256_shape", - "table_name": "artifact_contents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_contents", - "table_name": "artifact_contents" - }, - { - "definition": "UNIQUE (sha256, byte_count)", - "kind": "u", - "name": "uq_artifact_content_digest_size", - "table_name": "artifact_contents" - }, - { - "definition": "CHECK (attempt_number > 0)", - "kind": "c", - "name": "ck_artifact_operation_receipts_attempt_positive", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (contract_version = 2 AND put_attempt_id IS NOT NULL AND (guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND logical_role IS NULL OR guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR guide_source_item_id IS NULL AND checker_run_id IS NULL AND logical_role IS NULL))", - "kind": "c", - "name": "ck_artifact_operation_receipts_contract_producer_reference", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (operation::text = 'put'::text)", - "kind": "c", - "name": "ck_artifact_operation_receipts_operation", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (outcome::text = 'stored_pending_verification'::text)", - "kind": "c", - "name": "ck_artifact_operation_receipts_outcome", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_operation_receipts_request_digest_shape", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_operation_receipts_replica_id_artifact_replicas", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_receipt_checker_run", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_receipt_guide_item", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_receipt_put_attempt", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_operation_receipts", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "UNIQUE (put_attempt_id)", - "kind": "u", - "name": "uq_artifact_receipt_put_attempt", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempt_charges_attempt_id_artifact_put_b25d", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "FOREIGN KEY (charge_id) REFERENCES artifact_admission_charges(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempt_charges_charge_id_artifact_admi_85a9", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "PRIMARY KEY (attempt_id, charge_id)", - "kind": "p", - "name": "pk_artifact_put_attempt_charges", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_put_attempts_byte_count_nonnegative", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (canonical_target::text ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_canonical_target_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (execution_mode IS NULL OR (execution_mode::text = ANY (ARRAY['caller_put', 'observation'])))", - "kind": "c", - "name": "ck_artifact_put_attempts_execution_mode", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", - "kind": "c", - "name": "ck_artifact_put_attempts_executor_lease_pair", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK ((status::text = 'put_in_flight'::text) = (executor_id IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_put_attempts_inflight_fence", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (observation_count >= 0 AND maximum_observations > 0)", - "kind": "c", - "name": "ck_artifact_put_attempts_observation_counts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_operation_identity_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (status::text <> 'prepared'::text OR next_run_at IS NULL AND executor_id IS NULL AND lease_expires_at IS NULL AND execution_generation = 0 AND terminal_result_code IS NULL AND terminal_at IS NULL AND replica_id IS NULL AND receipt_id IS NULL)", - "kind": "c", - "name": "ck_artifact_put_attempts_prepared_execution_inactive", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_request_type::text = 'guide'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text OR producer_request_type::text = 'checker_output'::text AND producer_type::text = 'service_identity'::text AND producer_ref::text = 'workstream.artifact.checker_output'::text OR producer_request_type::text = 'submission_bundle'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_identity", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_request_type::text = 'guide'::text AND guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND task_id IS NULL AND logical_role IS NULL OR producer_request_type::text = 'checker_output'::text AND guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND task_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR producer_request_type::text = 'submission_bundle'::text AND guide_source_item_id IS NULL AND checker_run_id IS NULL AND task_id IS NOT NULL AND logical_role IS NULL)", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_reference", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_request_type::text = ANY (ARRAY['guide', 'checker_output', 'submission_bundle']))", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_request_type", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_type", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_request_digest_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_sha256_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['prepared', 'put_in_flight', 'acknowledgement_unknown', 'object_confirmed', 'absent_replay_required', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", - "kind": "c", - "name": "ck_artifact_put_attempts_status", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (status::text <> 'provider_unavailable'::text OR observation_count >= maximum_observations AND next_run_at IS NULL AND terminal_at IS NOT NULL)", - "kind": "c", - "name": "ck_artifact_put_attempts_unavailable_exhausted", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_put_attempts_versions_nonnegative", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_checker_run_id_checker_runs", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_guide_source_item_id_guide_sou_e48c", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (storage_namespace_id, namespace_fingerprint) REFERENCES artifact_storage_namespaces(id, namespace_fingerprint) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_namespace_fingerprint", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_project_id_projects", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_receipt_id_artifact_operation_receipts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_replica_id_artifact_replicas", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_task_id_workstream_tasks", - "table_name": "artifact_put_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_put_attempts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "UNIQUE (operation_identity)", - "kind": "u", - "name": "uq_artifact_put_attempt_operation", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (expected_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_expected_sha256", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (expected_byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_expected_size", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK ((outcome::text = ANY (ARRAY['observed_confirmed', 'observed_integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_observed_facts", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_observed_sha256", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_observed_size", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (outcome::text = ANY (ARRAY['observed_confirmed', 'observed_missing', 'observed_integrity_mismatch', 'conflict']))", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_outcome", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_observation_receipts_put_attempt_id_art_237d", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_put_observation_receipts", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "UNIQUE (put_attempt_id, execution_generation)", - "kind": "u", - "name": "uq_artifact_put_observation_fence", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_cas_nonnegative", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (source_verification_job_id::text <> retry_verification_job_id::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_distinct_jobs", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (recovery_class::text = 'provider_observation'::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_recovery_class", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_request_digest", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['requested', 'succeeded', 'failed']))", - "kind": "c", - "name": "ck_artifact_recovery_attempts_status", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (status::text = 'succeeded'::text AND terminal_result_code::text = 'verified'::text OR status::text = 'failed'::text AND (terminal_result_code::text = ANY (ARRAY['provider_unavailable', 'missing', 'integrity_mismatch', 'conflict'])) OR status::text = 'requested'::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_terminal_result", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (status::text = 'requested'::text AND terminal_result_code IS NULL AND terminal_at IS NULL AND terminal_audit_event_id IS NULL OR (status::text = ANY (ARRAY['succeeded', 'failed'])) AND terminal_result_code IS NOT NULL AND terminal_at IS NOT NULL AND terminal_audit_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_terminal_shape", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (initiation_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_initiation_audit_event_id_2af7", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (parent_recovery_attempt_id) REFERENCES artifact_recovery_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_parent_recovery_attempt_i_130d", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_project_id_projects", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (requester_actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_requester_actor_profile_i_77f5", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (requester_identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_requester_identity_link_i_3619", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (retry_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_retry_verification_job_id_b330", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (source_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_source_verification_job_i_5eac", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_submission_id_submissions", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_task_id_workstream_tasks", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (terminal_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_terminal_audit_event_id_a_47ab", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_recovery_attempts", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "UNIQUE (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", - "kind": "u", - "name": "uq_artifact_recovery_idempotency", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "UNIQUE (retry_verification_job_id)", - "kind": "u", - "name": "uq_artifact_recovery_retry_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "UNIQUE (source_verification_job_id)", - "kind": "u", - "name": "uq_artifact_recovery_source_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (availability_state::text = ANY (ARRAY['unknown', 'available', 'unavailable']))", - "kind": "c", - "name": "ck_artifact_replicas_availability_state", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_replicas_fingerprint_shape", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (integrity_state::text = ANY (ARRAY['unknown', 'valid', 'invalid']))", - "kind": "c", - "name": "ck_artifact_replicas_integrity_state", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (verification_state::text = ANY (ARRAY['pending', 'verified', 'missing', 'integrity_mismatch']))", - "kind": "c", - "name": "ck_artifact_replicas_verification_state", - "table_name": "artifact_replicas" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_replicas_content_id_artifact_contents", - "table_name": "artifact_replicas" - }, - { - "definition": "FOREIGN KEY (storage_namespace_id) REFERENCES artifact_storage_namespaces(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_replicas_storage_namespace_id_artifact_stor_d6cc", - "table_name": "artifact_replicas" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_replicas", - "table_name": "artifact_replicas" - }, - { - "definition": "UNIQUE (storage_namespace_id, provider_object_ref)", - "kind": "u", - "name": "uq_artifact_replica_provider_object", - "table_name": "artifact_replicas" - }, - { - "definition": "UNIQUE (id, content_id)", - "kind": "u", - "name": "uq_artifact_replicas_id_content", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_storage_namespaces_fingerprint_shape", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CHECK (id::text = 'primary'::text)", - "kind": "c", - "name": "ck_artifact_storage_namespaces_singleton_id", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_storage_namespaces", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "UNIQUE (namespace_fingerprint)", - "kind": "u", - "name": "uq_artifact_storage_namespace_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "UNIQUE (id, namespace_fingerprint)", - "kind": "u", - "name": "uq_artifact_storage_namespace_id_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CHECK (attempt_count >= 0 AND maximum_attempts > 0)", - "kind": "c", - "name": "ck_artifact_verification_jobs_attempts", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", - "kind": "c", - "name": "ck_artifact_verification_jobs_fence_pair", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK ((status::text = 'running'::text) = (executor_id IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_verification_jobs_running_fence", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'running', 'verified', 'missing', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", - "kind": "c", - "name": "ck_artifact_verification_jobs_status", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK (status::text <> 'provider_unavailable'::text OR next_run_at IS NOT NULL AND terminal_at IS NULL AND attempt_count < maximum_attempts OR next_run_at IS NULL AND terminal_at IS NOT NULL AND attempt_count >= maximum_attempts)", - "kind": "c", - "name": "ck_artifact_verification_jobs_unavailable_retryability", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_verification_jobs_versions", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "FOREIGN KEY (originating_put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_jobs_originating_put_attempt_i_3260", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_jobs_replica_id_artifact_replicas", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "FOREIGN KEY (parent_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_parent", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_verification_jobs", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "UNIQUE (parent_verification_job_id)", - "kind": "u", - "name": "uq_artifact_verification_parent", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK ((outcome::text = ANY (ARRAY['verified', 'integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_verification_receipts_observed_facts", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_verification_receipts_observed_sha256", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_verification_receipts_observed_size", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (outcome::text = ANY (ARRAY['verified', 'missing', 'integrity_mismatch', 'conflict']))", - "kind": "c", - "name": "ck_artifact_verification_receipts_outcome", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "FOREIGN KEY (verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_receipts_verification_job_id_a_dabf", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_verification_receipts", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "UNIQUE (verification_job_id, execution_generation)", - "kind": "u", - "name": "uq_artifact_verification_fence", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND (entity_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'authorization_decision', 'authority_invalidation'])) AND entity_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND ((actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile'])) AND actor_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR actor_ref_kind::text = 'system_principal'::text AND actor_id::text = 'workstream:system:bootstrap'::text) AND (target_actor_ref IS NULL OR target_actor_ref_kind::text = 'actor_profile'::text AND target_actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (matched_grant_id IS NULL OR matched_grant_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (project_id IS NULL OR project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (resource_type IS NULL OR (resource_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'project', 'qualification_snapshot', 'project_role_grant', 'task', 'submission', 'review', 'contribution', 'compensation_award', 'compensation_delivery', 'operations', 'audit_event', 'project_create_operation', 'project_submission_artifact_policy_mutation', 'project_guide_compilation_attempt', 'project_guide_compilation_request']))) AND (resource_id IS NULL OR resource_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (target_ref_kind IS NULL OR (target_ref_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'project'])) AND target_ref_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR target_ref_kind::text = 'permission_registry'::text AND (target_ref_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND (invalidation_target_kind IS NULL OR (invalidation_target_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant'])) AND invalidation_target_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR invalidation_target_kind::text = 'permission_registry'::text AND (invalidation_target_ref::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND ((entity_type::text <> ALL (ARRAY['authorization_decision', 'authority_invalidation'])) OR entity_id::text = id::text) AND (resource_type::text <> 'project'::text OR resource_id IS NULL OR project_id IS NOT NULL AND resource_id::text = project_id::text))", - "kind": "c", - "name": "ck_audit_events_authority_privacy_bounds", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR reason IS NOT NULL AND (event_type::text = 'ActorProfileProvisioned'::text AND reason = 'automatic_first_access'::text OR event_type::text = 'ServiceActorProvisioned'::text AND reason = 'manual_service_provisioning'::text OR event_type::text = 'ActorIdentityLinked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkRevoked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkReactivated'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorProfileSuspended'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'ActorProfileReactivated'::text AND reason = 'administrative_correction'::text OR event_type::text = 'ActorProfileDeactivated'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'InitialAccessAdministratorBootstrapped'::text AND reason = 'initial_access_bootstrap'::text OR event_type::text = 'AdminRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'AdminRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'AdminRoleGrantIssueDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'LastAccessAdministratorOperationDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'ProjectRoleQualificationSnapshotCaptured'::text AND reason = 'qualification_evidence_captured'::text OR event_type::text = 'ProjectRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'ProjectRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'SensitiveAuthorizationDenied'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'AuthorityInvalidationRequested'::text AND reason = 'authority_state_changed'::text) AND (permission_id IS NULL OR (permission_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.execute', 'project.guide_compilation.request']))) AND (denial_code IS NULL OR (denial_code::text = ANY (ARRAY['required_scope_missing', 'unsupported_subject_kind', 'service_actor_not_provisioned', 'identity_link_revoked', 'actor_suspended', 'actor_deactivated', 'permission_not_granted', 'scope_not_authorized', 'self_grant_forbidden', 'self_role_revoke_forbidden', 'resource_guard_denied', 'actor_not_found', 'grant_not_found', 'resource_not_found', 'actor_already_suspended', 'actor_not_suspended', 'actor_deactivated_terminal', 'last_access_administrator', 'admin_role_grant_exists', 'project_role_grant_exists', 'identity_link_conflict', 'project_role_grant_already_revoked', 'project_role_grant_replay_state_changed', 'identity_link_already_revoked', 'identity_link_not_revoked', 'resource_project_mismatch', 'idempotency_mismatch', 'invalid_role_scope', 'invalid_project_role', 'qualification_snapshot_invalid']))))", - "kind": "c", - "name": "ck_audit_events_authority_registries", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text = ANY (ARRAY['ActorProfileProvisioned', 'ServiceActorProvisioned', 'ActorIdentityLinked', 'ActorIdentityLinkRevoked', 'ActorIdentityLinkReactivated', 'ActorProfileSuspended', 'ActorProfileReactivated', 'ActorProfileDeactivated', 'InitialAccessAdministratorBootstrapped', 'AdminRoleGrantIssued', 'AdminRoleGrantRevoked', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied', 'ProjectRoleQualificationSnapshotCaptured', 'ProjectRoleGrantIssued', 'ProjectRoleGrantReplaced', 'ProjectRoleGrantRevoked', 'SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested'])))", - "kind": "c", - "name": "ck_audit_events_authority_tokens", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND action_id IS NULL OR event_domain::text = 'authority'::text AND (action_id IS NULL OR (event_type::text = ANY (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied'])) AND permission_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)) AND (permission_id IS NULL OR (permission_id::text <> ALL (ARRAY['operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'project.guide_compilation.request', 'project.guide_compilation.execute'])) OR action_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)))", - "kind": "c", - "name": "ck_audit_events_authorization_action_evidence", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND event_version IS NULL AND occurred_at IS NULL AND actor_ref_kind IS NULL AND request_id IS NULL AND correlation_id IS NULL AND target_actor_ref_kind IS NULL AND target_actor_ref IS NULL AND matched_grant_id IS NULL AND permission_id IS NULL AND project_id IS NULL AND resource_type IS NULL AND resource_id IS NULL AND target_ref_kind IS NULL AND target_ref_id IS NULL AND denial_code IS NULL AND idempotency_reference IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND invalidation_target_ref IS NULL AND before_facts IS NULL AND after_facts IS NULL AND external_subject IS NOT NULL AND external_issuer IS NOT NULL OR event_domain::text = 'authority'::text AND event_version = 1 AND occurred_at IS NOT NULL AND (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal'])) AND request_id IS NOT NULL AND correlation_id IS NOT NULL AND from_status IS NULL AND to_status IS NULL AND reason IS NOT NULL AND external_subject IS NULL AND external_issuer IS NULL AND actor_roles::jsonb = '[]'::jsonb AND claim_snapshot::jsonb = '{}'::jsonb AND auth_source::text = 'local_authority'::text AND is_dev_auth = false AND event_payload::jsonb = '{}'::jsonb)", - "kind": "c", - "name": "ck_audit_events_domain_shape", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR (before_facts IS NULL OR octet_length(before_facts::text) <= 4096) AND (after_facts IS NULL OR octet_length(after_facts::text) <= 4096) AND COALESCE(authority_event_facts_are_safe(event_type::text, before_facts, after_facts, project_id::text), false))", - "kind": "c", - "name": "ck_audit_events_fact_bounds", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text <> ALL (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) OR (event_type::text = ANY (ARRAY['AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) AND denial_code IS NOT NULL OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND permission_id IS NOT NULL AND denial_code IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL OR event_type::text = 'SensitiveAuthorizationDenied'::text AND permission_id IS NOT NULL AND denial_code IS NOT NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND idempotency_reference IS NULL OR event_type::text = 'AuthorityInvalidationRequested'::text AND invalidation_cause_event_id IS NOT NULL AND invalidation_target_kind IS NOT NULL AND denial_code IS NULL)", - "kind": "c", - "name": "ck_audit_events_foundation_shapes", - "table_name": "audit_events" - }, - { - "definition": "CHECK ((target_actor_ref_kind IS NULL) = (target_actor_ref IS NULL) AND (resource_type IS NOT NULL OR resource_id IS NULL) AND (target_ref_kind IS NULL) = (target_ref_id IS NULL) AND (invalidation_target_kind IS NULL) = (invalidation_target_ref IS NULL) AND (invalidation_cause_event_id IS NULL OR invalidation_cause_event_id::text <> id::text))", - "kind": "c", - "name": "ck_audit_events_reference_pairs", - "table_name": "audit_events" - }, - { - "definition": "FOREIGN KEY (idempotency_reference, actor_ref_kind, actor_id) REFERENCES authority_idempotency_records(id, actor_ref_kind, actor_ref) NOT VALID", - "kind": "f", - "name": "fk_audit_events_authority_idempotency", - "table_name": "audit_events" - }, - { - "definition": "FOREIGN KEY (invalidation_cause_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_audit_events_invalidation_cause", - "table_name": "audit_events" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_audit_events", - "table_name": "audit_events" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "authority_control_bootstrap_invariant", - "table_name": "authority_control" - }, - { - "definition": "CHECK (bootstrap_completed = false AND bootstrap_grant_id IS NULL AND version = 0 OR bootstrap_completed = true AND bootstrap_grant_id IS NOT NULL AND version = 1)", - "kind": "c", - "name": "ck_authority_control_bootstrap_state", - "table_name": "authority_control" - }, - { - "definition": "CHECK (id = 1)", - "kind": "c", - "name": "ck_authority_control_singleton", - "table_name": "authority_control" - }, - { - "definition": "FOREIGN KEY (bootstrap_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_authority_control_bootstrap_grant_id_admin_role_grants", - "table_name": "authority_control" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_authority_control", - "table_name": "authority_control" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "authority_idempotency_pending_guard", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal']))", - "kind": "c", - "name": "ck_authority_idempotency_records_actor_kind", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (actor_ref_kind::text = 'system_principal'::text AND actor_ref::text = 'workstream:system:bootstrap'::text OR actor_ref_kind::text <> 'system_principal'::text AND actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_authority_idempotency_records_actor_reference", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'admin_role_grant.revoke', 'project_role_grant.issue', 'project_role_grant.revoke', 'actor_profile.suspend', 'actor_profile.reactivate', 'actor_profile.deactivate', 'actor_identity_link.revoke', 'actor_identity_link.reactivate']))", - "kind": "c", - "name": "ck_authority_idempotency_records_operation", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_authority_idempotency_records_request_digest", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (response_http_status IS NULL OR (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 201 OR (operation::text <> ALL (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 200)", - "kind": "c", - "name": "ck_authority_idempotency_records_response_status", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (operation::text = 'service_actor.create'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'admin_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'admin_role_grant'::text) OR operation::text ~~ 'project_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'project_role_grant'::text) OR operation::text ~~ 'actor_profile.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'actor_identity_link.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_identity_link'::text))", - "kind": "c", - "name": "ck_authority_idempotency_records_response_type", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (response_resource_version IS NULL OR response_resource_version > 0)", - "kind": "c", - "name": "ck_authority_idempotency_records_response_version", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_resource_type IS NULL AND response_resource_id IS NULL AND response_resource_version IS NULL AND response_http_status IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_resource_type IS NOT NULL AND response_resource_id IS NOT NULL AND response_http_status IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_authority_idempotency_records_state_shape", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_authority_idempotency_records_status", - "table_name": "authority_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_authority_idempotency_records", - "table_name": "authority_idempotency_records" - }, - { - "definition": "UNIQUE (id, actor_ref_kind, actor_ref)", - "kind": "u", - "name": "uq_authority_idempotency_records_actor_reference", - "table_name": "authority_idempotency_records" - }, - { - "definition": "UNIQUE (actor_ref_kind, actor_ref, operation, idempotency_key)", - "kind": "u", - "name": "uq_authority_idempotency_records_replay_namespace", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", - "kind": "c", - "name": "ck_checker_policies_approval_provenance", - "table_name": "checker_policies" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'superseded'::text OR superseded_at IS NOT NULL AND (superseded_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND superseded_by_actor IS NOT NULL AND (supersession_kind::text = ANY (ARRAY['correction_requested', 'upstream_policy_changed'])) AND supersession_reason IS NOT NULL AND length(btrim(supersession_reason)) > 0)", - "kind": "c", - "name": "ck_checker_policies_correction_provenance", - "table_name": "checker_policies" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['compiled', 'approved', 'superseded']))", - "kind": "c", - "name": "ck_checker_policies_lifecycle_status", - "table_name": "checker_policies" - }, - { - "definition": "CHECK (policy_hash IS NULL OR policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_checker_policies_policy_hash_shape", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_checker_policies_effective_policy_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_checker_policies_guide_id_project_guides", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (pre_submit_checker_policy_id, pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", - "kind": "f", - "name": "fk_checker_policies_pre_submit_checker_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_checker_policies_project_guide", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_checker_policies_project_id_projects", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_checker_policies_source_snapshot_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES checker_policies(id)", - "kind": "f", - "name": "fk_checker_policies_supersedes_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_checker_policies", - "table_name": "checker_policies" - }, - { - "definition": "UNIQUE (id, guide_version, policy_hash)", - "kind": "u", - "name": "uq_checker_policies_id_version_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_checker_results_checker_run_id_checker_runs", - "table_name": "checker_results" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_checker_results_submission_id_submissions", - "table_name": "checker_results" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_checker_results_task_id_workstream_tasks", - "table_name": "checker_results" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_checker_results", - "table_name": "checker_results" - }, - { - "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", - "kind": "c", - "name": "ck_checker_runs_post_submit_policy_lock_complete", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (audit_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_checker_runs_audit_event_id_audit_events", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", - "kind": "f", - "name": "fk_checker_runs_locked_post_submit_policy_hash", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_checker_runs_submission_id_submissions", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (submission_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES submissions(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "f", - "name": "fk_checker_runs_submission_locked_post_submit_policy_hash", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_checker_runs_submission_version", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (supersedes_checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_checker_runs_supersedes_checker_run_id_checker_runs", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_checker_runs_task_id_workstream_tasks", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", - "kind": "f", - "name": "fk_checker_runs_task_locked_guide", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", - "kind": "f", - "name": "fk_checker_runs_task_locked_payment_policy", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "kind": "f", - "name": "fk_checker_runs_task_locked_review_policy", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "kind": "f", - "name": "fk_checker_runs_task_locked_revision_policy", - "table_name": "checker_runs" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_checker_runs", - "table_name": "checker_runs" - }, - { - "definition": "UNIQUE (submission_id, attempt_number)", - "kind": "u", - "name": "uq_checker_runs_submission_attempt", - "table_name": "checker_runs" - }, - { - "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", - "kind": "c", - "name": "ck_contribution_award_definitions_contribution_type", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", - "kind": "c", - "name": "ck_contribution_award_definitions_instrument_type", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (instrument_type::text <> 'project_points'::text OR scale(quantity) = 0)", - "kind": "c", - "name": "ck_contribution_award_definitions_project_points_whole", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (quantity > 0::numeric AND quantity < '100000000000000000000'::numeric AND scale(quantity) >= 0 AND scale(quantity) <= 18)", - "kind": "c", - "name": "ck_contribution_award_definitions_quantity_exact_bounds", - "table_name": "contribution_award_definitions" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_award_definitions_graph_guard", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (adapter_binding_id, project_id, instrument_type) REFERENCES project_compensation_adapter_bindings(id, project_id, instrument_type)", - "kind": "f", - "name": "fk_contribution_award_definition_binding", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_award_definition_project", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (contribution_rule_id, contribution_policy_version_id, project_id, contribution_type) REFERENCES contribution_rules(id, contribution_policy_version_id, project_id, contribution_type)", - "kind": "f", - "name": "fk_contribution_award_definition_rule", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (project_id, instrument_type, unit_code) REFERENCES project_compensation_units(project_id, instrument_type, unit_code)", - "kind": "f", - "name": "fk_contribution_award_definition_unit", - "table_name": "contribution_award_definitions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_award_definitions", - "table_name": "contribution_award_definitions" - }, - { - "definition": "UNIQUE (contribution_rule_id, instrument_type)", - "kind": "u", - "name": "uq_contribution_award_definition_instrument", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (status::text = 'draft'::text AND current_published_version_id IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'active'::text AND current_published_version_id IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND current_published_version_id IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", - "kind": "c", - "name": "ck_contribution_policies_lifecycle_shape", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (char_length(btrim(name::text)) >= 1 AND char_length(btrim(name::text)) <= 200)", - "kind": "c", - "name": "ck_contribution_policies_name", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", - "kind": "c", - "name": "ck_contribution_policies_retirement_timestamp", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['draft', 'active', 'retired']))", - "kind": "c", - "name": "ck_contribution_policies_status", - "table_name": "contribution_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_policies_graph_guard", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_created_by", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (current_published_version_id, id, project_id) REFERENCES contribution_policy_versions(id, contribution_policy_id, project_id) DEFERRABLE INITIALLY DEFERRED", - "kind": "f", - "name": "fk_contribution_policy_current_version", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_policy_project", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_retired_by", - "table_name": "contribution_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_policies", - "table_name": "contribution_policies" - }, - { - "definition": "UNIQUE (id, project_id)", - "kind": "u", - "name": "uq_contribution_policy_ownership", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (status::text = 'draft'::text AND published_by IS NULL AND published_at IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'published'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", - "kind": "c", - "name": "ck_contribution_policy_versions_lifecycle_shape", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK ((published_at IS NULL OR published_at >= created_at) AND (retired_at IS NULL OR retired_at >= published_at))", - "kind": "c", - "name": "ck_contribution_policy_versions_lifecycle_timestamps", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['draft', 'published', 'retired']))", - "kind": "c", - "name": "ck_contribution_policy_versions_status", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK (version_number > 0)", - "kind": "c", - "name": "ck_contribution_policy_versions_version_number_positive", - "table_name": "contribution_policy_versions" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_policy_versions_graph_guard", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_version_created_by", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (contribution_policy_id, project_id) REFERENCES contribution_policies(id, project_id)", - "kind": "f", - "name": "fk_contribution_policy_version_policy", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_policy_version_project", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (published_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_version_published_by", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_version_retired_by", - "table_name": "contribution_policy_versions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_policy_versions", - "table_name": "contribution_policy_versions" - }, - { - "definition": "UNIQUE (contribution_policy_id, version_number)", - "kind": "u", - "name": "uq_contribution_policy_version_number", - "table_name": "contribution_policy_versions" - }, - { - "definition": "UNIQUE (id, contribution_policy_id, project_id)", - "kind": "u", - "name": "uq_contribution_policy_version_ownership", - "table_name": "contribution_policy_versions" - }, - { - "definition": "UNIQUE (id, project_id)", - "kind": "u", - "name": "uq_contribution_policy_version_project", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK (compensation_mode::text = ANY (ARRAY['unpaid', 'compensated']))", - "kind": "c", - "name": "ck_contribution_rules_compensation_mode", - "table_name": "contribution_rules" - }, - { - "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", - "kind": "c", - "name": "ck_contribution_rules_contribution_type", - "table_name": "contribution_rules" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_rules_graph_guard", - "table_name": "contribution_rules" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_rule_project", - "table_name": "contribution_rules" - }, - { - "definition": "FOREIGN KEY (contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", - "kind": "f", - "name": "fk_contribution_rule_version", - "table_name": "contribution_rules" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_rules", - "table_name": "contribution_rules" - }, - { - "definition": "UNIQUE (id, contribution_policy_version_id, project_id, contribution_type)", - "kind": "u", - "name": "uq_contribution_rule_ownership", - "table_name": "contribution_rules" - }, - { - "definition": "UNIQUE (contribution_policy_version_id, contribution_type)", - "kind": "u", - "name": "uq_contribution_rule_type", - "table_name": "contribution_rules" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['approved', 'superseded']))", - "kind": "c", - "name": "ck_effective_project_submission_artifact_policies_ck_ef_7be7", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_effective_project_submission_artifact_policies_ck_ef_bd4e", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "effective_submission_policy_custody", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_effective_policy_creation_actor", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_effective_policy_creation_decision", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_effective_policy_creation_grant", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_effective_policy_creation_link", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_effective_policy_creation_project", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_effective_project_submission_artifact_policies_project_guide", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_effective_psap_guide", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_effective_psap_project", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_effective_psap_source_snapshot_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (submission_artifact_policy_id, submission_artifact_policy_hash) REFERENCES submission_artifact_policies(id, policy_hash)", - "kind": "f", - "name": "fk_effective_psap_submission_policy_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", - "kind": "f", - "name": "fk_effective_psap_supersedes", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_effective_project_submission_artifact_policies", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "UNIQUE (id, effective_policy_hash)", - "kind": "u", - "name": "uq_effective_project_submission_artifact_policies_id_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_evidence_items_submission_id_submissions", - "table_name": "evidence_items" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_evidence_items", - "table_name": "evidence_items" - }, - { - "definition": "CHECK (operation_generation > 0)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_6506", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL AND setup_run_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_9402", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create']))", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_action", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_b397", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_e32d", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_status", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_actor_profile_id__2ee3", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_identity_link_id__3ddf", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_project_id_projects", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_setup_run_id_proj_7dc3", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "guide_mutation_reservation_custody", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_mutation_idempotency_records", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_guide_mutation_operation_identity", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", - "kind": "u", - "name": "uq_guide_mutation_replay_namespace", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_gen_b5fe", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CHECK (logical_role::text = 'guide_source_original'::text)", - "kind": "c", - "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_role", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (source_item_id, source_snapshot_id) REFERENCES guide_source_snapshot_items(id, source_snapshot_id)", - "kind": "f", - "name": "fk_guide_bindings_exact_item", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (project_setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", - "kind": "f", - "name": "fk_guide_bindings_exact_setup_generation", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, project_id, guide_id) REFERENCES guide_source_snapshots(id, project_id, guide_id)", - "kind": "f", - "name": "fk_guide_bindings_exact_snapshot", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (verified_replica_id, content_id) REFERENCES artifact_replicas(id, content_id)", - "kind": "f", - "name": "fk_guide_bindings_verified_replica_content", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_guide_source_artifact_bindings_content_id_artifact_contents", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES guide_source_artifact_bindings(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_guide_source_artifact_bindings_supersedes_binding_id_bfa2", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_artifact_bindings", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (id, content_id, verified_replica_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_exact_read", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (id, content_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_extraction_attempt_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (id, content_id, source_item_id, project_setup_run_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_extraction_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (source_item_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_item_generation", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (supersedes_binding_id)", - "kind": "u", - "name": "uq_guide_bindings_supersedes", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CHECK (code::text = ANY (ARRAY['missing', 'changed', 'truncated', 'unavailable', 'stale', 'conflict']))", - "kind": "c", - "name": "ck_guide_source_artifact_incidents_ck_guide_incidents_code", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_621b", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_92fa", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", - "kind": "f", - "name": "fk_guide_incidents_exact_binding", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_artifact_incidents", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_2958", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_64cb", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_source_artifact_ingests_actor_profile_id_actor_22c1", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "FOREIGN KEY (source_item_id) REFERENCES guide_source_snapshot_items(id)", - "kind": "f", - "name": "fk_guide_source_artifact_ingests_source_item_id_guide_s_7ba9", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_artifact_ingests", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "UNIQUE (source_item_id)", - "kind": "u", - "name": "uq_guide_source_artifact_ingests_source_item_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CHECK (output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_1b91", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (octet_length(canonical_output) <= 4194304)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_54b5", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (source_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_988f", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (status::text = 'extracted'::text)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_a759", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (source_byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_fb79", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_guide_source_extracted_contents_content_id_artifact_contents", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_extracted_contents", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "UNIQUE (id, content_id)", - "kind": "u", - "name": "uq_guide_extracted_contents_exact_usage", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "UNIQUE (content_id, detected_format, extractor_name, extractor_version, policy_version)", - "kind": "u", - "name": "uq_guide_extracted_contents_identity", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (attempt_number > 0)", - "kind": "c", - "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_3927", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CHECK ((status::text = 'extracted'::text) = (error_code IS NULL))", - "kind": "c", - "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_940d", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['extracted', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded', 'parser_failure', 'cancelled', 'artifact_incident']))", - "kind": "c", - "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_ff6d", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_attempts_exact_binding", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_attempts_exact_classification", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "UNIQUE (binding_id, policy_version, attempt_number)", - "kind": "u", - "name": "uq_guide_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "UNIQUE (id, binding_id, content_id, setup_generation, status)", - "kind": "u", - "name": "uq_guide_extraction_attempts_exact_usage", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CHECK (claimed_slots >= 1 AND claimed_slots <= 2)", - "kind": "c", - "name": "ck_guide_source_extraction_retry_budgets_ck_guide_extra_99c3", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_retry_budgets_exact_binding", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_retry_budgets_exact_classification", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "PRIMARY KEY (binding_id)", - "kind": "p", - "name": "pk_guide_source_extraction_retry_budgets", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "CHECK (attempt_status::text = 'extracted'::text)", - "kind": "c", - "name": "ck_guide_source_extraction_usages_ck_guide_extraction_u_a2fd", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "FOREIGN KEY (extraction_attempt_id, binding_id, content_id, setup_generation, attempt_status) REFERENCES guide_source_extraction_attempts(id, binding_id, content_id, setup_generation, status)", - "kind": "f", - "name": "fk_guide_extraction_usages_exact_attempt", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, source_item_id, project_setup_run_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, source_item_id, project_setup_run_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_usages_exact_binding", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "FOREIGN KEY (extracted_content_id, content_id) REFERENCES guide_source_extracted_contents(id, content_id)", - "kind": "f", - "name": "fk_guide_extraction_usages_exact_content", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "UNIQUE (binding_id, extracted_content_id)", - "kind": "u", - "name": "uq_guide_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "UNIQUE (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", - "kind": "u", - "name": "uq_guide_extraction_usages_exact_provenance", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['classified', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded']))", - "kind": "c", - "name": "ck_guide_source_format_classifications_ck_guide_classif_8737", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_format_classifications_ck_guide_source__0dd2", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_format_classifications_ck_guide_source__7235", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", - "kind": "f", - "name": "fk_guide_classifications_exact_binding", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_format_classifications", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "UNIQUE (binding_id)", - "kind": "u", - "name": "uq_guide_classifications_binding", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "UNIQUE (id, binding_id, content_id, setup_generation)", - "kind": "u", - "name": "uq_guide_classifications_extraction_lineage", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_gssi_source_snapshot", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "guide_source_snapshot_items_custody", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_snapshot_items", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "UNIQUE (id, source_snapshot_id)", - "kind": "u", - "name": "uq_guide_source_snapshot_items_exact_lineage", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "UNIQUE (source_snapshot_id, item_order)", - "kind": "u", - "name": "uq_guide_source_snapshot_items_snapshot_order", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CHECK (creation_generation IS NULL AND created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR creation_generation > 0 AND created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (creation_scope_type::text = 'system'::text AND creation_scope_project_id IS NULL OR creation_scope_type::text = 'project'::text AND creation_scope_project_id::text = project_id::text) AND creation_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_guide_source_snapshots_source_snapshot_creation_auth_2f3e", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_actor", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_admin_grant", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_decision", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_identity_link", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_guide_id_project_guides", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_guide_source_snapshots_project_guide", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_project_id_projects", - "table_name": "guide_source_snapshots" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_snapshots", - "table_name": "guide_source_snapshots" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "source_snapshot_product_custody", - "table_name": "guide_source_snapshots" - }, - { - "definition": "UNIQUE (id, project_id, guide_id)", - "kind": "u", - "name": "uq_guide_source_snapshots_exact_lineage", - "table_name": "guide_source_snapshots" - }, - { - "definition": "UNIQUE (id, bundle_hash)", - "kind": "u", - "name": "uq_guide_source_snapshots_id_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "UNIQUE (project_id, guide_version, bundle_hash)", - "kind": "u", - "name": "uq_guide_source_snapshots_project_version_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_1033", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_177a", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run', 'project.guide_sufficiency.warnings.acknowledge']))", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_6651", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_87dd", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND (action_id::text = 'project.guide_sufficiency.run'::text AND (setup_run_id IS NOT NULL OR report_id IS NOT NULL) OR action_id::text <> 'project.guide_sufficiency.run'::text AND report_id IS NOT NULL))", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_e7f6", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_actor_16d8", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_guide_1d2b", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_ident_2378", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_proje_7f82", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_repor_48c3", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_setup_7059", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_sourc_9985", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_sufficiency_mutation_idempotency_records", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_sufficiency_mutation_operation_identity", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, idempotency_key)", - "kind": "u", - "name": "uq_sufficiency_mutation_replay_namespace", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_2983", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CHECK (canonical_output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_8148", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CHECK (item_order >= 0)", - "kind": "c", - "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_eb12", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id) ON DELETE CASCADE", - "kind": "f", - "name": "fk_guide_sufficiency_report_source_usages_report_id_gui_1d57", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "FOREIGN KEY (extraction_usage_id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation) REFERENCES guide_source_extraction_usages(id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", - "kind": "f", - "name": "fk_sufficiency_report_source_usage_exact_extraction", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_sufficiency_report_source_usages", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "UNIQUE (report_id, extraction_usage_id)", - "kind": "u", - "name": "uq_sufficiency_report_extraction_usage", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "UNIQUE (report_id, item_order)", - "kind": "u", - "name": "uq_sufficiency_report_item_order", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CHECK (warnings_acknowledged_by_actor_profile_id IS NULL AND warnings_acknowledged_via_identity_link_id IS NULL AND warnings_acknowledged_by_admin_role_grant_id IS NULL AND warning_acknowledgement_scope_type IS NULL AND warning_acknowledgement_scope_project_id IS NULL AND warning_acknowledgement_action_id IS NULL AND warning_acknowledgement_decision_event_id IS NULL OR warnings_acknowledged_by_actor_profile_id IS NOT NULL AND warnings_acknowledged_via_identity_link_id IS NOT NULL AND warnings_acknowledged_by_admin_role_grant_id IS NOT NULL AND (warning_acknowledgement_scope_type::text = ANY (ARRAY['system', 'project'])) AND warning_acknowledgement_scope_project_id IS NOT NULL AND warning_acknowledgement_action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND warning_acknowledgement_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_guide_sufficiency_ack_authority_shape", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run'])) AND authorization_decision_event_id IS NOT NULL AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.guide_sufficiency.run'::text AND project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL))", - "kind": "c", - "name": "ck_guide_sufficiency_creation_authority_shape", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (agent_material_byte_count IS NULL OR agent_material_byte_count >= 0)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_31bb", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (setup_generation IS NULL OR setup_generation > 0)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_3e43", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (project_setup_run_id IS NULL AND setup_generation IS NULL AND agent_material_sha256 IS NULL AND agent_material_byte_count IS NULL OR project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_4640", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['passed', 'blocked', 'passed_with_warnings']))", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_841c", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (agent_material_sha256 IS NULL OR agent_material_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_b3ec", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_guide_id_project_guides", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_project_guide", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_project_id_projects", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_source_snapshot_hash", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warnings_acknowledged_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_suff_ack_actor", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warning_acknowledgement_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_suff_ack_decision", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warnings_acknowledged_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_suff_ack_grant", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warnings_acknowledged_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_suff_ack_link", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warning_acknowledgement_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_suff_ack_project", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_suff_create_actor", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_suff_create_decision", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_suff_create_grant", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_suff_create_link", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_suff_create_project", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (project_setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_sufficiency_reports_setup_run", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_sufficiency_reports", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (code::text ~ '^[A-Z]{3}$'::text)", - "kind": "c", - "name": "ck_iso_4217_currency_codes_code", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "PRIMARY KEY (code)", - "kind": "p", - "name": "pk_iso_4217_currency_codes", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "PRIMARY KEY (actor_id)", - "kind": "p", - "name": "pk_legacy_actor_identities", - "table_name": "legacy_actor_identities" - }, - { - "definition": "UNIQUE (external_issuer, external_subject)", - "kind": "u", - "name": "uq_legacy_actor_identities_external_identity", - "table_name": "legacy_actor_identities" - }, - { - "definition": "CHECK (profile_type::text = ANY (ARRAY['worker', 'reviewer', 'admin', 'project_manager', 'project_owner']))", - "kind": "c", - "name": "ck_legacy_workflow_eligibility_profile_type", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['observed', 'active', 'disabled']))", - "kind": "c", - "name": "ck_legacy_workflow_eligibility_status", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "FOREIGN KEY (actor_id) REFERENCES legacy_actor_identities(actor_id)", - "kind": "f", - "name": "fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_legacy_workflow_eligibility", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "UNIQUE (actor_id, profile_type, scope_type, scope_id)", - "kind": "u", - "name": "uq_legacy_workflow_eligibility_actor_type_scope", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CHECK (aggregate_type::text ~ '^[a-z][a-z0-9_]{0,63}$'::text)", - "kind": "c", - "name": "ck_outbox_events_aggregate_type", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (claim_owner IS NULL OR claim_owner::text ~ '^[A-Za-z0-9._:-]{1,120}$'::text)", - "kind": "c", - "name": "ck_outbox_events_claim_owner", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (correlation_id::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", - "kind": "c", - "name": "ck_outbox_events_correlation_id", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (attempt_count >= 0 AND claim_generation >= 0 AND attempt_count = claim_generation)", - "kind": "c", - "name": "ck_outbox_events_delivery_counters", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (delivery_state::text = ANY (ARRAY['pending', 'claimed', 'retryable', 'acknowledged', 'dead_letter', 'cancelled']))", - "kind": "c", - "name": "ck_outbox_events_delivery_state", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (delivery_state::text = 'pending'::text AND attempt_count = 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NULL AND last_error_code IS NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'claimed'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NOT NULL AND claimed_at IS NOT NULL AND claim_expires_at IS NOT NULL AND last_attempt_at = claimed_at AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'retryable'::text AND attempt_count > 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'acknowledged'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'dead_letter'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'cancelled'::text AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND finalized_at IS NOT NULL AND (attempt_count = 0 AND last_attempt_at IS NULL AND last_error_code IS NULL OR attempt_count > 0 AND last_attempt_at IS NOT NULL))", - "kind": "c", - "name": "ck_outbox_events_delivery_state_shape", - "table_name": "outbox_events" - }, - { - "definition": "CHECK ((next_attempt_at IS NULL OR next_attempt_at >= occurred_at) AND (claimed_at IS NULL OR claimed_at >= occurred_at) AND (last_attempt_at IS NULL OR last_attempt_at >= occurred_at) AND (claim_expires_at IS NULL OR claim_expires_at > claimed_at) AND (finalized_at IS NULL OR finalized_at >= occurred_at) AND (finalized_at IS NULL OR last_attempt_at IS NULL OR finalized_at >= last_attempt_at) AND (archived_at IS NULL OR archived_at >= finalized_at))", - "kind": "c", - "name": "ck_outbox_events_delivery_timestamps", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (last_error_code IS NULL OR last_error_code::text ~ '^[A-Z][A-Z0-9_]{0,79}$'::text)", - "kind": "c", - "name": "ck_outbox_events_error_code", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (event_type::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'::text)", - "kind": "c", - "name": "ck_outbox_events_event_type", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (event_version >= 1 AND event_version <= 32767)", - "kind": "c", - "name": "ck_outbox_events_event_version", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (idempotency_key::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", - "kind": "c", - "name": "ck_outbox_events_idempotency_key", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (payload_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_outbox_events_payload_digest", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (jsonb_typeof(payload) = 'object'::text AND octet_length(payload::text) <= 262144)", - "kind": "c", - "name": "ck_outbox_events_payload_shape", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (producer::text = 'workstream'::text)", - "kind": "c", - "name": "ck_outbox_events_producer", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_outbox_events_project_id", - "table_name": "outbox_events" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_outbox_events_project_id_projects", - "table_name": "outbox_events" - }, - { - "definition": "PRIMARY KEY (event_id)", - "kind": "p", - "name": "pk_outbox_events", - "table_name": "outbox_events" - }, - { - "definition": "UNIQUE (idempotency_key)", - "kind": "u", - "name": "uq_outbox_events_idempotency_key", - "table_name": "outbox_events" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_payment_policies_project_guide", - "table_name": "payment_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_payment_policies_project_id_projects", - "table_name": "payment_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_payment_policies", - "table_name": "payment_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version)", - "kind": "u", - "name": "uq_payment_policies_project_version", - "table_name": "payment_policies" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_26aa", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_595e", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.review_policy.update', 'project.revision_policy.update']))", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_7f7f", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (policy_generation > 0)", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_8b22", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_dc05", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_actor_profile_id_41c2", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_guide_id_project_guides", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_identity_link_id_b806", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_project_id_projects", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_policy_mutation_idempotency_records", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "policy_mutation_replay_custody", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_policy_mutation_operation_identity", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", - "kind": "u", - "name": "uq_policy_mutation_replay_namespace", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'compiled'::text OR compiler_version IS NOT NULL AND compiled_bundle IS NOT NULL AND compiled_bundle_hash IS NOT NULL AND compiled_bundle_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_5010", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['pending_compilation', 'compiled', 'superseded']))", - "kind": "c", - "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_a935", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_pre_submit_checker_policies_ck_pre_submit_policy_aut_90fc", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_effective_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_guide", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_project", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_project_guide", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_source_snapshot_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_pre_submit_checker_policy_id) REFERENCES pre_submit_checker_policies(id)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_supersedes", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_actor", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_decision", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_grant", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_link", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_project", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_pre_submit_checker_policies", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "pre_submit_policy_custody", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "UNIQUE (id, compiled_bundle_hash)", - "kind": "u", - "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CHECK (classification::text = ANY (ARRAY['mandatory_security', 'mandatory_integrity', 'mandatory_accountability', 'advisory']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_b0de", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (classification::text = 'advisory'::text AND severity::text = 'warning'::text OR classification::text <> 'advisory'::text AND severity::text = 'blocking'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_f04e", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (result_order >= 0)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_order", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (phase::text = ANY (ARRAY['custody', 'identity', 'materialization', 'default_policy', 'project_policy']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_phase", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_plan_sha256", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (locked_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_pol_cef4", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (phase::text = 'project_policy'::text AND rule_instance_id IS NOT NULL AND rule_instance_id::text ~ '^sha256:[0-9a-f]{64}$'::text OR phase::text <> 'project_policy'::text AND rule_instance_id IS NULL)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_rul_321f", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (severity::text = ANY (ARRAY['blocking', 'warning']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_severity", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['passed', 'warning', 'advisory_disabled', 'dependency_not_run', 'failed']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_status", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (status::text = 'failed'::text AND failure_code IS NOT NULL OR status::text <> 'failed'::text AND failure_code IS NULL)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_result_failure_shape", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "FOREIGN KEY (evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_results_evidence_set_id_pre_subm_096e", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_pre_submit_evidence_results", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "UNIQUE (evidence_set_id, definition_id)", - "kind": "u", - "name": "uq_pre_submit_result_definition", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "UNIQUE (evidence_set_id, result_order)", - "kind": "u", - "name": "uq_pre_submit_result_order", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arch_8e95", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (archive_byte_count >= 0)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_archive_size", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_artifact_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arti_16f8", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (catalogue_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_cata_ffcb", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_checker_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_chec_765d", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_guide_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_guide_sha256", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_mani_7268", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_oper_f617", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_plan_sha256", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (predecessor_submission_id IS NULL AND predecessor_submission_version IS NULL OR predecessor_submission_id IS NOT NULL AND predecessor_submission_version IS NOT NULL)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_pred_bd87", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (result_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_resu_0b46", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (result_count > 0)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_result_count", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (source_snapshot_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_sour_982b", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (terminal_status::text = 'passed'::text AND eligible OR terminal_status::text = 'blocked'::text AND NOT eligible)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stat_1ae6", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (storage_scheme::text = ANY (ARRAY['local', 's3']))", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stor_022c", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (terminal_status::text = ANY (ARRAY['passed', 'blocked']))", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_term_a512", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_policy_context_sha256", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (assignment_id, task_id, actor_profile_id) REFERENCES task_assignments(id, task_id, contributor_id)", - "kind": "f", - "name": "fk_pre_submit_evidence_assignment", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (guide_id, project_id, guide_version) REFERENCES project_guides(id, project_id, version)", - "kind": "f", - "name": "fk_pre_submit_evidence_guide_lineage", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (identity_link_id, actor_profile_id) REFERENCES actor_identity_links(id, actor_profile_id)", - "kind": "f", - "name": "fk_pre_submit_evidence_identity_actor", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (predecessor_submission_id, task_id, predecessor_submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_pre_submit_evidence_predecessor", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_actor_profile_id_actor_profiles", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_assignment_id_task_assignments", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_effective_policy_id_effecti_6a99", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_guide_id_project_guides", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_identity_link_id_actor_iden_5cef", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_pre_submit_policy_id_pre_su_c77f", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_predecessor_submission_id_s_6ec2", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_project_id_projects", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_source_snapshot_id_guide_so_1667", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_task_id_workstream_tasks", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, effective_policy_id, locked_artifact_policy_sha256) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_artifact_policy", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, pre_submit_policy_id, locked_checker_policy_sha256) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_checker_policy", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_guide", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, project_id) REFERENCES workstream_tasks(id, project_id)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_project", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, source_snapshot_id, source_snapshot_sha256) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_source_snapshot", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_pre_submit_evidence_sets", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "UNIQUE (operation_identity)", - "kind": "u", - "name": "uq_pre_submit_evidence_operation", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (binding_lifecycle_version > 0)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_1870", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_3372", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (route_key::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'::text)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_6958", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (status::text = 'active'::text AND binding_lifecycle_version = 1 AND suspended_by IS NULL AND suspended_at IS NULL AND retired_by IS NULL AND retired_at IS NULL)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_95ba", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK ((suspended_at IS NULL OR suspended_at >= created_at) AND (retired_at IS NULL OR retired_at >= created_at) AND (retired_at IS NULL OR suspended_at IS NULL OR retired_at >= suspended_at))", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_ade1", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'retired']))", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_da73", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (route_key::text !~~ '%..%'::text)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_f32d", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (adapter_actor_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_adapter_actor", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_created_by", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_compensation_binding_project", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_retired_by", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (suspended_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_suspended_by", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_compensation_adapter_bindings", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "UNIQUE (id, project_id, instrument_type)", - "kind": "u", - "name": "uq_compensation_binding_ownership", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", - "kind": "c", - "name": "ck_project_compensation_units_instrument_type", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (status::text = 'active'::text AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", - "kind": "c", - "name": "ck_project_compensation_units_lifecycle_shape", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", - "kind": "c", - "name": "ck_project_compensation_units_retirement_time", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'retired']))", - "kind": "c", - "name": "ck_project_compensation_units_status", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (instrument_type::text = 'money'::text AND iso_currency_code IS NOT NULL AND unit_code::text = iso_currency_code::text OR instrument_type::text = 'project_points'::text AND iso_currency_code IS NULL AND unit_code::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$'::text)", - "kind": "c", - "name": "ck_project_compensation_units_unit_identity", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_compensation_unit_created_by", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (iso_currency_code) REFERENCES iso_4217_currency_codes(code)", - "kind": "f", - "name": "fk_project_compensation_unit_iso_currency", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_compensation_unit_project", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_compensation_unit_retired_by", - "table_name": "project_compensation_units" - }, - { - "definition": "PRIMARY KEY (project_id, instrument_type, unit_code)", - "kind": "p", - "name": "pk_project_compensation_units", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_0a41", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (operation_generation = 1)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_100d", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND committed_at IS NULL OR status::text = 'committed'::text AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_3aa0", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = 'project.create'::text)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_action", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_status", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_create_idempotency_records_actor_profile_id__ebb1", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_create_idempotency_records_identity_link_id__ddce", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_create_idempotency_records", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "project_create_reservation_custody", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_project_create_operation_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "UNIQUE (project_id)", - "kind": "u", - "name": "uq_project_create_project_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", - "kind": "u", - "name": "uq_project_create_replay_namespace", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_00d8", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (component_hashes IS NULL OR json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_31c4", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (status::text = 'compilation_reserved'::text AND provider_uncertain_at IS NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_provider_uncertain'::text AND provider_uncertain_at IS NOT NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'provider_result_accepted'::text AND accepted_at IS NOT NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_persisted'::text AND accepted_at IS NOT NULL AND persisted_at IS NOT NULL AND terminal_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NOT NULL OR status::text = 'compilation_invalid_terminal'::text AND terminal_at IS NOT NULL AND accepted_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND persisted_compilation_id IS NULL AND (failure_code::text = ANY (ARRAY['schema_invalid', 'unsafe_text', 'hash_mismatch', 'context_mismatch'])))", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_444c", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_513e", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (canonical_result IS NULL OR octet_length(canonical_result::text) <= 4194304)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6057", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (result_hash IS NULL OR result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6609", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['compilation_reserved', 'compilation_provider_uncertain', 'provider_result_accepted', 'compilation_invalid_terminal', 'compilation_persisted']))", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6c82", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (persisted_compilation_id, id) REFERENCES project_guide_compilations(id, attempt_id)", - "kind": "f", - "name": "fk_compilation_attempt_exact_persisted_compilation", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", - "kind": "f", - "name": "fk_compilation_attempt_exact_setup", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_compilation_attempt_snapshot_hash", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_project_guide_compilation_attempts_guide_id_project_guides", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_guide_compilation_attempts_project_id_projects", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_guide_compilation_attempts", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "UNIQUE (provider_idempotency_key)", - "kind": "u", - "name": "uq_compilation_attempt_provider_key", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "UNIQUE (setup_run_id, setup_generation)", - "kind": "u", - "name": "uq_compilation_attempt_setup_generation", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (setup_generation > 0 AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_action_id::text = 'project.guide_compilation.execute'::text)", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_8a51", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_9cd9", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK (authorization_resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_d554", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK (octet_length(canonical_result::text) <= 4194304 AND json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_dafe", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (supersedes_compilation_id, project_id, guide_id) REFERENCES project_guide_compilations(id, project_id, guide_id)", - "kind": "f", - "name": "fk_project_guide_compilation_predecessor", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (attempt_id) REFERENCES project_guide_compilation_attempts(id)", - "kind": "f", - "name": "fk_project_guide_compilations_attempt_id_project_guide__0e94", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_project_guide_compilations_authorization_decision_ev_42ad", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_guide_compilations_created_by_actor_profile__953f", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_guide_compilations_created_via_identity_link_b250", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_project_guide_compilations_guide_id_project_guides", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_guide_compilations_project_id_projects", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_project_guide_compilations_setup_run_id_project_setup_runs", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_project_guide_compilations_source_snapshot_id_guide__033a", - "table_name": "project_guide_compilations" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_guide_compilations", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (attempt_id)", - "kind": "u", - "name": "uq_project_guide_compilation_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (id, attempt_id)", - "kind": "u", - "name": "uq_project_guide_compilation_id_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (supersedes_compilation_id)", - "kind": "u", - "name": "uq_project_guide_compilation_predecessor", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (id, project_id, guide_id)", - "kind": "u", - "name": "uq_project_guide_compilation_scope", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK ((status::text <> ALL (ARRAY['active', 'superseded'])) OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL AND selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL)", - "kind": "c", - "name": "ck_project_guides_active_policy_selection_required", - "table_name": "project_guides" - }, - { - "definition": "CHECK (mutation_generation IS NULL AND last_mutated_by_actor_profile_id IS NULL AND last_mutated_via_identity_link_id IS NULL AND last_mutated_by_admin_role_grant_id IS NULL AND last_mutation_scope_type IS NULL AND last_mutation_scope_project_id IS NULL AND last_mutation_action_id IS NULL AND last_authorization_decision_event_id IS NULL OR mutation_generation > 0 AND last_mutated_by_actor_profile_id IS NOT NULL AND last_mutated_via_identity_link_id IS NOT NULL AND last_mutated_by_admin_role_grant_id IS NOT NULL AND (last_mutation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (last_mutation_scope_type::text = 'system'::text AND last_mutation_scope_project_id IS NULL OR last_mutation_scope_type::text = 'project'::text AND last_mutation_scope_project_id::text = project_id::text) AND (last_mutation_action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create'])) AND last_authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_project_guides_guide_mutation_authority_shape", - "table_name": "project_guides" - }, - { - "definition": "CHECK ((selected_review_policy_id IS NULL AND selected_review_policy_generation IS NULL AND selected_review_policy_hash IS NULL OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL) AND (selected_revision_policy_id IS NULL AND selected_revision_policy_generation IS NULL AND selected_revision_policy_hash IS NULL OR selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL))", - "kind": "c", - "name": "ck_project_guides_policy_selection_shape", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_mutated_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_actor", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_mutated_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_admin_grant", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_decision", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_mutated_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_identity_link", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_guides_project_id_projects", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (project_id, version, selected_review_policy_id, selected_review_policy_generation, selected_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_project_guides_selected_review_policy", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (project_id, version, selected_revision_policy_id, selected_revision_policy_generation, selected_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_project_guides_selected_revision_policy", - "table_name": "project_guides" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "guide_mutation_product_custody", - "table_name": "project_guides" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_guides", - "table_name": "project_guides" - }, - { - "definition": "UNIQUE (id, project_id, version)", - "kind": "u", - "name": "uq_project_guides_id_project_version", - "table_name": "project_guides" - }, - { - "definition": "UNIQUE (project_id, version)", - "kind": "u", - "name": "uq_project_guides_project_version", - "table_name": "project_guides" - }, - { - "definition": "CHECK (grant_method::text = 'manual'::text)", - "kind": "c", - "name": "ck_project_role_grants_grant_method", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND revoked_at IS NOT NULL)", - "kind": "c", - "name": "ck_project_role_grants_lifecycle", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (project_role_reason_is_safe(grant_reason) AND (revoked_reason IS NULL OR project_role_reason_is_safe(revoked_reason)))", - "kind": "c", - "name": "ck_project_role_grants_reason", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", - "kind": "c", - "name": "ck_project_role_grants_role", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_grants_actor_profile_id_actor_profiles", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_grants_granted_by_actor_profile_id_acto_c240", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_role_grants_granted_by_admin_role_grant_id_a_71d7", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_role_grants_project_id_projects", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_grants_revoked_by_actor_profile_id_acto_a5dd", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_role_grants_revoked_by_admin_role_grant_id_a_aa4d", - "table_name": "project_role_grants" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_role_grants", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (qualification_snapshot_id, actor_profile_id, project_id, role) REFERENCES project_role_qualification_snapshots(id, actor_profile_id, project_id, requested_role) ON DELETE RESTRICT", - "kind": "f", - "name": "qualification_ownership", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (project_role_availability_is_safe(skills_snapshot) AND project_role_availability_is_safe(reputation_snapshot))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_availability", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (project_role_reference_array_is_safe(external_expertise_refs, false))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_external_expertise_refs", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (project_role_reference_array_is_safe(prior_project_work_refs, true))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_prior_work_refs", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (requested_role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_role", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_actor_profile_i_aedc", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (captured_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_captured_by_act_ab57", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (captured_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_captured_by_adm_c8b8", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_project_id_projects", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "UNIQUE (id, actor_profile_id, project_id, requested_role)", - "kind": "u", - "name": "grant_reference", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_role_qualification_snapshots", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_project_setup_runs_ck_project_setup_runs_generation_positive", - "table_name": "project_setup_runs" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['queued', 'dispatch_pending', 'enqueue_failed', 'enqueue_identity_mismatch', 'running_sufficiency_agent', 'sufficiency_blocked', 'running_policy_derivation_agent', 'policy_draft_ready', 'running_post_submit_derivation_agent', 'post_submit_setup_blocked', 'post_submit_policy_compiled', 'setup_blocked', 'failed']))", - "kind": "c", - "name": "ck_project_setup_runs_ck_project_setup_runs_status", - "table_name": "project_setup_runs" - }, - { - "definition": "CHECK (authorized_by_actor_profile_id IS NULL AND authorized_via_identity_link_id IS NULL AND authorized_by_admin_role_grant_id IS NULL AND authorization_scope_type IS NULL AND authorization_scope_project_id IS NULL AND authorization_action_id IS NULL AND authorization_decision_event_id IS NULL OR authorized_by_actor_profile_id IS NOT NULL AND authorized_via_identity_link_id IS NOT NULL AND authorized_by_admin_role_grant_id IS NOT NULL AND (authorization_scope_type::text = ANY (ARRAY['system', 'project'])) AND (authorization_scope_type::text = 'system'::text AND authorization_scope_project_id IS NULL OR authorization_scope_type::text = 'project'::text AND authorization_scope_project_id::text = project_id::text) AND authorization_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_project_setup_runs_setup_run_authority_shape", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (error_artifact_incident_id) REFERENCES guide_source_artifact_incidents(id)", - "kind": "f", - "name": "fk_project_setup_runs_artifact_incident", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorized_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_actor", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorized_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_admin_grant", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_decision", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorized_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_identity_link", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (continuation_verification_job_id) REFERENCES artifact_verification_jobs(id)", - "kind": "f", - "name": "fk_project_setup_runs_continuation_verification_job", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_project_setup_runs_guide_id_project_guides", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (output_post_submit_checker_policy_id) REFERENCES checker_policies(id)", - "kind": "f", - "name": "fk_project_setup_runs_post_submit_checker_policy", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_project_setup_runs_project_guide", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_setup_runs_project_id_projects", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_project_setup_runs_source_snapshot_hash", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_project_setup_runs_source_snapshot_id_guide_source_snapshots", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (output_submission_artifact_policy_id) REFERENCES submission_artifact_policies(id)", - "kind": "f", - "name": "fk_project_setup_runs_submission_artifact_policy", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (output_sufficiency_report_id) REFERENCES guide_sufficiency_reports(id)", - "kind": "f", - "name": "fk_project_setup_runs_sufficiency_report", - "table_name": "project_setup_runs" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_setup_runs", - "table_name": "project_setup_runs" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "source_setup_run_custody", - "table_name": "project_setup_runs" - }, - { - "definition": "UNIQUE (id, project_id, guide_id, source_snapshot_id, setup_generation)", - "kind": "u", - "name": "uq_project_setup_runs_exact_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "UNIQUE (guide_id, setup_generation)", - "kind": "u", - "name": "uq_project_setup_runs_guide_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type::text = 'system'::text AND creation_action_id::text = 'project.create'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_projects_creation_authority_shape", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_projects_creation_actor", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_projects_creation_admin_grant", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_projects_creation_decision", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_projects_creation_identity_link", - "table_name": "projects" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_projects", - "table_name": "projects" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "project_creation_custody", - "table_name": "projects" - }, - { - "definition": "UNIQUE (slug)", - "kind": "u", - "name": "uq_projects_slug", - "table_name": "projects" - }, - { - "definition": "CHECK (submission_version > 0)", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_2b6d", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND review_queue_entry_id IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND review_queue_entry_id IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_4cd5", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_88bf", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_b8b8", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_review_admission_checker", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", - "kind": "f", - "name": "fk_review_admission_committed_queue", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_admission_project", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (review_queue_entry_id) REFERENCES review_queue_entries(id)", - "kind": "f", - "name": "fk_review_admission_queue", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_review_admission_submission", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_review_admission_submission_lineage", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_review_admission_task", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_admission_idempotency_records", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "UNIQUE (admitting_checker_run_id)", - "kind": "u", - "name": "uq_review_admission_checker_run", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_review_admission_operation", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "UNIQUE (idempotency_key)", - "kind": "u", - "name": "uq_review_admission_replay_key", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (attempt_generation > 0)", - "kind": "c", - "name": "ck_review_leases_attempt_generation_positive", - "table_name": "review_leases" - }, - { - "definition": "CHECK (closed_at IS NULL OR closed_at >= claimed_at)", - "kind": "c", - "name": "ck_review_leases_closure_after_claim", - "table_name": "review_leases" - }, - { - "definition": "CHECK (expires_at > claimed_at)", - "kind": "c", - "name": "ck_review_leases_expiry_after_claim", - "table_name": "review_leases" - }, - { - "definition": "CHECK (status::text = 'active'::text AND closed_at IS NULL AND close_reason IS NULL OR status::text = 'consumed'::text AND closed_at IS NOT NULL AND close_reason::text = 'review_recorded'::text OR status::text = 'released'::text AND closed_at IS NOT NULL AND close_reason::text = 'manual_release'::text OR status::text = 'expired'::text AND closed_at IS NOT NULL AND close_reason::text = 'lease_expired'::text OR status::text = 'revoked'::text AND closed_at IS NOT NULL AND (close_reason::text = ANY (ARRAY['grant_revoked', 'admin_override'])))", - "kind": "c", - "name": "ck_review_leases_lifecycle_shape", - "table_name": "review_leases" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'consumed', 'released', 'expired', 'revoked']))", - "kind": "c", - "name": "ck_review_leases_status", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (reviewer_contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", - "kind": "f", - "name": "fk_review_lease_policy_version", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_lease_project", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version)", - "kind": "f", - "name": "fk_review_lease_queue_lineage", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (reviewer_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_review_lease_reviewer", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_review_lease_submission", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_review_lease_task", - "table_name": "review_leases" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_leases", - "table_name": "review_leases" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "review_leases_active_lease_guard", - "table_name": "review_leases" - }, - { - "definition": "UNIQUE (review_queue_entry_id, attempt_generation)", - "kind": "u", - "name": "uq_review_lease_attempt", - "table_name": "review_leases" - }, - { - "definition": "UNIQUE (review_queue_entry_id, id)", - "kind": "u", - "name": "uq_review_lease_queue_identity", - "table_name": "review_leases" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.review_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_review_policies_review_policy_authority_shape", - "table_name": "review_policies" - }, - { - "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", - "kind": "c", - "name": "ck_review_policies_review_policy_identity_shape", - "table_name": "review_policies" - }, - { - "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", - "kind": "c", - "name": "ck_review_policies_review_policy_predecessor_shape", - "table_name": "review_policies" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR review_preference_window_seconds > 0 AND review_lease_duration_seconds > 0 AND max_active_review_leases_per_reviewer = 1 AND self_review_allowed = false AND reject_policy::text = 'close_task'::text AND (finding_evidence_requirement::text = ANY (ARRAY['optional', 'required_for_blocking', 'required_for_all'])))", - "kind": "c", - "name": "ck_review_policies_review_policy_semantics_shape", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_review_policies_actor_profile", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_review_policies_admin_grant", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_review_policies_decision_event", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_review_policies_identity_link", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_review_policies_project_guide", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_policies_project_id_projects", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES review_policies(id)", - "kind": "f", - "name": "fk_review_policies_supersedes", - "table_name": "review_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_policies", - "table_name": "review_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "review_policy_mutation_custody", - "table_name": "review_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, policy_generation)", - "kind": "u", - "name": "uq_review_policies_project_version_generation", - "table_name": "review_policies" - }, - { - "definition": "UNIQUE (id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_review_policy_lineage", - "table_name": "review_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_review_policy_scoped_lineage", - "table_name": "review_policies" - }, - { - "definition": "CHECK (available_since >= first_queued_at)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_availab_d484", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_generation > 0 AND lifecycle_generation > 0)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_generat_38b7", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (queue_state::text = 'pending'::text AND active_lease_id IS NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'leased'::text AND active_lease_id IS NOT NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'closed'::text AND active_lease_id IS NULL AND closed_at IS NOT NULL AND (closed_reason::text = ANY (ARRAY['review_recorded', 'task_closed', 'admin_cancelled'])) AND closed_at >= first_queued_at)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_lifecycle_shape", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (queue_state::text = ANY (ARRAY['pending', 'leased', 'closed']))", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_queue_state", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_mode::text = ANY (ARRAY['open', 'preferred']))", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_routing_mode", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_reason::text = ANY (ARRAY['first_submission', 'revision_return', 'admin_assignment']))", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_routing_reason", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_mode::text = 'open'::text AND preferred_reviewer_id IS NULL AND preference_expires_at IS NULL OR routing_mode::text = 'preferred'::text AND preferred_reviewer_id IS NOT NULL AND preference_expires_at IS NOT NULL AND preference_expires_at > first_queued_at)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_routing_shape", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (submission_version > 0)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_submiss_2f6b", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (active_lease_id, id) REFERENCES review_leases(id, review_queue_entry_id) DEFERRABLE INITIALLY DEFERRED", - "kind": "f", - "name": "fk_review_queue_active_lease", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_review_queue_checker", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (preferred_reviewer_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_review_queue_preferred_reviewer", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_queue_project", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_review_queue_submission", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_review_queue_submission_lineage", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_review_queue_task", - "table_name": "review_queue_entries" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_queue_entries", - "table_name": "review_queue_entries" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "review_queue_entries_active_lease_guard", - "table_name": "review_queue_entries" - }, - { - "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", - "kind": "u", - "name": "uq_review_queue_admission_identity", - "table_name": "review_queue_entries" - }, - { - "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version)", - "kind": "u", - "name": "uq_review_queue_lease_lineage", - "table_name": "review_queue_entries" - }, - { - "definition": "UNIQUE (submission_id)", - "kind": "u", - "name": "uq_review_queue_submission", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.revision_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_revision_policies_revision_policy_authority_shape", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", - "kind": "c", - "name": "ck_revision_policies_revision_policy_identity_shape", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", - "kind": "c", - "name": "ck_revision_policies_revision_policy_predecessor_shape", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR max_revision_rounds > 0 AND revision_deadline_hours > 0)", - "kind": "c", - "name": "ck_revision_policies_revision_policy_semantics_shape", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_revision_policies_actor_profile", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_revision_policies_admin_grant", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_revision_policies_decision_event", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_revision_policies_identity_link", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_revision_policies_project_guide", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_revision_policies_project_id_projects", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES revision_policies(id)", - "kind": "f", - "name": "fk_revision_policies_supersedes", - "table_name": "revision_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_revision_policies", - "table_name": "revision_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "revision_policy_mutation_custody", - "table_name": "revision_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, policy_generation)", - "kind": "u", - "name": "uq_revision_policies_project_version_generation", - "table_name": "revision_policies" - }, - { - "definition": "UNIQUE (id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_revision_policy_lineage", - "table_name": "revision_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_revision_policy_scoped_lineage", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['draft', 'approved', 'superseded']))", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_artifact__20ca", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_artifact__52ca", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (approved_by_actor_profile_id IS NULL AND approved_via_identity_link_id IS NULL AND approved_by_admin_role_grant_id IS NULL AND approval_scope_type IS NULL AND approval_scope_project_id IS NULL AND approval_action_id IS NULL AND approval_decision_event_id IS NULL OR approved_by_actor_profile_id IS NOT NULL AND approved_via_identity_link_id IS NOT NULL AND approved_by_admin_role_grant_id IS NOT NULL AND approval_scope_type IS NOT NULL AND approval_action_id IS NOT NULL AND (approval_scope_type::text = ANY (ARRAY['system', 'project'])) AND approval_scope_project_id IS NOT NULL AND approval_scope_project_id::text = project_id::text AND approval_action_id::text = 'project.submission_artifact_policy.approve'::text AND approval_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_policy_ap_0e4d", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_decision_event_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update'])) AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NOT NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.submission_artifact_policy.derive'::text))", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_policy_cr_0629", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES submission_artifact_policies(id)", - "kind": "f", - "name": "fk_sap_supersedes_policy", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_submission_artifact_policies_guide_id_project_guides", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_submission_artifact_policies_project_guide", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_artifact_policies_project_id_projects", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_submission_artifact_policies_source_snapshot_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approved_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submission_policy_approval_actor", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approval_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_submission_policy_approval_decision", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approved_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_submission_policy_approval_grant", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approved_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_submission_policy_approval_link", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approval_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_policy_approval_project", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submission_policy_creation_actor", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_submission_policy_creation_decision", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_submission_policy_creation_grant", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_submission_policy_creation_link", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_policy_creation_project", - "table_name": "submission_artifact_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_artifact_policies", - "table_name": "submission_artifact_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "submission_policy_creation_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "submission_policy_product_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "UNIQUE (id, policy_hash)", - "kind": "u", - "name": "uq_submission_artifact_policies_id_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, policy_version)", - "kind": "u", - "name": "uq_submission_artifact_policies_project_version_policy", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_bundle_admissions_archive_sha256", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (archive_byte_count >= 0)", - "kind": "c", - "name": "ck_submission_bundle_admissions_archive_size", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_bundle_admissions_manifest_sha256", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_bundle_admissions_policy_context_hash", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK ((predecessor_submission_id IS NULL) = (predecessor_submission_version IS NULL))", - "kind": "c", - "name": "ck_submission_bundle_admissions_predecessor_shape", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['ready', 'consumed', 'stale']))", - "kind": "c", - "name": "ck_submission_bundle_admissions_status", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (status::text = 'ready'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'consumed'::text AND consumed_at IS NOT NULL AND consumed_by_submission_id IS NOT NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'stale'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NOT NULL AND octet_length(stale_reason::text) >= 1 AND octet_length(stale_reason::text) <= 500)", - "kind": "c", - "name": "ck_submission_bundle_admissions_terminal_shape", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (((put_operation_receipt_id IS NOT NULL)::integer + (put_observation_receipt_id IS NOT NULL)::integer) = 1)", - "kind": "c", - "name": "ck_submission_bundle_admissions_write_receipt_shape", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_actor_profile_id_actor_profiles", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (artifact_content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_artifact_content_id_art_12c8", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_assignment_id_task_assignments", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (consumed_by_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_consumed_by_submission__2b23", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (durable_intent_id) REFERENCES submission_bundle_durable_intents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_durable_intent_id_submi_102c", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_identity_link_id_actor__d29d", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_pre_submit_evidence_set_a752", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_predecessor_submission__242d", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_project_id_projects", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_put_attempt_id_artifact_bbc3", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (put_observation_receipt_id) REFERENCES artifact_put_observation_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_put_observation_receipt_5136", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (put_operation_receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_put_operation_receipt_i_9602", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_task_id_workstream_tasks", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (verification_receipt_id) REFERENCES artifact_verification_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_verification_receipt_id_0ea1", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (verified_replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_verified_replica_id_art_3a4e", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_bundle_admissions", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "UNIQUE (pre_submit_evidence_set_id)", - "kind": "u", - "name": "uq_submission_bundle_admission_evidence", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "UNIQUE (durable_intent_id)", - "kind": "u", - "name": "uq_submission_bundle_admission_intent", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "UNIQUE (verification_receipt_id)", - "kind": "u", - "name": "uq_submission_bundle_admission_verification", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_durable_intents_pre_submit_evidenc_c406", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_durable_intents_put_attempt_id_art_b4e4", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_bundle_durable_intents", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "UNIQUE (pre_submit_evidence_set_id)", - "kind": "u", - "name": "uq_submission_bundle_intent_evidence", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "UNIQUE (put_attempt_id)", - "kind": "u", - "name": "uq_submission_bundle_intent_put_attempt", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0119", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update', 'project.submission_artifact_policy.approve']))", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0dbe", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_2b53", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK ((status::text = ANY (ARRAY['reserved', 'pending'])) AND response_json IS NULL AND committed_at IS NULL AND committed_policy_id IS NULL AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND committed_policy_id IS NOT NULL AND (action_id::text = 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NOT NULL AND committed_pre_submit_policy_id IS NOT NULL OR action_id::text <> 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL))", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_58d4", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['reserved', 'pending', 'committed']))", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_a824", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (service_identity IS NULL AND idempotency_key IS NOT NULL AND setup_run_id IS NULL AND setup_task_id IS NULL AND correlation_id IS NULL OR service_identity IS NOT NULL AND service_identity::text = 'workstream.project.setup'::text AND idempotency_key IS NULL AND action_id::text = 'project.submission_artifact_policy.derive'::text AND setup_run_id IS NOT NULL AND setup_task_id IS NOT NULL AND correlation_id IS NOT NULL)", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_b357", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_actor_f5bb", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (committed_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_commi_4fa6", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (committed_policy_id) REFERENCES submission_artifact_policies(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_commi_571a", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (committed_pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_commi_baa9", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_guide_ed8d", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_ident_2567", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_proje_442a", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_setup_a102", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_sourc_536e", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_policy_mutation_idempotency_records", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "submission_policy_replay_custody", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_submission_policy_operation_identity", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", - "kind": "c", - "name": "ck_submissions_post_submit_policy_lock_complete", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submissions_contributor_id_actor_profiles", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_submissions_locked_effective_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", - "kind": "f", - "name": "fk_submissions_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", - "kind": "f", - "name": "fk_submissions_locked_pre_submit_checker_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_submissions_locked_source_snapshot_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (supersedes_submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_submissions_supersedes_submission_id_submissions", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_submissions_task_id_workstream_tasks", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_effective_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", - "kind": "f", - "name": "fk_submissions_task_locked_guide", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", - "kind": "f", - "name": "fk_submissions_task_locked_payment_policy", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES workstream_tasks(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_pre_submit_checker_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_review_policy", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_revision_policy", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_source_snapshot_hash", - "table_name": "submissions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submissions", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "u", - "name": "uq_submissions_id_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (id, task_id, version)", - "kind": "u", - "name": "uq_submissions_id_task_version", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (id, version)", - "kind": "u", - "name": "uq_submissions_id_version", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (task_id, version)", - "kind": "u", - "name": "uq_submissions_task_version", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_task_assignments_contributor_id_actor_profiles", - "table_name": "task_assignments" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_task_assignments_task_id_workstream_tasks", - "table_name": "task_assignments" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_task_assignments", - "table_name": "task_assignments" - }, - { - "definition": "UNIQUE (id, task_id, contributor_id)", - "kind": "u", - "name": "uq_task_assignments_id_task_contributor", - "table_name": "task_assignments" - }, - { - "definition": "CHECK (status::text = 'draft'::text OR locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", - "kind": "c", - "name": "ck_workstream_tasks_post_submit_policy_lock_complete", - "table_name": "workstream_tasks" - }, - { - "definition": "CHECK (status::text = 'draft'::text OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", - "kind": "c", - "name": "ck_workstream_tasks_review_revision_policy_lock_required", - "table_name": "workstream_tasks" - }, - { - "definition": "CHECK (locked_review_policy_id IS NULL AND locked_review_policy_generation IS NULL AND locked_review_policy_hash IS NULL AND locked_revision_policy_id IS NULL AND locked_revision_policy_generation IS NULL AND locked_revision_policy_hash IS NULL OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", - "kind": "c", - "name": "ck_workstream_tasks_review_revision_policy_lock_shape", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_workstream_tasks_locked_guide", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_payment_policy_version) REFERENCES payment_policies(project_id, guide_version)", - "kind": "f", - "name": "fk_workstream_tasks_locked_payment_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_review_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_revision_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_source_snapshot_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_workstream_tasks_project_id_projects", - "table_name": "workstream_tasks" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_workstream_tasks", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_guide_version)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_guide", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_payment_policy_version)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_payment_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_review_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_revision_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, project_id)", - "kind": "u", - "name": "uq_workstream_tasks_id_project", - "table_name": "workstream_tasks" - } - ], - "format": "workstream-v01-schema-manifest-1", - "indexes": [ - { - "definition": "CREATE INDEX ix_actor_identity_links_issuer_subject_status ON public.actor_identity_links USING btree (issuer, subject, status)", - "name": "ix_actor_identity_links_issuer_subject_status", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX pk_actor_identity_links ON public.actor_identity_links USING btree (id)", - "name": "pk_actor_identity_links", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_actor_profile ON public.actor_identity_links USING btree (actor_profile_id)", - "name": "uq_actor_identity_links_actor_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_external_identity ON public.actor_identity_links USING btree (issuer, subject)", - "name": "uq_actor_identity_links_external_identity", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_id_profile ON public.actor_identity_links USING btree (id, actor_profile_id)", - "name": "uq_actor_identity_links_id_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX pk_actor_profile_migration_state ON public.actor_profile_migration_state USING btree (id)", - "name": "pk_actor_profile_migration_state", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CREATE INDEX ix_actor_profiles_last_seen_at ON public.actor_profiles USING btree (last_seen_at)", - "name": "ix_actor_profiles_last_seen_at", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE INDEX ix_actor_profiles_status_actor_kind ON public.actor_profiles USING btree (status, actor_kind)", - "name": "ix_actor_profiles_status_actor_kind", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE UNIQUE INDEX pk_actor_profiles ON public.actor_profiles USING btree (id)", - "name": "pk_actor_profiles", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE UNIQUE INDEX service_identity ON public.actor_profiles USING btree (service_identity)", - "name": "service_identity", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE INDEX ix_admin_role_grants_effective_candidate ON public.admin_role_grants USING btree (target_actor_profile_id, status, scope_type, scope_project_id)", - "name": "ix_admin_role_grants_effective_candidate", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE INDEX ix_admin_role_grants_final_access_admin ON public.admin_role_grants USING btree (role, status) WHERE (((role)::text = 'access_administrator'::text) AND ((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", - "name": "ix_admin_role_grants_final_access_admin", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE INDEX ix_admin_role_grants_history ON public.admin_role_grants USING btree (target_actor_profile_id, granted_at, id)", - "name": "ix_admin_role_grants_history", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX pk_admin_role_grants ON public.admin_role_grants USING btree (id)", - "name": "pk_admin_role_grants", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_project ON public.admin_role_grants USING btree (target_actor_profile_id, role, scope_project_id) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'project'::text))", - "name": "uq_admin_role_grants_active_project", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_system ON public.admin_role_grants USING btree (target_actor_profile_id, role) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", - "name": "uq_admin_role_grants_active_system", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE INDEX ix_api_rate_control_counters_window_expires_at ON public.api_rate_control_counters USING btree (window_expires_at)", - "name": "ix_api_rate_control_counters_window_expires_at", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CREATE UNIQUE INDEX pk_api_rate_control_counters ON public.api_rate_control_counters USING btree (control_scope, key_digest)", - "name": "pk_api_rate_control_counters", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_admission_charges ON public.artifact_admission_charges USING btree (id)", - "name": "pk_artifact_admission_charges", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_admission_charge_scope_content ON public.artifact_admission_charges USING btree (scope_type, scope_id, sha256, byte_count)", - "name": "uq_artifact_admission_charge_scope_content", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_admission_scopes ON public.artifact_admission_scopes USING btree (scope_type, scope_id)", - "name": "pk_artifact_admission_scopes", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_content_id ON public.artifact_bindings USING btree (content_id)", - "name": "ix_artifact_bindings_content_id", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_project_id ON public.artifact_bindings USING btree (project_id)", - "name": "ix_artifact_bindings_project_id", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_scope ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version DESC)", - "name": "ix_artifact_bindings_scope", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_supersedes_binding_id ON public.artifact_bindings USING btree (supersedes_binding_id)", - "name": "ix_artifact_bindings_supersedes_binding_id", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_bindings ON public.artifact_bindings USING btree (id)", - "name": "pk_artifact_bindings", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_binding_scope_version ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version)", - "name": "uq_artifact_binding_scope_version", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_binding_supersedes ON public.artifact_bindings USING btree (supersedes_binding_id)", - "name": "uq_artifact_binding_supersedes", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_contents_sha256 ON public.artifact_contents USING btree (sha256)", - "name": "ix_artifact_contents_sha256", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_contents ON public.artifact_contents USING btree (id)", - "name": "pk_artifact_contents", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_content_digest_size ON public.artifact_contents USING btree (sha256, byte_count)", - "name": "uq_artifact_content_digest_size", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE INDEX ix_artifact_operation_receipts_put_attempt_id ON public.artifact_operation_receipts USING btree (put_attempt_id)", - "name": "ix_artifact_operation_receipts_put_attempt_id", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE INDEX ix_artifact_operation_receipts_replica_id ON public.artifact_operation_receipts USING btree (replica_id)", - "name": "ix_artifact_operation_receipts_replica_id", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_operation_receipts ON public.artifact_operation_receipts USING btree (id)", - "name": "pk_artifact_operation_receipts", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_receipt_put_attempt ON public.artifact_operation_receipts USING btree (put_attempt_id)", - "name": "uq_artifact_receipt_put_attempt", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempt_charges ON public.artifact_put_attempt_charges USING btree (attempt_id, charge_id)", - "name": "pk_artifact_put_attempt_charges", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_checker_run_id ON public.artifact_put_attempts USING btree (checker_run_id)", - "name": "ix_artifact_put_attempts_checker_run_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_guide_source_item_id ON public.artifact_put_attempts USING btree (guide_source_item_id)", - "name": "ix_artifact_put_attempts_guide_source_item_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_next_run_at ON public.artifact_put_attempts USING btree (next_run_at)", - "name": "ix_artifact_put_attempts_next_run_at", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_project_id ON public.artifact_put_attempts USING btree (project_id)", - "name": "ix_artifact_put_attempts_project_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_receipt_id ON public.artifact_put_attempts USING btree (receipt_id)", - "name": "ix_artifact_put_attempts_receipt_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_replica_id ON public.artifact_put_attempts USING btree (replica_id)", - "name": "ix_artifact_put_attempts_replica_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_status ON public.artifact_put_attempts USING btree (status)", - "name": "ix_artifact_put_attempts_status", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_task_id ON public.artifact_put_attempts USING btree (task_id)", - "name": "ix_artifact_put_attempts_task_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempts ON public.artifact_put_attempts USING btree (id)", - "name": "pk_artifact_put_attempts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_put_attempt_operation ON public.artifact_put_attempts USING btree (operation_identity)", - "name": "uq_artifact_put_attempt_operation", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_observation_receipts_put_attempt_id ON public.artifact_put_observation_receipts USING btree (put_attempt_id)", - "name": "ix_artifact_put_observation_receipts_put_attempt_id", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_put_observation_receipts ON public.artifact_put_observation_receipts USING btree (id)", - "name": "pk_artifact_put_observation_receipts", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_put_observation_fence ON public.artifact_put_observation_receipts USING btree (put_attempt_id, execution_generation)", - "name": "uq_artifact_put_observation_fence", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_parent_recovery_attempt_id ON public.artifact_recovery_attempts USING btree (parent_recovery_attempt_id)", - "name": "ix_artifact_recovery_attempts_parent_recovery_attempt_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_project_id ON public.artifact_recovery_attempts USING btree (project_id)", - "name": "ix_artifact_recovery_attempts_project_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_requester_actor_profile_id ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id)", - "name": "ix_artifact_recovery_attempts_requester_actor_profile_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_submission_id ON public.artifact_recovery_attempts USING btree (submission_id)", - "name": "ix_artifact_recovery_attempts_submission_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_task_id ON public.artifact_recovery_attempts USING btree (task_id)", - "name": "ix_artifact_recovery_attempts_task_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_recovery_attempts ON public.artifact_recovery_attempts USING btree (id)", - "name": "pk_artifact_recovery_attempts", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_idempotency ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", - "name": "uq_artifact_recovery_idempotency", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_retry_job ON public.artifact_recovery_attempts USING btree (retry_verification_job_id)", - "name": "uq_artifact_recovery_retry_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_source_job ON public.artifact_recovery_attempts USING btree (source_verification_job_id)", - "name": "uq_artifact_recovery_source_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_replicas_content_id ON public.artifact_replicas USING btree (content_id)", - "name": "ix_artifact_replicas_content_id", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE INDEX ix_artifact_replicas_storage_namespace_id ON public.artifact_replicas USING btree (storage_namespace_id)", - "name": "ix_artifact_replicas_storage_namespace_id", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_replicas ON public.artifact_replicas USING btree (id)", - "name": "pk_artifact_replicas", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_replica_provider_object ON public.artifact_replicas USING btree (storage_namespace_id, provider_object_ref)", - "name": "uq_artifact_replica_provider_object", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_replicas_id_content ON public.artifact_replicas USING btree (id, content_id)", - "name": "uq_artifact_replicas_id_content", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_storage_namespaces ON public.artifact_storage_namespaces USING btree (id)", - "name": "pk_artifact_storage_namespaces", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_fingerprint ON public.artifact_storage_namespaces USING btree (namespace_fingerprint)", - "name": "uq_artifact_storage_namespace_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_id_fingerprint ON public.artifact_storage_namespaces USING btree (id, namespace_fingerprint)", - "name": "uq_artifact_storage_namespace_id_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_next_run_at ON public.artifact_verification_jobs USING btree (next_run_at)", - "name": "ix_artifact_verification_jobs_next_run_at", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_originating_put_attempt_id ON public.artifact_verification_jobs USING btree (originating_put_attempt_id)", - "name": "ix_artifact_verification_jobs_originating_put_attempt_id", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_parent_verification_job_id ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", - "name": "ix_artifact_verification_jobs_parent_verification_job_id", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_replica_id ON public.artifact_verification_jobs USING btree (replica_id)", - "name": "ix_artifact_verification_jobs_replica_id", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_status ON public.artifact_verification_jobs USING btree (status)", - "name": "ix_artifact_verification_jobs_status", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_verification_jobs ON public.artifact_verification_jobs USING btree (id)", - "name": "pk_artifact_verification_jobs", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_verification_initial_origin ON public.artifact_verification_jobs USING btree (originating_put_attempt_id) WHERE (parent_verification_job_id IS NULL)", - "name": "uq_artifact_verification_initial_origin", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_verification_parent ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", - "name": "uq_artifact_verification_parent", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_receipts_verification_job_id ON public.artifact_verification_receipts USING btree (verification_job_id)", - "name": "ix_artifact_verification_receipts_verification_job_id", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_verification_receipts ON public.artifact_verification_receipts USING btree (id)", - "name": "pk_artifact_verification_receipts", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_verification_fence ON public.artifact_verification_receipts USING btree (verification_job_id, execution_generation)", - "name": "uq_artifact_verification_fence", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE INDEX ix_audit_events_actor_id ON public.audit_events USING btree (actor_id)", - "name": "ix_audit_events_actor_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_actor_ref ON public.audit_events USING btree (actor_ref_kind, actor_id)", - "name": "ix_audit_events_actor_ref", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_correlation_id ON public.audit_events USING btree (correlation_id)", - "name": "ix_audit_events_correlation_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_entity_id ON public.audit_events USING btree (entity_id)", - "name": "ix_audit_events_entity_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_entity_type ON public.audit_events USING btree (entity_type)", - "name": "ix_audit_events_entity_type", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_event_type ON public.audit_events USING btree (event_type)", - "name": "ix_audit_events_event_type", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_occurred_at ON public.audit_events USING btree (occurred_at)", - "name": "ix_audit_events_occurred_at", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_project_id ON public.audit_events USING btree (project_id)", - "name": "ix_audit_events_project_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_request_id ON public.audit_events USING btree (request_id)", - "name": "ix_audit_events_request_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE UNIQUE INDEX pk_audit_events ON public.audit_events USING btree (id)", - "name": "pk_audit_events", - "table_name": "audit_events" - }, - { - "definition": "CREATE UNIQUE INDEX pk_authority_control ON public.authority_control USING btree (id)", - "name": "pk_authority_control", - "table_name": "authority_control" - }, - { - "definition": "CREATE UNIQUE INDEX pk_authority_idempotency_records ON public.authority_idempotency_records USING btree (id)", - "name": "pk_authority_idempotency_records", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_actor_reference ON public.authority_idempotency_records USING btree (id, actor_ref_kind, actor_ref)", - "name": "uq_authority_idempotency_records_actor_reference", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_replay_namespace ON public.authority_idempotency_records USING btree (actor_ref_kind, actor_ref, operation, idempotency_key)", - "name": "uq_authority_idempotency_records_replay_namespace", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_checker_policies_effective_policy_hash ON public.checker_policies USING btree (effective_policy_hash)", - "name": "ix_checker_policies_effective_policy_hash", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_effective_policy_id ON public.checker_policies USING btree (effective_policy_id)", - "name": "ix_checker_policies_effective_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_guide_id ON public.checker_policies USING btree (guide_id)", - "name": "ix_checker_policies_guide_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_bundle_hash ON public.checker_policies USING btree (pre_submit_checker_bundle_hash)", - "name": "ix_checker_policies_pre_submit_checker_bundle_hash", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_policy_id ON public.checker_policies USING btree (pre_submit_checker_policy_id)", - "name": "ix_checker_policies_pre_submit_checker_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_project_id ON public.checker_policies USING btree (project_id)", - "name": "ix_checker_policies_project_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_source_snapshot_id ON public.checker_policies USING btree (source_snapshot_id)", - "name": "ix_checker_policies_source_snapshot_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_supersedes_policy_id ON public.checker_policies USING btree (supersedes_policy_id)", - "name": "ix_checker_policies_supersedes_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_checker_policies ON public.checker_policies USING btree (id)", - "name": "pk_checker_policies", - "table_name": "checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_policies_current_project_version ON public.checker_policies USING btree (project_id, guide_version) WHERE ((lifecycle_status)::text = ANY (ARRAY['compiled', 'approved']))", - "name": "uq_checker_policies_current_project_version", - "table_name": "checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_policies_id_version_hash ON public.checker_policies USING btree (id, guide_version, policy_hash)", - "name": "uq_checker_policies_id_version_hash", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_results_checker_name ON public.checker_results USING btree (checker_name)", - "name": "ix_checker_results_checker_name", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_checker_run_id ON public.checker_results USING btree (checker_run_id)", - "name": "ix_checker_results_checker_run_id", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_submission_id ON public.checker_results USING btree (submission_id)", - "name": "ix_checker_results_submission_id", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_task_id ON public.checker_results USING btree (task_id)", - "name": "ix_checker_results_task_id", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_worker_visible ON public.checker_results USING btree (worker_visible)", - "name": "ix_checker_results_worker_visible", - "table_name": "checker_results" - }, - { - "definition": "CREATE UNIQUE INDEX pk_checker_results ON public.checker_results USING btree (id)", - "name": "pk_checker_results", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_runs_audit_event_id ON public.checker_runs USING btree (audit_event_id)", - "name": "ix_checker_runs_audit_event_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_locked_post_submit_policy_hash ON public.checker_runs USING btree (locked_post_submit_checker_policy_hash)", - "name": "ix_checker_runs_locked_post_submit_policy_hash", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_routing_recommendation ON public.checker_runs USING btree (routing_recommendation)", - "name": "ix_checker_runs_routing_recommendation", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_status ON public.checker_runs USING btree (status)", - "name": "ix_checker_runs_status", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_submission_id ON public.checker_runs USING btree (submission_id)", - "name": "ix_checker_runs_submission_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_supersedes_checker_run_id ON public.checker_runs USING btree (supersedes_checker_run_id)", - "name": "ix_checker_runs_supersedes_checker_run_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_task_id ON public.checker_runs USING btree (task_id)", - "name": "ix_checker_runs_task_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_checker_runs ON public.checker_runs USING btree (id)", - "name": "pk_checker_runs", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_runs_current_per_submission ON public.checker_runs USING btree (submission_id) WHERE (is_current_for_submission = true)", - "name": "uq_checker_runs_current_per_submission", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_runs_submission_attempt ON public.checker_runs USING btree (submission_id, attempt_number)", - "name": "uq_checker_runs_submission_attempt", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_award_definitions ON public.contribution_award_definitions USING btree (id)", - "name": "pk_contribution_award_definitions", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_award_definition_instrument ON public.contribution_award_definitions USING btree (contribution_rule_id, instrument_type)", - "name": "uq_contribution_award_definition_instrument", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_policies ON public.contribution_policies USING btree (id)", - "name": "pk_contribution_policies", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_active_project ON public.contribution_policies USING btree (project_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_contribution_policy_active_project", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_ownership ON public.contribution_policies USING btree (id, project_id)", - "name": "uq_contribution_policy_ownership", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_policy_versions ON public.contribution_policy_versions USING btree (id)", - "name": "pk_contribution_policy_versions", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_number ON public.contribution_policy_versions USING btree (contribution_policy_id, version_number)", - "name": "uq_contribution_policy_version_number", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_ownership ON public.contribution_policy_versions USING btree (id, contribution_policy_id, project_id)", - "name": "uq_contribution_policy_version_ownership", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_project ON public.contribution_policy_versions USING btree (id, project_id)", - "name": "uq_contribution_policy_version_project", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_rules ON public.contribution_rules USING btree (id)", - "name": "pk_contribution_rules", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_rule_ownership ON public.contribution_rules USING btree (id, contribution_policy_version_id, project_id, contribution_type)", - "name": "uq_contribution_rule_ownership", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_rule_type ON public.contribution_rules USING btree (contribution_policy_version_id, contribution_type)", - "name": "uq_contribution_rule_type", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE INDEX ix_effective_psap_effective_hash ON public.effective_project_submission_artifact_policies USING btree (effective_policy_hash)", - "name": "ix_effective_psap_effective_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_guide ON public.effective_project_submission_artifact_policies USING btree (guide_id)", - "name": "ix_effective_psap_guide", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_lifecycle ON public.effective_project_submission_artifact_policies USING btree (lifecycle_status)", - "name": "ix_effective_psap_lifecycle", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_project ON public.effective_project_submission_artifact_policies USING btree (project_id)", - "name": "ix_effective_psap_project", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_source_snapshot ON public.effective_project_submission_artifact_policies USING btree (source_snapshot_id)", - "name": "ix_effective_psap_source_snapshot", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_submission_policy ON public.effective_project_submission_artifact_policies USING btree (submission_artifact_policy_id)", - "name": "ix_effective_psap_submission_policy", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_effective_project_submission_artifact_policies ON public.effective_project_submission_artifact_policies USING btree (id)", - "name": "pk_effective_project_submission_artifact_policies", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_effective_project_submission_artifact_policies_id_hash ON public.effective_project_submission_artifact_policies USING btree (id, effective_policy_hash)", - "name": "uq_effective_project_submission_artifact_policies_id_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_evidence_items_submission_id ON public.evidence_items USING btree (submission_id)", - "name": "ix_evidence_items_submission_id", - "table_name": "evidence_items" - }, - { - "definition": "CREATE INDEX ix_evidence_items_type ON public.evidence_items USING btree (type)", - "name": "ix_evidence_items_type", - "table_name": "evidence_items" - }, - { - "definition": "CREATE UNIQUE INDEX pk_evidence_items ON public.evidence_items USING btree (id)", - "name": "pk_evidence_items", - "table_name": "evidence_items" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_mutation_idempotency_records ON public.guide_mutation_idempotency_records USING btree (id)", - "name": "pk_guide_mutation_idempotency_records", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_mutation_operation_identity ON public.guide_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_guide_mutation_operation_identity", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_mutation_replay_namespace ON public.guide_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", - "name": "uq_guide_mutation_replay_namespace", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_content_id ON public.guide_source_artifact_bindings USING btree (content_id)", - "name": "ix_guide_source_artifact_bindings_content_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_guide_id ON public.guide_source_artifact_bindings USING btree (guide_id)", - "name": "ix_guide_source_artifact_bindings_guide_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_id ON public.guide_source_artifact_bindings USING btree (project_id)", - "name": "ix_guide_source_artifact_bindings_project_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_setup_run_id ON public.guide_source_artifact_bindings USING btree (project_setup_run_id)", - "name": "ix_guide_source_artifact_bindings_project_setup_run_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_item_id ON public.guide_source_artifact_bindings USING btree (source_item_id)", - "name": "ix_guide_source_artifact_bindings_source_item_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_snapshot_id ON public.guide_source_artifact_bindings USING btree (source_snapshot_id)", - "name": "ix_guide_source_artifact_bindings_source_snapshot_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_supersedes_binding_id ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", - "name": "ix_guide_source_artifact_bindings_supersedes_binding_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_verified_replica_id ON public.guide_source_artifact_bindings USING btree (verified_replica_id)", - "name": "ix_guide_source_artifact_bindings_verified_replica_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_bindings ON public.guide_source_artifact_bindings USING btree (id)", - "name": "pk_guide_source_artifact_bindings", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_exact_read ON public.guide_source_artifact_bindings USING btree (id, content_id, verified_replica_id, setup_generation)", - "name": "uq_guide_bindings_exact_read", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_attempt_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, setup_generation)", - "name": "uq_guide_bindings_extraction_attempt_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, source_item_id, project_setup_run_id, setup_generation)", - "name": "uq_guide_bindings_extraction_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_item_generation ON public.guide_source_artifact_bindings USING btree (source_item_id, setup_generation)", - "name": "uq_guide_bindings_item_generation", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_supersedes ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", - "name": "uq_guide_bindings_supersedes", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_incidents_binding_id ON public.guide_source_artifact_incidents USING btree (binding_id)", - "name": "ix_guide_source_artifact_incidents_binding_id", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_incidents_content_id ON public.guide_source_artifact_incidents USING btree (content_id)", - "name": "ix_guide_source_artifact_incidents_content_id", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_incidents_verified_replica_id ON public.guide_source_artifact_incidents USING btree (verified_replica_id)", - "name": "ix_guide_source_artifact_incidents_verified_replica_id", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_incidents ON public.guide_source_artifact_incidents USING btree (id)", - "name": "pk_guide_source_artifact_incidents", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_ingests_actor_profile_id ON public.guide_source_artifact_ingests USING btree (actor_profile_id)", - "name": "ix_guide_source_artifact_ingests_actor_profile_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE UNIQUE INDEX ix_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", - "name": "ix_guide_source_artifact_ingests_source_item_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_ingests ON public.guide_source_artifact_ingests USING btree (id)", - "name": "pk_guide_source_artifact_ingests", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", - "name": "uq_guide_source_artifact_ingests_source_item_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE INDEX ix_guide_source_extracted_contents_content_id ON public.guide_source_extracted_contents USING btree (content_id)", - "name": "ix_guide_source_extracted_contents_content_id", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extracted_contents ON public.guide_source_extracted_contents USING btree (id)", - "name": "pk_guide_source_extracted_contents", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_exact_usage ON public.guide_source_extracted_contents USING btree (id, content_id)", - "name": "uq_guide_extracted_contents_exact_usage", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_identity ON public.guide_source_extracted_contents USING btree (content_id, detected_format, extractor_name, extractor_version, policy_version)", - "name": "uq_guide_extracted_contents_identity", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_attempts_binding_id ON public.guide_source_extraction_attempts USING btree (binding_id)", - "name": "ix_guide_source_extraction_attempts_binding_id", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_attempts_content_id ON public.guide_source_extraction_attempts USING btree (content_id)", - "name": "ix_guide_source_extraction_attempts_content_id", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_attempts ON public.guide_source_extraction_attempts USING btree (id)", - "name": "pk_guide_source_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts ON public.guide_source_extraction_attempts USING btree (binding_id, policy_version, attempt_number)", - "name": "uq_guide_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts_exact_usage ON public.guide_source_extraction_attempts USING btree (id, binding_id, content_id, setup_generation, status)", - "name": "uq_guide_extraction_attempts_exact_usage", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_retry_budgets ON public.guide_source_extraction_retry_budgets USING btree (binding_id)", - "name": "pk_guide_source_extraction_retry_budgets", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_binding_id ON public.guide_source_extraction_usages USING btree (binding_id)", - "name": "ix_guide_source_extraction_usages_binding_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_content_id ON public.guide_source_extraction_usages USING btree (content_id)", - "name": "ix_guide_source_extraction_usages_content_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_extracted_content_id ON public.guide_source_extraction_usages USING btree (extracted_content_id)", - "name": "ix_guide_source_extraction_usages_extracted_content_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_project_setup_run_id ON public.guide_source_extraction_usages USING btree (project_setup_run_id)", - "name": "ix_guide_source_extraction_usages_project_setup_run_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_source_item_id ON public.guide_source_extraction_usages USING btree (source_item_id)", - "name": "ix_guide_source_extraction_usages_source_item_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_usages ON public.guide_source_extraction_usages USING btree (id)", - "name": "pk_guide_source_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages ON public.guide_source_extraction_usages USING btree (binding_id, extracted_content_id)", - "name": "uq_guide_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages_exact_provenance ON public.guide_source_extraction_usages USING btree (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", - "name": "uq_guide_extraction_usages_exact_provenance", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_format_classifications_binding_id ON public.guide_source_format_classifications USING btree (binding_id)", - "name": "ix_guide_source_format_classifications_binding_id", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE INDEX ix_guide_source_format_classifications_content_id ON public.guide_source_format_classifications USING btree (content_id)", - "name": "ix_guide_source_format_classifications_content_id", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE INDEX ix_guide_source_format_classifications_verified_replica_id ON public.guide_source_format_classifications USING btree (verified_replica_id)", - "name": "ix_guide_source_format_classifications_verified_replica_id", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_format_classifications ON public.guide_source_format_classifications USING btree (id)", - "name": "pk_guide_source_format_classifications", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_classifications_binding ON public.guide_source_format_classifications USING btree (binding_id)", - "name": "uq_guide_classifications_binding", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_classifications_extraction_lineage ON public.guide_source_format_classifications USING btree (id, binding_id, content_id, setup_generation)", - "name": "uq_guide_classifications_extraction_lineage", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshot_items_source_snapshot_id ON public.guide_source_snapshot_items USING btree (source_snapshot_id)", - "name": "ix_guide_source_snapshot_items_source_snapshot_id", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshot_items ON public.guide_source_snapshot_items USING btree (id)", - "name": "pk_guide_source_snapshot_items", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_exact_lineage ON public.guide_source_snapshot_items USING btree (id, source_snapshot_id)", - "name": "uq_guide_source_snapshot_items_exact_lineage", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_snapshot_order ON public.guide_source_snapshot_items USING btree (source_snapshot_id, item_order)", - "name": "uq_guide_source_snapshot_items_snapshot_order", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshots_bundle_hash ON public.guide_source_snapshots USING btree (bundle_hash)", - "name": "ix_guide_source_snapshots_bundle_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshots_guide_id ON public.guide_source_snapshots USING btree (guide_id)", - "name": "ix_guide_source_snapshots_guide_id", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshots_project_id ON public.guide_source_snapshots USING btree (project_id)", - "name": "ix_guide_source_snapshots_project_id", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshots ON public.guide_source_snapshots USING btree (id)", - "name": "pk_guide_source_snapshots", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_exact_lineage ON public.guide_source_snapshots USING btree (id, project_id, guide_id)", - "name": "uq_guide_source_snapshots_exact_lineage", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_id_hash ON public.guide_source_snapshots USING btree (id, bundle_hash)", - "name": "uq_guide_source_snapshots_id_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_project_version_hash ON public.guide_source_snapshots USING btree (project_id, guide_version, bundle_hash)", - "name": "uq_guide_source_snapshots_project_version_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_mutation_idempotency_records ON public.guide_sufficiency_mutation_idempotency_records USING btree (id)", - "name": "pk_guide_sufficiency_mutation_idempotency_records", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_operation_identity ON public.guide_sufficiency_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_sufficiency_mutation_operation_identity", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_replay_namespace ON public.guide_sufficiency_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key)", - "name": "uq_sufficiency_mutation_replay_namespace", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_sufficiency_report_source_usage_report_id ON public.guide_sufficiency_report_source_usages USING btree (report_id)", - "name": "ix_sufficiency_report_source_usage_report_id", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_report_source_usages ON public.guide_sufficiency_report_source_usages USING btree (id)", - "name": "pk_guide_sufficiency_report_source_usages", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_extraction_usage ON public.guide_sufficiency_report_source_usages USING btree (report_id, extraction_usage_id)", - "name": "uq_sufficiency_report_extraction_usage", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_item_order ON public.guide_sufficiency_report_source_usages USING btree (report_id, item_order)", - "name": "uq_sufficiency_report_item_order", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_guide_id ON public.guide_sufficiency_reports USING btree (guide_id)", - "name": "ix_guide_sufficiency_reports_guide_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_id ON public.guide_sufficiency_reports USING btree (project_id)", - "name": "ix_guide_sufficiency_reports_project_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_setup_run_id ON public.guide_sufficiency_reports USING btree (project_setup_run_id)", - "name": "ix_guide_sufficiency_reports_project_setup_run_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_source_snapshot_id ON public.guide_sufficiency_reports USING btree (source_snapshot_id)", - "name": "ix_guide_sufficiency_reports_source_snapshot_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_status ON public.guide_sufficiency_reports USING btree (status)", - "name": "ix_guide_sufficiency_reports_status", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_reports ON public.guide_sufficiency_reports USING btree (id)", - "name": "pk_guide_sufficiency_reports", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_diagnostic_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NULL)", - "name": "uq_guide_sufficiency_reports_diagnostic_snapshot", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_verified_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NOT NULL)", - "name": "uq_guide_sufficiency_reports_verified_snapshot", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX pk_iso_4217_currency_codes ON public.iso_4217_currency_codes USING btree (code)", - "name": "pk_iso_4217_currency_codes", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "CREATE UNIQUE INDEX pk_legacy_actor_identities ON public.legacy_actor_identities USING btree (actor_id)", - "name": "pk_legacy_actor_identities", - "table_name": "legacy_actor_identities" - }, - { - "definition": "CREATE UNIQUE INDEX uq_legacy_actor_identities_external_identity ON public.legacy_actor_identities USING btree (external_issuer, external_subject)", - "name": "uq_legacy_actor_identities_external_identity", - "table_name": "legacy_actor_identities" - }, - { - "definition": "CREATE INDEX ix_legacy_workflow_eligibility_actor_id ON public.legacy_workflow_eligibility USING btree (actor_id)", - "name": "ix_legacy_workflow_eligibility_actor_id", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE INDEX ix_legacy_workflow_eligibility_profile_type ON public.legacy_workflow_eligibility USING btree (profile_type)", - "name": "ix_legacy_workflow_eligibility_profile_type", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE INDEX ix_legacy_workflow_eligibility_status ON public.legacy_workflow_eligibility USING btree (status)", - "name": "ix_legacy_workflow_eligibility_status", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE UNIQUE INDEX pk_legacy_workflow_eligibility ON public.legacy_workflow_eligibility USING btree (id)", - "name": "pk_legacy_workflow_eligibility", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE UNIQUE INDEX uq_legacy_workflow_eligibility_actor_type_scope ON public.legacy_workflow_eligibility USING btree (actor_id, profile_type, scope_type, scope_id)", - "name": "uq_legacy_workflow_eligibility_actor_type_scope", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE INDEX ix_outbox_events_aggregate ON public.outbox_events USING btree (aggregate_type, aggregate_id, occurred_at, event_id)", - "name": "ix_outbox_events_aggregate", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_eligible ON public.outbox_events USING btree (event_type, delivery_state, next_attempt_at, occurred_at, event_id) WHERE ((delivery_state)::text = ANY (ARRAY['pending', 'retryable']))", - "name": "ix_outbox_events_eligible", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_expired_claims ON public.outbox_events USING btree (claim_expires_at, event_id) WHERE ((delivery_state)::text = 'claimed'::text)", - "name": "ix_outbox_events_expired_claims", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_project_drain ON public.outbox_events USING btree (project_id, delivery_state, occurred_at, event_id)", - "name": "ix_outbox_events_project_drain", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_retention ON public.outbox_events USING btree (finalized_at, event_id) WHERE (((delivery_state)::text = ANY (ARRAY['acknowledged', 'dead_letter', 'cancelled'])) AND (archived_at IS NULL))", - "name": "ix_outbox_events_retention", - "table_name": "outbox_events" - }, - { - "definition": "CREATE UNIQUE INDEX pk_outbox_events ON public.outbox_events USING btree (event_id)", - "name": "pk_outbox_events", - "table_name": "outbox_events" - }, - { - "definition": "CREATE UNIQUE INDEX uq_outbox_events_idempotency_key ON public.outbox_events USING btree (idempotency_key)", - "name": "uq_outbox_events_idempotency_key", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_payment_policies_project_id ON public.payment_policies USING btree (project_id)", - "name": "ix_payment_policies_project_id", - "table_name": "payment_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_payment_policies ON public.payment_policies USING btree (id)", - "name": "pk_payment_policies", - "table_name": "payment_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_payment_policies_project_version ON public.payment_policies USING btree (project_id, guide_version)", - "name": "uq_payment_policies_project_version", - "table_name": "payment_policies" - }, - { - "definition": "CREATE INDEX ix_policy_mutation_custody_lookup ON public.policy_mutation_idempotency_records USING btree (policy_id, action_id, policy_generation, status)", - "name": "ix_policy_mutation_custody_lookup", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX pk_policy_mutation_idempotency_records ON public.policy_mutation_idempotency_records USING btree (id)", - "name": "pk_policy_mutation_idempotency_records", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_policy_mutation_operation_identity ON public.policy_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_policy_mutation_operation_identity", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_policy_mutation_replay_namespace ON public.policy_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", - "name": "uq_policy_mutation_replay_namespace", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_compiled_hash ON public.pre_submit_checker_policies USING btree (compiled_bundle_hash)", - "name": "ix_pre_submit_checker_compiled_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_effective ON public.pre_submit_checker_policies USING btree (effective_policy_id)", - "name": "ix_pre_submit_checker_effective", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_effective_hash ON public.pre_submit_checker_policies USING btree (effective_policy_hash)", - "name": "ix_pre_submit_checker_effective_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_guide ON public.pre_submit_checker_policies USING btree (guide_id)", - "name": "ix_pre_submit_checker_guide", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_lifecycle ON public.pre_submit_checker_policies USING btree (lifecycle_status)", - "name": "ix_pre_submit_checker_lifecycle", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_project ON public.pre_submit_checker_policies USING btree (project_id)", - "name": "ix_pre_submit_checker_project", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_source_snapshot ON public.pre_submit_checker_policies USING btree (source_snapshot_id)", - "name": "ix_pre_submit_checker_source_snapshot", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_pre_submit_checker_policies ON public.pre_submit_checker_policies USING btree (id)", - "name": "pk_pre_submit_checker_policies", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_checker_policies_id_compiled_bundle_hash ON public.pre_submit_checker_policies USING btree (id, compiled_bundle_hash)", - "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_results_evidence_set_id ON public.pre_submit_evidence_results USING btree (evidence_set_id)", - "name": "ix_pre_submit_evidence_results_evidence_set_id", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_results ON public.pre_submit_evidence_results USING btree (id)", - "name": "pk_pre_submit_evidence_results", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_definition ON public.pre_submit_evidence_results USING btree (evidence_set_id, definition_id)", - "name": "uq_pre_submit_result_definition", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_order ON public.pre_submit_evidence_results USING btree (evidence_set_id, result_order)", - "name": "uq_pre_submit_result_order", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_sets_actor_profile_id ON public.pre_submit_evidence_sets USING btree (actor_profile_id)", - "name": "ix_pre_submit_evidence_sets_actor_profile_id", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_sets_project_id ON public.pre_submit_evidence_sets USING btree (project_id)", - "name": "ix_pre_submit_evidence_sets_project_id", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_sets_task_id ON public.pre_submit_evidence_sets USING btree (task_id)", - "name": "ix_pre_submit_evidence_sets_task_id", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_sets ON public.pre_submit_evidence_sets USING btree (id)", - "name": "pk_pre_submit_evidence_sets", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_evidence_operation ON public.pre_submit_evidence_sets USING btree (operation_identity)", - "name": "uq_pre_submit_evidence_operation", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE INDEX ix_compensation_binding_adapter_actor ON public.project_compensation_adapter_bindings USING btree (adapter_actor_id, status, id)", - "name": "ix_compensation_binding_adapter_actor", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_compensation_adapter_bindings ON public.project_compensation_adapter_bindings USING btree (id)", - "name": "pk_project_compensation_adapter_bindings", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compensation_binding_active_project_instrument ON public.project_compensation_adapter_bindings USING btree (project_id, instrument_type) WHERE ((status)::text = 'active'::text)", - "name": "uq_compensation_binding_active_project_instrument", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compensation_binding_ownership ON public.project_compensation_adapter_bindings USING btree (id, project_id, instrument_type)", - "name": "uq_compensation_binding_ownership", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_compensation_units ON public.project_compensation_units USING btree (project_id, instrument_type, unit_code)", - "name": "pk_project_compensation_units", - "table_name": "project_compensation_units" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_create_idempotency_records ON public.project_create_idempotency_records USING btree (id)", - "name": "pk_project_create_idempotency_records", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_create_operation_identity ON public.project_create_idempotency_records USING btree (operation_id)", - "name": "uq_project_create_operation_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_create_project_identity ON public.project_create_idempotency_records USING btree (project_id)", - "name": "uq_project_create_project_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_create_replay_namespace ON public.project_create_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", - "name": "uq_project_create_replay_namespace", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_guide_id ON public.project_guide_compilation_attempts USING btree (guide_id)", - "name": "ix_project_guide_compilation_attempts_guide_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_project_id ON public.project_guide_compilation_attempts USING btree (project_id)", - "name": "ix_project_guide_compilation_attempts_project_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_setup_run_id ON public.project_guide_compilation_attempts USING btree (setup_run_id)", - "name": "ix_project_guide_compilation_attempts_setup_run_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_source_snapshot_id ON public.project_guide_compilation_attempts USING btree (source_snapshot_id)", - "name": "ix_project_guide_compilation_attempts_source_snapshot_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_guide_compilation_attempts ON public.project_guide_compilation_attempts USING btree (id)", - "name": "pk_project_guide_compilation_attempts", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_provider_key ON public.project_guide_compilation_attempts USING btree (provider_idempotency_key)", - "name": "uq_compilation_attempt_provider_key", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_setup_generation ON public.project_guide_compilation_attempts USING btree (setup_run_id, setup_generation)", - "name": "uq_compilation_attempt_setup_generation", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_guide_id ON public.project_guide_compilations USING btree (guide_id)", - "name": "ix_project_guide_compilations_guide_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_project_id ON public.project_guide_compilations USING btree (project_id)", - "name": "ix_project_guide_compilations_project_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_setup_run_id ON public.project_guide_compilations USING btree (setup_run_id)", - "name": "ix_project_guide_compilations_setup_run_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_source_snapshot_id ON public.project_guide_compilations USING btree (source_snapshot_id)", - "name": "ix_project_guide_compilations_source_snapshot_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_guide_compilations ON public.project_guide_compilations USING btree (id)", - "name": "pk_project_guide_compilations", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_attempt ON public.project_guide_compilations USING btree (attempt_id)", - "name": "uq_project_guide_compilation_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_id_attempt ON public.project_guide_compilations USING btree (id, attempt_id)", - "name": "uq_project_guide_compilation_id_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_predecessor ON public.project_guide_compilations USING btree (supersedes_compilation_id)", - "name": "uq_project_guide_compilation_predecessor", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_root ON public.project_guide_compilations USING btree (project_id, guide_id) WHERE (supersedes_compilation_id IS NULL)", - "name": "uq_project_guide_compilation_root", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_scope ON public.project_guide_compilations USING btree (id, project_id, guide_id)", - "name": "uq_project_guide_compilation_scope", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guides_project_id ON public.project_guides USING btree (project_id)", - "name": "ix_project_guides_project_id", - "table_name": "project_guides" - }, - { - "definition": "CREATE INDEX ix_project_guides_status ON public.project_guides USING btree (status)", - "name": "ix_project_guides_status", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_guides ON public.project_guides USING btree (id)", - "name": "pk_project_guides", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guides_id_project_version ON public.project_guides USING btree (id, project_id, version)", - "name": "uq_project_guides_id_project_version", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guides_one_active_per_project ON public.project_guides USING btree (project_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_project_guides_one_active_per_project", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guides_project_version ON public.project_guides USING btree (project_id, version)", - "name": "uq_project_guides_project_version", - "table_name": "project_guides" - }, - { - "definition": "CREATE INDEX ix_project_role_grants_actor_role_status ON public.project_role_grants USING btree (actor_profile_id, role, status)", - "name": "ix_project_role_grants_actor_role_status", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE INDEX ix_project_role_grants_project_actor_role_status ON public.project_role_grants USING btree (project_id, actor_profile_id, role, status)", - "name": "ix_project_role_grants_project_actor_role_status", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_role_grants ON public.project_role_grants USING btree (id)", - "name": "pk_project_role_grants", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_role_grants_active_exact_role ON public.project_role_grants USING btree (project_id, actor_profile_id, role) WHERE ((status)::text = 'active'::text)", - "name": "uq_project_role_grants_active_exact_role", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX grant_reference ON public.project_role_qualification_snapshots USING btree (id, actor_profile_id, project_id, requested_role)", - "name": "grant_reference", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE INDEX ix_project_role_qualification_snapshots_history ON public.project_role_qualification_snapshots USING btree (project_id, actor_profile_id, requested_role, captured_at)", - "name": "ix_project_role_qualification_snapshots_history", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_role_qualification_snapshots ON public.project_role_qualification_snapshots USING btree (id)", - "name": "pk_project_role_qualification_snapshots", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_celery_task_id ON public.project_setup_runs USING btree (celery_task_id)", - "name": "ix_project_setup_runs_celery_task_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_continuation_verification_job_id ON public.project_setup_runs USING btree (continuation_verification_job_id)", - "name": "ix_project_setup_runs_continuation_verification_job_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_error_artifact_incident_id ON public.project_setup_runs USING btree (error_artifact_incident_id)", - "name": "ix_project_setup_runs_error_artifact_incident_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_guide_id ON public.project_setup_runs USING btree (guide_id)", - "name": "ix_project_setup_runs_guide_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_output_post_submit_checker_policy_id ON public.project_setup_runs USING btree (output_post_submit_checker_policy_id)", - "name": "ix_project_setup_runs_output_post_submit_checker_policy_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_output_submission_artifact_policy_id ON public.project_setup_runs USING btree (output_submission_artifact_policy_id)", - "name": "ix_project_setup_runs_output_submission_artifact_policy_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_output_sufficiency_report_id ON public.project_setup_runs USING btree (output_sufficiency_report_id)", - "name": "ix_project_setup_runs_output_sufficiency_report_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_project_id ON public.project_setup_runs USING btree (project_id)", - "name": "ix_project_setup_runs_project_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_source_snapshot_id ON public.project_setup_runs USING btree (source_snapshot_id)", - "name": "ix_project_setup_runs_source_snapshot_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_status ON public.project_setup_runs USING btree (status)", - "name": "ix_project_setup_runs_status", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_setup_runs ON public.project_setup_runs USING btree (id)", - "name": "pk_project_setup_runs", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_exact_generation ON public.project_setup_runs USING btree (id, project_id, guide_id, source_snapshot_id, setup_generation)", - "name": "uq_project_setup_runs_exact_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_guide_generation ON public.project_setup_runs USING btree (guide_id, setup_generation)", - "name": "uq_project_setup_runs_guide_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_projects_slug ON public.projects USING btree (slug)", - "name": "ix_projects_slug", - "table_name": "projects" - }, - { - "definition": "CREATE INDEX ix_projects_status ON public.projects USING btree (status)", - "name": "ix_projects_status", - "table_name": "projects" - }, - { - "definition": "CREATE UNIQUE INDEX pk_projects ON public.projects USING btree (id)", - "name": "pk_projects", - "table_name": "projects" - }, - { - "definition": "CREATE UNIQUE INDEX uq_projects_slug ON public.projects USING btree (slug)", - "name": "uq_projects_slug", - "table_name": "projects" - }, - { - "definition": "CREATE INDEX ix_review_admission_submission ON public.review_admission_idempotency_records USING btree (submission_id, status, created_at, id)", - "name": "ix_review_admission_submission", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_admission_idempotency_records ON public.review_admission_idempotency_records USING btree (id)", - "name": "pk_review_admission_idempotency_records", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_admission_checker_run ON public.review_admission_idempotency_records USING btree (admitting_checker_run_id)", - "name": "uq_review_admission_checker_run", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_admission_operation ON public.review_admission_idempotency_records USING btree (operation_id)", - "name": "uq_review_admission_operation", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_admission_replay_key ON public.review_admission_idempotency_records USING btree (idempotency_key)", - "name": "uq_review_admission_replay_key", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_review_lease_expiry ON public.review_leases USING btree (status, expires_at, id)", - "name": "ix_review_lease_expiry", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_leases ON public.review_leases USING btree (id)", - "name": "pk_review_leases", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_active_queue ON public.review_leases USING btree (review_queue_entry_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_review_lease_active_queue", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_active_reviewer ON public.review_leases USING btree (reviewer_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_review_lease_active_reviewer", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_attempt ON public.review_leases USING btree (review_queue_entry_id, attempt_generation)", - "name": "uq_review_lease_attempt", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_queue_identity ON public.review_leases USING btree (review_queue_entry_id, id)", - "name": "uq_review_lease_queue_identity", - "table_name": "review_leases" - }, - { - "definition": "CREATE INDEX ix_review_policies_project_id ON public.review_policies USING btree (project_id)", - "name": "ix_review_policies_project_id", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_policies ON public.review_policies USING btree (id)", - "name": "pk_review_policies", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_policies_project_version_generation ON public.review_policies USING btree (project_id, guide_version, policy_generation)", - "name": "uq_review_policies_project_version_generation", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_policy_lineage ON public.review_policies USING btree (id, policy_generation, policy_hash)", - "name": "uq_review_policy_lineage", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_policy_scoped_lineage ON public.review_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", - "name": "uq_review_policy_scoped_lineage", - "table_name": "review_policies" - }, - { - "definition": "CREATE INDEX ix_review_queue_preference ON public.review_queue_entries USING btree (preferred_reviewer_id, queue_state, preference_expires_at, id)", - "name": "ix_review_queue_preference", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE INDEX ix_review_queue_selection ON public.review_queue_entries USING btree (project_id, queue_state, routing_mode, first_queued_at, id)", - "name": "ix_review_queue_selection", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_queue_entries ON public.review_queue_entries USING btree (id)", - "name": "pk_review_queue_entries", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_queue_admission_identity ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", - "name": "uq_review_queue_admission_identity", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_queue_lease_lineage ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version)", - "name": "uq_review_queue_lease_lineage", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_queue_submission ON public.review_queue_entries USING btree (submission_id)", - "name": "uq_review_queue_submission", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE INDEX ix_revision_policies_project_id ON public.revision_policies USING btree (project_id)", - "name": "ix_revision_policies_project_id", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_revision_policies ON public.revision_policies USING btree (id)", - "name": "pk_revision_policies", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_revision_policies_project_version_generation ON public.revision_policies USING btree (project_id, guide_version, policy_generation)", - "name": "uq_revision_policies_project_version_generation", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_revision_policy_lineage ON public.revision_policies USING btree (id, policy_generation, policy_hash)", - "name": "uq_revision_policy_lineage", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_revision_policy_scoped_lineage ON public.revision_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", - "name": "uq_revision_policy_scoped_lineage", - "table_name": "revision_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_guide_id ON public.submission_artifact_policies USING btree (guide_id)", - "name": "ix_submission_artifact_policies_guide_id", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_lifecycle_status ON public.submission_artifact_policies USING btree (lifecycle_status)", - "name": "ix_submission_artifact_policies_lifecycle_status", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_policy_hash ON public.submission_artifact_policies USING btree (policy_hash)", - "name": "ix_submission_artifact_policies_policy_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_project_id ON public.submission_artifact_policies USING btree (project_id)", - "name": "ix_submission_artifact_policies_project_id", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_source_snapshot_id ON public.submission_artifact_policies USING btree (source_snapshot_id)", - "name": "ix_submission_artifact_policies_source_snapshot_id", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_artifact_policies ON public.submission_artifact_policies USING btree (id)", - "name": "pk_submission_artifact_policies", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_id_hash ON public.submission_artifact_policies USING btree (id, policy_hash)", - "name": "uq_submission_artifact_policies_id_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_project_version_policy ON public.submission_artifact_policies USING btree (project_id, guide_version, policy_version)", - "name": "uq_submission_artifact_policies_project_version_policy", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_actor_profile_id ON public.submission_bundle_admissions USING btree (actor_profile_id)", - "name": "ix_submission_bundle_admissions_actor_profile_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_artifact_content_id ON public.submission_bundle_admissions USING btree (artifact_content_id)", - "name": "ix_submission_bundle_admissions_artifact_content_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_pre_submit_evidence_set_id ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", - "name": "ix_submission_bundle_admissions_pre_submit_evidence_set_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_project_id ON public.submission_bundle_admissions USING btree (project_id)", - "name": "ix_submission_bundle_admissions_project_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_status ON public.submission_bundle_admissions USING btree (status)", - "name": "ix_submission_bundle_admissions_status", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_task_id ON public.submission_bundle_admissions USING btree (task_id)", - "name": "ix_submission_bundle_admissions_task_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_bundle_admissions ON public.submission_bundle_admissions USING btree (id)", - "name": "pk_submission_bundle_admissions", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_consumer ON public.submission_bundle_admissions USING btree (consumed_by_submission_id) WHERE (consumed_by_submission_id IS NOT NULL)", - "name": "uq_submission_bundle_admission_consumer", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_evidence ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", - "name": "uq_submission_bundle_admission_evidence", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_intent ON public.submission_bundle_admissions USING btree (durable_intent_id)", - "name": "uq_submission_bundle_admission_intent", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_verification ON public.submission_bundle_admissions USING btree (verification_receipt_id)", - "name": "uq_submission_bundle_admission_verification", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_durable_intents_pre_submit_evidence_set_id ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", - "name": "ix_submission_bundle_durable_intents_pre_submit_evidence_set_id", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_durable_intents_put_attempt_id ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", - "name": "ix_submission_bundle_durable_intents_put_attempt_id", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_bundle_durable_intents ON public.submission_bundle_durable_intents USING btree (id)", - "name": "pk_submission_bundle_durable_intents", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_evidence ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", - "name": "uq_submission_bundle_intent_evidence", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_put_attempt ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", - "name": "uq_submission_bundle_intent_put_attempt", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_policy_mutation_idempotency_records ON public.submission_policy_mutation_idempotency_records USING btree (id)", - "name": "pk_submission_policy_mutation_idempotency_records", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_committed_policy_action ON public.submission_policy_mutation_idempotency_records USING btree (committed_policy_id, action_id) WHERE ((status)::text = 'committed'::text)", - "name": "uq_submission_policy_committed_policy_action", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_human_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key) WHERE (service_identity IS NULL)", - "name": "uq_submission_policy_human_replay_namespace", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_operation_identity ON public.submission_policy_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_submission_policy_operation_identity", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_service_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, setup_run_id, setup_generation, setup_task_id, correlation_id, action_id) WHERE (service_identity IS NOT NULL)", - "name": "uq_submission_policy_service_replay_namespace", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_submissions_contributor_id ON public.submissions USING btree (contributor_id)", - "name": "ix_submissions_contributor_id", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_effective_policy_hash ON public.submissions USING btree (locked_effective_project_submission_artifact_policy_hash)", - "name": "ix_submissions_locked_effective_policy_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_post_submit_policy_hash ON public.submissions USING btree (locked_post_submit_checker_policy_hash)", - "name": "ix_submissions_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_pre_submit_checker_hash ON public.submissions USING btree (locked_pre_submit_checker_bundle_hash)", - "name": "ix_submissions_locked_pre_submit_checker_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_source_snapshot ON public.submissions USING btree (locked_guide_source_snapshot_id)", - "name": "ix_submissions_locked_source_snapshot", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_status ON public.submissions USING btree (status)", - "name": "ix_submissions_status", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_supersedes_submission_id ON public.submissions USING btree (supersedes_submission_id)", - "name": "ix_submissions_supersedes_submission_id", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_task_id ON public.submissions USING btree (task_id)", - "name": "ix_submissions_task_id", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submissions ON public.submissions USING btree (id)", - "name": "pk_submissions", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_id_locked_post_submit_policy_hash ON public.submissions USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "name": "uq_submissions_id_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_id_task_version ON public.submissions USING btree (id, task_id, version)", - "name": "uq_submissions_id_task_version", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_id_version ON public.submissions USING btree (id, version)", - "name": "uq_submissions_id_version", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_task_version ON public.submissions USING btree (task_id, version)", - "name": "uq_submissions_task_version", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_task_assignments_contributor_id ON public.task_assignments USING btree (contributor_id)", - "name": "ix_task_assignments_contributor_id", - "table_name": "task_assignments" - }, - { - "definition": "CREATE INDEX ix_task_assignments_status ON public.task_assignments USING btree (status)", - "name": "ix_task_assignments_status", - "table_name": "task_assignments" - }, - { - "definition": "CREATE INDEX ix_task_assignments_task_id ON public.task_assignments USING btree (task_id)", - "name": "ix_task_assignments_task_id", - "table_name": "task_assignments" - }, - { - "definition": "CREATE UNIQUE INDEX pk_task_assignments ON public.task_assignments USING btree (id)", - "name": "pk_task_assignments", - "table_name": "task_assignments" - }, - { - "definition": "CREATE UNIQUE INDEX uq_task_assignments_id_task_contributor ON public.task_assignments USING btree (id, task_id, contributor_id)", - "name": "uq_task_assignments_id_task_contributor", - "table_name": "task_assignments" - }, - { - "definition": "CREATE UNIQUE INDEX uq_task_assignments_one_active_per_task ON public.task_assignments USING btree (task_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_task_assignments_one_active_per_task", - "table_name": "task_assignments" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_assigned_to ON public.workstream_tasks USING btree (assigned_to)", - "name": "ix_workstream_tasks_assigned_to", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_effective_policy_hash ON public.workstream_tasks USING btree (locked_effective_project_submission_artifact_policy_hash)", - "name": "ix_workstream_tasks_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (locked_post_submit_checker_policy_hash)", - "name": "ix_workstream_tasks_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (locked_pre_submit_checker_bundle_hash)", - "name": "ix_workstream_tasks_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_source_snapshot ON public.workstream_tasks USING btree (locked_guide_source_snapshot_id)", - "name": "ix_workstream_tasks_locked_source_snapshot", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_project_id ON public.workstream_tasks USING btree (project_id)", - "name": "ix_workstream_tasks_project_id", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_status ON public.workstream_tasks USING btree (status)", - "name": "ix_workstream_tasks_status", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX pk_workstream_tasks ON public.workstream_tasks USING btree (id)", - "name": "pk_workstream_tasks", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_effective_policy_hash ON public.workstream_tasks USING btree (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "name": "uq_workstream_tasks_id_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_guide ON public.workstream_tasks USING btree (id, locked_guide_version)", - "name": "uq_workstream_tasks_id_locked_guide", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_payment_policy ON public.workstream_tasks USING btree (id, locked_payment_policy_version)", - "name": "uq_workstream_tasks_id_locked_payment_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_review_policy ON public.workstream_tasks USING btree (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "name": "uq_workstream_tasks_id_locked_review_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_revision_policy ON public.workstream_tasks USING btree (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "name": "uq_workstream_tasks_id_locked_revision_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_source_snapshot_hash ON public.workstream_tasks USING btree (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_project ON public.workstream_tasks USING btree (id, project_id)", - "name": "uq_workstream_tasks_id_project", - "table_name": "workstream_tasks" - } - ], - "policies": [], - "reference_rows": { - "actor_profile_migration_state": [ - { - "classified_count": 0, - "envelope_sha256": null, - "id": 1, - "manifest_sha256": null, - "migrated_at": "2026-08-11T08:18:03.063940+00:00", - "schema_version": 1, - "service_identity_database_binding": "postgres-v1:aa1108b4a868ca4330673d1bbe499d99c330d196994696d89e56cf09bfc3c93e", - "service_identity_envelope_sha256": null, - "service_identity_manifest_sha256": null, - "service_identity_mapped_count": 0, - "service_identity_source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945", - "source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" - } - ], - "authority_control": [ - { - "bootstrap_completed": false, - "bootstrap_grant_id": null, - "created_at": "2026-08-11T08:18:13.474128+00:00", - "id": 1, - "updated_at": "2026-08-11T08:18:13.474148+00:00", - "version": 0 - } - ], - "iso_4217_currency_codes": [ - { - "code": "AED" - }, - { - "code": "AFN" - }, - { - "code": "ALL" - }, - { - "code": "AMD" - }, - { - "code": "AOA" - }, - { - "code": "ARS" - }, - { - "code": "AUD" - }, - { - "code": "AWG" - }, - { - "code": "AZN" - }, - { - "code": "BAM" - }, - { - "code": "BBD" - }, - { - "code": "BDT" - }, - { - "code": "BHD" - }, - { - "code": "BIF" - }, - { - "code": "BMD" - }, - { - "code": "BND" - }, - { - "code": "BOB" - }, - { - "code": "BOV" - }, - { - "code": "BRL" - }, - { - "code": "BSD" - }, - { - "code": "BTN" - }, - { - "code": "BWP" - }, - { - "code": "BYN" - }, - { - "code": "BZD" - }, - { - "code": "CAD" - }, - { - "code": "CDF" - }, - { - "code": "CHE" - }, - { - "code": "CHF" - }, - { - "code": "CHW" - }, - { - "code": "CLF" - }, - { - "code": "CLP" - }, - { - "code": "CNY" - }, - { - "code": "COP" - }, - { - "code": "COU" - }, - { - "code": "CRC" - }, - { - "code": "CUP" - }, - { - "code": "CVE" - }, - { - "code": "CZK" - }, - { - "code": "DJF" - }, - { - "code": "DKK" - }, - { - "code": "DOP" - }, - { - "code": "DZD" - }, - { - "code": "EGP" - }, - { - "code": "ERN" - }, - { - "code": "ETB" - }, - { - "code": "EUR" - }, - { - "code": "FJD" - }, - { - "code": "FKP" - }, - { - "code": "GBP" - }, - { - "code": "GEL" - }, - { - "code": "GHS" - }, - { - "code": "GIP" - }, - { - "code": "GMD" - }, - { - "code": "GNF" - }, - { - "code": "GTQ" - }, - { - "code": "GYD" - }, - { - "code": "HKD" - }, - { - "code": "HNL" - }, - { - "code": "HTG" - }, - { - "code": "HUF" - }, - { - "code": "IDR" - }, - { - "code": "ILS" - }, - { - "code": "INR" - }, - { - "code": "IQD" - }, - { - "code": "IRR" - }, - { - "code": "ISK" - }, - { - "code": "JMD" - }, - { - "code": "JOD" - }, - { - "code": "JPY" - }, - { - "code": "KES" - }, - { - "code": "KGS" - }, - { - "code": "KHR" - }, - { - "code": "KMF" - }, - { - "code": "KPW" - }, - { - "code": "KRW" - }, - { - "code": "KWD" - }, - { - "code": "KYD" - }, - { - "code": "KZT" - }, - { - "code": "LAK" - }, - { - "code": "LBP" - }, - { - "code": "LKR" - }, - { - "code": "LRD" - }, - { - "code": "LSL" - }, - { - "code": "LYD" - }, - { - "code": "MAD" - }, - { - "code": "MDL" - }, - { - "code": "MGA" - }, - { - "code": "MKD" - }, - { - "code": "MMK" - }, - { - "code": "MNT" - }, - { - "code": "MOP" - }, - { - "code": "MRU" - }, - { - "code": "MUR" - }, - { - "code": "MVR" - }, - { - "code": "MWK" - }, - { - "code": "MXN" - }, - { - "code": "MXV" - }, - { - "code": "MYR" - }, - { - "code": "MZN" - }, - { - "code": "NAD" - }, - { - "code": "NGN" - }, - { - "code": "NIO" - }, - { - "code": "NOK" - }, - { - "code": "NPR" - }, - { - "code": "NZD" - }, - { - "code": "OMR" - }, - { - "code": "PAB" - }, - { - "code": "PEN" - }, - { - "code": "PGK" - }, - { - "code": "PHP" - }, - { - "code": "PKR" - }, - { - "code": "PLN" - }, - { - "code": "PYG" - }, - { - "code": "QAR" - }, - { - "code": "RON" - }, - { - "code": "RSD" - }, - { - "code": "RUB" - }, - { - "code": "RWF" - }, - { - "code": "SAR" - }, - { - "code": "SBD" - }, - { - "code": "SCR" - }, - { - "code": "SDG" - }, - { - "code": "SEK" - }, - { - "code": "SGD" - }, - { - "code": "SHP" - }, - { - "code": "SLE" - }, - { - "code": "SOS" - }, - { - "code": "SRD" - }, - { - "code": "SSP" - }, - { - "code": "STN" - }, - { - "code": "SVC" - }, - { - "code": "SYP" - }, - { - "code": "SZL" - }, - { - "code": "THB" - }, - { - "code": "TJS" - }, - { - "code": "TMT" - }, - { - "code": "TND" - }, - { - "code": "TOP" - }, - { - "code": "TRY" - }, - { - "code": "TTD" - }, - { - "code": "TWD" - }, - { - "code": "TZS" - }, - { - "code": "UAH" - }, - { - "code": "UGX" - }, - { - "code": "USD" - }, - { - "code": "USN" - }, - { - "code": "UYI" - }, - { - "code": "UYU" - }, - { - "code": "UYW" - }, - { - "code": "UZS" - }, - { - "code": "VED" - }, - { - "code": "VES" - }, - { - "code": "VND" - }, - { - "code": "VUV" - }, - { - "code": "WST" - }, - { - "code": "XAD" - }, - { - "code": "XAF" - }, - { - "code": "XAG" - }, - { - "code": "XAU" - }, - { - "code": "XBA" - }, - { - "code": "XBB" - }, - { - "code": "XBC" - }, - { - "code": "XBD" - }, - { - "code": "XCD" - }, - { - "code": "XCG" - }, - { - "code": "XDR" - }, - { - "code": "XOF" - }, - { - "code": "XPD" - }, - { - "code": "XPF" - }, - { - "code": "XPT" - }, - { - "code": "XSU" - }, - { - "code": "XTS" - }, - { - "code": "XUA" - }, - { - "code": "XXX" - }, - { - "code": "YER" - }, - { - "code": "ZAR" - }, - { - "code": "ZMW" - }, - { - "code": "ZWG" - } - ] - }, - "routines": [ - { - "arguments": "event_name text, before_state json, after_state json, envelope_project_id text", - "definition": "CREATE OR REPLACE FUNCTION public.authority_event_facts_are_safe(event_name text, before_state json, after_state json, envelope_project_id text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE AS $function$ begin if not (event_name='AuthorityInvalidationRequested' and before_state is not null and after_state is not null and coalesce(before_state::jsonb ? 'future_obligation', false) and coalesce(after_state::jsonb ? 'future_obligation', false)) and ((before_state is not null and not authority_facts_are_safe(before_state)) or (after_state is not null and not authority_facts_are_safe(after_state))) then return false; end if; case event_name when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"human\",\"provisioning_method\":\"automatic_first_access\"}'::jsonb; when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"service\",\"provisioning_method\":\"manual_service_provisioning\"}'::jsonb; when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( '{\"status\":\"active\",\"subject_kind\":\"human\"}'::jsonb, '{\"status\":\"active\",\"subject_kind\":\"service\"}'::jsonb); when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"revoked\"}'::jsonb; when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{\"status\":\"revoked\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileSuspended' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"suspended\"}'::jsonb; when 'ActorProfileReactivated' then return before_state::jsonb='{\"status\":\"suspended\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileDeactivated' then return before_state::jsonb in ('{\"status\":\"active\"}'::jsonb,'{\"status\":\"suspended\"}'::jsonb) and after_state::jsonb='{\"status\":\"deactivated\"}'::jsonb; when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','adjudicator'],'active',true,envelope_project_id); when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then return authority_grant_facts_are_safe(before_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'active',true,envelope_project_id) and authority_grant_facts_are_safe(after_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'revoked',false,envelope_project_id) and before_state->>'role'=after_state->>'role' and before_state->>'scope_type'=after_state->>'scope_type' and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{\"status\":\"captured\"}'::jsonb; when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; when 'SensitiveAuthorizationAllowed' then return before_state is null and ( after_state::jsonb = '{\"allowed\": true}'::jsonb or ( after_state::jsonb->'allowed' = 'true'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'SensitiveAuthorizationDenied' then return before_state is null and ( after_state::jsonb = '{\"allowed\": false}'::jsonb or ( after_state::jsonb->'allowed' = 'false'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'AuthorityInvalidationRequested' then return (before_state::jsonb = '{\"effective\": true}'::jsonb and after_state::jsonb = '{\"effective\": false}'::jsonb) or (before_state::jsonb = '{\"effective\": false}'::jsonb and after_state::jsonb = '{\"effective\": true}'::jsonb) or ( jsonb_typeof(before_state::jsonb)='object' and jsonb_typeof(after_state::jsonb)='object' and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and before_state::jsonb->'effective'='true'::jsonb and after_state::jsonb->'effective'='false'::jsonb and jsonb_typeof(before_state::jsonb->'role')='string' and jsonb_typeof(before_state::jsonb->'scope_type')='string' and jsonb_typeof(before_state::jsonb->'scope_id')='string' and jsonb_typeof(before_state::jsonb->'future_obligation')='string' and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') and before_state::jsonb->>'scope_type'='project' and before_state::jsonb->>'scope_id'=envelope_project_id and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) ); else return false; end case; end $function$", - "name": "authority_event_facts_are_safe" - }, - { - "arguments": "facts json", - "definition": "CREATE OR REPLACE FUNCTION public.authority_facts_are_safe(facts json) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select json_typeof(facts) = 'object' and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) and not exists ( select 1 from json_each(facts) item where item.key not in ( 'status', 'subject_kind', 'provisioning_method', 'role', 'scope_type', 'scope_id', 'effective', 'allowed', 'resource_context_digest' ) or case item.key when 'status' then item.value #>> '{}' not in ( 'active', 'suspended', 'deactivated', 'revoked', 'captured' ) when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') when 'provisioning_method' then item.value #>> '{}' not in ( 'automatic_first_access', 'manual_service_provisioning' ) when 'role' then item.value #>> '{}' not in ( 'access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' ) when 'scope_type' then item.value #>> '{}' not in ('system', 'project') when 'scope_id' then (item.value #>> '{}') !~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' when 'effective' then json_typeof(item.value) <> 'boolean' when 'allowed' then json_typeof(item.value) <> 'boolean' when 'resource_context_digest' then (item.value #>> '{}') !~ '^sha256:[0-9a-f]{64}$' else true end ) $function$", - "name": "authority_facts_are_safe" - }, - { - "arguments": "facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text", - "definition": "CREATE OR REPLACE FUNCTION public.authority_grant_facts_are_safe(facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text) RETURNS boolean LANGUAGE sql IMMUTABLE AS $function$ select authority_facts_are_safe(facts) and facts->>'role' = any(roles) and facts->>'status' = expected_status and (facts->>'effective')::boolean = expected_effective and ( ( facts->>'scope_type' = 'system' and envelope_project_id is null and not facts::jsonb ? 'scope_id' and facts->>'role' not in ('submitter', 'reviewer', 'both') and (select count(*) from json_each(facts)) = 4 ) or ( facts->>'scope_type' = 'project' and envelope_project_id is not null and facts->>'scope_id' = envelope_project_id and facts->>'role' not in ('access_administrator', 'operator') and (select count(*) from json_each(facts)) = 5 ) ) $function$", - "name": "authority_grant_facts_are_safe" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.enforce_compensation_binding_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compensation_binding_updates_deferred'; return new; end; $function$", - "name": "enforce_compensation_binding_lifecycle" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_identity_link_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then raise exception 'actor identity link anchor is immutable' using errcode='55000'; end if; if new.status=old.status and (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'identity link attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='revoked' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid identity link revocation attribution' using errcode='23514'; end if; if old.status='revoked' and new.status='active' and ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then raise exception 'invalid identity link reactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status='revoked') or (old.status='revoked' and new.status='active')) then raise exception 'invalid identity link lifecycle transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_actor_identity_link_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_profile_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then raise exception 'actor profile identity is immutable' using errcode='55000'; end if; if old.status='deactivated' and new.status <> 'deactivated' then raise exception 'deactivated actor is terminal' using errcode='23514'; end if; if new.status = old.status and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='suspended' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'invalid actor suspension attribution' using errcode='23514'; end if; if old.status='suspended' and new.status='active' and ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then raise exception 'invalid actor reactivation attribution' using errcode='23514'; end if; if new.status='deactivated' and old.status in ('active','suspended') and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid actor deactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status in ('suspended','deactivated')) or (old.status='suspended' and new.status in ('active','deactivated'))) then raise exception 'invalid actor lifecycle transition' using errcode='23514'; end if; new.updated_at = statement_timestamp(); return new; end $function$", - "name": "guard_actor_profile_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_admin_role_grant() RETURNS trigger LANGUAGE plpgsql AS $function$ declare target_kind text; authorizer admin_role_grants%rowtype; bootstrap_done boolean; begin if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; if tg_op='INSERT' then select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; new.granted_at := clock_timestamp(); if new.granted_by_system_principal is not null then if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; if bootstrap_done is distinct from false or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then raise exception 'bootstrap already completed' using errcode='23514'; end if; else select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; end if; return new; end if; if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, new.granted_by_actor_profile_id,new.granted_by_system_principal, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, old.granted_by_actor_profile_id,old.granted_by_system_principal, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then raise exception 'invalid admin role grant transition' using errcode='23514'; end if; select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", - "name": "guard_admin_role_grant" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_artifact_receipt_producer_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id; if request_type is null or (request_type = 'guide' and not ( new.guide_source_item_id is not null and new.checker_run_id is null and new.logical_role is null)) or (request_type = 'checker_output' and not ( new.guide_source_item_id is null and new.checker_run_id is not null and octet_length(new.logical_role) between 1 and 100)) or (request_type = 'submission_bundle' and not ( new.guide_source_item_id is null and new.checker_run_id is null and new.logical_role is null)) then raise exception 'artifact receipt producer reference mismatch' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_artifact_receipt_producer_reference" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_control() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; if old.id <> 1 or old.bootstrap_completed or old.version <> 0 or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then raise exception 'invalid authority control transition' using errcode='23514'; end if; new.updated_at := clock_timestamp(); return new; end $function$", - "name": "guard_authority_control" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_idempotency_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare success_count integer; invalidation_count integer; success_id text; qualification_row audit_events%rowtype; success_row audit_events%rowtype; grant_row project_role_grants%rowtype; snapshot_row project_role_qualification_snapshots%rowtype; begin if tg_op = 'INSERT' then if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; new.created_at := statement_timestamp(); new.committed_at := null; return new; elsif tg_op = 'DELETE' then raise exception 'authority idempotency records are immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, new.request_digest,new.created_at) is distinct from (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, old.request_digest,old.created_at) then raise exception 'invalid authority idempotency transition' using errcode='23514'; end if; select count(*), min(id) into success_count, success_id from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type <> 'AuthorityInvalidationRequested'; select count(*) into invalidation_count from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type='AuthorityInvalidationRequested'; if new.operation='project_role_grant.issue' then if success_count <> 2 or invalidation_count <> 0 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued') <> 1 then raise exception 'project role issue evidence pair required' using errcode='23514'; end if; select * into qualification_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured'; select * into success_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued'; select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; select * into snapshot_row from project_role_qualification_snapshots where id=qualification_row.resource_id::uuid; if not found or grant_row.id is null or snapshot_row.id is null or grant_row.qualification_snapshot_id <> snapshot_row.id or grant_row.project_id <> snapshot_row.project_id or grant_row.actor_profile_id <> snapshot_row.actor_profile_id or grant_row.role <> snapshot_row.requested_role or qualification_row.project_id is distinct from grant_row.project_id or success_row.project_id is distinct from grant_row.project_id or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id or success_row.target_actor_ref is distinct from grant_row.actor_profile_id or qualification_row.request_id is distinct from success_row.request_id or qualification_row.correlation_id is distinct from success_row.correlation_id or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind or qualification_row.actor_id is distinct from success_row.actor_id or qualification_row.permission_id is distinct from success_row.permission_id or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then raise exception 'project role issue evidence mismatch' using errcode='23514'; end if; else if success_count <> 1 or invalidation_count <> 1 then raise exception 'authority evidence pair required' using errcode='23514'; end if; select * into success_row from audit_events where id=success_id; end if; if success_row.resource_type <> new.response_resource_type or success_row.resource_id <> new.response_resource_id::text then raise exception 'authority response does not match evidence' using errcode='23514'; end if; new.committed_at := statement_timestamp(); return new; end $function$", - "name": "guard_authority_idempotency_record" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_children() RETURNS trigger LANGUAGE plpgsql AS $function$ declare old_parent_status text; declare new_parent_status text; begin if tg_op in ('UPDATE','DELETE') then select status into old_parent_status from contribution_policy_versions where id=old.contribution_policy_version_id for update; end if; if tg_op in ('INSERT','UPDATE') then select status into new_parent_status from contribution_policy_versions where id=new.contribution_policy_version_id for update; end if; if old_parent_status in ('published','retired') or new_parent_status in ('published','retired') then raise exception 'published contribution policy rules and definitions are immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", - "name": "guard_contribution_policy_children" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_version_content() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' and old.status in ('published','retired') then raise exception 'published contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='retired' then raise exception 'retired contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='published' and not ( new.status='retired' and new.id=old.id and new.contribution_policy_id=old.contribution_policy_id and new.project_id=old.project_id and new.version_number=old.version_number and new.created_by=old.created_by and new.created_at=old.created_at and new.published_by=old.published_by and new.published_at=old.published_at and new.retired_by is not null and new.retired_at is not null ) then raise exception 'published contribution policy version content is immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", - "name": "guard_contribution_policy_version_content" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_lineage_and_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if (new.id,new.project_id,new.version) is distinct from (old.id,old.project_id,old.version) then raise exception 'guide identity and lineage are immutable' using errcode='23514'; end if; if (new.status,new.approved_by,new.effective_at,new.superseded_at) is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then raise exception 'guide lifecycle mutation requires activation authority' using errcode='23514'; end if; return new; end $function$", - "name": "guard_guide_lineage_and_lifecycle" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_mutation_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'guide mutation custody is immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status<>'pending' or new.status<>'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, new.operation_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, old.operation_generation,old.created_at) then raise exception 'invalid guide mutation custody transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_guide_mutation_idempotency" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_iso_4217_currency_codes() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' using errcode='55000'; end; $function$", - "name": "guard_iso_4217_currency_codes" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_outbox_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare event_time timestamptz; begin if tg_op = 'TRUNCATE' then raise exception 'outbox events cannot be truncated' using errcode='55000'; elsif tg_op = 'DELETE' then raise exception 'outbox events cannot be deleted' using errcode='55000'; elsif tg_op = 'INSERT' then event_time := statement_timestamp(); new.producer := 'workstream'; new.occurred_at := event_time; new.delivery_state := 'pending'; new.attempt_count := 0; new.next_attempt_at := event_time; new.claim_owner := null; new.claim_generation := 0; new.claimed_at := null; new.claim_expires_at := null; new.last_attempt_at := null; new.last_error_code := null; new.finalized_at := null; new.archived_at := null; return new; end if; if (new.event_id, new.event_type, new.event_version, new.producer, new.aggregate_type, new.aggregate_id, new.project_id, new.correlation_id, new.causation_event_id, new.idempotency_key, new.payload, new.payload_digest, new.occurred_at) is distinct from (old.event_id, old.event_type, old.event_version, old.producer, old.aggregate_type, old.aggregate_id, old.project_id, old.correlation_id, old.causation_event_id, old.idempotency_key, old.payload, old.payload_digest, old.occurred_at) then raise exception 'outbox event envelope is immutable' using errcode='55000'; end if; if new.attempt_count < old.attempt_count or new.claim_generation < old.claim_generation or new.attempt_count <> new.claim_generation then raise exception 'outbox counters cannot regress' using errcode='23514'; end if; if old.archived_at is not null and (new.delivery_state, new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.delivery_state, old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'archived outbox event is closed' using errcode='55000'; end if; if old.delivery_state in ('pending', 'retryable') and new.delivery_state = 'claimed' then if new.attempt_count <> old.attempt_count + 1 or new.claim_generation <> old.claim_generation + 1 or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox claim generation must increment once' using errcode='23514'; end if; elsif old.delivery_state = 'claimed' and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at then raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state = 'dead_letter' and new.delivery_state = 'retryable' and old.archived_at is null then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = 'cancelled' then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.attempt_count, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; end if; elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at) is distinct from (old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at) or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) or (old.archived_at is null and new.archived_at is null) then raise exception 'terminal outbox event permits archival only' using errcode='23514'; end if; else raise exception 'illegal outbox delivery transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_outbox_event" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_policy_mutation_replay() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'policy mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'policy mutation replay is immutable' using errcode='55000'; elsif new is not distinct from old then return new; elsif old.status='pending' and new.status='committed' and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest,new.policy_hash, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.policy_id, new.policy_generation,new.created_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest,old.policy_hash, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.policy_id, old.policy_generation,old.created_at) then return new; end if; raise exception 'policy mutation replay is immutable' using errcode='23514'; end $function$", - "name": "guard_policy_mutation_replay" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_result_membership() RETURNS trigger LANGUAGE plpgsql AS $function$ declare parent_created_at timestamptz; expected_count integer; current_count integer; begin select created_at, result_count into parent_created_at, expected_count from pre_submit_evidence_sets where id=new.evidence_set_id for key share; select count(*) into current_count from pre_submit_evidence_results where evidence_set_id=new.evidence_set_id; if parent_created_at is null or parent_created_at <> transaction_timestamp() or current_count >= expected_count then raise exception 'pre-submit evidence result membership is closed' using errcode='55000'; end if; return new; end; $function$", - "name": "guard_pre_submit_evidence_result_membership" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_results_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_results rows are immutable' using errcode='55000'; end; $function$", - "name": "guard_pre_submit_evidence_results_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_set_creation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.created_at is distinct from transaction_timestamp() then raise exception 'pre-submit evidence creation timestamp is invalid' using errcode='55000'; end if; return new; end; $function$", - "name": "guard_pre_submit_evidence_set_creation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_sets_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_sets rows are immutable' using errcode='55000'; end; $function$", - "name": "guard_pre_submit_evidence_sets_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_compensation_units() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('UPDATE','DELETE') then raise exception 'project compensation-unit lifecycle behavior is deferred' using errcode='55000'; end if; if new.status <> 'active' then raise exception 'project compensation units must begin active' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_project_compensation_units" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_create_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'INSERT' then if new.status <> 'pending' or new.committed_at is not null then raise exception 'project create reservation must begin pending' using errcode='23514'; end if; return new; elsif tg_op = 'DELETE' then raise exception 'project create reservations are immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, new.idempotency_key, new.request_digest, new.operation_id, new.project_id, new.operation_generation, new.created_at) is distinct from (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, old.idempotency_key, old.request_digest, old.operation_id, old.project_id, old.operation_generation, old.created_at) then raise exception 'invalid project create reservation transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_project_create_idempotency" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_attempt_update() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, new.pre_catalogue_version,new.pre_catalogue_schema_version, new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.provider_idempotency_key) is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, old.source_snapshot_hash,old.setup_run_id,old.setup_generation, old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, old.pre_catalogue_version,old.pre_catalogue_schema_version, old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, old.agent_identity,old.agent_version,old.instruction_version, old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; if new.reserved_at is distinct from old.reserved_at then raise exception 'compilation reservation timestamp is immutable'; end if; if new.provider_uncertain_at is distinct from old.provider_uncertain_at and not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then raise exception 'provider uncertainty timestamp is immutable'; end if; if new.accepted_at is distinct from old.accepted_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then raise exception 'accepted timestamp is immutable'; end if; if new.terminal_at is distinct from old.terminal_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then raise exception 'terminal timestamp is immutable'; end if; if row(new.persisted_at,new.persisted_compilation_id) is distinct from row(old.persisted_at,old.persisted_compilation_id) and not (old.status='provider_result_accepted' and new.status='compilation_persisted') then raise exception 'persisted custody is immutable'; end if; if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then raise exception 'accepted compilation result is immutable'; end if; if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or (old.status='provider_result_accepted' and new.status='compilation_persisted')) then raise exception 'invalid compilation attempt transition'; end if; return new; end $function$", - "name": "guard_project_guide_compilation_attempt_update" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_insert() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor_generation bigint; declare source_attempt project_guide_compilation_attempts%rowtype; begin select * into source_attempt from project_guide_compilation_attempts where id=new.attempt_id for update; if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash, new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) is distinct from row(source_attempt.project_id,source_attempt.guide_id, source_attempt.guide_version,source_attempt.source_snapshot_id, source_attempt.source_snapshot_hash,source_attempt.setup_run_id, source_attempt.setup_generation,source_attempt.canonical_input_hash, source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, source_attempt.agent_version,source_attempt.instruction_version, source_attempt.canonical_result::jsonb,source_attempt.result_hash, source_attempt.component_hashes::jsonb) then raise exception 'compilation does not match its accepted attempt'; end if; if not exists( select 1 from audit_events event join actor_profiles profile on profile.id=new.created_by_actor_profile_id join actor_identity_links link on link.id=new.created_via_identity_link_id and link.actor_profile_id=profile.id where event.id=new.authorization_decision_event_id and event.event_domain='authority' and event.event_type='SensitiveAuthorizationAllowed' and event.denial_code is null and event.actor_id=new.created_by_actor_profile_id and event.permission_id='project.guide_compilation.execute' and event.action_id='project.guide_compilation.execute' and event.project_id=new.project_id and event.resource_type='project_guide_compilation_attempt' and event.resource_id=new.attempt_id::text and event.after_facts->>'allowed'='true' and event.after_facts->>'resource_context_digest'= new.authorization_resource_context_digest and profile.actor_kind='service' and profile.status='active' and profile.service_identity='workstream.project.setup' and link.subject_kind='service' and link.status='active' and link.issuer='workstream-internal' and link.subject='workstream.project.setup' ) then raise exception 'compilation authorization evidence is invalid'; end if; if new.supersedes_compilation_id is null then return new; end if; select setup_generation into predecessor_generation from project_guide_compilations where id=new.supersedes_compilation_id and project_id=new.project_id and guide_id=new.guide_id; if predecessor_generation is null or predecessor_generation >= new.setup_generation then raise exception 'compilation generation must strictly advance'; end if; return new; end $function$", - "name": "guard_project_guide_compilation_insert" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_policy_selection() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.status in ('active','superseded') and ( new.selected_review_policy_id is distinct from old.selected_review_policy_id or new.selected_review_policy_generation is distinct from old.selected_review_policy_generation or new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or new.selected_revision_policy_generation is distinct from old.selected_revision_policy_generation or new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash ) then raise exception 'active guide policy selection is immutable' using errcode='55000'; end if; return new; end $function$", - "name": "guard_project_guide_policy_selection" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_grant_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, new.qualification_snapshot_id,new.granted_by_actor_profile_id, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, old.qualification_snapshot_id,old.granted_by_actor_profile_id, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null or new.revoked_reason is null then raise exception 'invalid project-role grant history transition' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", - "name": "guard_project_role_grant_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_snapshot_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; end $function$", - "name": "guard_project_role_snapshot_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_admission_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review admission records cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' and new.status <> 'pending' then raise exception 'review admission must begin pending' using errcode='23514'; end if; if tg_op='INSERT' then new.created_at := statement_timestamp(); end if; if tg_op='UPDATE' then if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.created_at) is distinct from (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.created_at) then raise exception 'review admission identity is immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' then raise exception 'invalid review admission transition' using errcode='23514'; end if; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review admission task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review admission checker lineage mismatch' using errcode='23514'; end if; if new.status='committed' and ( checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true) then raise exception 'review admission checker is not admissible' using errcode='23514'; end if; return new; end $function$", - "name": "guard_review_admission_record" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare actor_type text; policy_status text; begin if tg_op='DELETE' then raise exception 'review leases cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.status <> 'active' then raise exception 'review lease must begin active' using errcode='23514'; end if; new.claimed_at := statement_timestamp(); new.closed_at := null; new.close_reason := null; else if old.status <> 'active' then raise exception 'terminal review leases are immutable' using errcode='55000'; end if; if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, new.submission_version,new.reviewer_id, new.reviewer_contribution_policy_version_id,new.attempt_generation, new.claimed_at,new.expires_at) is distinct from (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, old.submission_version,old.reviewer_id, old.reviewer_contribution_policy_version_id,old.attempt_generation, old.claimed_at,old.expires_at) then raise exception 'review lease identity is immutable' using errcode='55000'; end if; if new.status='active' then raise exception 'review lease update must close attempt' using errcode='23514'; end if; end if; select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; if actor_type is distinct from 'human' then raise exception 'review lease reviewer must be human' using errcode='23514'; end if; if tg_op='INSERT' then select status into policy_status from contribution_policy_versions where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; if policy_status is distinct from 'published' then raise exception 'review lease policy version must be published' using errcode='23514'; end if; end if; return new; end $function$", - "name": "guard_review_lease" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review_policies rows are immutable' using errcode='55000'; end $function$", - "name": "guard_review_policies_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_queue_entry() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review queue entries cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.queue_state <> 'pending' then raise exception 'review queue must begin pending' using errcode='23514'; end if; new.first_queued_at := statement_timestamp(); new.available_since := new.first_queued_at; new.routing_generation := 1; new.lifecycle_generation := 1; new.created_at := new.first_queued_at; end if; if tg_op='UPDATE' then if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.first_queued_at,new.created_at) is distinct from (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.first_queued_at,old.created_at) then raise exception 'review queue identity is immutable' using errcode='55000'; end if; if old.queue_state='closed' and new.queue_state <> 'closed' then raise exception 'closed review queue entries cannot reopen' using errcode='23514'; end if; if new.routing_generation < old.routing_generation or new.lifecycle_generation < old.lifecycle_generation then raise exception 'review queue generations cannot decrease' using errcode='23514'; end if; end if; if new.preferred_reviewer_id is not null and not exists( select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' ) then raise exception 'preferred reviewer must be human' using errcode='23514'; end if; if tg_op='UPDATE' then return new; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review queue task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review queue checker lineage mismatch' using errcode='23514'; end if; if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true then raise exception 'review queue checker is not admissible' using errcode='23514'; end if; return new; end $function$", - "name": "guard_review_queue_entry" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_revision_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'revision_policies rows are immutable' using errcode='55000'; end $function$", - "name": "guard_revision_policies_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_service_identity_migration_evidence() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'service identity migration evidence is immutable' using errcode='55000'; end $function$", - "name": "guard_service_identity_migration_evidence" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_delete() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $function$", - "name": "guard_submission_bundle_admission_delete" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, old.put_operation_receipt_id, old.put_observation_receipt_id, old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, old.assignment_id, old.predecessor_submission_id, old.predecessor_submission_version, old.locked_policy_context_hash, old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, old.archive_byte_count, old.ready_at, old.created_at) is distinct from row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, new.put_operation_receipt_id, new.put_observation_receipt_id, new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, new.assignment_id, new.predecessor_submission_id, new.predecessor_submission_version, new.locked_policy_context_hash, new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, new.archive_byte_count, new.ready_at, new.created_at) then raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; end if; if old.status <> 'ready' or new.status not in ('consumed','stale') then raise exception 'invalid submission bundle admission transition' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_submission_bundle_admission_lineage" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_verified_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ declare matches integer; begin select count(*) into matches from submission_bundle_durable_intents intent join pre_submit_evidence_sets evidence on evidence.id=intent.pre_submit_evidence_set_id join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id join artifact_replicas replica on replica.id=attempt.replica_id join artifact_contents content on content.id=replica.content_id join artifact_verification_jobs job on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id join artifact_verification_receipts verification on verification.verification_job_id=job.id where intent.id=new.durable_intent_id and evidence.id=new.pre_submit_evidence_set_id and attempt.id=new.put_attempt_id and content.id=new.artifact_content_id and replica.id=new.verified_replica_id and verification.id=new.verification_receipt_id and attempt.producer_request_type='submission_bundle' and attempt.producer_type='actor_profile' and attempt.producer_ref=evidence.actor_profile_id and attempt.project_id=evidence.project_id and attempt.task_id=evidence.task_id and attempt.media_type='application/zip' and content.media_type='application/zip' and attempt.status='object_confirmed' and evidence.terminal_status='passed' and evidence.eligible and replica.verification_state='verified' and replica.availability_state='available' and replica.integrity_state='valid' and verification.outcome='verified' and verification.execution_generation=job.execution_generation and verification.observed_sha256=attempt.sha256 and verification.observed_sha256=content.sha256 and verification.observed_sha256=evidence.archive_sha256 and verification.observed_byte_count=attempt.byte_count and verification.observed_byte_count=content.byte_count and verification.observed_byte_count=evidence.archive_byte_count and new.actor_profile_id=evidence.actor_profile_id and new.identity_link_id=evidence.identity_link_id and new.project_id=evidence.project_id and new.task_id=evidence.task_id and new.assignment_id=evidence.assignment_id and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version and new.locked_policy_context_hash=evidence.locked_policy_context_hash and new.semantic_manifest_id=evidence.semantic_manifest_id and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 and new.archive_sha256=evidence.archive_sha256 and new.archive_byte_count=evidence.archive_byte_count and ((new.put_operation_receipt_id is not null and exists ( select 1 from artifact_operation_receipts receipt where receipt.id=new.put_operation_receipt_id and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id and receipt.outcome='stored_pending_verification')) or (new.put_observation_receipt_id is not null and exists ( select 1 from artifact_put_observation_receipts observation where observation.id=new.put_observation_receipt_id and observation.put_attempt_id=attempt.id and observation.outcome='observed_confirmed' and observation.observed_sha256=attempt.sha256 and observation.observed_byte_count=attempt.byte_count))); if matches <> 1 then raise exception 'submission bundle admission verified lineage mismatch' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_submission_bundle_admission_verified_lineage" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id for share; if request_type is distinct from 'submission_bundle' then raise exception 'submission bundle durable intent requires submission_bundle put attempt' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_submission_bundle_durable_intent_put_attempt" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intents_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission_bundle_durable_intents rows are immutable' using errcode='55000'; end; $function$", - "name": "guard_submission_bundle_durable_intents_immutable" - }, - { - "arguments": "value jsonb", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_availability_is_safe(value jsonb) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='object' and (select count(*)=3 from jsonb_object_keys(value)) and value ?& array['availability','reference_ids','unavailable_reason'] and project_role_reference_array_is_safe(value->'reference_ids',false) and ( (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 and value->'unavailable_reason'='null'::jsonb) or (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) ) $function$", - "name": "project_role_availability_is_safe" - }, - { - "arguments": "value text", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_reason_is_safe(value text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE STRICT AS $function$ declare point integer; index integer; begin if octet_length(value) not between 1 and 500 or value <> btrim(value, (E' \\t\\n\\r\\f\\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)||chr(8239)||chr(8287)||chr(12288))) then return false; end if; for index in 1..char_length(value) loop point := ascii(substr(value,index,1)); if point between 0 and 31 or point between 127 and 159 or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then return false; end if; end loop; return true; end $function$", - "name": "project_role_reason_is_safe" - }, - { - "arguments": "value jsonb, uuid_only boolean", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_array_is_safe(value jsonb, uuid_only boolean) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 and not exists ( select 1 from jsonb_array_elements(value) item where jsonb_typeof(item)<>'string' or case when uuid_only then not (item #>> '{}') ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' else not project_role_reference_token_is_safe(item #>> '{}') end ) $function$", - "name": "project_role_reference_array_is_safe" - }, - { - "arguments": "value text", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_token_is_safe(value text) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 $function$", - "name": "project_role_reference_token_is_safe" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_approval_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.approval_action_id is not null and (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, new.approved_by_admin_role_grant_id,new.approval_scope_type, new.approval_scope_project_id,new.approval_action_id, new.approval_decision_event_id) is distinct from (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, old.approved_by_admin_role_grant_id,old.approval_scope_type, old.approval_scope_project_id,old.approval_action_id, old.approval_decision_event_id) then raise exception 'submission-policy approval provenance is immutable' using errcode='23514'; end if; return new; end $function$", - "name": "protect_submission_policy_approval_provenance" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_creation_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.created_by_service_identity, new.creation_scope_type,new.creation_scope_project_id, new.creation_action_id,new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.created_by_service_identity, old.creation_scope_type,old.creation_scope_project_id, old.creation_action_id,old.creation_decision_event_id) then raise exception 'submission-policy creation provenance is immutable' using errcode='23514'; end if; return new; end $function$", - "name": "protect_submission_policy_creation_provenance" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_output_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.creation_scope_type, new.creation_scope_project_id,new.creation_action_id, new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.creation_scope_type, old.creation_scope_project_id,old.creation_action_id, old.creation_decision_event_id) then raise exception 'submission-policy output provenance is immutable' using errcode='23514'; end if; return new; end $function$", - "name": "protect_submission_policy_output_provenance" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_admin_role_grant_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'admin role grants are immutable' using errcode='55000'; end $function$", - "name": "reject_admin_role_grant_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_artifact_fact_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception '% rows are immutable', tg_table_name; end; $function$", - "name": "reject_artifact_fact_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_audit_event_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'audit events are append-only' using errcode = '55000'; end $function$", - "name": "reject_audit_event_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_control_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority control is immutable' using errcode='55000'; end $function$", - "name": "reject_authority_control_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority idempotency records are immutable' using errcode='55000'; end $function$", - "name": "reject_authority_idempotency_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_contribution_policy_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'contribution policy persistence cannot be truncated' using errcode='55000'; end; $function$", - "name": "reject_contribution_policy_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_mutation_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide mutation custody is immutable' using errcode='55000'; end $function$", - "name": "reject_guide_mutation_idempotency_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_source_snapshot_item_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide source snapshot items are immutable' using errcode='23514'; end $function$", - "name": "reject_guide_source_snapshot_item_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_pending_authority_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then raise exception 'pending authority idempotency cannot commit' using errcode='23514'; end if; return null; end $function$", - "name": "reject_pending_authority_idempotency" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_policy_mutation_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'policy mutation replay is immutable' using errcode='55000'; end $function$", - "name": "reject_policy_mutation_replay_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_project_create_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project create reservations are immutable' using errcode='55000'; end $function$", - "name": "reject_project_create_idempotency_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_project_guide_compilation_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compilation custody is append-only'; end $function$", - "name": "reject_project_guide_compilation_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_project_role_history_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $function$", - "name": "reject_project_role_history_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_review_lease_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review leases cannot be truncated' using errcode='55000'; end $function$", - "name": "reject_review_lease_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_review_queue_foundation_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review queue foundation cannot be truncated' using errcode='55000'; end $function$", - "name": "reject_review_queue_foundation_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'submission-policy replay rows cannot be deleted'; end if; if old.status = 'reserved' and new.status = 'pending' and old.service_identity = 'workstream.project.setup' and old.action_id = 'project.submission_artifact_policy.derive' and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.operation_id,new.project_id, new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, new.committed_pre_submit_policy_id,new.committed_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.operation_id,old.project_id, old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, old.committed_pre_submit_policy_id,old.committed_at) then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.request_digest, new.resource_context_digest,new.resource_context_json::text,new.operation_id, new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, new.setup_run_id,new.setup_generation,new.setup_task_id, new.correlation_id,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.request_digest, old.resource_context_digest,old.resource_context_json::text,old.operation_id, old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, old.setup_run_id,old.setup_generation,old.setup_task_id, old.correlation_id,old.created_at) then raise exception 'invalid submission-policy replay mutation'; end if; return new; end $function$", - "name": "reject_submission_policy_replay_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission-policy replay rows cannot be truncated'; end $function$", - "name": "reject_submission_policy_replay_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'guide sufficiency replay rows are append-only'; end if; if old.status = 'committed' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, new.setup_run_id,new.setup_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, old.setup_run_id,old.setup_generation,old.created_at) then raise exception 'invalid guide sufficiency replay mutation'; end if; return new; end $function$", - "name": "reject_sufficiency_replay_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide sufficiency replay rows are append-only'; end $function$", - "name": "reject_sufficiency_replay_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.require_human_actor_profile_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare referenced_id text; referenced_kind text; begin if tg_nargs <> 1 or tg_argv[0] is null or not (to_jsonb(new) ? tg_argv[0]) then raise exception 'human actor reference trigger is misconfigured' using errcode='55000'; end if; referenced_id := to_jsonb(new) ->> tg_argv[0]; if referenced_id is null then return new; end if; select profile.actor_kind into referenced_kind from public.actor_profiles profile where profile.id=referenced_id; if not found then return new; end if; if referenced_kind <> 'human' then raise exception 'actor reference must identify a human profile' using errcode='23514', constraint='require_human_actor_profile_reference'; end if; return new; end $function$", - "name": "require_human_actor_profile_reference" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.set_authority_audit_database_time() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.event_domain = 'authority' then if new.invalidation_cause_event_id is not null and not exists ( select 1 from audit_events where id = new.invalidation_cause_event_id and event_domain = 'authority' ) then raise exception 'invalid authority invalidation cause' using errcode = '23503'; end if; new.occurred_at = statement_timestamp(); else new.occurred_at = null; end if; return new; end $function$", - "name": "set_authority_audit_database_time" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_binding_history() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor artifact_bindings%rowtype; begin if new.scope_version = 1 then return new; end if; select * into predecessor from artifact_bindings where id = new.supersedes_binding_id; if not found or predecessor.project_id != new.project_id or predecessor.resource_type != new.resource_type or predecessor.resource_id != new.resource_id or predecessor.logical_role != new.logical_role or predecessor.scope_version + 1 != new.scope_version then raise exception 'artifact binding predecessor is invalid'; end if; return new; end; $function$", - "name": "validate_artifact_binding_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_recovery_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare source_row artifact_verification_jobs%rowtype; retry_row artifact_verification_jobs%rowtype; expected_parent text; begin if tg_op = 'DELETE' then raise exception 'artifact recovery attempts are append-only' using errcode='55000'; end if; if tg_op = 'UPDATE' and ( to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] is distinct from to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] ) then raise exception 'artifact recovery identity is immutable' using errcode='55000'; end if; select * into source_row from artifact_verification_jobs where id=new.source_verification_job_id; select * into retry_row from artifact_verification_jobs where id=new.retry_verification_job_id; if source_row.id is null or retry_row.id is null or source_row.status <> 'provider_unavailable' or source_row.terminal_result_code <> 'provider_unavailable' or source_row.terminal_at is null or source_row.next_run_at is not null or source_row.executor_id is not null or source_row.attempt_count < source_row.maximum_attempts or retry_row.parent_verification_job_id <> source_row.id or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id or retry_row.replica_id <> source_row.replica_id then raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; end if; if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) or (tg_op = 'UPDATE' and ( retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null )) then raise exception 'invalid artifact recovery retry state' using errcode='23514'; end if; select id into expected_parent from artifact_recovery_attempts where retry_verification_job_id=source_row.id; if new.parent_recovery_attempt_id is distinct from expected_parent then raise exception 'invalid artifact recovery parent chain' using errcode='23514'; end if; if not exists ( select 1 from audit_events where id=new.initiation_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryInitiated' ) then raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; end if; if new.terminal_audit_event_id is not null and not exists ( select 1 from audit_events where id=new.terminal_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryCompleted' ) then raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; end if; return new; end $function$", - "name": "validate_artifact_recovery_attempt" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_verification_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if ( old.parent_verification_job_id is not null or exists( select 1 from artifact_recovery_attempts where source_verification_job_id = old.id or retry_verification_job_id = old.id ) ) and ( old.originating_put_attempt_id is distinct from new.originating_put_attempt_id or old.replica_id is distinct from new.replica_id or old.parent_verification_job_id is distinct from new.parent_verification_job_id ) then raise exception 'artifact verification lineage is immutable' using errcode='55000'; end if; return new; end $function$", - "name": "validate_artifact_verification_lineage" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_bootstrap_authority_state() RETURNS trigger LANGUAGE plpgsql AS $function$ declare control authority_control%rowtype; bootstrap_count bigint; referenced_bootstrap boolean; begin select * into control from authority_control where id=1; if not found then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; select count(*) into bootstrap_count from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap'; referenced_bootstrap := exists( select 1 from admin_role_grants where id=control.bootstrap_grant_id and granted_by_system_principal='workstream:system:bootstrap' ); if (not control.bootstrap_completed and (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) or (control.bootstrap_completed and (control.bootstrap_grant_id is null or control.version <> 1 or bootstrap_count <> 1 or not referenced_bootstrap)) then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; return null; end $function$", - "name": "validate_bootstrap_authority_state" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_canonical_actor_link() RETURNS trigger LANGUAGE plpgsql AS $function$ declare profile_row actor_profiles%rowtype; link_count integer; begin if tg_table_name='actor_profiles' then select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; else select * into profile_row from actor_profiles where id=new.actor_profile_id; if not found or profile_row.actor_kind <> new.subject_kind then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; end if; return new; end $function$", - "name": "validate_canonical_actor_link" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_contribution_policy_graph() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists ( select 1 from contribution_policy_versions v where v.status in ('published','retired') and ( (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='accepted_submission') <> 1 or (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='completed_review') <> 1 or exists ( select 1 from contribution_rules r where r.contribution_policy_version_id=v.id and ( (r.compensation_mode='unpaid' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) <> 0) or (r.compensation_mode='compensated' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) not between 1 and 2) ) ) ) ) then raise exception 'published contribution policy graph is incomplete' using errcode='23514'; end if; if exists ( select 1 from contribution_policies p left join contribution_policy_versions v on v.id=p.current_published_version_id and v.contribution_policy_id=p.id and v.project_id=p.project_id where p.status='active' and (v.id is null or v.status <> 'published') ) then raise exception 'active contribution policy selector is invalid' using errcode='23514'; end if; return null; end; $function$", - "name": "validate_contribution_policy_graph" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation guide_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_resource text; product_generation integer; begin if tg_table_name='guide_mutation_idempotency_records' then select * into reservation from guide_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id in ('project.guide.create','project.guide.update') then select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, last_mutated_by_admin_role_grant_id,last_mutation_action_id, last_mutation_scope_type,last_mutation_scope_project_id, last_authorization_decision_event_id,project_id,id,mutation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from project_guides where id=reservation.resource_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,project_id,id,creation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from guide_source_snapshots where id=reservation.resource_id; end if; elsif tg_table_name='project_guides' then if tg_op='UPDATE' and (new.content_markdown is distinct from old.content_markdown or new.change_summary is distinct from old.change_summary) and (new.mutation_generation is not distinct from old.mutation_generation or new.last_authorization_decision_event_id is not distinct from old.last_authorization_decision_event_id) then raise exception 'guide content mutation requires fresh custody' using errcode='23514'; end if; if new.mutation_generation is null then if tg_op='INSERT' then raise exception 'new guides require mutation authority' using errcode='23514'; end if; return null; end if; actor_id:=new.last_mutated_by_actor_profile_id; link_id:=new.last_mutated_via_identity_link_id; grant_id:=new.last_mutated_by_admin_role_grant_id; action_value:=new.last_mutation_action_id; scope_type:=new.last_mutation_scope_type; scope_project:=new.last_mutation_scope_project_id; decision_id:=new.last_authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.mutation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id=new.last_mutation_action_id and operation_generation=new.mutation_generation and status='committed'; elsif tg_table_name='guide_source_snapshots' then if tg_op='UPDATE' and (new.project_id,new.guide_id,new.guide_version, new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) is distinct from (old.project_id,old.guide_id,old.guide_version, old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then raise exception 'guide source snapshot content is immutable' using errcode='23514'; end if; if new.creation_generation is null then raise exception 'new source snapshots require creation authority' using errcode='23514'; end if; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.creation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id='project.guide_source_snapshot.create' and operation_generation=new.creation_generation and status='committed'; else if new.authorization_action_id is null then return null; end if; actor_id:=new.authorized_by_actor_profile_id; link_id:=new.authorized_via_identity_link_id; grant_id:=new.authorized_by_admin_role_grant_id; action_value:=new.authorization_action_id; scope_type:=new.authorization_scope_type; scope_project:=new.authorization_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.source_snapshot_id; select * into reservation from guide_mutation_idempotency_records where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' and status='committed'; product_generation:=reservation.operation_generation; end if; if reservation.id is null or product_resource is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.resource_id is distinct from product_resource or reservation.operation_generation is distinct from product_generation or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'guide mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.guide.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'guide mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_guide_mutation_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_source_snapshot_items() RETURNS trigger LANGUAGE plpgsql AS $function$ declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; begin select snapshot.manifest_json::jsonb->'items' into expected from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; if expected is null then raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; end if; select coalesce(jsonb_agg(jsonb_build_object( 'item_id',id,'item_order',item_order,'source_kind',source_kind, 'source_label',source_label,'ingestion_adapter',ingestion_adapter, 'media_type',media_type) order by item_order),'[]'::jsonb) into actual from guide_source_snapshot_items where source_snapshot_id=new.source_snapshot_id; if actual is distinct from expected then raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; end if; select r.* into reservation from guide_mutation_idempotency_records r join guide_source_snapshots s on s.id=r.resource_id where s.id=new.source_snapshot_id and r.action_id='project.guide_source_snapshot.create' and r.operation_generation=s.creation_generation and r.status='committed'; if reservation.id is null then raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_guide_source_snapshot_items" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_linked_authority_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare record_row authority_idempotency_records%rowtype; cause_row audit_events%rowtype; expected_permission text; expected_resource text; expected_invalidation_resource text; expected_invalidation_id text; valid_success boolean; begin if new.event_domain <> 'authority' then return new; end if; valid_success := new.event_type in ( 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', 'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued','ProjectRoleGrantRevoked', 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then if new.idempotency_reference is not null then raise exception 'invalid authority idempotency event' using errcode='23514'; end if; return new; end if; if new.idempotency_reference is null then raise exception 'authority event requires idempotency reference' using errcode='23514'; end if; select * into record_row from authority_idempotency_records where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; expected_permission := case record_row.operation when 'service_actor.create' then 'actor.service.provision' when 'admin_role_grant.issue' then 'admin_role.grant' when 'admin_role_grant.revoke' then 'admin_role.revoke' when 'project_role_grant.issue' then 'project.role_grant.manage' when 'project_role_grant.revoke' then 'project.role_grant.manage' when 'actor_profile.suspend' then 'actor.profile.suspend' when 'actor_profile.reactivate' then 'actor.profile.reactivate' when 'actor_profile.deactivate' then 'actor.profile.deactivate' when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; expected_resource := case when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' when record_row.operation like 'project_role_grant.%' then 'project_role_grant' else 'actor_identity_link' end; if new.permission_id <> expected_permission or new.resource_id is null then raise exception 'authority event does not match operation' using errcode='23514'; end if; if new.event_type='ProjectRoleQualificationSnapshotCaptured' then if record_row.operation <> 'project_role_grant.issue' or new.resource_type <> 'qualification_snapshot' or new.entity_type <> 'qualification_snapshot' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'qualification_snapshot' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or exists(select 1 from audit_events where idempotency_reference=record_row.id) then raise exception 'invalid project role qualification evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='ProjectRoleGrantIssued' then select * into cause_row from audit_events where idempotency_reference=record_row.id and event_type='ProjectRoleQualificationSnapshotCaptured'; if not found or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.matched_grant_id is distinct from new.matched_grant_id or new.resource_type <> 'project_role_grant' or new.entity_type <> 'project_role_grant' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null then raise exception 'invalid project role issue evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.revoke' and new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from 'actor_profile' or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.resource_type <> 'project_role_grant' or cause_row.target_ref_kind <> 'project_role_grant' or cause_row.target_ref_id is distinct from cause_row.resource_id or new.resource_type <> 'project_role_grant' or new.resource_id is distinct from cause_row.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from cause_row.resource_id or new.invalidation_target_kind <> 'project_role_grant' or new.invalidation_target_ref is distinct from cause_row.resource_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or new.before_facts::jsonb->>'effective' <> 'true' or new.after_facts::jsonb->>'effective' <> 'false' or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' or new.before_facts::jsonb->>'scope_type' <> 'project' or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then raise exception 'invalid project role revoke invalidation' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='AuthorityInvalidationRequested' then raise exception 'project role issue forbids invalidation' using errcode='23514'; elsif new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; expected_invalidation_resource := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then 'actor_profile' else expected_resource end; expected_invalidation_id := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then cause_row.target_actor_ref else cause_row.resource_id end; if not found or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.resource_type is distinct from expected_resource or new.resource_type is distinct from expected_invalidation_resource or new.resource_id is distinct from expected_invalidation_id or new.invalidation_target_kind is distinct from expected_invalidation_resource or new.invalidation_target_ref is distinct from expected_invalidation_id or cause_row.target_ref_kind is distinct from cause_row.resource_type or cause_row.target_ref_id is distinct from cause_row.resource_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": false}'::jsonb or new.after_facts::jsonb <> '{\"effective\": true}'::jsonb)) or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": true}'::jsonb or new.after_facts::jsonb <> '{\"effective\": false}'::jsonb)) or not ( (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then raise exception 'invalid linked authority cause' using errcode='23514'; end if; else if new.resource_type <> expected_resource or new.entity_type <> expected_resource or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or not ( (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then raise exception 'authority success event does not match operation' using errcode='23514'; end if; end if; return new; end $function$", - "name": "validate_linked_authority_event" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_policy_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_guide text; product_id text; product_generation integer; product_hash text; predecessor_id text; predecessor_hash text; selector_id text; selector_generation integer; selector_hash text; predecessor_valid boolean; begin if tg_table_name='policy_mutation_idempotency_records' then select * into reservation from policy_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id='project.review_policy.update' then select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_review_policy_id, g.selected_review_policy_generation,g.selected_review_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from review_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_revision_policy_id, g.selected_revision_policy_generation,g.selected_revision_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from revision_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; end if; else actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_id:=new.id; product_generation:=new.policy_generation; product_hash:=new.policy_hash; predecessor_id:=new.supersedes_policy_id; predecessor_hash:=new.predecessor_policy_hash; if tg_table_name='review_policies' then select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, g.selected_review_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; else select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, g.selected_revision_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; end if; select r.* into reservation from policy_mutation_idempotency_records r where r.policy_id=new.id and r.action_id=new.creation_action_id and r.policy_generation=new.policy_generation and r.status='committed'; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.guide_id is distinct from product_guide or reservation.policy_id is distinct from product_id or reservation.policy_generation is distinct from product_generation or reservation.policy_hash is distinct from product_hash or selector_id is distinct from product_id or selector_generation is distinct from product_generation or selector_hash is distinct from product_hash or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'policy mutation custody mismatch' using errcode='23514'; end if; if product_generation=1 then predecessor_valid:=predecessor_id is null and predecessor_hash is null; elsif reservation.action_id='project.review_policy.update' then select exists(select 1 from review_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; else select exists(select 1 from revision_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; end if; if predecessor_valid is not true then raise exception 'policy mutation lineage mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.review_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'policy mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_policy_mutation_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_project_create_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; evidence audit_events%rowtype; begin if tg_table_name = 'projects' then if tg_op = 'INSERT' and new.creation_action_id is null then raise exception 'new projects require creation authority' using errcode='23514'; end if; if new.creation_action_id is null then return null; end if; project_row := new; select * into reservation from project_create_idempotency_records where project_id=project_row.id and status='committed'; else select * into reservation from project_create_idempotency_records where id=new.id; if reservation.status <> 'committed' then raise exception 'pending project create reservation cannot commit' using errcode='23514'; end if; select * into project_row from projects where id=reservation.project_id; end if; if project_row.id is null or reservation.id is null or project_row.created_by_actor_profile_id is distinct from reservation.actor_profile_id or project_row.created_via_identity_link_id is distinct from reservation.identity_link_id or project_row.creation_action_id is distinct from reservation.action_id then raise exception 'project create custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=project_row.authorization_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from project_row.created_by_actor_profile_id or evidence.matched_grant_id is distinct from project_row.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.create' or evidence.action_id is distinct from 'project.create' or evidence.resource_type is distinct from 'project_create_operation' or evidence.resource_id is distinct from reservation.operation_id::text or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from project_row.id or evidence.after_facts->>'allowed' is distinct from 'true' or coalesce( evidence.after_facts->>'resource_context_digest' !~ '^sha256:[0-9a-f]{64}$', true ) then raise exception 'project create evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_project_create_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_review_active_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare queue_row review_queue_entries%rowtype; active_count integer; begin if tg_table_name='review_queue_entries' then queue_row := new; else select * into queue_row from review_queue_entries where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); end if; if not found and tg_table_name='review_leases' then raise exception 'review lease queue is missing' using errcode='23514'; end if; select count(*) into active_count from review_leases where review_queue_entry_id=queue_row.id and status='active'; if queue_row.queue_state='leased' then if queue_row.active_lease_id is null or active_count <> 1 or not exists( select 1 from review_leases where id=queue_row.active_lease_id and review_queue_entry_id=queue_row.id and status='active' ) then raise exception 'leased queue must identify its active lease' using errcode='23514'; end if; elsif queue_row.active_lease_id is not null or active_count <> 0 then raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; end if; return null; end $function$", - "name": "validate_review_active_lease" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_authority_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; action_value varchar; decision_id varchar; product_project varchar; product_id varchar; approval_outputs_valid boolean; begin if tg_table_name='submission_policy_mutation_idempotency_records' then if new.status='pending' then return null; end if; reservation:=new; select project_id,id, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_actor_profile_id else created_by_actor_profile_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_via_identity_link_id else created_via_identity_link_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_admin_role_grant_id else created_by_admin_role_grant_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then null else created_by_service_identity end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_action_id else creation_action_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_decision_event_id else creation_decision_event_id end into product_project,product_id,actor_id,link_id,grant_id,service_id, action_value,decision_id from submission_artifact_policies where id=reservation.committed_policy_id; if reservation.action_id='project.submission_artifact_policy.approve' then select exists( select 1 from submission_artifact_policies s join effective_project_submission_artifact_policies e on e.id=reservation.committed_effective_policy_id and e.submission_artifact_policy_id=s.id and e.submission_artifact_policy_hash=s.policy_hash join pre_submit_checker_policies p on p.id=reservation.committed_pre_submit_policy_id and p.project_id=e.project_id where s.id=reservation.committed_policy_id and s.id=reservation.policy_id and s.guide_id=reservation.guide_id and s.source_snapshot_id=reservation.source_snapshot_id and s.guide_version=reservation.resource_context_json->>'guide_version' and s.policy_hash=reservation.resource_context_json->>'policy_digest' and e.effective_policy_hash= reservation.resource_context_json->>'effective_output_digest' and p.compiled_bundle_hash= reservation.resource_context_json->>'compiled_pre_submit_output_digest' and e.project_id=reservation.project_id and e.guide_id=s.guide_id and p.guide_id=s.guide_id and e.guide_version=s.guide_version and p.guide_version=s.guide_version and e.source_snapshot_id=s.source_snapshot_id and p.source_snapshot_id=s.source_snapshot_id and e.source_snapshot_hash=s.source_snapshot_hash and p.source_snapshot_hash=s.source_snapshot_hash and e.submission_artifact_policy_id=reservation.committed_policy_id and p.effective_policy_id=e.id and p.effective_policy_hash=e.effective_policy_hash and e.created_by_actor_profile_id=reservation.actor_profile_id and p.created_by_actor_profile_id=reservation.actor_profile_id and e.created_via_identity_link_id=reservation.identity_link_id and p.created_via_identity_link_id=reservation.identity_link_id and e.created_by_admin_role_grant_id=grant_id and p.created_by_admin_role_grant_id=grant_id and e.creation_scope_project_id=reservation.project_id and p.creation_scope_project_id=reservation.project_id and e.creation_action_id=reservation.action_id and p.creation_action_id=reservation.action_id and e.creation_decision_event_id=decision_id and p.creation_decision_event_id=decision_id ) into approval_outputs_valid; if approval_outputs_valid is not true then raise exception 'submission-policy approval output custody mismatch' using errcode='23514'; end if; end if; elsif tg_table_name='submission_artifact_policies' then if new.creation_action_id is null and new.approval_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null or new.approved_by_actor_profile_id is not null or new.approved_via_identity_link_id is not null or new.approved_by_admin_role_grant_id is not null or new.approval_scope_type is not null or new.approval_scope_project_id is not null or new.approval_decision_event_id is not null then raise exception 'partial submission-policy provenance' using errcode='23514'; end if; return null; end if; if new.approval_action_id is not null then select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.approval_action_id and status='committed'; actor_id:=new.approved_by_actor_profile_id; link_id:=new.approved_via_identity_link_id; grant_id:=new.approved_by_admin_role_grant_id; service_id:=null; action_value:=new.approval_action_id; decision_id:=new.approval_decision_event_id; else select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=new.created_by_service_identity; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; end if; product_project:=new.project_id; product_id:=new.id; elsif tg_table_name='effective_project_submission_artifact_policies' then if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial effective-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_effective_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; else if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial pre-submit-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_pre_submit_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.committed_policy_id is distinct from product_id or reservation.service_identity is distinct from service_id then raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from product_id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy authorization evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_submission_policy_authority_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_creation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; begin if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial submission-policy creation provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; if reservation.id is null or reservation.actor_profile_id is distinct from new.created_by_actor_profile_id or reservation.identity_link_id is distinct from new.created_via_identity_link_id or reservation.service_identity is distinct from new.created_by_service_identity or reservation.project_id is distinct from new.project_id or reservation.policy_id is distinct from new.id or reservation.guide_id is distinct from new.guide_id or reservation.source_snapshot_id is distinct from new.source_snapshot_id or reservation.resource_context_json->>'guide_version' is distinct from new.guide_version then raise exception 'submission-policy creation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=new.creation_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from new.created_by_actor_profile_id or evidence.matched_grant_id is distinct from new.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from new.creation_action_id or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from new.id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy creation evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_submission_policy_creation_custody" - } - ], - "sequences": [ - { - "cache_size": 1, - "cycle": false, - "data_type": "integer", - "increment_by": 1, - "is_called": true, - "last_value": 1, - "max_value": 2147483647, - "min_value": 1, - "name": "actor_profile_migration_state_id_seq", - "start_value": 1 - }, - { - "cache_size": 1, - "cycle": false, - "data_type": "smallint", - "increment_by": 1, - "is_called": true, - "last_value": 1, - "max_value": 32767, - "min_value": 1, - "name": "authority_control_id_seq", - "start_value": 1 - } - ], - "tables": [ - { - "force_row_security": false, - "kind": "r", - "name": "actor_identity_links", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "actor_profile_migration_state", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "actor_profiles", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "admin_role_grants", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "api_rate_control_counters", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_admission_charges", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_admission_scopes", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_bindings", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_contents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_operation_receipts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_put_attempt_charges", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_put_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_put_observation_receipts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_recovery_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_replicas", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_storage_namespaces", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_verification_jobs", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_verification_receipts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "audit_events", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "authority_control", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "authority_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "checker_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "checker_results", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "checker_runs", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_award_definitions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_policy_versions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_rules", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "effective_project_submission_artifact_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "evidence_items", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_artifact_bindings", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_artifact_incidents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_artifact_ingests", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extracted_contents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extraction_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extraction_retry_budgets", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extraction_usages", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_format_classifications", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_snapshot_items", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_snapshots", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_sufficiency_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_sufficiency_report_source_usages", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_sufficiency_reports", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "iso_4217_currency_codes", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "legacy_actor_identities", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "legacy_workflow_eligibility", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "outbox_events", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "payment_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "policy_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "pre_submit_checker_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "pre_submit_evidence_results", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "pre_submit_evidence_sets", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_compensation_adapter_bindings", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_compensation_units", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_create_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_guide_compilation_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_guide_compilations", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_guides", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_role_grants", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_role_qualification_snapshots", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_setup_runs", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "projects", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_admission_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_leases", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_queue_entries", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "revision_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_artifact_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_bundle_admissions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_bundle_durable_intents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_policy_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submissions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "task_assignments", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "workstream_tasks", - "persistence": "p", - "row_security": false - } - ], - "triggers": [ - { - "definition": "CREATE TRIGGER actor_identity_link_history_guard BEFORE DELETE OR UPDATE ON actor_identity_links FOR EACH ROW EXECUTE FUNCTION guard_actor_identity_link_history()", - "enabled": "O", - "name": "actor_identity_link_history_guard", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER actor_identity_link_profile_guard AFTER INSERT OR UPDATE ON actor_identity_links DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", - "enabled": "O", - "name": "actor_identity_link_profile_guard", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE TRIGGER service_identity_migration_evidence_row_guard BEFORE DELETE OR UPDATE ON actor_profile_migration_state FOR EACH ROW EXECUTE FUNCTION guard_service_identity_migration_evidence()", - "enabled": "O", - "name": "service_identity_migration_evidence_row_guard", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CREATE TRIGGER service_identity_migration_evidence_truncate_guard BEFORE TRUNCATE ON actor_profile_migration_state FOR EACH STATEMENT EXECUTE FUNCTION guard_service_identity_migration_evidence()", - "enabled": "O", - "name": "service_identity_migration_evidence_truncate_guard", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CREATE TRIGGER actor_profile_history_guard BEFORE DELETE OR UPDATE ON actor_profiles FOR EACH ROW EXECUTE FUNCTION guard_actor_profile_history()", - "enabled": "O", - "name": "actor_profile_history_guard", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER actor_profile_link_guard AFTER INSERT OR UPDATE ON actor_profiles DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", - "enabled": "O", - "name": "actor_profile_link_guard", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER admin_role_grants_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON admin_role_grants DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", - "enabled": "O", - "name": "admin_role_grants_bootstrap_invariant", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE TRIGGER admin_role_grants_guard BEFORE INSERT OR DELETE OR UPDATE ON admin_role_grants FOR EACH ROW EXECUTE FUNCTION guard_admin_role_grant()", - "enabled": "O", - "name": "admin_role_grants_guard", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE TRIGGER admin_role_grants_reject_truncate BEFORE TRUNCATE ON admin_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_admin_role_grant_truncate()", - "enabled": "O", - "name": "admin_role_grants_reject_truncate", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER trg_artifact_binding_history AFTER INSERT ON artifact_bindings DEFERRABLE INITIALLY IMMEDIATE FOR EACH ROW EXECUTE FUNCTION validate_artifact_binding_history()", - "enabled": "O", - "name": "trg_artifact_binding_history", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE TRIGGER trg_artifact_bindings_immutable BEFORE DELETE OR UPDATE ON artifact_bindings FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_bindings_immutable", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE TRIGGER trg_artifact_contents_immutable BEFORE DELETE OR UPDATE ON artifact_contents FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_contents_immutable", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE TRIGGER artifact_receipt_producer_reference BEFORE INSERT OR UPDATE OF put_attempt_id, guide_source_item_id, checker_run_id, logical_role ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION guard_artifact_receipt_producer_reference()", - "enabled": "O", - "name": "artifact_receipt_producer_reference", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE TRIGGER trg_artifact_operation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_operation_receipts_immutable", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE TRIGGER trg_artifact_put_observation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_put_observation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_put_observation_receipts_immutable", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE TRIGGER artifact_recovery_attempt_custody BEFORE INSERT OR DELETE OR UPDATE ON artifact_recovery_attempts FOR EACH ROW EXECUTE FUNCTION validate_artifact_recovery_attempt()", - "enabled": "O", - "name": "artifact_recovery_attempt_custody", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE TRIGGER trg_artifact_storage_namespaces_immutable BEFORE DELETE OR UPDATE ON artifact_storage_namespaces FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_storage_namespaces_immutable", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE TRIGGER artifact_verification_lineage_custody BEFORE UPDATE ON artifact_verification_jobs FOR EACH ROW EXECUTE FUNCTION validate_artifact_verification_lineage()", - "enabled": "O", - "name": "artifact_verification_lineage_custody", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE TRIGGER trg_artifact_verification_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_verification_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_verification_receipts_immutable", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE TRIGGER audit_events_reject_truncate BEFORE TRUNCATE ON audit_events FOR EACH STATEMENT EXECUTE FUNCTION reject_audit_event_mutation()", - "enabled": "O", - "name": "audit_events_reject_truncate", - "table_name": "audit_events" - }, - { - "definition": "CREATE TRIGGER audit_events_reject_update_delete BEFORE DELETE OR UPDATE ON audit_events FOR EACH ROW EXECUTE FUNCTION reject_audit_event_mutation()", - "enabled": "O", - "name": "audit_events_reject_update_delete", - "table_name": "audit_events" - }, - { - "definition": "CREATE TRIGGER audit_events_set_authority_time BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION set_authority_audit_database_time()", - "enabled": "O", - "name": "audit_events_set_authority_time", - "table_name": "audit_events" - }, - { - "definition": "CREATE TRIGGER audit_events_validate_idempotency BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION validate_linked_authority_event()", - "enabled": "O", - "name": "audit_events_validate_idempotency", - "table_name": "audit_events" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER authority_control_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON authority_control DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", - "enabled": "O", - "name": "authority_control_bootstrap_invariant", - "table_name": "authority_control" - }, - { - "definition": "CREATE TRIGGER authority_control_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_control FOR EACH ROW EXECUTE FUNCTION guard_authority_control()", - "enabled": "O", - "name": "authority_control_guard", - "table_name": "authority_control" - }, - { - "definition": "CREATE TRIGGER authority_control_reject_truncate BEFORE TRUNCATE ON authority_control FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_control_truncate()", - "enabled": "O", - "name": "authority_control_reject_truncate", - "table_name": "authority_control" - }, - { - "definition": "CREATE TRIGGER authority_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_authority_idempotency_record()", - "enabled": "O", - "name": "authority_idempotency_guard", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER authority_idempotency_pending_guard AFTER INSERT OR UPDATE ON authority_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION reject_pending_authority_idempotency()", - "enabled": "O", - "name": "authority_idempotency_pending_guard", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE TRIGGER authority_idempotency_reject_truncate BEFORE TRUNCATE ON authority_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_idempotency_truncate()", - "enabled": "O", - "name": "authority_idempotency_reject_truncate", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE TRIGGER contribution_award_definitions_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_award_definitions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", - "enabled": "O", - "name": "contribution_award_definitions_content_guard", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_award_definitions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_award_definitions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_award_definitions_graph_guard", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE TRIGGER contribution_award_definitions_reject_truncate BEFORE TRUNCATE ON contribution_award_definitions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_award_definitions_reject_truncate", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_policies_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_policies_graph_guard", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE TRIGGER contribution_policies_reject_truncate BEFORE TRUNCATE ON contribution_policies FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_policies_reject_truncate", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE TRIGGER contribution_policy_versions_content_guard BEFORE DELETE OR UPDATE ON contribution_policy_versions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_version_content()", - "enabled": "O", - "name": "contribution_policy_versions_content_guard", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_policy_versions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policy_versions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_policy_versions_graph_guard", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE TRIGGER contribution_policy_versions_reject_truncate BEFORE TRUNCATE ON contribution_policy_versions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_policy_versions_reject_truncate", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE TRIGGER contribution_rules_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_rules FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", - "enabled": "O", - "name": "contribution_rules_content_guard", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_rules_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_rules DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_rules_graph_guard", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE TRIGGER contribution_rules_reject_truncate BEFORE TRUNCATE ON contribution_rules FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_rules_reject_truncate", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER effective_submission_policy_custody AFTER INSERT OR UPDATE ON effective_project_submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "effective_submission_policy_custody", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER effective_submission_policy_provenance_immutable BEFORE UPDATE ON effective_project_submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", - "enabled": "O", - "name": "effective_submission_policy_provenance_immutable", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER guide_mutation_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON guide_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_guide_mutation_idempotency()", - "enabled": "O", - "name": "guide_mutation_idempotency_guard", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER guide_mutation_idempotency_reject_truncate BEFORE TRUNCATE ON guide_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_mutation_idempotency_truncate()", - "enabled": "O", - "name": "guide_mutation_idempotency_reject_truncate", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_reservation_custody AFTER INSERT OR UPDATE ON guide_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "guide_mutation_reservation_custody", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER guide_source_snapshot_items_custody AFTER INSERT ON guide_source_snapshot_items DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_source_snapshot_items()", - "enabled": "O", - "name": "guide_source_snapshot_items_custody", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE TRIGGER guide_source_snapshot_items_immutable BEFORE DELETE OR UPDATE OR TRUNCATE ON guide_source_snapshot_items FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_source_snapshot_item_mutation()", - "enabled": "O", - "name": "guide_source_snapshot_items_immutable", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER source_snapshot_product_custody AFTER INSERT OR UPDATE ON guide_source_snapshots DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "source_snapshot_product_custody", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE TRIGGER trg_sufficiency_replay_immutable BEFORE DELETE OR UPDATE ON guide_sufficiency_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_sufficiency_replay_mutation()", - "enabled": "O", - "name": "trg_sufficiency_replay_immutable", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_sufficiency_replay_no_truncate BEFORE TRUNCATE ON guide_sufficiency_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_sufficiency_replay_truncate()", - "enabled": "O", - "name": "trg_sufficiency_replay_no_truncate", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER iso_4217_currency_codes_immutable BEFORE INSERT OR DELETE OR UPDATE ON iso_4217_currency_codes FOR EACH ROW EXECUTE FUNCTION guard_iso_4217_currency_codes()", - "enabled": "O", - "name": "iso_4217_currency_codes_immutable", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "CREATE TRIGGER iso_4217_currency_codes_reject_truncate BEFORE TRUNCATE ON iso_4217_currency_codes FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "iso_4217_currency_codes_reject_truncate", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "CREATE TRIGGER outbox_events_custody BEFORE INSERT OR DELETE OR UPDATE ON outbox_events FOR EACH ROW EXECUTE FUNCTION guard_outbox_event()", - "enabled": "O", - "name": "outbox_events_custody", - "table_name": "outbox_events" - }, - { - "definition": "CREATE TRIGGER outbox_events_reject_truncate BEFORE TRUNCATE ON outbox_events FOR EACH STATEMENT EXECUTE FUNCTION guard_outbox_event()", - "enabled": "O", - "name": "outbox_events_reject_truncate", - "table_name": "outbox_events" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER policy_mutation_replay_custody AFTER INSERT OR UPDATE ON policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", - "enabled": "O", - "name": "policy_mutation_replay_custody", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER policy_mutation_replay_immutable BEFORE INSERT OR DELETE OR UPDATE ON policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_policy_mutation_replay()", - "enabled": "O", - "name": "policy_mutation_replay_immutable", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER policy_mutation_replay_reject_truncate BEFORE TRUNCATE ON policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_policy_mutation_replay_truncate()", - "enabled": "O", - "name": "policy_mutation_replay_reject_truncate", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER pre_submit_policy_custody AFTER INSERT OR UPDATE ON pre_submit_checker_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "pre_submit_policy_custody", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE TRIGGER pre_submit_policy_provenance_immutable BEFORE UPDATE ON pre_submit_checker_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", - "enabled": "O", - "name": "pre_submit_policy_provenance_immutable", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_results_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_results_immutable", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_results_membership BEFORE INSERT ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_result_membership()", - "enabled": "O", - "name": "pre_submit_evidence_results_membership", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_results_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_results FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_results_no_truncate", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_sets_creation BEFORE INSERT ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_set_creation()", - "enabled": "O", - "name": "pre_submit_evidence_sets_creation", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_sets_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_sets_immutable", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_sets_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_sets FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_sets_no_truncate", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE TRIGGER project_compensation_binding_update_guard BEFORE UPDATE ON project_compensation_adapter_bindings FOR EACH ROW EXECUTE FUNCTION enforce_compensation_binding_lifecycle()", - "enabled": "O", - "name": "project_compensation_binding_update_guard", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE TRIGGER project_compensation_units_lifecycle_guard BEFORE INSERT OR DELETE OR UPDATE ON project_compensation_units FOR EACH ROW EXECUTE FUNCTION guard_project_compensation_units()", - "enabled": "O", - "name": "project_compensation_units_lifecycle_guard", - "table_name": "project_compensation_units" - }, - { - "definition": "CREATE TRIGGER project_compensation_units_reject_truncate BEFORE TRUNCATE ON project_compensation_units FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "project_compensation_units_reject_truncate", - "table_name": "project_compensation_units" - }, - { - "definition": "CREATE TRIGGER project_create_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON project_create_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_project_create_idempotency()", - "enabled": "O", - "name": "project_create_idempotency_guard", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE TRIGGER project_create_idempotency_reject_truncate BEFORE TRUNCATE ON project_create_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_project_create_idempotency_truncate()", - "enabled": "O", - "name": "project_create_idempotency_reject_truncate", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER project_create_reservation_custody AFTER INSERT OR UPDATE ON project_create_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", - "enabled": "O", - "name": "project_create_reservation_custody", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_compilation_attempt_delete BEFORE DELETE OR TRUNCATE ON project_guide_compilation_attempts FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", - "enabled": "O", - "name": "trg_compilation_attempt_delete", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE TRIGGER trg_compilation_attempt_update BEFORE UPDATE ON project_guide_compilation_attempts FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_attempt_update()", - "enabled": "O", - "name": "trg_compilation_attempt_update", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE TRIGGER trg_compilation_insert BEFORE INSERT ON project_guide_compilations FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_insert()", - "enabled": "O", - "name": "trg_compilation_insert", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE TRIGGER trg_compilation_mutation BEFORE DELETE OR UPDATE OR TRUNCATE ON project_guide_compilations FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", - "enabled": "O", - "name": "trg_compilation_mutation", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE TRIGGER guide_lineage_lifecycle_guard BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_guide_lineage_and_lifecycle()", - "enabled": "O", - "name": "guide_lineage_lifecycle_guard", - "table_name": "project_guides" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_product_custody AFTER INSERT OR UPDATE ON project_guides DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "guide_mutation_product_custody", - "table_name": "project_guides" - }, - { - "definition": "CREATE TRIGGER project_guides_policy_selection_immutable BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_project_guide_policy_selection()", - "enabled": "O", - "name": "project_guides_policy_selection_immutable", - "table_name": "project_guides" - }, - { - "definition": "CREATE TRIGGER trg_project_role_grants_history BEFORE INSERT OR DELETE OR UPDATE ON project_role_grants FOR EACH ROW EXECUTE FUNCTION guard_project_role_grant_history()", - "enabled": "O", - "name": "trg_project_role_grants_history", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE TRIGGER trg_project_role_grants_reject_truncate BEFORE TRUNCATE ON project_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", - "enabled": "O", - "name": "trg_project_role_grants_reject_truncate", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE TRIGGER trg_project_role_qualification_snapshots_immutable BEFORE INSERT OR DELETE OR UPDATE ON project_role_qualification_snapshots FOR EACH ROW EXECUTE FUNCTION guard_project_role_snapshot_history()", - "enabled": "O", - "name": "trg_project_role_qualification_snapshots_immutable", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE TRIGGER trg_project_role_snapshots_reject_truncate BEFORE TRUNCATE ON project_role_qualification_snapshots FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", - "enabled": "O", - "name": "trg_project_role_snapshots_reject_truncate", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER source_setup_run_custody AFTER INSERT OR UPDATE ON project_setup_runs DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "source_setup_run_custody", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER project_creation_custody AFTER INSERT OR UPDATE OF created_by_actor_profile_id, created_via_identity_link_id, created_by_admin_role_grant_id, creation_scope_type, creation_action_id, authorization_decision_event_id ON projects DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", - "enabled": "O", - "name": "project_creation_custody", - "table_name": "projects" - }, - { - "definition": "CREATE TRIGGER review_admission_idempotency_records_reject_truncate BEFORE TRUNCATE ON review_admission_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", - "enabled": "O", - "name": "review_admission_idempotency_records_reject_truncate", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE TRIGGER review_admission_records_guard BEFORE INSERT OR DELETE OR UPDATE ON review_admission_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_review_admission_record()", - "enabled": "O", - "name": "review_admission_records_guard", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER review_leases_active_lease_guard AFTER INSERT OR UPDATE ON review_leases DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", - "enabled": "O", - "name": "review_leases_active_lease_guard", - "table_name": "review_leases" - }, - { - "definition": "CREATE TRIGGER review_leases_guard BEFORE INSERT OR DELETE OR UPDATE ON review_leases FOR EACH ROW EXECUTE FUNCTION guard_review_lease()", - "enabled": "O", - "name": "review_leases_guard", - "table_name": "review_leases" - }, - { - "definition": "CREATE TRIGGER review_leases_reject_truncate BEFORE TRUNCATE ON review_leases FOR EACH STATEMENT EXECUTE FUNCTION reject_review_lease_truncate()", - "enabled": "O", - "name": "review_leases_reject_truncate", - "table_name": "review_leases" - }, - { - "definition": "CREATE TRIGGER review_policies_immutable BEFORE DELETE OR UPDATE ON review_policies FOR EACH ROW EXECUTE FUNCTION guard_review_policies_immutable()", - "enabled": "O", - "name": "review_policies_immutable", - "table_name": "review_policies" - }, - { - "definition": "CREATE TRIGGER review_policies_reject_truncate BEFORE TRUNCATE ON review_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_review_policies_immutable()", - "enabled": "O", - "name": "review_policies_reject_truncate", - "table_name": "review_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER review_policy_mutation_custody AFTER INSERT OR UPDATE ON review_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", - "enabled": "O", - "name": "review_policy_mutation_custody", - "table_name": "review_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER review_queue_entries_active_lease_guard AFTER INSERT OR UPDATE ON review_queue_entries DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", - "enabled": "O", - "name": "review_queue_entries_active_lease_guard", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE TRIGGER review_queue_entries_guard BEFORE INSERT OR DELETE OR UPDATE ON review_queue_entries FOR EACH ROW EXECUTE FUNCTION guard_review_queue_entry()", - "enabled": "O", - "name": "review_queue_entries_guard", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE TRIGGER review_queue_entries_reject_truncate BEFORE TRUNCATE ON review_queue_entries FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", - "enabled": "O", - "name": "review_queue_entries_reject_truncate", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE TRIGGER revision_policies_immutable BEFORE DELETE OR UPDATE ON revision_policies FOR EACH ROW EXECUTE FUNCTION guard_revision_policies_immutable()", - "enabled": "O", - "name": "revision_policies_immutable", - "table_name": "revision_policies" - }, - { - "definition": "CREATE TRIGGER revision_policies_reject_truncate BEFORE TRUNCATE ON revision_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_revision_policies_immutable()", - "enabled": "O", - "name": "revision_policies_reject_truncate", - "table_name": "revision_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER revision_policy_mutation_custody AFTER INSERT OR UPDATE ON revision_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", - "enabled": "O", - "name": "revision_policy_mutation_custody", - "table_name": "revision_policies" - }, - { - "definition": "CREATE TRIGGER submission_policy_approval_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_approval_provenance()", - "enabled": "O", - "name": "submission_policy_approval_provenance_immutable", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER submission_policy_creation_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_creation_custody()", - "enabled": "O", - "name": "submission_policy_creation_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER submission_policy_creation_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_creation_provenance()", - "enabled": "O", - "name": "submission_policy_creation_provenance_immutable", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER submission_policy_product_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "submission_policy_product_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER submission_bundle_admission_delete BEFORE DELETE OR TRUNCATE ON submission_bundle_admissions FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_admission_delete()", - "enabled": "O", - "name": "submission_bundle_admission_delete", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE TRIGGER submission_bundle_admission_lineage BEFORE UPDATE ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_lineage()", - "enabled": "O", - "name": "submission_bundle_admission_lineage", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE TRIGGER submission_bundle_admission_verified_lineage BEFORE INSERT ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_verified_lineage()", - "enabled": "O", - "name": "submission_bundle_admission_verified_lineage", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE TRIGGER submission_bundle_durable_intent_put_attempt BEFORE INSERT ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intent_put_attempt()", - "enabled": "O", - "name": "submission_bundle_durable_intent_put_attempt", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE TRIGGER submission_bundle_durable_intents_immutable BEFORE DELETE OR UPDATE ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", - "enabled": "O", - "name": "submission_bundle_durable_intents_immutable", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE TRIGGER submission_bundle_durable_intents_no_truncate BEFORE TRUNCATE ON submission_bundle_durable_intents FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", - "enabled": "O", - "name": "submission_bundle_durable_intents_no_truncate", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER submission_policy_replay_custody AFTER INSERT OR UPDATE ON submission_policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW WHEN (new.status::text = 'committed'::text) EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "submission_policy_replay_custody", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_submission_policy_replay_immutable BEFORE DELETE OR UPDATE ON submission_policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_submission_policy_replay_mutation()", - "enabled": "O", - "name": "trg_submission_policy_replay_immutable", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_submission_policy_replay_no_truncate BEFORE TRUNCATE ON submission_policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_submission_policy_replay_truncate()", - "enabled": "O", - "name": "trg_submission_policy_replay_no_truncate", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER submissions_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON submissions FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", - "enabled": "O", - "name": "submissions_contributor_human", - "table_name": "submissions" - }, - { - "definition": "CREATE TRIGGER task_assignments_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON task_assignments FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", - "enabled": "O", - "name": "task_assignments_contributor_human", - "table_name": "task_assignments" - } - ], - "types": [] -} +{"acl":[{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"routine","name":"authority_event_facts_are_safe(event_name text, before_state js","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_event_facts_are_safe(event_name text, before_state js","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_facts_are_safe(facts json)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_facts_are_safe(facts json)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_grant_facts_are_safe(facts json, roles text[], expect","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_grant_facts_are_safe(facts json, roles text[], expect","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"enforce_compensation_binding_lifecycle()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"enforce_compensation_binding_lifecycle()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_identity_link_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_identity_link_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_profile_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_profile_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_admin_role_grant()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_admin_role_grant()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_artifact_receipt_producer_reference()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_artifact_receipt_producer_reference()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_control()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_control()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_idempotency_record()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_idempotency_record()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_children()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_children()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_version_content()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_version_content()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_lineage_and_lifecycle()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_lineage_and_lifecycle()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_mutation_idempotency()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_mutation_idempotency()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_iso_4217_currency_codes()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_iso_4217_currency_codes()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_outbox_event()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_outbox_event()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_policy_mutation_replay()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_policy_mutation_replay()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_result_membership()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_result_membership()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_results_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_results_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_set_creation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_set_creation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_sets_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_sets_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_compensation_units()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_compensation_units()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_create_idempotency()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_create_idempotency()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_attempt_update()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_attempt_update()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_insert()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_insert()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_policy_selection()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_policy_selection()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_grant_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_grant_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_snapshot_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_snapshot_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_admission_record()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_admission_record()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_lease()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_lease()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_policies_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_policies_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_queue_entry()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_queue_entry()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_revision_policies_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_revision_policies_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_service_identity_migration_evidence()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_service_identity_migration_evidence()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_delete()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_delete()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_lineage()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_lineage()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_verified_lineage()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_verified_lineage()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intent_put_attempt()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intent_put_attempt()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intents_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intents_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_availability_is_safe(value jsonb)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_availability_is_safe(value jsonb)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reason_is_safe(value text)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reason_is_safe(value text)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_array_is_safe(value jsonb, uuid_only boo","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_array_is_safe(value jsonb, uuid_only boo","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_token_is_safe(value text)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_token_is_safe(value text)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_approval_provenance()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_approval_provenance()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_creation_provenance()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_creation_provenance()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_output_provenance()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_output_provenance()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_admin_role_grant_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_admin_role_grant_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_artifact_fact_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_artifact_fact_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_audit_event_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_audit_event_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_control_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_control_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_idempotency_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_idempotency_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_contribution_policy_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_contribution_policy_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_mutation_idempotency_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_mutation_idempotency_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_source_snapshot_item_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_source_snapshot_item_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_pending_authority_idempotency()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_pending_authority_idempotency()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_policy_mutation_replay_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_policy_mutation_replay_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_create_idempotency_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_create_idempotency_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_guide_compilation_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_guide_compilation_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_role_history_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_role_history_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_lease_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_lease_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_queue_foundation_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_queue_foundation_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"require_human_actor_profile_reference()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"require_human_actor_profile_reference()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"set_authority_audit_database_time()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"set_authority_audit_database_time()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_binding_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_binding_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_recovery_attempt()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_recovery_attempt()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_verification_lineage()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_verification_lineage()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_bootstrap_authority_state()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_bootstrap_authority_state()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_canonical_actor_link()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_canonical_actor_link()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_contribution_policy_graph()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_contribution_policy_graph()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_mutation_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_mutation_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_source_snapshot_items()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_source_snapshot_items()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_linked_authority_event()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_linked_authority_event()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_policy_mutation_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_policy_mutation_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_project_create_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_project_create_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_review_active_lease()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_review_active_lease()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_authority_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_authority_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_creation_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_creation_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"sequence","name":"actor_profile_migration_state_id_seq","principal":"owner","privilege":"USAGE"},{"grantable":"false","kind":"sequence","name":"authority_control_id_seq","principal":"owner","privilege":"USAGE"}],"auxiliary_objects":[],"columns":[{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"actor_identity_links"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"actor_identity_links"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"issuer","not_null":true,"ordinal":3,"table_name":"actor_identity_links"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"subject","not_null":true,"ordinal":4,"table_name":"actor_identity_links"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"subject_kind","not_null":true,"ordinal":5,"table_name":"actor_identity_links"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"actor_identity_links"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"linked_by","not_null":true,"ordinal":7,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"linked_at","not_null":true,"ordinal":8,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_verified_at","not_null":false,"ordinal":9,"table_name":"actor_identity_links"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by","not_null":false,"ordinal":10,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_at","not_null":false,"ordinal":11,"table_name":"actor_identity_links"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_reason","not_null":false,"ordinal":12,"table_name":"actor_identity_links"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_by","not_null":false,"ordinal":13,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_at","not_null":false,"ordinal":14,"table_name":"actor_identity_links"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivation_reason","not_null":false,"ordinal":15,"table_name":"actor_identity_links"},{"data_type":"integer","default_expression":"nextval('actor_profile_migration_state_id_seq'::regclass)","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"actor_profile_migration_state"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"schema_version","not_null":true,"ordinal":2,"table_name":"actor_profile_migration_state"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classified_count","not_null":true,"ordinal":3,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_row_set_sha256","not_null":true,"ordinal":4,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"manifest_sha256","not_null":false,"ordinal":5,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"envelope_sha256","not_null":false,"ordinal":6,"table_name":"actor_profile_migration_state"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"migrated_at","not_null":true,"ordinal":7,"table_name":"actor_profile_migration_state"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_mapped_count","not_null":true,"ordinal":8,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_source_row_set_sha256","not_null":true,"ordinal":9,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_manifest_sha256","not_null":false,"ordinal":10,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_envelope_sha256","not_null":false,"ordinal":11,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(76)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_database_binding","not_null":true,"ordinal":12,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"actor_profiles"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_kind","not_null":true,"ordinal":2,"table_name":"actor_profiles"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":3,"table_name":"actor_profiles"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provisioning_method","not_null":true,"ordinal":4,"table_name":"actor_profiles"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"display_name","not_null":false,"ordinal":5,"table_name":"actor_profiles"},{"data_type":"character varying(320)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contact_email","not_null":false,"ordinal":6,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":7,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":8,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":9,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_seen_at","not_null":false,"ordinal":10,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_by","not_null":false,"ordinal":11,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_at","not_null":false,"ordinal":12,"table_name":"actor_profiles"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspension_reason","not_null":false,"ordinal":13,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deactivated_by","not_null":false,"ordinal":14,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deactivated_at","not_null":false,"ordinal":15,"table_name":"actor_profiles"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deactivation_reason","not_null":false,"ordinal":16,"table_name":"actor_profiles"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity","not_null":false,"ordinal":17,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_by","not_null":false,"ordinal":18,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_at","not_null":false,"ordinal":19,"table_name":"actor_profiles"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivation_reason","not_null":false,"ordinal":20,"table_name":"actor_profiles"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_actor_profile_id","not_null":true,"ordinal":2,"table_name":"admin_role_grants"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"role","not_null":true,"ordinal":3,"table_name":"admin_role_grants"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":4,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_project_id","not_null":false,"ordinal":5,"table_name":"admin_role_grants"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"admin_role_grants"},{"data_type":"smallint","default_expression":"'1'::smallint","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":7,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_actor_profile_id","not_null":false,"ordinal":8,"table_name":"admin_role_grants"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_system_principal","not_null":false,"ordinal":9,"table_name":"admin_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_admin_role_grant_id","not_null":false,"ordinal":10,"table_name":"admin_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"grant_reason","not_null":true,"ordinal":11,"table_name":"admin_role_grants"},{"data_type":"timestamp with time zone","default_expression":"clock_timestamp()","generated_kind":"00","identity_kind":"00","name":"granted_at","not_null":true,"ordinal":12,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_actor_profile_id","not_null":false,"ordinal":13,"table_name":"admin_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_admin_role_grant_id","not_null":false,"ordinal":14,"table_name":"admin_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_reason","not_null":false,"ordinal":15,"table_name":"admin_role_grants"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_at","not_null":false,"ordinal":16,"table_name":"admin_role_grants"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"control_scope","not_null":true,"ordinal":1,"table_name":"api_rate_control_counters"},{"data_type":"bytea","default_expression":"","generated_kind":"00","identity_kind":"00","name":"key_digest","not_null":true,"ordinal":2,"table_name":"api_rate_control_counters"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"window_started_at","not_null":true,"ordinal":3,"table_name":"api_rate_control_counters"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"window_expires_at","not_null":true,"ordinal":4,"table_name":"api_rate_control_counters"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_count","not_null":true,"ordinal":5,"table_name":"api_rate_control_counters"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":6,"table_name":"api_rate_control_counters"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_admission_charges"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":2,"table_name":"artifact_admission_charges"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_id","not_null":true,"ordinal":3,"table_name":"artifact_admission_charges"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":4,"table_name":"artifact_admission_charges"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":5,"table_name":"artifact_admission_charges"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_type","not_null":true,"ordinal":6,"table_name":"artifact_admission_charges"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_ref","not_null":true,"ordinal":7,"table_name":"artifact_admission_charges"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creating_operation_identity","not_null":true,"ordinal":8,"table_name":"artifact_admission_charges"},{"data_type":"character varying(20)","default_expression":"'provisional'::character varying","generated_kind":"00","identity_kind":"00","name":"state","not_null":true,"ordinal":9,"table_name":"artifact_admission_charges"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":10,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"reserved_at","not_null":true,"ordinal":11,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"completed_at","not_null":false,"ordinal":12,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"released_at","not_null":false,"ordinal":13,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":15,"table_name":"artifact_admission_charges"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":1,"table_name":"artifact_admission_scopes"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_id","not_null":true,"ordinal":2,"table_name":"artifact_admission_scopes"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"limit_bytes","not_null":true,"ordinal":3,"table_name":"artifact_admission_scopes"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"counted_bytes","not_null":true,"ordinal":4,"table_name":"artifact_admission_scopes"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":5,"table_name":"artifact_admission_scopes"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":6,"table_name":"artifact_admission_scopes"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":7,"table_name":"artifact_admission_scopes"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"artifact_bindings"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_type","not_null":true,"ordinal":4,"table_name":"artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_id","not_null":true,"ordinal":5,"table_name":"artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":true,"ordinal":6,"table_name":"artifact_bindings"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_version","not_null":true,"ordinal":7,"table_name":"artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":8,"table_name":"artifact_bindings"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attribution_type","not_null":true,"ordinal":9,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_binding_id","not_null":false,"ordinal":10,"table_name":"artifact_bindings"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":11,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_contents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":2,"table_name":"artifact_contents"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":3,"table_name":"artifact_contents"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":false,"ordinal":4,"table_name":"artifact_contents"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"normalized_display_name","not_null":false,"ordinal":5,"table_name":"artifact_contents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":6,"table_name":"artifact_contents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replica_id","not_null":true,"ordinal":2,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation","not_null":true,"ordinal":3,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":4,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":5,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(1024)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_object_ref","not_null":true,"ordinal":6,"table_name":"artifact_operation_receipts"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replayed","not_null":true,"ordinal":7,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome","not_null":true,"ordinal":8,"table_name":"artifact_operation_receipts"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_number","not_null":true,"ordinal":9,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":true,"ordinal":10,"table_name":"artifact_operation_receipts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"details","not_null":true,"ordinal":11,"table_name":"artifact_operation_receipts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":12,"table_name":"artifact_operation_receipts"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"contract_version","not_null":true,"ordinal":13,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":14,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_source_item_id","not_null":false,"ordinal":15,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_run_id","not_null":false,"ordinal":16,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":false,"ordinal":17,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_id","not_null":true,"ordinal":1,"table_name":"artifact_put_attempt_charges"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"charge_id","not_null":true,"ordinal":2,"table_name":"artifact_put_attempt_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":3,"table_name":"artifact_put_attempt_charges"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_put_attempts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_request_type","not_null":true,"ordinal":2,"table_name":"artifact_put_attempts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_type","not_null":true,"ordinal":3,"table_name":"artifact_put_attempts"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_ref","not_null":true,"ordinal":4,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":5,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":false,"ordinal":6,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_source_item_id","not_null":false,"ordinal":7,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_run_id","not_null":false,"ordinal":8,"table_name":"artifact_put_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":false,"ordinal":9,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":10,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":11,"table_name":"artifact_put_attempts"},{"data_type":"character varying(255)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":true,"ordinal":12,"table_name":"artifact_put_attempts"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"storage_namespace_id","not_null":true,"ordinal":13,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_fingerprint","not_null":true,"ordinal":14,"table_name":"artifact_put_attempts"},{"data_type":"character varying(1024)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_target","not_null":true,"ordinal":15,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_identity","not_null":true,"ordinal":16,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":17,"table_name":"artifact_put_attempts"},{"data_type":"character varying(40)","default_expression":"'prepared'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":18,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"next_run_at","not_null":false,"ordinal":19,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"executor_id","not_null":false,"ordinal":20,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lease_expires_at","not_null":false,"ordinal":21,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":22,"table_name":"artifact_put_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_result_code","not_null":false,"ordinal":23,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replica_id","not_null":false,"ordinal":24,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"receipt_id","not_null":false,"ordinal":25,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":26,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"prepared_at","not_null":true,"ordinal":27,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":28,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":29,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":30,"table_name":"artifact_put_attempts"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"execution_mode","not_null":false,"ordinal":31,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"observation_count","not_null":true,"ordinal":32,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'5'::bigint","generated_kind":"00","identity_kind":"00","name":"maximum_observations","not_null":true,"ordinal":33,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":2,"table_name":"artifact_put_observation_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":3,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome","not_null":true,"ordinal":4,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"expected_sha256","not_null":true,"ordinal":5,"table_name":"artifact_put_observation_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"expected_byte_count","not_null":true,"ordinal":6,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_sha256","not_null":false,"ordinal":7,"table_name":"artifact_put_observation_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_byte_count","not_null":false,"ordinal":8,"table_name":"artifact_put_observation_receipts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":9,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requester_actor_profile_id","not_null":true,"ordinal":2,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requester_identity_link_id","not_null":true,"ordinal":3,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_request_id","not_null":true,"ordinal":4,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_correlation_id","not_null":true,"ordinal":5,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":6,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":false,"ordinal":7,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":false,"ordinal":8,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_verification_job_id","not_null":true,"ordinal":9,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retry_verification_job_id","not_null":true,"ordinal":10,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"parent_recovery_attempt_id","not_null":false,"ordinal":11,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"recovery_class","not_null":true,"ordinal":12,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(1000)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reason","not_null":true,"ordinal":13,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"client_idempotency_key","not_null":true,"ordinal":14,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":15,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(20)","default_expression":"'requested'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":16,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_result_code","not_null":false,"ordinal":17,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"initiation_audit_event_id","not_null":true,"ordinal":18,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_audit_event_id","not_null":false,"ordinal":19,"table_name":"artifact_recovery_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":20,"table_name":"artifact_recovery_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":21,"table_name":"artifact_recovery_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":22,"table_name":"artifact_recovery_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":false,"ordinal":23,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_replicas"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"artifact_replicas"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter","not_null":true,"ordinal":3,"table_name":"artifact_replicas"},{"data_type":"character varying(1024)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_object_ref","not_null":true,"ordinal":4,"table_name":"artifact_replicas"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verification_state","not_null":true,"ordinal":5,"table_name":"artifact_replicas"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"availability_state","not_null":true,"ordinal":6,"table_name":"artifact_replicas"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"integrity_state","not_null":true,"ordinal":7,"table_name":"artifact_replicas"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_reconciled_at","not_null":false,"ordinal":8,"table_name":"artifact_replicas"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":9,"table_name":"artifact_replicas"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":10,"table_name":"artifact_replicas"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"storage_namespace_id","not_null":true,"ordinal":11,"table_name":"artifact_replicas"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_fingerprint","not_null":true,"ordinal":12,"table_name":"artifact_replicas"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_profile","not_null":true,"ordinal":13,"table_name":"artifact_replicas"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"backend","not_null":true,"ordinal":2,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter","not_null":true,"ordinal":3,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_profile","not_null":true,"ordinal":4,"table_name":"artifact_storage_namespaces"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_descriptor","not_null":true,"ordinal":5,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_fingerprint","not_null":true,"ordinal":6,"table_name":"artifact_storage_namespaces"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"originating_put_attempt_id","not_null":true,"ordinal":2,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replica_id","not_null":true,"ordinal":3,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(40)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"artifact_verification_jobs"},{"data_type":"integer","default_expression":"0","generated_kind":"00","identity_kind":"00","name":"attempt_count","not_null":true,"ordinal":5,"table_name":"artifact_verification_jobs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"maximum_attempts","not_null":true,"ordinal":6,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"next_run_at","not_null":false,"ordinal":7,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"executor_id","not_null":false,"ordinal":8,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lease_expires_at","not_null":false,"ordinal":9,"table_name":"artifact_verification_jobs"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":10,"table_name":"artifact_verification_jobs"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":11,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_result_code","not_null":false,"ordinal":12,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":13,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":14,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":false,"ordinal":15,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"parent_verification_job_id","not_null":false,"ordinal":16,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verification_job_id","not_null":true,"ordinal":2,"table_name":"artifact_verification_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":3,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome","not_null":true,"ordinal":4,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_sha256","not_null":false,"ordinal":5,"table_name":"artifact_verification_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_byte_count","not_null":false,"ordinal":6,"table_name":"artifact_verification_receipts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":7,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"audit_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"entity_type","not_null":true,"ordinal":2,"table_name":"audit_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"entity_id","not_null":true,"ordinal":3,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_type","not_null":true,"ordinal":4,"table_name":"audit_events"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"from_status","not_null":false,"ordinal":5,"table_name":"audit_events"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"to_status","not_null":false,"ordinal":6,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":7,"table_name":"audit_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_subject","not_null":false,"ordinal":8,"table_name":"audit_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_issuer","not_null":false,"ordinal":9,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_roles","not_null":true,"ordinal":10,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claim_snapshot","not_null":true,"ordinal":11,"table_name":"audit_events"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"auth_source","not_null":true,"ordinal":12,"table_name":"audit_events"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"is_dev_auth","not_null":true,"ordinal":13,"table_name":"audit_events"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reason","not_null":false,"ordinal":14,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_payload","not_null":true,"ordinal":15,"table_name":"audit_events"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"audit_events"},{"data_type":"character varying(24)","default_expression":"'legacy_lifecycle'::character varying","generated_kind":"00","identity_kind":"00","name":"event_domain","not_null":true,"ordinal":17,"table_name":"audit_events"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_version","not_null":false,"ordinal":18,"table_name":"audit_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"occurred_at","not_null":false,"ordinal":19,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_ref_kind","not_null":false,"ordinal":20,"table_name":"audit_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_id","not_null":false,"ordinal":21,"table_name":"audit_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":false,"ordinal":22,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_actor_ref_kind","not_null":false,"ordinal":23,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_actor_ref","not_null":false,"ordinal":24,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"matched_grant_id","not_null":false,"ordinal":25,"table_name":"audit_events"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"permission_id","not_null":false,"ordinal":26,"table_name":"audit_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":false,"ordinal":27,"table_name":"audit_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_type","not_null":false,"ordinal":28,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_id","not_null":false,"ordinal":29,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_ref_kind","not_null":false,"ordinal":30,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_ref_id","not_null":false,"ordinal":31,"table_name":"audit_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"denial_code","not_null":false,"ordinal":32,"table_name":"audit_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_reference","not_null":false,"ordinal":33,"table_name":"audit_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"invalidation_cause_event_id","not_null":false,"ordinal":34,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"invalidation_target_kind","not_null":false,"ordinal":35,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"invalidation_target_ref","not_null":false,"ordinal":36,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"before_facts","not_null":false,"ordinal":37,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"after_facts","not_null":false,"ordinal":38,"table_name":"audit_events"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":false,"ordinal":39,"table_name":"audit_events"},{"data_type":"smallint","default_expression":"nextval('authority_control_id_seq'::regclass)","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"authority_control"},{"data_type":"boolean","default_expression":"false","generated_kind":"00","identity_kind":"00","name":"bootstrap_completed","not_null":true,"ordinal":2,"table_name":"authority_control"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bootstrap_grant_id","not_null":false,"ordinal":3,"table_name":"authority_control"},{"data_type":"smallint","default_expression":"'0'::smallint","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":4,"table_name":"authority_control"},{"data_type":"timestamp with time zone","default_expression":"clock_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":5,"table_name":"authority_control"},{"data_type":"timestamp with time zone","default_expression":"clock_timestamp()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":6,"table_name":"authority_control"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"authority_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":2,"table_name":"authority_idempotency_records"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_ref_kind","not_null":true,"ordinal":3,"table_name":"authority_idempotency_records"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_ref","not_null":true,"ordinal":4,"table_name":"authority_idempotency_records"},{"data_type":"character varying(48)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation","not_null":true,"ordinal":5,"table_name":"authority_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"authority_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":7,"table_name":"authority_idempotency_records"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_resource_type","not_null":false,"ordinal":8,"table_name":"authority_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_resource_id","not_null":false,"ordinal":9,"table_name":"authority_idempotency_records"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_resource_version","not_null":false,"ordinal":10,"table_name":"authority_idempotency_records"},{"data_type":"smallint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_http_status","not_null":false,"ordinal":11,"table_name":"authority_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":12,"table_name":"authority_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":13,"table_name":"authority_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"required_checkers","not_null":true,"ordinal":4,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_checkers","not_null":true,"ordinal":5,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"blocking_severities","not_null":true,"ordinal":6,"table_name":"checker_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":false,"ordinal":8,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_body","not_null":false,"ordinal":9,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":10,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":11,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":12,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_id","not_null":true,"ordinal":13,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_hash","not_null":true,"ordinal":14,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_checker_policy_id","not_null":true,"ordinal":15,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_checker_bundle_hash","not_null":true,"ordinal":16,"table_name":"checker_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":17,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_role","not_null":false,"ordinal":18,"table_name":"checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_actor","not_null":false,"ordinal":19,"table_name":"checker_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_at","not_null":false,"ordinal":20,"table_name":"checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":21,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":22,"table_name":"checker_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":23,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_by_role","not_null":false,"ordinal":24,"table_name":"checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_by_actor","not_null":false,"ordinal":25,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersession_kind","not_null":false,"ordinal":26,"table_name":"checker_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersession_reason","not_null":false,"ordinal":27,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_run_id","not_null":true,"ordinal":2,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":3,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":4,"table_name":"checker_results"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_name","not_null":true,"ordinal":5,"table_name":"checker_results"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"checker_results"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"severity","not_null":true,"ordinal":7,"table_name":"checker_results"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"blocks_review","not_null":true,"ordinal":8,"table_name":"checker_results"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"message","not_null":true,"ordinal":9,"table_name":"checker_results"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_message","not_null":false,"ordinal":10,"table_name":"checker_results"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_suggested_fix","not_null":false,"ordinal":11,"table_name":"checker_results"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_evidence_refs","not_null":true,"ordinal":12,"table_name":"checker_results"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_visible","not_null":true,"ordinal":13,"table_name":"checker_results"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"metadata","not_null":true,"ordinal":14,"table_name":"checker_results"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":15,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":2,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":3,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":4,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"trigger_source","not_null":true,"ordinal":5,"table_name":"checker_runs"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"routing_recommendation","not_null":true,"ordinal":7,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome_source","not_null":true,"ordinal":8,"table_name":"checker_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"triggered_by","not_null":true,"ordinal":9,"table_name":"checker_runs"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"triggered_by_subject","not_null":true,"ordinal":10,"table_name":"checker_runs"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"triggered_by_issuer","not_null":true,"ordinal":11,"table_name":"checker_runs"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"trigger_auth_source","not_null":true,"ordinal":12,"table_name":"checker_runs"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"trigger_reason","not_null":false,"ordinal":13,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"audit_event_id","not_null":false,"ordinal":14,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_number","not_null":true,"ordinal":15,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_checker_run_id","not_null":false,"ordinal":16,"table_name":"checker_runs"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"is_current_for_submission","not_null":true,"ordinal":17,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_version","not_null":true,"ordinal":18,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_payment_policy_version","not_null":true,"ordinal":19,"table_name":"checker_runs"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"package_hash","not_null":true,"ordinal":20,"table_name":"checker_runs"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_hash_manifest","not_null":true,"ordinal":21,"table_name":"checker_runs"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_manifest_hash","not_null":true,"ordinal":22,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"passed_count","not_null":true,"ordinal":23,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_count","not_null":true,"ordinal":24,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failed_count","not_null":true,"ordinal":25,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"blocking_count","not_null":true,"ordinal":26,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"queued_at","not_null":true,"ordinal":27,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"started_at","not_null":false,"ordinal":28,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"completed_at","not_null":false,"ordinal":29,"table_name":"checker_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_code","not_null":false,"ordinal":30,"table_name":"checker_runs"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_message","not_null":false,"ordinal":31,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":32,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_id","not_null":false,"ordinal":33,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_version","not_null":false,"ordinal":34,"table_name":"checker_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_hash","not_null":false,"ordinal":35,"table_name":"checker_runs"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_body","not_null":false,"ordinal":36,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_id","not_null":true,"ordinal":37,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_generation","not_null":true,"ordinal":38,"table_name":"checker_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_hash","not_null":true,"ordinal":39,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_id","not_null":true,"ordinal":40,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_generation","not_null":true,"ordinal":41,"table_name":"checker_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_hash","not_null":true,"ordinal":42,"table_name":"checker_runs"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_rule_id","not_null":true,"ordinal":2,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_policy_version_id","not_null":true,"ordinal":3,"table_name":"contribution_award_definitions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":4,"table_name":"contribution_award_definitions"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_type","not_null":true,"ordinal":5,"table_name":"contribution_award_definitions"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instrument_type","not_null":true,"ordinal":6,"table_name":"contribution_award_definitions"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"unit_code","not_null":true,"ordinal":7,"table_name":"contribution_award_definitions"},{"data_type":"numeric","default_expression":"","generated_kind":"00","identity_kind":"00","name":"quantity","not_null":true,"ordinal":8,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter_binding_id","not_null":true,"ordinal":9,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"contribution_policies"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"name","not_null":true,"ordinal":3,"table_name":"contribution_policies"},{"data_type":"character varying(16)","default_expression":"'draft'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"contribution_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"current_published_version_id","not_null":false,"ordinal":5,"table_name":"contribution_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":6,"table_name":"contribution_policies"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"contribution_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":8,"table_name":"contribution_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":9,"table_name":"contribution_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_policy_versions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_policy_id","not_null":true,"ordinal":2,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"contribution_policy_versions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"version_number","not_null":true,"ordinal":4,"table_name":"contribution_policy_versions"},{"data_type":"character varying(16)","default_expression":"'draft'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":6,"table_name":"contribution_policy_versions"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"published_by","not_null":false,"ordinal":8,"table_name":"contribution_policy_versions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"published_at","not_null":false,"ordinal":9,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":10,"table_name":"contribution_policy_versions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":11,"table_name":"contribution_policy_versions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_rules"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_policy_version_id","not_null":true,"ordinal":2,"table_name":"contribution_rules"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"contribution_rules"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_type","not_null":true,"ordinal":4,"table_name":"contribution_rules"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compensation_mode","not_null":true,"ordinal":5,"table_name":"contribution_rules"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_artifact_policy_id","not_null":true,"ordinal":7,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_artifact_policy_hash","not_null":true,"ordinal":8,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":9,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"merge_algorithm_version","not_null":true,"ordinal":10,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy","not_null":true,"ordinal":11,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_hash","not_null":true,"ordinal":12,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":13,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_effective_policy_id","not_null":false,"ordinal":15,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":16,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":17,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":18,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":19,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":20,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":21,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":22,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_decision_event_id","not_null":false,"ordinal":23,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"evidence_items"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":2,"table_name":"evidence_items"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"type","not_null":true,"ordinal":3,"table_name":"evidence_items"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"label","not_null":true,"ordinal":4,"table_name":"evidence_items"},{"data_type":"character varying(1000)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"uri","not_null":false,"ordinal":5,"table_name":"evidence_items"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"hash","not_null":false,"ordinal":6,"table_name":"evidence_items"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"size_bytes","not_null":false,"ordinal":7,"table_name":"evidence_items"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_at","not_null":false,"ordinal":8,"table_name":"evidence_items"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"metadata","not_null":true,"ordinal":9,"table_name":"evidence_items"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"evidence_items"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"guide_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":7,"table_name":"guide_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":8,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":9,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_id","not_null":true,"ordinal":10,"table_name":"guide_mutation_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_generation","not_null":true,"ordinal":11,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":12,"table_name":"guide_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":13,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":false,"ordinal":14,"table_name":"guide_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":15,"table_name":"guide_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":16,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":4,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":5,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":true,"ordinal":6,"table_name":"guide_source_artifact_bindings"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":7,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":8,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":9,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":true,"ordinal":10,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_binding_id","not_null":false,"ordinal":11,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service","not_null":true,"ordinal":12,"table_name":"guide_source_artifact_bindings"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":13,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":2,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":3,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":4,"table_name":"guide_source_artifact_incidents"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":5,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"code","not_null":true,"ordinal":6,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_sha256","not_null":false,"ordinal":7,"table_name":"guide_source_artifact_incidents"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_byte_count","not_null":false,"ordinal":8,"table_name":"guide_source_artifact_incidents"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bounded_facts","not_null":true,"ordinal":9,"table_name":"guide_source_artifact_incidents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":2,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":4,"table_name":"guide_source_artifact_ingests"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":5,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(255)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":true,"ordinal":6,"table_name":"guide_source_artifact_ingests"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detected_format","not_null":true,"ordinal":3,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_name","not_null":true,"ordinal":4,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_version","not_null":true,"ordinal":5,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":6,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_sha256","not_null":true,"ordinal":7,"table_name":"guide_source_extracted_contents"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_byte_count","not_null":true,"ordinal":8,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":9,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_sha256","not_null":true,"ordinal":10,"table_name":"guide_source_extracted_contents"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_output","not_null":true,"ordinal":11,"table_name":"guide_source_extracted_contents"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"omission_facts","not_null":true,"ordinal":12,"table_name":"guide_source_extracted_contents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":13,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":2,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":3,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification_id","not_null":true,"ordinal":4,"table_name":"guide_source_extraction_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":5,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detected_format","not_null":true,"ordinal":6,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_name","not_null":true,"ordinal":7,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_version","not_null":true,"ordinal":8,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":9,"table_name":"guide_source_extraction_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_number","not_null":true,"ordinal":10,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":11,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_code","not_null":false,"ordinal":12,"table_name":"guide_source_extraction_attempts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bounded_facts","not_null":true,"ordinal":13,"table_name":"guide_source_extraction_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":1,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification_id","not_null":true,"ordinal":3,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":4,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":5,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claimed_slots","not_null":true,"ordinal":6,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":8,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extracted_content_id","not_null":true,"ordinal":2,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extraction_attempt_id","not_null":true,"ordinal":3,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_status","not_null":true,"ordinal":4,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":5,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":6,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":7,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":true,"ordinal":8,"table_name":"guide_source_extraction_usages"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":9,"table_name":"guide_source_extraction_usages"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":2,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":3,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":4,"table_name":"guide_source_format_classifications"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":5,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":6,"table_name":"guide_source_format_classifications"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":7,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(255)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":true,"ordinal":8,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detected_format","not_null":true,"ordinal":9,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detector_name","not_null":true,"ordinal":11,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detector_version","not_null":true,"ordinal":12,"table_name":"guide_source_format_classifications"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification_facts","not_null":true,"ordinal":13,"table_name":"guide_source_format_classifications"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":2,"table_name":"guide_source_snapshot_items"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"item_order","not_null":true,"ordinal":3,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_kind","not_null":true,"ordinal":4,"table_name":"guide_source_snapshot_items"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_label","not_null":true,"ordinal":5,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"ingestion_adapter","not_null":true,"ordinal":6,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":false,"ordinal":7,"table_name":"guide_source_snapshot_items"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":8,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"guide_source_snapshots"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"guide_source_snapshots"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"manifest_schema_version","not_null":true,"ordinal":5,"table_name":"guide_source_snapshots"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"manifest_json","not_null":true,"ordinal":6,"table_name":"guide_source_snapshots"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bundle_hash","not_null":true,"ordinal":7,"table_name":"guide_source_snapshots"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"captured_by","not_null":true,"ordinal":8,"table_name":"guide_source_snapshots"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"captured_at","not_null":true,"ordinal":9,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":10,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":11,"table_name":"guide_source_snapshots"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":12,"table_name":"guide_source_snapshots"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":13,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":14,"table_name":"guide_source_snapshots"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":15,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":16,"table_name":"guide_source_snapshots"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_generation","not_null":false,"ordinal":17,"table_name":"guide_source_snapshots"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":7,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":8,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":9,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":10,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":11,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"report_id","not_null":false,"ordinal":12,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":false,"ordinal":13,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":14,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":15,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":16,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":17,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":18,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"report_id","not_null":true,"ordinal":2,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"item_order","not_null":true,"ordinal":3,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":4,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":5,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":6,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extraction_usage_id","not_null":true,"ordinal":7,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extraction_attempt_id","not_null":true,"ordinal":8,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extracted_content_id","not_null":true,"ordinal":9,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":true,"ordinal":10,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":11,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_output_sha256","not_null":true,"ordinal":12,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":7,"table_name":"guide_sufficiency_reports"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"findings","not_null":true,"ordinal":8,"table_name":"guide_sufficiency_reports"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"summary","not_null":false,"ordinal":9,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_name","not_null":false,"ordinal":10,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_version","not_null":false,"ordinal":11,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":12,"table_name":"guide_sufficiency_reports"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":13,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_role","not_null":false,"ordinal":14,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_actor","not_null":false,"ordinal":15,"table_name":"guide_sufficiency_reports"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_at","not_null":false,"ordinal":16,"table_name":"guide_sufficiency_reports"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"acknowledgement_note","not_null":false,"ordinal":17,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":false,"ordinal":18,"table_name":"guide_sufficiency_reports"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":false,"ordinal":19,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_material_sha256","not_null":false,"ordinal":20,"table_name":"guide_sufficiency_reports"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_material_byte_count","not_null":false,"ordinal":21,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":22,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":23,"table_name":"guide_sufficiency_reports"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":24,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service_identity","not_null":false,"ordinal":25,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":26,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":27,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":28,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":29,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_actor_profile_id","not_null":false,"ordinal":30,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_via_identity_link_id","not_null":false,"ordinal":31,"table_name":"guide_sufficiency_reports"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_admin_role_grant_id","not_null":false,"ordinal":32,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_scope_type","not_null":false,"ordinal":33,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_scope_project_id","not_null":false,"ordinal":34,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_action_id","not_null":false,"ordinal":35,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_decision_event_id","not_null":false,"ordinal":36,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(3)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"code","not_null":true,"ordinal":1,"table_name":"iso_4217_currency_codes"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":1,"table_name":"legacy_actor_identities"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_subject","not_null":true,"ordinal":2,"table_name":"legacy_actor_identities"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_issuer","not_null":true,"ordinal":3,"table_name":"legacy_actor_identities"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"display_name","not_null":false,"ordinal":4,"table_name":"legacy_actor_identities"},{"data_type":"character varying(320)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"email","not_null":false,"ordinal":5,"table_name":"legacy_actor_identities"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_seen_roles","not_null":true,"ordinal":6,"table_name":"legacy_actor_identities"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_claim_snapshot","not_null":true,"ordinal":7,"table_name":"legacy_actor_identities"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"auth_source","not_null":true,"ordinal":8,"table_name":"legacy_actor_identities"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"is_dev_auth","not_null":true,"ordinal":9,"table_name":"legacy_actor_identities"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"first_seen_at","not_null":true,"ordinal":10,"table_name":"legacy_actor_identities"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"last_seen_at","not_null":true,"ordinal":11,"table_name":"legacy_actor_identities"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":12,"table_name":"legacy_actor_identities"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":2,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"profile_type","not_null":true,"ordinal":3,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"legacy_workflow_eligibility"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"skill_tags","not_null":true,"ordinal":5,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":6,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_id","not_null":true,"ordinal":7,"table_name":"legacy_workflow_eligibility"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"profile_metadata","not_null":true,"ordinal":8,"table_name":"legacy_workflow_eligibility"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":9,"table_name":"legacy_workflow_eligibility"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":10,"table_name":"legacy_workflow_eligibility"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_id","not_null":true,"ordinal":1,"table_name":"outbox_events"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_type","not_null":true,"ordinal":2,"table_name":"outbox_events"},{"data_type":"smallint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_version","not_null":true,"ordinal":3,"table_name":"outbox_events"},{"data_type":"character varying(32)","default_expression":"'workstream'::character varying","generated_kind":"00","identity_kind":"00","name":"producer","not_null":true,"ordinal":4,"table_name":"outbox_events"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"aggregate_type","not_null":true,"ordinal":5,"table_name":"outbox_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"aggregate_id","not_null":true,"ordinal":6,"table_name":"outbox_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":7,"table_name":"outbox_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":true,"ordinal":8,"table_name":"outbox_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"causation_event_id","not_null":false,"ordinal":9,"table_name":"outbox_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":10,"table_name":"outbox_events"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payload","not_null":true,"ordinal":11,"table_name":"outbox_events"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payload_digest","not_null":true,"ordinal":12,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"occurred_at","not_null":true,"ordinal":13,"table_name":"outbox_events"},{"data_type":"character varying(16)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"delivery_state","not_null":true,"ordinal":14,"table_name":"outbox_events"},{"data_type":"integer","default_expression":"0","generated_kind":"00","identity_kind":"00","name":"attempt_count","not_null":true,"ordinal":15,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"next_attempt_at","not_null":false,"ordinal":16,"table_name":"outbox_events"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claim_owner","not_null":false,"ordinal":17,"table_name":"outbox_events"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"claim_generation","not_null":true,"ordinal":18,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claimed_at","not_null":false,"ordinal":19,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claim_expires_at","not_null":false,"ordinal":20,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_attempt_at","not_null":false,"ordinal":21,"table_name":"outbox_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_error_code","not_null":false,"ordinal":22,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"finalized_at","not_null":false,"ordinal":23,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archived_at","not_null":false,"ordinal":24,"table_name":"outbox_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"payment_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"payment_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"payment_policies"},{"data_type":"numeric(12,2)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"base_amount","not_null":false,"ordinal":4,"table_name":"payment_policies"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"currency","not_null":false,"ordinal":5,"table_name":"payment_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payout_type","not_null":false,"ordinal":6,"table_name":"payment_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revision_payment_rule","not_null":false,"ordinal":7,"table_name":"payment_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"rejection_payment_rule","not_null":false,"ordinal":8,"table_name":"payment_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"accepted_payment_rule","not_null":false,"ordinal":9,"table_name":"payment_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"payment_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":7,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":8,"table_name":"policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":9,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":10,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":11,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_id","not_null":true,"ordinal":12,"table_name":"policy_mutation_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_generation","not_null":true,"ordinal":13,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":14,"table_name":"policy_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":15,"table_name":"policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":17,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_id","not_null":true,"ordinal":7,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_hash","not_null":true,"ordinal":8,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":9,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compiler_version","not_null":false,"ordinal":10,"table_name":"pre_submit_checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compiled_bundle","not_null":false,"ordinal":11,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compiled_bundle_hash","not_null":false,"ordinal":12,"table_name":"pre_submit_checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_names","not_null":true,"ordinal":13,"table_name":"pre_submit_checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_configs","not_null":true,"ordinal":14,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":15,"table_name":"pre_submit_checker_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_pre_submit_checker_policy_id","not_null":false,"ordinal":17,"table_name":"pre_submit_checker_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":18,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":19,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":20,"table_name":"pre_submit_checker_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":21,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":22,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":23,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":24,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_decision_event_id","not_null":false,"ordinal":25,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"evidence_set_id","not_null":true,"ordinal":2,"table_name":"pre_submit_evidence_results"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_order","not_null":true,"ordinal":3,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"schema_version","not_null":true,"ordinal":4,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"dispatch_authority","not_null":true,"ordinal":5,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"definition_id","not_null":true,"ordinal":6,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"definition_version","not_null":true,"ordinal":7,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"public_name","not_null":true,"ordinal":8,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source","not_null":true,"ordinal":9,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"phase","not_null":true,"ordinal":10,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification","not_null":true,"ordinal":11,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"severity","not_null":true,"ordinal":12,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":13,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_code","not_null":false,"ordinal":14,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"message_code","not_null":true,"ordinal":15,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_plan_sha256","not_null":true,"ordinal":16,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"rule_instance_id","not_null":false,"ordinal":17,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_policy_sha256","not_null":true,"ordinal":18,"table_name":"pre_submit_evidence_results"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":19,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_identity","not_null":true,"ordinal":2,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":4,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":5,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":6,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assignment_id","not_null":true,"ordinal":7,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_id","not_null":false,"ordinal":8,"table_name":"pre_submit_evidence_sets"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_version","not_null":false,"ordinal":9,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"prepared_generation_id","not_null":true,"ordinal":10,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_sha256","not_null":true,"ordinal":11,"table_name":"pre_submit_evidence_sets"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_byte_count","not_null":true,"ordinal":12,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_id","not_null":true,"ordinal":13,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_sha256","not_null":true,"ordinal":14,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":15,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":16,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":17,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_sha256","not_null":true,"ordinal":18,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_sha256","not_null":true,"ordinal":19,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_id","not_null":true,"ordinal":20,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_artifact_policy_sha256","not_null":true,"ordinal":21,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_policy_id","not_null":true,"ordinal":22,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_checker_policy_sha256","not_null":true,"ordinal":23,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_plan_sha256","not_null":true,"ordinal":24,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"catalogue_id","not_null":true,"ordinal":25,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"catalogue_version","not_null":true,"ordinal":26,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"catalogue_manifest_sha256","not_null":true,"ordinal":27,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"storage_scheme","not_null":true,"ordinal":28,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_status","not_null":true,"ordinal":29,"table_name":"pre_submit_evidence_sets"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"eligible","not_null":true,"ordinal":30,"table_name":"pre_submit_evidence_sets"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_count","not_null":true,"ordinal":31,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_manifest_sha256","not_null":true,"ordinal":32,"table_name":"pre_submit_evidence_sets"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":33,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_policy_context_hash","not_null":true,"ordinal":34,"table_name":"pre_submit_evidence_sets"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instrument_type","not_null":true,"ordinal":3,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter_actor_id","not_null":true,"ordinal":4,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"route_key","not_null":true,"ordinal":5,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"project_compensation_adapter_bindings"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"binding_lifecycle_version","not_null":true,"ordinal":7,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":8,"table_name":"project_compensation_adapter_bindings"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":9,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_by","not_null":false,"ordinal":10,"table_name":"project_compensation_adapter_bindings"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_at","not_null":false,"ordinal":11,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":12,"table_name":"project_compensation_adapter_bindings"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":13,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":1,"table_name":"project_compensation_units"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instrument_type","not_null":true,"ordinal":2,"table_name":"project_compensation_units"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"unit_code","not_null":true,"ordinal":3,"table_name":"project_compensation_units"},{"data_type":"character varying(3)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"iso_currency_code","not_null":false,"ordinal":4,"table_name":"project_compensation_units"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"project_compensation_units"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":6,"table_name":"project_compensation_units"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"project_compensation_units"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":8,"table_name":"project_compensation_units"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":9,"table_name":"project_compensation_units"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"project_create_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"project_create_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":7,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":8,"table_name":"project_create_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_generation","not_null":true,"ordinal":9,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"project_create_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":11,"table_name":"project_create_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":12,"table_name":"project_create_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":true,"ordinal":7,"table_name":"project_guide_compilation_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":8,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_input_hash","not_null":true,"ordinal":9,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_material_hash","not_null":true,"ordinal":10,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_id","not_null":true,"ordinal":11,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_version","not_null":true,"ordinal":12,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_schema_version","not_null":true,"ordinal":13,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_manifest_hash","not_null":true,"ordinal":14,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_id","not_null":true,"ordinal":15,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_version","not_null":true,"ordinal":16,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_schema_version","not_null":true,"ordinal":17,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_manifest_hash","not_null":true,"ordinal":18,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_identity","not_null":true,"ordinal":19,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_version","not_null":true,"ordinal":20,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instruction_version","not_null":true,"ordinal":21,"table_name":"project_guide_compilation_attempts"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_idempotency_key","not_null":true,"ordinal":22,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":23,"table_name":"project_guide_compilation_attempts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_result","not_null":false,"ordinal":24,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_hash","not_null":false,"ordinal":25,"table_name":"project_guide_compilation_attempts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"component_hashes","not_null":false,"ordinal":26,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_code","not_null":false,"ordinal":27,"table_name":"project_guide_compilation_attempts"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"persisted_compilation_id","not_null":false,"ordinal":28,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"reserved_at","not_null":true,"ordinal":29,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_uncertain_at","not_null":false,"ordinal":30,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"accepted_at","not_null":false,"ordinal":31,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":32,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"persisted_at","not_null":false,"ordinal":33,"table_name":"project_guide_compilation_attempts"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_guide_compilations"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_id","not_null":true,"ordinal":2,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":4,"table_name":"project_guide_compilations"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":5,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":6,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":7,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":true,"ordinal":8,"table_name":"project_guide_compilations"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":9,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_input_hash","not_null":true,"ordinal":10,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_material_hash","not_null":true,"ordinal":11,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_manifest_hash","not_null":true,"ordinal":12,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_manifest_hash","not_null":true,"ordinal":13,"table_name":"project_guide_compilations"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_identity","not_null":true,"ordinal":14,"table_name":"project_guide_compilations"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_version","not_null":true,"ordinal":15,"table_name":"project_guide_compilations"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instruction_version","not_null":true,"ordinal":16,"table_name":"project_guide_compilations"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_result","not_null":true,"ordinal":17,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_hash","not_null":true,"ordinal":18,"table_name":"project_guide_compilations"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"component_hashes","not_null":true,"ordinal":19,"table_name":"project_guide_compilations"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_compilation_id","not_null":false,"ordinal":20,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":true,"ordinal":21,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":true,"ordinal":22,"table_name":"project_guide_compilations"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service_identity","not_null":true,"ordinal":23,"table_name":"project_guide_compilations"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":true,"ordinal":24,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":true,"ordinal":25,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_resource_context_digest","not_null":true,"ordinal":26,"table_name":"project_guide_compilations"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":27,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_guides"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":3,"table_name":"project_guides"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"project_guides"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_markdown","not_null":true,"ordinal":5,"table_name":"project_guides"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by","not_null":false,"ordinal":6,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_at","not_null":false,"ordinal":7,"table_name":"project_guides"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"change_summary","not_null":false,"ordinal":8,"table_name":"project_guides"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":9,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":11,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":12,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutated_by_actor_profile_id","not_null":false,"ordinal":13,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutated_via_identity_link_id","not_null":false,"ordinal":14,"table_name":"project_guides"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutated_by_admin_role_grant_id","not_null":false,"ordinal":15,"table_name":"project_guides"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutation_scope_type","not_null":false,"ordinal":16,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutation_scope_project_id","not_null":false,"ordinal":17,"table_name":"project_guides"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutation_action_id","not_null":false,"ordinal":18,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_authorization_decision_event_id","not_null":false,"ordinal":19,"table_name":"project_guides"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"mutation_generation","not_null":false,"ordinal":20,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_review_policy_id","not_null":false,"ordinal":21,"table_name":"project_guides"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_review_policy_hash","not_null":false,"ordinal":22,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_revision_policy_id","not_null":false,"ordinal":23,"table_name":"project_guides"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_revision_policy_hash","not_null":false,"ordinal":24,"table_name":"project_guides"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_review_policy_generation","not_null":false,"ordinal":25,"table_name":"project_guides"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_revision_policy_generation","not_null":false,"ordinal":26,"table_name":"project_guides"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"project_role_grants"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"role","not_null":true,"ordinal":4,"table_name":"project_role_grants"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"project_role_grants"},{"data_type":"smallint","default_expression":"'1'::smallint","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":6,"table_name":"project_role_grants"},{"data_type":"character varying(16)","default_expression":"'manual'::character varying","generated_kind":"00","identity_kind":"00","name":"grant_method","not_null":true,"ordinal":7,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"qualification_snapshot_id","not_null":true,"ordinal":8,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_actor_profile_id","not_null":true,"ordinal":9,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_admin_role_grant_id","not_null":true,"ordinal":10,"table_name":"project_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"grant_reason","not_null":true,"ordinal":11,"table_name":"project_role_grants"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"granted_at","not_null":true,"ordinal":12,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_actor_profile_id","not_null":false,"ordinal":13,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_admin_role_grant_id","not_null":false,"ordinal":14,"table_name":"project_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_reason","not_null":false,"ordinal":15,"table_name":"project_role_grants"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_at","not_null":false,"ordinal":16,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requested_role","not_null":true,"ordinal":4,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"skills_snapshot","not_null":true,"ordinal":5,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reputation_snapshot","not_null":true,"ordinal":6,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"prior_project_work_refs","not_null":true,"ordinal":7,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_expertise_refs","not_null":true,"ordinal":8,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"captured_by_actor_profile_id","not_null":true,"ordinal":9,"table_name":"project_role_qualification_snapshots"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"captured_by_admin_role_grant_id","not_null":true,"ordinal":10,"table_name":"project_role_qualification_snapshots"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"captured_at","not_null":true,"ordinal":11,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"project_setup_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"project_setup_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"project_setup_runs"},{"data_type":"character varying(155)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"celery_task_id","not_null":false,"ordinal":7,"table_name":"project_setup_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":8,"table_name":"project_setup_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"current_step","not_null":true,"ordinal":9,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_sufficiency_report_id","not_null":false,"ordinal":10,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_submission_artifact_policy_id","not_null":false,"ordinal":11,"table_name":"project_setup_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_code","not_null":false,"ordinal":12,"table_name":"project_setup_runs"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_summary","not_null":false,"ordinal":13,"table_name":"project_setup_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":14,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":15,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":16,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"started_at","not_null":false,"ordinal":17,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"finished_at","not_null":false,"ordinal":18,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_post_submit_checker_policy_id","not_null":false,"ordinal":19,"table_name":"project_setup_runs"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_submit_derivation_summary","not_null":false,"ordinal":20,"table_name":"project_setup_runs"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":21,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorized_by_actor_profile_id","not_null":false,"ordinal":22,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorized_via_identity_link_id","not_null":false,"ordinal":23,"table_name":"project_setup_runs"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorized_by_admin_role_grant_id","not_null":false,"ordinal":24,"table_name":"project_setup_runs"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_scope_type","not_null":false,"ordinal":25,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_scope_project_id","not_null":false,"ordinal":26,"table_name":"project_setup_runs"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_action_id","not_null":false,"ordinal":27,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":28,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_artifact_incident_id","not_null":false,"ordinal":29,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"continuation_verification_job_id","not_null":false,"ordinal":30,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"continuation_started_at","not_null":false,"ordinal":31,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"projects"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"name","not_null":true,"ordinal":2,"table_name":"projects"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"slug","not_null":true,"ordinal":3,"table_name":"projects"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"description","not_null":false,"ordinal":4,"table_name":"projects"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"projects"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":6,"table_name":"projects"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":7,"table_name":"projects"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":8,"table_name":"projects"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":9,"table_name":"projects"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":10,"table_name":"projects"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":11,"table_name":"projects"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":12,"table_name":"projects"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":13,"table_name":"projects"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":2,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":3,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":4,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":5,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":6,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":7,"table_name":"review_admission_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":8,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"admitting_checker_run_id","not_null":true,"ordinal":9,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(16)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_queue_entry_id","not_null":false,"ordinal":11,"table_name":"review_admission_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":12,"table_name":"review_admission_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":13,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_leases"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_queue_entry_id","not_null":true,"ordinal":2,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":4,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":5,"table_name":"review_leases"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":6,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reviewer_id","not_null":true,"ordinal":7,"table_name":"review_leases"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reviewer_contribution_policy_version_id","not_null":true,"ordinal":8,"table_name":"review_leases"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_generation","not_null":true,"ordinal":9,"table_name":"review_leases"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"review_leases"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"claimed_at","not_null":true,"ordinal":11,"table_name":"review_leases"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"expires_at","not_null":true,"ordinal":12,"table_name":"review_leases"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"closed_at","not_null":false,"ordinal":13,"table_name":"review_leases"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"close_reason","not_null":false,"ordinal":14,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"review_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"review_policies"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requires_second_review","not_null":true,"ordinal":4,"table_name":"review_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"allowed_decisions","not_null":true,"ordinal":5,"table_name":"review_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"minimum_finding_fields","not_null":true,"ordinal":6,"table_name":"review_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_generation","not_null":true,"ordinal":8,"table_name":"review_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":9,"table_name":"review_policies"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantics_status","not_null":true,"ordinal":10,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":11,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_preference_window_seconds","not_null":false,"ordinal":12,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_lease_duration_seconds","not_null":false,"ordinal":13,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"max_active_review_leases_per_reviewer","not_null":false,"ordinal":14,"table_name":"review_policies"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"self_review_allowed","not_null":false,"ordinal":15,"table_name":"review_policies"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reject_policy","not_null":false,"ordinal":16,"table_name":"review_policies"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"finding_evidence_requirement","not_null":false,"ordinal":17,"table_name":"review_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_policy_hash","not_null":false,"ordinal":18,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":19,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":20,"table_name":"review_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":21,"table_name":"review_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":22,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":23,"table_name":"review_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":24,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":25,"table_name":"review_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":3,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":4,"table_name":"review_queue_entries"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":5,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"admitting_checker_run_id","not_null":true,"ordinal":6,"table_name":"review_queue_entries"},{"data_type":"character varying(16)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"queue_state","not_null":true,"ordinal":7,"table_name":"review_queue_entries"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"routing_mode","not_null":true,"ordinal":8,"table_name":"review_queue_entries"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"routing_reason","not_null":true,"ordinal":9,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"first_queued_at","not_null":true,"ordinal":10,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"available_since","not_null":true,"ordinal":11,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"preferred_reviewer_id","not_null":false,"ordinal":12,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"preference_expires_at","not_null":false,"ordinal":13,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"closed_at","not_null":false,"ordinal":14,"table_name":"review_queue_entries"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"closed_reason","not_null":false,"ordinal":15,"table_name":"review_queue_entries"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"routing_generation","not_null":true,"ordinal":16,"table_name":"review_queue_entries"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"lifecycle_generation","not_null":true,"ordinal":17,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":18,"table_name":"review_queue_entries"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"active_lease_id","not_null":false,"ordinal":19,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"revision_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"revision_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"max_revision_rounds","not_null":true,"ordinal":4,"table_name":"revision_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revision_deadline_hours","not_null":true,"ordinal":5,"table_name":"revision_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"allowed_resubmission_states","not_null":true,"ordinal":6,"table_name":"revision_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reviewer_reassignment_rule","not_null":false,"ordinal":7,"table_name":"revision_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":8,"table_name":"revision_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_generation","not_null":true,"ordinal":9,"table_name":"revision_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":10,"table_name":"revision_policies"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantics_status","not_null":true,"ordinal":11,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":12,"table_name":"revision_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_policy_hash","not_null":false,"ordinal":13,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":14,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":15,"table_name":"revision_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":16,"table_name":"revision_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":17,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":18,"table_name":"revision_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":19,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":20,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":7,"table_name":"submission_artifact_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":8,"table_name":"submission_artifact_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_body","not_null":true,"ordinal":9,"table_name":"submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":10,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"derivation_source","not_null":true,"ordinal":11,"table_name":"submission_artifact_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_material_refs","not_null":true,"ordinal":12,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"derivation_agent_name","not_null":false,"ordinal":13,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"derivation_agent_version","not_null":false,"ordinal":14,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":15,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":17,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_role","not_null":false,"ordinal":18,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_actor","not_null":false,"ordinal":19,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_at","not_null":false,"ordinal":20,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":21,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":22,"table_name":"submission_artifact_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"change_summary","not_null":false,"ordinal":23,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":24,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":25,"table_name":"submission_artifact_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":26,"table_name":"submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service_identity","not_null":false,"ordinal":27,"table_name":"submission_artifact_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":28,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":29,"table_name":"submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":30,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_decision_event_id","not_null":false,"ordinal":31,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_actor_profile_id","not_null":false,"ordinal":32,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_via_identity_link_id","not_null":false,"ordinal":33,"table_name":"submission_artifact_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_admin_role_grant_id","not_null":false,"ordinal":34,"table_name":"submission_artifact_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_scope_type","not_null":false,"ordinal":35,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_scope_project_id","not_null":false,"ordinal":36,"table_name":"submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_action_id","not_null":false,"ordinal":37,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_decision_event_id","not_null":false,"ordinal":38,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"durable_intent_id","not_null":true,"ordinal":2,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_evidence_set_id","not_null":true,"ordinal":3,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":4,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_content_id","not_null":true,"ordinal":5,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":6,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verification_receipt_id","not_null":true,"ordinal":7,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_operation_receipt_id","not_null":false,"ordinal":8,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_observation_receipt_id","not_null":false,"ordinal":9,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":10,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":11,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":12,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":13,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assignment_id","not_null":true,"ordinal":14,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_id","not_null":false,"ordinal":15,"table_name":"submission_bundle_admissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_version","not_null":false,"ordinal":16,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_policy_context_hash","not_null":true,"ordinal":17,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_id","not_null":true,"ordinal":18,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_sha256","not_null":true,"ordinal":19,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_sha256","not_null":true,"ordinal":20,"table_name":"submission_bundle_admissions"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_byte_count","not_null":true,"ordinal":21,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(16)","default_expression":"'ready'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":22,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"ready_at","not_null":true,"ordinal":23,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"consumed_at","not_null":false,"ordinal":24,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"consumed_by_submission_id","not_null":false,"ordinal":25,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"stale_at","not_null":false,"ordinal":26,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"stale_reason","not_null":false,"ordinal":27,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":28,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_bundle_durable_intents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_evidence_set_id","not_null":true,"ordinal":2,"table_name":"submission_bundle_durable_intents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":3,"table_name":"submission_bundle_durable_intents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":4,"table_name":"submission_bundle_durable_intents"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity","not_null":false,"ordinal":4,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":5,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":false,"ordinal":6,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":7,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":8,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_json","not_null":true,"ordinal":9,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":10,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":11,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":12,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":13,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_id","not_null":true,"ordinal":14,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":false,"ordinal":15,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":16,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_task_id","not_null":false,"ordinal":17,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":false,"ordinal":18,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":19,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":20,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_policy_id","not_null":false,"ordinal":21,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_effective_policy_id","not_null":false,"ordinal":22,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_pre_submit_policy_id","not_null":false,"ordinal":23,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":24,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":25,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":2,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contributor_id","not_null":true,"ordinal":3,"table_name":"submissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":4,"table_name":"submissions"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"submissions"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"summary","not_null":true,"ordinal":6,"table_name":"submissions"},{"data_type":"character varying(1000)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"package_uri","not_null":false,"ordinal":7,"table_name":"submissions"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"package_hash","not_null":true,"ordinal":8,"table_name":"submissions"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_hash_manifest","not_null":true,"ordinal":9,"table_name":"submissions"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_attestation","not_null":true,"ordinal":10,"table_name":"submissions"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_version","not_null":true,"ordinal":11,"table_name":"submissions"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_payment_policy_version","not_null":true,"ordinal":12,"table_name":"submissions"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"submitted_at","not_null":true,"ordinal":13,"table_name":"submissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_at","not_null":false,"ordinal":14,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_submission_id","not_null":false,"ordinal":15,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_id","not_null":false,"ordinal":16,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_hash","not_null":false,"ordinal":17,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_id","not_null":false,"ordinal":18,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_hash","not_null":false,"ordinal":19,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_policy_id","not_null":false,"ordinal":20,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_bundle_hash","not_null":false,"ordinal":21,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_id","not_null":false,"ordinal":22,"table_name":"submissions"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_version","not_null":false,"ordinal":23,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_hash","not_null":false,"ordinal":24,"table_name":"submissions"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_body","not_null":false,"ordinal":25,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_id","not_null":true,"ordinal":26,"table_name":"submissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_generation","not_null":true,"ordinal":27,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_hash","not_null":true,"ordinal":28,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_id","not_null":true,"ordinal":29,"table_name":"submissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_generation","not_null":true,"ordinal":30,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_hash","not_null":true,"ordinal":31,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"task_assignments"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":2,"table_name":"task_assignments"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contributor_id","not_null":true,"ordinal":3,"table_name":"task_assignments"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assigned_by","not_null":true,"ordinal":4,"table_name":"task_assignments"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"assigned_at","not_null":true,"ordinal":5,"table_name":"task_assignments"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"accepted_at","not_null":false,"ordinal":6,"table_name":"task_assignments"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"released_at","not_null":false,"ordinal":7,"table_name":"task_assignments"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":8,"table_name":"task_assignments"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_version","not_null":false,"ordinal":3,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_payment_policy_version","not_null":false,"ordinal":4,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_type","not_null":true,"ordinal":5,"table_name":"workstream_tasks"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_ref","not_null":false,"ordinal":6,"table_name":"workstream_tasks"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_payload_hash","not_null":false,"ordinal":7,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"import_batch_id","not_null":false,"ordinal":8,"table_name":"workstream_tasks"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_task_id","not_null":false,"ordinal":9,"table_name":"workstream_tasks"},{"data_type":"character varying(300)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"title","not_null":true,"ordinal":10,"table_name":"workstream_tasks"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"description","not_null":true,"ordinal":11,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_type","not_null":false,"ordinal":12,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"difficulty","not_null":false,"ordinal":13,"table_name":"workstream_tasks"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"skill_tags","not_null":true,"ordinal":14,"table_name":"workstream_tasks"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"estimated_time_minutes","not_null":false,"ordinal":15,"table_name":"workstream_tasks"},{"data_type":"numeric(12,2)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"base_amount","not_null":false,"ordinal":16,"table_name":"workstream_tasks"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"currency","not_null":false,"ordinal":17,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payout_type","not_null":false,"ordinal":18,"table_name":"workstream_tasks"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":19,"table_name":"workstream_tasks"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"acceptance_criteria","not_null":false,"ordinal":20,"table_name":"workstream_tasks"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"rejection_criteria","not_null":false,"ordinal":21,"table_name":"workstream_tasks"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deadline_at","not_null":false,"ordinal":22,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":23,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assigned_to","not_null":false,"ordinal":24,"table_name":"workstream_tasks"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":25,"table_name":"workstream_tasks"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":26,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_id","not_null":false,"ordinal":27,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_hash","not_null":false,"ordinal":28,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_id","not_null":false,"ordinal":29,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_hash","not_null":false,"ordinal":30,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_policy_id","not_null":false,"ordinal":31,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_bundle_hash","not_null":false,"ordinal":32,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_id","not_null":false,"ordinal":33,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_version","not_null":false,"ordinal":34,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_hash","not_null":false,"ordinal":35,"table_name":"workstream_tasks"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_body","not_null":false,"ordinal":36,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_id","not_null":false,"ordinal":37,"table_name":"workstream_tasks"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_generation","not_null":false,"ordinal":38,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_hash","not_null":false,"ordinal":39,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_id","not_null":false,"ordinal":40,"table_name":"workstream_tasks"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_generation","not_null":false,"ordinal":41,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_hash","not_null":false,"ordinal":42,"table_name":"workstream_tasks"}],"constraints":[{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"actor_identity_link_profile_guard","table_name":"actor_identity_links"},{"definition":"CHECK (subject_kind::text = 'service'::text OR last_verified_at IS NOT NULL)","kind":"c","name":"ck_actor_identity_links_human_verified","table_name":"actor_identity_links"},{"definition":"CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_actor_identity_links_id_uuid","table_name":"actor_identity_links"},{"definition":"CHECK (length(btrim(issuer::text)) >= 1 AND length(btrim(issuer::text)) <= 200)","kind":"c","name":"ck_actor_identity_links_issuer","table_name":"actor_identity_links"},{"definition":"CHECK ((revoked_reason IS NULL OR revoked_reason::text = btrim(revoked_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(revoked_reason::text) >= 1 AND octet_length(revoked_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500))","kind":"c","name":"ck_actor_identity_links_lifecycle_reason_bounds","table_name":"actor_identity_links"},{"definition":"CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)","kind":"c","name":"ck_actor_identity_links_reactivation_fields","table_name":"actor_identity_links"},{"definition":"CHECK (status::text = 'active'::text AND revoked_by IS NULL AND revoked_at IS NULL AND revoked_reason IS NULL OR status::text = 'revoked'::text AND revoked_by IS NOT NULL AND revoked_at IS NOT NULL AND revoked_reason IS NOT NULL)","kind":"c","name":"ck_actor_identity_links_revocation_fields","table_name":"actor_identity_links"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'revoked']))","kind":"c","name":"ck_actor_identity_links_status","table_name":"actor_identity_links"},{"definition":"CHECK (length(btrim(subject::text)) >= 1 AND length(btrim(subject::text)) <= 200)","kind":"c","name":"ck_actor_identity_links_subject","table_name":"actor_identity_links"},{"definition":"CHECK (subject_kind::text = ANY (ARRAY['human', 'service']))","kind":"c","name":"ck_actor_identity_links_subject_kind","table_name":"actor_identity_links"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_actor_identity_links_actor_profile_id_actor_profiles","table_name":"actor_identity_links"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_actor_identity_links","table_name":"actor_identity_links"},{"definition":"UNIQUE (actor_profile_id)","kind":"u","name":"uq_actor_identity_links_actor_profile","table_name":"actor_identity_links"},{"definition":"UNIQUE (issuer, subject)","kind":"u","name":"uq_actor_identity_links_external_identity","table_name":"actor_identity_links"},{"definition":"UNIQUE (id, actor_profile_id)","kind":"u","name":"uq_actor_identity_links_id_profile","table_name":"actor_identity_links"},{"definition":"CHECK (classified_count = 0 AND manifest_sha256 IS NULL AND envelope_sha256 IS NULL OR classified_count > 0 AND manifest_sha256 IS NOT NULL AND envelope_sha256 IS NOT NULL)","kind":"c","name":"ck_actor_profile_migration_state_evidence","table_name":"actor_profile_migration_state"},{"definition":"CHECK (service_identity_mapped_count >= 0 AND service_identity_mapped_count <= 7 AND service_identity_source_row_set_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_database_binding::text ~ '^postgres-v1:[0-9a-f]{64}$'::text AND (service_identity_mapped_count = 0 AND service_identity_manifest_sha256 IS NULL AND service_identity_envelope_sha256 IS NULL OR service_identity_mapped_count >= 1 AND service_identity_mapped_count <= 7 AND service_identity_manifest_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_envelope_sha256::text ~ '^[0-9a-f]{64}$'::text))","kind":"c","name":"ck_actor_profile_migration_state_service_identity_evidence","table_name":"actor_profile_migration_state"},{"definition":"CHECK (id = 1 AND schema_version = 1 AND classified_count >= 0)","kind":"c","name":"ck_actor_profile_migration_state_singleton","table_name":"actor_profile_migration_state"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_actor_profile_migration_state","table_name":"actor_profile_migration_state"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"actor_profile_link_guard","table_name":"actor_profiles"},{"definition":"CHECK (actor_kind::text = ANY (ARRAY['human', 'service']))","kind":"c","name":"ck_actor_profiles_actor_kind","table_name":"actor_profiles"},{"definition":"CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_actor_profiles_id_uuid","table_name":"actor_profiles"},{"definition":"CHECK (actor_kind::text = 'human'::text AND provisioning_method::text = 'automatic_first_access'::text OR actor_kind::text = 'service'::text AND provisioning_method::text = 'manual_service_provisioning'::text)","kind":"c","name":"ck_actor_profiles_kind_provisioning","table_name":"actor_profiles"},{"definition":"CHECK (actor_kind::text = 'human'::text AND service_identity IS NULL OR actor_kind::text = 'service'::text AND (service_identity::text = ANY (ARRAY['workstream.artifact.verifier', 'workstream.artifact.put_resolver', 'workstream.artifact.scheduler', 'workstream.artifact.binding', 'workstream.artifact.guide_reader', 'workstream.artifact.materializer', 'workstream.artifact.checker_output', 'workstream.project.setup', 'workstream.review.preference_expiry', 'workstream.review.lease_expiry', 'workstream.review.authority_invalidation_reconciliation', 'workstream.review.reconciliation', 'workstream.review.artifact_reference_reconciliation', 'workstream.review.projection'])))","kind":"c","name":"ck_actor_profiles_kind_service_identity","table_name":"actor_profiles"},{"definition":"CHECK (status::text = 'active'::text AND suspended_by IS NULL AND suspended_at IS NULL AND suspension_reason IS NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'suspended'::text AND suspended_by IS NOT NULL AND suspended_at IS NOT NULL AND suspension_reason IS NOT NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'deactivated'::text AND deactivated_by IS NOT NULL AND deactivated_at IS NOT NULL AND deactivation_reason IS NOT NULL)","kind":"c","name":"ck_actor_profiles_lifecycle_fields","table_name":"actor_profiles"},{"definition":"CHECK ((suspension_reason IS NULL OR suspension_reason::text = btrim(suspension_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(suspension_reason::text) >= 1 AND octet_length(suspension_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500) AND (deactivation_reason IS NULL OR deactivation_reason::text = btrim(deactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(deactivation_reason::text) >= 1 AND octet_length(deactivation_reason::text) <= 500))","kind":"c","name":"ck_actor_profiles_lifecycle_reason_bounds","table_name":"actor_profiles"},{"definition":"CHECK (provisioning_method::text = ANY (ARRAY['automatic_first_access', 'manual_service_provisioning']))","kind":"c","name":"ck_actor_profiles_provisioning_method","table_name":"actor_profiles"},{"definition":"CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)","kind":"c","name":"ck_actor_profiles_reactivation_fields","table_name":"actor_profiles"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'suspended', 'deactivated']))","kind":"c","name":"ck_actor_profiles_status","table_name":"actor_profiles"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_actor_profiles","table_name":"actor_profiles"},{"definition":"UNIQUE (service_identity)","kind":"u","name":"service_identity","table_name":"actor_profiles"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"admin_role_grants_bootstrap_invariant","table_name":"admin_role_grants"},{"definition":"CHECK (granted_by_system_principal::text = 'workstream:system:bootstrap'::text AND granted_by_actor_profile_id IS NULL AND granted_by_admin_role_grant_id IS NULL OR granted_by_system_principal IS NULL AND granted_by_actor_profile_id IS NOT NULL AND granted_by_admin_role_grant_id IS NOT NULL)","kind":"c","name":"ck_admin_role_grants_grant_attribution","table_name":"admin_role_grants"},{"definition":"CHECK (octet_length(grant_reason) >= 1 AND octet_length(grant_reason) <= 500)","kind":"c","name":"ck_admin_role_grants_grant_reason","table_name":"admin_role_grants"},{"definition":"CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND octet_length(revoked_reason) >= 1 AND octet_length(revoked_reason) <= 500 AND revoked_at IS NOT NULL)","kind":"c","name":"ck_admin_role_grants_lifecycle","table_name":"admin_role_grants"},{"definition":"CHECK (role::text = ANY (ARRAY['access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority']))","kind":"c","name":"ck_admin_role_grants_role","table_name":"admin_role_grants"},{"definition":"CHECK (scope_type::text = 'system'::text AND scope_project_id IS NULL OR scope_type::text = 'project'::text AND scope_project_id IS NOT NULL AND (role::text <> ALL (ARRAY['access_administrator', 'operator'])))","kind":"c","name":"ck_admin_role_grants_role_scope","table_name":"admin_role_grants"},{"definition":"CHECK (scope_type::text = ANY (ARRAY['system', 'project']))","kind":"c","name":"ck_admin_role_grants_scope_type","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_admin_role_grants_granted_by_admin_role_grant_id_adm_81e0","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_admin_role_grants_revoked_by_admin_role_grant_id_adm_78b5","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_admin_role_grants_scope_project_id_projects","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (target_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_admin_role_grants_target_actor_profile_id_actor_profiles","table_name":"admin_role_grants"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_admin_role_grants","table_name":"admin_role_grants"},{"definition":"CHECK (octet_length(key_digest) = 32)","kind":"c","name":"ck_api_rate_control_counters_digest_length","table_name":"api_rate_control_counters"},{"definition":"CHECK (request_count >= 1 AND request_count <= '9223372036854775807'::bigint)","kind":"c","name":"ck_api_rate_control_counters_request_count","table_name":"api_rate_control_counters"},{"definition":"CHECK (control_scope::text = ANY (ARRAY['first_access', 'admin_mutation', 'authorization_read']))","kind":"c","name":"ck_api_rate_control_counters_scope_token","table_name":"api_rate_control_counters"},{"definition":"CHECK (window_started_at < window_expires_at)","kind":"c","name":"ck_api_rate_control_counters_window_order","table_name":"api_rate_control_counters"},{"definition":"PRIMARY KEY (control_scope, key_digest)","kind":"p","name":"pk_api_rate_control_counters","table_name":"api_rate_control_counters"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_artifact_admission_charges_byte_count_nonnegative","table_name":"artifact_admission_charges"},{"definition":"CHECK (cas_version >= 0)","kind":"c","name":"ck_artifact_admission_charges_cas_nonnegative","table_name":"artifact_admission_charges"},{"definition":"CHECK ((state::text = 'completed'::text) = (completed_at IS NOT NULL))","kind":"c","name":"ck_artifact_admission_charges_completed_timestamp","table_name":"artifact_admission_charges"},{"definition":"CHECK (creating_operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_admission_charges_operation_identity_shape","table_name":"artifact_admission_charges"},{"definition":"CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))","kind":"c","name":"ck_artifact_admission_charges_producer_type","table_name":"artifact_admission_charges"},{"definition":"CHECK ((state::text = 'released'::text) = (released_at IS NOT NULL))","kind":"c","name":"ck_artifact_admission_charges_released_timestamp","table_name":"artifact_admission_charges"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_admission_charges_sha256_shape","table_name":"artifact_admission_charges"},{"definition":"CHECK (state::text = ANY (ARRAY['provisional', 'completed', 'released']))","kind":"c","name":"ck_artifact_admission_charges_state","table_name":"artifact_admission_charges"},{"definition":"FOREIGN KEY (scope_type, scope_id) REFERENCES artifact_admission_scopes(scope_type, scope_id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_admission_charges_scope","table_name":"artifact_admission_charges"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_admission_charges","table_name":"artifact_admission_charges"},{"definition":"UNIQUE (scope_type, scope_id, sha256, byte_count)","kind":"u","name":"uq_artifact_admission_charge_scope_content","table_name":"artifact_admission_charges"},{"definition":"CHECK (cas_version >= 0)","kind":"c","name":"ck_artifact_admission_scopes_cas_nonnegative","table_name":"artifact_admission_scopes"},{"definition":"CHECK (counted_bytes >= 0 AND counted_bytes <= limit_bytes)","kind":"c","name":"ck_artifact_admission_scopes_counted_bytes_within_limit","table_name":"artifact_admission_scopes"},{"definition":"CHECK (limit_bytes > 0)","kind":"c","name":"ck_artifact_admission_scopes_limit_positive","table_name":"artifact_admission_scopes"},{"definition":"CHECK (octet_length(scope_id::text) >= 1 AND octet_length(scope_id::text) <= 120)","kind":"c","name":"ck_artifact_admission_scopes_scope_id_bounds","table_name":"artifact_admission_scopes"},{"definition":"CHECK (scope_type::text = ANY (ARRAY['deployment', 'project', 'producer', 'task']))","kind":"c","name":"ck_artifact_admission_scopes_scope_type","table_name":"artifact_admission_scopes"},{"definition":"PRIMARY KEY (scope_type, scope_id)","kind":"p","name":"pk_artifact_admission_scopes","table_name":"artifact_admission_scopes"},{"definition":"CHECK (scope_version > 0)","kind":"c","name":"ck_artifact_bindings_scope_version_positive","table_name":"artifact_bindings"},{"definition":"CHECK (scope_version = 1 AND supersedes_binding_id IS NULL OR scope_version > 1 AND supersedes_binding_id IS NOT NULL)","kind":"c","name":"ck_artifact_bindings_scope_version_predecessor","table_name":"artifact_bindings"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_bindings_content_id_artifact_contents","table_name":"artifact_bindings"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_bindings_project_id_projects","table_name":"artifact_bindings"},{"definition":"FOREIGN KEY (supersedes_binding_id) REFERENCES artifact_bindings(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_bindings_supersedes_binding_id_artifact_bindings","table_name":"artifact_bindings"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_bindings","table_name":"artifact_bindings"},{"definition":"TRIGGER DEFERRABLE","kind":"t","name":"trg_artifact_binding_history","table_name":"artifact_bindings"},{"definition":"UNIQUE (project_id, resource_type, resource_id, logical_role, scope_version)","kind":"u","name":"uq_artifact_binding_scope_version","table_name":"artifact_bindings"},{"definition":"UNIQUE (supersedes_binding_id)","kind":"u","name":"uq_artifact_binding_supersedes","table_name":"artifact_bindings"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_artifact_contents_byte_count_nonnegative","table_name":"artifact_contents"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_contents_sha256_shape","table_name":"artifact_contents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_contents","table_name":"artifact_contents"},{"definition":"UNIQUE (sha256, byte_count)","kind":"u","name":"uq_artifact_content_digest_size","table_name":"artifact_contents"},{"definition":"CHECK (attempt_number > 0)","kind":"c","name":"ck_artifact_operation_receipts_attempt_positive","table_name":"artifact_operation_receipts"},{"definition":"CHECK (contract_version = 2 AND put_attempt_id IS NOT NULL AND (guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND logical_role IS NULL OR guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR guide_source_item_id IS NULL AND checker_run_id IS NULL AND logical_role IS NULL))","kind":"c","name":"ck_artifact_operation_receipts_contract_producer_reference","table_name":"artifact_operation_receipts"},{"definition":"CHECK (operation::text = 'put'::text)","kind":"c","name":"ck_artifact_operation_receipts_operation","table_name":"artifact_operation_receipts"},{"definition":"CHECK (outcome::text = 'stored_pending_verification'::text)","kind":"c","name":"ck_artifact_operation_receipts_outcome","table_name":"artifact_operation_receipts"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_operation_receipts_request_digest_shape","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_operation_receipts_replica_id_artifact_replicas","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_receipt_checker_run","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_receipt_guide_item","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_receipt_put_attempt","table_name":"artifact_operation_receipts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_operation_receipts","table_name":"artifact_operation_receipts"},{"definition":"UNIQUE (put_attempt_id)","kind":"u","name":"uq_artifact_receipt_put_attempt","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempt_charges_attempt_id_artifact_put_b25d","table_name":"artifact_put_attempt_charges"},{"definition":"FOREIGN KEY (charge_id) REFERENCES artifact_admission_charges(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempt_charges_charge_id_artifact_admi_85a9","table_name":"artifact_put_attempt_charges"},{"definition":"PRIMARY KEY (attempt_id, charge_id)","kind":"p","name":"pk_artifact_put_attempt_charges","table_name":"artifact_put_attempt_charges"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_artifact_put_attempts_byte_count_nonnegative","table_name":"artifact_put_attempts"},{"definition":"CHECK (canonical_target::text ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'::text)","kind":"c","name":"ck_artifact_put_attempts_canonical_target_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (execution_mode IS NULL OR (execution_mode::text = ANY (ARRAY['caller_put', 'observation'])))","kind":"c","name":"ck_artifact_put_attempts_execution_mode","table_name":"artifact_put_attempts"},{"definition":"CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))","kind":"c","name":"ck_artifact_put_attempts_executor_lease_pair","table_name":"artifact_put_attempts"},{"definition":"CHECK ((status::text = 'put_in_flight'::text) = (executor_id IS NOT NULL))","kind":"c","name":"ck_artifact_put_attempts_inflight_fence","table_name":"artifact_put_attempts"},{"definition":"CHECK (observation_count >= 0 AND maximum_observations > 0)","kind":"c","name":"ck_artifact_put_attempts_observation_counts","table_name":"artifact_put_attempts"},{"definition":"CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_attempts_operation_identity_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (status::text <> 'prepared'::text OR next_run_at IS NULL AND executor_id IS NULL AND lease_expires_at IS NULL AND execution_generation = 0 AND terminal_result_code IS NULL AND terminal_at IS NULL AND replica_id IS NULL AND receipt_id IS NULL)","kind":"c","name":"ck_artifact_put_attempts_prepared_execution_inactive","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_request_type::text = 'guide'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text OR producer_request_type::text = 'checker_output'::text AND producer_type::text = 'service_identity'::text AND producer_ref::text = 'workstream.artifact.checker_output'::text OR producer_request_type::text = 'submission_bundle'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_artifact_put_attempts_producer_identity","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_request_type::text = 'guide'::text AND guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND task_id IS NULL AND logical_role IS NULL OR producer_request_type::text = 'checker_output'::text AND guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND task_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR producer_request_type::text = 'submission_bundle'::text AND guide_source_item_id IS NULL AND checker_run_id IS NULL AND task_id IS NOT NULL AND logical_role IS NULL)","kind":"c","name":"ck_artifact_put_attempts_producer_reference","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_request_type::text = ANY (ARRAY['guide', 'checker_output', 'submission_bundle']))","kind":"c","name":"ck_artifact_put_attempts_producer_request_type","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))","kind":"c","name":"ck_artifact_put_attempts_producer_type","table_name":"artifact_put_attempts"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_attempts_request_digest_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_attempts_sha256_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['prepared', 'put_in_flight', 'acknowledgement_unknown', 'object_confirmed', 'absent_replay_required', 'integrity_mismatch', 'provider_unavailable', 'conflict']))","kind":"c","name":"ck_artifact_put_attempts_status","table_name":"artifact_put_attempts"},{"definition":"CHECK (status::text <> 'provider_unavailable'::text OR observation_count >= maximum_observations AND next_run_at IS NULL AND terminal_at IS NOT NULL)","kind":"c","name":"ck_artifact_put_attempts_unavailable_exhausted","table_name":"artifact_put_attempts"},{"definition":"CHECK (execution_generation >= 0 AND cas_version >= 0)","kind":"c","name":"ck_artifact_put_attempts_versions_nonnegative","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_checker_run_id_checker_runs","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_guide_source_item_id_guide_sou_e48c","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (storage_namespace_id, namespace_fingerprint) REFERENCES artifact_storage_namespaces(id, namespace_fingerprint) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_namespace_fingerprint","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_project_id_projects","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_receipt_id_artifact_operation_receipts","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_replica_id_artifact_replicas","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_task_id_workstream_tasks","table_name":"artifact_put_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_put_attempts","table_name":"artifact_put_attempts"},{"definition":"UNIQUE (operation_identity)","kind":"u","name":"uq_artifact_put_attempt_operation","table_name":"artifact_put_attempts"},{"definition":"CHECK (expected_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_observation_receipts_expected_sha256","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (expected_byte_count >= 0)","kind":"c","name":"ck_artifact_put_observation_receipts_expected_size","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK ((outcome::text = ANY (ARRAY['observed_confirmed', 'observed_integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))","kind":"c","name":"ck_artifact_put_observation_receipts_observed_facts","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_observation_receipts_observed_sha256","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)","kind":"c","name":"ck_artifact_put_observation_receipts_observed_size","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (outcome::text = ANY (ARRAY['observed_confirmed', 'observed_missing', 'observed_integrity_mismatch', 'conflict']))","kind":"c","name":"ck_artifact_put_observation_receipts_outcome","table_name":"artifact_put_observation_receipts"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_observation_receipts_put_attempt_id_art_237d","table_name":"artifact_put_observation_receipts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_put_observation_receipts","table_name":"artifact_put_observation_receipts"},{"definition":"UNIQUE (put_attempt_id, execution_generation)","kind":"u","name":"uq_artifact_put_observation_fence","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (cas_version >= 0)","kind":"c","name":"ck_artifact_recovery_attempts_cas_nonnegative","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (source_verification_job_id::text <> retry_verification_job_id::text)","kind":"c","name":"ck_artifact_recovery_attempts_distinct_jobs","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (recovery_class::text = 'provider_observation'::text)","kind":"c","name":"ck_artifact_recovery_attempts_recovery_class","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_recovery_attempts_request_digest","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['requested', 'succeeded', 'failed']))","kind":"c","name":"ck_artifact_recovery_attempts_status","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (status::text = 'succeeded'::text AND terminal_result_code::text = 'verified'::text OR status::text = 'failed'::text AND (terminal_result_code::text = ANY (ARRAY['provider_unavailable', 'missing', 'integrity_mismatch', 'conflict'])) OR status::text = 'requested'::text)","kind":"c","name":"ck_artifact_recovery_attempts_terminal_result","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (status::text = 'requested'::text AND terminal_result_code IS NULL AND terminal_at IS NULL AND terminal_audit_event_id IS NULL OR (status::text = ANY (ARRAY['succeeded', 'failed'])) AND terminal_result_code IS NOT NULL AND terminal_at IS NOT NULL AND terminal_audit_event_id IS NOT NULL)","kind":"c","name":"ck_artifact_recovery_attempts_terminal_shape","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (initiation_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_initiation_audit_event_id_2af7","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (parent_recovery_attempt_id) REFERENCES artifact_recovery_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_parent_recovery_attempt_i_130d","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_project_id_projects","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (requester_actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_requester_actor_profile_i_77f5","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (requester_identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_requester_identity_link_i_3619","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (retry_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_retry_verification_job_id_b330","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (source_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_source_verification_job_i_5eac","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_submission_id_submissions","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_task_id_workstream_tasks","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (terminal_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_terminal_audit_event_id_a_47ab","table_name":"artifact_recovery_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_recovery_attempts","table_name":"artifact_recovery_attempts"},{"definition":"UNIQUE (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)","kind":"u","name":"uq_artifact_recovery_idempotency","table_name":"artifact_recovery_attempts"},{"definition":"UNIQUE (retry_verification_job_id)","kind":"u","name":"uq_artifact_recovery_retry_job","table_name":"artifact_recovery_attempts"},{"definition":"UNIQUE (source_verification_job_id)","kind":"u","name":"uq_artifact_recovery_source_job","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (availability_state::text = ANY (ARRAY['unknown', 'available', 'unavailable']))","kind":"c","name":"ck_artifact_replicas_availability_state","table_name":"artifact_replicas"},{"definition":"CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_replicas_fingerprint_shape","table_name":"artifact_replicas"},{"definition":"CHECK (integrity_state::text = ANY (ARRAY['unknown', 'valid', 'invalid']))","kind":"c","name":"ck_artifact_replicas_integrity_state","table_name":"artifact_replicas"},{"definition":"CHECK (verification_state::text = ANY (ARRAY['pending', 'verified', 'missing', 'integrity_mismatch']))","kind":"c","name":"ck_artifact_replicas_verification_state","table_name":"artifact_replicas"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_replicas_content_id_artifact_contents","table_name":"artifact_replicas"},{"definition":"FOREIGN KEY (storage_namespace_id) REFERENCES artifact_storage_namespaces(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_replicas_storage_namespace_id_artifact_stor_d6cc","table_name":"artifact_replicas"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_replicas","table_name":"artifact_replicas"},{"definition":"UNIQUE (storage_namespace_id, provider_object_ref)","kind":"u","name":"uq_artifact_replica_provider_object","table_name":"artifact_replicas"},{"definition":"UNIQUE (id, content_id)","kind":"u","name":"uq_artifact_replicas_id_content","table_name":"artifact_replicas"},{"definition":"CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_storage_namespaces_fingerprint_shape","table_name":"artifact_storage_namespaces"},{"definition":"CHECK (id::text = 'primary'::text)","kind":"c","name":"ck_artifact_storage_namespaces_singleton_id","table_name":"artifact_storage_namespaces"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_storage_namespaces","table_name":"artifact_storage_namespaces"},{"definition":"UNIQUE (namespace_fingerprint)","kind":"u","name":"uq_artifact_storage_namespace_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"UNIQUE (id, namespace_fingerprint)","kind":"u","name":"uq_artifact_storage_namespace_id_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"CHECK (attempt_count >= 0 AND maximum_attempts > 0)","kind":"c","name":"ck_artifact_verification_jobs_attempts","table_name":"artifact_verification_jobs"},{"definition":"CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))","kind":"c","name":"ck_artifact_verification_jobs_fence_pair","table_name":"artifact_verification_jobs"},{"definition":"CHECK ((status::text = 'running'::text) = (executor_id IS NOT NULL))","kind":"c","name":"ck_artifact_verification_jobs_running_fence","table_name":"artifact_verification_jobs"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'running', 'verified', 'missing', 'integrity_mismatch', 'provider_unavailable', 'conflict']))","kind":"c","name":"ck_artifact_verification_jobs_status","table_name":"artifact_verification_jobs"},{"definition":"CHECK (status::text <> 'provider_unavailable'::text OR next_run_at IS NOT NULL AND terminal_at IS NULL AND attempt_count < maximum_attempts OR next_run_at IS NULL AND terminal_at IS NOT NULL AND attempt_count >= maximum_attempts)","kind":"c","name":"ck_artifact_verification_jobs_unavailable_retryability","table_name":"artifact_verification_jobs"},{"definition":"CHECK (execution_generation >= 0 AND cas_version >= 0)","kind":"c","name":"ck_artifact_verification_jobs_versions","table_name":"artifact_verification_jobs"},{"definition":"FOREIGN KEY (originating_put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_jobs_originating_put_attempt_i_3260","table_name":"artifact_verification_jobs"},{"definition":"FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_jobs_replica_id_artifact_replicas","table_name":"artifact_verification_jobs"},{"definition":"FOREIGN KEY (parent_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_parent","table_name":"artifact_verification_jobs"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_verification_jobs","table_name":"artifact_verification_jobs"},{"definition":"UNIQUE (parent_verification_job_id)","kind":"u","name":"uq_artifact_verification_parent","table_name":"artifact_verification_jobs"},{"definition":"CHECK ((outcome::text = ANY (ARRAY['verified', 'integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))","kind":"c","name":"ck_artifact_verification_receipts_observed_facts","table_name":"artifact_verification_receipts"},{"definition":"CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_verification_receipts_observed_sha256","table_name":"artifact_verification_receipts"},{"definition":"CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)","kind":"c","name":"ck_artifact_verification_receipts_observed_size","table_name":"artifact_verification_receipts"},{"definition":"CHECK (outcome::text = ANY (ARRAY['verified', 'missing', 'integrity_mismatch', 'conflict']))","kind":"c","name":"ck_artifact_verification_receipts_outcome","table_name":"artifact_verification_receipts"},{"definition":"FOREIGN KEY (verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_receipts_verification_job_id_a_dabf","table_name":"artifact_verification_receipts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_verification_receipts","table_name":"artifact_verification_receipts"},{"definition":"UNIQUE (verification_job_id, execution_generation)","kind":"u","name":"uq_artifact_verification_fence","table_name":"artifact_verification_receipts"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND (entity_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'authorization_decision', 'authority_invalidation'])) AND entity_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND ((actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile'])) AND actor_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR actor_ref_kind::text = 'system_principal'::text AND actor_id::text = 'workstream:system:bootstrap'::text) AND (target_actor_ref IS NULL OR target_actor_ref_kind::text = 'actor_profile'::text AND target_actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (matched_grant_id IS NULL OR matched_grant_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (project_id IS NULL OR project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (resource_type IS NULL OR (resource_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'project', 'qualification_snapshot', 'project_role_grant', 'task', 'submission', 'review', 'contribution', 'compensation_award', 'compensation_delivery', 'operations', 'audit_event', 'project_create_operation', 'project_submission_artifact_policy_mutation', 'project_guide_compilation_attempt', 'project_guide_compilation_request']))) AND (resource_id IS NULL OR resource_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (target_ref_kind IS NULL OR (target_ref_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'project'])) AND target_ref_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR target_ref_kind::text = 'permission_registry'::text AND (target_ref_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND (invalidation_target_kind IS NULL OR (invalidation_target_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant'])) AND invalidation_target_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR invalidation_target_kind::text = 'permission_registry'::text AND (invalidation_target_ref::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND ((entity_type::text <> ALL (ARRAY['authorization_decision', 'authority_invalidation'])) OR entity_id::text = id::text) AND (resource_type::text <> 'project'::text OR resource_id IS NULL OR project_id IS NOT NULL AND resource_id::text = project_id::text))","kind":"c","name":"ck_audit_events_authority_privacy_bounds","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR reason IS NOT NULL AND (event_type::text = 'ActorProfileProvisioned'::text AND reason = 'automatic_first_access'::text OR event_type::text = 'ServiceActorProvisioned'::text AND reason = 'manual_service_provisioning'::text OR event_type::text = 'ActorIdentityLinked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkRevoked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkReactivated'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorProfileSuspended'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'ActorProfileReactivated'::text AND reason = 'administrative_correction'::text OR event_type::text = 'ActorProfileDeactivated'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'InitialAccessAdministratorBootstrapped'::text AND reason = 'initial_access_bootstrap'::text OR event_type::text = 'AdminRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'AdminRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'AdminRoleGrantIssueDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'LastAccessAdministratorOperationDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'ProjectRoleQualificationSnapshotCaptured'::text AND reason = 'qualification_evidence_captured'::text OR event_type::text = 'ProjectRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'ProjectRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'SensitiveAuthorizationDenied'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'AuthorityInvalidationRequested'::text AND reason = 'authority_state_changed'::text) AND (permission_id IS NULL OR (permission_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.execute', 'project.guide_compilation.request']))) AND (denial_code IS NULL OR (denial_code::text = ANY (ARRAY['required_scope_missing', 'unsupported_subject_kind', 'service_actor_not_provisioned', 'identity_link_revoked', 'actor_suspended', 'actor_deactivated', 'permission_not_granted', 'scope_not_authorized', 'self_grant_forbidden', 'self_role_revoke_forbidden', 'resource_guard_denied', 'actor_not_found', 'grant_not_found', 'resource_not_found', 'actor_already_suspended', 'actor_not_suspended', 'actor_deactivated_terminal', 'last_access_administrator', 'admin_role_grant_exists', 'project_role_grant_exists', 'identity_link_conflict', 'project_role_grant_already_revoked', 'project_role_grant_replay_state_changed', 'identity_link_already_revoked', 'identity_link_not_revoked', 'resource_project_mismatch', 'idempotency_mismatch', 'invalid_role_scope', 'invalid_project_role', 'qualification_snapshot_invalid']))))","kind":"c","name":"ck_audit_events_authority_registries","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR (event_type::text = ANY (ARRAY['ActorProfileProvisioned', 'ServiceActorProvisioned', 'ActorIdentityLinked', 'ActorIdentityLinkRevoked', 'ActorIdentityLinkReactivated', 'ActorProfileSuspended', 'ActorProfileReactivated', 'ActorProfileDeactivated', 'InitialAccessAdministratorBootstrapped', 'AdminRoleGrantIssued', 'AdminRoleGrantRevoked', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied', 'ProjectRoleQualificationSnapshotCaptured', 'ProjectRoleGrantIssued', 'ProjectRoleGrantReplaced', 'ProjectRoleGrantRevoked', 'SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested'])))","kind":"c","name":"ck_audit_events_authority_tokens","table_name":"audit_events"},{"definition":"CHECK (event_domain::text = 'legacy_lifecycle'::text AND action_id IS NULL OR event_domain::text = 'authority'::text AND (action_id IS NULL OR (event_type::text = ANY (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied'])) AND permission_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)) AND (permission_id IS NULL OR (permission_id::text <> ALL (ARRAY['operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'project.guide_compilation.request', 'project.guide_compilation.execute'])) OR action_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)))","kind":"c","name":"ck_audit_events_authorization_action_evidence","table_name":"audit_events"},{"definition":"CHECK (event_domain::text = 'legacy_lifecycle'::text AND event_version IS NULL AND occurred_at IS NULL AND actor_ref_kind IS NULL AND request_id IS NULL AND correlation_id IS NULL AND target_actor_ref_kind IS NULL AND target_actor_ref IS NULL AND matched_grant_id IS NULL AND permission_id IS NULL AND project_id IS NULL AND resource_type IS NULL AND resource_id IS NULL AND target_ref_kind IS NULL AND target_ref_id IS NULL AND denial_code IS NULL AND idempotency_reference IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND invalidation_target_ref IS NULL AND before_facts IS NULL AND after_facts IS NULL AND external_subject IS NOT NULL AND external_issuer IS NOT NULL OR event_domain::text = 'authority'::text AND event_version = 1 AND occurred_at IS NOT NULL AND (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal'])) AND request_id IS NOT NULL AND correlation_id IS NOT NULL AND from_status IS NULL AND to_status IS NULL AND reason IS NOT NULL AND external_subject IS NULL AND external_issuer IS NULL AND actor_roles::jsonb = '[]'::jsonb AND claim_snapshot::jsonb = '{}'::jsonb AND auth_source::text = 'local_authority'::text AND is_dev_auth = false AND event_payload::jsonb = '{}'::jsonb)","kind":"c","name":"ck_audit_events_domain_shape","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR (before_facts IS NULL OR octet_length(before_facts::text) <= 4096) AND (after_facts IS NULL OR octet_length(after_facts::text) <= 4096) AND COALESCE(authority_event_facts_are_safe(event_type::text, before_facts, after_facts, project_id::text), false))","kind":"c","name":"ck_audit_events_fact_bounds","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR (event_type::text <> ALL (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) OR (event_type::text = ANY (ARRAY['AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) AND denial_code IS NOT NULL OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND permission_id IS NOT NULL AND denial_code IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL OR event_type::text = 'SensitiveAuthorizationDenied'::text AND permission_id IS NOT NULL AND denial_code IS NOT NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND idempotency_reference IS NULL OR event_type::text = 'AuthorityInvalidationRequested'::text AND invalidation_cause_event_id IS NOT NULL AND invalidation_target_kind IS NOT NULL AND denial_code IS NULL)","kind":"c","name":"ck_audit_events_foundation_shapes","table_name":"audit_events"},{"definition":"CHECK ((target_actor_ref_kind IS NULL) = (target_actor_ref IS NULL) AND (resource_type IS NOT NULL OR resource_id IS NULL) AND (target_ref_kind IS NULL) = (target_ref_id IS NULL) AND (invalidation_target_kind IS NULL) = (invalidation_target_ref IS NULL) AND (invalidation_cause_event_id IS NULL OR invalidation_cause_event_id::text <> id::text))","kind":"c","name":"ck_audit_events_reference_pairs","table_name":"audit_events"},{"definition":"FOREIGN KEY (idempotency_reference, actor_ref_kind, actor_id) REFERENCES authority_idempotency_records(id, actor_ref_kind, actor_ref) NOT VALID","kind":"f","name":"fk_audit_events_authority_idempotency","table_name":"audit_events"},{"definition":"FOREIGN KEY (invalidation_cause_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_audit_events_invalidation_cause","table_name":"audit_events"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_audit_events","table_name":"audit_events"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"authority_control_bootstrap_invariant","table_name":"authority_control"},{"definition":"CHECK (bootstrap_completed = false AND bootstrap_grant_id IS NULL AND version = 0 OR bootstrap_completed = true AND bootstrap_grant_id IS NOT NULL AND version = 1)","kind":"c","name":"ck_authority_control_bootstrap_state","table_name":"authority_control"},{"definition":"CHECK (id = 1)","kind":"c","name":"ck_authority_control_singleton","table_name":"authority_control"},{"definition":"FOREIGN KEY (bootstrap_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_authority_control_bootstrap_grant_id_admin_role_grants","table_name":"authority_control"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_authority_control","table_name":"authority_control"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"authority_idempotency_pending_guard","table_name":"authority_idempotency_records"},{"definition":"CHECK (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal']))","kind":"c","name":"ck_authority_idempotency_records_actor_kind","table_name":"authority_idempotency_records"},{"definition":"CHECK (actor_ref_kind::text = 'system_principal'::text AND actor_ref::text = 'workstream:system:bootstrap'::text OR actor_ref_kind::text <> 'system_principal'::text AND actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_authority_idempotency_records_actor_reference","table_name":"authority_idempotency_records"},{"definition":"CHECK (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'admin_role_grant.revoke', 'project_role_grant.issue', 'project_role_grant.revoke', 'actor_profile.suspend', 'actor_profile.reactivate', 'actor_profile.deactivate', 'actor_identity_link.revoke', 'actor_identity_link.reactivate']))","kind":"c","name":"ck_authority_idempotency_records_operation","table_name":"authority_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_authority_idempotency_records_request_digest","table_name":"authority_idempotency_records"},{"definition":"CHECK (response_http_status IS NULL OR (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 201 OR (operation::text <> ALL (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 200)","kind":"c","name":"ck_authority_idempotency_records_response_status","table_name":"authority_idempotency_records"},{"definition":"CHECK (operation::text = 'service_actor.create'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'admin_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'admin_role_grant'::text) OR operation::text ~~ 'project_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'project_role_grant'::text) OR operation::text ~~ 'actor_profile.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'actor_identity_link.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_identity_link'::text))","kind":"c","name":"ck_authority_idempotency_records_response_type","table_name":"authority_idempotency_records"},{"definition":"CHECK (response_resource_version IS NULL OR response_resource_version > 0)","kind":"c","name":"ck_authority_idempotency_records_response_version","table_name":"authority_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND response_resource_type IS NULL AND response_resource_id IS NULL AND response_resource_version IS NULL AND response_http_status IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_resource_type IS NOT NULL AND response_resource_id IS NOT NULL AND response_http_status IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_authority_idempotency_records_state_shape","table_name":"authority_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_authority_idempotency_records_status","table_name":"authority_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_authority_idempotency_records","table_name":"authority_idempotency_records"},{"definition":"UNIQUE (id, actor_ref_kind, actor_ref)","kind":"u","name":"uq_authority_idempotency_records_actor_reference","table_name":"authority_idempotency_records"},{"definition":"UNIQUE (actor_ref_kind, actor_ref, operation, idempotency_key)","kind":"u","name":"uq_authority_idempotency_records_replay_namespace","table_name":"authority_idempotency_records"},{"definition":"CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)","kind":"c","name":"ck_checker_policies_approval_provenance","table_name":"checker_policies"},{"definition":"CHECK (lifecycle_status::text <> 'superseded'::text OR superseded_at IS NOT NULL AND (superseded_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND superseded_by_actor IS NOT NULL AND (supersession_kind::text = ANY (ARRAY['correction_requested', 'upstream_policy_changed'])) AND supersession_reason IS NOT NULL AND length(btrim(supersession_reason)) > 0)","kind":"c","name":"ck_checker_policies_correction_provenance","table_name":"checker_policies"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['compiled', 'approved', 'superseded']))","kind":"c","name":"ck_checker_policies_lifecycle_status","table_name":"checker_policies"},{"definition":"CHECK (policy_hash IS NULL OR policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_checker_policies_policy_hash_shape","table_name":"checker_policies"},{"definition":"FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_checker_policies_effective_policy_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_checker_policies_guide_id_project_guides","table_name":"checker_policies"},{"definition":"FOREIGN KEY (pre_submit_checker_policy_id, pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)","kind":"f","name":"fk_checker_policies_pre_submit_checker_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_checker_policies_project_guide","table_name":"checker_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_checker_policies_project_id_projects","table_name":"checker_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_checker_policies_source_snapshot_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES checker_policies(id)","kind":"f","name":"fk_checker_policies_supersedes_policy_id","table_name":"checker_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_checker_policies","table_name":"checker_policies"},{"definition":"UNIQUE (id, guide_version, policy_hash)","kind":"u","name":"uq_checker_policies_id_version_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_checker_results_checker_run_id_checker_runs","table_name":"checker_results"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_checker_results_submission_id_submissions","table_name":"checker_results"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_checker_results_task_id_workstream_tasks","table_name":"checker_results"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_checker_results","table_name":"checker_results"},{"definition":"CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)","kind":"c","name":"ck_checker_runs_post_submit_policy_lock_complete","table_name":"checker_runs"},{"definition":"FOREIGN KEY (audit_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_checker_runs_audit_event_id_audit_events","table_name":"checker_runs"},{"definition":"FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)","kind":"f","name":"fk_checker_runs_locked_post_submit_policy_hash","table_name":"checker_runs"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_checker_runs_submission_id_submissions","table_name":"checker_runs"},{"definition":"FOREIGN KEY (submission_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES submissions(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"f","name":"fk_checker_runs_submission_locked_post_submit_policy_hash","table_name":"checker_runs"},{"definition":"FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_checker_runs_submission_version","table_name":"checker_runs"},{"definition":"FOREIGN KEY (supersedes_checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_checker_runs_supersedes_checker_run_id_checker_runs","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_checker_runs_task_id_workstream_tasks","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)","kind":"f","name":"fk_checker_runs_task_locked_guide","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)","kind":"f","name":"fk_checker_runs_task_locked_payment_policy","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","kind":"f","name":"fk_checker_runs_task_locked_review_policy","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","kind":"f","name":"fk_checker_runs_task_locked_revision_policy","table_name":"checker_runs"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_checker_runs","table_name":"checker_runs"},{"definition":"UNIQUE (submission_id, attempt_number)","kind":"u","name":"uq_checker_runs_submission_attempt","table_name":"checker_runs"},{"definition":"CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))","kind":"c","name":"ck_contribution_award_definitions_contribution_type","table_name":"contribution_award_definitions"},{"definition":"CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))","kind":"c","name":"ck_contribution_award_definitions_instrument_type","table_name":"contribution_award_definitions"},{"definition":"CHECK (instrument_type::text <> 'project_points'::text OR scale(quantity) = 0)","kind":"c","name":"ck_contribution_award_definitions_project_points_whole","table_name":"contribution_award_definitions"},{"definition":"CHECK (quantity > 0::numeric AND quantity < '100000000000000000000'::numeric AND scale(quantity) >= 0 AND scale(quantity) <= 18)","kind":"c","name":"ck_contribution_award_definitions_quantity_exact_bounds","table_name":"contribution_award_definitions"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_award_definitions_graph_guard","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (adapter_binding_id, project_id, instrument_type) REFERENCES project_compensation_adapter_bindings(id, project_id, instrument_type)","kind":"f","name":"fk_contribution_award_definition_binding","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_award_definition_project","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (contribution_rule_id, contribution_policy_version_id, project_id, contribution_type) REFERENCES contribution_rules(id, contribution_policy_version_id, project_id, contribution_type)","kind":"f","name":"fk_contribution_award_definition_rule","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (project_id, instrument_type, unit_code) REFERENCES project_compensation_units(project_id, instrument_type, unit_code)","kind":"f","name":"fk_contribution_award_definition_unit","table_name":"contribution_award_definitions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_award_definitions","table_name":"contribution_award_definitions"},{"definition":"UNIQUE (contribution_rule_id, instrument_type)","kind":"u","name":"uq_contribution_award_definition_instrument","table_name":"contribution_award_definitions"},{"definition":"CHECK (status::text = 'draft'::text AND current_published_version_id IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'active'::text AND current_published_version_id IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND current_published_version_id IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)","kind":"c","name":"ck_contribution_policies_lifecycle_shape","table_name":"contribution_policies"},{"definition":"CHECK (char_length(btrim(name::text)) >= 1 AND char_length(btrim(name::text)) <= 200)","kind":"c","name":"ck_contribution_policies_name","table_name":"contribution_policies"},{"definition":"CHECK (retired_at IS NULL OR retired_at >= created_at)","kind":"c","name":"ck_contribution_policies_retirement_timestamp","table_name":"contribution_policies"},{"definition":"CHECK (status::text = ANY (ARRAY['draft', 'active', 'retired']))","kind":"c","name":"ck_contribution_policies_status","table_name":"contribution_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_policies_graph_guard","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_created_by","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (current_published_version_id, id, project_id) REFERENCES contribution_policy_versions(id, contribution_policy_id, project_id) DEFERRABLE INITIALLY DEFERRED","kind":"f","name":"fk_contribution_policy_current_version","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_policy_project","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_retired_by","table_name":"contribution_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_policies","table_name":"contribution_policies"},{"definition":"UNIQUE (id, project_id)","kind":"u","name":"uq_contribution_policy_ownership","table_name":"contribution_policies"},{"definition":"CHECK (status::text = 'draft'::text AND published_by IS NULL AND published_at IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'published'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)","kind":"c","name":"ck_contribution_policy_versions_lifecycle_shape","table_name":"contribution_policy_versions"},{"definition":"CHECK ((published_at IS NULL OR published_at >= created_at) AND (retired_at IS NULL OR retired_at >= published_at))","kind":"c","name":"ck_contribution_policy_versions_lifecycle_timestamps","table_name":"contribution_policy_versions"},{"definition":"CHECK (status::text = ANY (ARRAY['draft', 'published', 'retired']))","kind":"c","name":"ck_contribution_policy_versions_status","table_name":"contribution_policy_versions"},{"definition":"CHECK (version_number > 0)","kind":"c","name":"ck_contribution_policy_versions_version_number_positive","table_name":"contribution_policy_versions"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_policy_versions_graph_guard","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_version_created_by","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (contribution_policy_id, project_id) REFERENCES contribution_policies(id, project_id)","kind":"f","name":"fk_contribution_policy_version_policy","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_policy_version_project","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (published_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_version_published_by","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_version_retired_by","table_name":"contribution_policy_versions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_policy_versions","table_name":"contribution_policy_versions"},{"definition":"UNIQUE (contribution_policy_id, version_number)","kind":"u","name":"uq_contribution_policy_version_number","table_name":"contribution_policy_versions"},{"definition":"UNIQUE (id, contribution_policy_id, project_id)","kind":"u","name":"uq_contribution_policy_version_ownership","table_name":"contribution_policy_versions"},{"definition":"UNIQUE (id, project_id)","kind":"u","name":"uq_contribution_policy_version_project","table_name":"contribution_policy_versions"},{"definition":"CHECK (compensation_mode::text = ANY (ARRAY['unpaid', 'compensated']))","kind":"c","name":"ck_contribution_rules_compensation_mode","table_name":"contribution_rules"},{"definition":"CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))","kind":"c","name":"ck_contribution_rules_contribution_type","table_name":"contribution_rules"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_rules_graph_guard","table_name":"contribution_rules"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_rule_project","table_name":"contribution_rules"},{"definition":"FOREIGN KEY (contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)","kind":"f","name":"fk_contribution_rule_version","table_name":"contribution_rules"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_rules","table_name":"contribution_rules"},{"definition":"UNIQUE (id, contribution_policy_version_id, project_id, contribution_type)","kind":"u","name":"uq_contribution_rule_ownership","table_name":"contribution_rules"},{"definition":"UNIQUE (contribution_policy_version_id, contribution_type)","kind":"u","name":"uq_contribution_rule_type","table_name":"contribution_rules"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['approved', 'superseded']))","kind":"c","name":"ck_effective_project_submission_artifact_policies_ck_ef_7be7","table_name":"effective_project_submission_artifact_policies"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)","kind":"c","name":"ck_effective_project_submission_artifact_policies_ck_ef_bd4e","table_name":"effective_project_submission_artifact_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"effective_submission_policy_custody","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_effective_policy_creation_actor","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_effective_policy_creation_decision","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_effective_policy_creation_grant","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_effective_policy_creation_link","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_effective_policy_creation_project","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_effective_project_submission_artifact_policies_project_guide","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_effective_psap_guide","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_effective_psap_project","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_effective_psap_source_snapshot_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (submission_artifact_policy_id, submission_artifact_policy_hash) REFERENCES submission_artifact_policies(id, policy_hash)","kind":"f","name":"fk_effective_psap_submission_policy_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (supersedes_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)","kind":"f","name":"fk_effective_psap_supersedes","table_name":"effective_project_submission_artifact_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_effective_project_submission_artifact_policies","table_name":"effective_project_submission_artifact_policies"},{"definition":"UNIQUE (id, effective_policy_hash)","kind":"u","name":"uq_effective_project_submission_artifact_policies_id_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_evidence_items_submission_id_submissions","table_name":"evidence_items"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_evidence_items","table_name":"evidence_items"},{"definition":"CHECK (operation_generation > 0)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_6506","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL AND setup_run_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_9402","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create']))","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_action","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_b397","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_e32d","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_status","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_actor_profile_id__2ee3","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_identity_link_id__3ddf","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_project_id_projects","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_setup_run_id_proj_7dc3","table_name":"guide_mutation_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"guide_mutation_reservation_custody","table_name":"guide_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_mutation_idempotency_records","table_name":"guide_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_guide_mutation_operation_identity","table_name":"guide_mutation_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, action_id, idempotency_key)","kind":"u","name":"uq_guide_mutation_replay_namespace","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_guide_source_artifact_bindings_ck_guide_bindings_gen_b5fe","table_name":"guide_source_artifact_bindings"},{"definition":"CHECK (logical_role::text = 'guide_source_original'::text)","kind":"c","name":"ck_guide_source_artifact_bindings_ck_guide_bindings_role","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (source_item_id, source_snapshot_id) REFERENCES guide_source_snapshot_items(id, source_snapshot_id)","kind":"f","name":"fk_guide_bindings_exact_item","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (project_setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)","kind":"f","name":"fk_guide_bindings_exact_setup_generation","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (source_snapshot_id, project_id, guide_id) REFERENCES guide_source_snapshots(id, project_id, guide_id)","kind":"f","name":"fk_guide_bindings_exact_snapshot","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (verified_replica_id, content_id) REFERENCES artifact_replicas(id, content_id)","kind":"f","name":"fk_guide_bindings_verified_replica_content","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_guide_source_artifact_bindings_content_id_artifact_contents","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (supersedes_binding_id) REFERENCES guide_source_artifact_bindings(id) ON DELETE RESTRICT","kind":"f","name":"fk_guide_source_artifact_bindings_supersedes_binding_id_bfa2","table_name":"guide_source_artifact_bindings"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_artifact_bindings","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (id, content_id, verified_replica_id, setup_generation)","kind":"u","name":"uq_guide_bindings_exact_read","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (id, content_id, setup_generation)","kind":"u","name":"uq_guide_bindings_extraction_attempt_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (id, content_id, source_item_id, project_setup_run_id, setup_generation)","kind":"u","name":"uq_guide_bindings_extraction_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (source_item_id, setup_generation)","kind":"u","name":"uq_guide_bindings_item_generation","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (supersedes_binding_id)","kind":"u","name":"uq_guide_bindings_supersedes","table_name":"guide_source_artifact_bindings"},{"definition":"CHECK (code::text = ANY (ARRAY['missing', 'changed', 'truncated', 'unavailable', 'stale', 'conflict']))","kind":"c","name":"ck_guide_source_artifact_incidents_ck_guide_incidents_code","table_name":"guide_source_artifact_incidents"},{"definition":"CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_artifact_incidents_ck_guide_source_arti_621b","table_name":"guide_source_artifact_incidents"},{"definition":"CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)","kind":"c","name":"ck_guide_source_artifact_incidents_ck_guide_source_arti_92fa","table_name":"guide_source_artifact_incidents"},{"definition":"FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)","kind":"f","name":"fk_guide_incidents_exact_binding","table_name":"guide_source_artifact_incidents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_artifact_incidents","table_name":"guide_source_artifact_incidents"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_guide_source_artifact_ingests_ck_guide_source_artifa_2958","table_name":"guide_source_artifact_ingests"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_artifact_ingests_ck_guide_source_artifa_64cb","table_name":"guide_source_artifact_ingests"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_source_artifact_ingests_actor_profile_id_actor_22c1","table_name":"guide_source_artifact_ingests"},{"definition":"FOREIGN KEY (source_item_id) REFERENCES guide_source_snapshot_items(id)","kind":"f","name":"fk_guide_source_artifact_ingests_source_item_id_guide_s_7ba9","table_name":"guide_source_artifact_ingests"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_artifact_ingests","table_name":"guide_source_artifact_ingests"},{"definition":"UNIQUE (source_item_id)","kind":"u","name":"uq_guide_source_artifact_ingests_source_item_id","table_name":"guide_source_artifact_ingests"},{"definition":"CHECK (output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_1b91","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (octet_length(canonical_output) <= 4194304)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_54b5","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (source_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_988f","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (status::text = 'extracted'::text)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_a759","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (source_byte_count >= 0)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_fb79","table_name":"guide_source_extracted_contents"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_guide_source_extracted_contents_content_id_artifact_contents","table_name":"guide_source_extracted_contents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_extracted_contents","table_name":"guide_source_extracted_contents"},{"definition":"UNIQUE (id, content_id)","kind":"u","name":"uq_guide_extracted_contents_exact_usage","table_name":"guide_source_extracted_contents"},{"definition":"UNIQUE (content_id, detected_format, extractor_name, extractor_version, policy_version)","kind":"u","name":"uq_guide_extracted_contents_identity","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (attempt_number > 0)","kind":"c","name":"ck_guide_source_extraction_attempts_ck_guide_extraction_3927","table_name":"guide_source_extraction_attempts"},{"definition":"CHECK ((status::text = 'extracted'::text) = (error_code IS NULL))","kind":"c","name":"ck_guide_source_extraction_attempts_ck_guide_extraction_940d","table_name":"guide_source_extraction_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['extracted', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded', 'parser_failure', 'cancelled', 'artifact_incident']))","kind":"c","name":"ck_guide_source_extraction_attempts_ck_guide_extraction_ff6d","table_name":"guide_source_extraction_attempts"},{"definition":"FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_attempts_exact_binding","table_name":"guide_source_extraction_attempts"},{"definition":"FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_attempts_exact_classification","table_name":"guide_source_extraction_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"UNIQUE (binding_id, policy_version, attempt_number)","kind":"u","name":"uq_guide_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"UNIQUE (id, binding_id, content_id, setup_generation, status)","kind":"u","name":"uq_guide_extraction_attempts_exact_usage","table_name":"guide_source_extraction_attempts"},{"definition":"CHECK (claimed_slots >= 1 AND claimed_slots <= 2)","kind":"c","name":"ck_guide_source_extraction_retry_budgets_ck_guide_extra_99c3","table_name":"guide_source_extraction_retry_budgets"},{"definition":"FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_retry_budgets_exact_binding","table_name":"guide_source_extraction_retry_budgets"},{"definition":"FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_retry_budgets_exact_classification","table_name":"guide_source_extraction_retry_budgets"},{"definition":"PRIMARY KEY (binding_id)","kind":"p","name":"pk_guide_source_extraction_retry_budgets","table_name":"guide_source_extraction_retry_budgets"},{"definition":"CHECK (attempt_status::text = 'extracted'::text)","kind":"c","name":"ck_guide_source_extraction_usages_ck_guide_extraction_u_a2fd","table_name":"guide_source_extraction_usages"},{"definition":"FOREIGN KEY (extraction_attempt_id, binding_id, content_id, setup_generation, attempt_status) REFERENCES guide_source_extraction_attempts(id, binding_id, content_id, setup_generation, status)","kind":"f","name":"fk_guide_extraction_usages_exact_attempt","table_name":"guide_source_extraction_usages"},{"definition":"FOREIGN KEY (binding_id, content_id, source_item_id, project_setup_run_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, source_item_id, project_setup_run_id, setup_generation)","kind":"f","name":"fk_guide_extraction_usages_exact_binding","table_name":"guide_source_extraction_usages"},{"definition":"FOREIGN KEY (extracted_content_id, content_id) REFERENCES guide_source_extracted_contents(id, content_id)","kind":"f","name":"fk_guide_extraction_usages_exact_content","table_name":"guide_source_extraction_usages"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"UNIQUE (binding_id, extracted_content_id)","kind":"u","name":"uq_guide_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"UNIQUE (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)","kind":"u","name":"uq_guide_extraction_usages_exact_provenance","table_name":"guide_source_extraction_usages"},{"definition":"CHECK (status::text = ANY (ARRAY['classified', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded']))","kind":"c","name":"ck_guide_source_format_classifications_ck_guide_classif_8737","table_name":"guide_source_format_classifications"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_format_classifications_ck_guide_source__0dd2","table_name":"guide_source_format_classifications"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_guide_source_format_classifications_ck_guide_source__7235","table_name":"guide_source_format_classifications"},{"definition":"FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)","kind":"f","name":"fk_guide_classifications_exact_binding","table_name":"guide_source_format_classifications"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_format_classifications","table_name":"guide_source_format_classifications"},{"definition":"UNIQUE (binding_id)","kind":"u","name":"uq_guide_classifications_binding","table_name":"guide_source_format_classifications"},{"definition":"UNIQUE (id, binding_id, content_id, setup_generation)","kind":"u","name":"uq_guide_classifications_extraction_lineage","table_name":"guide_source_format_classifications"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_gssi_source_snapshot","table_name":"guide_source_snapshot_items"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"guide_source_snapshot_items_custody","table_name":"guide_source_snapshot_items"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_snapshot_items","table_name":"guide_source_snapshot_items"},{"definition":"UNIQUE (id, source_snapshot_id)","kind":"u","name":"uq_guide_source_snapshot_items_exact_lineage","table_name":"guide_source_snapshot_items"},{"definition":"UNIQUE (source_snapshot_id, item_order)","kind":"u","name":"uq_guide_source_snapshot_items_snapshot_order","table_name":"guide_source_snapshot_items"},{"definition":"CHECK (creation_generation IS NULL AND created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR creation_generation > 0 AND created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (creation_scope_type::text = 'system'::text AND creation_scope_project_id IS NULL OR creation_scope_type::text = 'project'::text AND creation_scope_project_id::text = project_id::text) AND creation_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_guide_source_snapshots_source_snapshot_creation_auth_2f3e","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_source_snapshots_created_actor","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_guide_source_snapshots_created_admin_grant","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_guide_source_snapshots_created_decision","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_guide_source_snapshots_created_identity_link","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_guide_source_snapshots_guide_id_project_guides","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_guide_source_snapshots_project_guide","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_source_snapshots_project_id_projects","table_name":"guide_source_snapshots"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_snapshots","table_name":"guide_source_snapshots"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"source_snapshot_product_custody","table_name":"guide_source_snapshots"},{"definition":"UNIQUE (id, project_id, guide_id)","kind":"u","name":"uq_guide_source_snapshots_exact_lineage","table_name":"guide_source_snapshots"},{"definition":"UNIQUE (id, bundle_hash)","kind":"u","name":"uq_guide_source_snapshots_id_hash","table_name":"guide_source_snapshots"},{"definition":"UNIQUE (project_id, guide_version, bundle_hash)","kind":"u","name":"uq_guide_source_snapshots_project_version_hash","table_name":"guide_source_snapshots"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_1033","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_177a","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run', 'project.guide_sufficiency.warnings.acknowledge']))","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_6651","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_87dd","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND (action_id::text = 'project.guide_sufficiency.run'::text AND (setup_run_id IS NOT NULL OR report_id IS NOT NULL) OR action_id::text <> 'project.guide_sufficiency.run'::text AND report_id IS NOT NULL))","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_e7f6","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_actor_16d8","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_guide_1d2b","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_ident_2378","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_proje_7f82","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_repor_48c3","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_setup_7059","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_sourc_9985","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_sufficiency_mutation_idempotency_records","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_sufficiency_mutation_operation_identity","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, idempotency_key)","kind":"u","name":"uq_sufficiency_mutation_replay_namespace","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_guide_sufficiency_report_source_usages_ck_sufficienc_2983","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CHECK (canonical_output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_sufficiency_report_source_usages_ck_sufficienc_8148","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CHECK (item_order >= 0)","kind":"c","name":"ck_guide_sufficiency_report_source_usages_ck_sufficienc_eb12","table_name":"guide_sufficiency_report_source_usages"},{"definition":"FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id) ON DELETE CASCADE","kind":"f","name":"fk_guide_sufficiency_report_source_usages_report_id_gui_1d57","table_name":"guide_sufficiency_report_source_usages"},{"definition":"FOREIGN KEY (extraction_usage_id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation) REFERENCES guide_source_extraction_usages(id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)","kind":"f","name":"fk_sufficiency_report_source_usage_exact_extraction","table_name":"guide_sufficiency_report_source_usages"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_sufficiency_report_source_usages","table_name":"guide_sufficiency_report_source_usages"},{"definition":"UNIQUE (report_id, extraction_usage_id)","kind":"u","name":"uq_sufficiency_report_extraction_usage","table_name":"guide_sufficiency_report_source_usages"},{"definition":"UNIQUE (report_id, item_order)","kind":"u","name":"uq_sufficiency_report_item_order","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CHECK (warnings_acknowledged_by_actor_profile_id IS NULL AND warnings_acknowledged_via_identity_link_id IS NULL AND warnings_acknowledged_by_admin_role_grant_id IS NULL AND warning_acknowledgement_scope_type IS NULL AND warning_acknowledgement_scope_project_id IS NULL AND warning_acknowledgement_action_id IS NULL AND warning_acknowledgement_decision_event_id IS NULL OR warnings_acknowledged_by_actor_profile_id IS NOT NULL AND warnings_acknowledged_via_identity_link_id IS NOT NULL AND warnings_acknowledged_by_admin_role_grant_id IS NOT NULL AND (warning_acknowledgement_scope_type::text = ANY (ARRAY['system', 'project'])) AND warning_acknowledgement_scope_project_id IS NOT NULL AND warning_acknowledgement_action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND warning_acknowledgement_decision_event_id IS NOT NULL)","kind":"c","name":"ck_guide_sufficiency_ack_authority_shape","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run'])) AND authorization_decision_event_id IS NOT NULL AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.guide_sufficiency.run'::text AND project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL))","kind":"c","name":"ck_guide_sufficiency_creation_authority_shape","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (agent_material_byte_count IS NULL OR agent_material_byte_count >= 0)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_31bb","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (setup_generation IS NULL OR setup_generation > 0)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_3e43","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (project_setup_run_id IS NULL AND setup_generation IS NULL AND agent_material_sha256 IS NULL AND agent_material_byte_count IS NULL OR project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_4640","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (status::text = ANY (ARRAY['passed', 'blocked', 'passed_with_warnings']))","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_841c","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (agent_material_sha256 IS NULL OR agent_material_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_b3ec","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_guide_sufficiency_reports_guide_id_project_guides","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_guide_sufficiency_reports_project_guide","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_sufficiency_reports_project_id_projects","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_guide_sufficiency_reports_source_snapshot_hash","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warnings_acknowledged_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_suff_ack_actor","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warning_acknowledgement_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_suff_ack_decision","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warnings_acknowledged_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_suff_ack_grant","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warnings_acknowledged_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_suff_ack_link","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warning_acknowledgement_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_suff_ack_project","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_suff_create_actor","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_suff_create_decision","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_suff_create_grant","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_suff_create_link","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_suff_create_project","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (project_setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_sufficiency_reports_setup_run","table_name":"guide_sufficiency_reports"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_sufficiency_reports","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (code::text ~ '^[A-Z]{3}$'::text)","kind":"c","name":"ck_iso_4217_currency_codes_code","table_name":"iso_4217_currency_codes"},{"definition":"PRIMARY KEY (code)","kind":"p","name":"pk_iso_4217_currency_codes","table_name":"iso_4217_currency_codes"},{"definition":"PRIMARY KEY (actor_id)","kind":"p","name":"pk_legacy_actor_identities","table_name":"legacy_actor_identities"},{"definition":"UNIQUE (external_issuer, external_subject)","kind":"u","name":"uq_legacy_actor_identities_external_identity","table_name":"legacy_actor_identities"},{"definition":"CHECK (profile_type::text = ANY (ARRAY['worker', 'reviewer', 'admin', 'project_manager', 'project_owner']))","kind":"c","name":"ck_legacy_workflow_eligibility_profile_type","table_name":"legacy_workflow_eligibility"},{"definition":"CHECK (status::text = ANY (ARRAY['observed', 'active', 'disabled']))","kind":"c","name":"ck_legacy_workflow_eligibility_status","table_name":"legacy_workflow_eligibility"},{"definition":"FOREIGN KEY (actor_id) REFERENCES legacy_actor_identities(actor_id)","kind":"f","name":"fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities","table_name":"legacy_workflow_eligibility"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_legacy_workflow_eligibility","table_name":"legacy_workflow_eligibility"},{"definition":"UNIQUE (actor_id, profile_type, scope_type, scope_id)","kind":"u","name":"uq_legacy_workflow_eligibility_actor_type_scope","table_name":"legacy_workflow_eligibility"},{"definition":"CHECK (aggregate_type::text ~ '^[a-z][a-z0-9_]{0,63}$'::text)","kind":"c","name":"ck_outbox_events_aggregate_type","table_name":"outbox_events"},{"definition":"CHECK (claim_owner IS NULL OR claim_owner::text ~ '^[A-Za-z0-9._:-]{1,120}$'::text)","kind":"c","name":"ck_outbox_events_claim_owner","table_name":"outbox_events"},{"definition":"CHECK (correlation_id::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)","kind":"c","name":"ck_outbox_events_correlation_id","table_name":"outbox_events"},{"definition":"CHECK (attempt_count >= 0 AND claim_generation >= 0 AND attempt_count = claim_generation)","kind":"c","name":"ck_outbox_events_delivery_counters","table_name":"outbox_events"},{"definition":"CHECK (delivery_state::text = ANY (ARRAY['pending', 'claimed', 'retryable', 'acknowledged', 'dead_letter', 'cancelled']))","kind":"c","name":"ck_outbox_events_delivery_state","table_name":"outbox_events"},{"definition":"CHECK (delivery_state::text = 'pending'::text AND attempt_count = 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NULL AND last_error_code IS NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'claimed'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NOT NULL AND claimed_at IS NOT NULL AND claim_expires_at IS NOT NULL AND last_attempt_at = claimed_at AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'retryable'::text AND attempt_count > 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'acknowledged'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'dead_letter'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'cancelled'::text AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND finalized_at IS NOT NULL AND (attempt_count = 0 AND last_attempt_at IS NULL AND last_error_code IS NULL OR attempt_count > 0 AND last_attempt_at IS NOT NULL))","kind":"c","name":"ck_outbox_events_delivery_state_shape","table_name":"outbox_events"},{"definition":"CHECK ((next_attempt_at IS NULL OR next_attempt_at >= occurred_at) AND (claimed_at IS NULL OR claimed_at >= occurred_at) AND (last_attempt_at IS NULL OR last_attempt_at >= occurred_at) AND (claim_expires_at IS NULL OR claim_expires_at > claimed_at) AND (finalized_at IS NULL OR finalized_at >= occurred_at) AND (finalized_at IS NULL OR last_attempt_at IS NULL OR finalized_at >= last_attempt_at) AND (archived_at IS NULL OR archived_at >= finalized_at))","kind":"c","name":"ck_outbox_events_delivery_timestamps","table_name":"outbox_events"},{"definition":"CHECK (last_error_code IS NULL OR last_error_code::text ~ '^[A-Z][A-Z0-9_]{0,79}$'::text)","kind":"c","name":"ck_outbox_events_error_code","table_name":"outbox_events"},{"definition":"CHECK (event_type::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'::text)","kind":"c","name":"ck_outbox_events_event_type","table_name":"outbox_events"},{"definition":"CHECK (event_version >= 1 AND event_version <= 32767)","kind":"c","name":"ck_outbox_events_event_version","table_name":"outbox_events"},{"definition":"CHECK (idempotency_key::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)","kind":"c","name":"ck_outbox_events_idempotency_key","table_name":"outbox_events"},{"definition":"CHECK (payload_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_outbox_events_payload_digest","table_name":"outbox_events"},{"definition":"CHECK (jsonb_typeof(payload) = 'object'::text AND octet_length(payload::text) <= 262144)","kind":"c","name":"ck_outbox_events_payload_shape","table_name":"outbox_events"},{"definition":"CHECK (producer::text = 'workstream'::text)","kind":"c","name":"ck_outbox_events_producer","table_name":"outbox_events"},{"definition":"CHECK (project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_outbox_events_project_id","table_name":"outbox_events"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_outbox_events_project_id_projects","table_name":"outbox_events"},{"definition":"PRIMARY KEY (event_id)","kind":"p","name":"pk_outbox_events","table_name":"outbox_events"},{"definition":"UNIQUE (idempotency_key)","kind":"u","name":"uq_outbox_events_idempotency_key","table_name":"outbox_events"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_payment_policies_project_guide","table_name":"payment_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_payment_policies_project_id_projects","table_name":"payment_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_payment_policies","table_name":"payment_policies"},{"definition":"UNIQUE (project_id, guide_version)","kind":"u","name":"uq_payment_policies_project_version","table_name":"payment_policies"},{"definition":"CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_26aa","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_595e","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.review_policy.update', 'project.revision_policy.update']))","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_7f7f","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (policy_generation > 0)","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_8b22","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_dc05","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_actor_profile_id_41c2","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_guide_id_project_guides","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_identity_link_id_b806","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_project_id_projects","table_name":"policy_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_policy_mutation_idempotency_records","table_name":"policy_mutation_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"policy_mutation_replay_custody","table_name":"policy_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_policy_mutation_operation_identity","table_name":"policy_mutation_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, action_id, idempotency_key)","kind":"u","name":"uq_policy_mutation_replay_namespace","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (lifecycle_status::text <> 'compiled'::text OR compiler_version IS NOT NULL AND compiled_bundle IS NOT NULL AND compiled_bundle_hash IS NOT NULL AND compiled_bundle_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_checker_policies_ck_pre_submit_checker_po_5010","table_name":"pre_submit_checker_policies"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['pending_compilation', 'compiled', 'superseded']))","kind":"c","name":"ck_pre_submit_checker_policies_ck_pre_submit_checker_po_a935","table_name":"pre_submit_checker_policies"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)","kind":"c","name":"ck_pre_submit_checker_policies_ck_pre_submit_policy_aut_90fc","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_pre_submit_checker_policies_effective_hash","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_pre_submit_checker_policies_guide","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_pre_submit_checker_policies_project","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_pre_submit_checker_policies_project_guide","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_pre_submit_checker_policies_source_snapshot_hash","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (supersedes_pre_submit_checker_policy_id) REFERENCES pre_submit_checker_policies(id)","kind":"f","name":"fk_pre_submit_checker_policies_supersedes","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_pre_submit_policy_creation_actor","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_pre_submit_policy_creation_decision","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_pre_submit_policy_creation_grant","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_pre_submit_policy_creation_link","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_pre_submit_policy_creation_project","table_name":"pre_submit_checker_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_pre_submit_checker_policies","table_name":"pre_submit_checker_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"pre_submit_policy_custody","table_name":"pre_submit_checker_policies"},{"definition":"UNIQUE (id, compiled_bundle_hash)","kind":"u","name":"uq_pre_submit_checker_policies_id_compiled_bundle_hash","table_name":"pre_submit_checker_policies"},{"definition":"CHECK (classification::text = ANY (ARRAY['mandatory_security', 'mandatory_integrity', 'mandatory_accountability', 'advisory']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_cla_b0de","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (classification::text = 'advisory'::text AND severity::text = 'warning'::text OR classification::text <> 'advisory'::text AND severity::text = 'blocking'::text)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_cla_f04e","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (result_order >= 0)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_order","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (phase::text = ANY (ARRAY['custody', 'identity', 'materialization', 'default_policy', 'project_policy']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_phase","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_plan_sha256","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (locked_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_pol_cef4","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (phase::text = 'project_policy'::text AND rule_instance_id IS NOT NULL AND rule_instance_id::text ~ '^sha256:[0-9a-f]{64}$'::text OR phase::text <> 'project_policy'::text AND rule_instance_id IS NULL)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_rul_321f","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (severity::text = ANY (ARRAY['blocking', 'warning']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_severity","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (status::text = ANY (ARRAY['passed', 'warning', 'advisory_disabled', 'dependency_not_run', 'failed']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_status","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (status::text = 'failed'::text AND failure_code IS NOT NULL OR status::text <> 'failed'::text AND failure_code IS NULL)","kind":"c","name":"ck_pre_submit_evidence_results_result_failure_shape","table_name":"pre_submit_evidence_results"},{"definition":"FOREIGN KEY (evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_results_evidence_set_id_pre_subm_096e","table_name":"pre_submit_evidence_results"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_pre_submit_evidence_results","table_name":"pre_submit_evidence_results"},{"definition":"UNIQUE (evidence_set_id, definition_id)","kind":"u","name":"uq_pre_submit_result_definition","table_name":"pre_submit_evidence_results"},{"definition":"UNIQUE (evidence_set_id, result_order)","kind":"u","name":"uq_pre_submit_result_order","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arch_8e95","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (archive_byte_count >= 0)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_archive_size","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_artifact_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arti_16f8","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (catalogue_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_cata_ffcb","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_checker_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_chec_765d","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_guide_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_guide_sha256","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_mani_7268","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_oper_f617","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_plan_sha256","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (predecessor_submission_id IS NULL AND predecessor_submission_version IS NULL OR predecessor_submission_id IS NOT NULL AND predecessor_submission_version IS NOT NULL)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_pred_bd87","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (result_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_resu_0b46","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (result_count > 0)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_result_count","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (source_snapshot_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_sour_982b","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (terminal_status::text = 'passed'::text AND eligible OR terminal_status::text = 'blocked'::text AND NOT eligible)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stat_1ae6","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (storage_scheme::text = ANY (ARRAY['local', 's3']))","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stor_022c","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (terminal_status::text = ANY (ARRAY['passed', 'blocked']))","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_term_a512","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_policy_context_sha256","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (assignment_id, task_id, actor_profile_id) REFERENCES task_assignments(id, task_id, contributor_id)","kind":"f","name":"fk_pre_submit_evidence_assignment","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (guide_id, project_id, guide_version) REFERENCES project_guides(id, project_id, version)","kind":"f","name":"fk_pre_submit_evidence_guide_lineage","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (identity_link_id, actor_profile_id) REFERENCES actor_identity_links(id, actor_profile_id)","kind":"f","name":"fk_pre_submit_evidence_identity_actor","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (predecessor_submission_id, task_id, predecessor_submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_pre_submit_evidence_predecessor","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_actor_profile_id_actor_profiles","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_assignment_id_task_assignments","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_effective_policy_id_effecti_6a99","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_guide_id_project_guides","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_identity_link_id_actor_iden_5cef","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_pre_submit_policy_id_pre_su_c77f","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_predecessor_submission_id_s_6ec2","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_project_id_projects","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_source_snapshot_id_guide_so_1667","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_task_id_workstream_tasks","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, effective_policy_id, locked_artifact_policy_sha256) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","kind":"f","name":"fk_pre_submit_evidence_task_artifact_policy","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, pre_submit_policy_id, locked_checker_policy_sha256) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","kind":"f","name":"fk_pre_submit_evidence_task_checker_policy","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, guide_version) REFERENCES workstream_tasks(id, locked_guide_version)","kind":"f","name":"fk_pre_submit_evidence_task_guide","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, project_id) REFERENCES workstream_tasks(id, project_id)","kind":"f","name":"fk_pre_submit_evidence_task_project","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, source_snapshot_id, source_snapshot_sha256) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","kind":"f","name":"fk_pre_submit_evidence_task_source_snapshot","table_name":"pre_submit_evidence_sets"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_pre_submit_evidence_sets","table_name":"pre_submit_evidence_sets"},{"definition":"UNIQUE (operation_identity)","kind":"u","name":"uq_pre_submit_evidence_operation","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (binding_lifecycle_version > 0)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_1870","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_3372","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (route_key::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'::text)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_6958","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (status::text = 'active'::text AND binding_lifecycle_version = 1 AND suspended_by IS NULL AND suspended_at IS NULL AND retired_by IS NULL AND retired_at IS NULL)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_95ba","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK ((suspended_at IS NULL OR suspended_at >= created_at) AND (retired_at IS NULL OR retired_at >= created_at) AND (retired_at IS NULL OR suspended_at IS NULL OR retired_at >= suspended_at))","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_ade1","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'suspended', 'retired']))","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_da73","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (route_key::text !~~ '%..%'::text)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_f32d","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (adapter_actor_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_adapter_actor","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_created_by","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_compensation_binding_project","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_retired_by","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (suspended_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_suspended_by","table_name":"project_compensation_adapter_bindings"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_compensation_adapter_bindings","table_name":"project_compensation_adapter_bindings"},{"definition":"UNIQUE (id, project_id, instrument_type)","kind":"u","name":"uq_compensation_binding_ownership","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))","kind":"c","name":"ck_project_compensation_units_instrument_type","table_name":"project_compensation_units"},{"definition":"CHECK (status::text = 'active'::text AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND retired_by IS NOT NULL AND retired_at IS NOT NULL)","kind":"c","name":"ck_project_compensation_units_lifecycle_shape","table_name":"project_compensation_units"},{"definition":"CHECK (retired_at IS NULL OR retired_at >= created_at)","kind":"c","name":"ck_project_compensation_units_retirement_time","table_name":"project_compensation_units"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'retired']))","kind":"c","name":"ck_project_compensation_units_status","table_name":"project_compensation_units"},{"definition":"CHECK (instrument_type::text = 'money'::text AND iso_currency_code IS NOT NULL AND unit_code::text = iso_currency_code::text OR instrument_type::text = 'project_points'::text AND iso_currency_code IS NULL AND unit_code::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$'::text)","kind":"c","name":"ck_project_compensation_units_unit_identity","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_compensation_unit_created_by","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (iso_currency_code) REFERENCES iso_4217_currency_codes(code)","kind":"f","name":"fk_project_compensation_unit_iso_currency","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_compensation_unit_project","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_compensation_unit_retired_by","table_name":"project_compensation_units"},{"definition":"PRIMARY KEY (project_id, instrument_type, unit_code)","kind":"p","name":"pk_project_compensation_units","table_name":"project_compensation_units"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_0a41","table_name":"project_create_idempotency_records"},{"definition":"CHECK (operation_generation = 1)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_100d","table_name":"project_create_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND committed_at IS NULL OR status::text = 'committed'::text AND committed_at IS NOT NULL)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_3aa0","table_name":"project_create_idempotency_records"},{"definition":"CHECK (action_id::text = 'project.create'::text)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_action","table_name":"project_create_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_status","table_name":"project_create_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_create_idempotency_records_actor_profile_id__ebb1","table_name":"project_create_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_create_idempotency_records_identity_link_id__ddce","table_name":"project_create_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_create_idempotency_records","table_name":"project_create_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"project_create_reservation_custody","table_name":"project_create_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_project_create_operation_identity","table_name":"project_create_idempotency_records"},{"definition":"UNIQUE (project_id)","kind":"u","name":"uq_project_create_project_identity","table_name":"project_create_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, action_id, idempotency_key)","kind":"u","name":"uq_project_create_replay_namespace","table_name":"project_create_idempotency_records"},{"definition":"CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_00d8","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (component_hashes IS NULL OR json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_31c4","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (status::text = 'compilation_reserved'::text AND provider_uncertain_at IS NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_provider_uncertain'::text AND provider_uncertain_at IS NOT NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'provider_result_accepted'::text AND accepted_at IS NOT NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_persisted'::text AND accepted_at IS NOT NULL AND persisted_at IS NOT NULL AND terminal_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NOT NULL OR status::text = 'compilation_invalid_terminal'::text AND terminal_at IS NOT NULL AND accepted_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND persisted_compilation_id IS NULL AND (failure_code::text = ANY (ARRAY['schema_invalid', 'unsafe_text', 'hash_mismatch', 'context_mismatch'])))","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_444c","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_513e","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (canonical_result IS NULL OR octet_length(canonical_result::text) <= 4194304)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_6057","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (result_hash IS NULL OR result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_6609","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['compilation_reserved', 'compilation_provider_uncertain', 'provider_result_accepted', 'compilation_invalid_terminal', 'compilation_persisted']))","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_6c82","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (persisted_compilation_id, id) REFERENCES project_guide_compilations(id, attempt_id)","kind":"f","name":"fk_compilation_attempt_exact_persisted_compilation","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)","kind":"f","name":"fk_compilation_attempt_exact_setup","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_compilation_attempt_snapshot_hash","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_project_guide_compilation_attempts_guide_id_project_guides","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_guide_compilation_attempts_project_id_projects","table_name":"project_guide_compilation_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_guide_compilation_attempts","table_name":"project_guide_compilation_attempts"},{"definition":"UNIQUE (provider_idempotency_key)","kind":"u","name":"uq_compilation_attempt_provider_key","table_name":"project_guide_compilation_attempts"},{"definition":"UNIQUE (setup_run_id, setup_generation)","kind":"u","name":"uq_compilation_attempt_setup_generation","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (setup_generation > 0 AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_action_id::text = 'project.guide_compilation.execute'::text)","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_8a51","table_name":"project_guide_compilations"},{"definition":"CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_9cd9","table_name":"project_guide_compilations"},{"definition":"CHECK (authorization_resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_d554","table_name":"project_guide_compilations"},{"definition":"CHECK (octet_length(canonical_result::text) <= 4194304 AND json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_dafe","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (supersedes_compilation_id, project_id, guide_id) REFERENCES project_guide_compilations(id, project_id, guide_id)","kind":"f","name":"fk_project_guide_compilation_predecessor","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (attempt_id) REFERENCES project_guide_compilation_attempts(id)","kind":"f","name":"fk_project_guide_compilations_attempt_id_project_guide__0e94","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_project_guide_compilations_authorization_decision_ev_42ad","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_guide_compilations_created_by_actor_profile__953f","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_guide_compilations_created_via_identity_link_b250","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_project_guide_compilations_guide_id_project_guides","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_guide_compilations_project_id_projects","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_project_guide_compilations_setup_run_id_project_setup_runs","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_project_guide_compilations_source_snapshot_id_guide__033a","table_name":"project_guide_compilations"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_guide_compilations","table_name":"project_guide_compilations"},{"definition":"UNIQUE (attempt_id)","kind":"u","name":"uq_project_guide_compilation_attempt","table_name":"project_guide_compilations"},{"definition":"UNIQUE (id, attempt_id)","kind":"u","name":"uq_project_guide_compilation_id_attempt","table_name":"project_guide_compilations"},{"definition":"UNIQUE (supersedes_compilation_id)","kind":"u","name":"uq_project_guide_compilation_predecessor","table_name":"project_guide_compilations"},{"definition":"UNIQUE (id, project_id, guide_id)","kind":"u","name":"uq_project_guide_compilation_scope","table_name":"project_guide_compilations"},{"definition":"CHECK ((status::text <> ALL (ARRAY['active', 'superseded'])) OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL AND selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL)","kind":"c","name":"ck_project_guides_active_policy_selection_required","table_name":"project_guides"},{"definition":"CHECK (mutation_generation IS NULL AND last_mutated_by_actor_profile_id IS NULL AND last_mutated_via_identity_link_id IS NULL AND last_mutated_by_admin_role_grant_id IS NULL AND last_mutation_scope_type IS NULL AND last_mutation_scope_project_id IS NULL AND last_mutation_action_id IS NULL AND last_authorization_decision_event_id IS NULL OR mutation_generation > 0 AND last_mutated_by_actor_profile_id IS NOT NULL AND last_mutated_via_identity_link_id IS NOT NULL AND last_mutated_by_admin_role_grant_id IS NOT NULL AND (last_mutation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (last_mutation_scope_type::text = 'system'::text AND last_mutation_scope_project_id IS NULL OR last_mutation_scope_type::text = 'project'::text AND last_mutation_scope_project_id::text = project_id::text) AND (last_mutation_action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create'])) AND last_authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_project_guides_guide_mutation_authority_shape","table_name":"project_guides"},{"definition":"CHECK ((selected_review_policy_id IS NULL AND selected_review_policy_generation IS NULL AND selected_review_policy_hash IS NULL OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL) AND (selected_revision_policy_id IS NULL AND selected_revision_policy_generation IS NULL AND selected_revision_policy_hash IS NULL OR selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL))","kind":"c","name":"ck_project_guides_policy_selection_shape","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_mutated_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_guides_last_mutated_actor","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_mutated_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_guides_last_mutated_admin_grant","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_project_guides_last_mutated_decision","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_mutated_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_guides_last_mutated_identity_link","table_name":"project_guides"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_guides_project_id_projects","table_name":"project_guides"},{"definition":"FOREIGN KEY (project_id, version, selected_review_policy_id, selected_review_policy_generation, selected_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_project_guides_selected_review_policy","table_name":"project_guides"},{"definition":"FOREIGN KEY (project_id, version, selected_revision_policy_id, selected_revision_policy_generation, selected_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_project_guides_selected_revision_policy","table_name":"project_guides"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"guide_mutation_product_custody","table_name":"project_guides"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_guides","table_name":"project_guides"},{"definition":"UNIQUE (id, project_id, version)","kind":"u","name":"uq_project_guides_id_project_version","table_name":"project_guides"},{"definition":"UNIQUE (project_id, version)","kind":"u","name":"uq_project_guides_project_version","table_name":"project_guides"},{"definition":"CHECK (grant_method::text = 'manual'::text)","kind":"c","name":"ck_project_role_grants_grant_method","table_name":"project_role_grants"},{"definition":"CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND revoked_at IS NOT NULL)","kind":"c","name":"ck_project_role_grants_lifecycle","table_name":"project_role_grants"},{"definition":"CHECK (project_role_reason_is_safe(grant_reason) AND (revoked_reason IS NULL OR project_role_reason_is_safe(revoked_reason)))","kind":"c","name":"ck_project_role_grants_reason","table_name":"project_role_grants"},{"definition":"CHECK (role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))","kind":"c","name":"ck_project_role_grants_role","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_grants_actor_profile_id_actor_profiles","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_grants_granted_by_actor_profile_id_acto_c240","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_role_grants_granted_by_admin_role_grant_id_a_71d7","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_role_grants_project_id_projects","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_grants_revoked_by_actor_profile_id_acto_a5dd","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_role_grants_revoked_by_admin_role_grant_id_a_aa4d","table_name":"project_role_grants"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_role_grants","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (qualification_snapshot_id, actor_profile_id, project_id, role) REFERENCES project_role_qualification_snapshots(id, actor_profile_id, project_id, requested_role) ON DELETE RESTRICT","kind":"f","name":"qualification_ownership","table_name":"project_role_grants"},{"definition":"CHECK (project_role_availability_is_safe(skills_snapshot) AND project_role_availability_is_safe(reputation_snapshot))","kind":"c","name":"ck_project_role_qualification_snapshots_availability","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (project_role_reference_array_is_safe(external_expertise_refs, false))","kind":"c","name":"ck_project_role_qualification_snapshots_external_expertise_refs","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (project_role_reference_array_is_safe(prior_project_work_refs, true))","kind":"c","name":"ck_project_role_qualification_snapshots_prior_work_refs","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (requested_role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))","kind":"c","name":"ck_project_role_qualification_snapshots_role","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_qualification_snapshots_actor_profile_i_aedc","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (captured_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_qualification_snapshots_captured_by_act_ab57","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (captured_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_role_qualification_snapshots_captured_by_adm_c8b8","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_role_qualification_snapshots_project_id_projects","table_name":"project_role_qualification_snapshots"},{"definition":"UNIQUE (id, actor_profile_id, project_id, requested_role)","kind":"u","name":"grant_reference","table_name":"project_role_qualification_snapshots"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_role_qualification_snapshots","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_project_setup_runs_ck_project_setup_runs_generation_positive","table_name":"project_setup_runs"},{"definition":"CHECK (status::text = ANY (ARRAY['queued', 'dispatch_pending', 'enqueue_failed', 'enqueue_identity_mismatch', 'running_sufficiency_agent', 'sufficiency_blocked', 'running_policy_derivation_agent', 'policy_draft_ready', 'running_post_submit_derivation_agent', 'post_submit_setup_blocked', 'post_submit_policy_compiled', 'setup_blocked', 'failed']))","kind":"c","name":"ck_project_setup_runs_ck_project_setup_runs_status","table_name":"project_setup_runs"},{"definition":"CHECK (authorized_by_actor_profile_id IS NULL AND authorized_via_identity_link_id IS NULL AND authorized_by_admin_role_grant_id IS NULL AND authorization_scope_type IS NULL AND authorization_scope_project_id IS NULL AND authorization_action_id IS NULL AND authorization_decision_event_id IS NULL OR authorized_by_actor_profile_id IS NOT NULL AND authorized_via_identity_link_id IS NOT NULL AND authorized_by_admin_role_grant_id IS NOT NULL AND (authorization_scope_type::text = ANY (ARRAY['system', 'project'])) AND (authorization_scope_type::text = 'system'::text AND authorization_scope_project_id IS NULL OR authorization_scope_type::text = 'project'::text AND authorization_scope_project_id::text = project_id::text) AND authorization_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_project_setup_runs_setup_run_authority_shape","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (error_artifact_incident_id) REFERENCES guide_source_artifact_incidents(id)","kind":"f","name":"fk_project_setup_runs_artifact_incident","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorized_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_setup_runs_authorized_actor","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorized_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_setup_runs_authorized_admin_grant","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_project_setup_runs_authorized_decision","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorized_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_setup_runs_authorized_identity_link","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (continuation_verification_job_id) REFERENCES artifact_verification_jobs(id)","kind":"f","name":"fk_project_setup_runs_continuation_verification_job","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_project_setup_runs_guide_id_project_guides","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (output_post_submit_checker_policy_id) REFERENCES checker_policies(id)","kind":"f","name":"fk_project_setup_runs_post_submit_checker_policy","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_project_setup_runs_project_guide","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_setup_runs_project_id_projects","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_project_setup_runs_source_snapshot_hash","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_project_setup_runs_source_snapshot_id_guide_source_snapshots","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (output_submission_artifact_policy_id) REFERENCES submission_artifact_policies(id)","kind":"f","name":"fk_project_setup_runs_submission_artifact_policy","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (output_sufficiency_report_id) REFERENCES guide_sufficiency_reports(id)","kind":"f","name":"fk_project_setup_runs_sufficiency_report","table_name":"project_setup_runs"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_setup_runs","table_name":"project_setup_runs"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"source_setup_run_custody","table_name":"project_setup_runs"},{"definition":"UNIQUE (id, project_id, guide_id, source_snapshot_id, setup_generation)","kind":"u","name":"uq_project_setup_runs_exact_generation","table_name":"project_setup_runs"},{"definition":"UNIQUE (guide_id, setup_generation)","kind":"u","name":"uq_project_setup_runs_guide_generation","table_name":"project_setup_runs"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type::text = 'system'::text AND creation_action_id::text = 'project.create'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_projects_creation_authority_shape","table_name":"projects"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_projects_creation_actor","table_name":"projects"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_projects_creation_admin_grant","table_name":"projects"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_projects_creation_decision","table_name":"projects"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_projects_creation_identity_link","table_name":"projects"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_projects","table_name":"projects"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"project_creation_custody","table_name":"projects"},{"definition":"UNIQUE (slug)","kind":"u","name":"uq_projects_slug","table_name":"projects"},{"definition":"CHECK (submission_version > 0)","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_2b6d","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND review_queue_entry_id IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND review_queue_entry_id IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_4cd5","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_88bf","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_b8b8","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_review_admission_checker","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)","kind":"f","name":"fk_review_admission_committed_queue","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_admission_project","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (review_queue_entry_id) REFERENCES review_queue_entries(id)","kind":"f","name":"fk_review_admission_queue","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_review_admission_submission","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_review_admission_submission_lineage","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_review_admission_task","table_name":"review_admission_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_admission_idempotency_records","table_name":"review_admission_idempotency_records"},{"definition":"UNIQUE (admitting_checker_run_id)","kind":"u","name":"uq_review_admission_checker_run","table_name":"review_admission_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_review_admission_operation","table_name":"review_admission_idempotency_records"},{"definition":"UNIQUE (idempotency_key)","kind":"u","name":"uq_review_admission_replay_key","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (attempt_generation > 0)","kind":"c","name":"ck_review_leases_attempt_generation_positive","table_name":"review_leases"},{"definition":"CHECK (closed_at IS NULL OR closed_at >= claimed_at)","kind":"c","name":"ck_review_leases_closure_after_claim","table_name":"review_leases"},{"definition":"CHECK (expires_at > claimed_at)","kind":"c","name":"ck_review_leases_expiry_after_claim","table_name":"review_leases"},{"definition":"CHECK (status::text = 'active'::text AND closed_at IS NULL AND close_reason IS NULL OR status::text = 'consumed'::text AND closed_at IS NOT NULL AND close_reason::text = 'review_recorded'::text OR status::text = 'released'::text AND closed_at IS NOT NULL AND close_reason::text = 'manual_release'::text OR status::text = 'expired'::text AND closed_at IS NOT NULL AND close_reason::text = 'lease_expired'::text OR status::text = 'revoked'::text AND closed_at IS NOT NULL AND (close_reason::text = ANY (ARRAY['grant_revoked', 'admin_override'])))","kind":"c","name":"ck_review_leases_lifecycle_shape","table_name":"review_leases"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'consumed', 'released', 'expired', 'revoked']))","kind":"c","name":"ck_review_leases_status","table_name":"review_leases"},{"definition":"FOREIGN KEY (reviewer_contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)","kind":"f","name":"fk_review_lease_policy_version","table_name":"review_leases"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_lease_project","table_name":"review_leases"},{"definition":"FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version)","kind":"f","name":"fk_review_lease_queue_lineage","table_name":"review_leases"},{"definition":"FOREIGN KEY (reviewer_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_review_lease_reviewer","table_name":"review_leases"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_review_lease_submission","table_name":"review_leases"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_review_lease_task","table_name":"review_leases"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_leases","table_name":"review_leases"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"review_leases_active_lease_guard","table_name":"review_leases"},{"definition":"UNIQUE (review_queue_entry_id, attempt_generation)","kind":"u","name":"uq_review_lease_attempt","table_name":"review_leases"},{"definition":"UNIQUE (review_queue_entry_id, id)","kind":"u","name":"uq_review_lease_queue_identity","table_name":"review_leases"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.review_policy.update'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_review_policies_review_policy_authority_shape","table_name":"review_policies"},{"definition":"CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))","kind":"c","name":"ck_review_policies_review_policy_identity_shape","table_name":"review_policies"},{"definition":"CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)","kind":"c","name":"ck_review_policies_review_policy_predecessor_shape","table_name":"review_policies"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR review_preference_window_seconds > 0 AND review_lease_duration_seconds > 0 AND max_active_review_leases_per_reviewer = 1 AND self_review_allowed = false AND reject_policy::text = 'close_task'::text AND (finding_evidence_requirement::text = ANY (ARRAY['optional', 'required_for_blocking', 'required_for_all'])))","kind":"c","name":"ck_review_policies_review_policy_semantics_shape","table_name":"review_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_review_policies_actor_profile","table_name":"review_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_review_policies_admin_grant","table_name":"review_policies"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_review_policies_decision_event","table_name":"review_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_review_policies_identity_link","table_name":"review_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_review_policies_project_guide","table_name":"review_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_policies_project_id_projects","table_name":"review_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES review_policies(id)","kind":"f","name":"fk_review_policies_supersedes","table_name":"review_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_policies","table_name":"review_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"review_policy_mutation_custody","table_name":"review_policies"},{"definition":"UNIQUE (project_id, guide_version, policy_generation)","kind":"u","name":"uq_review_policies_project_version_generation","table_name":"review_policies"},{"definition":"UNIQUE (id, policy_generation, policy_hash)","kind":"u","name":"uq_review_policy_lineage","table_name":"review_policies"},{"definition":"UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)","kind":"u","name":"uq_review_policy_scoped_lineage","table_name":"review_policies"},{"definition":"CHECK (available_since >= first_queued_at)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_availab_d484","table_name":"review_queue_entries"},{"definition":"CHECK (routing_generation > 0 AND lifecycle_generation > 0)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_generat_38b7","table_name":"review_queue_entries"},{"definition":"CHECK (queue_state::text = 'pending'::text AND active_lease_id IS NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'leased'::text AND active_lease_id IS NOT NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'closed'::text AND active_lease_id IS NULL AND closed_at IS NOT NULL AND (closed_reason::text = ANY (ARRAY['review_recorded', 'task_closed', 'admin_cancelled'])) AND closed_at >= first_queued_at)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_lifecycle_shape","table_name":"review_queue_entries"},{"definition":"CHECK (queue_state::text = ANY (ARRAY['pending', 'leased', 'closed']))","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_queue_state","table_name":"review_queue_entries"},{"definition":"CHECK (routing_mode::text = ANY (ARRAY['open', 'preferred']))","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_routing_mode","table_name":"review_queue_entries"},{"definition":"CHECK (routing_reason::text = ANY (ARRAY['first_submission', 'revision_return', 'admin_assignment']))","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_routing_reason","table_name":"review_queue_entries"},{"definition":"CHECK (routing_mode::text = 'open'::text AND preferred_reviewer_id IS NULL AND preference_expires_at IS NULL OR routing_mode::text = 'preferred'::text AND preferred_reviewer_id IS NOT NULL AND preference_expires_at IS NOT NULL AND preference_expires_at > first_queued_at)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_routing_shape","table_name":"review_queue_entries"},{"definition":"CHECK (submission_version > 0)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_submiss_2f6b","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (active_lease_id, id) REFERENCES review_leases(id, review_queue_entry_id) DEFERRABLE INITIALLY DEFERRED","kind":"f","name":"fk_review_queue_active_lease","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_review_queue_checker","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (preferred_reviewer_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_review_queue_preferred_reviewer","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_queue_project","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_review_queue_submission","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_review_queue_submission_lineage","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_review_queue_task","table_name":"review_queue_entries"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_queue_entries","table_name":"review_queue_entries"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"review_queue_entries_active_lease_guard","table_name":"review_queue_entries"},{"definition":"UNIQUE (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)","kind":"u","name":"uq_review_queue_admission_identity","table_name":"review_queue_entries"},{"definition":"UNIQUE (id, project_id, task_id, submission_id, submission_version)","kind":"u","name":"uq_review_queue_lease_lineage","table_name":"review_queue_entries"},{"definition":"UNIQUE (submission_id)","kind":"u","name":"uq_review_queue_submission","table_name":"review_queue_entries"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.revision_policy.update'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_revision_policies_revision_policy_authority_shape","table_name":"revision_policies"},{"definition":"CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))","kind":"c","name":"ck_revision_policies_revision_policy_identity_shape","table_name":"revision_policies"},{"definition":"CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)","kind":"c","name":"ck_revision_policies_revision_policy_predecessor_shape","table_name":"revision_policies"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR max_revision_rounds > 0 AND revision_deadline_hours > 0)","kind":"c","name":"ck_revision_policies_revision_policy_semantics_shape","table_name":"revision_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_revision_policies_actor_profile","table_name":"revision_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_revision_policies_admin_grant","table_name":"revision_policies"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_revision_policies_decision_event","table_name":"revision_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_revision_policies_identity_link","table_name":"revision_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_revision_policies_project_guide","table_name":"revision_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_revision_policies_project_id_projects","table_name":"revision_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES revision_policies(id)","kind":"f","name":"fk_revision_policies_supersedes","table_name":"revision_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_revision_policies","table_name":"revision_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"revision_policy_mutation_custody","table_name":"revision_policies"},{"definition":"UNIQUE (project_id, guide_version, policy_generation)","kind":"u","name":"uq_revision_policies_project_version_generation","table_name":"revision_policies"},{"definition":"UNIQUE (id, policy_generation, policy_hash)","kind":"u","name":"uq_revision_policy_lineage","table_name":"revision_policies"},{"definition":"UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)","kind":"u","name":"uq_revision_policy_scoped_lineage","table_name":"revision_policies"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['draft', 'approved', 'superseded']))","kind":"c","name":"ck_submission_artifact_policies_ck_submission_artifact__20ca","table_name":"submission_artifact_policies"},{"definition":"CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)","kind":"c","name":"ck_submission_artifact_policies_ck_submission_artifact__52ca","table_name":"submission_artifact_policies"},{"definition":"CHECK (approved_by_actor_profile_id IS NULL AND approved_via_identity_link_id IS NULL AND approved_by_admin_role_grant_id IS NULL AND approval_scope_type IS NULL AND approval_scope_project_id IS NULL AND approval_action_id IS NULL AND approval_decision_event_id IS NULL OR approved_by_actor_profile_id IS NOT NULL AND approved_via_identity_link_id IS NOT NULL AND approved_by_admin_role_grant_id IS NOT NULL AND approval_scope_type IS NOT NULL AND approval_action_id IS NOT NULL AND (approval_scope_type::text = ANY (ARRAY['system', 'project'])) AND approval_scope_project_id IS NOT NULL AND approval_scope_project_id::text = project_id::text AND approval_action_id::text = 'project.submission_artifact_policy.approve'::text AND approval_decision_event_id IS NOT NULL)","kind":"c","name":"ck_submission_artifact_policies_ck_submission_policy_ap_0e4d","table_name":"submission_artifact_policies"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_decision_event_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update'])) AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NOT NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.submission_artifact_policy.derive'::text))","kind":"c","name":"ck_submission_artifact_policies_ck_submission_policy_cr_0629","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES submission_artifact_policies(id)","kind":"f","name":"fk_sap_supersedes_policy","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_submission_artifact_policies_guide_id_project_guides","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_submission_artifact_policies_project_guide","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_artifact_policies_project_id_projects","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_submission_artifact_policies_source_snapshot_hash","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approved_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submission_policy_approval_actor","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approval_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_submission_policy_approval_decision","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approved_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_submission_policy_approval_grant","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approved_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_submission_policy_approval_link","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approval_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_policy_approval_project","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submission_policy_creation_actor","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_submission_policy_creation_decision","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_submission_policy_creation_grant","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_submission_policy_creation_link","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_policy_creation_project","table_name":"submission_artifact_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_artifact_policies","table_name":"submission_artifact_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"submission_policy_creation_custody","table_name":"submission_artifact_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"submission_policy_product_custody","table_name":"submission_artifact_policies"},{"definition":"UNIQUE (id, policy_hash)","kind":"u","name":"uq_submission_artifact_policies_id_hash","table_name":"submission_artifact_policies"},{"definition":"UNIQUE (project_id, guide_version, policy_version)","kind":"u","name":"uq_submission_artifact_policies_project_version_policy","table_name":"submission_artifact_policies"},{"definition":"CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_bundle_admissions_archive_sha256","table_name":"submission_bundle_admissions"},{"definition":"CHECK (archive_byte_count >= 0)","kind":"c","name":"ck_submission_bundle_admissions_archive_size","table_name":"submission_bundle_admissions"},{"definition":"CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_bundle_admissions_manifest_sha256","table_name":"submission_bundle_admissions"},{"definition":"CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_bundle_admissions_policy_context_hash","table_name":"submission_bundle_admissions"},{"definition":"CHECK ((predecessor_submission_id IS NULL) = (predecessor_submission_version IS NULL))","kind":"c","name":"ck_submission_bundle_admissions_predecessor_shape","table_name":"submission_bundle_admissions"},{"definition":"CHECK (status::text = ANY (ARRAY['ready', 'consumed', 'stale']))","kind":"c","name":"ck_submission_bundle_admissions_status","table_name":"submission_bundle_admissions"},{"definition":"CHECK (status::text = 'ready'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'consumed'::text AND consumed_at IS NOT NULL AND consumed_by_submission_id IS NOT NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'stale'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NOT NULL AND octet_length(stale_reason::text) >= 1 AND octet_length(stale_reason::text) <= 500)","kind":"c","name":"ck_submission_bundle_admissions_terminal_shape","table_name":"submission_bundle_admissions"},{"definition":"CHECK (((put_operation_receipt_id IS NOT NULL)::integer + (put_observation_receipt_id IS NOT NULL)::integer) = 1)","kind":"c","name":"ck_submission_bundle_admissions_write_receipt_shape","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_actor_profile_id_actor_profiles","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (artifact_content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_artifact_content_id_art_12c8","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_assignment_id_task_assignments","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (consumed_by_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_consumed_by_submission__2b23","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (durable_intent_id) REFERENCES submission_bundle_durable_intents(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_durable_intent_id_submi_102c","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_identity_link_id_actor__d29d","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_pre_submit_evidence_set_a752","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_predecessor_submission__242d","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_project_id_projects","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_put_attempt_id_artifact_bbc3","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (put_observation_receipt_id) REFERENCES artifact_put_observation_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_put_observation_receipt_5136","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (put_operation_receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_put_operation_receipt_i_9602","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_task_id_workstream_tasks","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (verification_receipt_id) REFERENCES artifact_verification_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_verification_receipt_id_0ea1","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (verified_replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_verified_replica_id_art_3a4e","table_name":"submission_bundle_admissions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_bundle_admissions","table_name":"submission_bundle_admissions"},{"definition":"UNIQUE (pre_submit_evidence_set_id)","kind":"u","name":"uq_submission_bundle_admission_evidence","table_name":"submission_bundle_admissions"},{"definition":"UNIQUE (durable_intent_id)","kind":"u","name":"uq_submission_bundle_admission_intent","table_name":"submission_bundle_admissions"},{"definition":"UNIQUE (verification_receipt_id)","kind":"u","name":"uq_submission_bundle_admission_verification","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_durable_intents_pre_submit_evidenc_c406","table_name":"submission_bundle_durable_intents"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_durable_intents_put_attempt_id_art_b4e4","table_name":"submission_bundle_durable_intents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_bundle_durable_intents","table_name":"submission_bundle_durable_intents"},{"definition":"UNIQUE (pre_submit_evidence_set_id)","kind":"u","name":"uq_submission_bundle_intent_evidence","table_name":"submission_bundle_durable_intents"},{"definition":"UNIQUE (put_attempt_id)","kind":"u","name":"uq_submission_bundle_intent_put_attempt","table_name":"submission_bundle_durable_intents"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_0119","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update', 'project.submission_artifact_policy.approve']))","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_0dbe","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_2b53","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK ((status::text = ANY (ARRAY['reserved', 'pending'])) AND response_json IS NULL AND committed_at IS NULL AND committed_policy_id IS NULL AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND committed_policy_id IS NOT NULL AND (action_id::text = 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NOT NULL AND committed_pre_submit_policy_id IS NOT NULL OR action_id::text <> 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL))","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_58d4","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['reserved', 'pending', 'committed']))","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_a824","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (service_identity IS NULL AND idempotency_key IS NOT NULL AND setup_run_id IS NULL AND setup_task_id IS NULL AND correlation_id IS NULL OR service_identity IS NOT NULL AND service_identity::text = 'workstream.project.setup'::text AND idempotency_key IS NULL AND action_id::text = 'project.submission_artifact_policy.derive'::text AND setup_run_id IS NOT NULL AND setup_task_id IS NOT NULL AND correlation_id IS NOT NULL)","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_b357","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_actor_f5bb","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (committed_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_commi_4fa6","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (committed_policy_id) REFERENCES submission_artifact_policies(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_commi_571a","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (committed_pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_commi_baa9","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_guide_ed8d","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_ident_2567","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_proje_442a","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_setup_a102","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_sourc_536e","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_policy_mutation_idempotency_records","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"submission_policy_replay_custody","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_submission_policy_operation_identity","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)","kind":"c","name":"ck_submissions_post_submit_policy_lock_complete","table_name":"submissions"},{"definition":"FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submissions_contributor_id_actor_profiles","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_submissions_locked_effective_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)","kind":"f","name":"fk_submissions_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)","kind":"f","name":"fk_submissions_locked_pre_submit_checker_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_submissions_locked_source_snapshot_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (supersedes_submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_submissions_supersedes_submission_id_submissions","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_submissions_task_id_workstream_tasks","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","kind":"f","name":"fk_submissions_task_locked_effective_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)","kind":"f","name":"fk_submissions_task_locked_guide","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)","kind":"f","name":"fk_submissions_task_locked_payment_policy","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES workstream_tasks(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"f","name":"fk_submissions_task_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","kind":"f","name":"fk_submissions_task_locked_pre_submit_checker_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","kind":"f","name":"fk_submissions_task_locked_review_policy","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","kind":"f","name":"fk_submissions_task_locked_revision_policy","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","kind":"f","name":"fk_submissions_task_locked_source_snapshot_hash","table_name":"submissions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submissions","table_name":"submissions"},{"definition":"UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"u","name":"uq_submissions_id_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"UNIQUE (id, task_id, version)","kind":"u","name":"uq_submissions_id_task_version","table_name":"submissions"},{"definition":"UNIQUE (id, version)","kind":"u","name":"uq_submissions_id_version","table_name":"submissions"},{"definition":"UNIQUE (task_id, version)","kind":"u","name":"uq_submissions_task_version","table_name":"submissions"},{"definition":"FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_task_assignments_contributor_id_actor_profiles","table_name":"task_assignments"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_task_assignments_task_id_workstream_tasks","table_name":"task_assignments"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_task_assignments","table_name":"task_assignments"},{"definition":"UNIQUE (id, task_id, contributor_id)","kind":"u","name":"uq_task_assignments_id_task_contributor","table_name":"task_assignments"},{"definition":"CHECK (status::text = 'draft'::text OR locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)","kind":"c","name":"ck_workstream_tasks_post_submit_policy_lock_complete","table_name":"workstream_tasks"},{"definition":"CHECK (status::text = 'draft'::text OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)","kind":"c","name":"ck_workstream_tasks_review_revision_policy_lock_required","table_name":"workstream_tasks"},{"definition":"CHECK (locked_review_policy_id IS NULL AND locked_review_policy_generation IS NULL AND locked_review_policy_hash IS NULL AND locked_revision_policy_id IS NULL AND locked_revision_policy_generation IS NULL AND locked_revision_policy_hash IS NULL OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)","kind":"c","name":"ck_workstream_tasks_review_revision_policy_lock_shape","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_workstream_tasks_locked_guide","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_payment_policy_version) REFERENCES payment_policies(project_id, guide_version)","kind":"f","name":"fk_workstream_tasks_locked_payment_policy","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)","kind":"f","name":"fk_workstream_tasks_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_guide_version, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_review_policy","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_guide_version, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_revision_policy","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_workstream_tasks_locked_source_snapshot_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_workstream_tasks_project_id_projects","table_name":"workstream_tasks"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_workstream_tasks","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_guide_version)","kind":"u","name":"uq_workstream_tasks_id_locked_guide","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_payment_policy_version)","kind":"u","name":"uq_workstream_tasks_id_locked_payment_policy","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_review_policy","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_revision_policy","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_source_snapshot_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, project_id)","kind":"u","name":"uq_workstream_tasks_id_project","table_name":"workstream_tasks"}],"format":"workstream-v01-schema-manifest-1","indexes":[{"definition":"CREATE INDEX ix_actor_identity_links_issuer_subject_status ON public.actor_identity_links USING btree (issuer, subject, status)","name":"ix_actor_identity_links_issuer_subject_status","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX pk_actor_identity_links ON public.actor_identity_links USING btree (id)","name":"pk_actor_identity_links","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX uq_actor_identity_links_actor_profile ON public.actor_identity_links USING btree (actor_profile_id)","name":"uq_actor_identity_links_actor_profile","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX uq_actor_identity_links_external_identity ON public.actor_identity_links USING btree (issuer, subject)","name":"uq_actor_identity_links_external_identity","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX uq_actor_identity_links_id_profile ON public.actor_identity_links USING btree (id, actor_profile_id)","name":"uq_actor_identity_links_id_profile","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX pk_actor_profile_migration_state ON public.actor_profile_migration_state USING btree (id)","name":"pk_actor_profile_migration_state","table_name":"actor_profile_migration_state"},{"definition":"CREATE INDEX ix_actor_profiles_last_seen_at ON public.actor_profiles USING btree (last_seen_at)","name":"ix_actor_profiles_last_seen_at","table_name":"actor_profiles"},{"definition":"CREATE INDEX ix_actor_profiles_status_actor_kind ON public.actor_profiles USING btree (status, actor_kind)","name":"ix_actor_profiles_status_actor_kind","table_name":"actor_profiles"},{"definition":"CREATE UNIQUE INDEX pk_actor_profiles ON public.actor_profiles USING btree (id)","name":"pk_actor_profiles","table_name":"actor_profiles"},{"definition":"CREATE UNIQUE INDEX service_identity ON public.actor_profiles USING btree (service_identity)","name":"service_identity","table_name":"actor_profiles"},{"definition":"CREATE INDEX ix_admin_role_grants_effective_candidate ON public.admin_role_grants USING btree (target_actor_profile_id, status, scope_type, scope_project_id)","name":"ix_admin_role_grants_effective_candidate","table_name":"admin_role_grants"},{"definition":"CREATE INDEX ix_admin_role_grants_final_access_admin ON public.admin_role_grants USING btree (role, status) WHERE (((role)::text = 'access_administrator'::text) AND ((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))","name":"ix_admin_role_grants_final_access_admin","table_name":"admin_role_grants"},{"definition":"CREATE INDEX ix_admin_role_grants_history ON public.admin_role_grants USING btree (target_actor_profile_id, granted_at, id)","name":"ix_admin_role_grants_history","table_name":"admin_role_grants"},{"definition":"CREATE UNIQUE INDEX pk_admin_role_grants ON public.admin_role_grants USING btree (id)","name":"pk_admin_role_grants","table_name":"admin_role_grants"},{"definition":"CREATE UNIQUE INDEX uq_admin_role_grants_active_project ON public.admin_role_grants USING btree (target_actor_profile_id, role, scope_project_id) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'project'::text))","name":"uq_admin_role_grants_active_project","table_name":"admin_role_grants"},{"definition":"CREATE UNIQUE INDEX uq_admin_role_grants_active_system ON public.admin_role_grants USING btree (target_actor_profile_id, role) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))","name":"uq_admin_role_grants_active_system","table_name":"admin_role_grants"},{"definition":"CREATE INDEX ix_api_rate_control_counters_window_expires_at ON public.api_rate_control_counters USING btree (window_expires_at)","name":"ix_api_rate_control_counters_window_expires_at","table_name":"api_rate_control_counters"},{"definition":"CREATE UNIQUE INDEX pk_api_rate_control_counters ON public.api_rate_control_counters USING btree (control_scope, key_digest)","name":"pk_api_rate_control_counters","table_name":"api_rate_control_counters"},{"definition":"CREATE UNIQUE INDEX pk_artifact_admission_charges ON public.artifact_admission_charges USING btree (id)","name":"pk_artifact_admission_charges","table_name":"artifact_admission_charges"},{"definition":"CREATE UNIQUE INDEX uq_artifact_admission_charge_scope_content ON public.artifact_admission_charges USING btree (scope_type, scope_id, sha256, byte_count)","name":"uq_artifact_admission_charge_scope_content","table_name":"artifact_admission_charges"},{"definition":"CREATE UNIQUE INDEX pk_artifact_admission_scopes ON public.artifact_admission_scopes USING btree (scope_type, scope_id)","name":"pk_artifact_admission_scopes","table_name":"artifact_admission_scopes"},{"definition":"CREATE INDEX ix_artifact_bindings_content_id ON public.artifact_bindings USING btree (content_id)","name":"ix_artifact_bindings_content_id","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_bindings_project_id ON public.artifact_bindings USING btree (project_id)","name":"ix_artifact_bindings_project_id","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_bindings_scope ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version DESC)","name":"ix_artifact_bindings_scope","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_bindings_supersedes_binding_id ON public.artifact_bindings USING btree (supersedes_binding_id)","name":"ix_artifact_bindings_supersedes_binding_id","table_name":"artifact_bindings"},{"definition":"CREATE UNIQUE INDEX pk_artifact_bindings ON public.artifact_bindings USING btree (id)","name":"pk_artifact_bindings","table_name":"artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_artifact_binding_scope_version ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version)","name":"uq_artifact_binding_scope_version","table_name":"artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_artifact_binding_supersedes ON public.artifact_bindings USING btree (supersedes_binding_id)","name":"uq_artifact_binding_supersedes","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_contents_sha256 ON public.artifact_contents USING btree (sha256)","name":"ix_artifact_contents_sha256","table_name":"artifact_contents"},{"definition":"CREATE UNIQUE INDEX pk_artifact_contents ON public.artifact_contents USING btree (id)","name":"pk_artifact_contents","table_name":"artifact_contents"},{"definition":"CREATE UNIQUE INDEX uq_artifact_content_digest_size ON public.artifact_contents USING btree (sha256, byte_count)","name":"uq_artifact_content_digest_size","table_name":"artifact_contents"},{"definition":"CREATE INDEX ix_artifact_operation_receipts_put_attempt_id ON public.artifact_operation_receipts USING btree (put_attempt_id)","name":"ix_artifact_operation_receipts_put_attempt_id","table_name":"artifact_operation_receipts"},{"definition":"CREATE INDEX ix_artifact_operation_receipts_replica_id ON public.artifact_operation_receipts USING btree (replica_id)","name":"ix_artifact_operation_receipts_replica_id","table_name":"artifact_operation_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_operation_receipts ON public.artifact_operation_receipts USING btree (id)","name":"pk_artifact_operation_receipts","table_name":"artifact_operation_receipts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_receipt_put_attempt ON public.artifact_operation_receipts USING btree (put_attempt_id)","name":"uq_artifact_receipt_put_attempt","table_name":"artifact_operation_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_put_attempt_charges ON public.artifact_put_attempt_charges USING btree (attempt_id, charge_id)","name":"pk_artifact_put_attempt_charges","table_name":"artifact_put_attempt_charges"},{"definition":"CREATE INDEX ix_artifact_put_attempts_checker_run_id ON public.artifact_put_attempts USING btree (checker_run_id)","name":"ix_artifact_put_attempts_checker_run_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_guide_source_item_id ON public.artifact_put_attempts USING btree (guide_source_item_id)","name":"ix_artifact_put_attempts_guide_source_item_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_next_run_at ON public.artifact_put_attempts USING btree (next_run_at)","name":"ix_artifact_put_attempts_next_run_at","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_project_id ON public.artifact_put_attempts USING btree (project_id)","name":"ix_artifact_put_attempts_project_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_receipt_id ON public.artifact_put_attempts USING btree (receipt_id)","name":"ix_artifact_put_attempts_receipt_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_replica_id ON public.artifact_put_attempts USING btree (replica_id)","name":"ix_artifact_put_attempts_replica_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_status ON public.artifact_put_attempts USING btree (status)","name":"ix_artifact_put_attempts_status","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_task_id ON public.artifact_put_attempts USING btree (task_id)","name":"ix_artifact_put_attempts_task_id","table_name":"artifact_put_attempts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_put_attempts ON public.artifact_put_attempts USING btree (id)","name":"pk_artifact_put_attempts","table_name":"artifact_put_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_put_attempt_operation ON public.artifact_put_attempts USING btree (operation_identity)","name":"uq_artifact_put_attempt_operation","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_observation_receipts_put_attempt_id ON public.artifact_put_observation_receipts USING btree (put_attempt_id)","name":"ix_artifact_put_observation_receipts_put_attempt_id","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_put_observation_receipts ON public.artifact_put_observation_receipts USING btree (id)","name":"pk_artifact_put_observation_receipts","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_put_observation_fence ON public.artifact_put_observation_receipts USING btree (put_attempt_id, execution_generation)","name":"uq_artifact_put_observation_fence","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_parent_recovery_attempt_id ON public.artifact_recovery_attempts USING btree (parent_recovery_attempt_id)","name":"ix_artifact_recovery_attempts_parent_recovery_attempt_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_project_id ON public.artifact_recovery_attempts USING btree (project_id)","name":"ix_artifact_recovery_attempts_project_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_requester_actor_profile_id ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id)","name":"ix_artifact_recovery_attempts_requester_actor_profile_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_submission_id ON public.artifact_recovery_attempts USING btree (submission_id)","name":"ix_artifact_recovery_attempts_submission_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_task_id ON public.artifact_recovery_attempts USING btree (task_id)","name":"ix_artifact_recovery_attempts_task_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_recovery_attempts ON public.artifact_recovery_attempts USING btree (id)","name":"pk_artifact_recovery_attempts","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_recovery_idempotency ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)","name":"uq_artifact_recovery_idempotency","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_recovery_retry_job ON public.artifact_recovery_attempts USING btree (retry_verification_job_id)","name":"uq_artifact_recovery_retry_job","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_recovery_source_job ON public.artifact_recovery_attempts USING btree (source_verification_job_id)","name":"uq_artifact_recovery_source_job","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_replicas_content_id ON public.artifact_replicas USING btree (content_id)","name":"ix_artifact_replicas_content_id","table_name":"artifact_replicas"},{"definition":"CREATE INDEX ix_artifact_replicas_storage_namespace_id ON public.artifact_replicas USING btree (storage_namespace_id)","name":"ix_artifact_replicas_storage_namespace_id","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX pk_artifact_replicas ON public.artifact_replicas USING btree (id)","name":"pk_artifact_replicas","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX uq_artifact_replica_provider_object ON public.artifact_replicas USING btree (storage_namespace_id, provider_object_ref)","name":"uq_artifact_replica_provider_object","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX uq_artifact_replicas_id_content ON public.artifact_replicas USING btree (id, content_id)","name":"uq_artifact_replicas_id_content","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX pk_artifact_storage_namespaces ON public.artifact_storage_namespaces USING btree (id)","name":"pk_artifact_storage_namespaces","table_name":"artifact_storage_namespaces"},{"definition":"CREATE UNIQUE INDEX uq_artifact_storage_namespace_fingerprint ON public.artifact_storage_namespaces USING btree (namespace_fingerprint)","name":"uq_artifact_storage_namespace_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"CREATE UNIQUE INDEX uq_artifact_storage_namespace_id_fingerprint ON public.artifact_storage_namespaces USING btree (id, namespace_fingerprint)","name":"uq_artifact_storage_namespace_id_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_next_run_at ON public.artifact_verification_jobs USING btree (next_run_at)","name":"ix_artifact_verification_jobs_next_run_at","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_originating_put_attempt_id ON public.artifact_verification_jobs USING btree (originating_put_attempt_id)","name":"ix_artifact_verification_jobs_originating_put_attempt_id","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_parent_verification_job_id ON public.artifact_verification_jobs USING btree (parent_verification_job_id)","name":"ix_artifact_verification_jobs_parent_verification_job_id","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_replica_id ON public.artifact_verification_jobs USING btree (replica_id)","name":"ix_artifact_verification_jobs_replica_id","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_status ON public.artifact_verification_jobs USING btree (status)","name":"ix_artifact_verification_jobs_status","table_name":"artifact_verification_jobs"},{"definition":"CREATE UNIQUE INDEX pk_artifact_verification_jobs ON public.artifact_verification_jobs USING btree (id)","name":"pk_artifact_verification_jobs","table_name":"artifact_verification_jobs"},{"definition":"CREATE UNIQUE INDEX uq_artifact_verification_initial_origin ON public.artifact_verification_jobs USING btree (originating_put_attempt_id) WHERE (parent_verification_job_id IS NULL)","name":"uq_artifact_verification_initial_origin","table_name":"artifact_verification_jobs"},{"definition":"CREATE UNIQUE INDEX uq_artifact_verification_parent ON public.artifact_verification_jobs USING btree (parent_verification_job_id)","name":"uq_artifact_verification_parent","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_receipts_verification_job_id ON public.artifact_verification_receipts USING btree (verification_job_id)","name":"ix_artifact_verification_receipts_verification_job_id","table_name":"artifact_verification_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_verification_receipts ON public.artifact_verification_receipts USING btree (id)","name":"pk_artifact_verification_receipts","table_name":"artifact_verification_receipts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_verification_fence ON public.artifact_verification_receipts USING btree (verification_job_id, execution_generation)","name":"uq_artifact_verification_fence","table_name":"artifact_verification_receipts"},{"definition":"CREATE INDEX ix_audit_events_actor_id ON public.audit_events USING btree (actor_id)","name":"ix_audit_events_actor_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_actor_ref ON public.audit_events USING btree (actor_ref_kind, actor_id)","name":"ix_audit_events_actor_ref","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_correlation_id ON public.audit_events USING btree (correlation_id)","name":"ix_audit_events_correlation_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_entity_id ON public.audit_events USING btree (entity_id)","name":"ix_audit_events_entity_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_entity_type ON public.audit_events USING btree (entity_type)","name":"ix_audit_events_entity_type","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_event_type ON public.audit_events USING btree (event_type)","name":"ix_audit_events_event_type","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_occurred_at ON public.audit_events USING btree (occurred_at)","name":"ix_audit_events_occurred_at","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_project_id ON public.audit_events USING btree (project_id)","name":"ix_audit_events_project_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_request_id ON public.audit_events USING btree (request_id)","name":"ix_audit_events_request_id","table_name":"audit_events"},{"definition":"CREATE UNIQUE INDEX pk_audit_events ON public.audit_events USING btree (id)","name":"pk_audit_events","table_name":"audit_events"},{"definition":"CREATE UNIQUE INDEX pk_authority_control ON public.authority_control USING btree (id)","name":"pk_authority_control","table_name":"authority_control"},{"definition":"CREATE UNIQUE INDEX pk_authority_idempotency_records ON public.authority_idempotency_records USING btree (id)","name":"pk_authority_idempotency_records","table_name":"authority_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_authority_idempotency_records_actor_reference ON public.authority_idempotency_records USING btree (id, actor_ref_kind, actor_ref)","name":"uq_authority_idempotency_records_actor_reference","table_name":"authority_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_authority_idempotency_records_replay_namespace ON public.authority_idempotency_records USING btree (actor_ref_kind, actor_ref, operation, idempotency_key)","name":"uq_authority_idempotency_records_replay_namespace","table_name":"authority_idempotency_records"},{"definition":"CREATE INDEX ix_checker_policies_effective_policy_hash ON public.checker_policies USING btree (effective_policy_hash)","name":"ix_checker_policies_effective_policy_hash","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_effective_policy_id ON public.checker_policies USING btree (effective_policy_id)","name":"ix_checker_policies_effective_policy_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_guide_id ON public.checker_policies USING btree (guide_id)","name":"ix_checker_policies_guide_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_pre_submit_checker_bundle_hash ON public.checker_policies USING btree (pre_submit_checker_bundle_hash)","name":"ix_checker_policies_pre_submit_checker_bundle_hash","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_pre_submit_checker_policy_id ON public.checker_policies USING btree (pre_submit_checker_policy_id)","name":"ix_checker_policies_pre_submit_checker_policy_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_project_id ON public.checker_policies USING btree (project_id)","name":"ix_checker_policies_project_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_source_snapshot_id ON public.checker_policies USING btree (source_snapshot_id)","name":"ix_checker_policies_source_snapshot_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_supersedes_policy_id ON public.checker_policies USING btree (supersedes_policy_id)","name":"ix_checker_policies_supersedes_policy_id","table_name":"checker_policies"},{"definition":"CREATE UNIQUE INDEX pk_checker_policies ON public.checker_policies USING btree (id)","name":"pk_checker_policies","table_name":"checker_policies"},{"definition":"CREATE UNIQUE INDEX uq_checker_policies_current_project_version ON public.checker_policies USING btree (project_id, guide_version) WHERE ((lifecycle_status)::text = ANY (ARRAY['compiled', 'approved']))","name":"uq_checker_policies_current_project_version","table_name":"checker_policies"},{"definition":"CREATE UNIQUE INDEX uq_checker_policies_id_version_hash ON public.checker_policies USING btree (id, guide_version, policy_hash)","name":"uq_checker_policies_id_version_hash","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_results_checker_name ON public.checker_results USING btree (checker_name)","name":"ix_checker_results_checker_name","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_checker_run_id ON public.checker_results USING btree (checker_run_id)","name":"ix_checker_results_checker_run_id","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_submission_id ON public.checker_results USING btree (submission_id)","name":"ix_checker_results_submission_id","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_task_id ON public.checker_results USING btree (task_id)","name":"ix_checker_results_task_id","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_worker_visible ON public.checker_results USING btree (worker_visible)","name":"ix_checker_results_worker_visible","table_name":"checker_results"},{"definition":"CREATE UNIQUE INDEX pk_checker_results ON public.checker_results USING btree (id)","name":"pk_checker_results","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_runs_audit_event_id ON public.checker_runs USING btree (audit_event_id)","name":"ix_checker_runs_audit_event_id","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_locked_post_submit_policy_hash ON public.checker_runs USING btree (locked_post_submit_checker_policy_hash)","name":"ix_checker_runs_locked_post_submit_policy_hash","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_routing_recommendation ON public.checker_runs USING btree (routing_recommendation)","name":"ix_checker_runs_routing_recommendation","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_status ON public.checker_runs USING btree (status)","name":"ix_checker_runs_status","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_submission_id ON public.checker_runs USING btree (submission_id)","name":"ix_checker_runs_submission_id","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_supersedes_checker_run_id ON public.checker_runs USING btree (supersedes_checker_run_id)","name":"ix_checker_runs_supersedes_checker_run_id","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_task_id ON public.checker_runs USING btree (task_id)","name":"ix_checker_runs_task_id","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX pk_checker_runs ON public.checker_runs USING btree (id)","name":"pk_checker_runs","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX uq_checker_runs_current_per_submission ON public.checker_runs USING btree (submission_id) WHERE (is_current_for_submission = true)","name":"uq_checker_runs_current_per_submission","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX uq_checker_runs_submission_attempt ON public.checker_runs USING btree (submission_id, attempt_number)","name":"uq_checker_runs_submission_attempt","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX pk_contribution_award_definitions ON public.contribution_award_definitions USING btree (id)","name":"pk_contribution_award_definitions","table_name":"contribution_award_definitions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_award_definition_instrument ON public.contribution_award_definitions USING btree (contribution_rule_id, instrument_type)","name":"uq_contribution_award_definition_instrument","table_name":"contribution_award_definitions"},{"definition":"CREATE UNIQUE INDEX pk_contribution_policies ON public.contribution_policies USING btree (id)","name":"pk_contribution_policies","table_name":"contribution_policies"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_active_project ON public.contribution_policies USING btree (project_id) WHERE ((status)::text = 'active'::text)","name":"uq_contribution_policy_active_project","table_name":"contribution_policies"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_ownership ON public.contribution_policies USING btree (id, project_id)","name":"uq_contribution_policy_ownership","table_name":"contribution_policies"},{"definition":"CREATE UNIQUE INDEX pk_contribution_policy_versions ON public.contribution_policy_versions USING btree (id)","name":"pk_contribution_policy_versions","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_version_number ON public.contribution_policy_versions USING btree (contribution_policy_id, version_number)","name":"uq_contribution_policy_version_number","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_version_ownership ON public.contribution_policy_versions USING btree (id, contribution_policy_id, project_id)","name":"uq_contribution_policy_version_ownership","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_version_project ON public.contribution_policy_versions USING btree (id, project_id)","name":"uq_contribution_policy_version_project","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX pk_contribution_rules ON public.contribution_rules USING btree (id)","name":"pk_contribution_rules","table_name":"contribution_rules"},{"definition":"CREATE UNIQUE INDEX uq_contribution_rule_ownership ON public.contribution_rules USING btree (id, contribution_policy_version_id, project_id, contribution_type)","name":"uq_contribution_rule_ownership","table_name":"contribution_rules"},{"definition":"CREATE UNIQUE INDEX uq_contribution_rule_type ON public.contribution_rules USING btree (contribution_policy_version_id, contribution_type)","name":"uq_contribution_rule_type","table_name":"contribution_rules"},{"definition":"CREATE INDEX ix_effective_psap_effective_hash ON public.effective_project_submission_artifact_policies USING btree (effective_policy_hash)","name":"ix_effective_psap_effective_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_guide ON public.effective_project_submission_artifact_policies USING btree (guide_id)","name":"ix_effective_psap_guide","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_lifecycle ON public.effective_project_submission_artifact_policies USING btree (lifecycle_status)","name":"ix_effective_psap_lifecycle","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_project ON public.effective_project_submission_artifact_policies USING btree (project_id)","name":"ix_effective_psap_project","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_source_snapshot ON public.effective_project_submission_artifact_policies USING btree (source_snapshot_id)","name":"ix_effective_psap_source_snapshot","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_submission_policy ON public.effective_project_submission_artifact_policies USING btree (submission_artifact_policy_id)","name":"ix_effective_psap_submission_policy","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX pk_effective_project_submission_artifact_policies ON public.effective_project_submission_artifact_policies USING btree (id)","name":"pk_effective_project_submission_artifact_policies","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX uq_effective_project_submission_artifact_policies_id_hash ON public.effective_project_submission_artifact_policies USING btree (id, effective_policy_hash)","name":"uq_effective_project_submission_artifact_policies_id_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_evidence_items_submission_id ON public.evidence_items USING btree (submission_id)","name":"ix_evidence_items_submission_id","table_name":"evidence_items"},{"definition":"CREATE INDEX ix_evidence_items_type ON public.evidence_items USING btree (type)","name":"ix_evidence_items_type","table_name":"evidence_items"},{"definition":"CREATE UNIQUE INDEX pk_evidence_items ON public.evidence_items USING btree (id)","name":"pk_evidence_items","table_name":"evidence_items"},{"definition":"CREATE UNIQUE INDEX pk_guide_mutation_idempotency_records ON public.guide_mutation_idempotency_records USING btree (id)","name":"pk_guide_mutation_idempotency_records","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_guide_mutation_operation_identity ON public.guide_mutation_idempotency_records USING btree (operation_id)","name":"uq_guide_mutation_operation_identity","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_guide_mutation_replay_namespace ON public.guide_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)","name":"uq_guide_mutation_replay_namespace","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_content_id ON public.guide_source_artifact_bindings USING btree (content_id)","name":"ix_guide_source_artifact_bindings_content_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_guide_id ON public.guide_source_artifact_bindings USING btree (guide_id)","name":"ix_guide_source_artifact_bindings_guide_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_project_id ON public.guide_source_artifact_bindings USING btree (project_id)","name":"ix_guide_source_artifact_bindings_project_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_project_setup_run_id ON public.guide_source_artifact_bindings USING btree (project_setup_run_id)","name":"ix_guide_source_artifact_bindings_project_setup_run_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_source_item_id ON public.guide_source_artifact_bindings USING btree (source_item_id)","name":"ix_guide_source_artifact_bindings_source_item_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_source_snapshot_id ON public.guide_source_artifact_bindings USING btree (source_snapshot_id)","name":"ix_guide_source_artifact_bindings_source_snapshot_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_supersedes_binding_id ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)","name":"ix_guide_source_artifact_bindings_supersedes_binding_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_verified_replica_id ON public.guide_source_artifact_bindings USING btree (verified_replica_id)","name":"ix_guide_source_artifact_bindings_verified_replica_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_artifact_bindings ON public.guide_source_artifact_bindings USING btree (id)","name":"pk_guide_source_artifact_bindings","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_exact_read ON public.guide_source_artifact_bindings USING btree (id, content_id, verified_replica_id, setup_generation)","name":"uq_guide_bindings_exact_read","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_extraction_attempt_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, setup_generation)","name":"uq_guide_bindings_extraction_attempt_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_extraction_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, source_item_id, project_setup_run_id, setup_generation)","name":"uq_guide_bindings_extraction_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_item_generation ON public.guide_source_artifact_bindings USING btree (source_item_id, setup_generation)","name":"uq_guide_bindings_item_generation","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_supersedes ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)","name":"uq_guide_bindings_supersedes","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_incidents_binding_id ON public.guide_source_artifact_incidents USING btree (binding_id)","name":"ix_guide_source_artifact_incidents_binding_id","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE INDEX ix_guide_source_artifact_incidents_content_id ON public.guide_source_artifact_incidents USING btree (content_id)","name":"ix_guide_source_artifact_incidents_content_id","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE INDEX ix_guide_source_artifact_incidents_verified_replica_id ON public.guide_source_artifact_incidents USING btree (verified_replica_id)","name":"ix_guide_source_artifact_incidents_verified_replica_id","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_artifact_incidents ON public.guide_source_artifact_incidents USING btree (id)","name":"pk_guide_source_artifact_incidents","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE INDEX ix_guide_source_artifact_ingests_actor_profile_id ON public.guide_source_artifact_ingests USING btree (actor_profile_id)","name":"ix_guide_source_artifact_ingests_actor_profile_id","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE UNIQUE INDEX ix_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)","name":"ix_guide_source_artifact_ingests_source_item_id","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_artifact_ingests ON public.guide_source_artifact_ingests USING btree (id)","name":"pk_guide_source_artifact_ingests","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)","name":"uq_guide_source_artifact_ingests_source_item_id","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE INDEX ix_guide_source_extracted_contents_content_id ON public.guide_source_extracted_contents USING btree (content_id)","name":"ix_guide_source_extracted_contents_content_id","table_name":"guide_source_extracted_contents"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extracted_contents ON public.guide_source_extracted_contents USING btree (id)","name":"pk_guide_source_extracted_contents","table_name":"guide_source_extracted_contents"},{"definition":"CREATE UNIQUE INDEX uq_guide_extracted_contents_exact_usage ON public.guide_source_extracted_contents USING btree (id, content_id)","name":"uq_guide_extracted_contents_exact_usage","table_name":"guide_source_extracted_contents"},{"definition":"CREATE UNIQUE INDEX uq_guide_extracted_contents_identity ON public.guide_source_extracted_contents USING btree (content_id, detected_format, extractor_name, extractor_version, policy_version)","name":"uq_guide_extracted_contents_identity","table_name":"guide_source_extracted_contents"},{"definition":"CREATE INDEX ix_guide_source_extraction_attempts_binding_id ON public.guide_source_extraction_attempts USING btree (binding_id)","name":"ix_guide_source_extraction_attempts_binding_id","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE INDEX ix_guide_source_extraction_attempts_content_id ON public.guide_source_extraction_attempts USING btree (content_id)","name":"ix_guide_source_extraction_attempts_content_id","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extraction_attempts ON public.guide_source_extraction_attempts USING btree (id)","name":"pk_guide_source_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_attempts ON public.guide_source_extraction_attempts USING btree (binding_id, policy_version, attempt_number)","name":"uq_guide_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_attempts_exact_usage ON public.guide_source_extraction_attempts USING btree (id, binding_id, content_id, setup_generation, status)","name":"uq_guide_extraction_attempts_exact_usage","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extraction_retry_budgets ON public.guide_source_extraction_retry_budgets USING btree (binding_id)","name":"pk_guide_source_extraction_retry_budgets","table_name":"guide_source_extraction_retry_budgets"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_binding_id ON public.guide_source_extraction_usages USING btree (binding_id)","name":"ix_guide_source_extraction_usages_binding_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_content_id ON public.guide_source_extraction_usages USING btree (content_id)","name":"ix_guide_source_extraction_usages_content_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_extracted_content_id ON public.guide_source_extraction_usages USING btree (extracted_content_id)","name":"ix_guide_source_extraction_usages_extracted_content_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_project_setup_run_id ON public.guide_source_extraction_usages USING btree (project_setup_run_id)","name":"ix_guide_source_extraction_usages_project_setup_run_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_source_item_id ON public.guide_source_extraction_usages USING btree (source_item_id)","name":"ix_guide_source_extraction_usages_source_item_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extraction_usages ON public.guide_source_extraction_usages USING btree (id)","name":"pk_guide_source_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_usages ON public.guide_source_extraction_usages USING btree (binding_id, extracted_content_id)","name":"uq_guide_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_usages_exact_provenance ON public.guide_source_extraction_usages USING btree (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)","name":"uq_guide_extraction_usages_exact_provenance","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_format_classifications_binding_id ON public.guide_source_format_classifications USING btree (binding_id)","name":"ix_guide_source_format_classifications_binding_id","table_name":"guide_source_format_classifications"},{"definition":"CREATE INDEX ix_guide_source_format_classifications_content_id ON public.guide_source_format_classifications USING btree (content_id)","name":"ix_guide_source_format_classifications_content_id","table_name":"guide_source_format_classifications"},{"definition":"CREATE INDEX ix_guide_source_format_classifications_verified_replica_id ON public.guide_source_format_classifications USING btree (verified_replica_id)","name":"ix_guide_source_format_classifications_verified_replica_id","table_name":"guide_source_format_classifications"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_format_classifications ON public.guide_source_format_classifications USING btree (id)","name":"pk_guide_source_format_classifications","table_name":"guide_source_format_classifications"},{"definition":"CREATE UNIQUE INDEX uq_guide_classifications_binding ON public.guide_source_format_classifications USING btree (binding_id)","name":"uq_guide_classifications_binding","table_name":"guide_source_format_classifications"},{"definition":"CREATE UNIQUE INDEX uq_guide_classifications_extraction_lineage ON public.guide_source_format_classifications USING btree (id, binding_id, content_id, setup_generation)","name":"uq_guide_classifications_extraction_lineage","table_name":"guide_source_format_classifications"},{"definition":"CREATE INDEX ix_guide_source_snapshot_items_source_snapshot_id ON public.guide_source_snapshot_items USING btree (source_snapshot_id)","name":"ix_guide_source_snapshot_items_source_snapshot_id","table_name":"guide_source_snapshot_items"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_snapshot_items ON public.guide_source_snapshot_items USING btree (id)","name":"pk_guide_source_snapshot_items","table_name":"guide_source_snapshot_items"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshot_items_exact_lineage ON public.guide_source_snapshot_items USING btree (id, source_snapshot_id)","name":"uq_guide_source_snapshot_items_exact_lineage","table_name":"guide_source_snapshot_items"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshot_items_snapshot_order ON public.guide_source_snapshot_items USING btree (source_snapshot_id, item_order)","name":"uq_guide_source_snapshot_items_snapshot_order","table_name":"guide_source_snapshot_items"},{"definition":"CREATE INDEX ix_guide_source_snapshots_bundle_hash ON public.guide_source_snapshots USING btree (bundle_hash)","name":"ix_guide_source_snapshots_bundle_hash","table_name":"guide_source_snapshots"},{"definition":"CREATE INDEX ix_guide_source_snapshots_guide_id ON public.guide_source_snapshots USING btree (guide_id)","name":"ix_guide_source_snapshots_guide_id","table_name":"guide_source_snapshots"},{"definition":"CREATE INDEX ix_guide_source_snapshots_project_id ON public.guide_source_snapshots USING btree (project_id)","name":"ix_guide_source_snapshots_project_id","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_snapshots ON public.guide_source_snapshots USING btree (id)","name":"pk_guide_source_snapshots","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshots_exact_lineage ON public.guide_source_snapshots USING btree (id, project_id, guide_id)","name":"uq_guide_source_snapshots_exact_lineage","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshots_id_hash ON public.guide_source_snapshots USING btree (id, bundle_hash)","name":"uq_guide_source_snapshots_id_hash","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshots_project_version_hash ON public.guide_source_snapshots USING btree (project_id, guide_version, bundle_hash)","name":"uq_guide_source_snapshots_project_version_hash","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX pk_guide_sufficiency_mutation_idempotency_records ON public.guide_sufficiency_mutation_idempotency_records USING btree (id)","name":"pk_guide_sufficiency_mutation_idempotency_records","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_mutation_operation_identity ON public.guide_sufficiency_mutation_idempotency_records USING btree (operation_id)","name":"uq_sufficiency_mutation_operation_identity","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_mutation_replay_namespace ON public.guide_sufficiency_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key)","name":"uq_sufficiency_mutation_replay_namespace","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_sufficiency_report_source_usage_report_id ON public.guide_sufficiency_report_source_usages USING btree (report_id)","name":"ix_sufficiency_report_source_usage_report_id","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE UNIQUE INDEX pk_guide_sufficiency_report_source_usages ON public.guide_sufficiency_report_source_usages USING btree (id)","name":"pk_guide_sufficiency_report_source_usages","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_report_extraction_usage ON public.guide_sufficiency_report_source_usages USING btree (report_id, extraction_usage_id)","name":"uq_sufficiency_report_extraction_usage","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_report_item_order ON public.guide_sufficiency_report_source_usages USING btree (report_id, item_order)","name":"uq_sufficiency_report_item_order","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_guide_id ON public.guide_sufficiency_reports USING btree (guide_id)","name":"ix_guide_sufficiency_reports_guide_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_project_id ON public.guide_sufficiency_reports USING btree (project_id)","name":"ix_guide_sufficiency_reports_project_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_project_setup_run_id ON public.guide_sufficiency_reports USING btree (project_setup_run_id)","name":"ix_guide_sufficiency_reports_project_setup_run_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_source_snapshot_id ON public.guide_sufficiency_reports USING btree (source_snapshot_id)","name":"ix_guide_sufficiency_reports_source_snapshot_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_status ON public.guide_sufficiency_reports USING btree (status)","name":"ix_guide_sufficiency_reports_status","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX pk_guide_sufficiency_reports ON public.guide_sufficiency_reports USING btree (id)","name":"pk_guide_sufficiency_reports","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX uq_guide_sufficiency_reports_diagnostic_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NULL)","name":"uq_guide_sufficiency_reports_diagnostic_snapshot","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX uq_guide_sufficiency_reports_verified_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NOT NULL)","name":"uq_guide_sufficiency_reports_verified_snapshot","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX pk_iso_4217_currency_codes ON public.iso_4217_currency_codes USING btree (code)","name":"pk_iso_4217_currency_codes","table_name":"iso_4217_currency_codes"},{"definition":"CREATE UNIQUE INDEX pk_legacy_actor_identities ON public.legacy_actor_identities USING btree (actor_id)","name":"pk_legacy_actor_identities","table_name":"legacy_actor_identities"},{"definition":"CREATE UNIQUE INDEX uq_legacy_actor_identities_external_identity ON public.legacy_actor_identities USING btree (external_issuer, external_subject)","name":"uq_legacy_actor_identities_external_identity","table_name":"legacy_actor_identities"},{"definition":"CREATE INDEX ix_legacy_workflow_eligibility_actor_id ON public.legacy_workflow_eligibility USING btree (actor_id)","name":"ix_legacy_workflow_eligibility_actor_id","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE INDEX ix_legacy_workflow_eligibility_profile_type ON public.legacy_workflow_eligibility USING btree (profile_type)","name":"ix_legacy_workflow_eligibility_profile_type","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE INDEX ix_legacy_workflow_eligibility_status ON public.legacy_workflow_eligibility USING btree (status)","name":"ix_legacy_workflow_eligibility_status","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE UNIQUE INDEX pk_legacy_workflow_eligibility ON public.legacy_workflow_eligibility USING btree (id)","name":"pk_legacy_workflow_eligibility","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE UNIQUE INDEX uq_legacy_workflow_eligibility_actor_type_scope ON public.legacy_workflow_eligibility USING btree (actor_id, profile_type, scope_type, scope_id)","name":"uq_legacy_workflow_eligibility_actor_type_scope","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE INDEX ix_outbox_events_aggregate ON public.outbox_events USING btree (aggregate_type, aggregate_id, occurred_at, event_id)","name":"ix_outbox_events_aggregate","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_eligible ON public.outbox_events USING btree (event_type, delivery_state, next_attempt_at, occurred_at, event_id) WHERE ((delivery_state)::text = ANY (ARRAY['pending', 'retryable']))","name":"ix_outbox_events_eligible","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_expired_claims ON public.outbox_events USING btree (claim_expires_at, event_id) WHERE ((delivery_state)::text = 'claimed'::text)","name":"ix_outbox_events_expired_claims","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_project_drain ON public.outbox_events USING btree (project_id, delivery_state, occurred_at, event_id)","name":"ix_outbox_events_project_drain","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_retention ON public.outbox_events USING btree (finalized_at, event_id) WHERE (((delivery_state)::text = ANY (ARRAY['acknowledged', 'dead_letter', 'cancelled'])) AND (archived_at IS NULL))","name":"ix_outbox_events_retention","table_name":"outbox_events"},{"definition":"CREATE UNIQUE INDEX pk_outbox_events ON public.outbox_events USING btree (event_id)","name":"pk_outbox_events","table_name":"outbox_events"},{"definition":"CREATE UNIQUE INDEX uq_outbox_events_idempotency_key ON public.outbox_events USING btree (idempotency_key)","name":"uq_outbox_events_idempotency_key","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_payment_policies_project_id ON public.payment_policies USING btree (project_id)","name":"ix_payment_policies_project_id","table_name":"payment_policies"},{"definition":"CREATE UNIQUE INDEX pk_payment_policies ON public.payment_policies USING btree (id)","name":"pk_payment_policies","table_name":"payment_policies"},{"definition":"CREATE UNIQUE INDEX uq_payment_policies_project_version ON public.payment_policies USING btree (project_id, guide_version)","name":"uq_payment_policies_project_version","table_name":"payment_policies"},{"definition":"CREATE INDEX ix_policy_mutation_custody_lookup ON public.policy_mutation_idempotency_records USING btree (policy_id, action_id, policy_generation, status)","name":"ix_policy_mutation_custody_lookup","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX pk_policy_mutation_idempotency_records ON public.policy_mutation_idempotency_records USING btree (id)","name":"pk_policy_mutation_idempotency_records","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_policy_mutation_operation_identity ON public.policy_mutation_idempotency_records USING btree (operation_id)","name":"uq_policy_mutation_operation_identity","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_policy_mutation_replay_namespace ON public.policy_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)","name":"uq_policy_mutation_replay_namespace","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_pre_submit_checker_compiled_hash ON public.pre_submit_checker_policies USING btree (compiled_bundle_hash)","name":"ix_pre_submit_checker_compiled_hash","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_effective ON public.pre_submit_checker_policies USING btree (effective_policy_id)","name":"ix_pre_submit_checker_effective","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_effective_hash ON public.pre_submit_checker_policies USING btree (effective_policy_hash)","name":"ix_pre_submit_checker_effective_hash","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_guide ON public.pre_submit_checker_policies USING btree (guide_id)","name":"ix_pre_submit_checker_guide","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_lifecycle ON public.pre_submit_checker_policies USING btree (lifecycle_status)","name":"ix_pre_submit_checker_lifecycle","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_project ON public.pre_submit_checker_policies USING btree (project_id)","name":"ix_pre_submit_checker_project","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_source_snapshot ON public.pre_submit_checker_policies USING btree (source_snapshot_id)","name":"ix_pre_submit_checker_source_snapshot","table_name":"pre_submit_checker_policies"},{"definition":"CREATE UNIQUE INDEX pk_pre_submit_checker_policies ON public.pre_submit_checker_policies USING btree (id)","name":"pk_pre_submit_checker_policies","table_name":"pre_submit_checker_policies"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_checker_policies_id_compiled_bundle_hash ON public.pre_submit_checker_policies USING btree (id, compiled_bundle_hash)","name":"uq_pre_submit_checker_policies_id_compiled_bundle_hash","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_evidence_results_evidence_set_id ON public.pre_submit_evidence_results USING btree (evidence_set_id)","name":"ix_pre_submit_evidence_results_evidence_set_id","table_name":"pre_submit_evidence_results"},{"definition":"CREATE UNIQUE INDEX pk_pre_submit_evidence_results ON public.pre_submit_evidence_results USING btree (id)","name":"pk_pre_submit_evidence_results","table_name":"pre_submit_evidence_results"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_result_definition ON public.pre_submit_evidence_results USING btree (evidence_set_id, definition_id)","name":"uq_pre_submit_result_definition","table_name":"pre_submit_evidence_results"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_result_order ON public.pre_submit_evidence_results USING btree (evidence_set_id, result_order)","name":"uq_pre_submit_result_order","table_name":"pre_submit_evidence_results"},{"definition":"CREATE INDEX ix_pre_submit_evidence_sets_actor_profile_id ON public.pre_submit_evidence_sets USING btree (actor_profile_id)","name":"ix_pre_submit_evidence_sets_actor_profile_id","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE INDEX ix_pre_submit_evidence_sets_project_id ON public.pre_submit_evidence_sets USING btree (project_id)","name":"ix_pre_submit_evidence_sets_project_id","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE INDEX ix_pre_submit_evidence_sets_task_id ON public.pre_submit_evidence_sets USING btree (task_id)","name":"ix_pre_submit_evidence_sets_task_id","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE UNIQUE INDEX pk_pre_submit_evidence_sets ON public.pre_submit_evidence_sets USING btree (id)","name":"pk_pre_submit_evidence_sets","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_evidence_operation ON public.pre_submit_evidence_sets USING btree (operation_identity)","name":"uq_pre_submit_evidence_operation","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE INDEX ix_compensation_binding_adapter_actor ON public.project_compensation_adapter_bindings USING btree (adapter_actor_id, status, id)","name":"ix_compensation_binding_adapter_actor","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX pk_project_compensation_adapter_bindings ON public.project_compensation_adapter_bindings USING btree (id)","name":"pk_project_compensation_adapter_bindings","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX uq_compensation_binding_active_project_instrument ON public.project_compensation_adapter_bindings USING btree (project_id, instrument_type) WHERE ((status)::text = 'active'::text)","name":"uq_compensation_binding_active_project_instrument","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX uq_compensation_binding_ownership ON public.project_compensation_adapter_bindings USING btree (id, project_id, instrument_type)","name":"uq_compensation_binding_ownership","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX pk_project_compensation_units ON public.project_compensation_units USING btree (project_id, instrument_type, unit_code)","name":"pk_project_compensation_units","table_name":"project_compensation_units"},{"definition":"CREATE UNIQUE INDEX pk_project_create_idempotency_records ON public.project_create_idempotency_records USING btree (id)","name":"pk_project_create_idempotency_records","table_name":"project_create_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_project_create_operation_identity ON public.project_create_idempotency_records USING btree (operation_id)","name":"uq_project_create_operation_identity","table_name":"project_create_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_project_create_project_identity ON public.project_create_idempotency_records USING btree (project_id)","name":"uq_project_create_project_identity","table_name":"project_create_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_project_create_replay_namespace ON public.project_create_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)","name":"uq_project_create_replay_namespace","table_name":"project_create_idempotency_records"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_guide_id ON public.project_guide_compilation_attempts USING btree (guide_id)","name":"ix_project_guide_compilation_attempts_guide_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_project_id ON public.project_guide_compilation_attempts USING btree (project_id)","name":"ix_project_guide_compilation_attempts_project_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_setup_run_id ON public.project_guide_compilation_attempts USING btree (setup_run_id)","name":"ix_project_guide_compilation_attempts_setup_run_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_source_snapshot_id ON public.project_guide_compilation_attempts USING btree (source_snapshot_id)","name":"ix_project_guide_compilation_attempts_source_snapshot_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE UNIQUE INDEX pk_project_guide_compilation_attempts ON public.project_guide_compilation_attempts USING btree (id)","name":"pk_project_guide_compilation_attempts","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE UNIQUE INDEX uq_compilation_attempt_provider_key ON public.project_guide_compilation_attempts USING btree (provider_idempotency_key)","name":"uq_compilation_attempt_provider_key","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE UNIQUE INDEX uq_compilation_attempt_setup_generation ON public.project_guide_compilation_attempts USING btree (setup_run_id, setup_generation)","name":"uq_compilation_attempt_setup_generation","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilations_guide_id ON public.project_guide_compilations USING btree (guide_id)","name":"ix_project_guide_compilations_guide_id","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guide_compilations_project_id ON public.project_guide_compilations USING btree (project_id)","name":"ix_project_guide_compilations_project_id","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guide_compilations_setup_run_id ON public.project_guide_compilations USING btree (setup_run_id)","name":"ix_project_guide_compilations_setup_run_id","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guide_compilations_source_snapshot_id ON public.project_guide_compilations USING btree (source_snapshot_id)","name":"ix_project_guide_compilations_source_snapshot_id","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX pk_project_guide_compilations ON public.project_guide_compilations USING btree (id)","name":"pk_project_guide_compilations","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_attempt ON public.project_guide_compilations USING btree (attempt_id)","name":"uq_project_guide_compilation_attempt","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_id_attempt ON public.project_guide_compilations USING btree (id, attempt_id)","name":"uq_project_guide_compilation_id_attempt","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_predecessor ON public.project_guide_compilations USING btree (supersedes_compilation_id)","name":"uq_project_guide_compilation_predecessor","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_root ON public.project_guide_compilations USING btree (project_id, guide_id) WHERE (supersedes_compilation_id IS NULL)","name":"uq_project_guide_compilation_root","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_scope ON public.project_guide_compilations USING btree (id, project_id, guide_id)","name":"uq_project_guide_compilation_scope","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guides_project_id ON public.project_guides USING btree (project_id)","name":"ix_project_guides_project_id","table_name":"project_guides"},{"definition":"CREATE INDEX ix_project_guides_status ON public.project_guides USING btree (status)","name":"ix_project_guides_status","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX pk_project_guides ON public.project_guides USING btree (id)","name":"pk_project_guides","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX uq_project_guides_id_project_version ON public.project_guides USING btree (id, project_id, version)","name":"uq_project_guides_id_project_version","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX uq_project_guides_one_active_per_project ON public.project_guides USING btree (project_id) WHERE ((status)::text = 'active'::text)","name":"uq_project_guides_one_active_per_project","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX uq_project_guides_project_version ON public.project_guides USING btree (project_id, version)","name":"uq_project_guides_project_version","table_name":"project_guides"},{"definition":"CREATE INDEX ix_project_role_grants_actor_role_status ON public.project_role_grants USING btree (actor_profile_id, role, status)","name":"ix_project_role_grants_actor_role_status","table_name":"project_role_grants"},{"definition":"CREATE INDEX ix_project_role_grants_project_actor_role_status ON public.project_role_grants USING btree (project_id, actor_profile_id, role, status)","name":"ix_project_role_grants_project_actor_role_status","table_name":"project_role_grants"},{"definition":"CREATE UNIQUE INDEX pk_project_role_grants ON public.project_role_grants USING btree (id)","name":"pk_project_role_grants","table_name":"project_role_grants"},{"definition":"CREATE UNIQUE INDEX uq_project_role_grants_active_exact_role ON public.project_role_grants USING btree (project_id, actor_profile_id, role) WHERE ((status)::text = 'active'::text)","name":"uq_project_role_grants_active_exact_role","table_name":"project_role_grants"},{"definition":"CREATE UNIQUE INDEX grant_reference ON public.project_role_qualification_snapshots USING btree (id, actor_profile_id, project_id, requested_role)","name":"grant_reference","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE INDEX ix_project_role_qualification_snapshots_history ON public.project_role_qualification_snapshots USING btree (project_id, actor_profile_id, requested_role, captured_at)","name":"ix_project_role_qualification_snapshots_history","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE UNIQUE INDEX pk_project_role_qualification_snapshots ON public.project_role_qualification_snapshots USING btree (id)","name":"pk_project_role_qualification_snapshots","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE INDEX ix_project_setup_runs_celery_task_id ON public.project_setup_runs USING btree (celery_task_id)","name":"ix_project_setup_runs_celery_task_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_continuation_verification_job_id ON public.project_setup_runs USING btree (continuation_verification_job_id)","name":"ix_project_setup_runs_continuation_verification_job_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_error_artifact_incident_id ON public.project_setup_runs USING btree (error_artifact_incident_id)","name":"ix_project_setup_runs_error_artifact_incident_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_guide_id ON public.project_setup_runs USING btree (guide_id)","name":"ix_project_setup_runs_guide_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_output_post_submit_checker_policy_id ON public.project_setup_runs USING btree (output_post_submit_checker_policy_id)","name":"ix_project_setup_runs_output_post_submit_checker_policy_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_output_submission_artifact_policy_id ON public.project_setup_runs USING btree (output_submission_artifact_policy_id)","name":"ix_project_setup_runs_output_submission_artifact_policy_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_output_sufficiency_report_id ON public.project_setup_runs USING btree (output_sufficiency_report_id)","name":"ix_project_setup_runs_output_sufficiency_report_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_project_id ON public.project_setup_runs USING btree (project_id)","name":"ix_project_setup_runs_project_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_source_snapshot_id ON public.project_setup_runs USING btree (source_snapshot_id)","name":"ix_project_setup_runs_source_snapshot_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_status ON public.project_setup_runs USING btree (status)","name":"ix_project_setup_runs_status","table_name":"project_setup_runs"},{"definition":"CREATE UNIQUE INDEX pk_project_setup_runs ON public.project_setup_runs USING btree (id)","name":"pk_project_setup_runs","table_name":"project_setup_runs"},{"definition":"CREATE UNIQUE INDEX uq_project_setup_runs_exact_generation ON public.project_setup_runs USING btree (id, project_id, guide_id, source_snapshot_id, setup_generation)","name":"uq_project_setup_runs_exact_generation","table_name":"project_setup_runs"},{"definition":"CREATE UNIQUE INDEX uq_project_setup_runs_guide_generation ON public.project_setup_runs USING btree (guide_id, setup_generation)","name":"uq_project_setup_runs_guide_generation","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_projects_slug ON public.projects USING btree (slug)","name":"ix_projects_slug","table_name":"projects"},{"definition":"CREATE INDEX ix_projects_status ON public.projects USING btree (status)","name":"ix_projects_status","table_name":"projects"},{"definition":"CREATE UNIQUE INDEX pk_projects ON public.projects USING btree (id)","name":"pk_projects","table_name":"projects"},{"definition":"CREATE UNIQUE INDEX uq_projects_slug ON public.projects USING btree (slug)","name":"uq_projects_slug","table_name":"projects"},{"definition":"CREATE INDEX ix_review_admission_submission ON public.review_admission_idempotency_records USING btree (submission_id, status, created_at, id)","name":"ix_review_admission_submission","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX pk_review_admission_idempotency_records ON public.review_admission_idempotency_records USING btree (id)","name":"pk_review_admission_idempotency_records","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_review_admission_checker_run ON public.review_admission_idempotency_records USING btree (admitting_checker_run_id)","name":"uq_review_admission_checker_run","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_review_admission_operation ON public.review_admission_idempotency_records USING btree (operation_id)","name":"uq_review_admission_operation","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_review_admission_replay_key ON public.review_admission_idempotency_records USING btree (idempotency_key)","name":"uq_review_admission_replay_key","table_name":"review_admission_idempotency_records"},{"definition":"CREATE INDEX ix_review_lease_expiry ON public.review_leases USING btree (status, expires_at, id)","name":"ix_review_lease_expiry","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX pk_review_leases ON public.review_leases USING btree (id)","name":"pk_review_leases","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_active_queue ON public.review_leases USING btree (review_queue_entry_id) WHERE ((status)::text = 'active'::text)","name":"uq_review_lease_active_queue","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_active_reviewer ON public.review_leases USING btree (reviewer_id) WHERE ((status)::text = 'active'::text)","name":"uq_review_lease_active_reviewer","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_attempt ON public.review_leases USING btree (review_queue_entry_id, attempt_generation)","name":"uq_review_lease_attempt","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_queue_identity ON public.review_leases USING btree (review_queue_entry_id, id)","name":"uq_review_lease_queue_identity","table_name":"review_leases"},{"definition":"CREATE INDEX ix_review_policies_project_id ON public.review_policies USING btree (project_id)","name":"ix_review_policies_project_id","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX pk_review_policies ON public.review_policies USING btree (id)","name":"pk_review_policies","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX uq_review_policies_project_version_generation ON public.review_policies USING btree (project_id, guide_version, policy_generation)","name":"uq_review_policies_project_version_generation","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX uq_review_policy_lineage ON public.review_policies USING btree (id, policy_generation, policy_hash)","name":"uq_review_policy_lineage","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX uq_review_policy_scoped_lineage ON public.review_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)","name":"uq_review_policy_scoped_lineage","table_name":"review_policies"},{"definition":"CREATE INDEX ix_review_queue_preference ON public.review_queue_entries USING btree (preferred_reviewer_id, queue_state, preference_expires_at, id)","name":"ix_review_queue_preference","table_name":"review_queue_entries"},{"definition":"CREATE INDEX ix_review_queue_selection ON public.review_queue_entries USING btree (project_id, queue_state, routing_mode, first_queued_at, id)","name":"ix_review_queue_selection","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX pk_review_queue_entries ON public.review_queue_entries USING btree (id)","name":"pk_review_queue_entries","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX uq_review_queue_admission_identity ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)","name":"uq_review_queue_admission_identity","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX uq_review_queue_lease_lineage ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version)","name":"uq_review_queue_lease_lineage","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX uq_review_queue_submission ON public.review_queue_entries USING btree (submission_id)","name":"uq_review_queue_submission","table_name":"review_queue_entries"},{"definition":"CREATE INDEX ix_revision_policies_project_id ON public.revision_policies USING btree (project_id)","name":"ix_revision_policies_project_id","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX pk_revision_policies ON public.revision_policies USING btree (id)","name":"pk_revision_policies","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX uq_revision_policies_project_version_generation ON public.revision_policies USING btree (project_id, guide_version, policy_generation)","name":"uq_revision_policies_project_version_generation","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX uq_revision_policy_lineage ON public.revision_policies USING btree (id, policy_generation, policy_hash)","name":"uq_revision_policy_lineage","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX uq_revision_policy_scoped_lineage ON public.revision_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)","name":"uq_revision_policy_scoped_lineage","table_name":"revision_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_guide_id ON public.submission_artifact_policies USING btree (guide_id)","name":"ix_submission_artifact_policies_guide_id","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_lifecycle_status ON public.submission_artifact_policies USING btree (lifecycle_status)","name":"ix_submission_artifact_policies_lifecycle_status","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_policy_hash ON public.submission_artifact_policies USING btree (policy_hash)","name":"ix_submission_artifact_policies_policy_hash","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_project_id ON public.submission_artifact_policies USING btree (project_id)","name":"ix_submission_artifact_policies_project_id","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_source_snapshot_id ON public.submission_artifact_policies USING btree (source_snapshot_id)","name":"ix_submission_artifact_policies_source_snapshot_id","table_name":"submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX pk_submission_artifact_policies ON public.submission_artifact_policies USING btree (id)","name":"pk_submission_artifact_policies","table_name":"submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX uq_submission_artifact_policies_id_hash ON public.submission_artifact_policies USING btree (id, policy_hash)","name":"uq_submission_artifact_policies_id_hash","table_name":"submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX uq_submission_artifact_policies_project_version_policy ON public.submission_artifact_policies USING btree (project_id, guide_version, policy_version)","name":"uq_submission_artifact_policies_project_version_policy","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_actor_profile_id ON public.submission_bundle_admissions USING btree (actor_profile_id)","name":"ix_submission_bundle_admissions_actor_profile_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_artifact_content_id ON public.submission_bundle_admissions USING btree (artifact_content_id)","name":"ix_submission_bundle_admissions_artifact_content_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_pre_submit_evidence_set_id ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)","name":"ix_submission_bundle_admissions_pre_submit_evidence_set_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_project_id ON public.submission_bundle_admissions USING btree (project_id)","name":"ix_submission_bundle_admissions_project_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_status ON public.submission_bundle_admissions USING btree (status)","name":"ix_submission_bundle_admissions_status","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_task_id ON public.submission_bundle_admissions USING btree (task_id)","name":"ix_submission_bundle_admissions_task_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX pk_submission_bundle_admissions ON public.submission_bundle_admissions USING btree (id)","name":"pk_submission_bundle_admissions","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_consumer ON public.submission_bundle_admissions USING btree (consumed_by_submission_id) WHERE (consumed_by_submission_id IS NOT NULL)","name":"uq_submission_bundle_admission_consumer","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_evidence ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)","name":"uq_submission_bundle_admission_evidence","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_intent ON public.submission_bundle_admissions USING btree (durable_intent_id)","name":"uq_submission_bundle_admission_intent","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_verification ON public.submission_bundle_admissions USING btree (verification_receipt_id)","name":"uq_submission_bundle_admission_verification","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_durable_intents_pre_submit_evidence_set_id ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)","name":"ix_submission_bundle_durable_intents_pre_submit_evidence_set_id","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE INDEX ix_submission_bundle_durable_intents_put_attempt_id ON public.submission_bundle_durable_intents USING btree (put_attempt_id)","name":"ix_submission_bundle_durable_intents_put_attempt_id","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX pk_submission_bundle_durable_intents ON public.submission_bundle_durable_intents USING btree (id)","name":"pk_submission_bundle_durable_intents","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_intent_evidence ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)","name":"uq_submission_bundle_intent_evidence","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_intent_put_attempt ON public.submission_bundle_durable_intents USING btree (put_attempt_id)","name":"uq_submission_bundle_intent_put_attempt","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX pk_submission_policy_mutation_idempotency_records ON public.submission_policy_mutation_idempotency_records USING btree (id)","name":"pk_submission_policy_mutation_idempotency_records","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_committed_policy_action ON public.submission_policy_mutation_idempotency_records USING btree (committed_policy_id, action_id) WHERE ((status)::text = 'committed'::text)","name":"uq_submission_policy_committed_policy_action","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_human_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key) WHERE (service_identity IS NULL)","name":"uq_submission_policy_human_replay_namespace","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_operation_identity ON public.submission_policy_mutation_idempotency_records USING btree (operation_id)","name":"uq_submission_policy_operation_identity","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_service_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, setup_run_id, setup_generation, setup_task_id, correlation_id, action_id) WHERE (service_identity IS NOT NULL)","name":"uq_submission_policy_service_replay_namespace","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_submissions_contributor_id ON public.submissions USING btree (contributor_id)","name":"ix_submissions_contributor_id","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_effective_policy_hash ON public.submissions USING btree (locked_effective_project_submission_artifact_policy_hash)","name":"ix_submissions_locked_effective_policy_hash","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_post_submit_policy_hash ON public.submissions USING btree (locked_post_submit_checker_policy_hash)","name":"ix_submissions_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_pre_submit_checker_hash ON public.submissions USING btree (locked_pre_submit_checker_bundle_hash)","name":"ix_submissions_locked_pre_submit_checker_hash","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_source_snapshot ON public.submissions USING btree (locked_guide_source_snapshot_id)","name":"ix_submissions_locked_source_snapshot","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_status ON public.submissions USING btree (status)","name":"ix_submissions_status","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_supersedes_submission_id ON public.submissions USING btree (supersedes_submission_id)","name":"ix_submissions_supersedes_submission_id","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_task_id ON public.submissions USING btree (task_id)","name":"ix_submissions_task_id","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX pk_submissions ON public.submissions USING btree (id)","name":"pk_submissions","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_id_locked_post_submit_policy_hash ON public.submissions USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","name":"uq_submissions_id_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_id_task_version ON public.submissions USING btree (id, task_id, version)","name":"uq_submissions_id_task_version","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_id_version ON public.submissions USING btree (id, version)","name":"uq_submissions_id_version","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_task_version ON public.submissions USING btree (task_id, version)","name":"uq_submissions_task_version","table_name":"submissions"},{"definition":"CREATE INDEX ix_task_assignments_contributor_id ON public.task_assignments USING btree (contributor_id)","name":"ix_task_assignments_contributor_id","table_name":"task_assignments"},{"definition":"CREATE INDEX ix_task_assignments_status ON public.task_assignments USING btree (status)","name":"ix_task_assignments_status","table_name":"task_assignments"},{"definition":"CREATE INDEX ix_task_assignments_task_id ON public.task_assignments USING btree (task_id)","name":"ix_task_assignments_task_id","table_name":"task_assignments"},{"definition":"CREATE UNIQUE INDEX pk_task_assignments ON public.task_assignments USING btree (id)","name":"pk_task_assignments","table_name":"task_assignments"},{"definition":"CREATE UNIQUE INDEX uq_task_assignments_id_task_contributor ON public.task_assignments USING btree (id, task_id, contributor_id)","name":"uq_task_assignments_id_task_contributor","table_name":"task_assignments"},{"definition":"CREATE UNIQUE INDEX uq_task_assignments_one_active_per_task ON public.task_assignments USING btree (task_id) WHERE ((status)::text = 'active'::text)","name":"uq_task_assignments_one_active_per_task","table_name":"task_assignments"},{"definition":"CREATE INDEX ix_workstream_tasks_assigned_to ON public.workstream_tasks USING btree (assigned_to)","name":"ix_workstream_tasks_assigned_to","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_effective_policy_hash ON public.workstream_tasks USING btree (locked_effective_project_submission_artifact_policy_hash)","name":"ix_workstream_tasks_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (locked_post_submit_checker_policy_hash)","name":"ix_workstream_tasks_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (locked_pre_submit_checker_bundle_hash)","name":"ix_workstream_tasks_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_source_snapshot ON public.workstream_tasks USING btree (locked_guide_source_snapshot_id)","name":"ix_workstream_tasks_locked_source_snapshot","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_project_id ON public.workstream_tasks USING btree (project_id)","name":"ix_workstream_tasks_project_id","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_status ON public.workstream_tasks USING btree (status)","name":"ix_workstream_tasks_status","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX pk_workstream_tasks ON public.workstream_tasks USING btree (id)","name":"pk_workstream_tasks","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_effective_policy_hash ON public.workstream_tasks USING btree (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","name":"uq_workstream_tasks_id_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_guide ON public.workstream_tasks USING btree (id, locked_guide_version)","name":"uq_workstream_tasks_id_locked_guide","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_payment_policy ON public.workstream_tasks USING btree (id, locked_payment_policy_version)","name":"uq_workstream_tasks_id_locked_payment_policy","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","name":"uq_workstream_tasks_id_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","name":"uq_workstream_tasks_id_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_review_policy ON public.workstream_tasks USING btree (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","name":"uq_workstream_tasks_id_locked_review_policy","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_revision_policy ON public.workstream_tasks USING btree (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","name":"uq_workstream_tasks_id_locked_revision_policy","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_source_snapshot_hash ON public.workstream_tasks USING btree (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","name":"uq_workstream_tasks_id_locked_source_snapshot_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_project ON public.workstream_tasks USING btree (id, project_id)","name":"uq_workstream_tasks_id_project","table_name":"workstream_tasks"}],"policies":[],"reference_rows":{"actor_profile_migration_state":[{"classified_count":0,"envelope_sha256":null,"id":1,"manifest_sha256":null,"migrated_at":"2026-08-11T08:18:03.063940+00:00","schema_version":1,"service_identity_database_binding":"postgres-v1:aa1108b4a868ca4330673d1bbe499d99c330d196994696d89e56cf09bfc3c93e","service_identity_envelope_sha256":null,"service_identity_manifest_sha256":null,"service_identity_mapped_count":0,"service_identity_source_row_set_sha256":"4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945","source_row_set_sha256":"4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"}],"authority_control":[{"bootstrap_completed":false,"bootstrap_grant_id":null,"created_at":"2026-08-11T08:18:13.474128+00:00","id":1,"updated_at":"2026-08-11T08:18:13.474148+00:00","version":0}],"iso_4217_currency_codes":[{"code":"AED"},{"code":"AFN"},{"code":"ALL"},{"code":"AMD"},{"code":"AOA"},{"code":"ARS"},{"code":"AUD"},{"code":"AWG"},{"code":"AZN"},{"code":"BAM"},{"code":"BBD"},{"code":"BDT"},{"code":"BHD"},{"code":"BIF"},{"code":"BMD"},{"code":"BND"},{"code":"BOB"},{"code":"BOV"},{"code":"BRL"},{"code":"BSD"},{"code":"BTN"},{"code":"BWP"},{"code":"BYN"},{"code":"BZD"},{"code":"CAD"},{"code":"CDF"},{"code":"CHE"},{"code":"CHF"},{"code":"CHW"},{"code":"CLF"},{"code":"CLP"},{"code":"CNY"},{"code":"COP"},{"code":"COU"},{"code":"CRC"},{"code":"CUP"},{"code":"CVE"},{"code":"CZK"},{"code":"DJF"},{"code":"DKK"},{"code":"DOP"},{"code":"DZD"},{"code":"EGP"},{"code":"ERN"},{"code":"ETB"},{"code":"EUR"},{"code":"FJD"},{"code":"FKP"},{"code":"GBP"},{"code":"GEL"},{"code":"GHS"},{"code":"GIP"},{"code":"GMD"},{"code":"GNF"},{"code":"GTQ"},{"code":"GYD"},{"code":"HKD"},{"code":"HNL"},{"code":"HTG"},{"code":"HUF"},{"code":"IDR"},{"code":"ILS"},{"code":"INR"},{"code":"IQD"},{"code":"IRR"},{"code":"ISK"},{"code":"JMD"},{"code":"JOD"},{"code":"JPY"},{"code":"KES"},{"code":"KGS"},{"code":"KHR"},{"code":"KMF"},{"code":"KPW"},{"code":"KRW"},{"code":"KWD"},{"code":"KYD"},{"code":"KZT"},{"code":"LAK"},{"code":"LBP"},{"code":"LKR"},{"code":"LRD"},{"code":"LSL"},{"code":"LYD"},{"code":"MAD"},{"code":"MDL"},{"code":"MGA"},{"code":"MKD"},{"code":"MMK"},{"code":"MNT"},{"code":"MOP"},{"code":"MRU"},{"code":"MUR"},{"code":"MVR"},{"code":"MWK"},{"code":"MXN"},{"code":"MXV"},{"code":"MYR"},{"code":"MZN"},{"code":"NAD"},{"code":"NGN"},{"code":"NIO"},{"code":"NOK"},{"code":"NPR"},{"code":"NZD"},{"code":"OMR"},{"code":"PAB"},{"code":"PEN"},{"code":"PGK"},{"code":"PHP"},{"code":"PKR"},{"code":"PLN"},{"code":"PYG"},{"code":"QAR"},{"code":"RON"},{"code":"RSD"},{"code":"RUB"},{"code":"RWF"},{"code":"SAR"},{"code":"SBD"},{"code":"SCR"},{"code":"SDG"},{"code":"SEK"},{"code":"SGD"},{"code":"SHP"},{"code":"SLE"},{"code":"SOS"},{"code":"SRD"},{"code":"SSP"},{"code":"STN"},{"code":"SVC"},{"code":"SYP"},{"code":"SZL"},{"code":"THB"},{"code":"TJS"},{"code":"TMT"},{"code":"TND"},{"code":"TOP"},{"code":"TRY"},{"code":"TTD"},{"code":"TWD"},{"code":"TZS"},{"code":"UAH"},{"code":"UGX"},{"code":"USD"},{"code":"USN"},{"code":"UYI"},{"code":"UYU"},{"code":"UYW"},{"code":"UZS"},{"code":"VED"},{"code":"VES"},{"code":"VND"},{"code":"VUV"},{"code":"WST"},{"code":"XAD"},{"code":"XAF"},{"code":"XAG"},{"code":"XAU"},{"code":"XBA"},{"code":"XBB"},{"code":"XBC"},{"code":"XBD"},{"code":"XCD"},{"code":"XCG"},{"code":"XDR"},{"code":"XOF"},{"code":"XPD"},{"code":"XPF"},{"code":"XPT"},{"code":"XSU"},{"code":"XTS"},{"code":"XUA"},{"code":"XXX"},{"code":"YER"},{"code":"ZAR"},{"code":"ZMW"},{"code":"ZWG"}]},"routines":[{"arguments":"event_name text, before_state json, after_state json, envelope_project_id text","definition":"CREATE OR REPLACE FUNCTION public.authority_event_facts_are_safe(event_name text, before_state json, after_state json, envelope_project_id text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE AS $function$ begin if not (event_name='AuthorityInvalidationRequested' and before_state is not null and after_state is not null and coalesce(before_state::jsonb ? 'future_obligation', false) and coalesce(after_state::jsonb ? 'future_obligation', false)) and ((before_state is not null and not authority_facts_are_safe(before_state)) or (after_state is not null and not authority_facts_are_safe(after_state))) then return false; end if; case event_name when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"human\",\"provisioning_method\":\"automatic_first_access\"}'::jsonb; when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"service\",\"provisioning_method\":\"manual_service_provisioning\"}'::jsonb; when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( '{\"status\":\"active\",\"subject_kind\":\"human\"}'::jsonb, '{\"status\":\"active\",\"subject_kind\":\"service\"}'::jsonb); when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"revoked\"}'::jsonb; when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{\"status\":\"revoked\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileSuspended' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"suspended\"}'::jsonb; when 'ActorProfileReactivated' then return before_state::jsonb='{\"status\":\"suspended\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileDeactivated' then return before_state::jsonb in ('{\"status\":\"active\"}'::jsonb,'{\"status\":\"suspended\"}'::jsonb) and after_state::jsonb='{\"status\":\"deactivated\"}'::jsonb; when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','adjudicator'],'active',true,envelope_project_id); when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then return authority_grant_facts_are_safe(before_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'active',true,envelope_project_id) and authority_grant_facts_are_safe(after_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'revoked',false,envelope_project_id) and before_state->>'role'=after_state->>'role' and before_state->>'scope_type'=after_state->>'scope_type' and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{\"status\":\"captured\"}'::jsonb; when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; when 'SensitiveAuthorizationAllowed' then return before_state is null and ( after_state::jsonb = '{\"allowed\": true}'::jsonb or ( after_state::jsonb->'allowed' = 'true'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'SensitiveAuthorizationDenied' then return before_state is null and ( after_state::jsonb = '{\"allowed\": false}'::jsonb or ( after_state::jsonb->'allowed' = 'false'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'AuthorityInvalidationRequested' then return (before_state::jsonb = '{\"effective\": true}'::jsonb and after_state::jsonb = '{\"effective\": false}'::jsonb) or (before_state::jsonb = '{\"effective\": false}'::jsonb and after_state::jsonb = '{\"effective\": true}'::jsonb) or ( jsonb_typeof(before_state::jsonb)='object' and jsonb_typeof(after_state::jsonb)='object' and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and before_state::jsonb->'effective'='true'::jsonb and after_state::jsonb->'effective'='false'::jsonb and jsonb_typeof(before_state::jsonb->'role')='string' and jsonb_typeof(before_state::jsonb->'scope_type')='string' and jsonb_typeof(before_state::jsonb->'scope_id')='string' and jsonb_typeof(before_state::jsonb->'future_obligation')='string' and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') and before_state::jsonb->>'scope_type'='project' and before_state::jsonb->>'scope_id'=envelope_project_id and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) ); else return false; end case; end $function$","name":"authority_event_facts_are_safe"},{"arguments":"facts json","definition":"CREATE OR REPLACE FUNCTION public.authority_facts_are_safe(facts json) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select json_typeof(facts) = 'object' and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) and not exists ( select 1 from json_each(facts) item where item.key not in ( 'status', 'subject_kind', 'provisioning_method', 'role', 'scope_type', 'scope_id', 'effective', 'allowed', 'resource_context_digest' ) or case item.key when 'status' then item.value #>> '{}' not in ( 'active', 'suspended', 'deactivated', 'revoked', 'captured' ) when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') when 'provisioning_method' then item.value #>> '{}' not in ( 'automatic_first_access', 'manual_service_provisioning' ) when 'role' then item.value #>> '{}' not in ( 'access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' ) when 'scope_type' then item.value #>> '{}' not in ('system', 'project') when 'scope_id' then (item.value #>> '{}') !~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' when 'effective' then json_typeof(item.value) <> 'boolean' when 'allowed' then json_typeof(item.value) <> 'boolean' when 'resource_context_digest' then (item.value #>> '{}') !~ '^sha256:[0-9a-f]{64}$' else true end ) $function$","name":"authority_facts_are_safe"},{"arguments":"facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text","definition":"CREATE OR REPLACE FUNCTION public.authority_grant_facts_are_safe(facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text) RETURNS boolean LANGUAGE sql IMMUTABLE AS $function$ select authority_facts_are_safe(facts) and facts->>'role' = any(roles) and facts->>'status' = expected_status and (facts->>'effective')::boolean = expected_effective and ( ( facts->>'scope_type' = 'system' and envelope_project_id is null and not facts::jsonb ? 'scope_id' and facts->>'role' not in ('submitter', 'reviewer', 'both') and (select count(*) from json_each(facts)) = 4 ) or ( facts->>'scope_type' = 'project' and envelope_project_id is not null and facts->>'scope_id' = envelope_project_id and facts->>'role' not in ('access_administrator', 'operator') and (select count(*) from json_each(facts)) = 5 ) ) $function$","name":"authority_grant_facts_are_safe"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.enforce_compensation_binding_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compensation_binding_updates_deferred'; return new; end; $function$","name":"enforce_compensation_binding_lifecycle"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_actor_identity_link_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then raise exception 'actor identity link anchor is immutable' using errcode='55000'; end if; if new.status=old.status and (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'identity link attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='revoked' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid identity link revocation attribution' using errcode='23514'; end if; if old.status='revoked' and new.status='active' and ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then raise exception 'invalid identity link reactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status='revoked') or (old.status='revoked' and new.status='active')) then raise exception 'invalid identity link lifecycle transition' using errcode='23514'; end if; return new; end $function$","name":"guard_actor_identity_link_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_actor_profile_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then raise exception 'actor profile identity is immutable' using errcode='55000'; end if; if old.status='deactivated' and new.status <> 'deactivated' then raise exception 'deactivated actor is terminal' using errcode='23514'; end if; if new.status = old.status and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='suspended' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'invalid actor suspension attribution' using errcode='23514'; end if; if old.status='suspended' and new.status='active' and ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then raise exception 'invalid actor reactivation attribution' using errcode='23514'; end if; if new.status='deactivated' and old.status in ('active','suspended') and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid actor deactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status in ('suspended','deactivated')) or (old.status='suspended' and new.status in ('active','deactivated'))) then raise exception 'invalid actor lifecycle transition' using errcode='23514'; end if; new.updated_at = statement_timestamp(); return new; end $function$","name":"guard_actor_profile_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_admin_role_grant() RETURNS trigger LANGUAGE plpgsql AS $function$ declare target_kind text; authorizer admin_role_grants%rowtype; bootstrap_done boolean; begin if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; if tg_op='INSERT' then select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; new.granted_at := clock_timestamp(); if new.granted_by_system_principal is not null then if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; if bootstrap_done is distinct from false or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then raise exception 'bootstrap already completed' using errcode='23514'; end if; else select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; end if; return new; end if; if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, new.granted_by_actor_profile_id,new.granted_by_system_principal, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, old.granted_by_actor_profile_id,old.granted_by_system_principal, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then raise exception 'invalid admin role grant transition' using errcode='23514'; end if; select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$","name":"guard_admin_role_grant"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_artifact_receipt_producer_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id; if request_type is null or (request_type = 'guide' and not ( new.guide_source_item_id is not null and new.checker_run_id is null and new.logical_role is null)) or (request_type = 'checker_output' and not ( new.guide_source_item_id is null and new.checker_run_id is not null and octet_length(new.logical_role) between 1 and 100)) or (request_type = 'submission_bundle' and not ( new.guide_source_item_id is null and new.checker_run_id is null and new.logical_role is null)) then raise exception 'artifact receipt producer reference mismatch' using errcode='23514'; end if; return new; end; $function$","name":"guard_artifact_receipt_producer_reference"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_authority_control() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; if old.id <> 1 or old.bootstrap_completed or old.version <> 0 or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then raise exception 'invalid authority control transition' using errcode='23514'; end if; new.updated_at := clock_timestamp(); return new; end $function$","name":"guard_authority_control"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_authority_idempotency_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare success_count integer; invalidation_count integer; success_id text; qualification_row audit_events%rowtype; success_row audit_events%rowtype; grant_row project_role_grants%rowtype; snapshot_row project_role_qualification_snapshots%rowtype; begin if tg_op = 'INSERT' then if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; new.created_at := statement_timestamp(); new.committed_at := null; return new; elsif tg_op = 'DELETE' then raise exception 'authority idempotency records are immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, new.request_digest,new.created_at) is distinct from (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, old.request_digest,old.created_at) then raise exception 'invalid authority idempotency transition' using errcode='23514'; end if; select count(*), min(id) into success_count, success_id from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type <> 'AuthorityInvalidationRequested'; select count(*) into invalidation_count from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type='AuthorityInvalidationRequested'; if new.operation='project_role_grant.issue' then if success_count <> 2 or invalidation_count <> 0 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued') <> 1 then raise exception 'project role issue evidence pair required' using errcode='23514'; end if; select * into qualification_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured'; select * into success_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued'; select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; select * into snapshot_row from project_role_qualification_snapshots where id=qualification_row.resource_id::uuid; if not found or grant_row.id is null or snapshot_row.id is null or grant_row.qualification_snapshot_id <> snapshot_row.id or grant_row.project_id <> snapshot_row.project_id or grant_row.actor_profile_id <> snapshot_row.actor_profile_id or grant_row.role <> snapshot_row.requested_role or qualification_row.project_id is distinct from grant_row.project_id or success_row.project_id is distinct from grant_row.project_id or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id or success_row.target_actor_ref is distinct from grant_row.actor_profile_id or qualification_row.request_id is distinct from success_row.request_id or qualification_row.correlation_id is distinct from success_row.correlation_id or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind or qualification_row.actor_id is distinct from success_row.actor_id or qualification_row.permission_id is distinct from success_row.permission_id or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then raise exception 'project role issue evidence mismatch' using errcode='23514'; end if; else if success_count <> 1 or invalidation_count <> 1 then raise exception 'authority evidence pair required' using errcode='23514'; end if; select * into success_row from audit_events where id=success_id; end if; if success_row.resource_type <> new.response_resource_type or success_row.resource_id <> new.response_resource_id::text then raise exception 'authority response does not match evidence' using errcode='23514'; end if; new.committed_at := statement_timestamp(); return new; end $function$","name":"guard_authority_idempotency_record"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_contribution_policy_children() RETURNS trigger LANGUAGE plpgsql AS $function$ declare old_parent_status text; declare new_parent_status text; begin if tg_op in ('UPDATE','DELETE') then select status into old_parent_status from contribution_policy_versions where id=old.contribution_policy_version_id for update; end if; if tg_op in ('INSERT','UPDATE') then select status into new_parent_status from contribution_policy_versions where id=new.contribution_policy_version_id for update; end if; if old_parent_status in ('published','retired') or new_parent_status in ('published','retired') then raise exception 'published contribution policy rules and definitions are immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$","name":"guard_contribution_policy_children"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_contribution_policy_version_content() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' and old.status in ('published','retired') then raise exception 'published contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='retired' then raise exception 'retired contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='published' and not ( new.status='retired' and new.id=old.id and new.contribution_policy_id=old.contribution_policy_id and new.project_id=old.project_id and new.version_number=old.version_number and new.created_by=old.created_by and new.created_at=old.created_at and new.published_by=old.published_by and new.published_at=old.published_at and new.retired_by is not null and new.retired_at is not null ) then raise exception 'published contribution policy version content is immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$","name":"guard_contribution_policy_version_content"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_guide_lineage_and_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if (new.id,new.project_id,new.version) is distinct from (old.id,old.project_id,old.version) then raise exception 'guide identity and lineage are immutable' using errcode='23514'; end if; if (new.status,new.approved_by,new.effective_at,new.superseded_at) is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then raise exception 'guide lifecycle mutation requires activation authority' using errcode='23514'; end if; return new; end $function$","name":"guard_guide_lineage_and_lifecycle"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_guide_mutation_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'guide mutation custody is immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status<>'pending' or new.status<>'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, new.operation_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, old.operation_generation,old.created_at) then raise exception 'invalid guide mutation custody transition' using errcode='23514'; end if; return new; end $function$","name":"guard_guide_mutation_idempotency"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_iso_4217_currency_codes() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' using errcode='55000'; end; $function$","name":"guard_iso_4217_currency_codes"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_outbox_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare event_time timestamptz; begin if tg_op = 'TRUNCATE' then raise exception 'outbox events cannot be truncated' using errcode='55000'; elsif tg_op = 'DELETE' then raise exception 'outbox events cannot be deleted' using errcode='55000'; elsif tg_op = 'INSERT' then event_time := statement_timestamp(); new.producer := 'workstream'; new.occurred_at := event_time; new.delivery_state := 'pending'; new.attempt_count := 0; new.next_attempt_at := event_time; new.claim_owner := null; new.claim_generation := 0; new.claimed_at := null; new.claim_expires_at := null; new.last_attempt_at := null; new.last_error_code := null; new.finalized_at := null; new.archived_at := null; return new; end if; if (new.event_id, new.event_type, new.event_version, new.producer, new.aggregate_type, new.aggregate_id, new.project_id, new.correlation_id, new.causation_event_id, new.idempotency_key, new.payload, new.payload_digest, new.occurred_at) is distinct from (old.event_id, old.event_type, old.event_version, old.producer, old.aggregate_type, old.aggregate_id, old.project_id, old.correlation_id, old.causation_event_id, old.idempotency_key, old.payload, old.payload_digest, old.occurred_at) then raise exception 'outbox event envelope is immutable' using errcode='55000'; end if; if new.attempt_count < old.attempt_count or new.claim_generation < old.claim_generation or new.attempt_count <> new.claim_generation then raise exception 'outbox counters cannot regress' using errcode='23514'; end if; if old.archived_at is not null and (new.delivery_state, new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.delivery_state, old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'archived outbox event is closed' using errcode='55000'; end if; if old.delivery_state in ('pending', 'retryable') and new.delivery_state = 'claimed' then if new.attempt_count <> old.attempt_count + 1 or new.claim_generation <> old.claim_generation + 1 or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox claim generation must increment once' using errcode='23514'; end if; elsif old.delivery_state = 'claimed' and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at then raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state = 'dead_letter' and new.delivery_state = 'retryable' and old.archived_at is null then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = 'cancelled' then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.attempt_count, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; end if; elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at) is distinct from (old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at) or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) or (old.archived_at is null and new.archived_at is null) then raise exception 'terminal outbox event permits archival only' using errcode='23514'; end if; else raise exception 'illegal outbox delivery transition' using errcode='23514'; end if; return new; end $function$","name":"guard_outbox_event"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_policy_mutation_replay() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'policy mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'policy mutation replay is immutable' using errcode='55000'; elsif new is not distinct from old then return new; elsif old.status='pending' and new.status='committed' and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest,new.policy_hash, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.policy_id, new.policy_generation,new.created_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest,old.policy_hash, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.policy_id, old.policy_generation,old.created_at) then return new; end if; raise exception 'policy mutation replay is immutable' using errcode='23514'; end $function$","name":"guard_policy_mutation_replay"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_result_membership() RETURNS trigger LANGUAGE plpgsql AS $function$ declare parent_created_at timestamptz; expected_count integer; current_count integer; begin select created_at, result_count into parent_created_at, expected_count from pre_submit_evidence_sets where id=new.evidence_set_id for key share; select count(*) into current_count from pre_submit_evidence_results where evidence_set_id=new.evidence_set_id; if parent_created_at is null or parent_created_at <> transaction_timestamp() or current_count >= expected_count then raise exception 'pre-submit evidence result membership is closed' using errcode='55000'; end if; return new; end; $function$","name":"guard_pre_submit_evidence_result_membership"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_results_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_results rows are immutable' using errcode='55000'; end; $function$","name":"guard_pre_submit_evidence_results_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_set_creation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.created_at is distinct from transaction_timestamp() then raise exception 'pre-submit evidence creation timestamp is invalid' using errcode='55000'; end if; return new; end; $function$","name":"guard_pre_submit_evidence_set_creation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_sets_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_sets rows are immutable' using errcode='55000'; end; $function$","name":"guard_pre_submit_evidence_sets_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_compensation_units() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('UPDATE','DELETE') then raise exception 'project compensation-unit lifecycle behavior is deferred' using errcode='55000'; end if; if new.status <> 'active' then raise exception 'project compensation units must begin active' using errcode='23514'; end if; return new; end; $function$","name":"guard_project_compensation_units"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_create_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'INSERT' then if new.status <> 'pending' or new.committed_at is not null then raise exception 'project create reservation must begin pending' using errcode='23514'; end if; return new; elsif tg_op = 'DELETE' then raise exception 'project create reservations are immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, new.idempotency_key, new.request_digest, new.operation_id, new.project_id, new.operation_generation, new.created_at) is distinct from (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, old.idempotency_key, old.request_digest, old.operation_id, old.project_id, old.operation_generation, old.created_at) then raise exception 'invalid project create reservation transition' using errcode='23514'; end if; return new; end $function$","name":"guard_project_create_idempotency"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_attempt_update() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, new.pre_catalogue_version,new.pre_catalogue_schema_version, new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.provider_idempotency_key) is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, old.source_snapshot_hash,old.setup_run_id,old.setup_generation, old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, old.pre_catalogue_version,old.pre_catalogue_schema_version, old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, old.agent_identity,old.agent_version,old.instruction_version, old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; if new.reserved_at is distinct from old.reserved_at then raise exception 'compilation reservation timestamp is immutable'; end if; if new.provider_uncertain_at is distinct from old.provider_uncertain_at and not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then raise exception 'provider uncertainty timestamp is immutable'; end if; if new.accepted_at is distinct from old.accepted_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then raise exception 'accepted timestamp is immutable'; end if; if new.terminal_at is distinct from old.terminal_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then raise exception 'terminal timestamp is immutable'; end if; if row(new.persisted_at,new.persisted_compilation_id) is distinct from row(old.persisted_at,old.persisted_compilation_id) and not (old.status='provider_result_accepted' and new.status='compilation_persisted') then raise exception 'persisted custody is immutable'; end if; if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then raise exception 'accepted compilation result is immutable'; end if; if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or (old.status='provider_result_accepted' and new.status='compilation_persisted')) then raise exception 'invalid compilation attempt transition'; end if; return new; end $function$","name":"guard_project_guide_compilation_attempt_update"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_insert() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor_generation bigint; declare source_attempt project_guide_compilation_attempts%rowtype; begin select * into source_attempt from project_guide_compilation_attempts where id=new.attempt_id for update; if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash, new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) is distinct from row(source_attempt.project_id,source_attempt.guide_id, source_attempt.guide_version,source_attempt.source_snapshot_id, source_attempt.source_snapshot_hash,source_attempt.setup_run_id, source_attempt.setup_generation,source_attempt.canonical_input_hash, source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, source_attempt.agent_version,source_attempt.instruction_version, source_attempt.canonical_result::jsonb,source_attempt.result_hash, source_attempt.component_hashes::jsonb) then raise exception 'compilation does not match its accepted attempt'; end if; if not exists( select 1 from audit_events event join actor_profiles profile on profile.id=new.created_by_actor_profile_id join actor_identity_links link on link.id=new.created_via_identity_link_id and link.actor_profile_id=profile.id where event.id=new.authorization_decision_event_id and event.event_domain='authority' and event.event_type='SensitiveAuthorizationAllowed' and event.denial_code is null and event.actor_id=new.created_by_actor_profile_id and event.permission_id='project.guide_compilation.execute' and event.action_id='project.guide_compilation.execute' and event.project_id=new.project_id and event.resource_type='project_guide_compilation_attempt' and event.resource_id=new.attempt_id::text and event.after_facts->>'allowed'='true' and event.after_facts->>'resource_context_digest'= new.authorization_resource_context_digest and profile.actor_kind='service' and profile.status='active' and profile.service_identity='workstream.project.setup' and link.subject_kind='service' and link.status='active' and link.issuer='workstream-internal' and link.subject='workstream.project.setup' ) then raise exception 'compilation authorization evidence is invalid'; end if; if new.supersedes_compilation_id is null then return new; end if; select setup_generation into predecessor_generation from project_guide_compilations where id=new.supersedes_compilation_id and project_id=new.project_id and guide_id=new.guide_id; if predecessor_generation is null or predecessor_generation >= new.setup_generation then raise exception 'compilation generation must strictly advance'; end if; return new; end $function$","name":"guard_project_guide_compilation_insert"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_guide_policy_selection() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.status in ('active','superseded') and ( new.selected_review_policy_id is distinct from old.selected_review_policy_id or new.selected_review_policy_generation is distinct from old.selected_review_policy_generation or new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or new.selected_revision_policy_generation is distinct from old.selected_revision_policy_generation or new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash ) then raise exception 'active guide policy selection is immutable' using errcode='55000'; end if; return new; end $function$","name":"guard_project_guide_policy_selection"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_role_grant_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, new.qualification_snapshot_id,new.granted_by_actor_profile_id, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, old.qualification_snapshot_id,old.granted_by_actor_profile_id, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null or new.revoked_reason is null then raise exception 'invalid project-role grant history transition' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$","name":"guard_project_role_grant_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_role_snapshot_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; end $function$","name":"guard_project_role_snapshot_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_admission_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review admission records cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' and new.status <> 'pending' then raise exception 'review admission must begin pending' using errcode='23514'; end if; if tg_op='INSERT' then new.created_at := statement_timestamp(); end if; if tg_op='UPDATE' then if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.created_at) is distinct from (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.created_at) then raise exception 'review admission identity is immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' then raise exception 'invalid review admission transition' using errcode='23514'; end if; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review admission task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review admission checker lineage mismatch' using errcode='23514'; end if; if new.status='committed' and ( checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true) then raise exception 'review admission checker is not admissible' using errcode='23514'; end if; return new; end $function$","name":"guard_review_admission_record"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare actor_type text; policy_status text; begin if tg_op='DELETE' then raise exception 'review leases cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.status <> 'active' then raise exception 'review lease must begin active' using errcode='23514'; end if; new.claimed_at := statement_timestamp(); new.closed_at := null; new.close_reason := null; else if old.status <> 'active' then raise exception 'terminal review leases are immutable' using errcode='55000'; end if; if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, new.submission_version,new.reviewer_id, new.reviewer_contribution_policy_version_id,new.attempt_generation, new.claimed_at,new.expires_at) is distinct from (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, old.submission_version,old.reviewer_id, old.reviewer_contribution_policy_version_id,old.attempt_generation, old.claimed_at,old.expires_at) then raise exception 'review lease identity is immutable' using errcode='55000'; end if; if new.status='active' then raise exception 'review lease update must close attempt' using errcode='23514'; end if; end if; select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; if actor_type is distinct from 'human' then raise exception 'review lease reviewer must be human' using errcode='23514'; end if; if tg_op='INSERT' then select status into policy_status from contribution_policy_versions where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; if policy_status is distinct from 'published' then raise exception 'review lease policy version must be published' using errcode='23514'; end if; end if; return new; end $function$","name":"guard_review_lease"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review_policies rows are immutable' using errcode='55000'; end $function$","name":"guard_review_policies_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_queue_entry() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review queue entries cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.queue_state <> 'pending' then raise exception 'review queue must begin pending' using errcode='23514'; end if; new.first_queued_at := statement_timestamp(); new.available_since := new.first_queued_at; new.routing_generation := 1; new.lifecycle_generation := 1; new.created_at := new.first_queued_at; end if; if tg_op='UPDATE' then if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.first_queued_at,new.created_at) is distinct from (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.first_queued_at,old.created_at) then raise exception 'review queue identity is immutable' using errcode='55000'; end if; if old.queue_state='closed' and new.queue_state <> 'closed' then raise exception 'closed review queue entries cannot reopen' using errcode='23514'; end if; if new.routing_generation < old.routing_generation or new.lifecycle_generation < old.lifecycle_generation then raise exception 'review queue generations cannot decrease' using errcode='23514'; end if; end if; if new.preferred_reviewer_id is not null and not exists( select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' ) then raise exception 'preferred reviewer must be human' using errcode='23514'; end if; if tg_op='UPDATE' then return new; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review queue task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review queue checker lineage mismatch' using errcode='23514'; end if; if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true then raise exception 'review queue checker is not admissible' using errcode='23514'; end if; return new; end $function$","name":"guard_review_queue_entry"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_revision_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'revision_policies rows are immutable' using errcode='55000'; end $function$","name":"guard_revision_policies_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_service_identity_migration_evidence() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'service identity migration evidence is immutable' using errcode='55000'; end $function$","name":"guard_service_identity_migration_evidence"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_delete() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $function$","name":"guard_submission_bundle_admission_delete"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, old.put_operation_receipt_id, old.put_observation_receipt_id, old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, old.assignment_id, old.predecessor_submission_id, old.predecessor_submission_version, old.locked_policy_context_hash, old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, old.archive_byte_count, old.ready_at, old.created_at) is distinct from row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, new.put_operation_receipt_id, new.put_observation_receipt_id, new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, new.assignment_id, new.predecessor_submission_id, new.predecessor_submission_version, new.locked_policy_context_hash, new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, new.archive_byte_count, new.ready_at, new.created_at) then raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; end if; if old.status <> 'ready' or new.status not in ('consumed','stale') then raise exception 'invalid submission bundle admission transition' using errcode='23514'; end if; return new; end; $function$","name":"guard_submission_bundle_admission_lineage"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_verified_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ declare matches integer; begin select count(*) into matches from submission_bundle_durable_intents intent join pre_submit_evidence_sets evidence on evidence.id=intent.pre_submit_evidence_set_id join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id join artifact_replicas replica on replica.id=attempt.replica_id join artifact_contents content on content.id=replica.content_id join artifact_verification_jobs job on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id join artifact_verification_receipts verification on verification.verification_job_id=job.id where intent.id=new.durable_intent_id and evidence.id=new.pre_submit_evidence_set_id and attempt.id=new.put_attempt_id and content.id=new.artifact_content_id and replica.id=new.verified_replica_id and verification.id=new.verification_receipt_id and attempt.producer_request_type='submission_bundle' and attempt.producer_type='actor_profile' and attempt.producer_ref=evidence.actor_profile_id and attempt.project_id=evidence.project_id and attempt.task_id=evidence.task_id and attempt.media_type='application/zip' and content.media_type='application/zip' and attempt.status='object_confirmed' and evidence.terminal_status='passed' and evidence.eligible and replica.verification_state='verified' and replica.availability_state='available' and replica.integrity_state='valid' and verification.outcome='verified' and verification.execution_generation=job.execution_generation and verification.observed_sha256=attempt.sha256 and verification.observed_sha256=content.sha256 and verification.observed_sha256=evidence.archive_sha256 and verification.observed_byte_count=attempt.byte_count and verification.observed_byte_count=content.byte_count and verification.observed_byte_count=evidence.archive_byte_count and new.actor_profile_id=evidence.actor_profile_id and new.identity_link_id=evidence.identity_link_id and new.project_id=evidence.project_id and new.task_id=evidence.task_id and new.assignment_id=evidence.assignment_id and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version and new.locked_policy_context_hash=evidence.locked_policy_context_hash and new.semantic_manifest_id=evidence.semantic_manifest_id and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 and new.archive_sha256=evidence.archive_sha256 and new.archive_byte_count=evidence.archive_byte_count and ((new.put_operation_receipt_id is not null and exists ( select 1 from artifact_operation_receipts receipt where receipt.id=new.put_operation_receipt_id and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id and receipt.outcome='stored_pending_verification')) or (new.put_observation_receipt_id is not null and exists ( select 1 from artifact_put_observation_receipts observation where observation.id=new.put_observation_receipt_id and observation.put_attempt_id=attempt.id and observation.outcome='observed_confirmed' and observation.observed_sha256=attempt.sha256 and observation.observed_byte_count=attempt.byte_count))); if matches <> 1 then raise exception 'submission bundle admission verified lineage mismatch' using errcode='23514'; end if; return new; end; $function$","name":"guard_submission_bundle_admission_verified_lineage"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id for share; if request_type is distinct from 'submission_bundle' then raise exception 'submission bundle durable intent requires submission_bundle put attempt' using errcode='23514'; end if; return new; end; $function$","name":"guard_submission_bundle_durable_intent_put_attempt"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intents_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission_bundle_durable_intents rows are immutable' using errcode='55000'; end; $function$","name":"guard_submission_bundle_durable_intents_immutable"},{"arguments":"value jsonb","definition":"CREATE OR REPLACE FUNCTION public.project_role_availability_is_safe(value jsonb) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='object' and (select count(*)=3 from jsonb_object_keys(value)) and value ?& array['availability','reference_ids','unavailable_reason'] and project_role_reference_array_is_safe(value->'reference_ids',false) and ( (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 and value->'unavailable_reason'='null'::jsonb) or (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) ) $function$","name":"project_role_availability_is_safe"},{"arguments":"value text","definition":"CREATE OR REPLACE FUNCTION public.project_role_reason_is_safe(value text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE STRICT AS $function$ declare point integer; index integer; begin if octet_length(value) not between 1 and 500 or value <> btrim(value, (E' \\t\\n\\r\\f\\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)||chr(8239)||chr(8287)||chr(12288))) then return false; end if; for index in 1..char_length(value) loop point := ascii(substr(value,index,1)); if point between 0 and 31 or point between 127 and 159 or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then return false; end if; end loop; return true; end $function$","name":"project_role_reason_is_safe"},{"arguments":"value jsonb, uuid_only boolean","definition":"CREATE OR REPLACE FUNCTION public.project_role_reference_array_is_safe(value jsonb, uuid_only boolean) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 and not exists ( select 1 from jsonb_array_elements(value) item where jsonb_typeof(item)<>'string' or case when uuid_only then not (item #>> '{}') ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' else not project_role_reference_token_is_safe(item #>> '{}') end ) $function$","name":"project_role_reference_array_is_safe"},{"arguments":"value text","definition":"CREATE OR REPLACE FUNCTION public.project_role_reference_token_is_safe(value text) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 $function$","name":"project_role_reference_token_is_safe"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.protect_submission_policy_approval_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.approval_action_id is not null and (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, new.approved_by_admin_role_grant_id,new.approval_scope_type, new.approval_scope_project_id,new.approval_action_id, new.approval_decision_event_id) is distinct from (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, old.approved_by_admin_role_grant_id,old.approval_scope_type, old.approval_scope_project_id,old.approval_action_id, old.approval_decision_event_id) then raise exception 'submission-policy approval provenance is immutable' using errcode='23514'; end if; return new; end $function$","name":"protect_submission_policy_approval_provenance"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.protect_submission_policy_creation_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.created_by_service_identity, new.creation_scope_type,new.creation_scope_project_id, new.creation_action_id,new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.created_by_service_identity, old.creation_scope_type,old.creation_scope_project_id, old.creation_action_id,old.creation_decision_event_id) then raise exception 'submission-policy creation provenance is immutable' using errcode='23514'; end if; return new; end $function$","name":"protect_submission_policy_creation_provenance"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.protect_submission_policy_output_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.creation_scope_type, new.creation_scope_project_id,new.creation_action_id, new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.creation_scope_type, old.creation_scope_project_id,old.creation_action_id, old.creation_decision_event_id) then raise exception 'submission-policy output provenance is immutable' using errcode='23514'; end if; return new; end $function$","name":"protect_submission_policy_output_provenance"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_admin_role_grant_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'admin role grants are immutable' using errcode='55000'; end $function$","name":"reject_admin_role_grant_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_artifact_fact_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception '% rows are immutable', tg_table_name; end; $function$","name":"reject_artifact_fact_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_audit_event_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'audit events are append-only' using errcode = '55000'; end $function$","name":"reject_audit_event_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_authority_control_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority control is immutable' using errcode='55000'; end $function$","name":"reject_authority_control_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_authority_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority idempotency records are immutable' using errcode='55000'; end $function$","name":"reject_authority_idempotency_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_contribution_policy_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'contribution policy persistence cannot be truncated' using errcode='55000'; end; $function$","name":"reject_contribution_policy_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_guide_mutation_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide mutation custody is immutable' using errcode='55000'; end $function$","name":"reject_guide_mutation_idempotency_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_guide_source_snapshot_item_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide source snapshot items are immutable' using errcode='23514'; end $function$","name":"reject_guide_source_snapshot_item_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_pending_authority_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then raise exception 'pending authority idempotency cannot commit' using errcode='23514'; end if; return null; end $function$","name":"reject_pending_authority_idempotency"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_policy_mutation_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'policy mutation replay is immutable' using errcode='55000'; end $function$","name":"reject_policy_mutation_replay_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_project_create_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project create reservations are immutable' using errcode='55000'; end $function$","name":"reject_project_create_idempotency_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_project_guide_compilation_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compilation custody is append-only'; end $function$","name":"reject_project_guide_compilation_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_project_role_history_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $function$","name":"reject_project_role_history_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_review_lease_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review leases cannot be truncated' using errcode='55000'; end $function$","name":"reject_review_lease_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_review_queue_foundation_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review queue foundation cannot be truncated' using errcode='55000'; end $function$","name":"reject_review_queue_foundation_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'submission-policy replay rows cannot be deleted'; end if; if old.status = 'reserved' and new.status = 'pending' and old.service_identity = 'workstream.project.setup' and old.action_id = 'project.submission_artifact_policy.derive' and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.operation_id,new.project_id, new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, new.committed_pre_submit_policy_id,new.committed_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.operation_id,old.project_id, old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, old.committed_pre_submit_policy_id,old.committed_at) then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.request_digest, new.resource_context_digest,new.resource_context_json::text,new.operation_id, new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, new.setup_run_id,new.setup_generation,new.setup_task_id, new.correlation_id,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.request_digest, old.resource_context_digest,old.resource_context_json::text,old.operation_id, old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, old.setup_run_id,old.setup_generation,old.setup_task_id, old.correlation_id,old.created_at) then raise exception 'invalid submission-policy replay mutation'; end if; return new; end $function$","name":"reject_submission_policy_replay_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission-policy replay rows cannot be truncated'; end $function$","name":"reject_submission_policy_replay_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'guide sufficiency replay rows are append-only'; end if; if old.status = 'committed' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, new.setup_run_id,new.setup_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, old.setup_run_id,old.setup_generation,old.created_at) then raise exception 'invalid guide sufficiency replay mutation'; end if; return new; end $function$","name":"reject_sufficiency_replay_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide sufficiency replay rows are append-only'; end $function$","name":"reject_sufficiency_replay_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.require_human_actor_profile_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare referenced_id text; referenced_kind text; begin if tg_nargs <> 1 or tg_argv[0] is null or not (to_jsonb(new) ? tg_argv[0]) then raise exception 'human actor reference trigger is misconfigured' using errcode='55000'; end if; referenced_id := to_jsonb(new) ->> tg_argv[0]; if referenced_id is null then return new; end if; select profile.actor_kind into referenced_kind from public.actor_profiles profile where profile.id=referenced_id; if not found then return new; end if; if referenced_kind <> 'human' then raise exception 'actor reference must identify a human profile' using errcode='23514', constraint='require_human_actor_profile_reference'; end if; return new; end $function$","name":"require_human_actor_profile_reference"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.set_authority_audit_database_time() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.event_domain = 'authority' then if new.invalidation_cause_event_id is not null and not exists ( select 1 from audit_events where id = new.invalidation_cause_event_id and event_domain = 'authority' ) then raise exception 'invalid authority invalidation cause' using errcode = '23503'; end if; new.occurred_at = statement_timestamp(); else new.occurred_at = null; end if; return new; end $function$","name":"set_authority_audit_database_time"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_artifact_binding_history() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor artifact_bindings%rowtype; begin if new.scope_version = 1 then return new; end if; select * into predecessor from artifact_bindings where id = new.supersedes_binding_id; if not found or predecessor.project_id != new.project_id or predecessor.resource_type != new.resource_type or predecessor.resource_id != new.resource_id or predecessor.logical_role != new.logical_role or predecessor.scope_version + 1 != new.scope_version then raise exception 'artifact binding predecessor is invalid'; end if; return new; end; $function$","name":"validate_artifact_binding_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_artifact_recovery_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare source_row artifact_verification_jobs%rowtype; retry_row artifact_verification_jobs%rowtype; expected_parent text; begin if tg_op = 'DELETE' then raise exception 'artifact recovery attempts are append-only' using errcode='55000'; end if; if tg_op = 'UPDATE' and ( to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] is distinct from to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] ) then raise exception 'artifact recovery identity is immutable' using errcode='55000'; end if; select * into source_row from artifact_verification_jobs where id=new.source_verification_job_id; select * into retry_row from artifact_verification_jobs where id=new.retry_verification_job_id; if source_row.id is null or retry_row.id is null or source_row.status <> 'provider_unavailable' or source_row.terminal_result_code <> 'provider_unavailable' or source_row.terminal_at is null or source_row.next_run_at is not null or source_row.executor_id is not null or source_row.attempt_count < source_row.maximum_attempts or retry_row.parent_verification_job_id <> source_row.id or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id or retry_row.replica_id <> source_row.replica_id then raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; end if; if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) or (tg_op = 'UPDATE' and ( retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null )) then raise exception 'invalid artifact recovery retry state' using errcode='23514'; end if; select id into expected_parent from artifact_recovery_attempts where retry_verification_job_id=source_row.id; if new.parent_recovery_attempt_id is distinct from expected_parent then raise exception 'invalid artifact recovery parent chain' using errcode='23514'; end if; if not exists ( select 1 from audit_events where id=new.initiation_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryInitiated' ) then raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; end if; if new.terminal_audit_event_id is not null and not exists ( select 1 from audit_events where id=new.terminal_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryCompleted' ) then raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; end if; return new; end $function$","name":"validate_artifact_recovery_attempt"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_artifact_verification_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if ( old.parent_verification_job_id is not null or exists( select 1 from artifact_recovery_attempts where source_verification_job_id = old.id or retry_verification_job_id = old.id ) ) and ( old.originating_put_attempt_id is distinct from new.originating_put_attempt_id or old.replica_id is distinct from new.replica_id or old.parent_verification_job_id is distinct from new.parent_verification_job_id ) then raise exception 'artifact verification lineage is immutable' using errcode='55000'; end if; return new; end $function$","name":"validate_artifact_verification_lineage"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_bootstrap_authority_state() RETURNS trigger LANGUAGE plpgsql AS $function$ declare control authority_control%rowtype; bootstrap_count bigint; referenced_bootstrap boolean; begin select * into control from authority_control where id=1; if not found then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; select count(*) into bootstrap_count from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap'; referenced_bootstrap := exists( select 1 from admin_role_grants where id=control.bootstrap_grant_id and granted_by_system_principal='workstream:system:bootstrap' ); if (not control.bootstrap_completed and (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) or (control.bootstrap_completed and (control.bootstrap_grant_id is null or control.version <> 1 or bootstrap_count <> 1 or not referenced_bootstrap)) then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; return null; end $function$","name":"validate_bootstrap_authority_state"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_canonical_actor_link() RETURNS trigger LANGUAGE plpgsql AS $function$ declare profile_row actor_profiles%rowtype; link_count integer; begin if tg_table_name='actor_profiles' then select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; else select * into profile_row from actor_profiles where id=new.actor_profile_id; if not found or profile_row.actor_kind <> new.subject_kind then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; end if; return new; end $function$","name":"validate_canonical_actor_link"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_contribution_policy_graph() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists ( select 1 from contribution_policy_versions v where v.status in ('published','retired') and ( (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='accepted_submission') <> 1 or (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='completed_review') <> 1 or exists ( select 1 from contribution_rules r where r.contribution_policy_version_id=v.id and ( (r.compensation_mode='unpaid' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) <> 0) or (r.compensation_mode='compensated' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) not between 1 and 2) ) ) ) ) then raise exception 'published contribution policy graph is incomplete' using errcode='23514'; end if; if exists ( select 1 from contribution_policies p left join contribution_policy_versions v on v.id=p.current_published_version_id and v.contribution_policy_id=p.id and v.project_id=p.project_id where p.status='active' and (v.id is null or v.status <> 'published') ) then raise exception 'active contribution policy selector is invalid' using errcode='23514'; end if; return null; end; $function$","name":"validate_contribution_policy_graph"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_guide_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation guide_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_resource text; product_generation integer; begin if tg_table_name='guide_mutation_idempotency_records' then select * into reservation from guide_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id in ('project.guide.create','project.guide.update') then select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, last_mutated_by_admin_role_grant_id,last_mutation_action_id, last_mutation_scope_type,last_mutation_scope_project_id, last_authorization_decision_event_id,project_id,id,mutation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from project_guides where id=reservation.resource_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,project_id,id,creation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from guide_source_snapshots where id=reservation.resource_id; end if; elsif tg_table_name='project_guides' then if tg_op='UPDATE' and (new.content_markdown is distinct from old.content_markdown or new.change_summary is distinct from old.change_summary) and (new.mutation_generation is not distinct from old.mutation_generation or new.last_authorization_decision_event_id is not distinct from old.last_authorization_decision_event_id) then raise exception 'guide content mutation requires fresh custody' using errcode='23514'; end if; if new.mutation_generation is null then if tg_op='INSERT' then raise exception 'new guides require mutation authority' using errcode='23514'; end if; return null; end if; actor_id:=new.last_mutated_by_actor_profile_id; link_id:=new.last_mutated_via_identity_link_id; grant_id:=new.last_mutated_by_admin_role_grant_id; action_value:=new.last_mutation_action_id; scope_type:=new.last_mutation_scope_type; scope_project:=new.last_mutation_scope_project_id; decision_id:=new.last_authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.mutation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id=new.last_mutation_action_id and operation_generation=new.mutation_generation and status='committed'; elsif tg_table_name='guide_source_snapshots' then if tg_op='UPDATE' and (new.project_id,new.guide_id,new.guide_version, new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) is distinct from (old.project_id,old.guide_id,old.guide_version, old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then raise exception 'guide source snapshot content is immutable' using errcode='23514'; end if; if new.creation_generation is null then raise exception 'new source snapshots require creation authority' using errcode='23514'; end if; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.creation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id='project.guide_source_snapshot.create' and operation_generation=new.creation_generation and status='committed'; else if new.authorization_action_id is null then return null; end if; actor_id:=new.authorized_by_actor_profile_id; link_id:=new.authorized_via_identity_link_id; grant_id:=new.authorized_by_admin_role_grant_id; action_value:=new.authorization_action_id; scope_type:=new.authorization_scope_type; scope_project:=new.authorization_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.source_snapshot_id; select * into reservation from guide_mutation_idempotency_records where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' and status='committed'; product_generation:=reservation.operation_generation; end if; if reservation.id is null or product_resource is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.resource_id is distinct from product_resource or reservation.operation_generation is distinct from product_generation or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'guide mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.guide.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'guide mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_guide_mutation_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_guide_source_snapshot_items() RETURNS trigger LANGUAGE plpgsql AS $function$ declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; begin select snapshot.manifest_json::jsonb->'items' into expected from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; if expected is null then raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; end if; select coalesce(jsonb_agg(jsonb_build_object( 'item_id',id,'item_order',item_order,'source_kind',source_kind, 'source_label',source_label,'ingestion_adapter',ingestion_adapter, 'media_type',media_type) order by item_order),'[]'::jsonb) into actual from guide_source_snapshot_items where source_snapshot_id=new.source_snapshot_id; if actual is distinct from expected then raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; end if; select r.* into reservation from guide_mutation_idempotency_records r join guide_source_snapshots s on s.id=r.resource_id where s.id=new.source_snapshot_id and r.action_id='project.guide_source_snapshot.create' and r.operation_generation=s.creation_generation and r.status='committed'; if reservation.id is null then raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_guide_source_snapshot_items"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_linked_authority_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare record_row authority_idempotency_records%rowtype; cause_row audit_events%rowtype; expected_permission text; expected_resource text; expected_invalidation_resource text; expected_invalidation_id text; valid_success boolean; begin if new.event_domain <> 'authority' then return new; end if; valid_success := new.event_type in ( 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', 'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued','ProjectRoleGrantRevoked', 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then if new.idempotency_reference is not null then raise exception 'invalid authority idempotency event' using errcode='23514'; end if; return new; end if; if new.idempotency_reference is null then raise exception 'authority event requires idempotency reference' using errcode='23514'; end if; select * into record_row from authority_idempotency_records where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; expected_permission := case record_row.operation when 'service_actor.create' then 'actor.service.provision' when 'admin_role_grant.issue' then 'admin_role.grant' when 'admin_role_grant.revoke' then 'admin_role.revoke' when 'project_role_grant.issue' then 'project.role_grant.manage' when 'project_role_grant.revoke' then 'project.role_grant.manage' when 'actor_profile.suspend' then 'actor.profile.suspend' when 'actor_profile.reactivate' then 'actor.profile.reactivate' when 'actor_profile.deactivate' then 'actor.profile.deactivate' when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; expected_resource := case when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' when record_row.operation like 'project_role_grant.%' then 'project_role_grant' else 'actor_identity_link' end; if new.permission_id <> expected_permission or new.resource_id is null then raise exception 'authority event does not match operation' using errcode='23514'; end if; if new.event_type='ProjectRoleQualificationSnapshotCaptured' then if record_row.operation <> 'project_role_grant.issue' or new.resource_type <> 'qualification_snapshot' or new.entity_type <> 'qualification_snapshot' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'qualification_snapshot' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or exists(select 1 from audit_events where idempotency_reference=record_row.id) then raise exception 'invalid project role qualification evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='ProjectRoleGrantIssued' then select * into cause_row from audit_events where idempotency_reference=record_row.id and event_type='ProjectRoleQualificationSnapshotCaptured'; if not found or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.matched_grant_id is distinct from new.matched_grant_id or new.resource_type <> 'project_role_grant' or new.entity_type <> 'project_role_grant' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null then raise exception 'invalid project role issue evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.revoke' and new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from 'actor_profile' or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.resource_type <> 'project_role_grant' or cause_row.target_ref_kind <> 'project_role_grant' or cause_row.target_ref_id is distinct from cause_row.resource_id or new.resource_type <> 'project_role_grant' or new.resource_id is distinct from cause_row.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from cause_row.resource_id or new.invalidation_target_kind <> 'project_role_grant' or new.invalidation_target_ref is distinct from cause_row.resource_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or new.before_facts::jsonb->>'effective' <> 'true' or new.after_facts::jsonb->>'effective' <> 'false' or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' or new.before_facts::jsonb->>'scope_type' <> 'project' or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then raise exception 'invalid project role revoke invalidation' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='AuthorityInvalidationRequested' then raise exception 'project role issue forbids invalidation' using errcode='23514'; elsif new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; expected_invalidation_resource := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then 'actor_profile' else expected_resource end; expected_invalidation_id := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then cause_row.target_actor_ref else cause_row.resource_id end; if not found or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.resource_type is distinct from expected_resource or new.resource_type is distinct from expected_invalidation_resource or new.resource_id is distinct from expected_invalidation_id or new.invalidation_target_kind is distinct from expected_invalidation_resource or new.invalidation_target_ref is distinct from expected_invalidation_id or cause_row.target_ref_kind is distinct from cause_row.resource_type or cause_row.target_ref_id is distinct from cause_row.resource_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": false}'::jsonb or new.after_facts::jsonb <> '{\"effective\": true}'::jsonb)) or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": true}'::jsonb or new.after_facts::jsonb <> '{\"effective\": false}'::jsonb)) or not ( (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then raise exception 'invalid linked authority cause' using errcode='23514'; end if; else if new.resource_type <> expected_resource or new.entity_type <> expected_resource or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or not ( (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then raise exception 'authority success event does not match operation' using errcode='23514'; end if; end if; return new; end $function$","name":"validate_linked_authority_event"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_policy_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_guide text; product_id text; product_generation integer; product_hash text; predecessor_id text; predecessor_hash text; selector_id text; selector_generation integer; selector_hash text; predecessor_valid boolean; begin if tg_table_name='policy_mutation_idempotency_records' then select * into reservation from policy_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id='project.review_policy.update' then select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_review_policy_id, g.selected_review_policy_generation,g.selected_review_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from review_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_revision_policy_id, g.selected_revision_policy_generation,g.selected_revision_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from revision_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; end if; else actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_id:=new.id; product_generation:=new.policy_generation; product_hash:=new.policy_hash; predecessor_id:=new.supersedes_policy_id; predecessor_hash:=new.predecessor_policy_hash; if tg_table_name='review_policies' then select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, g.selected_review_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; else select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, g.selected_revision_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; end if; select r.* into reservation from policy_mutation_idempotency_records r where r.policy_id=new.id and r.action_id=new.creation_action_id and r.policy_generation=new.policy_generation and r.status='committed'; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.guide_id is distinct from product_guide or reservation.policy_id is distinct from product_id or reservation.policy_generation is distinct from product_generation or reservation.policy_hash is distinct from product_hash or selector_id is distinct from product_id or selector_generation is distinct from product_generation or selector_hash is distinct from product_hash or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'policy mutation custody mismatch' using errcode='23514'; end if; if product_generation=1 then predecessor_valid:=predecessor_id is null and predecessor_hash is null; elsif reservation.action_id='project.review_policy.update' then select exists(select 1 from review_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; else select exists(select 1 from revision_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; end if; if predecessor_valid is not true then raise exception 'policy mutation lineage mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.review_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'policy mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_policy_mutation_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_project_create_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; evidence audit_events%rowtype; begin if tg_table_name = 'projects' then if tg_op = 'INSERT' and new.creation_action_id is null then raise exception 'new projects require creation authority' using errcode='23514'; end if; if new.creation_action_id is null then return null; end if; project_row := new; select * into reservation from project_create_idempotency_records where project_id=project_row.id and status='committed'; else select * into reservation from project_create_idempotency_records where id=new.id; if reservation.status <> 'committed' then raise exception 'pending project create reservation cannot commit' using errcode='23514'; end if; select * into project_row from projects where id=reservation.project_id; end if; if project_row.id is null or reservation.id is null or project_row.created_by_actor_profile_id is distinct from reservation.actor_profile_id or project_row.created_via_identity_link_id is distinct from reservation.identity_link_id or project_row.creation_action_id is distinct from reservation.action_id then raise exception 'project create custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=project_row.authorization_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from project_row.created_by_actor_profile_id or evidence.matched_grant_id is distinct from project_row.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.create' or evidence.action_id is distinct from 'project.create' or evidence.resource_type is distinct from 'project_create_operation' or evidence.resource_id is distinct from reservation.operation_id::text or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from project_row.id or evidence.after_facts->>'allowed' is distinct from 'true' or coalesce( evidence.after_facts->>'resource_context_digest' !~ '^sha256:[0-9a-f]{64}$', true ) then raise exception 'project create evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_project_create_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_review_active_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare queue_row review_queue_entries%rowtype; active_count integer; begin if tg_table_name='review_queue_entries' then queue_row := new; else select * into queue_row from review_queue_entries where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); end if; if not found and tg_table_name='review_leases' then raise exception 'review lease queue is missing' using errcode='23514'; end if; select count(*) into active_count from review_leases where review_queue_entry_id=queue_row.id and status='active'; if queue_row.queue_state='leased' then if queue_row.active_lease_id is null or active_count <> 1 or not exists( select 1 from review_leases where id=queue_row.active_lease_id and review_queue_entry_id=queue_row.id and status='active' ) then raise exception 'leased queue must identify its active lease' using errcode='23514'; end if; elsif queue_row.active_lease_id is not null or active_count <> 0 then raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; end if; return null; end $function$","name":"validate_review_active_lease"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_submission_policy_authority_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; action_value varchar; decision_id varchar; product_project varchar; product_id varchar; approval_outputs_valid boolean; begin if tg_table_name='submission_policy_mutation_idempotency_records' then if new.status='pending' then return null; end if; reservation:=new; select project_id,id, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_actor_profile_id else created_by_actor_profile_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_via_identity_link_id else created_via_identity_link_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_admin_role_grant_id else created_by_admin_role_grant_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then null else created_by_service_identity end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_action_id else creation_action_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_decision_event_id else creation_decision_event_id end into product_project,product_id,actor_id,link_id,grant_id,service_id, action_value,decision_id from submission_artifact_policies where id=reservation.committed_policy_id; if reservation.action_id='project.submission_artifact_policy.approve' then select exists( select 1 from submission_artifact_policies s join effective_project_submission_artifact_policies e on e.id=reservation.committed_effective_policy_id and e.submission_artifact_policy_id=s.id and e.submission_artifact_policy_hash=s.policy_hash join pre_submit_checker_policies p on p.id=reservation.committed_pre_submit_policy_id and p.project_id=e.project_id where s.id=reservation.committed_policy_id and s.id=reservation.policy_id and s.guide_id=reservation.guide_id and s.source_snapshot_id=reservation.source_snapshot_id and s.guide_version=reservation.resource_context_json->>'guide_version' and s.policy_hash=reservation.resource_context_json->>'policy_digest' and e.effective_policy_hash= reservation.resource_context_json->>'effective_output_digest' and p.compiled_bundle_hash= reservation.resource_context_json->>'compiled_pre_submit_output_digest' and e.project_id=reservation.project_id and e.guide_id=s.guide_id and p.guide_id=s.guide_id and e.guide_version=s.guide_version and p.guide_version=s.guide_version and e.source_snapshot_id=s.source_snapshot_id and p.source_snapshot_id=s.source_snapshot_id and e.source_snapshot_hash=s.source_snapshot_hash and p.source_snapshot_hash=s.source_snapshot_hash and e.submission_artifact_policy_id=reservation.committed_policy_id and p.effective_policy_id=e.id and p.effective_policy_hash=e.effective_policy_hash and e.created_by_actor_profile_id=reservation.actor_profile_id and p.created_by_actor_profile_id=reservation.actor_profile_id and e.created_via_identity_link_id=reservation.identity_link_id and p.created_via_identity_link_id=reservation.identity_link_id and e.created_by_admin_role_grant_id=grant_id and p.created_by_admin_role_grant_id=grant_id and e.creation_scope_project_id=reservation.project_id and p.creation_scope_project_id=reservation.project_id and e.creation_action_id=reservation.action_id and p.creation_action_id=reservation.action_id and e.creation_decision_event_id=decision_id and p.creation_decision_event_id=decision_id ) into approval_outputs_valid; if approval_outputs_valid is not true then raise exception 'submission-policy approval output custody mismatch' using errcode='23514'; end if; end if; elsif tg_table_name='submission_artifact_policies' then if new.creation_action_id is null and new.approval_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null or new.approved_by_actor_profile_id is not null or new.approved_via_identity_link_id is not null or new.approved_by_admin_role_grant_id is not null or new.approval_scope_type is not null or new.approval_scope_project_id is not null or new.approval_decision_event_id is not null then raise exception 'partial submission-policy provenance' using errcode='23514'; end if; return null; end if; if new.approval_action_id is not null then select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.approval_action_id and status='committed'; actor_id:=new.approved_by_actor_profile_id; link_id:=new.approved_via_identity_link_id; grant_id:=new.approved_by_admin_role_grant_id; service_id:=null; action_value:=new.approval_action_id; decision_id:=new.approval_decision_event_id; else select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=new.created_by_service_identity; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; end if; product_project:=new.project_id; product_id:=new.id; elsif tg_table_name='effective_project_submission_artifact_policies' then if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial effective-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_effective_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; else if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial pre-submit-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_pre_submit_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.committed_policy_id is distinct from product_id or reservation.service_identity is distinct from service_id then raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from product_id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy authorization evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_submission_policy_authority_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_submission_policy_creation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; begin if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial submission-policy creation provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; if reservation.id is null or reservation.actor_profile_id is distinct from new.created_by_actor_profile_id or reservation.identity_link_id is distinct from new.created_via_identity_link_id or reservation.service_identity is distinct from new.created_by_service_identity or reservation.project_id is distinct from new.project_id or reservation.policy_id is distinct from new.id or reservation.guide_id is distinct from new.guide_id or reservation.source_snapshot_id is distinct from new.source_snapshot_id or reservation.resource_context_json->>'guide_version' is distinct from new.guide_version then raise exception 'submission-policy creation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=new.creation_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from new.created_by_actor_profile_id or evidence.matched_grant_id is distinct from new.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from new.creation_action_id or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from new.id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy creation evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_submission_policy_creation_custody"}],"sequences":[{"cache_size":1,"cycle":false,"data_type":"integer","increment_by":1,"is_called":true,"last_value":1,"max_value":2147483647,"min_value":1,"name":"actor_profile_migration_state_id_seq","start_value":1},{"cache_size":1,"cycle":false,"data_type":"smallint","increment_by":1,"is_called":true,"last_value":1,"max_value":32767,"min_value":1,"name":"authority_control_id_seq","start_value":1}],"tables":[{"force_row_security":false,"kind":"r","name":"actor_identity_links","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"actor_profile_migration_state","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"actor_profiles","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"admin_role_grants","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"api_rate_control_counters","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_admission_charges","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_admission_scopes","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_bindings","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_contents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_operation_receipts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_put_attempt_charges","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_put_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_put_observation_receipts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_recovery_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_replicas","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_storage_namespaces","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_verification_jobs","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_verification_receipts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"audit_events","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"authority_control","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"authority_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"checker_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"checker_results","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"checker_runs","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_award_definitions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_policy_versions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_rules","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"effective_project_submission_artifact_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"evidence_items","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_artifact_bindings","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_artifact_incidents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_artifact_ingests","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extracted_contents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extraction_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extraction_retry_budgets","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extraction_usages","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_format_classifications","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_snapshot_items","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_snapshots","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_sufficiency_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_sufficiency_report_source_usages","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_sufficiency_reports","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"iso_4217_currency_codes","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"legacy_actor_identities","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"legacy_workflow_eligibility","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"outbox_events","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"payment_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"policy_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"pre_submit_checker_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"pre_submit_evidence_results","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"pre_submit_evidence_sets","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_compensation_adapter_bindings","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_compensation_units","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_create_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_guide_compilation_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_guide_compilations","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_guides","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_role_grants","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_role_qualification_snapshots","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_setup_runs","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"projects","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_admission_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_leases","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_queue_entries","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"revision_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_artifact_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_bundle_admissions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_bundle_durable_intents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_policy_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submissions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"task_assignments","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"workstream_tasks","persistence":"p","row_security":false}],"triggers":[{"definition":"CREATE TRIGGER actor_identity_link_history_guard BEFORE DELETE OR UPDATE ON actor_identity_links FOR EACH ROW EXECUTE FUNCTION guard_actor_identity_link_history()","enabled":"O","name":"actor_identity_link_history_guard","table_name":"actor_identity_links"},{"definition":"CREATE CONSTRAINT TRIGGER actor_identity_link_profile_guard AFTER INSERT OR UPDATE ON actor_identity_links DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()","enabled":"O","name":"actor_identity_link_profile_guard","table_name":"actor_identity_links"},{"definition":"CREATE TRIGGER service_identity_migration_evidence_row_guard BEFORE DELETE OR UPDATE ON actor_profile_migration_state FOR EACH ROW EXECUTE FUNCTION guard_service_identity_migration_evidence()","enabled":"O","name":"service_identity_migration_evidence_row_guard","table_name":"actor_profile_migration_state"},{"definition":"CREATE TRIGGER service_identity_migration_evidence_truncate_guard BEFORE TRUNCATE ON actor_profile_migration_state FOR EACH STATEMENT EXECUTE FUNCTION guard_service_identity_migration_evidence()","enabled":"O","name":"service_identity_migration_evidence_truncate_guard","table_name":"actor_profile_migration_state"},{"definition":"CREATE TRIGGER actor_profile_history_guard BEFORE DELETE OR UPDATE ON actor_profiles FOR EACH ROW EXECUTE FUNCTION guard_actor_profile_history()","enabled":"O","name":"actor_profile_history_guard","table_name":"actor_profiles"},{"definition":"CREATE CONSTRAINT TRIGGER actor_profile_link_guard AFTER INSERT OR UPDATE ON actor_profiles DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()","enabled":"O","name":"actor_profile_link_guard","table_name":"actor_profiles"},{"definition":"CREATE CONSTRAINT TRIGGER admin_role_grants_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON admin_role_grants DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()","enabled":"O","name":"admin_role_grants_bootstrap_invariant","table_name":"admin_role_grants"},{"definition":"CREATE TRIGGER admin_role_grants_guard BEFORE INSERT OR DELETE OR UPDATE ON admin_role_grants FOR EACH ROW EXECUTE FUNCTION guard_admin_role_grant()","enabled":"O","name":"admin_role_grants_guard","table_name":"admin_role_grants"},{"definition":"CREATE TRIGGER admin_role_grants_reject_truncate BEFORE TRUNCATE ON admin_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_admin_role_grant_truncate()","enabled":"O","name":"admin_role_grants_reject_truncate","table_name":"admin_role_grants"},{"definition":"CREATE CONSTRAINT TRIGGER trg_artifact_binding_history AFTER INSERT ON artifact_bindings DEFERRABLE INITIALLY IMMEDIATE FOR EACH ROW EXECUTE FUNCTION validate_artifact_binding_history()","enabled":"O","name":"trg_artifact_binding_history","table_name":"artifact_bindings"},{"definition":"CREATE TRIGGER trg_artifact_bindings_immutable BEFORE DELETE OR UPDATE ON artifact_bindings FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_bindings_immutable","table_name":"artifact_bindings"},{"definition":"CREATE TRIGGER trg_artifact_contents_immutable BEFORE DELETE OR UPDATE ON artifact_contents FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_contents_immutable","table_name":"artifact_contents"},{"definition":"CREATE TRIGGER artifact_receipt_producer_reference BEFORE INSERT OR UPDATE OF put_attempt_id, guide_source_item_id, checker_run_id, logical_role ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION guard_artifact_receipt_producer_reference()","enabled":"O","name":"artifact_receipt_producer_reference","table_name":"artifact_operation_receipts"},{"definition":"CREATE TRIGGER trg_artifact_operation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_operation_receipts_immutable","table_name":"artifact_operation_receipts"},{"definition":"CREATE TRIGGER trg_artifact_put_observation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_put_observation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_put_observation_receipts_immutable","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE TRIGGER artifact_recovery_attempt_custody BEFORE INSERT OR DELETE OR UPDATE ON artifact_recovery_attempts FOR EACH ROW EXECUTE FUNCTION validate_artifact_recovery_attempt()","enabled":"O","name":"artifact_recovery_attempt_custody","table_name":"artifact_recovery_attempts"},{"definition":"CREATE TRIGGER trg_artifact_storage_namespaces_immutable BEFORE DELETE OR UPDATE ON artifact_storage_namespaces FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_storage_namespaces_immutable","table_name":"artifact_storage_namespaces"},{"definition":"CREATE TRIGGER artifact_verification_lineage_custody BEFORE UPDATE ON artifact_verification_jobs FOR EACH ROW EXECUTE FUNCTION validate_artifact_verification_lineage()","enabled":"O","name":"artifact_verification_lineage_custody","table_name":"artifact_verification_jobs"},{"definition":"CREATE TRIGGER trg_artifact_verification_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_verification_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_verification_receipts_immutable","table_name":"artifact_verification_receipts"},{"definition":"CREATE TRIGGER audit_events_reject_truncate BEFORE TRUNCATE ON audit_events FOR EACH STATEMENT EXECUTE FUNCTION reject_audit_event_mutation()","enabled":"O","name":"audit_events_reject_truncate","table_name":"audit_events"},{"definition":"CREATE TRIGGER audit_events_reject_update_delete BEFORE DELETE OR UPDATE ON audit_events FOR EACH ROW EXECUTE FUNCTION reject_audit_event_mutation()","enabled":"O","name":"audit_events_reject_update_delete","table_name":"audit_events"},{"definition":"CREATE TRIGGER audit_events_set_authority_time BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION set_authority_audit_database_time()","enabled":"O","name":"audit_events_set_authority_time","table_name":"audit_events"},{"definition":"CREATE TRIGGER audit_events_validate_idempotency BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION validate_linked_authority_event()","enabled":"O","name":"audit_events_validate_idempotency","table_name":"audit_events"},{"definition":"CREATE CONSTRAINT TRIGGER authority_control_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON authority_control DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()","enabled":"O","name":"authority_control_bootstrap_invariant","table_name":"authority_control"},{"definition":"CREATE TRIGGER authority_control_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_control FOR EACH ROW EXECUTE FUNCTION guard_authority_control()","enabled":"O","name":"authority_control_guard","table_name":"authority_control"},{"definition":"CREATE TRIGGER authority_control_reject_truncate BEFORE TRUNCATE ON authority_control FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_control_truncate()","enabled":"O","name":"authority_control_reject_truncate","table_name":"authority_control"},{"definition":"CREATE TRIGGER authority_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_authority_idempotency_record()","enabled":"O","name":"authority_idempotency_guard","table_name":"authority_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER authority_idempotency_pending_guard AFTER INSERT OR UPDATE ON authority_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION reject_pending_authority_idempotency()","enabled":"O","name":"authority_idempotency_pending_guard","table_name":"authority_idempotency_records"},{"definition":"CREATE TRIGGER authority_idempotency_reject_truncate BEFORE TRUNCATE ON authority_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_idempotency_truncate()","enabled":"O","name":"authority_idempotency_reject_truncate","table_name":"authority_idempotency_records"},{"definition":"CREATE TRIGGER contribution_award_definitions_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_award_definitions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()","enabled":"O","name":"contribution_award_definitions_content_guard","table_name":"contribution_award_definitions"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_award_definitions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_award_definitions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_award_definitions_graph_guard","table_name":"contribution_award_definitions"},{"definition":"CREATE TRIGGER contribution_award_definitions_reject_truncate BEFORE TRUNCATE ON contribution_award_definitions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_award_definitions_reject_truncate","table_name":"contribution_award_definitions"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_policies_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_policies_graph_guard","table_name":"contribution_policies"},{"definition":"CREATE TRIGGER contribution_policies_reject_truncate BEFORE TRUNCATE ON contribution_policies FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_policies_reject_truncate","table_name":"contribution_policies"},{"definition":"CREATE TRIGGER contribution_policy_versions_content_guard BEFORE DELETE OR UPDATE ON contribution_policy_versions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_version_content()","enabled":"O","name":"contribution_policy_versions_content_guard","table_name":"contribution_policy_versions"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_policy_versions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policy_versions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_policy_versions_graph_guard","table_name":"contribution_policy_versions"},{"definition":"CREATE TRIGGER contribution_policy_versions_reject_truncate BEFORE TRUNCATE ON contribution_policy_versions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_policy_versions_reject_truncate","table_name":"contribution_policy_versions"},{"definition":"CREATE TRIGGER contribution_rules_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_rules FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()","enabled":"O","name":"contribution_rules_content_guard","table_name":"contribution_rules"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_rules_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_rules DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_rules_graph_guard","table_name":"contribution_rules"},{"definition":"CREATE TRIGGER contribution_rules_reject_truncate BEFORE TRUNCATE ON contribution_rules FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_rules_reject_truncate","table_name":"contribution_rules"},{"definition":"CREATE CONSTRAINT TRIGGER effective_submission_policy_custody AFTER INSERT OR UPDATE ON effective_project_submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"effective_submission_policy_custody","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE TRIGGER effective_submission_policy_provenance_immutable BEFORE UPDATE ON effective_project_submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()","enabled":"O","name":"effective_submission_policy_provenance_immutable","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE TRIGGER guide_mutation_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON guide_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_guide_mutation_idempotency()","enabled":"O","name":"guide_mutation_idempotency_guard","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE TRIGGER guide_mutation_idempotency_reject_truncate BEFORE TRUNCATE ON guide_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_mutation_idempotency_truncate()","enabled":"O","name":"guide_mutation_idempotency_reject_truncate","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER guide_mutation_reservation_custody AFTER INSERT OR UPDATE ON guide_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"guide_mutation_reservation_custody","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER guide_source_snapshot_items_custody AFTER INSERT ON guide_source_snapshot_items DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_source_snapshot_items()","enabled":"O","name":"guide_source_snapshot_items_custody","table_name":"guide_source_snapshot_items"},{"definition":"CREATE TRIGGER guide_source_snapshot_items_immutable BEFORE DELETE OR UPDATE OR TRUNCATE ON guide_source_snapshot_items FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_source_snapshot_item_mutation()","enabled":"O","name":"guide_source_snapshot_items_immutable","table_name":"guide_source_snapshot_items"},{"definition":"CREATE CONSTRAINT TRIGGER source_snapshot_product_custody AFTER INSERT OR UPDATE ON guide_source_snapshots DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"source_snapshot_product_custody","table_name":"guide_source_snapshots"},{"definition":"CREATE TRIGGER trg_sufficiency_replay_immutable BEFORE DELETE OR UPDATE ON guide_sufficiency_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_sufficiency_replay_mutation()","enabled":"O","name":"trg_sufficiency_replay_immutable","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE TRIGGER trg_sufficiency_replay_no_truncate BEFORE TRUNCATE ON guide_sufficiency_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_sufficiency_replay_truncate()","enabled":"O","name":"trg_sufficiency_replay_no_truncate","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE TRIGGER iso_4217_currency_codes_immutable BEFORE INSERT OR DELETE OR UPDATE ON iso_4217_currency_codes FOR EACH ROW EXECUTE FUNCTION guard_iso_4217_currency_codes()","enabled":"O","name":"iso_4217_currency_codes_immutable","table_name":"iso_4217_currency_codes"},{"definition":"CREATE TRIGGER iso_4217_currency_codes_reject_truncate BEFORE TRUNCATE ON iso_4217_currency_codes FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"iso_4217_currency_codes_reject_truncate","table_name":"iso_4217_currency_codes"},{"definition":"CREATE TRIGGER outbox_events_custody BEFORE INSERT OR DELETE OR UPDATE ON outbox_events FOR EACH ROW EXECUTE FUNCTION guard_outbox_event()","enabled":"O","name":"outbox_events_custody","table_name":"outbox_events"},{"definition":"CREATE TRIGGER outbox_events_reject_truncate BEFORE TRUNCATE ON outbox_events FOR EACH STATEMENT EXECUTE FUNCTION guard_outbox_event()","enabled":"O","name":"outbox_events_reject_truncate","table_name":"outbox_events"},{"definition":"CREATE CONSTRAINT TRIGGER policy_mutation_replay_custody AFTER INSERT OR UPDATE ON policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()","enabled":"O","name":"policy_mutation_replay_custody","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER policy_mutation_replay_immutable BEFORE INSERT OR DELETE OR UPDATE ON policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_policy_mutation_replay()","enabled":"O","name":"policy_mutation_replay_immutable","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER policy_mutation_replay_reject_truncate BEFORE TRUNCATE ON policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_policy_mutation_replay_truncate()","enabled":"O","name":"policy_mutation_replay_reject_truncate","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER pre_submit_policy_custody AFTER INSERT OR UPDATE ON pre_submit_checker_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"pre_submit_policy_custody","table_name":"pre_submit_checker_policies"},{"definition":"CREATE TRIGGER pre_submit_policy_provenance_immutable BEFORE UPDATE ON pre_submit_checker_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()","enabled":"O","name":"pre_submit_policy_provenance_immutable","table_name":"pre_submit_checker_policies"},{"definition":"CREATE TRIGGER pre_submit_evidence_results_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()","enabled":"O","name":"pre_submit_evidence_results_immutable","table_name":"pre_submit_evidence_results"},{"definition":"CREATE TRIGGER pre_submit_evidence_results_membership BEFORE INSERT ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_result_membership()","enabled":"O","name":"pre_submit_evidence_results_membership","table_name":"pre_submit_evidence_results"},{"definition":"CREATE TRIGGER pre_submit_evidence_results_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_results FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()","enabled":"O","name":"pre_submit_evidence_results_no_truncate","table_name":"pre_submit_evidence_results"},{"definition":"CREATE TRIGGER pre_submit_evidence_sets_creation BEFORE INSERT ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_set_creation()","enabled":"O","name":"pre_submit_evidence_sets_creation","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE TRIGGER pre_submit_evidence_sets_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()","enabled":"O","name":"pre_submit_evidence_sets_immutable","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE TRIGGER pre_submit_evidence_sets_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_sets FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()","enabled":"O","name":"pre_submit_evidence_sets_no_truncate","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE TRIGGER project_compensation_binding_update_guard BEFORE UPDATE ON project_compensation_adapter_bindings FOR EACH ROW EXECUTE FUNCTION enforce_compensation_binding_lifecycle()","enabled":"O","name":"project_compensation_binding_update_guard","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE TRIGGER project_compensation_units_lifecycle_guard BEFORE INSERT OR DELETE OR UPDATE ON project_compensation_units FOR EACH ROW EXECUTE FUNCTION guard_project_compensation_units()","enabled":"O","name":"project_compensation_units_lifecycle_guard","table_name":"project_compensation_units"},{"definition":"CREATE TRIGGER project_compensation_units_reject_truncate BEFORE TRUNCATE ON project_compensation_units FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"project_compensation_units_reject_truncate","table_name":"project_compensation_units"},{"definition":"CREATE TRIGGER project_create_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON project_create_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_project_create_idempotency()","enabled":"O","name":"project_create_idempotency_guard","table_name":"project_create_idempotency_records"},{"definition":"CREATE TRIGGER project_create_idempotency_reject_truncate BEFORE TRUNCATE ON project_create_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_project_create_idempotency_truncate()","enabled":"O","name":"project_create_idempotency_reject_truncate","table_name":"project_create_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER project_create_reservation_custody AFTER INSERT OR UPDATE ON project_create_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()","enabled":"O","name":"project_create_reservation_custody","table_name":"project_create_idempotency_records"},{"definition":"CREATE TRIGGER trg_compilation_attempt_delete BEFORE DELETE OR TRUNCATE ON project_guide_compilation_attempts FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()","enabled":"O","name":"trg_compilation_attempt_delete","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE TRIGGER trg_compilation_attempt_update BEFORE UPDATE ON project_guide_compilation_attempts FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_attempt_update()","enabled":"O","name":"trg_compilation_attempt_update","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE TRIGGER trg_compilation_insert BEFORE INSERT ON project_guide_compilations FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_insert()","enabled":"O","name":"trg_compilation_insert","table_name":"project_guide_compilations"},{"definition":"CREATE TRIGGER trg_compilation_mutation BEFORE DELETE OR UPDATE OR TRUNCATE ON project_guide_compilations FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()","enabled":"O","name":"trg_compilation_mutation","table_name":"project_guide_compilations"},{"definition":"CREATE TRIGGER guide_lineage_lifecycle_guard BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_guide_lineage_and_lifecycle()","enabled":"O","name":"guide_lineage_lifecycle_guard","table_name":"project_guides"},{"definition":"CREATE CONSTRAINT TRIGGER guide_mutation_product_custody AFTER INSERT OR UPDATE ON project_guides DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"guide_mutation_product_custody","table_name":"project_guides"},{"definition":"CREATE TRIGGER project_guides_policy_selection_immutable BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_project_guide_policy_selection()","enabled":"O","name":"project_guides_policy_selection_immutable","table_name":"project_guides"},{"definition":"CREATE TRIGGER trg_project_role_grants_history BEFORE INSERT OR DELETE OR UPDATE ON project_role_grants FOR EACH ROW EXECUTE FUNCTION guard_project_role_grant_history()","enabled":"O","name":"trg_project_role_grants_history","table_name":"project_role_grants"},{"definition":"CREATE TRIGGER trg_project_role_grants_reject_truncate BEFORE TRUNCATE ON project_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()","enabled":"O","name":"trg_project_role_grants_reject_truncate","table_name":"project_role_grants"},{"definition":"CREATE TRIGGER trg_project_role_qualification_snapshots_immutable BEFORE INSERT OR DELETE OR UPDATE ON project_role_qualification_snapshots FOR EACH ROW EXECUTE FUNCTION guard_project_role_snapshot_history()","enabled":"O","name":"trg_project_role_qualification_snapshots_immutable","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE TRIGGER trg_project_role_snapshots_reject_truncate BEFORE TRUNCATE ON project_role_qualification_snapshots FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()","enabled":"O","name":"trg_project_role_snapshots_reject_truncate","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE CONSTRAINT TRIGGER source_setup_run_custody AFTER INSERT OR UPDATE ON project_setup_runs DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"source_setup_run_custody","table_name":"project_setup_runs"},{"definition":"CREATE CONSTRAINT TRIGGER project_creation_custody AFTER INSERT OR UPDATE OF created_by_actor_profile_id, created_via_identity_link_id, created_by_admin_role_grant_id, creation_scope_type, creation_action_id, authorization_decision_event_id ON projects DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()","enabled":"O","name":"project_creation_custody","table_name":"projects"},{"definition":"CREATE TRIGGER review_admission_idempotency_records_reject_truncate BEFORE TRUNCATE ON review_admission_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()","enabled":"O","name":"review_admission_idempotency_records_reject_truncate","table_name":"review_admission_idempotency_records"},{"definition":"CREATE TRIGGER review_admission_records_guard BEFORE INSERT OR DELETE OR UPDATE ON review_admission_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_review_admission_record()","enabled":"O","name":"review_admission_records_guard","table_name":"review_admission_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER review_leases_active_lease_guard AFTER INSERT OR UPDATE ON review_leases DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()","enabled":"O","name":"review_leases_active_lease_guard","table_name":"review_leases"},{"definition":"CREATE TRIGGER review_leases_guard BEFORE INSERT OR DELETE OR UPDATE ON review_leases FOR EACH ROW EXECUTE FUNCTION guard_review_lease()","enabled":"O","name":"review_leases_guard","table_name":"review_leases"},{"definition":"CREATE TRIGGER review_leases_reject_truncate BEFORE TRUNCATE ON review_leases FOR EACH STATEMENT EXECUTE FUNCTION reject_review_lease_truncate()","enabled":"O","name":"review_leases_reject_truncate","table_name":"review_leases"},{"definition":"CREATE TRIGGER review_policies_immutable BEFORE DELETE OR UPDATE ON review_policies FOR EACH ROW EXECUTE FUNCTION guard_review_policies_immutable()","enabled":"O","name":"review_policies_immutable","table_name":"review_policies"},{"definition":"CREATE TRIGGER review_policies_reject_truncate BEFORE TRUNCATE ON review_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_review_policies_immutable()","enabled":"O","name":"review_policies_reject_truncate","table_name":"review_policies"},{"definition":"CREATE CONSTRAINT TRIGGER review_policy_mutation_custody AFTER INSERT OR UPDATE ON review_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()","enabled":"O","name":"review_policy_mutation_custody","table_name":"review_policies"},{"definition":"CREATE CONSTRAINT TRIGGER review_queue_entries_active_lease_guard AFTER INSERT OR UPDATE ON review_queue_entries DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()","enabled":"O","name":"review_queue_entries_active_lease_guard","table_name":"review_queue_entries"},{"definition":"CREATE TRIGGER review_queue_entries_guard BEFORE INSERT OR DELETE OR UPDATE ON review_queue_entries FOR EACH ROW EXECUTE FUNCTION guard_review_queue_entry()","enabled":"O","name":"review_queue_entries_guard","table_name":"review_queue_entries"},{"definition":"CREATE TRIGGER review_queue_entries_reject_truncate BEFORE TRUNCATE ON review_queue_entries FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()","enabled":"O","name":"review_queue_entries_reject_truncate","table_name":"review_queue_entries"},{"definition":"CREATE TRIGGER revision_policies_immutable BEFORE DELETE OR UPDATE ON revision_policies FOR EACH ROW EXECUTE FUNCTION guard_revision_policies_immutable()","enabled":"O","name":"revision_policies_immutable","table_name":"revision_policies"},{"definition":"CREATE TRIGGER revision_policies_reject_truncate BEFORE TRUNCATE ON revision_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_revision_policies_immutable()","enabled":"O","name":"revision_policies_reject_truncate","table_name":"revision_policies"},{"definition":"CREATE CONSTRAINT TRIGGER revision_policy_mutation_custody AFTER INSERT OR UPDATE ON revision_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()","enabled":"O","name":"revision_policy_mutation_custody","table_name":"revision_policies"},{"definition":"CREATE TRIGGER submission_policy_approval_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_approval_provenance()","enabled":"O","name":"submission_policy_approval_provenance_immutable","table_name":"submission_artifact_policies"},{"definition":"CREATE CONSTRAINT TRIGGER submission_policy_creation_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_creation_custody()","enabled":"O","name":"submission_policy_creation_custody","table_name":"submission_artifact_policies"},{"definition":"CREATE TRIGGER submission_policy_creation_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_creation_provenance()","enabled":"O","name":"submission_policy_creation_provenance_immutable","table_name":"submission_artifact_policies"},{"definition":"CREATE CONSTRAINT TRIGGER submission_policy_product_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"submission_policy_product_custody","table_name":"submission_artifact_policies"},{"definition":"CREATE TRIGGER submission_bundle_admission_delete BEFORE DELETE OR TRUNCATE ON submission_bundle_admissions FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_admission_delete()","enabled":"O","name":"submission_bundle_admission_delete","table_name":"submission_bundle_admissions"},{"definition":"CREATE TRIGGER submission_bundle_admission_lineage BEFORE UPDATE ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_lineage()","enabled":"O","name":"submission_bundle_admission_lineage","table_name":"submission_bundle_admissions"},{"definition":"CREATE TRIGGER submission_bundle_admission_verified_lineage BEFORE INSERT ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_verified_lineage()","enabled":"O","name":"submission_bundle_admission_verified_lineage","table_name":"submission_bundle_admissions"},{"definition":"CREATE TRIGGER submission_bundle_durable_intent_put_attempt BEFORE INSERT ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intent_put_attempt()","enabled":"O","name":"submission_bundle_durable_intent_put_attempt","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE TRIGGER submission_bundle_durable_intents_immutable BEFORE DELETE OR UPDATE ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()","enabled":"O","name":"submission_bundle_durable_intents_immutable","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE TRIGGER submission_bundle_durable_intents_no_truncate BEFORE TRUNCATE ON submission_bundle_durable_intents FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()","enabled":"O","name":"submission_bundle_durable_intents_no_truncate","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE CONSTRAINT TRIGGER submission_policy_replay_custody AFTER INSERT OR UPDATE ON submission_policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW WHEN (new.status::text = 'committed'::text) EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"submission_policy_replay_custody","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER trg_submission_policy_replay_immutable BEFORE DELETE OR UPDATE ON submission_policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_submission_policy_replay_mutation()","enabled":"O","name":"trg_submission_policy_replay_immutable","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER trg_submission_policy_replay_no_truncate BEFORE TRUNCATE ON submission_policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_submission_policy_replay_truncate()","enabled":"O","name":"trg_submission_policy_replay_no_truncate","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER submissions_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON submissions FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')","enabled":"O","name":"submissions_contributor_human","table_name":"submissions"},{"definition":"CREATE TRIGGER task_assignments_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON task_assignments FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')","enabled":"O","name":"task_assignments_contributor_human","table_name":"task_assignments"}],"types":[]} diff --git a/backend/alembic/baseline/v01_pre_reset_source_manifest.json b/backend/alembic/baseline/v01_pre_reset_source_manifest.json index 782531c5d..cb9a02e26 100644 --- a/backend/alembic/baseline/v01_pre_reset_source_manifest.json +++ b/backend/alembic/baseline/v01_pre_reset_source_manifest.json @@ -1,26923 +1 @@ -{ - "acl": [ - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_identity_links", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profile_migration_state", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "actor_profiles", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "admin_role_grants", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "api_rate_control_counters", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_charges", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_admission_scopes", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_bindings", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_contents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_operation_receipts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempt_charges", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_put_observation_receipts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_recovery_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_replicas", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_storage_namespaces", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_jobs", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "artifact_verification_receipts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "audit_events", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_control", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "authority_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_results", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "checker_runs", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_award_definitions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_policy_versions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "contribution_rules", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "effective_project_submission_artifact_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "evidence_items", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_bindings", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_incidents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_artifact_ingests", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extracted_contents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_retry_budgets", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_extraction_usages", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_format_classifications", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshot_items", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_source_snapshots", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_report_source_usages", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "guide_sufficiency_reports", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "iso_4217_currency_codes", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_actor_identities", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "legacy_workflow_eligibility", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "outbox_events", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "payment_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_checker_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_results", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "pre_submit_evidence_sets", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_adapter_bindings", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_compensation_units", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_create_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilation_attempts", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guide_compilations", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_guides", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_grants", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_role_qualification_snapshots", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "project_setup_runs", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "projects", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_admission_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_leases", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "review_queue_entries", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "revision_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_artifact_policies", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_admissions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_bundle_durable_intents", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submission_policy_mutation_idempotency_records", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "submissions", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "task_assignments", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "DELETE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "INSERT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "REFERENCES" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "SELECT" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "TRIGGER" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "TRUNCATE" - }, - { - "grantable": "false", - "kind": "relation", - "name": "workstream_tasks", - "principal": "owner", - "privilege": "UPDATE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_event_facts_are_safe(event_name text, before_state js", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_event_facts_are_safe(event_name text, before_state js", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_facts_are_safe(facts json)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_facts_are_safe(facts json)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "authority_grant_facts_are_safe(facts json, roles text[], expect", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "enforce_compensation_binding_lifecycle()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "enforce_compensation_binding_lifecycle()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_identity_link_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_identity_link_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_profile_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_actor_profile_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_admin_role_grant()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_admin_role_grant()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_artifact_receipt_producer_reference()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_artifact_receipt_producer_reference()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_control()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_control()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_idempotency_record()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_authority_idempotency_record()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_children()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_children()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_version_content()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_contribution_policy_version_content()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_lineage_and_lifecycle()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_lineage_and_lifecycle()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_mutation_idempotency()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_guide_mutation_idempotency()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_iso_4217_currency_codes()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_iso_4217_currency_codes()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_outbox_event()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_outbox_event()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_policy_mutation_replay()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_policy_mutation_replay()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_result_membership()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_result_membership()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_results_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_results_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_set_creation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_set_creation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_sets_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_pre_submit_evidence_sets_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_compensation_units()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_compensation_units()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_create_idempotency()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_create_idempotency()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_attempt_update()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_attempt_update()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_insert()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_compilation_insert()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_policy_selection()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_guide_policy_selection()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_grant_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_grant_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_snapshot_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_project_role_snapshot_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_admission_record()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_admission_record()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_lease()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_lease()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_policies_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_policies_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_queue_entry()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_review_queue_entry()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_revision_policies_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_revision_policies_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_service_identity_migration_evidence()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_service_identity_migration_evidence()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_delete()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_delete()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_lineage()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_lineage()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_verified_lineage()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_admission_verified_lineage()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intent_put_attempt()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intent_put_attempt()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intents_immutable()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "guard_submission_bundle_durable_intents_immutable()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_availability_is_safe(value jsonb)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_availability_is_safe(value jsonb)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reason_is_safe(value text)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reason_is_safe(value text)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_array_is_safe(value jsonb, uuid_only boo", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_token_is_safe(value text)", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "project_role_reference_token_is_safe(value text)", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_approval_provenance()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_approval_provenance()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_creation_provenance()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_creation_provenance()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_output_provenance()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "protect_submission_policy_output_provenance()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_admin_role_grant_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_admin_role_grant_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_artifact_fact_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_artifact_fact_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_audit_event_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_audit_event_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_control_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_control_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_idempotency_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_authority_idempotency_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_contribution_policy_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_contribution_policy_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_mutation_idempotency_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_mutation_idempotency_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_source_snapshot_item_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_guide_source_snapshot_item_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_pending_authority_idempotency()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_pending_authority_idempotency()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_policy_mutation_replay_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_policy_mutation_replay_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_create_idempotency_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_create_idempotency_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_guide_compilation_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_guide_compilation_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_role_history_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_project_role_history_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_lease_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_lease_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_queue_foundation_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_review_queue_foundation_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_submission_policy_replay_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_mutation()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_mutation()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_truncate()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "reject_sufficiency_replay_truncate()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "require_human_actor_profile_reference()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "require_human_actor_profile_reference()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "set_authority_audit_database_time()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "set_authority_audit_database_time()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_binding_history()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_binding_history()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_recovery_attempt()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_recovery_attempt()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_verification_lineage()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_artifact_verification_lineage()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_bootstrap_authority_state()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_bootstrap_authority_state()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_canonical_actor_link()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_canonical_actor_link()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_contribution_policy_graph()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_contribution_policy_graph()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_mutation_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_mutation_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_source_snapshot_items()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_guide_source_snapshot_items()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_linked_authority_event()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_linked_authority_event()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_policy_mutation_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_policy_mutation_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_project_create_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_project_create_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_review_active_lease()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_review_active_lease()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_authority_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_authority_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_creation_custody()", - "principal": "PUBLIC", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "routine", - "name": "validate_submission_policy_creation_custody()", - "principal": "owner", - "privilege": "EXECUTE" - }, - { - "grantable": "false", - "kind": "sequence", - "name": "actor_profile_migration_state_id_seq", - "principal": "owner", - "privilege": "USAGE" - }, - { - "grantable": "false", - "kind": "sequence", - "name": "authority_control_id_seq", - "principal": "owner", - "privilege": "USAGE" - } - ], - "auxiliary_objects": [], - "columns": [ - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "issuer", - "not_null": true, - "ordinal": 3, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "subject", - "not_null": true, - "ordinal": 4, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "subject_kind", - "not_null": true, - "ordinal": 5, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "linked_by", - "not_null": true, - "ordinal": 7, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "linked_at", - "not_null": true, - "ordinal": 8, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_verified_at", - "not_null": false, - "ordinal": 9, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by", - "not_null": false, - "ordinal": 10, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_at", - "not_null": false, - "ordinal": 11, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_reason", - "not_null": false, - "ordinal": 12, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_by", - "not_null": false, - "ordinal": 13, - "table_name": "actor_identity_links" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_at", - "not_null": false, - "ordinal": 14, - "table_name": "actor_identity_links" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivation_reason", - "not_null": false, - "ordinal": 15, - "table_name": "actor_identity_links" - }, - { - "data_type": "integer", - "default_expression": "nextval('actor_profile_migration_state_id_seq'::regclass)", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "schema_version", - "not_null": true, - "ordinal": 2, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classified_count", - "not_null": true, - "ordinal": 3, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_row_set_sha256", - "not_null": true, - "ordinal": 4, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "manifest_sha256", - "not_null": false, - "ordinal": 5, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "envelope_sha256", - "not_null": false, - "ordinal": 6, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "migrated_at", - "not_null": true, - "ordinal": 7, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_mapped_count", - "not_null": true, - "ordinal": 8, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_source_row_set_sha256", - "not_null": true, - "ordinal": 9, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_manifest_sha256", - "not_null": false, - "ordinal": 10, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_envelope_sha256", - "not_null": false, - "ordinal": 11, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(76)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity_database_binding", - "not_null": true, - "ordinal": 12, - "table_name": "actor_profile_migration_state" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_kind", - "not_null": true, - "ordinal": 2, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 3, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provisioning_method", - "not_null": true, - "ordinal": 4, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "display_name", - "not_null": false, - "ordinal": 5, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(320)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contact_email", - "not_null": false, - "ordinal": 6, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 7, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 8, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 9, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_seen_at", - "not_null": false, - "ordinal": 10, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_by", - "not_null": false, - "ordinal": 11, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_at", - "not_null": false, - "ordinal": 12, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspension_reason", - "not_null": false, - "ordinal": 13, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deactivated_by", - "not_null": false, - "ordinal": 14, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deactivated_at", - "not_null": false, - "ordinal": 15, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deactivation_reason", - "not_null": false, - "ordinal": 16, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity", - "not_null": false, - "ordinal": 17, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_by", - "not_null": false, - "ordinal": 18, - "table_name": "actor_profiles" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivated_at", - "not_null": false, - "ordinal": 19, - "table_name": "actor_profiles" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reactivation_reason", - "not_null": false, - "ordinal": 20, - "table_name": "actor_profiles" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "role", - "not_null": true, - "ordinal": 3, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 4, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_project_id", - "not_null": false, - "ordinal": 5, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "admin_role_grants" - }, - { - "data_type": "smallint", - "default_expression": "'1'::smallint", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 7, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_actor_profile_id", - "not_null": false, - "ordinal": 8, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_system_principal", - "not_null": false, - "ordinal": 9, - "table_name": "admin_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_admin_role_grant_id", - "not_null": false, - "ordinal": 10, - "table_name": "admin_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "grant_reason", - "not_null": true, - "ordinal": 11, - "table_name": "admin_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "clock_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_at", - "not_null": true, - "ordinal": 12, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_actor_profile_id", - "not_null": false, - "ordinal": 13, - "table_name": "admin_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_admin_role_grant_id", - "not_null": false, - "ordinal": 14, - "table_name": "admin_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_reason", - "not_null": false, - "ordinal": 15, - "table_name": "admin_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_at", - "not_null": false, - "ordinal": 16, - "table_name": "admin_role_grants" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "control_scope", - "not_null": true, - "ordinal": 1, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "bytea", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "key_digest", - "not_null": true, - "ordinal": 2, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "window_started_at", - "not_null": true, - "ordinal": 3, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "window_expires_at", - "not_null": true, - "ordinal": 4, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_count", - "not_null": true, - "ordinal": 5, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 6, - "table_name": "api_rate_control_counters" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_type", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_ref", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creating_operation_identity", - "not_null": true, - "ordinal": 8, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(20)", - "default_expression": "'provisional'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "state", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "reserved_at", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "completed_at", - "not_null": false, - "ordinal": 12, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "released_at", - "not_null": false, - "ordinal": 13, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 15, - "table_name": "artifact_admission_charges" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "limit_bytes", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "counted_bytes", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_admission_scopes" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_type", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_id", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_bindings" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_version", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 8, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attribution_type", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_binding_id", - "not_null": false, - "ordinal": 10, - "table_name": "artifact_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_contents" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": false, - "ordinal": 4, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "normalized_display_name", - "not_null": false, - "ordinal": 5, - "table_name": "artifact_contents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_contents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replica_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(1024)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_object_ref", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replayed", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome", - "not_null": true, - "ordinal": 8, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_number", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "details", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "contract_version", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_source_item_id", - "not_null": false, - "ordinal": 15, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_run_id", - "not_null": false, - "ordinal": 16, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": false, - "ordinal": 17, - "table_name": "artifact_operation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_put_attempt_charges" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "charge_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_put_attempt_charges" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_put_attempt_charges" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_request_type", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_type", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer_ref", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": false, - "ordinal": 6, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_source_item_id", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_run_id", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": false, - "ordinal": 9, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(255)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "storage_namespace_id", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_fingerprint", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(1024)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_target", - "not_null": true, - "ordinal": 15, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_identity", - "not_null": true, - "ordinal": 16, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 17, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "'prepared'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 18, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "next_run_at", - "not_null": false, - "ordinal": 19, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "executor_id", - "not_null": false, - "ordinal": 20, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lease_expires_at", - "not_null": false, - "ordinal": 21, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 22, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_result_code", - "not_null": false, - "ordinal": 23, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replica_id", - "not_null": false, - "ordinal": 24, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "receipt_id", - "not_null": false, - "ordinal": 25, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 26, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "prepared_at", - "not_null": true, - "ordinal": 27, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 28, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 29, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 30, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_mode", - "not_null": false, - "ordinal": 31, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "observation_count", - "not_null": true, - "ordinal": 32, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'5'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "maximum_observations", - "not_null": true, - "ordinal": 33, - "table_name": "artifact_put_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "expected_sha256", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "expected_byte_count", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_sha256", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_byte_count", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 9, - "table_name": "artifact_put_observation_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requester_actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requester_identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_request_id", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_correlation_id", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_verification_job_id", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retry_verification_job_id", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "parent_recovery_attempt_id", - "not_null": false, - "ordinal": 11, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "recovery_class", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(1000)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reason", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "client_idempotency_key", - "not_null": true, - "ordinal": 14, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 15, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(20)", - "default_expression": "'requested'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 16, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_result_code", - "not_null": false, - "ordinal": 17, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "initiation_audit_event_id", - "not_null": true, - "ordinal": 18, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_audit_event_id", - "not_null": false, - "ordinal": 19, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 20, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 21, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 22, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": false, - "ordinal": 23, - "table_name": "artifact_recovery_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(1024)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_object_ref", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verification_state", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "availability_state", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "integrity_state", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_replicas" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_reconciled_at", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_replicas" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 9, - "table_name": "artifact_replicas" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "storage_namespace_id", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_fingerprint", - "not_null": true, - "ordinal": 12, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_profile", - "not_null": true, - "ordinal": 13, - "table_name": "artifact_replicas" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "backend", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_profile", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_descriptor", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "namespace_fingerprint", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "artifact_storage_namespaces" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "originating_put_attempt_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "replica_id", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(40)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "integer", - "default_expression": "0", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_count", - "not_null": true, - "ordinal": 5, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "maximum_attempts", - "not_null": true, - "ordinal": 6, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "next_run_at", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "executor_id", - "not_null": false, - "ordinal": 8, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lease_expires_at", - "not_null": false, - "ordinal": 9, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 10, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "cas_version", - "not_null": true, - "ordinal": 11, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_result_code", - "not_null": false, - "ordinal": 12, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 13, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 14, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": false, - "ordinal": 15, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "parent_verification_job_id", - "not_null": false, - "ordinal": 16, - "table_name": "artifact_verification_jobs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verification_job_id", - "not_null": true, - "ordinal": 2, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "execution_generation", - "not_null": true, - "ordinal": 3, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome", - "not_null": true, - "ordinal": 4, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_sha256", - "not_null": false, - "ordinal": 5, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_byte_count", - "not_null": false, - "ordinal": 6, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": false, - "ordinal": 7, - "table_name": "artifact_verification_receipts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "audit_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "entity_type", - "not_null": true, - "ordinal": 2, - "table_name": "audit_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "entity_id", - "not_null": true, - "ordinal": 3, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_type", - "not_null": true, - "ordinal": 4, - "table_name": "audit_events" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "from_status", - "not_null": false, - "ordinal": 5, - "table_name": "audit_events" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "to_status", - "not_null": false, - "ordinal": 6, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 7, - "table_name": "audit_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_subject", - "not_null": false, - "ordinal": 8, - "table_name": "audit_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_issuer", - "not_null": false, - "ordinal": 9, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_roles", - "not_null": true, - "ordinal": 10, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_snapshot", - "not_null": true, - "ordinal": 11, - "table_name": "audit_events" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "auth_source", - "not_null": true, - "ordinal": 12, - "table_name": "audit_events" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "is_dev_auth", - "not_null": true, - "ordinal": 13, - "table_name": "audit_events" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reason", - "not_null": false, - "ordinal": 14, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_payload", - "not_null": true, - "ordinal": 15, - "table_name": "audit_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "audit_events" - }, - { - "data_type": "character varying(24)", - "default_expression": "'legacy_lifecycle'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_domain", - "not_null": true, - "ordinal": 17, - "table_name": "audit_events" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_version", - "not_null": false, - "ordinal": 18, - "table_name": "audit_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "occurred_at", - "not_null": false, - "ordinal": 19, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_ref_kind", - "not_null": false, - "ordinal": 20, - "table_name": "audit_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_id", - "not_null": false, - "ordinal": 21, - "table_name": "audit_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": false, - "ordinal": 22, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_actor_ref_kind", - "not_null": false, - "ordinal": 23, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_actor_ref", - "not_null": false, - "ordinal": 24, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "matched_grant_id", - "not_null": false, - "ordinal": 25, - "table_name": "audit_events" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "permission_id", - "not_null": false, - "ordinal": 26, - "table_name": "audit_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": false, - "ordinal": 27, - "table_name": "audit_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_type", - "not_null": false, - "ordinal": 28, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_id", - "not_null": false, - "ordinal": 29, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_ref_kind", - "not_null": false, - "ordinal": 30, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "target_ref_id", - "not_null": false, - "ordinal": 31, - "table_name": "audit_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "denial_code", - "not_null": false, - "ordinal": 32, - "table_name": "audit_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_reference", - "not_null": false, - "ordinal": 33, - "table_name": "audit_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "invalidation_cause_event_id", - "not_null": false, - "ordinal": 34, - "table_name": "audit_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "invalidation_target_kind", - "not_null": false, - "ordinal": 35, - "table_name": "audit_events" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "invalidation_target_ref", - "not_null": false, - "ordinal": 36, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "before_facts", - "not_null": false, - "ordinal": 37, - "table_name": "audit_events" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "after_facts", - "not_null": false, - "ordinal": 38, - "table_name": "audit_events" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": false, - "ordinal": 39, - "table_name": "audit_events" - }, - { - "data_type": "smallint", - "default_expression": "nextval('authority_control_id_seq'::regclass)", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "authority_control" - }, - { - "data_type": "boolean", - "default_expression": "false", - "generated_kind": "00", - "identity_kind": "00", - "name": "bootstrap_completed", - "not_null": true, - "ordinal": 2, - "table_name": "authority_control" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bootstrap_grant_id", - "not_null": false, - "ordinal": 3, - "table_name": "authority_control" - }, - { - "data_type": "smallint", - "default_expression": "'0'::smallint", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 4, - "table_name": "authority_control" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "clock_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 5, - "table_name": "authority_control" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "clock_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 6, - "table_name": "authority_control" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 2, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_ref_kind", - "not_null": true, - "ordinal": 3, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_ref", - "not_null": true, - "ordinal": 4, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(48)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation", - "not_null": true, - "ordinal": 5, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 7, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_resource_type", - "not_null": false, - "ordinal": 8, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_resource_id", - "not_null": false, - "ordinal": 9, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_resource_version", - "not_null": false, - "ordinal": 10, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "smallint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_http_status", - "not_null": false, - "ordinal": 11, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 12, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 13, - "table_name": "authority_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "required_checkers", - "not_null": true, - "ordinal": 4, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_checkers", - "not_null": true, - "ordinal": 5, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "blocking_severities", - "not_null": true, - "ordinal": 6, - "table_name": "checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": false, - "ordinal": 8, - "table_name": "checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_body", - "not_null": false, - "ordinal": 9, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 10, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 11, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 12, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_id", - "not_null": true, - "ordinal": 13, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_hash", - "not_null": true, - "ordinal": 14, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_checker_policy_id", - "not_null": true, - "ordinal": 15, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_checker_bundle_hash", - "not_null": true, - "ordinal": 16, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 17, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_role", - "not_null": false, - "ordinal": 18, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_actor", - "not_null": false, - "ordinal": 19, - "table_name": "checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_at", - "not_null": false, - "ordinal": 20, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 21, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 22, - "table_name": "checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 23, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_by_role", - "not_null": false, - "ordinal": 24, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_by_actor", - "not_null": false, - "ordinal": 25, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersession_kind", - "not_null": false, - "ordinal": 26, - "table_name": "checker_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersession_reason", - "not_null": false, - "ordinal": 27, - "table_name": "checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_run_id", - "not_null": true, - "ordinal": 2, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 3, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 4, - "table_name": "checker_results" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_name", - "not_null": true, - "ordinal": 5, - "table_name": "checker_results" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "checker_results" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "severity", - "not_null": true, - "ordinal": 7, - "table_name": "checker_results" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "blocks_review", - "not_null": true, - "ordinal": 8, - "table_name": "checker_results" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "message", - "not_null": true, - "ordinal": 9, - "table_name": "checker_results" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_message", - "not_null": false, - "ordinal": 10, - "table_name": "checker_results" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_suggested_fix", - "not_null": false, - "ordinal": 11, - "table_name": "checker_results" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_evidence_refs", - "not_null": true, - "ordinal": 12, - "table_name": "checker_results" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_visible", - "not_null": true, - "ordinal": 13, - "table_name": "checker_results" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "metadata", - "not_null": true, - "ordinal": 14, - "table_name": "checker_results" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 15, - "table_name": "checker_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 2, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 3, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 4, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "trigger_source", - "not_null": true, - "ordinal": 5, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_recommendation", - "not_null": true, - "ordinal": 7, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "outcome_source", - "not_null": true, - "ordinal": 8, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "triggered_by", - "not_null": true, - "ordinal": 9, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "triggered_by_subject", - "not_null": true, - "ordinal": 10, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "triggered_by_issuer", - "not_null": true, - "ordinal": 11, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "trigger_auth_source", - "not_null": true, - "ordinal": 12, - "table_name": "checker_runs" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "trigger_reason", - "not_null": false, - "ordinal": 13, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "audit_event_id", - "not_null": false, - "ordinal": 14, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_number", - "not_null": true, - "ordinal": 15, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_checker_run_id", - "not_null": false, - "ordinal": 16, - "table_name": "checker_runs" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "is_current_for_submission", - "not_null": true, - "ordinal": 17, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_version", - "not_null": true, - "ordinal": 18, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_payment_policy_version", - "not_null": true, - "ordinal": 19, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "package_hash", - "not_null": true, - "ordinal": 20, - "table_name": "checker_runs" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_hash_manifest", - "not_null": true, - "ordinal": 21, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_manifest_hash", - "not_null": true, - "ordinal": 22, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "passed_count", - "not_null": true, - "ordinal": 23, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_count", - "not_null": true, - "ordinal": 24, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failed_count", - "not_null": true, - "ordinal": 25, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "blocking_count", - "not_null": true, - "ordinal": 26, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "queued_at", - "not_null": true, - "ordinal": 27, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "started_at", - "not_null": false, - "ordinal": 28, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "completed_at", - "not_null": false, - "ordinal": 29, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_code", - "not_null": false, - "ordinal": 30, - "table_name": "checker_runs" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_message", - "not_null": false, - "ordinal": 31, - "table_name": "checker_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 32, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 33, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_version", - "not_null": false, - "ordinal": 34, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_hash", - "not_null": false, - "ordinal": 35, - "table_name": "checker_runs" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_body", - "not_null": false, - "ordinal": 36, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_id", - "not_null": true, - "ordinal": 37, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_generation", - "not_null": true, - "ordinal": 38, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_hash", - "not_null": true, - "ordinal": 39, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_id", - "not_null": true, - "ordinal": 40, - "table_name": "checker_runs" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_generation", - "not_null": true, - "ordinal": 41, - "table_name": "checker_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_hash", - "not_null": true, - "ordinal": 42, - "table_name": "checker_runs" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_rule_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_policy_version_id", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_type", - "not_null": true, - "ordinal": 5, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instrument_type", - "not_null": true, - "ordinal": 6, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "unit_code", - "not_null": true, - "ordinal": 7, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "numeric", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "quantity", - "not_null": true, - "ordinal": 8, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter_binding_id", - "not_null": true, - "ordinal": 9, - "table_name": "contribution_award_definitions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "name", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "'draft'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "current_published_version_id", - "not_null": false, - "ordinal": 5, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 6, - "table_name": "contribution_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "contribution_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 8, - "table_name": "contribution_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 9, - "table_name": "contribution_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_policy_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "version_number", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(16)", - "default_expression": "'draft'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 6, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "published_by", - "not_null": false, - "ordinal": 8, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "published_at", - "not_null": false, - "ordinal": 9, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 10, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 11, - "table_name": "contribution_policy_versions" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "contribution_rules" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_policy_version_id", - "not_null": true, - "ordinal": 2, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contribution_type", - "not_null": true, - "ordinal": 4, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compensation_mode", - "not_null": true, - "ordinal": 5, - "table_name": "contribution_rules" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_artifact_policy_id", - "not_null": true, - "ordinal": 7, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_artifact_policy_hash", - "not_null": true, - "ordinal": 8, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 9, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "merge_algorithm_version", - "not_null": true, - "ordinal": 10, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy", - "not_null": true, - "ordinal": 11, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_hash", - "not_null": true, - "ordinal": 12, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 13, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_effective_policy_id", - "not_null": false, - "ordinal": 15, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 16, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 17, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 18, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 19, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 20, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 21, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 22, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_decision_event_id", - "not_null": false, - "ordinal": 23, - "table_name": "effective_project_submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 2, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "type", - "not_null": true, - "ordinal": 3, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "label", - "not_null": true, - "ordinal": 4, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(1000)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "uri", - "not_null": false, - "ordinal": 5, - "table_name": "evidence_items" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "hash", - "not_null": false, - "ordinal": 6, - "table_name": "evidence_items" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "size_bytes", - "not_null": false, - "ordinal": 7, - "table_name": "evidence_items" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_at", - "not_null": false, - "ordinal": 8, - "table_name": "evidence_items" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "metadata", - "not_null": true, - "ordinal": 9, - "table_name": "evidence_items" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "evidence_items" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 7, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_id", - "not_null": true, - "ordinal": 10, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_generation", - "not_null": true, - "ordinal": 11, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 12, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 13, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": false, - "ordinal": 14, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 15, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 16, - "table_name": "guide_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "logical_role", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_binding_id", - "not_null": false, - "ordinal": 11, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service", - "not_null": true, - "ordinal": 12, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_artifact_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "code", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_sha256", - "not_null": false, - "ordinal": 7, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "observed_byte_count", - "not_null": false, - "ordinal": 8, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bounded_facts", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_artifact_incidents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(255)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_artifact_ingests" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detected_format", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_name", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_version", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_sha256", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_byte_count", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_sha256", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_output", - "not_null": true, - "ordinal": 11, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "omission_facts", - "not_null": true, - "ordinal": 12, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_extracted_contents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detected_format", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_name", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extractor_version", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_number", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 11, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_code", - "not_null": false, - "ordinal": 12, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bounded_facts", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "guide_source_extraction_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claimed_slots", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extracted_content_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extraction_attempt_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_status", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_extraction_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "sha256", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "byte_count", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(255)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detected_format", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detector_name", - "not_null": true, - "ordinal": 11, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "detector_version", - "not_null": true, - "ordinal": 12, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification_facts", - "not_null": true, - "ordinal": 13, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 14, - "table_name": "guide_source_format_classifications" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "item_order", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_kind", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_label", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "ingestion_adapter", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "media_type", - "not_null": false, - "ordinal": 7, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_snapshot_items" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "manifest_schema_version", - "not_null": true, - "ordinal": 5, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "manifest_json", - "not_null": true, - "ordinal": 6, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "bundle_hash", - "not_null": true, - "ordinal": 7, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_by", - "not_null": true, - "ordinal": 8, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_at", - "not_null": true, - "ordinal": 9, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 10, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 11, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 12, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 13, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 14, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 15, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 16, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_generation", - "not_null": false, - "ordinal": 17, - "table_name": "guide_source_snapshots" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 7, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 10, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 11, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "report_id", - "not_null": false, - "ordinal": 12, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": false, - "ordinal": 13, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 14, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 15, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 16, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 17, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 18, - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "report_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "item_order", - "not_null": true, - "ordinal": 3, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_item_id", - "not_null": true, - "ordinal": 4, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_id", - "not_null": true, - "ordinal": 6, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extraction_usage_id", - "not_null": true, - "ordinal": 7, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extraction_attempt_id", - "not_null": true, - "ordinal": 8, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "extracted_content_id", - "not_null": true, - "ordinal": 9, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": true, - "ordinal": 10, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 11, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_output_sha256", - "not_null": true, - "ordinal": 12, - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 7, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "findings", - "not_null": true, - "ordinal": 8, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "summary", - "not_null": false, - "ordinal": 9, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_name", - "not_null": false, - "ordinal": 10, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_version", - "not_null": false, - "ordinal": 11, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 12, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 13, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_role", - "not_null": false, - "ordinal": 14, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_actor", - "not_null": false, - "ordinal": 15, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_at", - "not_null": false, - "ordinal": 16, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "acknowledgement_note", - "not_null": false, - "ordinal": 17, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_setup_run_id", - "not_null": false, - "ordinal": 18, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": false, - "ordinal": 19, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_material_sha256", - "not_null": false, - "ordinal": 20, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_material_byte_count", - "not_null": false, - "ordinal": 21, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 22, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 23, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 24, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service_identity", - "not_null": false, - "ordinal": 25, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 26, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 27, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 28, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 29, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_actor_profile_id", - "not_null": false, - "ordinal": 30, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_via_identity_link_id", - "not_null": false, - "ordinal": 31, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warnings_acknowledged_by_admin_role_grant_id", - "not_null": false, - "ordinal": 32, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_scope_type", - "not_null": false, - "ordinal": 33, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_scope_project_id", - "not_null": false, - "ordinal": 34, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_action_id", - "not_null": false, - "ordinal": 35, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "warning_acknowledgement_decision_event_id", - "not_null": false, - "ordinal": 36, - "table_name": "guide_sufficiency_reports" - }, - { - "data_type": "character varying(3)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "code", - "not_null": true, - "ordinal": 1, - "table_name": "iso_4217_currency_codes" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 1, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_subject", - "not_null": true, - "ordinal": 2, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_issuer", - "not_null": true, - "ordinal": 3, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "display_name", - "not_null": false, - "ordinal": 4, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(320)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "email", - "not_null": false, - "ordinal": 5, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_seen_roles", - "not_null": true, - "ordinal": 6, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_claim_snapshot", - "not_null": true, - "ordinal": 7, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "auth_source", - "not_null": true, - "ordinal": 8, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "is_dev_auth", - "not_null": true, - "ordinal": 9, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "first_seen_at", - "not_null": true, - "ordinal": 10, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_seen_at", - "not_null": true, - "ordinal": 11, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 12, - "table_name": "legacy_actor_identities" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_id", - "not_null": true, - "ordinal": 2, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "profile_type", - "not_null": true, - "ordinal": 3, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "skill_tags", - "not_null": true, - "ordinal": 5, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_type", - "not_null": true, - "ordinal": 6, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "scope_id", - "not_null": true, - "ordinal": 7, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "profile_metadata", - "not_null": true, - "ordinal": 8, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 9, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 10, - "table_name": "legacy_workflow_eligibility" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_id", - "not_null": true, - "ordinal": 1, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_type", - "not_null": true, - "ordinal": 2, - "table_name": "outbox_events" - }, - { - "data_type": "smallint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "event_version", - "not_null": true, - "ordinal": 3, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(32)", - "default_expression": "'workstream'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "producer", - "not_null": true, - "ordinal": 4, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(64)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "aggregate_type", - "not_null": true, - "ordinal": 5, - "table_name": "outbox_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "aggregate_id", - "not_null": true, - "ordinal": 6, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 7, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": true, - "ordinal": 8, - "table_name": "outbox_events" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "causation_event_id", - "not_null": false, - "ordinal": 9, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 10, - "table_name": "outbox_events" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payload", - "not_null": true, - "ordinal": 11, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payload_digest", - "not_null": true, - "ordinal": 12, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "occurred_at", - "not_null": true, - "ordinal": 13, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(16)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "delivery_state", - "not_null": true, - "ordinal": 14, - "table_name": "outbox_events" - }, - { - "data_type": "integer", - "default_expression": "0", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_count", - "not_null": true, - "ordinal": 15, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "next_attempt_at", - "not_null": false, - "ordinal": 16, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_owner", - "not_null": false, - "ordinal": 17, - "table_name": "outbox_events" - }, - { - "data_type": "bigint", - "default_expression": "'0'::bigint", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_generation", - "not_null": true, - "ordinal": 18, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claimed_at", - "not_null": false, - "ordinal": 19, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "claim_expires_at", - "not_null": false, - "ordinal": 20, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_attempt_at", - "not_null": false, - "ordinal": 21, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_error_code", - "not_null": false, - "ordinal": 22, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "finalized_at", - "not_null": false, - "ordinal": 23, - "table_name": "outbox_events" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archived_at", - "not_null": false, - "ordinal": 24, - "table_name": "outbox_events" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "payment_policies" - }, - { - "data_type": "numeric(12,2)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "base_amount", - "not_null": false, - "ordinal": 4, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "currency", - "not_null": false, - "ordinal": 5, - "table_name": "payment_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payout_type", - "not_null": false, - "ordinal": 6, - "table_name": "payment_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revision_payment_rule", - "not_null": false, - "ordinal": 7, - "table_name": "payment_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "rejection_payment_rule", - "not_null": false, - "ordinal": 8, - "table_name": "payment_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "accepted_payment_rule", - "not_null": false, - "ordinal": 9, - "table_name": "payment_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "payment_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 7, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 8, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 9, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 10, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 11, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_id", - "not_null": true, - "ordinal": 12, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_generation", - "not_null": true, - "ordinal": 13, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 14, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 15, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 17, - "table_name": "policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_id", - "not_null": true, - "ordinal": 7, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_hash", - "not_null": true, - "ordinal": 8, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 9, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compiler_version", - "not_null": false, - "ordinal": 10, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compiled_bundle", - "not_null": false, - "ordinal": 11, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "compiled_bundle_hash", - "not_null": false, - "ordinal": 12, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_names", - "not_null": true, - "ordinal": 13, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "checker_configs", - "not_null": true, - "ordinal": 14, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 15, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_pre_submit_checker_policy_id", - "not_null": false, - "ordinal": 17, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 18, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 19, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 20, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 21, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 22, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 23, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 24, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_decision_event_id", - "not_null": false, - "ordinal": 25, - "table_name": "pre_submit_checker_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "evidence_set_id", - "not_null": true, - "ordinal": 2, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_order", - "not_null": true, - "ordinal": 3, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(80)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "schema_version", - "not_null": true, - "ordinal": 4, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "dispatch_authority", - "not_null": true, - "ordinal": 5, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "definition_id", - "not_null": true, - "ordinal": 6, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "definition_version", - "not_null": true, - "ordinal": 7, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "public_name", - "not_null": true, - "ordinal": 8, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source", - "not_null": true, - "ordinal": 9, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "phase", - "not_null": true, - "ordinal": 10, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "classification", - "not_null": true, - "ordinal": 11, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "severity", - "not_null": true, - "ordinal": 12, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 13, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_code", - "not_null": false, - "ordinal": 14, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "message_code", - "not_null": true, - "ordinal": 15, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_plan_sha256", - "not_null": true, - "ordinal": 16, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "rule_instance_id", - "not_null": false, - "ordinal": 17, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_policy_sha256", - "not_null": true, - "ordinal": 18, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 19, - "table_name": "pre_submit_evidence_results" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_identity", - "not_null": true, - "ordinal": 2, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 4, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 5, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 6, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assignment_id", - "not_null": true, - "ordinal": 7, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_id", - "not_null": false, - "ordinal": 8, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_version", - "not_null": false, - "ordinal": 9, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "prepared_generation_id", - "not_null": true, - "ordinal": 10, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_sha256", - "not_null": true, - "ordinal": 11, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_byte_count", - "not_null": true, - "ordinal": 12, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_id", - "not_null": true, - "ordinal": 13, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_sha256", - "not_null": true, - "ordinal": 14, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 15, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 16, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 17, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_sha256", - "not_null": true, - "ordinal": 18, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_sha256", - "not_null": true, - "ordinal": 19, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_policy_id", - "not_null": true, - "ordinal": 20, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_artifact_policy_sha256", - "not_null": true, - "ordinal": 21, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_policy_id", - "not_null": true, - "ordinal": 22, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_checker_policy_sha256", - "not_null": true, - "ordinal": 23, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_plan_sha256", - "not_null": true, - "ordinal": 24, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "catalogue_id", - "not_null": true, - "ordinal": 25, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(40)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "catalogue_version", - "not_null": true, - "ordinal": 26, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "catalogue_manifest_sha256", - "not_null": true, - "ordinal": 27, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "storage_scheme", - "not_null": true, - "ordinal": 28, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_status", - "not_null": true, - "ordinal": 29, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "eligible", - "not_null": true, - "ordinal": 30, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_count", - "not_null": true, - "ordinal": 31, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_manifest_sha256", - "not_null": true, - "ordinal": 32, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 33, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_policy_context_hash", - "not_null": true, - "ordinal": 34, - "table_name": "pre_submit_evidence_sets" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instrument_type", - "not_null": true, - "ordinal": 3, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "adapter_actor_id", - "not_null": true, - "ordinal": 4, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "route_key", - "not_null": true, - "ordinal": 5, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 6, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "binding_lifecycle_version", - "not_null": true, - "ordinal": 7, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 8, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 9, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_by", - "not_null": false, - "ordinal": 10, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "suspended_at", - "not_null": false, - "ordinal": 11, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 12, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 13, - "table_name": "project_compensation_adapter_bindings" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 1, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instrument_type", - "not_null": true, - "ordinal": 2, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "unit_code", - "not_null": true, - "ordinal": 3, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(3)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "iso_currency_code", - "not_null": false, - "ordinal": 4, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 6, - "table_name": "project_compensation_units" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "project_compensation_units" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_by", - "not_null": false, - "ordinal": 8, - "table_name": "project_compensation_units" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "retired_at", - "not_null": false, - "ordinal": 9, - "table_name": "project_compensation_units" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 4, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 5, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 6, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 7, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 8, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_generation", - "not_null": true, - "ordinal": 9, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 11, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 12, - "table_name": "project_create_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": true, - "ordinal": 7, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 8, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_input_hash", - "not_null": true, - "ordinal": 9, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_material_hash", - "not_null": true, - "ordinal": 10, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_id", - "not_null": true, - "ordinal": 11, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_version", - "not_null": true, - "ordinal": 12, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_schema_version", - "not_null": true, - "ordinal": 13, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_manifest_hash", - "not_null": true, - "ordinal": 14, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_id", - "not_null": true, - "ordinal": 15, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_version", - "not_null": true, - "ordinal": 16, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_schema_version", - "not_null": true, - "ordinal": 17, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_manifest_hash", - "not_null": true, - "ordinal": 18, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_identity", - "not_null": true, - "ordinal": 19, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_version", - "not_null": true, - "ordinal": 20, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instruction_version", - "not_null": true, - "ordinal": 21, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_idempotency_key", - "not_null": true, - "ordinal": 22, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 23, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_result", - "not_null": false, - "ordinal": 24, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_hash", - "not_null": false, - "ordinal": 25, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "component_hashes", - "not_null": false, - "ordinal": 26, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "failure_code", - "not_null": false, - "ordinal": 27, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "persisted_compilation_id", - "not_null": false, - "ordinal": 28, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "reserved_at", - "not_null": true, - "ordinal": 29, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "provider_uncertain_at", - "not_null": false, - "ordinal": 30, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "accepted_at", - "not_null": false, - "ordinal": 31, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "terminal_at", - "not_null": false, - "ordinal": 32, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "persisted_at", - "not_null": false, - "ordinal": 33, - "table_name": "project_guide_compilation_attempts" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_guide_compilations" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 4, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 5, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 6, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 7, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": true, - "ordinal": 8, - "table_name": "project_guide_compilations" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 9, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_input_hash", - "not_null": true, - "ordinal": 10, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_material_hash", - "not_null": true, - "ordinal": 11, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_catalogue_manifest_hash", - "not_null": true, - "ordinal": 12, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_catalogue_manifest_hash", - "not_null": true, - "ordinal": 13, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_identity", - "not_null": true, - "ordinal": 14, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "agent_version", - "not_null": true, - "ordinal": 15, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "instruction_version", - "not_null": true, - "ordinal": 16, - "table_name": "project_guide_compilations" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "canonical_result", - "not_null": true, - "ordinal": 17, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "result_hash", - "not_null": true, - "ordinal": 18, - "table_name": "project_guide_compilations" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "component_hashes", - "not_null": true, - "ordinal": 19, - "table_name": "project_guide_compilations" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_compilation_id", - "not_null": false, - "ordinal": 20, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": true, - "ordinal": 21, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": true, - "ordinal": 22, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service_identity", - "not_null": true, - "ordinal": 23, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": true, - "ordinal": 24, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": true, - "ordinal": 25, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_resource_context_digest", - "not_null": true, - "ordinal": 26, - "table_name": "project_guide_compilations" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 27, - "table_name": "project_guide_compilations" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_guides" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 3, - "table_name": "project_guides" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 4, - "table_name": "project_guides" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "content_markdown", - "not_null": true, - "ordinal": 5, - "table_name": "project_guides" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by", - "not_null": false, - "ordinal": 6, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "effective_at", - "not_null": false, - "ordinal": 7, - "table_name": "project_guides" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "change_summary", - "not_null": false, - "ordinal": 8, - "table_name": "project_guides" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 9, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 10, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 11, - "table_name": "project_guides" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 12, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutated_by_actor_profile_id", - "not_null": false, - "ordinal": 13, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutated_via_identity_link_id", - "not_null": false, - "ordinal": 14, - "table_name": "project_guides" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutated_by_admin_role_grant_id", - "not_null": false, - "ordinal": 15, - "table_name": "project_guides" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutation_scope_type", - "not_null": false, - "ordinal": 16, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutation_scope_project_id", - "not_null": false, - "ordinal": 17, - "table_name": "project_guides" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_mutation_action_id", - "not_null": false, - "ordinal": 18, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "last_authorization_decision_event_id", - "not_null": false, - "ordinal": 19, - "table_name": "project_guides" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "mutation_generation", - "not_null": false, - "ordinal": 20, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_review_policy_id", - "not_null": false, - "ordinal": 21, - "table_name": "project_guides" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_review_policy_hash", - "not_null": false, - "ordinal": 22, - "table_name": "project_guides" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_revision_policy_id", - "not_null": false, - "ordinal": 23, - "table_name": "project_guides" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_revision_policy_hash", - "not_null": false, - "ordinal": 24, - "table_name": "project_guides" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_review_policy_generation", - "not_null": false, - "ordinal": 25, - "table_name": "project_guides" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "selected_revision_policy_generation", - "not_null": false, - "ordinal": 26, - "table_name": "project_guides" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "role", - "not_null": true, - "ordinal": 4, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "project_role_grants" - }, - { - "data_type": "smallint", - "default_expression": "'1'::smallint", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 6, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(16)", - "default_expression": "'manual'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "grant_method", - "not_null": true, - "ordinal": 7, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "qualification_snapshot_id", - "not_null": true, - "ordinal": 8, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_actor_profile_id", - "not_null": true, - "ordinal": 9, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_by_admin_role_grant_id", - "not_null": true, - "ordinal": 10, - "table_name": "project_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "grant_reason", - "not_null": true, - "ordinal": 11, - "table_name": "project_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "granted_at", - "not_null": true, - "ordinal": 12, - "table_name": "project_role_grants" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_actor_profile_id", - "not_null": false, - "ordinal": 13, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_by_admin_role_grant_id", - "not_null": false, - "ordinal": 14, - "table_name": "project_role_grants" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_reason", - "not_null": false, - "ordinal": 15, - "table_name": "project_role_grants" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revoked_at", - "not_null": false, - "ordinal": 16, - "table_name": "project_role_grants" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requested_role", - "not_null": true, - "ordinal": 4, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "skills_snapshot", - "not_null": true, - "ordinal": 5, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reputation_snapshot", - "not_null": true, - "ordinal": 6, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "prior_project_work_refs", - "not_null": true, - "ordinal": 7, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "jsonb", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_expertise_refs", - "not_null": true, - "ordinal": 8, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_by_actor_profile_id", - "not_null": true, - "ordinal": 9, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_by_admin_role_grant_id", - "not_null": true, - "ordinal": 10, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "captured_at", - "not_null": true, - "ordinal": 11, - "table_name": "project_role_qualification_snapshots" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(155)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "celery_task_id", - "not_null": false, - "ordinal": 7, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 8, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "current_step", - "not_null": true, - "ordinal": 9, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_sufficiency_report_id", - "not_null": false, - "ordinal": 10, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_submission_artifact_policy_id", - "not_null": false, - "ordinal": 11, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_code", - "not_null": false, - "ordinal": 12, - "table_name": "project_setup_runs" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_summary", - "not_null": false, - "ordinal": 13, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 14, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 15, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 16, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "started_at", - "not_null": false, - "ordinal": 17, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "finished_at", - "not_null": false, - "ordinal": 18, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "output_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 19, - "table_name": "project_setup_runs" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "post_submit_derivation_summary", - "not_null": false, - "ordinal": 20, - "table_name": "project_setup_runs" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 21, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorized_by_actor_profile_id", - "not_null": false, - "ordinal": 22, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorized_via_identity_link_id", - "not_null": false, - "ordinal": 23, - "table_name": "project_setup_runs" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorized_by_admin_role_grant_id", - "not_null": false, - "ordinal": 24, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_scope_type", - "not_null": false, - "ordinal": 25, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_scope_project_id", - "not_null": false, - "ordinal": 26, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_action_id", - "not_null": false, - "ordinal": 27, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 28, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "error_artifact_incident_id", - "not_null": false, - "ordinal": 29, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "continuation_verification_job_id", - "not_null": false, - "ordinal": 30, - "table_name": "project_setup_runs" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "continuation_started_at", - "not_null": false, - "ordinal": 31, - "table_name": "project_setup_runs" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "projects" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "name", - "not_null": true, - "ordinal": 2, - "table_name": "projects" - }, - { - "data_type": "character varying(120)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "slug", - "not_null": true, - "ordinal": 3, - "table_name": "projects" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "description", - "not_null": false, - "ordinal": 4, - "table_name": "projects" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "projects" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 6, - "table_name": "projects" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 7, - "table_name": "projects" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 8, - "table_name": "projects" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 9, - "table_name": "projects" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 10, - "table_name": "projects" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 11, - "table_name": "projects" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 12, - "table_name": "projects" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 13, - "table_name": "projects" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": true, - "ordinal": 2, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 3, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 4, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 5, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 6, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 7, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 8, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "admitting_checker_run_id", - "not_null": true, - "ordinal": 9, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_queue_entry_id", - "not_null": false, - "ordinal": 11, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 12, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 13, - "table_name": "review_admission_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_leases" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_queue_entry_id", - "not_null": true, - "ordinal": 2, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 3, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 4, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 5, - "table_name": "review_leases" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 6, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reviewer_id", - "not_null": true, - "ordinal": 7, - "table_name": "review_leases" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reviewer_contribution_policy_version_id", - "not_null": true, - "ordinal": 8, - "table_name": "review_leases" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "attempt_generation", - "not_null": true, - "ordinal": 9, - "table_name": "review_leases" - }, - { - "data_type": "character varying(16)", - "default_expression": "'active'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 10, - "table_name": "review_leases" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "claimed_at", - "not_null": true, - "ordinal": 11, - "table_name": "review_leases" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "expires_at", - "not_null": true, - "ordinal": 12, - "table_name": "review_leases" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "closed_at", - "not_null": false, - "ordinal": 13, - "table_name": "review_leases" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "close_reason", - "not_null": false, - "ordinal": 14, - "table_name": "review_leases" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "review_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "review_policies" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "requires_second_review", - "not_null": true, - "ordinal": 4, - "table_name": "review_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "allowed_decisions", - "not_null": true, - "ordinal": 5, - "table_name": "review_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "minimum_finding_fields", - "not_null": true, - "ordinal": 6, - "table_name": "review_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 7, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_generation", - "not_null": true, - "ordinal": 8, - "table_name": "review_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 9, - "table_name": "review_policies" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantics_status", - "not_null": true, - "ordinal": 10, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 11, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_preference_window_seconds", - "not_null": false, - "ordinal": 12, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "review_lease_duration_seconds", - "not_null": false, - "ordinal": 13, - "table_name": "review_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "max_active_review_leases_per_reviewer", - "not_null": false, - "ordinal": 14, - "table_name": "review_policies" - }, - { - "data_type": "boolean", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "self_review_allowed", - "not_null": false, - "ordinal": 15, - "table_name": "review_policies" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reject_policy", - "not_null": false, - "ordinal": 16, - "table_name": "review_policies" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "finding_evidence_requirement", - "not_null": false, - "ordinal": 17, - "table_name": "review_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_policy_hash", - "not_null": false, - "ordinal": 18, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 19, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 20, - "table_name": "review_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 21, - "table_name": "review_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 22, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 23, - "table_name": "review_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 24, - "table_name": "review_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 25, - "table_name": "review_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 3, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_id", - "not_null": true, - "ordinal": 4, - "table_name": "review_queue_entries" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "submission_version", - "not_null": true, - "ordinal": 5, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "admitting_checker_run_id", - "not_null": true, - "ordinal": 6, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(16)", - "default_expression": "'pending'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "queue_state", - "not_null": true, - "ordinal": 7, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_mode", - "not_null": true, - "ordinal": 8, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_reason", - "not_null": true, - "ordinal": 9, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "first_queued_at", - "not_null": true, - "ordinal": 10, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "available_since", - "not_null": true, - "ordinal": 11, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "preferred_reviewer_id", - "not_null": false, - "ordinal": 12, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "preference_expires_at", - "not_null": false, - "ordinal": 13, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "closed_at", - "not_null": false, - "ordinal": 14, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(32)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "closed_reason", - "not_null": false, - "ordinal": 15, - "table_name": "review_queue_entries" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "routing_generation", - "not_null": true, - "ordinal": 16, - "table_name": "review_queue_entries" - }, - { - "data_type": "integer", - "default_expression": "1", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_generation", - "not_null": true, - "ordinal": 17, - "table_name": "review_queue_entries" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "statement_timestamp()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 18, - "table_name": "review_queue_entries" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "active_lease_id", - "not_null": false, - "ordinal": 19, - "table_name": "review_queue_entries" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 3, - "table_name": "revision_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "max_revision_rounds", - "not_null": true, - "ordinal": 4, - "table_name": "revision_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "revision_deadline_hours", - "not_null": true, - "ordinal": 5, - "table_name": "revision_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "allowed_resubmission_states", - "not_null": true, - "ordinal": 6, - "table_name": "revision_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "reviewer_reassignment_rule", - "not_null": false, - "ordinal": 7, - "table_name": "revision_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 8, - "table_name": "revision_policies" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_generation", - "not_null": true, - "ordinal": 9, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 10, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(24)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantics_status", - "not_null": true, - "ordinal": 11, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 12, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_policy_hash", - "not_null": false, - "ordinal": 13, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 14, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 15, - "table_name": "revision_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 16, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 17, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 18, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 19, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "authorization_decision_event_id", - "not_null": false, - "ordinal": 20, - "table_name": "revision_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_version", - "not_null": true, - "ordinal": 4, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 5, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_hash", - "not_null": true, - "ordinal": 6, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_version", - "not_null": true, - "ordinal": 7, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "lifecycle_status", - "not_null": true, - "ordinal": 8, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_body", - "not_null": true, - "ordinal": 9, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_hash", - "not_null": true, - "ordinal": 10, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "derivation_source", - "not_null": true, - "ordinal": 11, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_material_refs", - "not_null": true, - "ordinal": 12, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "derivation_agent_name", - "not_null": false, - "ordinal": 13, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "derivation_agent_version", - "not_null": false, - "ordinal": 14, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 15, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 16, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 17, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_role", - "not_null": false, - "ordinal": 18, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_actor", - "not_null": false, - "ordinal": 19, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_at", - "not_null": false, - "ordinal": 20, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_policy_id", - "not_null": false, - "ordinal": 21, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "superseded_at", - "not_null": false, - "ordinal": 22, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "change_summary", - "not_null": false, - "ordinal": 23, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_actor_profile_id", - "not_null": false, - "ordinal": 24, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_via_identity_link_id", - "not_null": false, - "ordinal": 25, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_admin_role_grant_id", - "not_null": false, - "ordinal": 26, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by_service_identity", - "not_null": false, - "ordinal": 27, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_type", - "not_null": false, - "ordinal": 28, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_scope_project_id", - "not_null": false, - "ordinal": 29, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_action_id", - "not_null": false, - "ordinal": 30, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "creation_decision_event_id", - "not_null": false, - "ordinal": 31, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_actor_profile_id", - "not_null": false, - "ordinal": 32, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_via_identity_link_id", - "not_null": false, - "ordinal": 33, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approved_by_admin_role_grant_id", - "not_null": false, - "ordinal": 34, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_scope_type", - "not_null": false, - "ordinal": 35, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_scope_project_id", - "not_null": false, - "ordinal": 36, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_action_id", - "not_null": false, - "ordinal": 37, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "approval_decision_event_id", - "not_null": false, - "ordinal": 38, - "table_name": "submission_artifact_policies" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "durable_intent_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_evidence_set_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 4, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_content_id", - "not_null": true, - "ordinal": 5, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verified_replica_id", - "not_null": true, - "ordinal": 6, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "verification_receipt_id", - "not_null": true, - "ordinal": 7, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_operation_receipt_id", - "not_null": false, - "ordinal": 8, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_observation_receipt_id", - "not_null": false, - "ordinal": 9, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 10, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 11, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 12, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 13, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assignment_id", - "not_null": true, - "ordinal": 14, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_id", - "not_null": false, - "ordinal": 15, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "predecessor_submission_version", - "not_null": false, - "ordinal": 16, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_policy_context_hash", - "not_null": true, - "ordinal": 17, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_id", - "not_null": true, - "ordinal": 18, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "semantic_manifest_sha256", - "not_null": true, - "ordinal": 19, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_sha256", - "not_null": true, - "ordinal": 20, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "archive_byte_count", - "not_null": true, - "ordinal": 21, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(16)", - "default_expression": "'ready'::character varying", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 22, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "ready_at", - "not_null": true, - "ordinal": 23, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "consumed_at", - "not_null": false, - "ordinal": 24, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "consumed_by_submission_id", - "not_null": false, - "ordinal": 25, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "stale_at", - "not_null": false, - "ordinal": 26, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "stale_reason", - "not_null": false, - "ordinal": 27, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 28, - "table_name": "submission_bundle_admissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "pre_submit_evidence_set_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "put_attempt_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 4, - "table_name": "submission_bundle_durable_intents" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "actor_profile_id", - "not_null": true, - "ordinal": 2, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "identity_link_id", - "not_null": true, - "ordinal": 3, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "service_identity", - "not_null": false, - "ordinal": 4, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(160)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "action_id", - "not_null": true, - "ordinal": 5, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "idempotency_key", - "not_null": false, - "ordinal": 6, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "request_digest", - "not_null": true, - "ordinal": 7, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_digest", - "not_null": true, - "ordinal": 8, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "resource_context_json", - "not_null": true, - "ordinal": 9, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "operation_id", - "not_null": true, - "ordinal": 10, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 11, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "guide_id", - "not_null": true, - "ordinal": 12, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_snapshot_id", - "not_null": true, - "ordinal": 13, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "policy_id", - "not_null": true, - "ordinal": 14, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_run_id", - "not_null": false, - "ordinal": 15, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "bigint", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_generation", - "not_null": true, - "ordinal": 16, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "setup_task_id", - "not_null": false, - "ordinal": 17, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "uuid", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "correlation_id", - "not_null": false, - "ordinal": 18, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(16)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 19, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "response_json", - "not_null": false, - "ordinal": 20, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_policy_id", - "not_null": false, - "ordinal": 21, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_effective_policy_id", - "not_null": false, - "ordinal": 22, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_pre_submit_policy_id", - "not_null": false, - "ordinal": 23, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 24, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "committed_at", - "not_null": false, - "ordinal": 25, - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 2, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contributor_id", - "not_null": true, - "ordinal": 3, - "table_name": "submissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "version", - "not_null": true, - "ordinal": 4, - "table_name": "submissions" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 5, - "table_name": "submissions" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "summary", - "not_null": true, - "ordinal": 6, - "table_name": "submissions" - }, - { - "data_type": "character varying(1000)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "package_uri", - "not_null": false, - "ordinal": 7, - "table_name": "submissions" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "package_hash", - "not_null": true, - "ordinal": 8, - "table_name": "submissions" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "artifact_hash_manifest", - "not_null": true, - "ordinal": 9, - "table_name": "submissions" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "worker_attestation", - "not_null": true, - "ordinal": 10, - "table_name": "submissions" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_version", - "not_null": true, - "ordinal": 11, - "table_name": "submissions" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_payment_policy_version", - "not_null": true, - "ordinal": 12, - "table_name": "submissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "submitted_at", - "not_null": true, - "ordinal": 13, - "table_name": "submissions" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_at", - "not_null": false, - "ordinal": 14, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "supersedes_submission_id", - "not_null": false, - "ordinal": 15, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_id", - "not_null": false, - "ordinal": 16, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_hash", - "not_null": false, - "ordinal": 17, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_id", - "not_null": false, - "ordinal": 18, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_hash", - "not_null": false, - "ordinal": 19, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_policy_id", - "not_null": false, - "ordinal": 20, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_bundle_hash", - "not_null": false, - "ordinal": 21, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 22, - "table_name": "submissions" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_version", - "not_null": false, - "ordinal": 23, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_hash", - "not_null": false, - "ordinal": 24, - "table_name": "submissions" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_body", - "not_null": false, - "ordinal": 25, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_id", - "not_null": true, - "ordinal": 26, - "table_name": "submissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_generation", - "not_null": true, - "ordinal": 27, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_hash", - "not_null": true, - "ordinal": 28, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_id", - "not_null": true, - "ordinal": 29, - "table_name": "submissions" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_generation", - "not_null": true, - "ordinal": 30, - "table_name": "submissions" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_hash", - "not_null": true, - "ordinal": 31, - "table_name": "submissions" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_id", - "not_null": true, - "ordinal": 2, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "contributor_id", - "not_null": true, - "ordinal": 3, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assigned_by", - "not_null": true, - "ordinal": 4, - "table_name": "task_assignments" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "assigned_at", - "not_null": true, - "ordinal": 5, - "table_name": "task_assignments" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "accepted_at", - "not_null": false, - "ordinal": 6, - "table_name": "task_assignments" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "released_at", - "not_null": false, - "ordinal": 7, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 8, - "table_name": "task_assignments" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "id", - "not_null": true, - "ordinal": 1, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "project_id", - "not_null": true, - "ordinal": 2, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_version", - "not_null": false, - "ordinal": 3, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_payment_policy_version", - "not_null": false, - "ordinal": 4, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_type", - "not_null": true, - "ordinal": 5, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(500)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_ref", - "not_null": false, - "ordinal": 6, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(128)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "source_payload_hash", - "not_null": false, - "ordinal": 7, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "import_batch_id", - "not_null": false, - "ordinal": 8, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(200)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "external_task_id", - "not_null": false, - "ordinal": 9, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(300)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "title", - "not_null": true, - "ordinal": 10, - "table_name": "workstream_tasks" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "description", - "not_null": true, - "ordinal": 11, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "task_type", - "not_null": false, - "ordinal": 12, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "difficulty", - "not_null": false, - "ordinal": 13, - "table_name": "workstream_tasks" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "skill_tags", - "not_null": true, - "ordinal": 14, - "table_name": "workstream_tasks" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "estimated_time_minutes", - "not_null": false, - "ordinal": 15, - "table_name": "workstream_tasks" - }, - { - "data_type": "numeric(12,2)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "base_amount", - "not_null": false, - "ordinal": 16, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(20)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "currency", - "not_null": false, - "ordinal": 17, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "payout_type", - "not_null": false, - "ordinal": 18, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(30)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "status", - "not_null": true, - "ordinal": 19, - "table_name": "workstream_tasks" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "acceptance_criteria", - "not_null": false, - "ordinal": 20, - "table_name": "workstream_tasks" - }, - { - "data_type": "text", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "rejection_criteria", - "not_null": false, - "ordinal": 21, - "table_name": "workstream_tasks" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "deadline_at", - "not_null": false, - "ordinal": 22, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_by", - "not_null": true, - "ordinal": 23, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(100)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "assigned_to", - "not_null": false, - "ordinal": 24, - "table_name": "workstream_tasks" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "created_at", - "not_null": true, - "ordinal": 25, - "table_name": "workstream_tasks" - }, - { - "data_type": "timestamp with time zone", - "default_expression": "now()", - "generated_kind": "00", - "identity_kind": "00", - "name": "updated_at", - "not_null": true, - "ordinal": 26, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_id", - "not_null": false, - "ordinal": 27, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_guide_source_snapshot_hash", - "not_null": false, - "ordinal": 28, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_id", - "not_null": false, - "ordinal": 29, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_effective_project_submission_artifact_policy_hash", - "not_null": false, - "ordinal": 30, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_policy_id", - "not_null": false, - "ordinal": 31, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_pre_submit_checker_bundle_hash", - "not_null": false, - "ordinal": 32, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_id", - "not_null": false, - "ordinal": 33, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(50)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_version", - "not_null": false, - "ordinal": 34, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_hash", - "not_null": false, - "ordinal": 35, - "table_name": "workstream_tasks" - }, - { - "data_type": "json", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_post_submit_checker_policy_body", - "not_null": false, - "ordinal": 36, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_id", - "not_null": false, - "ordinal": 37, - "table_name": "workstream_tasks" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_generation", - "not_null": false, - "ordinal": 38, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_review_policy_hash", - "not_null": false, - "ordinal": 39, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(36)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_id", - "not_null": false, - "ordinal": 40, - "table_name": "workstream_tasks" - }, - { - "data_type": "integer", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_generation", - "not_null": false, - "ordinal": 41, - "table_name": "workstream_tasks" - }, - { - "data_type": "character varying(71)", - "default_expression": "", - "generated_kind": "00", - "identity_kind": "00", - "name": "locked_revision_policy_hash", - "not_null": false, - "ordinal": 42, - "table_name": "workstream_tasks" - } - ], - "constraints": [ - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "actor_identity_link_profile_guard", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (subject_kind::text = 'service'::text OR last_verified_at IS NOT NULL)", - "kind": "c", - "name": "ck_actor_identity_links_human_verified", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_actor_identity_links_id_uuid", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (length(btrim(issuer::text)) >= 1 AND length(btrim(issuer::text)) <= 200)", - "kind": "c", - "name": "ck_actor_identity_links_issuer", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK ((revoked_reason IS NULL OR revoked_reason::text = btrim(revoked_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(revoked_reason::text) >= 1 AND octet_length(revoked_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500))", - "kind": "c", - "name": "ck_actor_identity_links_lifecycle_reason_bounds", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_identity_links_reactivation_fields", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (status::text = 'active'::text AND revoked_by IS NULL AND revoked_at IS NULL AND revoked_reason IS NULL OR status::text = 'revoked'::text AND revoked_by IS NOT NULL AND revoked_at IS NOT NULL AND revoked_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_identity_links_revocation_fields", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'revoked']))", - "kind": "c", - "name": "ck_actor_identity_links_status", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (length(btrim(subject::text)) >= 1 AND length(btrim(subject::text)) <= 200)", - "kind": "c", - "name": "ck_actor_identity_links_subject", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (subject_kind::text = ANY (ARRAY['human', 'service']))", - "kind": "c", - "name": "ck_actor_identity_links_subject_kind", - "table_name": "actor_identity_links" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_actor_identity_links_actor_profile_id_actor_profiles", - "table_name": "actor_identity_links" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_actor_identity_links", - "table_name": "actor_identity_links" - }, - { - "definition": "UNIQUE (actor_profile_id)", - "kind": "u", - "name": "uq_actor_identity_links_actor_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "UNIQUE (issuer, subject)", - "kind": "u", - "name": "uq_actor_identity_links_external_identity", - "table_name": "actor_identity_links" - }, - { - "definition": "UNIQUE (id, actor_profile_id)", - "kind": "u", - "name": "uq_actor_identity_links_id_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "CHECK (classified_count = 0 AND manifest_sha256 IS NULL AND envelope_sha256 IS NULL OR classified_count > 0 AND manifest_sha256 IS NOT NULL AND envelope_sha256 IS NOT NULL)", - "kind": "c", - "name": "ck_actor_profile_migration_state_evidence", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CHECK (service_identity_mapped_count >= 0 AND service_identity_mapped_count <= 7 AND service_identity_source_row_set_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_database_binding::text ~ '^postgres-v1:[0-9a-f]{64}$'::text AND (service_identity_mapped_count = 0 AND service_identity_manifest_sha256 IS NULL AND service_identity_envelope_sha256 IS NULL OR service_identity_mapped_count >= 1 AND service_identity_mapped_count <= 7 AND service_identity_manifest_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_envelope_sha256::text ~ '^[0-9a-f]{64}$'::text))", - "kind": "c", - "name": "ck_actor_profile_migration_state_service_identity_evidence", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CHECK (id = 1 AND schema_version = 1 AND classified_count >= 0)", - "kind": "c", - "name": "ck_actor_profile_migration_state_singleton", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_actor_profile_migration_state", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "actor_profile_link_guard", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (actor_kind::text = ANY (ARRAY['human', 'service']))", - "kind": "c", - "name": "ck_actor_profiles_actor_kind", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_actor_profiles_id_uuid", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (actor_kind::text = 'human'::text AND provisioning_method::text = 'automatic_first_access'::text OR actor_kind::text = 'service'::text AND provisioning_method::text = 'manual_service_provisioning'::text)", - "kind": "c", - "name": "ck_actor_profiles_kind_provisioning", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (actor_kind::text = 'human'::text AND service_identity IS NULL OR actor_kind::text = 'service'::text AND (service_identity::text = ANY (ARRAY['workstream.artifact.verifier', 'workstream.artifact.put_resolver', 'workstream.artifact.scheduler', 'workstream.artifact.binding', 'workstream.artifact.guide_reader', 'workstream.artifact.materializer', 'workstream.artifact.checker_output', 'workstream.project.setup', 'workstream.review.preference_expiry', 'workstream.review.lease_expiry', 'workstream.review.authority_invalidation_reconciliation', 'workstream.review.reconciliation', 'workstream.review.artifact_reference_reconciliation', 'workstream.review.projection'])))", - "kind": "c", - "name": "ck_actor_profiles_kind_service_identity", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (status::text = 'active'::text AND suspended_by IS NULL AND suspended_at IS NULL AND suspension_reason IS NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'suspended'::text AND suspended_by IS NOT NULL AND suspended_at IS NOT NULL AND suspension_reason IS NOT NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'deactivated'::text AND deactivated_by IS NOT NULL AND deactivated_at IS NOT NULL AND deactivation_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_profiles_lifecycle_fields", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK ((suspension_reason IS NULL OR suspension_reason::text = btrim(suspension_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(suspension_reason::text) >= 1 AND octet_length(suspension_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500) AND (deactivation_reason IS NULL OR deactivation_reason::text = btrim(deactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(deactivation_reason::text) >= 1 AND octet_length(deactivation_reason::text) <= 500))", - "kind": "c", - "name": "ck_actor_profiles_lifecycle_reason_bounds", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (provisioning_method::text = ANY (ARRAY['automatic_first_access', 'manual_service_provisioning']))", - "kind": "c", - "name": "ck_actor_profiles_provisioning_method", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)", - "kind": "c", - "name": "ck_actor_profiles_reactivation_fields", - "table_name": "actor_profiles" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'deactivated']))", - "kind": "c", - "name": "ck_actor_profiles_status", - "table_name": "actor_profiles" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_actor_profiles", - "table_name": "actor_profiles" - }, - { - "definition": "UNIQUE (service_identity)", - "kind": "u", - "name": "service_identity", - "table_name": "actor_profiles" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "admin_role_grants_bootstrap_invariant", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (granted_by_system_principal::text = 'workstream:system:bootstrap'::text AND granted_by_actor_profile_id IS NULL AND granted_by_admin_role_grant_id IS NULL OR granted_by_system_principal IS NULL AND granted_by_actor_profile_id IS NOT NULL AND granted_by_admin_role_grant_id IS NOT NULL)", - "kind": "c", - "name": "ck_admin_role_grants_grant_attribution", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (octet_length(grant_reason) >= 1 AND octet_length(grant_reason) <= 500)", - "kind": "c", - "name": "ck_admin_role_grants_grant_reason", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND octet_length(revoked_reason) >= 1 AND octet_length(revoked_reason) <= 500 AND revoked_at IS NOT NULL)", - "kind": "c", - "name": "ck_admin_role_grants_lifecycle", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (role::text = ANY (ARRAY['access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority']))", - "kind": "c", - "name": "ck_admin_role_grants_role", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (scope_type::text = 'system'::text AND scope_project_id IS NULL OR scope_type::text = 'project'::text AND scope_project_id IS NOT NULL AND (role::text <> ALL (ARRAY['access_administrator', 'operator'])))", - "kind": "c", - "name": "ck_admin_role_grants_role_scope", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (scope_type::text = ANY (ARRAY['system', 'project']))", - "kind": "c", - "name": "ck_admin_role_grants_scope_type", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_admin_role_grants_granted_by_admin_role_grant_id_adm_81e0", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_admin_role_grants_revoked_by_admin_role_grant_id_adm_78b5", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_admin_role_grants_scope_project_id_projects", - "table_name": "admin_role_grants" - }, - { - "definition": "FOREIGN KEY (target_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_admin_role_grants_target_actor_profile_id_actor_profiles", - "table_name": "admin_role_grants" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_admin_role_grants", - "table_name": "admin_role_grants" - }, - { - "definition": "CHECK (octet_length(key_digest) = 32)", - "kind": "c", - "name": "ck_api_rate_control_counters_digest_length", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (request_count >= 1 AND request_count <= '9223372036854775807'::bigint)", - "kind": "c", - "name": "ck_api_rate_control_counters_request_count", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (control_scope::text = ANY (ARRAY['first_access', 'admin_mutation', 'authorization_read']))", - "kind": "c", - "name": "ck_api_rate_control_counters_scope_token", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (window_started_at < window_expires_at)", - "kind": "c", - "name": "ck_api_rate_control_counters_window_order", - "table_name": "api_rate_control_counters" - }, - { - "definition": "PRIMARY KEY (control_scope, key_digest)", - "kind": "p", - "name": "pk_api_rate_control_counters", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_admission_charges_byte_count_nonnegative", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_admission_charges_cas_nonnegative", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK ((state::text = 'completed'::text) = (completed_at IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_admission_charges_completed_timestamp", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (creating_operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_admission_charges_operation_identity_shape", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", - "kind": "c", - "name": "ck_artifact_admission_charges_producer_type", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK ((state::text = 'released'::text) = (released_at IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_admission_charges_released_timestamp", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_admission_charges_sha256_shape", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (state::text = ANY (ARRAY['provisional', 'completed', 'released']))", - "kind": "c", - "name": "ck_artifact_admission_charges_state", - "table_name": "artifact_admission_charges" - }, - { - "definition": "FOREIGN KEY (scope_type, scope_id) REFERENCES artifact_admission_scopes(scope_type, scope_id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_admission_charges_scope", - "table_name": "artifact_admission_charges" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_admission_charges", - "table_name": "artifact_admission_charges" - }, - { - "definition": "UNIQUE (scope_type, scope_id, sha256, byte_count)", - "kind": "u", - "name": "uq_artifact_admission_charge_scope_content", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CHECK (cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_admission_scopes_cas_nonnegative", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (counted_bytes >= 0 AND counted_bytes <= limit_bytes)", - "kind": "c", - "name": "ck_artifact_admission_scopes_counted_bytes_within_limit", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (limit_bytes > 0)", - "kind": "c", - "name": "ck_artifact_admission_scopes_limit_positive", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (octet_length(scope_id::text) >= 1 AND octet_length(scope_id::text) <= 120)", - "kind": "c", - "name": "ck_artifact_admission_scopes_scope_id_bounds", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (scope_type::text = ANY (ARRAY['deployment', 'project', 'producer', 'task']))", - "kind": "c", - "name": "ck_artifact_admission_scopes_scope_type", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "PRIMARY KEY (scope_type, scope_id)", - "kind": "p", - "name": "pk_artifact_admission_scopes", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CHECK (scope_version > 0)", - "kind": "c", - "name": "ck_artifact_bindings_scope_version_positive", - "table_name": "artifact_bindings" - }, - { - "definition": "CHECK (scope_version = 1 AND supersedes_binding_id IS NULL OR scope_version > 1 AND supersedes_binding_id IS NOT NULL)", - "kind": "c", - "name": "ck_artifact_bindings_scope_version_predecessor", - "table_name": "artifact_bindings" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_bindings_content_id_artifact_contents", - "table_name": "artifact_bindings" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_bindings_project_id_projects", - "table_name": "artifact_bindings" - }, - { - "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES artifact_bindings(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_bindings_supersedes_binding_id_artifact_bindings", - "table_name": "artifact_bindings" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_bindings", - "table_name": "artifact_bindings" - }, - { - "definition": "TRIGGER DEFERRABLE", - "kind": "t", - "name": "trg_artifact_binding_history", - "table_name": "artifact_bindings" - }, - { - "definition": "UNIQUE (project_id, resource_type, resource_id, logical_role, scope_version)", - "kind": "u", - "name": "uq_artifact_binding_scope_version", - "table_name": "artifact_bindings" - }, - { - "definition": "UNIQUE (supersedes_binding_id)", - "kind": "u", - "name": "uq_artifact_binding_supersedes", - "table_name": "artifact_bindings" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_contents_byte_count_nonnegative", - "table_name": "artifact_contents" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_contents_sha256_shape", - "table_name": "artifact_contents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_contents", - "table_name": "artifact_contents" - }, - { - "definition": "UNIQUE (sha256, byte_count)", - "kind": "u", - "name": "uq_artifact_content_digest_size", - "table_name": "artifact_contents" - }, - { - "definition": "CHECK (attempt_number > 0)", - "kind": "c", - "name": "ck_artifact_operation_receipts_attempt_positive", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (contract_version = 2 AND put_attempt_id IS NOT NULL AND (guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND logical_role IS NULL OR guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR guide_source_item_id IS NULL AND checker_run_id IS NULL AND logical_role IS NULL))", - "kind": "c", - "name": "ck_artifact_operation_receipts_contract_producer_reference", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (operation::text = 'put'::text)", - "kind": "c", - "name": "ck_artifact_operation_receipts_operation", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (outcome::text = 'stored_pending_verification'::text)", - "kind": "c", - "name": "ck_artifact_operation_receipts_outcome", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_operation_receipts_request_digest_shape", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_operation_receipts_replica_id_artifact_replicas", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_receipt_checker_run", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_receipt_guide_item", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_receipt_put_attempt", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_operation_receipts", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "UNIQUE (put_attempt_id)", - "kind": "u", - "name": "uq_artifact_receipt_put_attempt", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "FOREIGN KEY (attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempt_charges_attempt_id_artifact_put_b25d", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "FOREIGN KEY (charge_id) REFERENCES artifact_admission_charges(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempt_charges_charge_id_artifact_admi_85a9", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "PRIMARY KEY (attempt_id, charge_id)", - "kind": "p", - "name": "pk_artifact_put_attempt_charges", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_put_attempts_byte_count_nonnegative", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (canonical_target::text ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_canonical_target_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (execution_mode IS NULL OR (execution_mode::text = ANY (ARRAY['caller_put', 'observation'])))", - "kind": "c", - "name": "ck_artifact_put_attempts_execution_mode", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", - "kind": "c", - "name": "ck_artifact_put_attempts_executor_lease_pair", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK ((status::text = 'put_in_flight'::text) = (executor_id IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_put_attempts_inflight_fence", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (observation_count >= 0 AND maximum_observations > 0)", - "kind": "c", - "name": "ck_artifact_put_attempts_observation_counts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_operation_identity_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (status::text <> 'prepared'::text OR next_run_at IS NULL AND executor_id IS NULL AND lease_expires_at IS NULL AND execution_generation = 0 AND terminal_result_code IS NULL AND terminal_at IS NULL AND replica_id IS NULL AND receipt_id IS NULL)", - "kind": "c", - "name": "ck_artifact_put_attempts_prepared_execution_inactive", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_request_type::text = 'guide'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text OR producer_request_type::text = 'checker_output'::text AND producer_type::text = 'service_identity'::text AND producer_ref::text = 'workstream.artifact.checker_output'::text OR producer_request_type::text = 'submission_bundle'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_identity", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_request_type::text = 'guide'::text AND guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND task_id IS NULL AND logical_role IS NULL OR producer_request_type::text = 'checker_output'::text AND guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND task_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR producer_request_type::text = 'submission_bundle'::text AND guide_source_item_id IS NULL AND checker_run_id IS NULL AND task_id IS NOT NULL AND logical_role IS NULL)", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_reference", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_request_type::text = ANY (ARRAY['guide', 'checker_output', 'submission_bundle']))", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_request_type", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))", - "kind": "c", - "name": "ck_artifact_put_attempts_producer_type", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_request_digest_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_attempts_sha256_shape", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['prepared', 'put_in_flight', 'acknowledgement_unknown', 'object_confirmed', 'absent_replay_required', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", - "kind": "c", - "name": "ck_artifact_put_attempts_status", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (status::text <> 'provider_unavailable'::text OR observation_count >= maximum_observations AND next_run_at IS NULL AND terminal_at IS NOT NULL)", - "kind": "c", - "name": "ck_artifact_put_attempts_unavailable_exhausted", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_put_attempts_versions_nonnegative", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_checker_run_id_checker_runs", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_guide_source_item_id_guide_sou_e48c", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (storage_namespace_id, namespace_fingerprint) REFERENCES artifact_storage_namespaces(id, namespace_fingerprint) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_namespace_fingerprint", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_project_id_projects", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_receipt_id_artifact_operation_receipts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_replica_id_artifact_replicas", - "table_name": "artifact_put_attempts" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_attempts_task_id_workstream_tasks", - "table_name": "artifact_put_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_put_attempts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "UNIQUE (operation_identity)", - "kind": "u", - "name": "uq_artifact_put_attempt_operation", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CHECK (expected_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_expected_sha256", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (expected_byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_expected_size", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK ((outcome::text = ANY (ARRAY['observed_confirmed', 'observed_integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_observed_facts", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_observed_sha256", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_observed_size", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (outcome::text = ANY (ARRAY['observed_confirmed', 'observed_missing', 'observed_integrity_mismatch', 'conflict']))", - "kind": "c", - "name": "ck_artifact_put_observation_receipts_outcome", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_put_observation_receipts_put_attempt_id_art_237d", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_put_observation_receipts", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "UNIQUE (put_attempt_id, execution_generation)", - "kind": "u", - "name": "uq_artifact_put_observation_fence", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CHECK (cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_cas_nonnegative", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (source_verification_job_id::text <> retry_verification_job_id::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_distinct_jobs", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (recovery_class::text = 'provider_observation'::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_recovery_class", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_request_digest", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['requested', 'succeeded', 'failed']))", - "kind": "c", - "name": "ck_artifact_recovery_attempts_status", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (status::text = 'succeeded'::text AND terminal_result_code::text = 'verified'::text OR status::text = 'failed'::text AND (terminal_result_code::text = ANY (ARRAY['provider_unavailable', 'missing', 'integrity_mismatch', 'conflict'])) OR status::text = 'requested'::text)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_terminal_result", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (status::text = 'requested'::text AND terminal_result_code IS NULL AND terminal_at IS NULL AND terminal_audit_event_id IS NULL OR (status::text = ANY (ARRAY['succeeded', 'failed'])) AND terminal_result_code IS NOT NULL AND terminal_at IS NOT NULL AND terminal_audit_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_artifact_recovery_attempts_terminal_shape", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (initiation_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_initiation_audit_event_id_2af7", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (parent_recovery_attempt_id) REFERENCES artifact_recovery_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_parent_recovery_attempt_i_130d", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_project_id_projects", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (requester_actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_requester_actor_profile_i_77f5", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (requester_identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_requester_identity_link_i_3619", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (retry_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_retry_verification_job_id_b330", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (source_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_source_verification_job_i_5eac", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_submission_id_submissions", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_task_id_workstream_tasks", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "FOREIGN KEY (terminal_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_recovery_attempts_terminal_audit_event_id_a_47ab", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_recovery_attempts", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "UNIQUE (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", - "kind": "u", - "name": "uq_artifact_recovery_idempotency", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "UNIQUE (retry_verification_job_id)", - "kind": "u", - "name": "uq_artifact_recovery_retry_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "UNIQUE (source_verification_job_id)", - "kind": "u", - "name": "uq_artifact_recovery_source_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CHECK (availability_state::text = ANY (ARRAY['unknown', 'available', 'unavailable']))", - "kind": "c", - "name": "ck_artifact_replicas_availability_state", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_replicas_fingerprint_shape", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (integrity_state::text = ANY (ARRAY['unknown', 'valid', 'invalid']))", - "kind": "c", - "name": "ck_artifact_replicas_integrity_state", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (verification_state::text = ANY (ARRAY['pending', 'verified', 'missing', 'integrity_mismatch']))", - "kind": "c", - "name": "ck_artifact_replicas_verification_state", - "table_name": "artifact_replicas" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_replicas_content_id_artifact_contents", - "table_name": "artifact_replicas" - }, - { - "definition": "FOREIGN KEY (storage_namespace_id) REFERENCES artifact_storage_namespaces(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_replicas_storage_namespace_id_artifact_stor_d6cc", - "table_name": "artifact_replicas" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_replicas", - "table_name": "artifact_replicas" - }, - { - "definition": "UNIQUE (storage_namespace_id, provider_object_ref)", - "kind": "u", - "name": "uq_artifact_replica_provider_object", - "table_name": "artifact_replicas" - }, - { - "definition": "UNIQUE (id, content_id)", - "kind": "u", - "name": "uq_artifact_replicas_id_content", - "table_name": "artifact_replicas" - }, - { - "definition": "CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_storage_namespaces_fingerprint_shape", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CHECK (id::text = 'primary'::text)", - "kind": "c", - "name": "ck_artifact_storage_namespaces_singleton_id", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_storage_namespaces", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "UNIQUE (namespace_fingerprint)", - "kind": "u", - "name": "uq_artifact_storage_namespace_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "UNIQUE (id, namespace_fingerprint)", - "kind": "u", - "name": "uq_artifact_storage_namespace_id_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CHECK (attempt_count >= 0 AND maximum_attempts > 0)", - "kind": "c", - "name": "ck_artifact_verification_jobs_attempts", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))", - "kind": "c", - "name": "ck_artifact_verification_jobs_fence_pair", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK ((status::text = 'running'::text) = (executor_id IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_verification_jobs_running_fence", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'running', 'verified', 'missing', 'integrity_mismatch', 'provider_unavailable', 'conflict']))", - "kind": "c", - "name": "ck_artifact_verification_jobs_status", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK (status::text <> 'provider_unavailable'::text OR next_run_at IS NOT NULL AND terminal_at IS NULL AND attempt_count < maximum_attempts OR next_run_at IS NULL AND terminal_at IS NOT NULL AND attempt_count >= maximum_attempts)", - "kind": "c", - "name": "ck_artifact_verification_jobs_unavailable_retryability", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK (execution_generation >= 0 AND cas_version >= 0)", - "kind": "c", - "name": "ck_artifact_verification_jobs_versions", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "FOREIGN KEY (originating_put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_jobs_originating_put_attempt_i_3260", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_jobs_replica_id_artifact_replicas", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "FOREIGN KEY (parent_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_parent", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_verification_jobs", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "UNIQUE (parent_verification_job_id)", - "kind": "u", - "name": "uq_artifact_verification_parent", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CHECK ((outcome::text = ANY (ARRAY['verified', 'integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))", - "kind": "c", - "name": "ck_artifact_verification_receipts_observed_facts", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_artifact_verification_receipts_observed_sha256", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", - "kind": "c", - "name": "ck_artifact_verification_receipts_observed_size", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (outcome::text = ANY (ARRAY['verified', 'missing', 'integrity_mismatch', 'conflict']))", - "kind": "c", - "name": "ck_artifact_verification_receipts_outcome", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "FOREIGN KEY (verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_artifact_verification_receipts_verification_job_id_a_dabf", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_artifact_verification_receipts", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "UNIQUE (verification_job_id, execution_generation)", - "kind": "u", - "name": "uq_artifact_verification_fence", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND (entity_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'authorization_decision', 'authority_invalidation'])) AND entity_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND ((actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile'])) AND actor_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR actor_ref_kind::text = 'system_principal'::text AND actor_id::text = 'workstream:system:bootstrap'::text) AND (target_actor_ref IS NULL OR target_actor_ref_kind::text = 'actor_profile'::text AND target_actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (matched_grant_id IS NULL OR matched_grant_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (project_id IS NULL OR project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (resource_type IS NULL OR (resource_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'project', 'qualification_snapshot', 'project_role_grant', 'task', 'submission', 'review', 'contribution', 'compensation_award', 'compensation_delivery', 'operations', 'audit_event', 'project_create_operation', 'project_submission_artifact_policy_mutation', 'project_guide_compilation_attempt', 'project_guide_compilation_request']))) AND (resource_id IS NULL OR resource_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (target_ref_kind IS NULL OR (target_ref_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'project'])) AND target_ref_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR target_ref_kind::text = 'permission_registry'::text AND (target_ref_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND (invalidation_target_kind IS NULL OR (invalidation_target_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant'])) AND invalidation_target_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR invalidation_target_kind::text = 'permission_registry'::text AND (invalidation_target_ref::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND ((entity_type::text <> ALL (ARRAY['authorization_decision', 'authority_invalidation'])) OR entity_id::text = id::text) AND (resource_type::text <> 'project'::text OR resource_id IS NULL OR project_id IS NOT NULL AND resource_id::text = project_id::text))", - "kind": "c", - "name": "ck_audit_events_authority_privacy_bounds", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR reason IS NOT NULL AND (event_type::text = 'ActorProfileProvisioned'::text AND reason = 'automatic_first_access'::text OR event_type::text = 'ServiceActorProvisioned'::text AND reason = 'manual_service_provisioning'::text OR event_type::text = 'ActorIdentityLinked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkRevoked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkReactivated'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorProfileSuspended'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'ActorProfileReactivated'::text AND reason = 'administrative_correction'::text OR event_type::text = 'ActorProfileDeactivated'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'InitialAccessAdministratorBootstrapped'::text AND reason = 'initial_access_bootstrap'::text OR event_type::text = 'AdminRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'AdminRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'AdminRoleGrantIssueDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'LastAccessAdministratorOperationDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'ProjectRoleQualificationSnapshotCaptured'::text AND reason = 'qualification_evidence_captured'::text OR event_type::text = 'ProjectRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'ProjectRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'SensitiveAuthorizationDenied'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'AuthorityInvalidationRequested'::text AND reason = 'authority_state_changed'::text) AND (permission_id IS NULL OR (permission_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.execute', 'project.guide_compilation.request']))) AND (denial_code IS NULL OR (denial_code::text = ANY (ARRAY['required_scope_missing', 'unsupported_subject_kind', 'service_actor_not_provisioned', 'identity_link_revoked', 'actor_suspended', 'actor_deactivated', 'permission_not_granted', 'scope_not_authorized', 'self_grant_forbidden', 'self_role_revoke_forbidden', 'resource_guard_denied', 'actor_not_found', 'grant_not_found', 'resource_not_found', 'actor_already_suspended', 'actor_not_suspended', 'actor_deactivated_terminal', 'last_access_administrator', 'admin_role_grant_exists', 'project_role_grant_exists', 'identity_link_conflict', 'project_role_grant_already_revoked', 'project_role_grant_replay_state_changed', 'identity_link_already_revoked', 'identity_link_not_revoked', 'resource_project_mismatch', 'idempotency_mismatch', 'invalid_role_scope', 'invalid_project_role', 'qualification_snapshot_invalid']))))", - "kind": "c", - "name": "ck_audit_events_authority_registries", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text = ANY (ARRAY['ActorProfileProvisioned', 'ServiceActorProvisioned', 'ActorIdentityLinked', 'ActorIdentityLinkRevoked', 'ActorIdentityLinkReactivated', 'ActorProfileSuspended', 'ActorProfileReactivated', 'ActorProfileDeactivated', 'InitialAccessAdministratorBootstrapped', 'AdminRoleGrantIssued', 'AdminRoleGrantRevoked', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied', 'ProjectRoleQualificationSnapshotCaptured', 'ProjectRoleGrantIssued', 'ProjectRoleGrantReplaced', 'ProjectRoleGrantRevoked', 'SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested'])))", - "kind": "c", - "name": "ck_audit_events_authority_tokens", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND action_id IS NULL OR event_domain::text = 'authority'::text AND (action_id IS NULL OR (event_type::text = ANY (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied'])) AND permission_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)) AND (permission_id IS NULL OR (permission_id::text <> ALL (ARRAY['operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'project.guide_compilation.request', 'project.guide_compilation.execute'])) OR action_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)))", - "kind": "c", - "name": "ck_audit_events_authorization_action_evidence", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text = 'legacy_lifecycle'::text AND event_version IS NULL AND occurred_at IS NULL AND actor_ref_kind IS NULL AND request_id IS NULL AND correlation_id IS NULL AND target_actor_ref_kind IS NULL AND target_actor_ref IS NULL AND matched_grant_id IS NULL AND permission_id IS NULL AND project_id IS NULL AND resource_type IS NULL AND resource_id IS NULL AND target_ref_kind IS NULL AND target_ref_id IS NULL AND denial_code IS NULL AND idempotency_reference IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND invalidation_target_ref IS NULL AND before_facts IS NULL AND after_facts IS NULL AND external_subject IS NOT NULL AND external_issuer IS NOT NULL OR event_domain::text = 'authority'::text AND event_version = 1 AND occurred_at IS NOT NULL AND (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal'])) AND request_id IS NOT NULL AND correlation_id IS NOT NULL AND from_status IS NULL AND to_status IS NULL AND reason IS NOT NULL AND external_subject IS NULL AND external_issuer IS NULL AND actor_roles::jsonb = '[]'::jsonb AND claim_snapshot::jsonb = '{}'::jsonb AND auth_source::text = 'local_authority'::text AND is_dev_auth = false AND event_payload::jsonb = '{}'::jsonb)", - "kind": "c", - "name": "ck_audit_events_domain_shape", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR (before_facts IS NULL OR octet_length(before_facts::text) <= 4096) AND (after_facts IS NULL OR octet_length(after_facts::text) <= 4096) AND COALESCE(authority_event_facts_are_safe(event_type::text, before_facts, after_facts, project_id::text), false))", - "kind": "c", - "name": "ck_audit_events_fact_bounds", - "table_name": "audit_events" - }, - { - "definition": "CHECK (event_domain::text <> 'authority'::text OR (event_type::text <> ALL (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) OR (event_type::text = ANY (ARRAY['AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) AND denial_code IS NOT NULL OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND permission_id IS NOT NULL AND denial_code IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL OR event_type::text = 'SensitiveAuthorizationDenied'::text AND permission_id IS NOT NULL AND denial_code IS NOT NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND idempotency_reference IS NULL OR event_type::text = 'AuthorityInvalidationRequested'::text AND invalidation_cause_event_id IS NOT NULL AND invalidation_target_kind IS NOT NULL AND denial_code IS NULL)", - "kind": "c", - "name": "ck_audit_events_foundation_shapes", - "table_name": "audit_events" - }, - { - "definition": "CHECK ((target_actor_ref_kind IS NULL) = (target_actor_ref IS NULL) AND (resource_type IS NOT NULL OR resource_id IS NULL) AND (target_ref_kind IS NULL) = (target_ref_id IS NULL) AND (invalidation_target_kind IS NULL) = (invalidation_target_ref IS NULL) AND (invalidation_cause_event_id IS NULL OR invalidation_cause_event_id::text <> id::text))", - "kind": "c", - "name": "ck_audit_events_reference_pairs", - "table_name": "audit_events" - }, - { - "definition": "FOREIGN KEY (idempotency_reference, actor_ref_kind, actor_id) REFERENCES authority_idempotency_records(id, actor_ref_kind, actor_ref) NOT VALID", - "kind": "f", - "name": "fk_audit_events_authority_idempotency", - "table_name": "audit_events" - }, - { - "definition": "FOREIGN KEY (invalidation_cause_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_audit_events_invalidation_cause", - "table_name": "audit_events" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_audit_events", - "table_name": "audit_events" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "authority_control_bootstrap_invariant", - "table_name": "authority_control" - }, - { - "definition": "CHECK (bootstrap_completed = false AND bootstrap_grant_id IS NULL AND version = 0 OR bootstrap_completed = true AND bootstrap_grant_id IS NOT NULL AND version = 1)", - "kind": "c", - "name": "ck_authority_control_bootstrap_state", - "table_name": "authority_control" - }, - { - "definition": "CHECK (id = 1)", - "kind": "c", - "name": "ck_authority_control_singleton", - "table_name": "authority_control" - }, - { - "definition": "FOREIGN KEY (bootstrap_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_authority_control_bootstrap_grant_id_admin_role_grants", - "table_name": "authority_control" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_authority_control", - "table_name": "authority_control" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "authority_idempotency_pending_guard", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal']))", - "kind": "c", - "name": "ck_authority_idempotency_records_actor_kind", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (actor_ref_kind::text = 'system_principal'::text AND actor_ref::text = 'workstream:system:bootstrap'::text OR actor_ref_kind::text <> 'system_principal'::text AND actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_authority_idempotency_records_actor_reference", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'admin_role_grant.revoke', 'project_role_grant.issue', 'project_role_grant.revoke', 'actor_profile.suspend', 'actor_profile.reactivate', 'actor_profile.deactivate', 'actor_identity_link.revoke', 'actor_identity_link.reactivate']))", - "kind": "c", - "name": "ck_authority_idempotency_records_operation", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_authority_idempotency_records_request_digest", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (response_http_status IS NULL OR (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 201 OR (operation::text <> ALL (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 200)", - "kind": "c", - "name": "ck_authority_idempotency_records_response_status", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (operation::text = 'service_actor.create'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'admin_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'admin_role_grant'::text) OR operation::text ~~ 'project_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'project_role_grant'::text) OR operation::text ~~ 'actor_profile.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'actor_identity_link.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_identity_link'::text))", - "kind": "c", - "name": "ck_authority_idempotency_records_response_type", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (response_resource_version IS NULL OR response_resource_version > 0)", - "kind": "c", - "name": "ck_authority_idempotency_records_response_version", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_resource_type IS NULL AND response_resource_id IS NULL AND response_resource_version IS NULL AND response_http_status IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_resource_type IS NOT NULL AND response_resource_id IS NOT NULL AND response_http_status IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_authority_idempotency_records_state_shape", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_authority_idempotency_records_status", - "table_name": "authority_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_authority_idempotency_records", - "table_name": "authority_idempotency_records" - }, - { - "definition": "UNIQUE (id, actor_ref_kind, actor_ref)", - "kind": "u", - "name": "uq_authority_idempotency_records_actor_reference", - "table_name": "authority_idempotency_records" - }, - { - "definition": "UNIQUE (actor_ref_kind, actor_ref, operation, idempotency_key)", - "kind": "u", - "name": "uq_authority_idempotency_records_replay_namespace", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", - "kind": "c", - "name": "ck_checker_policies_approval_provenance", - "table_name": "checker_policies" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'superseded'::text OR superseded_at IS NOT NULL AND (superseded_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND superseded_by_actor IS NOT NULL AND (supersession_kind::text = ANY (ARRAY['correction_requested', 'upstream_policy_changed'])) AND supersession_reason IS NOT NULL AND length(btrim(supersession_reason)) > 0)", - "kind": "c", - "name": "ck_checker_policies_correction_provenance", - "table_name": "checker_policies" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['compiled', 'approved', 'superseded']))", - "kind": "c", - "name": "ck_checker_policies_lifecycle_status", - "table_name": "checker_policies" - }, - { - "definition": "CHECK (policy_hash IS NULL OR policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_checker_policies_policy_hash_shape", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_checker_policies_effective_policy_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_checker_policies_guide_id_project_guides", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (pre_submit_checker_policy_id, pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", - "kind": "f", - "name": "fk_checker_policies_pre_submit_checker_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_checker_policies_project_guide", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_checker_policies_project_id_projects", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_checker_policies_source_snapshot_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES checker_policies(id)", - "kind": "f", - "name": "fk_checker_policies_supersedes_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_checker_policies", - "table_name": "checker_policies" - }, - { - "definition": "UNIQUE (id, guide_version, policy_hash)", - "kind": "u", - "name": "uq_checker_policies_id_version_hash", - "table_name": "checker_policies" - }, - { - "definition": "FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_checker_results_checker_run_id_checker_runs", - "table_name": "checker_results" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_checker_results_submission_id_submissions", - "table_name": "checker_results" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_checker_results_task_id_workstream_tasks", - "table_name": "checker_results" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_checker_results", - "table_name": "checker_results" - }, - { - "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", - "kind": "c", - "name": "ck_checker_runs_post_submit_policy_lock_complete", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (audit_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_checker_runs_audit_event_id_audit_events", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", - "kind": "f", - "name": "fk_checker_runs_locked_post_submit_policy_hash", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_checker_runs_submission_id_submissions", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (submission_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES submissions(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "f", - "name": "fk_checker_runs_submission_locked_post_submit_policy_hash", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_checker_runs_submission_version", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (supersedes_checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_checker_runs_supersedes_checker_run_id_checker_runs", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_checker_runs_task_id_workstream_tasks", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", - "kind": "f", - "name": "fk_checker_runs_task_locked_guide", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", - "kind": "f", - "name": "fk_checker_runs_task_locked_payment_policy", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "kind": "f", - "name": "fk_checker_runs_task_locked_review_policy", - "table_name": "checker_runs" - }, - { - "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "kind": "f", - "name": "fk_checker_runs_task_locked_revision_policy", - "table_name": "checker_runs" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_checker_runs", - "table_name": "checker_runs" - }, - { - "definition": "UNIQUE (submission_id, attempt_number)", - "kind": "u", - "name": "uq_checker_runs_submission_attempt", - "table_name": "checker_runs" - }, - { - "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", - "kind": "c", - "name": "ck_contribution_award_definitions_contribution_type", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", - "kind": "c", - "name": "ck_contribution_award_definitions_instrument_type", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (instrument_type::text <> 'project_points'::text OR scale(quantity) = 0)", - "kind": "c", - "name": "ck_contribution_award_definitions_project_points_whole", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (quantity > 0::numeric AND quantity < '100000000000000000000'::numeric AND scale(quantity) >= 0 AND scale(quantity) <= 18)", - "kind": "c", - "name": "ck_contribution_award_definitions_quantity_exact_bounds", - "table_name": "contribution_award_definitions" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_award_definitions_graph_guard", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (adapter_binding_id, project_id, instrument_type) REFERENCES project_compensation_adapter_bindings(id, project_id, instrument_type)", - "kind": "f", - "name": "fk_contribution_award_definition_binding", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_award_definition_project", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (contribution_rule_id, contribution_policy_version_id, project_id, contribution_type) REFERENCES contribution_rules(id, contribution_policy_version_id, project_id, contribution_type)", - "kind": "f", - "name": "fk_contribution_award_definition_rule", - "table_name": "contribution_award_definitions" - }, - { - "definition": "FOREIGN KEY (project_id, instrument_type, unit_code) REFERENCES project_compensation_units(project_id, instrument_type, unit_code)", - "kind": "f", - "name": "fk_contribution_award_definition_unit", - "table_name": "contribution_award_definitions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_award_definitions", - "table_name": "contribution_award_definitions" - }, - { - "definition": "UNIQUE (contribution_rule_id, instrument_type)", - "kind": "u", - "name": "uq_contribution_award_definition_instrument", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CHECK (status::text = 'draft'::text AND current_published_version_id IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'active'::text AND current_published_version_id IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND current_published_version_id IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", - "kind": "c", - "name": "ck_contribution_policies_lifecycle_shape", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (char_length(btrim(name::text)) >= 1 AND char_length(btrim(name::text)) <= 200)", - "kind": "c", - "name": "ck_contribution_policies_name", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", - "kind": "c", - "name": "ck_contribution_policies_retirement_timestamp", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['draft', 'active', 'retired']))", - "kind": "c", - "name": "ck_contribution_policies_status", - "table_name": "contribution_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_policies_graph_guard", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_created_by", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (current_published_version_id, id, project_id) REFERENCES contribution_policy_versions(id, contribution_policy_id, project_id) DEFERRABLE INITIALLY DEFERRED", - "kind": "f", - "name": "fk_contribution_policy_current_version", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_policy_project", - "table_name": "contribution_policies" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_retired_by", - "table_name": "contribution_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_policies", - "table_name": "contribution_policies" - }, - { - "definition": "UNIQUE (id, project_id)", - "kind": "u", - "name": "uq_contribution_policy_ownership", - "table_name": "contribution_policies" - }, - { - "definition": "CHECK (status::text = 'draft'::text AND published_by IS NULL AND published_at IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'published'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", - "kind": "c", - "name": "ck_contribution_policy_versions_lifecycle_shape", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK ((published_at IS NULL OR published_at >= created_at) AND (retired_at IS NULL OR retired_at >= published_at))", - "kind": "c", - "name": "ck_contribution_policy_versions_lifecycle_timestamps", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['draft', 'published', 'retired']))", - "kind": "c", - "name": "ck_contribution_policy_versions_status", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK (version_number > 0)", - "kind": "c", - "name": "ck_contribution_policy_versions_version_number_positive", - "table_name": "contribution_policy_versions" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_policy_versions_graph_guard", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_version_created_by", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (contribution_policy_id, project_id) REFERENCES contribution_policies(id, project_id)", - "kind": "f", - "name": "fk_contribution_policy_version_policy", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_policy_version_project", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (published_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_version_published_by", - "table_name": "contribution_policy_versions" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_contribution_policy_version_retired_by", - "table_name": "contribution_policy_versions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_policy_versions", - "table_name": "contribution_policy_versions" - }, - { - "definition": "UNIQUE (contribution_policy_id, version_number)", - "kind": "u", - "name": "uq_contribution_policy_version_number", - "table_name": "contribution_policy_versions" - }, - { - "definition": "UNIQUE (id, contribution_policy_id, project_id)", - "kind": "u", - "name": "uq_contribution_policy_version_ownership", - "table_name": "contribution_policy_versions" - }, - { - "definition": "UNIQUE (id, project_id)", - "kind": "u", - "name": "uq_contribution_policy_version_project", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CHECK (compensation_mode::text = ANY (ARRAY['unpaid', 'compensated']))", - "kind": "c", - "name": "ck_contribution_rules_compensation_mode", - "table_name": "contribution_rules" - }, - { - "definition": "CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))", - "kind": "c", - "name": "ck_contribution_rules_contribution_type", - "table_name": "contribution_rules" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "contribution_rules_graph_guard", - "table_name": "contribution_rules" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_contribution_rule_project", - "table_name": "contribution_rules" - }, - { - "definition": "FOREIGN KEY (contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", - "kind": "f", - "name": "fk_contribution_rule_version", - "table_name": "contribution_rules" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_contribution_rules", - "table_name": "contribution_rules" - }, - { - "definition": "UNIQUE (id, contribution_policy_version_id, project_id, contribution_type)", - "kind": "u", - "name": "uq_contribution_rule_ownership", - "table_name": "contribution_rules" - }, - { - "definition": "UNIQUE (contribution_policy_version_id, contribution_type)", - "kind": "u", - "name": "uq_contribution_rule_type", - "table_name": "contribution_rules" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['approved', 'superseded']))", - "kind": "c", - "name": "ck_effective_project_submission_artifact_policies_ck_ef_7be7", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_effective_project_submission_artifact_policies_ck_ef_bd4e", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "effective_submission_policy_custody", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_effective_policy_creation_actor", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_effective_policy_creation_decision", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_effective_policy_creation_grant", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_effective_policy_creation_link", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_effective_policy_creation_project", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_effective_project_submission_artifact_policies_project_guide", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_effective_psap_guide", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_effective_psap_project", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_effective_psap_source_snapshot_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (submission_artifact_policy_id, submission_artifact_policy_hash) REFERENCES submission_artifact_policies(id, policy_hash)", - "kind": "f", - "name": "fk_effective_psap_submission_policy_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", - "kind": "f", - "name": "fk_effective_psap_supersedes", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_effective_project_submission_artifact_policies", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "UNIQUE (id, effective_policy_hash)", - "kind": "u", - "name": "uq_effective_project_submission_artifact_policies_id_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_evidence_items_submission_id_submissions", - "table_name": "evidence_items" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_evidence_items", - "table_name": "evidence_items" - }, - { - "definition": "CHECK (operation_generation > 0)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_6506", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL AND setup_run_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_9402", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create']))", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_action", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_b397", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_e32d", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_guide_mutation_idempotency_records_ck_guide_mutation_status", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_actor_profile_id__2ee3", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_identity_link_id__3ddf", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_project_id_projects", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_guide_mutation_idempotency_records_setup_run_id_proj_7dc3", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "guide_mutation_reservation_custody", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_mutation_idempotency_records", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_guide_mutation_operation_identity", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", - "kind": "u", - "name": "uq_guide_mutation_replay_namespace", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_gen_b5fe", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CHECK (logical_role::text = 'guide_source_original'::text)", - "kind": "c", - "name": "ck_guide_source_artifact_bindings_ck_guide_bindings_role", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (source_item_id, source_snapshot_id) REFERENCES guide_source_snapshot_items(id, source_snapshot_id)", - "kind": "f", - "name": "fk_guide_bindings_exact_item", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (project_setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", - "kind": "f", - "name": "fk_guide_bindings_exact_setup_generation", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, project_id, guide_id) REFERENCES guide_source_snapshots(id, project_id, guide_id)", - "kind": "f", - "name": "fk_guide_bindings_exact_snapshot", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (verified_replica_id, content_id) REFERENCES artifact_replicas(id, content_id)", - "kind": "f", - "name": "fk_guide_bindings_verified_replica_content", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_guide_source_artifact_bindings_content_id_artifact_contents", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "FOREIGN KEY (supersedes_binding_id) REFERENCES guide_source_artifact_bindings(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_guide_source_artifact_bindings_supersedes_binding_id_bfa2", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_artifact_bindings", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (id, content_id, verified_replica_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_exact_read", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (id, content_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_extraction_attempt_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (id, content_id, source_item_id, project_setup_run_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_extraction_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (source_item_id, setup_generation)", - "kind": "u", - "name": "uq_guide_bindings_item_generation", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "UNIQUE (supersedes_binding_id)", - "kind": "u", - "name": "uq_guide_bindings_supersedes", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CHECK (code::text = ANY (ARRAY['missing', 'changed', 'truncated', 'unavailable', 'stale', 'conflict']))", - "kind": "c", - "name": "ck_guide_source_artifact_incidents_ck_guide_incidents_code", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_621b", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_artifact_incidents_ck_guide_source_arti_92fa", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", - "kind": "f", - "name": "fk_guide_incidents_exact_binding", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_artifact_incidents", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_2958", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_artifact_ingests_ck_guide_source_artifa_64cb", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_source_artifact_ingests_actor_profile_id_actor_22c1", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "FOREIGN KEY (source_item_id) REFERENCES guide_source_snapshot_items(id)", - "kind": "f", - "name": "fk_guide_source_artifact_ingests_source_item_id_guide_s_7ba9", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_artifact_ingests", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "UNIQUE (source_item_id)", - "kind": "u", - "name": "uq_guide_source_artifact_ingests_source_item_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CHECK (output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_1b91", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (octet_length(canonical_output) <= 4194304)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_54b5", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (source_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_988f", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (status::text = 'extracted'::text)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_a759", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (source_byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_extracted_contents_ck_guide_extracted_c_fb79", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_guide_source_extracted_contents_content_id_artifact_contents", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_extracted_contents", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "UNIQUE (id, content_id)", - "kind": "u", - "name": "uq_guide_extracted_contents_exact_usage", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "UNIQUE (content_id, detected_format, extractor_name, extractor_version, policy_version)", - "kind": "u", - "name": "uq_guide_extracted_contents_identity", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CHECK (attempt_number > 0)", - "kind": "c", - "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_3927", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CHECK ((status::text = 'extracted'::text) = (error_code IS NULL))", - "kind": "c", - "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_940d", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['extracted', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded', 'parser_failure', 'cancelled', 'artifact_incident']))", - "kind": "c", - "name": "ck_guide_source_extraction_attempts_ck_guide_extraction_ff6d", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_attempts_exact_binding", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_attempts_exact_classification", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "UNIQUE (binding_id, policy_version, attempt_number)", - "kind": "u", - "name": "uq_guide_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "UNIQUE (id, binding_id, content_id, setup_generation, status)", - "kind": "u", - "name": "uq_guide_extraction_attempts_exact_usage", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CHECK (claimed_slots >= 1 AND claimed_slots <= 2)", - "kind": "c", - "name": "ck_guide_source_extraction_retry_budgets_ck_guide_extra_99c3", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_retry_budgets_exact_binding", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_retry_budgets_exact_classification", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "PRIMARY KEY (binding_id)", - "kind": "p", - "name": "pk_guide_source_extraction_retry_budgets", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "CHECK (attempt_status::text = 'extracted'::text)", - "kind": "c", - "name": "ck_guide_source_extraction_usages_ck_guide_extraction_u_a2fd", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "FOREIGN KEY (extraction_attempt_id, binding_id, content_id, setup_generation, attempt_status) REFERENCES guide_source_extraction_attempts(id, binding_id, content_id, setup_generation, status)", - "kind": "f", - "name": "fk_guide_extraction_usages_exact_attempt", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, source_item_id, project_setup_run_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, source_item_id, project_setup_run_id, setup_generation)", - "kind": "f", - "name": "fk_guide_extraction_usages_exact_binding", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "FOREIGN KEY (extracted_content_id, content_id) REFERENCES guide_source_extracted_contents(id, content_id)", - "kind": "f", - "name": "fk_guide_extraction_usages_exact_content", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "UNIQUE (binding_id, extracted_content_id)", - "kind": "u", - "name": "uq_guide_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "UNIQUE (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", - "kind": "u", - "name": "uq_guide_extraction_usages_exact_provenance", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['classified', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded']))", - "kind": "c", - "name": "ck_guide_source_format_classifications_ck_guide_classif_8737", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_source_format_classifications_ck_guide_source__0dd2", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CHECK (byte_count >= 0)", - "kind": "c", - "name": "ck_guide_source_format_classifications_ck_guide_source__7235", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)", - "kind": "f", - "name": "fk_guide_classifications_exact_binding", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_format_classifications", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "UNIQUE (binding_id)", - "kind": "u", - "name": "uq_guide_classifications_binding", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "UNIQUE (id, binding_id, content_id, setup_generation)", - "kind": "u", - "name": "uq_guide_classifications_extraction_lineage", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_gssi_source_snapshot", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "guide_source_snapshot_items_custody", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_snapshot_items", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "UNIQUE (id, source_snapshot_id)", - "kind": "u", - "name": "uq_guide_source_snapshot_items_exact_lineage", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "UNIQUE (source_snapshot_id, item_order)", - "kind": "u", - "name": "uq_guide_source_snapshot_items_snapshot_order", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CHECK (creation_generation IS NULL AND created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR creation_generation > 0 AND created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (creation_scope_type::text = 'system'::text AND creation_scope_project_id IS NULL OR creation_scope_type::text = 'project'::text AND creation_scope_project_id::text = project_id::text) AND creation_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_guide_source_snapshots_source_snapshot_creation_auth_2f3e", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_actor", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_admin_grant", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_decision", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_created_identity_link", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_guide_id_project_guides", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_guide_source_snapshots_project_guide", - "table_name": "guide_source_snapshots" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_source_snapshots_project_id_projects", - "table_name": "guide_source_snapshots" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_source_snapshots", - "table_name": "guide_source_snapshots" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "source_snapshot_product_custody", - "table_name": "guide_source_snapshots" - }, - { - "definition": "UNIQUE (id, project_id, guide_id)", - "kind": "u", - "name": "uq_guide_source_snapshots_exact_lineage", - "table_name": "guide_source_snapshots" - }, - { - "definition": "UNIQUE (id, bundle_hash)", - "kind": "u", - "name": "uq_guide_source_snapshots_id_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "UNIQUE (project_id, guide_version, bundle_hash)", - "kind": "u", - "name": "uq_guide_source_snapshots_project_version_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_1033", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_177a", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run', 'project.guide_sufficiency.warnings.acknowledge']))", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_6651", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_87dd", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND (action_id::text = 'project.guide_sufficiency.run'::text AND (setup_run_id IS NOT NULL OR report_id IS NOT NULL) OR action_id::text <> 'project.guide_sufficiency.run'::text AND report_id IS NOT NULL))", - "kind": "c", - "name": "ck_guide_sufficiency_mutation_idempotency_records_ck_su_e7f6", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_actor_16d8", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_guide_1d2b", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_ident_2378", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_proje_7f82", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_repor_48c3", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_setup_7059", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_guide_sufficiency_mutation_idempotency_records_sourc_9985", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_sufficiency_mutation_idempotency_records", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_sufficiency_mutation_operation_identity", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, idempotency_key)", - "kind": "u", - "name": "uq_sufficiency_mutation_replay_namespace", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_2983", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CHECK (canonical_output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_8148", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CHECK (item_order >= 0)", - "kind": "c", - "name": "ck_guide_sufficiency_report_source_usages_ck_sufficienc_eb12", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id) ON DELETE CASCADE", - "kind": "f", - "name": "fk_guide_sufficiency_report_source_usages_report_id_gui_1d57", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "FOREIGN KEY (extraction_usage_id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation) REFERENCES guide_source_extraction_usages(id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", - "kind": "f", - "name": "fk_sufficiency_report_source_usage_exact_extraction", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_sufficiency_report_source_usages", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "UNIQUE (report_id, extraction_usage_id)", - "kind": "u", - "name": "uq_sufficiency_report_extraction_usage", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "UNIQUE (report_id, item_order)", - "kind": "u", - "name": "uq_sufficiency_report_item_order", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CHECK (warnings_acknowledged_by_actor_profile_id IS NULL AND warnings_acknowledged_via_identity_link_id IS NULL AND warnings_acknowledged_by_admin_role_grant_id IS NULL AND warning_acknowledgement_scope_type IS NULL AND warning_acknowledgement_scope_project_id IS NULL AND warning_acknowledgement_action_id IS NULL AND warning_acknowledgement_decision_event_id IS NULL OR warnings_acknowledged_by_actor_profile_id IS NOT NULL AND warnings_acknowledged_via_identity_link_id IS NOT NULL AND warnings_acknowledged_by_admin_role_grant_id IS NOT NULL AND (warning_acknowledgement_scope_type::text = ANY (ARRAY['system', 'project'])) AND warning_acknowledgement_scope_project_id IS NOT NULL AND warning_acknowledgement_action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND warning_acknowledgement_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_guide_sufficiency_ack_authority_shape", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run'])) AND authorization_decision_event_id IS NOT NULL AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.guide_sufficiency.run'::text AND project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL))", - "kind": "c", - "name": "ck_guide_sufficiency_creation_authority_shape", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (agent_material_byte_count IS NULL OR agent_material_byte_count >= 0)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_31bb", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (setup_generation IS NULL OR setup_generation > 0)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_3e43", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (project_setup_run_id IS NULL AND setup_generation IS NULL AND agent_material_sha256 IS NULL AND agent_material_byte_count IS NULL OR project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_4640", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['passed', 'blocked', 'passed_with_warnings']))", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_841c", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (agent_material_sha256 IS NULL OR agent_material_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_b3ec", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_guide_id_project_guides", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_project_guide", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_project_id_projects", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_guide_sufficiency_reports_source_snapshot_hash", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warnings_acknowledged_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_suff_ack_actor", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warning_acknowledgement_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_suff_ack_decision", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warnings_acknowledged_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_suff_ack_grant", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warnings_acknowledged_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_suff_ack_link", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (warning_acknowledgement_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_suff_ack_project", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_suff_create_actor", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_suff_create_decision", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_suff_create_grant", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_suff_create_link", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_suff_create_project", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "FOREIGN KEY (project_setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_sufficiency_reports_setup_run", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_guide_sufficiency_reports", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CHECK (code::text ~ '^[A-Z]{3}$'::text)", - "kind": "c", - "name": "ck_iso_4217_currency_codes_code", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "PRIMARY KEY (code)", - "kind": "p", - "name": "pk_iso_4217_currency_codes", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "PRIMARY KEY (actor_id)", - "kind": "p", - "name": "pk_legacy_actor_identities", - "table_name": "legacy_actor_identities" - }, - { - "definition": "UNIQUE (external_issuer, external_subject)", - "kind": "u", - "name": "uq_legacy_actor_identities_external_identity", - "table_name": "legacy_actor_identities" - }, - { - "definition": "CHECK (profile_type::text = ANY (ARRAY['worker', 'reviewer', 'admin', 'project_manager', 'project_owner']))", - "kind": "c", - "name": "ck_legacy_workflow_eligibility_profile_type", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['observed', 'active', 'disabled']))", - "kind": "c", - "name": "ck_legacy_workflow_eligibility_status", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "FOREIGN KEY (actor_id) REFERENCES legacy_actor_identities(actor_id)", - "kind": "f", - "name": "fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_legacy_workflow_eligibility", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "UNIQUE (actor_id, profile_type, scope_type, scope_id)", - "kind": "u", - "name": "uq_legacy_workflow_eligibility_actor_type_scope", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CHECK (aggregate_type::text ~ '^[a-z][a-z0-9_]{0,63}$'::text)", - "kind": "c", - "name": "ck_outbox_events_aggregate_type", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (claim_owner IS NULL OR claim_owner::text ~ '^[A-Za-z0-9._:-]{1,120}$'::text)", - "kind": "c", - "name": "ck_outbox_events_claim_owner", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (correlation_id::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", - "kind": "c", - "name": "ck_outbox_events_correlation_id", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (attempt_count >= 0 AND claim_generation >= 0 AND attempt_count = claim_generation)", - "kind": "c", - "name": "ck_outbox_events_delivery_counters", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (delivery_state::text = ANY (ARRAY['pending', 'claimed', 'retryable', 'acknowledged', 'dead_letter', 'cancelled']))", - "kind": "c", - "name": "ck_outbox_events_delivery_state", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (delivery_state::text = 'pending'::text AND attempt_count = 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NULL AND last_error_code IS NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'claimed'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NOT NULL AND claimed_at IS NOT NULL AND claim_expires_at IS NOT NULL AND last_attempt_at = claimed_at AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'retryable'::text AND attempt_count > 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'acknowledged'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'dead_letter'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'cancelled'::text AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND finalized_at IS NOT NULL AND (attempt_count = 0 AND last_attempt_at IS NULL AND last_error_code IS NULL OR attempt_count > 0 AND last_attempt_at IS NOT NULL))", - "kind": "c", - "name": "ck_outbox_events_delivery_state_shape", - "table_name": "outbox_events" - }, - { - "definition": "CHECK ((next_attempt_at IS NULL OR next_attempt_at >= occurred_at) AND (claimed_at IS NULL OR claimed_at >= occurred_at) AND (last_attempt_at IS NULL OR last_attempt_at >= occurred_at) AND (claim_expires_at IS NULL OR claim_expires_at > claimed_at) AND (finalized_at IS NULL OR finalized_at >= occurred_at) AND (finalized_at IS NULL OR last_attempt_at IS NULL OR finalized_at >= last_attempt_at) AND (archived_at IS NULL OR archived_at >= finalized_at))", - "kind": "c", - "name": "ck_outbox_events_delivery_timestamps", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (last_error_code IS NULL OR last_error_code::text ~ '^[A-Z][A-Z0-9_]{0,79}$'::text)", - "kind": "c", - "name": "ck_outbox_events_error_code", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (event_type::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'::text)", - "kind": "c", - "name": "ck_outbox_events_event_type", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (event_version >= 1 AND event_version <= 32767)", - "kind": "c", - "name": "ck_outbox_events_event_version", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (idempotency_key::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)", - "kind": "c", - "name": "ck_outbox_events_idempotency_key", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (payload_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_outbox_events_payload_digest", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (jsonb_typeof(payload) = 'object'::text AND octet_length(payload::text) <= 262144)", - "kind": "c", - "name": "ck_outbox_events_payload_shape", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (producer::text = 'workstream'::text)", - "kind": "c", - "name": "ck_outbox_events_producer", - "table_name": "outbox_events" - }, - { - "definition": "CHECK (project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)", - "kind": "c", - "name": "ck_outbox_events_project_id", - "table_name": "outbox_events" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_outbox_events_project_id_projects", - "table_name": "outbox_events" - }, - { - "definition": "PRIMARY KEY (event_id)", - "kind": "p", - "name": "pk_outbox_events", - "table_name": "outbox_events" - }, - { - "definition": "UNIQUE (idempotency_key)", - "kind": "u", - "name": "uq_outbox_events_idempotency_key", - "table_name": "outbox_events" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_payment_policies_project_guide", - "table_name": "payment_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_payment_policies_project_id_projects", - "table_name": "payment_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_payment_policies", - "table_name": "payment_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version)", - "kind": "u", - "name": "uq_payment_policies_project_version", - "table_name": "payment_policies" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_26aa", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_595e", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.review_policy.update', 'project.revision_policy.update']))", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_7f7f", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (policy_generation > 0)", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_8b22", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_policy_mutation_idempotency_records_ck_policy_mutati_dc05", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_actor_profile_id_41c2", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_guide_id_project_guides", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_identity_link_id_b806", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_policy_mutation_idempotency_records_project_id_projects", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_policy_mutation_idempotency_records", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "policy_mutation_replay_custody", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_policy_mutation_operation_identity", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", - "kind": "u", - "name": "uq_policy_mutation_replay_namespace", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'compiled'::text OR compiler_version IS NOT NULL AND compiled_bundle IS NOT NULL AND compiled_bundle_hash IS NOT NULL AND compiled_bundle_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_5010", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['pending_compilation', 'compiled', 'superseded']))", - "kind": "c", - "name": "ck_pre_submit_checker_policies_ck_pre_submit_checker_po_a935", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_pre_submit_checker_policies_ck_pre_submit_policy_aut_90fc", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_effective_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_guide", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_project", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_project_guide", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_source_snapshot_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_pre_submit_checker_policy_id) REFERENCES pre_submit_checker_policies(id)", - "kind": "f", - "name": "fk_pre_submit_checker_policies_supersedes", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_actor", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_decision", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_grant", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_link", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_pre_submit_policy_creation_project", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_pre_submit_checker_policies", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "pre_submit_policy_custody", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "UNIQUE (id, compiled_bundle_hash)", - "kind": "u", - "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CHECK (classification::text = ANY (ARRAY['mandatory_security', 'mandatory_integrity', 'mandatory_accountability', 'advisory']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_b0de", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (classification::text = 'advisory'::text AND severity::text = 'warning'::text OR classification::text <> 'advisory'::text AND severity::text = 'blocking'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_cla_f04e", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (result_order >= 0)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_order", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (phase::text = ANY (ARRAY['custody', 'identity', 'materialization', 'default_policy', 'project_policy']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_phase", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_plan_sha256", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (locked_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_pol_cef4", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (phase::text = 'project_policy'::text AND rule_instance_id IS NOT NULL AND rule_instance_id::text ~ '^sha256:[0-9a-f]{64}$'::text OR phase::text <> 'project_policy'::text AND rule_instance_id IS NULL)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_rul_321f", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (severity::text = ANY (ARRAY['blocking', 'warning']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_severity", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['passed', 'warning', 'advisory_disabled', 'dependency_not_run', 'failed']))", - "kind": "c", - "name": "ck_pre_submit_evidence_results_ck_pre_submit_result_status", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (status::text = 'failed'::text AND failure_code IS NOT NULL OR status::text <> 'failed'::text AND failure_code IS NULL)", - "kind": "c", - "name": "ck_pre_submit_evidence_results_result_failure_shape", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "FOREIGN KEY (evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_results_evidence_set_id_pre_subm_096e", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_pre_submit_evidence_results", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "UNIQUE (evidence_set_id, definition_id)", - "kind": "u", - "name": "uq_pre_submit_result_definition", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "UNIQUE (evidence_set_id, result_order)", - "kind": "u", - "name": "uq_pre_submit_result_order", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arch_8e95", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (archive_byte_count >= 0)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_archive_size", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_artifact_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arti_16f8", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (catalogue_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_cata_ffcb", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_checker_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_chec_765d", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_guide_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_guide_sha256", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_mani_7268", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_oper_f617", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_plan_sha256", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (predecessor_submission_id IS NULL AND predecessor_submission_version IS NULL OR predecessor_submission_id IS NOT NULL AND predecessor_submission_version IS NOT NULL)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_pred_bd87", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (result_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_resu_0b46", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (result_count > 0)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_result_count", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (source_snapshot_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_sour_982b", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (terminal_status::text = 'passed'::text AND eligible OR terminal_status::text = 'blocked'::text AND NOT eligible)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stat_1ae6", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (storage_scheme::text = ANY (ARRAY['local', 's3']))", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stor_022c", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (terminal_status::text = ANY (ARRAY['passed', 'blocked']))", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_ck_pre_submit_evidence_term_a512", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_pre_submit_evidence_sets_policy_context_sha256", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (assignment_id, task_id, actor_profile_id) REFERENCES task_assignments(id, task_id, contributor_id)", - "kind": "f", - "name": "fk_pre_submit_evidence_assignment", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (guide_id, project_id, guide_version) REFERENCES project_guides(id, project_id, version)", - "kind": "f", - "name": "fk_pre_submit_evidence_guide_lineage", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (identity_link_id, actor_profile_id) REFERENCES actor_identity_links(id, actor_profile_id)", - "kind": "f", - "name": "fk_pre_submit_evidence_identity_actor", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (predecessor_submission_id, task_id, predecessor_submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_pre_submit_evidence_predecessor", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_actor_profile_id_actor_profiles", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_assignment_id_task_assignments", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_effective_policy_id_effecti_6a99", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_guide_id_project_guides", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_identity_link_id_actor_iden_5cef", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_pre_submit_policy_id_pre_su_c77f", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_predecessor_submission_id_s_6ec2", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_project_id_projects", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_source_snapshot_id_guide_so_1667", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_pre_submit_evidence_sets_task_id_workstream_tasks", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, effective_policy_id, locked_artifact_policy_sha256) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_artifact_policy", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, pre_submit_policy_id, locked_checker_policy_sha256) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_checker_policy", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_guide", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, project_id) REFERENCES workstream_tasks(id, project_id)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_project", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "FOREIGN KEY (task_id, source_snapshot_id, source_snapshot_sha256) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "kind": "f", - "name": "fk_pre_submit_evidence_task_source_snapshot", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_pre_submit_evidence_sets", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "UNIQUE (operation_identity)", - "kind": "u", - "name": "uq_pre_submit_evidence_operation", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CHECK (binding_lifecycle_version > 0)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_1870", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_3372", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (route_key::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'::text)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_6958", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (status::text = 'active'::text AND binding_lifecycle_version = 1 AND suspended_by IS NULL AND suspended_at IS NULL AND retired_by IS NULL AND retired_at IS NULL)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_95ba", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK ((suspended_at IS NULL OR suspended_at >= created_at) AND (retired_at IS NULL OR retired_at >= created_at) AND (retired_at IS NULL OR suspended_at IS NULL OR retired_at >= suspended_at))", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_ade1", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'suspended', 'retired']))", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_da73", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (route_key::text !~~ '%..%'::text)", - "kind": "c", - "name": "ck_project_compensation_adapter_bindings_ck_project_com_f32d", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (adapter_actor_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_adapter_actor", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_created_by", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_compensation_binding_project", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_retired_by", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "FOREIGN KEY (suspended_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_compensation_binding_suspended_by", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_compensation_adapter_bindings", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "UNIQUE (id, project_id, instrument_type)", - "kind": "u", - "name": "uq_compensation_binding_ownership", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))", - "kind": "c", - "name": "ck_project_compensation_units_instrument_type", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (status::text = 'active'::text AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND retired_by IS NOT NULL AND retired_at IS NOT NULL)", - "kind": "c", - "name": "ck_project_compensation_units_lifecycle_shape", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (retired_at IS NULL OR retired_at >= created_at)", - "kind": "c", - "name": "ck_project_compensation_units_retirement_time", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'retired']))", - "kind": "c", - "name": "ck_project_compensation_units_status", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (instrument_type::text = 'money'::text AND iso_currency_code IS NOT NULL AND unit_code::text = iso_currency_code::text OR instrument_type::text = 'project_points'::text AND iso_currency_code IS NULL AND unit_code::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$'::text)", - "kind": "c", - "name": "ck_project_compensation_units_unit_identity", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (created_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_compensation_unit_created_by", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (iso_currency_code) REFERENCES iso_4217_currency_codes(code)", - "kind": "f", - "name": "fk_project_compensation_unit_iso_currency", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_compensation_unit_project", - "table_name": "project_compensation_units" - }, - { - "definition": "FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_compensation_unit_retired_by", - "table_name": "project_compensation_units" - }, - { - "definition": "PRIMARY KEY (project_id, instrument_type, unit_code)", - "kind": "p", - "name": "pk_project_compensation_units", - "table_name": "project_compensation_units" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_0a41", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (operation_generation = 1)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_100d", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND committed_at IS NULL OR status::text = 'committed'::text AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_3aa0", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = 'project.create'::text)", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_action", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_project_create_idempotency_records_ck_project_create_status", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_create_idempotency_records_actor_profile_id__ebb1", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_create_idempotency_records_identity_link_id__ddce", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_create_idempotency_records", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "project_create_reservation_custody", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_project_create_operation_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "UNIQUE (project_id)", - "kind": "u", - "name": "uq_project_create_project_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "UNIQUE (actor_profile_id, action_id, idempotency_key)", - "kind": "u", - "name": "uq_project_create_replay_namespace", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_00d8", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (component_hashes IS NULL OR json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_31c4", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (status::text = 'compilation_reserved'::text AND provider_uncertain_at IS NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_provider_uncertain'::text AND provider_uncertain_at IS NOT NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'provider_result_accepted'::text AND accepted_at IS NOT NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_persisted'::text AND accepted_at IS NOT NULL AND persisted_at IS NOT NULL AND terminal_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NOT NULL OR status::text = 'compilation_invalid_terminal'::text AND terminal_at IS NOT NULL AND accepted_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND persisted_compilation_id IS NULL AND (failure_code::text = ANY (ARRAY['schema_invalid', 'unsafe_text', 'hash_mismatch', 'context_mismatch'])))", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_444c", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_513e", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (canonical_result IS NULL OR octet_length(canonical_result::text) <= 4194304)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6057", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (result_hash IS NULL OR result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6609", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['compilation_reserved', 'compilation_provider_uncertain', 'provider_result_accepted', 'compilation_invalid_terminal', 'compilation_persisted']))", - "kind": "c", - "name": "ck_project_guide_compilation_attempts_ck_compilation_at_6c82", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (persisted_compilation_id, id) REFERENCES project_guide_compilations(id, attempt_id)", - "kind": "f", - "name": "fk_compilation_attempt_exact_persisted_compilation", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)", - "kind": "f", - "name": "fk_compilation_attempt_exact_setup", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_compilation_attempt_snapshot_hash", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_project_guide_compilation_attempts_guide_id_project_guides", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_guide_compilation_attempts_project_id_projects", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_guide_compilation_attempts", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "UNIQUE (provider_idempotency_key)", - "kind": "u", - "name": "uq_compilation_attempt_provider_key", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "UNIQUE (setup_run_id, setup_generation)", - "kind": "u", - "name": "uq_compilation_attempt_setup_generation", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CHECK (setup_generation > 0 AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_action_id::text = 'project.guide_compilation.execute'::text)", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_8a51", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_9cd9", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK (authorization_resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_d554", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK (octet_length(canonical_result::text) <= 4194304 AND json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))", - "kind": "c", - "name": "ck_project_guide_compilations_ck_project_guide_compilat_dafe", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (supersedes_compilation_id, project_id, guide_id) REFERENCES project_guide_compilations(id, project_id, guide_id)", - "kind": "f", - "name": "fk_project_guide_compilation_predecessor", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (attempt_id) REFERENCES project_guide_compilation_attempts(id)", - "kind": "f", - "name": "fk_project_guide_compilations_attempt_id_project_guide__0e94", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_project_guide_compilations_authorization_decision_ev_42ad", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_guide_compilations_created_by_actor_profile__953f", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_guide_compilations_created_via_identity_link_b250", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_project_guide_compilations_guide_id_project_guides", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_guide_compilations_project_id_projects", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_project_guide_compilations_setup_run_id_project_setup_runs", - "table_name": "project_guide_compilations" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_project_guide_compilations_source_snapshot_id_guide__033a", - "table_name": "project_guide_compilations" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_guide_compilations", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (attempt_id)", - "kind": "u", - "name": "uq_project_guide_compilation_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (id, attempt_id)", - "kind": "u", - "name": "uq_project_guide_compilation_id_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (supersedes_compilation_id)", - "kind": "u", - "name": "uq_project_guide_compilation_predecessor", - "table_name": "project_guide_compilations" - }, - { - "definition": "UNIQUE (id, project_id, guide_id)", - "kind": "u", - "name": "uq_project_guide_compilation_scope", - "table_name": "project_guide_compilations" - }, - { - "definition": "CHECK ((status::text <> ALL (ARRAY['active', 'superseded'])) OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL AND selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL)", - "kind": "c", - "name": "ck_project_guides_active_policy_selection_required", - "table_name": "project_guides" - }, - { - "definition": "CHECK (mutation_generation IS NULL AND last_mutated_by_actor_profile_id IS NULL AND last_mutated_via_identity_link_id IS NULL AND last_mutated_by_admin_role_grant_id IS NULL AND last_mutation_scope_type IS NULL AND last_mutation_scope_project_id IS NULL AND last_mutation_action_id IS NULL AND last_authorization_decision_event_id IS NULL OR mutation_generation > 0 AND last_mutated_by_actor_profile_id IS NOT NULL AND last_mutated_via_identity_link_id IS NOT NULL AND last_mutated_by_admin_role_grant_id IS NOT NULL AND (last_mutation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (last_mutation_scope_type::text = 'system'::text AND last_mutation_scope_project_id IS NULL OR last_mutation_scope_type::text = 'project'::text AND last_mutation_scope_project_id::text = project_id::text) AND (last_mutation_action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create'])) AND last_authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_project_guides_guide_mutation_authority_shape", - "table_name": "project_guides" - }, - { - "definition": "CHECK ((selected_review_policy_id IS NULL AND selected_review_policy_generation IS NULL AND selected_review_policy_hash IS NULL OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL) AND (selected_revision_policy_id IS NULL AND selected_revision_policy_generation IS NULL AND selected_revision_policy_hash IS NULL OR selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL))", - "kind": "c", - "name": "ck_project_guides_policy_selection_shape", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_mutated_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_actor", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_mutated_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_admin_grant", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_decision", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (last_mutated_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_guides_last_mutated_identity_link", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_guides_project_id_projects", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (project_id, version, selected_review_policy_id, selected_review_policy_generation, selected_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_project_guides_selected_review_policy", - "table_name": "project_guides" - }, - { - "definition": "FOREIGN KEY (project_id, version, selected_revision_policy_id, selected_revision_policy_generation, selected_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_project_guides_selected_revision_policy", - "table_name": "project_guides" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "guide_mutation_product_custody", - "table_name": "project_guides" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_guides", - "table_name": "project_guides" - }, - { - "definition": "UNIQUE (id, project_id, version)", - "kind": "u", - "name": "uq_project_guides_id_project_version", - "table_name": "project_guides" - }, - { - "definition": "UNIQUE (project_id, version)", - "kind": "u", - "name": "uq_project_guides_project_version", - "table_name": "project_guides" - }, - { - "definition": "CHECK (grant_method::text = 'manual'::text)", - "kind": "c", - "name": "ck_project_role_grants_grant_method", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND revoked_at IS NOT NULL)", - "kind": "c", - "name": "ck_project_role_grants_lifecycle", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (project_role_reason_is_safe(grant_reason) AND (revoked_reason IS NULL OR project_role_reason_is_safe(revoked_reason)))", - "kind": "c", - "name": "ck_project_role_grants_reason", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", - "kind": "c", - "name": "ck_project_role_grants_role", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_grants_actor_profile_id_actor_profiles", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_grants_granted_by_actor_profile_id_acto_c240", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_role_grants_granted_by_admin_role_grant_id_a_71d7", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_role_grants_project_id_projects", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_grants_revoked_by_actor_profile_id_acto_a5dd", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_role_grants_revoked_by_admin_role_grant_id_a_aa4d", - "table_name": "project_role_grants" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_role_grants", - "table_name": "project_role_grants" - }, - { - "definition": "FOREIGN KEY (qualification_snapshot_id, actor_profile_id, project_id, role) REFERENCES project_role_qualification_snapshots(id, actor_profile_id, project_id, requested_role) ON DELETE RESTRICT", - "kind": "f", - "name": "qualification_ownership", - "table_name": "project_role_grants" - }, - { - "definition": "CHECK (project_role_availability_is_safe(skills_snapshot) AND project_role_availability_is_safe(reputation_snapshot))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_availability", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (project_role_reference_array_is_safe(external_expertise_refs, false))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_external_expertise_refs", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (project_role_reference_array_is_safe(prior_project_work_refs, true))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_prior_work_refs", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (requested_role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))", - "kind": "c", - "name": "ck_project_role_qualification_snapshots_role", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_actor_profile_i_aedc", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (captured_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_captured_by_act_ab57", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (captured_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_captured_by_adm_c8b8", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_role_qualification_snapshots_project_id_projects", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "UNIQUE (id, actor_profile_id, project_id, requested_role)", - "kind": "u", - "name": "grant_reference", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_role_qualification_snapshots", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_project_setup_runs_ck_project_setup_runs_generation_positive", - "table_name": "project_setup_runs" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['queued', 'dispatch_pending', 'enqueue_failed', 'enqueue_identity_mismatch', 'running_sufficiency_agent', 'sufficiency_blocked', 'running_policy_derivation_agent', 'policy_draft_ready', 'running_post_submit_derivation_agent', 'post_submit_setup_blocked', 'post_submit_policy_compiled', 'setup_blocked', 'failed']))", - "kind": "c", - "name": "ck_project_setup_runs_ck_project_setup_runs_status", - "table_name": "project_setup_runs" - }, - { - "definition": "CHECK (authorized_by_actor_profile_id IS NULL AND authorized_via_identity_link_id IS NULL AND authorized_by_admin_role_grant_id IS NULL AND authorization_scope_type IS NULL AND authorization_scope_project_id IS NULL AND authorization_action_id IS NULL AND authorization_decision_event_id IS NULL OR authorized_by_actor_profile_id IS NOT NULL AND authorized_via_identity_link_id IS NOT NULL AND authorized_by_admin_role_grant_id IS NOT NULL AND (authorization_scope_type::text = ANY (ARRAY['system', 'project'])) AND (authorization_scope_type::text = 'system'::text AND authorization_scope_project_id IS NULL OR authorization_scope_type::text = 'project'::text AND authorization_scope_project_id::text = project_id::text) AND authorization_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_project_setup_runs_setup_run_authority_shape", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (error_artifact_incident_id) REFERENCES guide_source_artifact_incidents(id)", - "kind": "f", - "name": "fk_project_setup_runs_artifact_incident", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorized_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_actor", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorized_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_admin_grant", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_decision", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (authorized_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_project_setup_runs_authorized_identity_link", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (continuation_verification_job_id) REFERENCES artifact_verification_jobs(id)", - "kind": "f", - "name": "fk_project_setup_runs_continuation_verification_job", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_project_setup_runs_guide_id_project_guides", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (output_post_submit_checker_policy_id) REFERENCES checker_policies(id)", - "kind": "f", - "name": "fk_project_setup_runs_post_submit_checker_policy", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_project_setup_runs_project_guide", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_project_setup_runs_project_id_projects", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_project_setup_runs_source_snapshot_hash", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_project_setup_runs_source_snapshot_id_guide_source_snapshots", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (output_submission_artifact_policy_id) REFERENCES submission_artifact_policies(id)", - "kind": "f", - "name": "fk_project_setup_runs_submission_artifact_policy", - "table_name": "project_setup_runs" - }, - { - "definition": "FOREIGN KEY (output_sufficiency_report_id) REFERENCES guide_sufficiency_reports(id)", - "kind": "f", - "name": "fk_project_setup_runs_sufficiency_report", - "table_name": "project_setup_runs" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_project_setup_runs", - "table_name": "project_setup_runs" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "source_setup_run_custody", - "table_name": "project_setup_runs" - }, - { - "definition": "UNIQUE (id, project_id, guide_id, source_snapshot_id, setup_generation)", - "kind": "u", - "name": "uq_project_setup_runs_exact_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "UNIQUE (guide_id, setup_generation)", - "kind": "u", - "name": "uq_project_setup_runs_guide_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type::text = 'system'::text AND creation_action_id::text = 'project.create'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_projects_creation_authority_shape", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_projects_creation_actor", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_projects_creation_admin_grant", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_projects_creation_decision", - "table_name": "projects" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_projects_creation_identity_link", - "table_name": "projects" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_projects", - "table_name": "projects" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "project_creation_custody", - "table_name": "projects" - }, - { - "definition": "UNIQUE (slug)", - "kind": "u", - "name": "uq_projects_slug", - "table_name": "projects" - }, - { - "definition": "CHECK (submission_version > 0)", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_2b6d", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (status::text = 'pending'::text AND review_queue_entry_id IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND review_queue_entry_id IS NOT NULL AND committed_at IS NOT NULL)", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_4cd5", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_88bf", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['pending', 'committed']))", - "kind": "c", - "name": "ck_review_admission_idempotency_records_ck_review_admis_b8b8", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_review_admission_checker", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", - "kind": "f", - "name": "fk_review_admission_committed_queue", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_admission_project", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (review_queue_entry_id) REFERENCES review_queue_entries(id)", - "kind": "f", - "name": "fk_review_admission_queue", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_review_admission_submission", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_review_admission_submission_lineage", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_review_admission_task", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_admission_idempotency_records", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "UNIQUE (admitting_checker_run_id)", - "kind": "u", - "name": "uq_review_admission_checker_run", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_review_admission_operation", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "UNIQUE (idempotency_key)", - "kind": "u", - "name": "uq_review_admission_replay_key", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CHECK (attempt_generation > 0)", - "kind": "c", - "name": "ck_review_leases_attempt_generation_positive", - "table_name": "review_leases" - }, - { - "definition": "CHECK (closed_at IS NULL OR closed_at >= claimed_at)", - "kind": "c", - "name": "ck_review_leases_closure_after_claim", - "table_name": "review_leases" - }, - { - "definition": "CHECK (expires_at > claimed_at)", - "kind": "c", - "name": "ck_review_leases_expiry_after_claim", - "table_name": "review_leases" - }, - { - "definition": "CHECK (status::text = 'active'::text AND closed_at IS NULL AND close_reason IS NULL OR status::text = 'consumed'::text AND closed_at IS NOT NULL AND close_reason::text = 'review_recorded'::text OR status::text = 'released'::text AND closed_at IS NOT NULL AND close_reason::text = 'manual_release'::text OR status::text = 'expired'::text AND closed_at IS NOT NULL AND close_reason::text = 'lease_expired'::text OR status::text = 'revoked'::text AND closed_at IS NOT NULL AND (close_reason::text = ANY (ARRAY['grant_revoked', 'admin_override'])))", - "kind": "c", - "name": "ck_review_leases_lifecycle_shape", - "table_name": "review_leases" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['active', 'consumed', 'released', 'expired', 'revoked']))", - "kind": "c", - "name": "ck_review_leases_status", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (reviewer_contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)", - "kind": "f", - "name": "fk_review_lease_policy_version", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_lease_project", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version)", - "kind": "f", - "name": "fk_review_lease_queue_lineage", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (reviewer_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_review_lease_reviewer", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_review_lease_submission", - "table_name": "review_leases" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_review_lease_task", - "table_name": "review_leases" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_leases", - "table_name": "review_leases" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "review_leases_active_lease_guard", - "table_name": "review_leases" - }, - { - "definition": "UNIQUE (review_queue_entry_id, attempt_generation)", - "kind": "u", - "name": "uq_review_lease_attempt", - "table_name": "review_leases" - }, - { - "definition": "UNIQUE (review_queue_entry_id, id)", - "kind": "u", - "name": "uq_review_lease_queue_identity", - "table_name": "review_leases" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.review_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_review_policies_review_policy_authority_shape", - "table_name": "review_policies" - }, - { - "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", - "kind": "c", - "name": "ck_review_policies_review_policy_identity_shape", - "table_name": "review_policies" - }, - { - "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", - "kind": "c", - "name": "ck_review_policies_review_policy_predecessor_shape", - "table_name": "review_policies" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR review_preference_window_seconds > 0 AND review_lease_duration_seconds > 0 AND max_active_review_leases_per_reviewer = 1 AND self_review_allowed = false AND reject_policy::text = 'close_task'::text AND (finding_evidence_requirement::text = ANY (ARRAY['optional', 'required_for_blocking', 'required_for_all'])))", - "kind": "c", - "name": "ck_review_policies_review_policy_semantics_shape", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_review_policies_actor_profile", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_review_policies_admin_grant", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_review_policies_decision_event", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_review_policies_identity_link", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_review_policies_project_guide", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_policies_project_id_projects", - "table_name": "review_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES review_policies(id)", - "kind": "f", - "name": "fk_review_policies_supersedes", - "table_name": "review_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_policies", - "table_name": "review_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "review_policy_mutation_custody", - "table_name": "review_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, policy_generation)", - "kind": "u", - "name": "uq_review_policies_project_version_generation", - "table_name": "review_policies" - }, - { - "definition": "UNIQUE (id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_review_policy_lineage", - "table_name": "review_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_review_policy_scoped_lineage", - "table_name": "review_policies" - }, - { - "definition": "CHECK (available_since >= first_queued_at)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_availab_d484", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_generation > 0 AND lifecycle_generation > 0)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_generat_38b7", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (queue_state::text = 'pending'::text AND active_lease_id IS NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'leased'::text AND active_lease_id IS NOT NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'closed'::text AND active_lease_id IS NULL AND closed_at IS NOT NULL AND (closed_reason::text = ANY (ARRAY['review_recorded', 'task_closed', 'admin_cancelled'])) AND closed_at >= first_queued_at)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_lifecycle_shape", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (queue_state::text = ANY (ARRAY['pending', 'leased', 'closed']))", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_queue_state", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_mode::text = ANY (ARRAY['open', 'preferred']))", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_routing_mode", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_reason::text = ANY (ARRAY['first_submission', 'revision_return', 'admin_assignment']))", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_routing_reason", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (routing_mode::text = 'open'::text AND preferred_reviewer_id IS NULL AND preference_expires_at IS NULL OR routing_mode::text = 'preferred'::text AND preferred_reviewer_id IS NOT NULL AND preference_expires_at IS NOT NULL AND preference_expires_at > first_queued_at)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_routing_shape", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (submission_version > 0)", - "kind": "c", - "name": "ck_review_queue_entries_ck_review_queue_entries_submiss_2f6b", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (active_lease_id, id) REFERENCES review_leases(id, review_queue_entry_id) DEFERRABLE INITIALLY DEFERRED", - "kind": "f", - "name": "fk_review_queue_active_lease", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)", - "kind": "f", - "name": "fk_review_queue_checker", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (preferred_reviewer_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_review_queue_preferred_reviewer", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_review_queue_project", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_review_queue_submission", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)", - "kind": "f", - "name": "fk_review_queue_submission_lineage", - "table_name": "review_queue_entries" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_review_queue_task", - "table_name": "review_queue_entries" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_review_queue_entries", - "table_name": "review_queue_entries" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "review_queue_entries_active_lease_guard", - "table_name": "review_queue_entries" - }, - { - "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", - "kind": "u", - "name": "uq_review_queue_admission_identity", - "table_name": "review_queue_entries" - }, - { - "definition": "UNIQUE (id, project_id, task_id, submission_id, submission_version)", - "kind": "u", - "name": "uq_review_queue_lease_lineage", - "table_name": "review_queue_entries" - }, - { - "definition": "UNIQUE (submission_id)", - "kind": "u", - "name": "uq_review_queue_submission", - "table_name": "review_queue_entries" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.revision_policy.update'::text AND authorization_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_revision_policies_revision_policy_authority_shape", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))", - "kind": "c", - "name": "ck_revision_policies_revision_policy_identity_shape", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)", - "kind": "c", - "name": "ck_revision_policies_revision_policy_predecessor_shape", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (semantics_status::text = 'legacy_incomplete'::text OR max_revision_rounds > 0 AND revision_deadline_hours > 0)", - "kind": "c", - "name": "ck_revision_policies_revision_policy_semantics_shape", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_revision_policies_actor_profile", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_revision_policies_admin_grant", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_revision_policies_decision_event", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_revision_policies_identity_link", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_revision_policies_project_guide", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_revision_policies_project_id_projects", - "table_name": "revision_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES revision_policies(id)", - "kind": "f", - "name": "fk_revision_policies_supersedes", - "table_name": "revision_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_revision_policies", - "table_name": "revision_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "revision_policy_mutation_custody", - "table_name": "revision_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, policy_generation)", - "kind": "u", - "name": "uq_revision_policies_project_version_generation", - "table_name": "revision_policies" - }, - { - "definition": "UNIQUE (id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_revision_policy_lineage", - "table_name": "revision_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "u", - "name": "uq_revision_policy_scoped_lineage", - "table_name": "revision_policies" - }, - { - "definition": "CHECK (lifecycle_status::text = ANY (ARRAY['draft', 'approved', 'superseded']))", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_artifact__20ca", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_artifact__52ca", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (approved_by_actor_profile_id IS NULL AND approved_via_identity_link_id IS NULL AND approved_by_admin_role_grant_id IS NULL AND approval_scope_type IS NULL AND approval_scope_project_id IS NULL AND approval_action_id IS NULL AND approval_decision_event_id IS NULL OR approved_by_actor_profile_id IS NOT NULL AND approved_via_identity_link_id IS NOT NULL AND approved_by_admin_role_grant_id IS NOT NULL AND approval_scope_type IS NOT NULL AND approval_action_id IS NOT NULL AND (approval_scope_type::text = ANY (ARRAY['system', 'project'])) AND approval_scope_project_id IS NOT NULL AND approval_scope_project_id::text = project_id::text AND approval_action_id::text = 'project.submission_artifact_policy.approve'::text AND approval_decision_event_id IS NOT NULL)", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_policy_ap_0e4d", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_decision_event_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update'])) AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NOT NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.submission_artifact_policy.derive'::text))", - "kind": "c", - "name": "ck_submission_artifact_policies_ck_submission_policy_cr_0629", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (supersedes_policy_id) REFERENCES submission_artifact_policies(id)", - "kind": "f", - "name": "fk_sap_supersedes_policy", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_submission_artifact_policies_guide_id_project_guides", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_submission_artifact_policies_project_guide", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_artifact_policies_project_id_projects", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_submission_artifact_policies_source_snapshot_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approved_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submission_policy_approval_actor", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approval_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_submission_policy_approval_decision", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approved_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_submission_policy_approval_grant", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approved_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_submission_policy_approval_link", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (approval_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_policy_approval_project", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submission_policy_creation_actor", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)", - "kind": "f", - "name": "fk_submission_policy_creation_decision", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)", - "kind": "f", - "name": "fk_submission_policy_creation_grant", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_submission_policy_creation_link", - "table_name": "submission_artifact_policies" - }, - { - "definition": "FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_policy_creation_project", - "table_name": "submission_artifact_policies" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_artifact_policies", - "table_name": "submission_artifact_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "submission_policy_creation_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "submission_policy_product_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "UNIQUE (id, policy_hash)", - "kind": "u", - "name": "uq_submission_artifact_policies_id_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "UNIQUE (project_id, guide_version, policy_version)", - "kind": "u", - "name": "uq_submission_artifact_policies_project_version_policy", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_bundle_admissions_archive_sha256", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (archive_byte_count >= 0)", - "kind": "c", - "name": "ck_submission_bundle_admissions_archive_size", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_bundle_admissions_manifest_sha256", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_bundle_admissions_policy_context_hash", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK ((predecessor_submission_id IS NULL) = (predecessor_submission_version IS NULL))", - "kind": "c", - "name": "ck_submission_bundle_admissions_predecessor_shape", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['ready', 'consumed', 'stale']))", - "kind": "c", - "name": "ck_submission_bundle_admissions_status", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (status::text = 'ready'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'consumed'::text AND consumed_at IS NOT NULL AND consumed_by_submission_id IS NOT NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'stale'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NOT NULL AND octet_length(stale_reason::text) >= 1 AND octet_length(stale_reason::text) <= 500)", - "kind": "c", - "name": "ck_submission_bundle_admissions_terminal_shape", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CHECK (((put_operation_receipt_id IS NOT NULL)::integer + (put_observation_receipt_id IS NOT NULL)::integer) = 1)", - "kind": "c", - "name": "ck_submission_bundle_admissions_write_receipt_shape", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_actor_profile_id_actor_profiles", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (artifact_content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_artifact_content_id_art_12c8", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_assignment_id_task_assignments", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (consumed_by_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_consumed_by_submission__2b23", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (durable_intent_id) REFERENCES submission_bundle_durable_intents(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_durable_intent_id_submi_102c", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_identity_link_id_actor__d29d", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_pre_submit_evidence_set_a752", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_predecessor_submission__242d", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_project_id_projects", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_put_attempt_id_artifact_bbc3", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (put_observation_receipt_id) REFERENCES artifact_put_observation_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_put_observation_receipt_5136", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (put_operation_receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_put_operation_receipt_i_9602", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_task_id_workstream_tasks", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (verification_receipt_id) REFERENCES artifact_verification_receipts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_verification_receipt_id_0ea1", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (verified_replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_admissions_verified_replica_id_art_3a4e", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_bundle_admissions", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "UNIQUE (pre_submit_evidence_set_id)", - "kind": "u", - "name": "uq_submission_bundle_admission_evidence", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "UNIQUE (durable_intent_id)", - "kind": "u", - "name": "uq_submission_bundle_admission_intent", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "UNIQUE (verification_receipt_id)", - "kind": "u", - "name": "uq_submission_bundle_admission_verification", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_durable_intents_pre_submit_evidenc_c406", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT", - "kind": "f", - "name": "fk_submission_bundle_durable_intents_put_attempt_id_art_b4e4", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_bundle_durable_intents", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "UNIQUE (pre_submit_evidence_set_id)", - "kind": "u", - "name": "uq_submission_bundle_intent_evidence", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "UNIQUE (put_attempt_id)", - "kind": "u", - "name": "uq_submission_bundle_intent_put_attempt", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0119", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update', 'project.submission_artifact_policy.approve']))", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_0dbe", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (setup_generation > 0)", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_2b53", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK ((status::text = ANY (ARRAY['reserved', 'pending'])) AND response_json IS NULL AND committed_at IS NULL AND committed_policy_id IS NULL AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND committed_policy_id IS NOT NULL AND (action_id::text = 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NOT NULL AND committed_pre_submit_policy_id IS NOT NULL OR action_id::text <> 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL))", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_58d4", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (status::text = ANY (ARRAY['reserved', 'pending', 'committed']))", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_a824", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (service_identity IS NULL AND idempotency_key IS NOT NULL AND setup_run_id IS NULL AND setup_task_id IS NULL AND correlation_id IS NULL OR service_identity IS NOT NULL AND service_identity::text = 'workstream.project.setup'::text AND idempotency_key IS NULL AND action_id::text = 'project.submission_artifact_policy.derive'::text AND setup_run_id IS NOT NULL AND setup_task_id IS NOT NULL AND correlation_id IS NOT NULL)", - "kind": "c", - "name": "ck_submission_policy_mutation_idempotency_records_ck_su_b357", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_actor_f5bb", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (committed_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_commi_4fa6", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (committed_policy_id) REFERENCES submission_artifact_policies(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_commi_571a", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (committed_pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_commi_baa9", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (guide_id) REFERENCES project_guides(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_guide_ed8d", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_ident_2567", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_proje_442a", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_setup_a102", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)", - "kind": "f", - "name": "fk_submission_policy_mutation_idempotency_records_sourc_536e", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submission_policy_mutation_idempotency_records", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "TRIGGER DEFERRABLE INITIALLY DEFERRED", - "kind": "t", - "name": "submission_policy_replay_custody", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "UNIQUE (operation_id)", - "kind": "u", - "name": "uq_submission_policy_operation_identity", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", - "kind": "c", - "name": "ck_submissions_post_submit_policy_lock_complete", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_submissions_contributor_id_actor_profiles", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_submissions_locked_effective_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", - "kind": "f", - "name": "fk_submissions_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", - "kind": "f", - "name": "fk_submissions_locked_pre_submit_checker_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_submissions_locked_source_snapshot_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (supersedes_submission_id) REFERENCES submissions(id)", - "kind": "f", - "name": "fk_submissions_supersedes_submission_id_submissions", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_submissions_task_id_workstream_tasks", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_effective_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)", - "kind": "f", - "name": "fk_submissions_task_locked_guide", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)", - "kind": "f", - "name": "fk_submissions_task_locked_payment_policy", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES workstream_tasks(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_pre_submit_checker_hash", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_review_policy", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_revision_policy", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (task_id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "kind": "f", - "name": "fk_submissions_task_locked_source_snapshot_hash", - "table_name": "submissions" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_submissions", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "u", - "name": "uq_submissions_id_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (id, task_id, version)", - "kind": "u", - "name": "uq_submissions_id_task_version", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (id, version)", - "kind": "u", - "name": "uq_submissions_id_version", - "table_name": "submissions" - }, - { - "definition": "UNIQUE (task_id, version)", - "kind": "u", - "name": "uq_submissions_task_version", - "table_name": "submissions" - }, - { - "definition": "FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)", - "kind": "f", - "name": "fk_task_assignments_contributor_id_actor_profiles", - "table_name": "task_assignments" - }, - { - "definition": "FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)", - "kind": "f", - "name": "fk_task_assignments_task_id_workstream_tasks", - "table_name": "task_assignments" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_task_assignments", - "table_name": "task_assignments" - }, - { - "definition": "UNIQUE (id, task_id, contributor_id)", - "kind": "u", - "name": "uq_task_assignments_id_task_contributor", - "table_name": "task_assignments" - }, - { - "definition": "CHECK (status::text = 'draft'::text OR locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)", - "kind": "c", - "name": "ck_workstream_tasks_post_submit_policy_lock_complete", - "table_name": "workstream_tasks" - }, - { - "definition": "CHECK (status::text = 'draft'::text OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", - "kind": "c", - "name": "ck_workstream_tasks_review_revision_policy_lock_required", - "table_name": "workstream_tasks" - }, - { - "definition": "CHECK (locked_review_policy_id IS NULL AND locked_review_policy_generation IS NULL AND locked_review_policy_hash IS NULL AND locked_revision_policy_id IS NULL AND locked_revision_policy_generation IS NULL AND locked_revision_policy_hash IS NULL OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)", - "kind": "c", - "name": "ck_workstream_tasks_review_revision_policy_lock_shape", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_guide_version) REFERENCES project_guides(project_id, version)", - "kind": "f", - "name": "fk_workstream_tasks_locked_guide", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_payment_policy_version) REFERENCES payment_policies(project_id, guide_version)", - "kind": "f", - "name": "fk_workstream_tasks_locked_payment_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_review_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id, locked_guide_version, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_revision_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)", - "kind": "f", - "name": "fk_workstream_tasks_locked_source_snapshot_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "FOREIGN KEY (project_id) REFERENCES projects(id)", - "kind": "f", - "name": "fk_workstream_tasks_project_id_projects", - "table_name": "workstream_tasks" - }, - { - "definition": "PRIMARY KEY (id)", - "kind": "p", - "name": "pk_workstream_tasks", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_guide_version)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_guide", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_payment_policy_version)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_payment_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_review_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_revision_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "kind": "u", - "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "UNIQUE (id, project_id)", - "kind": "u", - "name": "uq_workstream_tasks_id_project", - "table_name": "workstream_tasks" - } - ], - "format": "workstream-v01-schema-manifest-1", - "indexes": [ - { - "definition": "CREATE INDEX ix_actor_identity_links_issuer_subject_status ON public.actor_identity_links USING btree (issuer, subject, status)", - "name": "ix_actor_identity_links_issuer_subject_status", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX pk_actor_identity_links ON public.actor_identity_links USING btree (id)", - "name": "pk_actor_identity_links", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_actor_profile ON public.actor_identity_links USING btree (actor_profile_id)", - "name": "uq_actor_identity_links_actor_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_external_identity ON public.actor_identity_links USING btree (issuer, subject)", - "name": "uq_actor_identity_links_external_identity", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX uq_actor_identity_links_id_profile ON public.actor_identity_links USING btree (id, actor_profile_id)", - "name": "uq_actor_identity_links_id_profile", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE UNIQUE INDEX pk_actor_profile_migration_state ON public.actor_profile_migration_state USING btree (id)", - "name": "pk_actor_profile_migration_state", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CREATE INDEX ix_actor_profiles_last_seen_at ON public.actor_profiles USING btree (last_seen_at)", - "name": "ix_actor_profiles_last_seen_at", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE INDEX ix_actor_profiles_status_actor_kind ON public.actor_profiles USING btree (status, actor_kind)", - "name": "ix_actor_profiles_status_actor_kind", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE UNIQUE INDEX pk_actor_profiles ON public.actor_profiles USING btree (id)", - "name": "pk_actor_profiles", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE UNIQUE INDEX service_identity ON public.actor_profiles USING btree (service_identity)", - "name": "service_identity", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE INDEX ix_admin_role_grants_effective_candidate ON public.admin_role_grants USING btree (target_actor_profile_id, status, scope_type, scope_project_id)", - "name": "ix_admin_role_grants_effective_candidate", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE INDEX ix_admin_role_grants_final_access_admin ON public.admin_role_grants USING btree (role, status) WHERE (((role)::text = 'access_administrator'::text) AND ((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", - "name": "ix_admin_role_grants_final_access_admin", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE INDEX ix_admin_role_grants_history ON public.admin_role_grants USING btree (target_actor_profile_id, granted_at, id)", - "name": "ix_admin_role_grants_history", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX pk_admin_role_grants ON public.admin_role_grants USING btree (id)", - "name": "pk_admin_role_grants", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_project ON public.admin_role_grants USING btree (target_actor_profile_id, role, scope_project_id) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'project'::text))", - "name": "uq_admin_role_grants_active_project", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX uq_admin_role_grants_active_system ON public.admin_role_grants USING btree (target_actor_profile_id, role) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))", - "name": "uq_admin_role_grants_active_system", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE INDEX ix_api_rate_control_counters_window_expires_at ON public.api_rate_control_counters USING btree (window_expires_at)", - "name": "ix_api_rate_control_counters_window_expires_at", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CREATE UNIQUE INDEX pk_api_rate_control_counters ON public.api_rate_control_counters USING btree (control_scope, key_digest)", - "name": "pk_api_rate_control_counters", - "table_name": "api_rate_control_counters" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_admission_charges ON public.artifact_admission_charges USING btree (id)", - "name": "pk_artifact_admission_charges", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_admission_charge_scope_content ON public.artifact_admission_charges USING btree (scope_type, scope_id, sha256, byte_count)", - "name": "uq_artifact_admission_charge_scope_content", - "table_name": "artifact_admission_charges" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_admission_scopes ON public.artifact_admission_scopes USING btree (scope_type, scope_id)", - "name": "pk_artifact_admission_scopes", - "table_name": "artifact_admission_scopes" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_content_id ON public.artifact_bindings USING btree (content_id)", - "name": "ix_artifact_bindings_content_id", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_project_id ON public.artifact_bindings USING btree (project_id)", - "name": "ix_artifact_bindings_project_id", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_scope ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version DESC)", - "name": "ix_artifact_bindings_scope", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_bindings_supersedes_binding_id ON public.artifact_bindings USING btree (supersedes_binding_id)", - "name": "ix_artifact_bindings_supersedes_binding_id", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_bindings ON public.artifact_bindings USING btree (id)", - "name": "pk_artifact_bindings", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_binding_scope_version ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version)", - "name": "uq_artifact_binding_scope_version", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_binding_supersedes ON public.artifact_bindings USING btree (supersedes_binding_id)", - "name": "uq_artifact_binding_supersedes", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_artifact_contents_sha256 ON public.artifact_contents USING btree (sha256)", - "name": "ix_artifact_contents_sha256", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_contents ON public.artifact_contents USING btree (id)", - "name": "pk_artifact_contents", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_content_digest_size ON public.artifact_contents USING btree (sha256, byte_count)", - "name": "uq_artifact_content_digest_size", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE INDEX ix_artifact_operation_receipts_put_attempt_id ON public.artifact_operation_receipts USING btree (put_attempt_id)", - "name": "ix_artifact_operation_receipts_put_attempt_id", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE INDEX ix_artifact_operation_receipts_replica_id ON public.artifact_operation_receipts USING btree (replica_id)", - "name": "ix_artifact_operation_receipts_replica_id", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_operation_receipts ON public.artifact_operation_receipts USING btree (id)", - "name": "pk_artifact_operation_receipts", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_receipt_put_attempt ON public.artifact_operation_receipts USING btree (put_attempt_id)", - "name": "uq_artifact_receipt_put_attempt", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempt_charges ON public.artifact_put_attempt_charges USING btree (attempt_id, charge_id)", - "name": "pk_artifact_put_attempt_charges", - "table_name": "artifact_put_attempt_charges" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_checker_run_id ON public.artifact_put_attempts USING btree (checker_run_id)", - "name": "ix_artifact_put_attempts_checker_run_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_guide_source_item_id ON public.artifact_put_attempts USING btree (guide_source_item_id)", - "name": "ix_artifact_put_attempts_guide_source_item_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_next_run_at ON public.artifact_put_attempts USING btree (next_run_at)", - "name": "ix_artifact_put_attempts_next_run_at", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_project_id ON public.artifact_put_attempts USING btree (project_id)", - "name": "ix_artifact_put_attempts_project_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_receipt_id ON public.artifact_put_attempts USING btree (receipt_id)", - "name": "ix_artifact_put_attempts_receipt_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_replica_id ON public.artifact_put_attempts USING btree (replica_id)", - "name": "ix_artifact_put_attempts_replica_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_status ON public.artifact_put_attempts USING btree (status)", - "name": "ix_artifact_put_attempts_status", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_attempts_task_id ON public.artifact_put_attempts USING btree (task_id)", - "name": "ix_artifact_put_attempts_task_id", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_put_attempts ON public.artifact_put_attempts USING btree (id)", - "name": "pk_artifact_put_attempts", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_put_attempt_operation ON public.artifact_put_attempts USING btree (operation_identity)", - "name": "uq_artifact_put_attempt_operation", - "table_name": "artifact_put_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_put_observation_receipts_put_attempt_id ON public.artifact_put_observation_receipts USING btree (put_attempt_id)", - "name": "ix_artifact_put_observation_receipts_put_attempt_id", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_put_observation_receipts ON public.artifact_put_observation_receipts USING btree (id)", - "name": "pk_artifact_put_observation_receipts", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_put_observation_fence ON public.artifact_put_observation_receipts USING btree (put_attempt_id, execution_generation)", - "name": "uq_artifact_put_observation_fence", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_parent_recovery_attempt_id ON public.artifact_recovery_attempts USING btree (parent_recovery_attempt_id)", - "name": "ix_artifact_recovery_attempts_parent_recovery_attempt_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_project_id ON public.artifact_recovery_attempts USING btree (project_id)", - "name": "ix_artifact_recovery_attempts_project_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_requester_actor_profile_id ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id)", - "name": "ix_artifact_recovery_attempts_requester_actor_profile_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_submission_id ON public.artifact_recovery_attempts USING btree (submission_id)", - "name": "ix_artifact_recovery_attempts_submission_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_recovery_attempts_task_id ON public.artifact_recovery_attempts USING btree (task_id)", - "name": "ix_artifact_recovery_attempts_task_id", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_recovery_attempts ON public.artifact_recovery_attempts USING btree (id)", - "name": "pk_artifact_recovery_attempts", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_idempotency ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)", - "name": "uq_artifact_recovery_idempotency", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_retry_job ON public.artifact_recovery_attempts USING btree (retry_verification_job_id)", - "name": "uq_artifact_recovery_retry_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_recovery_source_job ON public.artifact_recovery_attempts USING btree (source_verification_job_id)", - "name": "uq_artifact_recovery_source_job", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE INDEX ix_artifact_replicas_content_id ON public.artifact_replicas USING btree (content_id)", - "name": "ix_artifact_replicas_content_id", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE INDEX ix_artifact_replicas_storage_namespace_id ON public.artifact_replicas USING btree (storage_namespace_id)", - "name": "ix_artifact_replicas_storage_namespace_id", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_replicas ON public.artifact_replicas USING btree (id)", - "name": "pk_artifact_replicas", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_replica_provider_object ON public.artifact_replicas USING btree (storage_namespace_id, provider_object_ref)", - "name": "uq_artifact_replica_provider_object", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_replicas_id_content ON public.artifact_replicas USING btree (id, content_id)", - "name": "uq_artifact_replicas_id_content", - "table_name": "artifact_replicas" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_storage_namespaces ON public.artifact_storage_namespaces USING btree (id)", - "name": "pk_artifact_storage_namespaces", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_fingerprint ON public.artifact_storage_namespaces USING btree (namespace_fingerprint)", - "name": "uq_artifact_storage_namespace_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_storage_namespace_id_fingerprint ON public.artifact_storage_namespaces USING btree (id, namespace_fingerprint)", - "name": "uq_artifact_storage_namespace_id_fingerprint", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_next_run_at ON public.artifact_verification_jobs USING btree (next_run_at)", - "name": "ix_artifact_verification_jobs_next_run_at", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_originating_put_attempt_id ON public.artifact_verification_jobs USING btree (originating_put_attempt_id)", - "name": "ix_artifact_verification_jobs_originating_put_attempt_id", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_parent_verification_job_id ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", - "name": "ix_artifact_verification_jobs_parent_verification_job_id", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_replica_id ON public.artifact_verification_jobs USING btree (replica_id)", - "name": "ix_artifact_verification_jobs_replica_id", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_jobs_status ON public.artifact_verification_jobs USING btree (status)", - "name": "ix_artifact_verification_jobs_status", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_verification_jobs ON public.artifact_verification_jobs USING btree (id)", - "name": "pk_artifact_verification_jobs", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_verification_initial_origin ON public.artifact_verification_jobs USING btree (originating_put_attempt_id) WHERE (parent_verification_job_id IS NULL)", - "name": "uq_artifact_verification_initial_origin", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_verification_parent ON public.artifact_verification_jobs USING btree (parent_verification_job_id)", - "name": "uq_artifact_verification_parent", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE INDEX ix_artifact_verification_receipts_verification_job_id ON public.artifact_verification_receipts USING btree (verification_job_id)", - "name": "ix_artifact_verification_receipts_verification_job_id", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_artifact_verification_receipts ON public.artifact_verification_receipts USING btree (id)", - "name": "pk_artifact_verification_receipts", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_artifact_verification_fence ON public.artifact_verification_receipts USING btree (verification_job_id, execution_generation)", - "name": "uq_artifact_verification_fence", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE INDEX ix_audit_events_actor_id ON public.audit_events USING btree (actor_id)", - "name": "ix_audit_events_actor_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_actor_ref ON public.audit_events USING btree (actor_ref_kind, actor_id)", - "name": "ix_audit_events_actor_ref", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_correlation_id ON public.audit_events USING btree (correlation_id)", - "name": "ix_audit_events_correlation_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_entity_id ON public.audit_events USING btree (entity_id)", - "name": "ix_audit_events_entity_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_entity_type ON public.audit_events USING btree (entity_type)", - "name": "ix_audit_events_entity_type", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_event_type ON public.audit_events USING btree (event_type)", - "name": "ix_audit_events_event_type", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_occurred_at ON public.audit_events USING btree (occurred_at)", - "name": "ix_audit_events_occurred_at", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_project_id ON public.audit_events USING btree (project_id)", - "name": "ix_audit_events_project_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE INDEX ix_audit_events_request_id ON public.audit_events USING btree (request_id)", - "name": "ix_audit_events_request_id", - "table_name": "audit_events" - }, - { - "definition": "CREATE UNIQUE INDEX pk_audit_events ON public.audit_events USING btree (id)", - "name": "pk_audit_events", - "table_name": "audit_events" - }, - { - "definition": "CREATE UNIQUE INDEX pk_authority_control ON public.authority_control USING btree (id)", - "name": "pk_authority_control", - "table_name": "authority_control" - }, - { - "definition": "CREATE UNIQUE INDEX pk_authority_idempotency_records ON public.authority_idempotency_records USING btree (id)", - "name": "pk_authority_idempotency_records", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_actor_reference ON public.authority_idempotency_records USING btree (id, actor_ref_kind, actor_ref)", - "name": "uq_authority_idempotency_records_actor_reference", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_authority_idempotency_records_replay_namespace ON public.authority_idempotency_records USING btree (actor_ref_kind, actor_ref, operation, idempotency_key)", - "name": "uq_authority_idempotency_records_replay_namespace", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_checker_policies_effective_policy_hash ON public.checker_policies USING btree (effective_policy_hash)", - "name": "ix_checker_policies_effective_policy_hash", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_effective_policy_id ON public.checker_policies USING btree (effective_policy_id)", - "name": "ix_checker_policies_effective_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_guide_id ON public.checker_policies USING btree (guide_id)", - "name": "ix_checker_policies_guide_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_bundle_hash ON public.checker_policies USING btree (pre_submit_checker_bundle_hash)", - "name": "ix_checker_policies_pre_submit_checker_bundle_hash", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_pre_submit_checker_policy_id ON public.checker_policies USING btree (pre_submit_checker_policy_id)", - "name": "ix_checker_policies_pre_submit_checker_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_project_id ON public.checker_policies USING btree (project_id)", - "name": "ix_checker_policies_project_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_source_snapshot_id ON public.checker_policies USING btree (source_snapshot_id)", - "name": "ix_checker_policies_source_snapshot_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_policies_supersedes_policy_id ON public.checker_policies USING btree (supersedes_policy_id)", - "name": "ix_checker_policies_supersedes_policy_id", - "table_name": "checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_checker_policies ON public.checker_policies USING btree (id)", - "name": "pk_checker_policies", - "table_name": "checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_policies_current_project_version ON public.checker_policies USING btree (project_id, guide_version) WHERE ((lifecycle_status)::text = ANY (ARRAY['compiled', 'approved']))", - "name": "uq_checker_policies_current_project_version", - "table_name": "checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_policies_id_version_hash ON public.checker_policies USING btree (id, guide_version, policy_hash)", - "name": "uq_checker_policies_id_version_hash", - "table_name": "checker_policies" - }, - { - "definition": "CREATE INDEX ix_checker_results_checker_name ON public.checker_results USING btree (checker_name)", - "name": "ix_checker_results_checker_name", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_checker_run_id ON public.checker_results USING btree (checker_run_id)", - "name": "ix_checker_results_checker_run_id", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_submission_id ON public.checker_results USING btree (submission_id)", - "name": "ix_checker_results_submission_id", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_task_id ON public.checker_results USING btree (task_id)", - "name": "ix_checker_results_task_id", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_results_worker_visible ON public.checker_results USING btree (worker_visible)", - "name": "ix_checker_results_worker_visible", - "table_name": "checker_results" - }, - { - "definition": "CREATE UNIQUE INDEX pk_checker_results ON public.checker_results USING btree (id)", - "name": "pk_checker_results", - "table_name": "checker_results" - }, - { - "definition": "CREATE INDEX ix_checker_runs_audit_event_id ON public.checker_runs USING btree (audit_event_id)", - "name": "ix_checker_runs_audit_event_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_locked_post_submit_policy_hash ON public.checker_runs USING btree (locked_post_submit_checker_policy_hash)", - "name": "ix_checker_runs_locked_post_submit_policy_hash", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_routing_recommendation ON public.checker_runs USING btree (routing_recommendation)", - "name": "ix_checker_runs_routing_recommendation", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_status ON public.checker_runs USING btree (status)", - "name": "ix_checker_runs_status", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_submission_id ON public.checker_runs USING btree (submission_id)", - "name": "ix_checker_runs_submission_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_supersedes_checker_run_id ON public.checker_runs USING btree (supersedes_checker_run_id)", - "name": "ix_checker_runs_supersedes_checker_run_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE INDEX ix_checker_runs_task_id ON public.checker_runs USING btree (task_id)", - "name": "ix_checker_runs_task_id", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_checker_runs ON public.checker_runs USING btree (id)", - "name": "pk_checker_runs", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_runs_current_per_submission ON public.checker_runs USING btree (submission_id) WHERE (is_current_for_submission = true)", - "name": "uq_checker_runs_current_per_submission", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_checker_runs_submission_attempt ON public.checker_runs USING btree (submission_id, attempt_number)", - "name": "uq_checker_runs_submission_attempt", - "table_name": "checker_runs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_award_definitions ON public.contribution_award_definitions USING btree (id)", - "name": "pk_contribution_award_definitions", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_award_definition_instrument ON public.contribution_award_definitions USING btree (contribution_rule_id, instrument_type)", - "name": "uq_contribution_award_definition_instrument", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_policies ON public.contribution_policies USING btree (id)", - "name": "pk_contribution_policies", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_active_project ON public.contribution_policies USING btree (project_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_contribution_policy_active_project", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_ownership ON public.contribution_policies USING btree (id, project_id)", - "name": "uq_contribution_policy_ownership", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_policy_versions ON public.contribution_policy_versions USING btree (id)", - "name": "pk_contribution_policy_versions", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_number ON public.contribution_policy_versions USING btree (contribution_policy_id, version_number)", - "name": "uq_contribution_policy_version_number", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_ownership ON public.contribution_policy_versions USING btree (id, contribution_policy_id, project_id)", - "name": "uq_contribution_policy_version_ownership", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_policy_version_project ON public.contribution_policy_versions USING btree (id, project_id)", - "name": "uq_contribution_policy_version_project", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_contribution_rules ON public.contribution_rules USING btree (id)", - "name": "pk_contribution_rules", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_rule_ownership ON public.contribution_rules USING btree (id, contribution_policy_version_id, project_id, contribution_type)", - "name": "uq_contribution_rule_ownership", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE UNIQUE INDEX uq_contribution_rule_type ON public.contribution_rules USING btree (contribution_policy_version_id, contribution_type)", - "name": "uq_contribution_rule_type", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE INDEX ix_effective_psap_effective_hash ON public.effective_project_submission_artifact_policies USING btree (effective_policy_hash)", - "name": "ix_effective_psap_effective_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_guide ON public.effective_project_submission_artifact_policies USING btree (guide_id)", - "name": "ix_effective_psap_guide", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_lifecycle ON public.effective_project_submission_artifact_policies USING btree (lifecycle_status)", - "name": "ix_effective_psap_lifecycle", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_project ON public.effective_project_submission_artifact_policies USING btree (project_id)", - "name": "ix_effective_psap_project", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_source_snapshot ON public.effective_project_submission_artifact_policies USING btree (source_snapshot_id)", - "name": "ix_effective_psap_source_snapshot", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_effective_psap_submission_policy ON public.effective_project_submission_artifact_policies USING btree (submission_artifact_policy_id)", - "name": "ix_effective_psap_submission_policy", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_effective_project_submission_artifact_policies ON public.effective_project_submission_artifact_policies USING btree (id)", - "name": "pk_effective_project_submission_artifact_policies", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_effective_project_submission_artifact_policies_id_hash ON public.effective_project_submission_artifact_policies USING btree (id, effective_policy_hash)", - "name": "uq_effective_project_submission_artifact_policies_id_hash", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_evidence_items_submission_id ON public.evidence_items USING btree (submission_id)", - "name": "ix_evidence_items_submission_id", - "table_name": "evidence_items" - }, - { - "definition": "CREATE INDEX ix_evidence_items_type ON public.evidence_items USING btree (type)", - "name": "ix_evidence_items_type", - "table_name": "evidence_items" - }, - { - "definition": "CREATE UNIQUE INDEX pk_evidence_items ON public.evidence_items USING btree (id)", - "name": "pk_evidence_items", - "table_name": "evidence_items" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_mutation_idempotency_records ON public.guide_mutation_idempotency_records USING btree (id)", - "name": "pk_guide_mutation_idempotency_records", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_mutation_operation_identity ON public.guide_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_guide_mutation_operation_identity", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_mutation_replay_namespace ON public.guide_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", - "name": "uq_guide_mutation_replay_namespace", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_content_id ON public.guide_source_artifact_bindings USING btree (content_id)", - "name": "ix_guide_source_artifact_bindings_content_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_guide_id ON public.guide_source_artifact_bindings USING btree (guide_id)", - "name": "ix_guide_source_artifact_bindings_guide_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_id ON public.guide_source_artifact_bindings USING btree (project_id)", - "name": "ix_guide_source_artifact_bindings_project_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_project_setup_run_id ON public.guide_source_artifact_bindings USING btree (project_setup_run_id)", - "name": "ix_guide_source_artifact_bindings_project_setup_run_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_item_id ON public.guide_source_artifact_bindings USING btree (source_item_id)", - "name": "ix_guide_source_artifact_bindings_source_item_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_source_snapshot_id ON public.guide_source_artifact_bindings USING btree (source_snapshot_id)", - "name": "ix_guide_source_artifact_bindings_source_snapshot_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_supersedes_binding_id ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", - "name": "ix_guide_source_artifact_bindings_supersedes_binding_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_bindings_verified_replica_id ON public.guide_source_artifact_bindings USING btree (verified_replica_id)", - "name": "ix_guide_source_artifact_bindings_verified_replica_id", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_bindings ON public.guide_source_artifact_bindings USING btree (id)", - "name": "pk_guide_source_artifact_bindings", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_exact_read ON public.guide_source_artifact_bindings USING btree (id, content_id, verified_replica_id, setup_generation)", - "name": "uq_guide_bindings_exact_read", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_attempt_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, setup_generation)", - "name": "uq_guide_bindings_extraction_attempt_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_extraction_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, source_item_id, project_setup_run_id, setup_generation)", - "name": "uq_guide_bindings_extraction_lineage", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_item_generation ON public.guide_source_artifact_bindings USING btree (source_item_id, setup_generation)", - "name": "uq_guide_bindings_item_generation", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_bindings_supersedes ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)", - "name": "uq_guide_bindings_supersedes", - "table_name": "guide_source_artifact_bindings" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_incidents_binding_id ON public.guide_source_artifact_incidents USING btree (binding_id)", - "name": "ix_guide_source_artifact_incidents_binding_id", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_incidents_content_id ON public.guide_source_artifact_incidents USING btree (content_id)", - "name": "ix_guide_source_artifact_incidents_content_id", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_incidents_verified_replica_id ON public.guide_source_artifact_incidents USING btree (verified_replica_id)", - "name": "ix_guide_source_artifact_incidents_verified_replica_id", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_incidents ON public.guide_source_artifact_incidents USING btree (id)", - "name": "pk_guide_source_artifact_incidents", - "table_name": "guide_source_artifact_incidents" - }, - { - "definition": "CREATE INDEX ix_guide_source_artifact_ingests_actor_profile_id ON public.guide_source_artifact_ingests USING btree (actor_profile_id)", - "name": "ix_guide_source_artifact_ingests_actor_profile_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE UNIQUE INDEX ix_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", - "name": "ix_guide_source_artifact_ingests_source_item_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_artifact_ingests ON public.guide_source_artifact_ingests USING btree (id)", - "name": "pk_guide_source_artifact_ingests", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)", - "name": "uq_guide_source_artifact_ingests_source_item_id", - "table_name": "guide_source_artifact_ingests" - }, - { - "definition": "CREATE INDEX ix_guide_source_extracted_contents_content_id ON public.guide_source_extracted_contents USING btree (content_id)", - "name": "ix_guide_source_extracted_contents_content_id", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extracted_contents ON public.guide_source_extracted_contents USING btree (id)", - "name": "pk_guide_source_extracted_contents", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_exact_usage ON public.guide_source_extracted_contents USING btree (id, content_id)", - "name": "uq_guide_extracted_contents_exact_usage", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extracted_contents_identity ON public.guide_source_extracted_contents USING btree (content_id, detected_format, extractor_name, extractor_version, policy_version)", - "name": "uq_guide_extracted_contents_identity", - "table_name": "guide_source_extracted_contents" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_attempts_binding_id ON public.guide_source_extraction_attempts USING btree (binding_id)", - "name": "ix_guide_source_extraction_attempts_binding_id", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_attempts_content_id ON public.guide_source_extraction_attempts USING btree (content_id)", - "name": "ix_guide_source_extraction_attempts_content_id", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_attempts ON public.guide_source_extraction_attempts USING btree (id)", - "name": "pk_guide_source_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts ON public.guide_source_extraction_attempts USING btree (binding_id, policy_version, attempt_number)", - "name": "uq_guide_extraction_attempts", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_attempts_exact_usage ON public.guide_source_extraction_attempts USING btree (id, binding_id, content_id, setup_generation, status)", - "name": "uq_guide_extraction_attempts_exact_usage", - "table_name": "guide_source_extraction_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_retry_budgets ON public.guide_source_extraction_retry_budgets USING btree (binding_id)", - "name": "pk_guide_source_extraction_retry_budgets", - "table_name": "guide_source_extraction_retry_budgets" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_binding_id ON public.guide_source_extraction_usages USING btree (binding_id)", - "name": "ix_guide_source_extraction_usages_binding_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_content_id ON public.guide_source_extraction_usages USING btree (content_id)", - "name": "ix_guide_source_extraction_usages_content_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_extracted_content_id ON public.guide_source_extraction_usages USING btree (extracted_content_id)", - "name": "ix_guide_source_extraction_usages_extracted_content_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_project_setup_run_id ON public.guide_source_extraction_usages USING btree (project_setup_run_id)", - "name": "ix_guide_source_extraction_usages_project_setup_run_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_extraction_usages_source_item_id ON public.guide_source_extraction_usages USING btree (source_item_id)", - "name": "ix_guide_source_extraction_usages_source_item_id", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_extraction_usages ON public.guide_source_extraction_usages USING btree (id)", - "name": "pk_guide_source_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages ON public.guide_source_extraction_usages USING btree (binding_id, extracted_content_id)", - "name": "uq_guide_extraction_usages", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_extraction_usages_exact_provenance ON public.guide_source_extraction_usages USING btree (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)", - "name": "uq_guide_extraction_usages_exact_provenance", - "table_name": "guide_source_extraction_usages" - }, - { - "definition": "CREATE INDEX ix_guide_source_format_classifications_binding_id ON public.guide_source_format_classifications USING btree (binding_id)", - "name": "ix_guide_source_format_classifications_binding_id", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE INDEX ix_guide_source_format_classifications_content_id ON public.guide_source_format_classifications USING btree (content_id)", - "name": "ix_guide_source_format_classifications_content_id", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE INDEX ix_guide_source_format_classifications_verified_replica_id ON public.guide_source_format_classifications USING btree (verified_replica_id)", - "name": "ix_guide_source_format_classifications_verified_replica_id", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_format_classifications ON public.guide_source_format_classifications USING btree (id)", - "name": "pk_guide_source_format_classifications", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_classifications_binding ON public.guide_source_format_classifications USING btree (binding_id)", - "name": "uq_guide_classifications_binding", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_classifications_extraction_lineage ON public.guide_source_format_classifications USING btree (id, binding_id, content_id, setup_generation)", - "name": "uq_guide_classifications_extraction_lineage", - "table_name": "guide_source_format_classifications" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshot_items_source_snapshot_id ON public.guide_source_snapshot_items USING btree (source_snapshot_id)", - "name": "ix_guide_source_snapshot_items_source_snapshot_id", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshot_items ON public.guide_source_snapshot_items USING btree (id)", - "name": "pk_guide_source_snapshot_items", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_exact_lineage ON public.guide_source_snapshot_items USING btree (id, source_snapshot_id)", - "name": "uq_guide_source_snapshot_items_exact_lineage", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshot_items_snapshot_order ON public.guide_source_snapshot_items USING btree (source_snapshot_id, item_order)", - "name": "uq_guide_source_snapshot_items_snapshot_order", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshots_bundle_hash ON public.guide_source_snapshots USING btree (bundle_hash)", - "name": "ix_guide_source_snapshots_bundle_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshots_guide_id ON public.guide_source_snapshots USING btree (guide_id)", - "name": "ix_guide_source_snapshots_guide_id", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE INDEX ix_guide_source_snapshots_project_id ON public.guide_source_snapshots USING btree (project_id)", - "name": "ix_guide_source_snapshots_project_id", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_source_snapshots ON public.guide_source_snapshots USING btree (id)", - "name": "pk_guide_source_snapshots", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_exact_lineage ON public.guide_source_snapshots USING btree (id, project_id, guide_id)", - "name": "uq_guide_source_snapshots_exact_lineage", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_id_hash ON public.guide_source_snapshots USING btree (id, bundle_hash)", - "name": "uq_guide_source_snapshots_id_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_source_snapshots_project_version_hash ON public.guide_source_snapshots USING btree (project_id, guide_version, bundle_hash)", - "name": "uq_guide_source_snapshots_project_version_hash", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_mutation_idempotency_records ON public.guide_sufficiency_mutation_idempotency_records USING btree (id)", - "name": "pk_guide_sufficiency_mutation_idempotency_records", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_operation_identity ON public.guide_sufficiency_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_sufficiency_mutation_operation_identity", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_mutation_replay_namespace ON public.guide_sufficiency_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key)", - "name": "uq_sufficiency_mutation_replay_namespace", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_sufficiency_report_source_usage_report_id ON public.guide_sufficiency_report_source_usages USING btree (report_id)", - "name": "ix_sufficiency_report_source_usage_report_id", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_report_source_usages ON public.guide_sufficiency_report_source_usages USING btree (id)", - "name": "pk_guide_sufficiency_report_source_usages", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_extraction_usage ON public.guide_sufficiency_report_source_usages USING btree (report_id, extraction_usage_id)", - "name": "uq_sufficiency_report_extraction_usage", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE UNIQUE INDEX uq_sufficiency_report_item_order ON public.guide_sufficiency_report_source_usages USING btree (report_id, item_order)", - "name": "uq_sufficiency_report_item_order", - "table_name": "guide_sufficiency_report_source_usages" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_guide_id ON public.guide_sufficiency_reports USING btree (guide_id)", - "name": "ix_guide_sufficiency_reports_guide_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_id ON public.guide_sufficiency_reports USING btree (project_id)", - "name": "ix_guide_sufficiency_reports_project_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_project_setup_run_id ON public.guide_sufficiency_reports USING btree (project_setup_run_id)", - "name": "ix_guide_sufficiency_reports_project_setup_run_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_source_snapshot_id ON public.guide_sufficiency_reports USING btree (source_snapshot_id)", - "name": "ix_guide_sufficiency_reports_source_snapshot_id", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE INDEX ix_guide_sufficiency_reports_status ON public.guide_sufficiency_reports USING btree (status)", - "name": "ix_guide_sufficiency_reports_status", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX pk_guide_sufficiency_reports ON public.guide_sufficiency_reports USING btree (id)", - "name": "pk_guide_sufficiency_reports", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_diagnostic_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NULL)", - "name": "uq_guide_sufficiency_reports_diagnostic_snapshot", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX uq_guide_sufficiency_reports_verified_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NOT NULL)", - "name": "uq_guide_sufficiency_reports_verified_snapshot", - "table_name": "guide_sufficiency_reports" - }, - { - "definition": "CREATE UNIQUE INDEX pk_iso_4217_currency_codes ON public.iso_4217_currency_codes USING btree (code)", - "name": "pk_iso_4217_currency_codes", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "CREATE UNIQUE INDEX pk_legacy_actor_identities ON public.legacy_actor_identities USING btree (actor_id)", - "name": "pk_legacy_actor_identities", - "table_name": "legacy_actor_identities" - }, - { - "definition": "CREATE UNIQUE INDEX uq_legacy_actor_identities_external_identity ON public.legacy_actor_identities USING btree (external_issuer, external_subject)", - "name": "uq_legacy_actor_identities_external_identity", - "table_name": "legacy_actor_identities" - }, - { - "definition": "CREATE INDEX ix_legacy_workflow_eligibility_actor_id ON public.legacy_workflow_eligibility USING btree (actor_id)", - "name": "ix_legacy_workflow_eligibility_actor_id", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE INDEX ix_legacy_workflow_eligibility_profile_type ON public.legacy_workflow_eligibility USING btree (profile_type)", - "name": "ix_legacy_workflow_eligibility_profile_type", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE INDEX ix_legacy_workflow_eligibility_status ON public.legacy_workflow_eligibility USING btree (status)", - "name": "ix_legacy_workflow_eligibility_status", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE UNIQUE INDEX pk_legacy_workflow_eligibility ON public.legacy_workflow_eligibility USING btree (id)", - "name": "pk_legacy_workflow_eligibility", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE UNIQUE INDEX uq_legacy_workflow_eligibility_actor_type_scope ON public.legacy_workflow_eligibility USING btree (actor_id, profile_type, scope_type, scope_id)", - "name": "uq_legacy_workflow_eligibility_actor_type_scope", - "table_name": "legacy_workflow_eligibility" - }, - { - "definition": "CREATE INDEX ix_outbox_events_aggregate ON public.outbox_events USING btree (aggregate_type, aggregate_id, occurred_at, event_id)", - "name": "ix_outbox_events_aggregate", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_eligible ON public.outbox_events USING btree (event_type, delivery_state, next_attempt_at, occurred_at, event_id) WHERE ((delivery_state)::text = ANY (ARRAY['pending', 'retryable']))", - "name": "ix_outbox_events_eligible", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_expired_claims ON public.outbox_events USING btree (claim_expires_at, event_id) WHERE ((delivery_state)::text = 'claimed'::text)", - "name": "ix_outbox_events_expired_claims", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_project_drain ON public.outbox_events USING btree (project_id, delivery_state, occurred_at, event_id)", - "name": "ix_outbox_events_project_drain", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_outbox_events_retention ON public.outbox_events USING btree (finalized_at, event_id) WHERE (((delivery_state)::text = ANY (ARRAY['acknowledged', 'dead_letter', 'cancelled'])) AND (archived_at IS NULL))", - "name": "ix_outbox_events_retention", - "table_name": "outbox_events" - }, - { - "definition": "CREATE UNIQUE INDEX pk_outbox_events ON public.outbox_events USING btree (event_id)", - "name": "pk_outbox_events", - "table_name": "outbox_events" - }, - { - "definition": "CREATE UNIQUE INDEX uq_outbox_events_idempotency_key ON public.outbox_events USING btree (idempotency_key)", - "name": "uq_outbox_events_idempotency_key", - "table_name": "outbox_events" - }, - { - "definition": "CREATE INDEX ix_payment_policies_project_id ON public.payment_policies USING btree (project_id)", - "name": "ix_payment_policies_project_id", - "table_name": "payment_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_payment_policies ON public.payment_policies USING btree (id)", - "name": "pk_payment_policies", - "table_name": "payment_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_payment_policies_project_version ON public.payment_policies USING btree (project_id, guide_version)", - "name": "uq_payment_policies_project_version", - "table_name": "payment_policies" - }, - { - "definition": "CREATE INDEX ix_policy_mutation_custody_lookup ON public.policy_mutation_idempotency_records USING btree (policy_id, action_id, policy_generation, status)", - "name": "ix_policy_mutation_custody_lookup", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX pk_policy_mutation_idempotency_records ON public.policy_mutation_idempotency_records USING btree (id)", - "name": "pk_policy_mutation_idempotency_records", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_policy_mutation_operation_identity ON public.policy_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_policy_mutation_operation_identity", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_policy_mutation_replay_namespace ON public.policy_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", - "name": "uq_policy_mutation_replay_namespace", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_compiled_hash ON public.pre_submit_checker_policies USING btree (compiled_bundle_hash)", - "name": "ix_pre_submit_checker_compiled_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_effective ON public.pre_submit_checker_policies USING btree (effective_policy_id)", - "name": "ix_pre_submit_checker_effective", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_effective_hash ON public.pre_submit_checker_policies USING btree (effective_policy_hash)", - "name": "ix_pre_submit_checker_effective_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_guide ON public.pre_submit_checker_policies USING btree (guide_id)", - "name": "ix_pre_submit_checker_guide", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_lifecycle ON public.pre_submit_checker_policies USING btree (lifecycle_status)", - "name": "ix_pre_submit_checker_lifecycle", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_project ON public.pre_submit_checker_policies USING btree (project_id)", - "name": "ix_pre_submit_checker_project", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_checker_source_snapshot ON public.pre_submit_checker_policies USING btree (source_snapshot_id)", - "name": "ix_pre_submit_checker_source_snapshot", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_pre_submit_checker_policies ON public.pre_submit_checker_policies USING btree (id)", - "name": "pk_pre_submit_checker_policies", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_checker_policies_id_compiled_bundle_hash ON public.pre_submit_checker_policies USING btree (id, compiled_bundle_hash)", - "name": "uq_pre_submit_checker_policies_id_compiled_bundle_hash", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_results_evidence_set_id ON public.pre_submit_evidence_results USING btree (evidence_set_id)", - "name": "ix_pre_submit_evidence_results_evidence_set_id", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_results ON public.pre_submit_evidence_results USING btree (id)", - "name": "pk_pre_submit_evidence_results", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_definition ON public.pre_submit_evidence_results USING btree (evidence_set_id, definition_id)", - "name": "uq_pre_submit_result_definition", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_result_order ON public.pre_submit_evidence_results USING btree (evidence_set_id, result_order)", - "name": "uq_pre_submit_result_order", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_sets_actor_profile_id ON public.pre_submit_evidence_sets USING btree (actor_profile_id)", - "name": "ix_pre_submit_evidence_sets_actor_profile_id", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_sets_project_id ON public.pre_submit_evidence_sets USING btree (project_id)", - "name": "ix_pre_submit_evidence_sets_project_id", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE INDEX ix_pre_submit_evidence_sets_task_id ON public.pre_submit_evidence_sets USING btree (task_id)", - "name": "ix_pre_submit_evidence_sets_task_id", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE UNIQUE INDEX pk_pre_submit_evidence_sets ON public.pre_submit_evidence_sets USING btree (id)", - "name": "pk_pre_submit_evidence_sets", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE UNIQUE INDEX uq_pre_submit_evidence_operation ON public.pre_submit_evidence_sets USING btree (operation_identity)", - "name": "uq_pre_submit_evidence_operation", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE INDEX ix_compensation_binding_adapter_actor ON public.project_compensation_adapter_bindings USING btree (adapter_actor_id, status, id)", - "name": "ix_compensation_binding_adapter_actor", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_compensation_adapter_bindings ON public.project_compensation_adapter_bindings USING btree (id)", - "name": "pk_project_compensation_adapter_bindings", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compensation_binding_active_project_instrument ON public.project_compensation_adapter_bindings USING btree (project_id, instrument_type) WHERE ((status)::text = 'active'::text)", - "name": "uq_compensation_binding_active_project_instrument", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compensation_binding_ownership ON public.project_compensation_adapter_bindings USING btree (id, project_id, instrument_type)", - "name": "uq_compensation_binding_ownership", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_compensation_units ON public.project_compensation_units USING btree (project_id, instrument_type, unit_code)", - "name": "pk_project_compensation_units", - "table_name": "project_compensation_units" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_create_idempotency_records ON public.project_create_idempotency_records USING btree (id)", - "name": "pk_project_create_idempotency_records", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_create_operation_identity ON public.project_create_idempotency_records USING btree (operation_id)", - "name": "uq_project_create_operation_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_create_project_identity ON public.project_create_idempotency_records USING btree (project_id)", - "name": "uq_project_create_project_identity", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_create_replay_namespace ON public.project_create_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)", - "name": "uq_project_create_replay_namespace", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_guide_id ON public.project_guide_compilation_attempts USING btree (guide_id)", - "name": "ix_project_guide_compilation_attempts_guide_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_project_id ON public.project_guide_compilation_attempts USING btree (project_id)", - "name": "ix_project_guide_compilation_attempts_project_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_setup_run_id ON public.project_guide_compilation_attempts USING btree (setup_run_id)", - "name": "ix_project_guide_compilation_attempts_setup_run_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilation_attempts_source_snapshot_id ON public.project_guide_compilation_attempts USING btree (source_snapshot_id)", - "name": "ix_project_guide_compilation_attempts_source_snapshot_id", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_guide_compilation_attempts ON public.project_guide_compilation_attempts USING btree (id)", - "name": "pk_project_guide_compilation_attempts", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_provider_key ON public.project_guide_compilation_attempts USING btree (provider_idempotency_key)", - "name": "uq_compilation_attempt_provider_key", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE UNIQUE INDEX uq_compilation_attempt_setup_generation ON public.project_guide_compilation_attempts USING btree (setup_run_id, setup_generation)", - "name": "uq_compilation_attempt_setup_generation", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_guide_id ON public.project_guide_compilations USING btree (guide_id)", - "name": "ix_project_guide_compilations_guide_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_project_id ON public.project_guide_compilations USING btree (project_id)", - "name": "ix_project_guide_compilations_project_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_setup_run_id ON public.project_guide_compilations USING btree (setup_run_id)", - "name": "ix_project_guide_compilations_setup_run_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guide_compilations_source_snapshot_id ON public.project_guide_compilations USING btree (source_snapshot_id)", - "name": "ix_project_guide_compilations_source_snapshot_id", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_guide_compilations ON public.project_guide_compilations USING btree (id)", - "name": "pk_project_guide_compilations", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_attempt ON public.project_guide_compilations USING btree (attempt_id)", - "name": "uq_project_guide_compilation_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_id_attempt ON public.project_guide_compilations USING btree (id, attempt_id)", - "name": "uq_project_guide_compilation_id_attempt", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_predecessor ON public.project_guide_compilations USING btree (supersedes_compilation_id)", - "name": "uq_project_guide_compilation_predecessor", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_root ON public.project_guide_compilations USING btree (project_id, guide_id) WHERE (supersedes_compilation_id IS NULL)", - "name": "uq_project_guide_compilation_root", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guide_compilation_scope ON public.project_guide_compilations USING btree (id, project_id, guide_id)", - "name": "uq_project_guide_compilation_scope", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE INDEX ix_project_guides_project_id ON public.project_guides USING btree (project_id)", - "name": "ix_project_guides_project_id", - "table_name": "project_guides" - }, - { - "definition": "CREATE INDEX ix_project_guides_status ON public.project_guides USING btree (status)", - "name": "ix_project_guides_status", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_guides ON public.project_guides USING btree (id)", - "name": "pk_project_guides", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guides_id_project_version ON public.project_guides USING btree (id, project_id, version)", - "name": "uq_project_guides_id_project_version", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guides_one_active_per_project ON public.project_guides USING btree (project_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_project_guides_one_active_per_project", - "table_name": "project_guides" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_guides_project_version ON public.project_guides USING btree (project_id, version)", - "name": "uq_project_guides_project_version", - "table_name": "project_guides" - }, - { - "definition": "CREATE INDEX ix_project_role_grants_actor_role_status ON public.project_role_grants USING btree (actor_profile_id, role, status)", - "name": "ix_project_role_grants_actor_role_status", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE INDEX ix_project_role_grants_project_actor_role_status ON public.project_role_grants USING btree (project_id, actor_profile_id, role, status)", - "name": "ix_project_role_grants_project_actor_role_status", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_role_grants ON public.project_role_grants USING btree (id)", - "name": "pk_project_role_grants", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_role_grants_active_exact_role ON public.project_role_grants USING btree (project_id, actor_profile_id, role) WHERE ((status)::text = 'active'::text)", - "name": "uq_project_role_grants_active_exact_role", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE UNIQUE INDEX grant_reference ON public.project_role_qualification_snapshots USING btree (id, actor_profile_id, project_id, requested_role)", - "name": "grant_reference", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE INDEX ix_project_role_qualification_snapshots_history ON public.project_role_qualification_snapshots USING btree (project_id, actor_profile_id, requested_role, captured_at)", - "name": "ix_project_role_qualification_snapshots_history", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_role_qualification_snapshots ON public.project_role_qualification_snapshots USING btree (id)", - "name": "pk_project_role_qualification_snapshots", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_celery_task_id ON public.project_setup_runs USING btree (celery_task_id)", - "name": "ix_project_setup_runs_celery_task_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_continuation_verification_job_id ON public.project_setup_runs USING btree (continuation_verification_job_id)", - "name": "ix_project_setup_runs_continuation_verification_job_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_error_artifact_incident_id ON public.project_setup_runs USING btree (error_artifact_incident_id)", - "name": "ix_project_setup_runs_error_artifact_incident_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_guide_id ON public.project_setup_runs USING btree (guide_id)", - "name": "ix_project_setup_runs_guide_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_output_post_submit_checker_policy_id ON public.project_setup_runs USING btree (output_post_submit_checker_policy_id)", - "name": "ix_project_setup_runs_output_post_submit_checker_policy_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_output_submission_artifact_policy_id ON public.project_setup_runs USING btree (output_submission_artifact_policy_id)", - "name": "ix_project_setup_runs_output_submission_artifact_policy_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_output_sufficiency_report_id ON public.project_setup_runs USING btree (output_sufficiency_report_id)", - "name": "ix_project_setup_runs_output_sufficiency_report_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_project_id ON public.project_setup_runs USING btree (project_id)", - "name": "ix_project_setup_runs_project_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_source_snapshot_id ON public.project_setup_runs USING btree (source_snapshot_id)", - "name": "ix_project_setup_runs_source_snapshot_id", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_project_setup_runs_status ON public.project_setup_runs USING btree (status)", - "name": "ix_project_setup_runs_status", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE UNIQUE INDEX pk_project_setup_runs ON public.project_setup_runs USING btree (id)", - "name": "pk_project_setup_runs", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_exact_generation ON public.project_setup_runs USING btree (id, project_id, guide_id, source_snapshot_id, setup_generation)", - "name": "uq_project_setup_runs_exact_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE UNIQUE INDEX uq_project_setup_runs_guide_generation ON public.project_setup_runs USING btree (guide_id, setup_generation)", - "name": "uq_project_setup_runs_guide_generation", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE INDEX ix_projects_slug ON public.projects USING btree (slug)", - "name": "ix_projects_slug", - "table_name": "projects" - }, - { - "definition": "CREATE INDEX ix_projects_status ON public.projects USING btree (status)", - "name": "ix_projects_status", - "table_name": "projects" - }, - { - "definition": "CREATE UNIQUE INDEX pk_projects ON public.projects USING btree (id)", - "name": "pk_projects", - "table_name": "projects" - }, - { - "definition": "CREATE UNIQUE INDEX uq_projects_slug ON public.projects USING btree (slug)", - "name": "uq_projects_slug", - "table_name": "projects" - }, - { - "definition": "CREATE INDEX ix_review_admission_submission ON public.review_admission_idempotency_records USING btree (submission_id, status, created_at, id)", - "name": "ix_review_admission_submission", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_admission_idempotency_records ON public.review_admission_idempotency_records USING btree (id)", - "name": "pk_review_admission_idempotency_records", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_admission_checker_run ON public.review_admission_idempotency_records USING btree (admitting_checker_run_id)", - "name": "uq_review_admission_checker_run", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_admission_operation ON public.review_admission_idempotency_records USING btree (operation_id)", - "name": "uq_review_admission_operation", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_admission_replay_key ON public.review_admission_idempotency_records USING btree (idempotency_key)", - "name": "uq_review_admission_replay_key", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_review_lease_expiry ON public.review_leases USING btree (status, expires_at, id)", - "name": "ix_review_lease_expiry", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_leases ON public.review_leases USING btree (id)", - "name": "pk_review_leases", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_active_queue ON public.review_leases USING btree (review_queue_entry_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_review_lease_active_queue", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_active_reviewer ON public.review_leases USING btree (reviewer_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_review_lease_active_reviewer", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_attempt ON public.review_leases USING btree (review_queue_entry_id, attempt_generation)", - "name": "uq_review_lease_attempt", - "table_name": "review_leases" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_lease_queue_identity ON public.review_leases USING btree (review_queue_entry_id, id)", - "name": "uq_review_lease_queue_identity", - "table_name": "review_leases" - }, - { - "definition": "CREATE INDEX ix_review_policies_project_id ON public.review_policies USING btree (project_id)", - "name": "ix_review_policies_project_id", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_policies ON public.review_policies USING btree (id)", - "name": "pk_review_policies", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_policies_project_version_generation ON public.review_policies USING btree (project_id, guide_version, policy_generation)", - "name": "uq_review_policies_project_version_generation", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_policy_lineage ON public.review_policies USING btree (id, policy_generation, policy_hash)", - "name": "uq_review_policy_lineage", - "table_name": "review_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_policy_scoped_lineage ON public.review_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", - "name": "uq_review_policy_scoped_lineage", - "table_name": "review_policies" - }, - { - "definition": "CREATE INDEX ix_review_queue_preference ON public.review_queue_entries USING btree (preferred_reviewer_id, queue_state, preference_expires_at, id)", - "name": "ix_review_queue_preference", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE INDEX ix_review_queue_selection ON public.review_queue_entries USING btree (project_id, queue_state, routing_mode, first_queued_at, id)", - "name": "ix_review_queue_selection", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX pk_review_queue_entries ON public.review_queue_entries USING btree (id)", - "name": "pk_review_queue_entries", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_queue_admission_identity ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)", - "name": "uq_review_queue_admission_identity", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_queue_lease_lineage ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version)", - "name": "uq_review_queue_lease_lineage", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE UNIQUE INDEX uq_review_queue_submission ON public.review_queue_entries USING btree (submission_id)", - "name": "uq_review_queue_submission", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE INDEX ix_revision_policies_project_id ON public.revision_policies USING btree (project_id)", - "name": "ix_revision_policies_project_id", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_revision_policies ON public.revision_policies USING btree (id)", - "name": "pk_revision_policies", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_revision_policies_project_version_generation ON public.revision_policies USING btree (project_id, guide_version, policy_generation)", - "name": "uq_revision_policies_project_version_generation", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_revision_policy_lineage ON public.revision_policies USING btree (id, policy_generation, policy_hash)", - "name": "uq_revision_policy_lineage", - "table_name": "revision_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_revision_policy_scoped_lineage ON public.revision_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)", - "name": "uq_revision_policy_scoped_lineage", - "table_name": "revision_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_guide_id ON public.submission_artifact_policies USING btree (guide_id)", - "name": "ix_submission_artifact_policies_guide_id", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_lifecycle_status ON public.submission_artifact_policies USING btree (lifecycle_status)", - "name": "ix_submission_artifact_policies_lifecycle_status", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_policy_hash ON public.submission_artifact_policies USING btree (policy_hash)", - "name": "ix_submission_artifact_policies_policy_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_project_id ON public.submission_artifact_policies USING btree (project_id)", - "name": "ix_submission_artifact_policies_project_id", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_artifact_policies_source_snapshot_id ON public.submission_artifact_policies USING btree (source_snapshot_id)", - "name": "ix_submission_artifact_policies_source_snapshot_id", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_artifact_policies ON public.submission_artifact_policies USING btree (id)", - "name": "pk_submission_artifact_policies", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_id_hash ON public.submission_artifact_policies USING btree (id, policy_hash)", - "name": "uq_submission_artifact_policies_id_hash", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_artifact_policies_project_version_policy ON public.submission_artifact_policies USING btree (project_id, guide_version, policy_version)", - "name": "uq_submission_artifact_policies_project_version_policy", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_actor_profile_id ON public.submission_bundle_admissions USING btree (actor_profile_id)", - "name": "ix_submission_bundle_admissions_actor_profile_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_artifact_content_id ON public.submission_bundle_admissions USING btree (artifact_content_id)", - "name": "ix_submission_bundle_admissions_artifact_content_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_pre_submit_evidence_set_id ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", - "name": "ix_submission_bundle_admissions_pre_submit_evidence_set_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_project_id ON public.submission_bundle_admissions USING btree (project_id)", - "name": "ix_submission_bundle_admissions_project_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_status ON public.submission_bundle_admissions USING btree (status)", - "name": "ix_submission_bundle_admissions_status", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_admissions_task_id ON public.submission_bundle_admissions USING btree (task_id)", - "name": "ix_submission_bundle_admissions_task_id", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_bundle_admissions ON public.submission_bundle_admissions USING btree (id)", - "name": "pk_submission_bundle_admissions", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_consumer ON public.submission_bundle_admissions USING btree (consumed_by_submission_id) WHERE (consumed_by_submission_id IS NOT NULL)", - "name": "uq_submission_bundle_admission_consumer", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_evidence ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)", - "name": "uq_submission_bundle_admission_evidence", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_intent ON public.submission_bundle_admissions USING btree (durable_intent_id)", - "name": "uq_submission_bundle_admission_intent", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_admission_verification ON public.submission_bundle_admissions USING btree (verification_receipt_id)", - "name": "uq_submission_bundle_admission_verification", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_durable_intents_pre_submit_evidence_set_id ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", - "name": "ix_submission_bundle_durable_intents_pre_submit_evidence_set_id", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE INDEX ix_submission_bundle_durable_intents_put_attempt_id ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", - "name": "ix_submission_bundle_durable_intents_put_attempt_id", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_bundle_durable_intents ON public.submission_bundle_durable_intents USING btree (id)", - "name": "pk_submission_bundle_durable_intents", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_evidence ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)", - "name": "uq_submission_bundle_intent_evidence", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_bundle_intent_put_attempt ON public.submission_bundle_durable_intents USING btree (put_attempt_id)", - "name": "uq_submission_bundle_intent_put_attempt", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submission_policy_mutation_idempotency_records ON public.submission_policy_mutation_idempotency_records USING btree (id)", - "name": "pk_submission_policy_mutation_idempotency_records", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_committed_policy_action ON public.submission_policy_mutation_idempotency_records USING btree (committed_policy_id, action_id) WHERE ((status)::text = 'committed'::text)", - "name": "uq_submission_policy_committed_policy_action", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_human_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key) WHERE (service_identity IS NULL)", - "name": "uq_submission_policy_human_replay_namespace", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_operation_identity ON public.submission_policy_mutation_idempotency_records USING btree (operation_id)", - "name": "uq_submission_policy_operation_identity", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submission_policy_service_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, setup_run_id, setup_generation, setup_task_id, correlation_id, action_id) WHERE (service_identity IS NOT NULL)", - "name": "uq_submission_policy_service_replay_namespace", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE INDEX ix_submissions_contributor_id ON public.submissions USING btree (contributor_id)", - "name": "ix_submissions_contributor_id", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_effective_policy_hash ON public.submissions USING btree (locked_effective_project_submission_artifact_policy_hash)", - "name": "ix_submissions_locked_effective_policy_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_post_submit_policy_hash ON public.submissions USING btree (locked_post_submit_checker_policy_hash)", - "name": "ix_submissions_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_pre_submit_checker_hash ON public.submissions USING btree (locked_pre_submit_checker_bundle_hash)", - "name": "ix_submissions_locked_pre_submit_checker_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_locked_source_snapshot ON public.submissions USING btree (locked_guide_source_snapshot_id)", - "name": "ix_submissions_locked_source_snapshot", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_status ON public.submissions USING btree (status)", - "name": "ix_submissions_status", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_supersedes_submission_id ON public.submissions USING btree (supersedes_submission_id)", - "name": "ix_submissions_supersedes_submission_id", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_submissions_task_id ON public.submissions USING btree (task_id)", - "name": "ix_submissions_task_id", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX pk_submissions ON public.submissions USING btree (id)", - "name": "pk_submissions", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_id_locked_post_submit_policy_hash ON public.submissions USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "name": "uq_submissions_id_locked_post_submit_policy_hash", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_id_task_version ON public.submissions USING btree (id, task_id, version)", - "name": "uq_submissions_id_task_version", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_id_version ON public.submissions USING btree (id, version)", - "name": "uq_submissions_id_version", - "table_name": "submissions" - }, - { - "definition": "CREATE UNIQUE INDEX uq_submissions_task_version ON public.submissions USING btree (task_id, version)", - "name": "uq_submissions_task_version", - "table_name": "submissions" - }, - { - "definition": "CREATE INDEX ix_task_assignments_contributor_id ON public.task_assignments USING btree (contributor_id)", - "name": "ix_task_assignments_contributor_id", - "table_name": "task_assignments" - }, - { - "definition": "CREATE INDEX ix_task_assignments_status ON public.task_assignments USING btree (status)", - "name": "ix_task_assignments_status", - "table_name": "task_assignments" - }, - { - "definition": "CREATE INDEX ix_task_assignments_task_id ON public.task_assignments USING btree (task_id)", - "name": "ix_task_assignments_task_id", - "table_name": "task_assignments" - }, - { - "definition": "CREATE UNIQUE INDEX pk_task_assignments ON public.task_assignments USING btree (id)", - "name": "pk_task_assignments", - "table_name": "task_assignments" - }, - { - "definition": "CREATE UNIQUE INDEX uq_task_assignments_id_task_contributor ON public.task_assignments USING btree (id, task_id, contributor_id)", - "name": "uq_task_assignments_id_task_contributor", - "table_name": "task_assignments" - }, - { - "definition": "CREATE UNIQUE INDEX uq_task_assignments_one_active_per_task ON public.task_assignments USING btree (task_id) WHERE ((status)::text = 'active'::text)", - "name": "uq_task_assignments_one_active_per_task", - "table_name": "task_assignments" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_assigned_to ON public.workstream_tasks USING btree (assigned_to)", - "name": "ix_workstream_tasks_assigned_to", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_effective_policy_hash ON public.workstream_tasks USING btree (locked_effective_project_submission_artifact_policy_hash)", - "name": "ix_workstream_tasks_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (locked_post_submit_checker_policy_hash)", - "name": "ix_workstream_tasks_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (locked_pre_submit_checker_bundle_hash)", - "name": "ix_workstream_tasks_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_locked_source_snapshot ON public.workstream_tasks USING btree (locked_guide_source_snapshot_id)", - "name": "ix_workstream_tasks_locked_source_snapshot", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_project_id ON public.workstream_tasks USING btree (project_id)", - "name": "ix_workstream_tasks_project_id", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE INDEX ix_workstream_tasks_status ON public.workstream_tasks USING btree (status)", - "name": "ix_workstream_tasks_status", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX pk_workstream_tasks ON public.workstream_tasks USING btree (id)", - "name": "pk_workstream_tasks", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_effective_policy_hash ON public.workstream_tasks USING btree (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)", - "name": "uq_workstream_tasks_id_locked_effective_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_guide ON public.workstream_tasks USING btree (id, locked_guide_version)", - "name": "uq_workstream_tasks_id_locked_guide", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_payment_policy ON public.workstream_tasks USING btree (id, locked_payment_policy_version)", - "name": "uq_workstream_tasks_id_locked_payment_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)", - "name": "uq_workstream_tasks_id_locked_post_submit_policy_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)", - "name": "uq_workstream_tasks_id_locked_pre_submit_checker_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_review_policy ON public.workstream_tasks USING btree (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)", - "name": "uq_workstream_tasks_id_locked_review_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_revision_policy ON public.workstream_tasks USING btree (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)", - "name": "uq_workstream_tasks_id_locked_revision_policy", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_source_snapshot_hash ON public.workstream_tasks USING btree (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)", - "name": "uq_workstream_tasks_id_locked_source_snapshot_hash", - "table_name": "workstream_tasks" - }, - { - "definition": "CREATE UNIQUE INDEX uq_workstream_tasks_id_project ON public.workstream_tasks USING btree (id, project_id)", - "name": "uq_workstream_tasks_id_project", - "table_name": "workstream_tasks" - } - ], - "policies": [], - "reference_rows": { - "actor_profile_migration_state": [ - { - "classified_count": 0, - "envelope_sha256": null, - "id": 1, - "manifest_sha256": null, - "migrated_at": "2026-08-11T08:18:03.063940+00:00", - "schema_version": 1, - "service_identity_database_binding": "postgres-v1:aa1108b4a868ca4330673d1bbe499d99c330d196994696d89e56cf09bfc3c93e", - "service_identity_envelope_sha256": null, - "service_identity_manifest_sha256": null, - "service_identity_mapped_count": 0, - "service_identity_source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945", - "source_row_set_sha256": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945" - } - ], - "authority_control": [ - { - "bootstrap_completed": false, - "bootstrap_grant_id": null, - "created_at": "2026-08-11T08:18:13.474128+00:00", - "id": 1, - "updated_at": "2026-08-11T08:18:13.474148+00:00", - "version": 0 - } - ], - "iso_4217_currency_codes": [ - { - "code": "AED" - }, - { - "code": "AFN" - }, - { - "code": "ALL" - }, - { - "code": "AMD" - }, - { - "code": "AOA" - }, - { - "code": "ARS" - }, - { - "code": "AUD" - }, - { - "code": "AWG" - }, - { - "code": "AZN" - }, - { - "code": "BAM" - }, - { - "code": "BBD" - }, - { - "code": "BDT" - }, - { - "code": "BHD" - }, - { - "code": "BIF" - }, - { - "code": "BMD" - }, - { - "code": "BND" - }, - { - "code": "BOB" - }, - { - "code": "BOV" - }, - { - "code": "BRL" - }, - { - "code": "BSD" - }, - { - "code": "BTN" - }, - { - "code": "BWP" - }, - { - "code": "BYN" - }, - { - "code": "BZD" - }, - { - "code": "CAD" - }, - { - "code": "CDF" - }, - { - "code": "CHE" - }, - { - "code": "CHF" - }, - { - "code": "CHW" - }, - { - "code": "CLF" - }, - { - "code": "CLP" - }, - { - "code": "CNY" - }, - { - "code": "COP" - }, - { - "code": "COU" - }, - { - "code": "CRC" - }, - { - "code": "CUP" - }, - { - "code": "CVE" - }, - { - "code": "CZK" - }, - { - "code": "DJF" - }, - { - "code": "DKK" - }, - { - "code": "DOP" - }, - { - "code": "DZD" - }, - { - "code": "EGP" - }, - { - "code": "ERN" - }, - { - "code": "ETB" - }, - { - "code": "EUR" - }, - { - "code": "FJD" - }, - { - "code": "FKP" - }, - { - "code": "GBP" - }, - { - "code": "GEL" - }, - { - "code": "GHS" - }, - { - "code": "GIP" - }, - { - "code": "GMD" - }, - { - "code": "GNF" - }, - { - "code": "GTQ" - }, - { - "code": "GYD" - }, - { - "code": "HKD" - }, - { - "code": "HNL" - }, - { - "code": "HTG" - }, - { - "code": "HUF" - }, - { - "code": "IDR" - }, - { - "code": "ILS" - }, - { - "code": "INR" - }, - { - "code": "IQD" - }, - { - "code": "IRR" - }, - { - "code": "ISK" - }, - { - "code": "JMD" - }, - { - "code": "JOD" - }, - { - "code": "JPY" - }, - { - "code": "KES" - }, - { - "code": "KGS" - }, - { - "code": "KHR" - }, - { - "code": "KMF" - }, - { - "code": "KPW" - }, - { - "code": "KRW" - }, - { - "code": "KWD" - }, - { - "code": "KYD" - }, - { - "code": "KZT" - }, - { - "code": "LAK" - }, - { - "code": "LBP" - }, - { - "code": "LKR" - }, - { - "code": "LRD" - }, - { - "code": "LSL" - }, - { - "code": "LYD" - }, - { - "code": "MAD" - }, - { - "code": "MDL" - }, - { - "code": "MGA" - }, - { - "code": "MKD" - }, - { - "code": "MMK" - }, - { - "code": "MNT" - }, - { - "code": "MOP" - }, - { - "code": "MRU" - }, - { - "code": "MUR" - }, - { - "code": "MVR" - }, - { - "code": "MWK" - }, - { - "code": "MXN" - }, - { - "code": "MXV" - }, - { - "code": "MYR" - }, - { - "code": "MZN" - }, - { - "code": "NAD" - }, - { - "code": "NGN" - }, - { - "code": "NIO" - }, - { - "code": "NOK" - }, - { - "code": "NPR" - }, - { - "code": "NZD" - }, - { - "code": "OMR" - }, - { - "code": "PAB" - }, - { - "code": "PEN" - }, - { - "code": "PGK" - }, - { - "code": "PHP" - }, - { - "code": "PKR" - }, - { - "code": "PLN" - }, - { - "code": "PYG" - }, - { - "code": "QAR" - }, - { - "code": "RON" - }, - { - "code": "RSD" - }, - { - "code": "RUB" - }, - { - "code": "RWF" - }, - { - "code": "SAR" - }, - { - "code": "SBD" - }, - { - "code": "SCR" - }, - { - "code": "SDG" - }, - { - "code": "SEK" - }, - { - "code": "SGD" - }, - { - "code": "SHP" - }, - { - "code": "SLE" - }, - { - "code": "SOS" - }, - { - "code": "SRD" - }, - { - "code": "SSP" - }, - { - "code": "STN" - }, - { - "code": "SVC" - }, - { - "code": "SYP" - }, - { - "code": "SZL" - }, - { - "code": "THB" - }, - { - "code": "TJS" - }, - { - "code": "TMT" - }, - { - "code": "TND" - }, - { - "code": "TOP" - }, - { - "code": "TRY" - }, - { - "code": "TTD" - }, - { - "code": "TWD" - }, - { - "code": "TZS" - }, - { - "code": "UAH" - }, - { - "code": "UGX" - }, - { - "code": "USD" - }, - { - "code": "USN" - }, - { - "code": "UYI" - }, - { - "code": "UYU" - }, - { - "code": "UYW" - }, - { - "code": "UZS" - }, - { - "code": "VED" - }, - { - "code": "VES" - }, - { - "code": "VND" - }, - { - "code": "VUV" - }, - { - "code": "WST" - }, - { - "code": "XAD" - }, - { - "code": "XAF" - }, - { - "code": "XAG" - }, - { - "code": "XAU" - }, - { - "code": "XBA" - }, - { - "code": "XBB" - }, - { - "code": "XBC" - }, - { - "code": "XBD" - }, - { - "code": "XCD" - }, - { - "code": "XCG" - }, - { - "code": "XDR" - }, - { - "code": "XOF" - }, - { - "code": "XPD" - }, - { - "code": "XPF" - }, - { - "code": "XPT" - }, - { - "code": "XSU" - }, - { - "code": "XTS" - }, - { - "code": "XUA" - }, - { - "code": "XXX" - }, - { - "code": "YER" - }, - { - "code": "ZAR" - }, - { - "code": "ZMW" - }, - { - "code": "ZWG" - } - ] - }, - "routines": [ - { - "arguments": "event_name text, before_state json, after_state json, envelope_project_id text", - "definition": "CREATE OR REPLACE FUNCTION public.authority_event_facts_are_safe(event_name text, before_state json, after_state json, envelope_project_id text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE AS $function$ begin if not (event_name='AuthorityInvalidationRequested' and before_state is not null and after_state is not null and coalesce(before_state::jsonb ? 'future_obligation', false) and coalesce(after_state::jsonb ? 'future_obligation', false)) and ((before_state is not null and not authority_facts_are_safe(before_state)) or (after_state is not null and not authority_facts_are_safe(after_state))) then return false; end if; case event_name when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"human\",\"provisioning_method\":\"automatic_first_access\"}'::jsonb; when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"service\",\"provisioning_method\":\"manual_service_provisioning\"}'::jsonb; when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( '{\"status\":\"active\",\"subject_kind\":\"human\"}'::jsonb, '{\"status\":\"active\",\"subject_kind\":\"service\"}'::jsonb); when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"revoked\"}'::jsonb; when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{\"status\":\"revoked\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileSuspended' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"suspended\"}'::jsonb; when 'ActorProfileReactivated' then return before_state::jsonb='{\"status\":\"suspended\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileDeactivated' then return before_state::jsonb in ('{\"status\":\"active\"}'::jsonb,'{\"status\":\"suspended\"}'::jsonb) and after_state::jsonb='{\"status\":\"deactivated\"}'::jsonb; when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','adjudicator'],'active',true,envelope_project_id); when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then return authority_grant_facts_are_safe(before_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'active',true,envelope_project_id) and authority_grant_facts_are_safe(after_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'revoked',false,envelope_project_id) and before_state->>'role'=after_state->>'role' and before_state->>'scope_type'=after_state->>'scope_type' and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{\"status\":\"captured\"}'::jsonb; when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; when 'SensitiveAuthorizationAllowed' then return before_state is null and ( after_state::jsonb = '{\"allowed\": true}'::jsonb or ( after_state::jsonb->'allowed' = 'true'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'SensitiveAuthorizationDenied' then return before_state is null and ( after_state::jsonb = '{\"allowed\": false}'::jsonb or ( after_state::jsonb->'allowed' = 'false'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'AuthorityInvalidationRequested' then return (before_state::jsonb = '{\"effective\": true}'::jsonb and after_state::jsonb = '{\"effective\": false}'::jsonb) or (before_state::jsonb = '{\"effective\": false}'::jsonb and after_state::jsonb = '{\"effective\": true}'::jsonb) or ( jsonb_typeof(before_state::jsonb)='object' and jsonb_typeof(after_state::jsonb)='object' and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and before_state::jsonb->'effective'='true'::jsonb and after_state::jsonb->'effective'='false'::jsonb and jsonb_typeof(before_state::jsonb->'role')='string' and jsonb_typeof(before_state::jsonb->'scope_type')='string' and jsonb_typeof(before_state::jsonb->'scope_id')='string' and jsonb_typeof(before_state::jsonb->'future_obligation')='string' and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') and before_state::jsonb->>'scope_type'='project' and before_state::jsonb->>'scope_id'=envelope_project_id and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) ); else return false; end case; end $function$", - "name": "authority_event_facts_are_safe" - }, - { - "arguments": "facts json", - "definition": "CREATE OR REPLACE FUNCTION public.authority_facts_are_safe(facts json) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select json_typeof(facts) = 'object' and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) and not exists ( select 1 from json_each(facts) item where item.key not in ( 'status', 'subject_kind', 'provisioning_method', 'role', 'scope_type', 'scope_id', 'effective', 'allowed', 'resource_context_digest' ) or case item.key when 'status' then item.value #>> '{}' not in ( 'active', 'suspended', 'deactivated', 'revoked', 'captured' ) when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') when 'provisioning_method' then item.value #>> '{}' not in ( 'automatic_first_access', 'manual_service_provisioning' ) when 'role' then item.value #>> '{}' not in ( 'access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' ) when 'scope_type' then item.value #>> '{}' not in ('system', 'project') when 'scope_id' then (item.value #>> '{}') !~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' when 'effective' then json_typeof(item.value) <> 'boolean' when 'allowed' then json_typeof(item.value) <> 'boolean' when 'resource_context_digest' then (item.value #>> '{}') !~ '^sha256:[0-9a-f]{64}$' else true end ) $function$", - "name": "authority_facts_are_safe" - }, - { - "arguments": "facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text", - "definition": "CREATE OR REPLACE FUNCTION public.authority_grant_facts_are_safe(facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text) RETURNS boolean LANGUAGE sql IMMUTABLE AS $function$ select authority_facts_are_safe(facts) and facts->>'role' = any(roles) and facts->>'status' = expected_status and (facts->>'effective')::boolean = expected_effective and ( ( facts->>'scope_type' = 'system' and envelope_project_id is null and not facts::jsonb ? 'scope_id' and facts->>'role' not in ('submitter', 'reviewer', 'both') and (select count(*) from json_each(facts)) = 4 ) or ( facts->>'scope_type' = 'project' and envelope_project_id is not null and facts->>'scope_id' = envelope_project_id and facts->>'role' not in ('access_administrator', 'operator') and (select count(*) from json_each(facts)) = 5 ) ) $function$", - "name": "authority_grant_facts_are_safe" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.enforce_compensation_binding_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compensation_binding_updates_deferred'; return new; end; $function$", - "name": "enforce_compensation_binding_lifecycle" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_identity_link_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then raise exception 'actor identity link anchor is immutable' using errcode='55000'; end if; if new.status=old.status and (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'identity link attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='revoked' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid identity link revocation attribution' using errcode='23514'; end if; if old.status='revoked' and new.status='active' and ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then raise exception 'invalid identity link reactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status='revoked') or (old.status='revoked' and new.status='active')) then raise exception 'invalid identity link lifecycle transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_actor_identity_link_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_actor_profile_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then raise exception 'actor profile identity is immutable' using errcode='55000'; end if; if old.status='deactivated' and new.status <> 'deactivated' then raise exception 'deactivated actor is terminal' using errcode='23514'; end if; if new.status = old.status and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='suspended' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'invalid actor suspension attribution' using errcode='23514'; end if; if old.status='suspended' and new.status='active' and ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then raise exception 'invalid actor reactivation attribution' using errcode='23514'; end if; if new.status='deactivated' and old.status in ('active','suspended') and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid actor deactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status in ('suspended','deactivated')) or (old.status='suspended' and new.status in ('active','deactivated'))) then raise exception 'invalid actor lifecycle transition' using errcode='23514'; end if; new.updated_at = statement_timestamp(); return new; end $function$", - "name": "guard_actor_profile_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_admin_role_grant() RETURNS trigger LANGUAGE plpgsql AS $function$ declare target_kind text; authorizer admin_role_grants%rowtype; bootstrap_done boolean; begin if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; if tg_op='INSERT' then select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; new.granted_at := clock_timestamp(); if new.granted_by_system_principal is not null then if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; if bootstrap_done is distinct from false or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then raise exception 'bootstrap already completed' using errcode='23514'; end if; else select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; end if; return new; end if; if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, new.granted_by_actor_profile_id,new.granted_by_system_principal, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, old.granted_by_actor_profile_id,old.granted_by_system_principal, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then raise exception 'invalid admin role grant transition' using errcode='23514'; end if; select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", - "name": "guard_admin_role_grant" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_artifact_receipt_producer_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id; if request_type is null or (request_type = 'guide' and not ( new.guide_source_item_id is not null and new.checker_run_id is null and new.logical_role is null)) or (request_type = 'checker_output' and not ( new.guide_source_item_id is null and new.checker_run_id is not null and octet_length(new.logical_role) between 1 and 100)) or (request_type = 'submission_bundle' and not ( new.guide_source_item_id is null and new.checker_run_id is null and new.logical_role is null)) then raise exception 'artifact receipt producer reference mismatch' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_artifact_receipt_producer_reference" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_control() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; if old.id <> 1 or old.bootstrap_completed or old.version <> 0 or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then raise exception 'invalid authority control transition' using errcode='23514'; end if; new.updated_at := clock_timestamp(); return new; end $function$", - "name": "guard_authority_control" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_authority_idempotency_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare success_count integer; invalidation_count integer; success_id text; qualification_row audit_events%rowtype; success_row audit_events%rowtype; grant_row project_role_grants%rowtype; snapshot_row project_role_qualification_snapshots%rowtype; begin if tg_op = 'INSERT' then if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; new.created_at := statement_timestamp(); new.committed_at := null; return new; elsif tg_op = 'DELETE' then raise exception 'authority idempotency records are immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, new.request_digest,new.created_at) is distinct from (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, old.request_digest,old.created_at) then raise exception 'invalid authority idempotency transition' using errcode='23514'; end if; select count(*), min(id) into success_count, success_id from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type <> 'AuthorityInvalidationRequested'; select count(*) into invalidation_count from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type='AuthorityInvalidationRequested'; if new.operation='project_role_grant.issue' then if success_count <> 2 or invalidation_count <> 0 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued') <> 1 then raise exception 'project role issue evidence pair required' using errcode='23514'; end if; select * into qualification_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured'; select * into success_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued'; select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; select * into snapshot_row from project_role_qualification_snapshots where id=qualification_row.resource_id::uuid; if not found or grant_row.id is null or snapshot_row.id is null or grant_row.qualification_snapshot_id <> snapshot_row.id or grant_row.project_id <> snapshot_row.project_id or grant_row.actor_profile_id <> snapshot_row.actor_profile_id or grant_row.role <> snapshot_row.requested_role or qualification_row.project_id is distinct from grant_row.project_id or success_row.project_id is distinct from grant_row.project_id or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id or success_row.target_actor_ref is distinct from grant_row.actor_profile_id or qualification_row.request_id is distinct from success_row.request_id or qualification_row.correlation_id is distinct from success_row.correlation_id or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind or qualification_row.actor_id is distinct from success_row.actor_id or qualification_row.permission_id is distinct from success_row.permission_id or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then raise exception 'project role issue evidence mismatch' using errcode='23514'; end if; else if success_count <> 1 or invalidation_count <> 1 then raise exception 'authority evidence pair required' using errcode='23514'; end if; select * into success_row from audit_events where id=success_id; end if; if success_row.resource_type <> new.response_resource_type or success_row.resource_id <> new.response_resource_id::text then raise exception 'authority response does not match evidence' using errcode='23514'; end if; new.committed_at := statement_timestamp(); return new; end $function$", - "name": "guard_authority_idempotency_record" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_children() RETURNS trigger LANGUAGE plpgsql AS $function$ declare old_parent_status text; declare new_parent_status text; begin if tg_op in ('UPDATE','DELETE') then select status into old_parent_status from contribution_policy_versions where id=old.contribution_policy_version_id for update; end if; if tg_op in ('INSERT','UPDATE') then select status into new_parent_status from contribution_policy_versions where id=new.contribution_policy_version_id for update; end if; if old_parent_status in ('published','retired') or new_parent_status in ('published','retired') then raise exception 'published contribution policy rules and definitions are immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", - "name": "guard_contribution_policy_children" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_contribution_policy_version_content() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' and old.status in ('published','retired') then raise exception 'published contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='retired' then raise exception 'retired contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='published' and not ( new.status='retired' and new.id=old.id and new.contribution_policy_id=old.contribution_policy_id and new.project_id=old.project_id and new.version_number=old.version_number and new.created_by=old.created_by and new.created_at=old.created_at and new.published_by=old.published_by and new.published_at=old.published_at and new.retired_by is not null and new.retired_at is not null ) then raise exception 'published contribution policy version content is immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$", - "name": "guard_contribution_policy_version_content" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_lineage_and_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if (new.id,new.project_id,new.version) is distinct from (old.id,old.project_id,old.version) then raise exception 'guide identity and lineage are immutable' using errcode='23514'; end if; if (new.status,new.approved_by,new.effective_at,new.superseded_at) is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then raise exception 'guide lifecycle mutation requires activation authority' using errcode='23514'; end if; return new; end $function$", - "name": "guard_guide_lineage_and_lifecycle" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_guide_mutation_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'guide mutation custody is immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status<>'pending' or new.status<>'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, new.operation_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, old.operation_generation,old.created_at) then raise exception 'invalid guide mutation custody transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_guide_mutation_idempotency" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_iso_4217_currency_codes() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' using errcode='55000'; end; $function$", - "name": "guard_iso_4217_currency_codes" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_outbox_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare event_time timestamptz; begin if tg_op = 'TRUNCATE' then raise exception 'outbox events cannot be truncated' using errcode='55000'; elsif tg_op = 'DELETE' then raise exception 'outbox events cannot be deleted' using errcode='55000'; elsif tg_op = 'INSERT' then event_time := statement_timestamp(); new.producer := 'workstream'; new.occurred_at := event_time; new.delivery_state := 'pending'; new.attempt_count := 0; new.next_attempt_at := event_time; new.claim_owner := null; new.claim_generation := 0; new.claimed_at := null; new.claim_expires_at := null; new.last_attempt_at := null; new.last_error_code := null; new.finalized_at := null; new.archived_at := null; return new; end if; if (new.event_id, new.event_type, new.event_version, new.producer, new.aggregate_type, new.aggregate_id, new.project_id, new.correlation_id, new.causation_event_id, new.idempotency_key, new.payload, new.payload_digest, new.occurred_at) is distinct from (old.event_id, old.event_type, old.event_version, old.producer, old.aggregate_type, old.aggregate_id, old.project_id, old.correlation_id, old.causation_event_id, old.idempotency_key, old.payload, old.payload_digest, old.occurred_at) then raise exception 'outbox event envelope is immutable' using errcode='55000'; end if; if new.attempt_count < old.attempt_count or new.claim_generation < old.claim_generation or new.attempt_count <> new.claim_generation then raise exception 'outbox counters cannot regress' using errcode='23514'; end if; if old.archived_at is not null and (new.delivery_state, new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.delivery_state, old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'archived outbox event is closed' using errcode='55000'; end if; if old.delivery_state in ('pending', 'retryable') and new.delivery_state = 'claimed' then if new.attempt_count <> old.attempt_count + 1 or new.claim_generation <> old.claim_generation + 1 or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox claim generation must increment once' using errcode='23514'; end if; elsif old.delivery_state = 'claimed' and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at then raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state = 'dead_letter' and new.delivery_state = 'retryable' and old.archived_at is null then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = 'cancelled' then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.attempt_count, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; end if; elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at) is distinct from (old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at) or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) or (old.archived_at is null and new.archived_at is null) then raise exception 'terminal outbox event permits archival only' using errcode='23514'; end if; else raise exception 'illegal outbox delivery transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_outbox_event" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_policy_mutation_replay() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'policy mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'policy mutation replay is immutable' using errcode='55000'; elsif new is not distinct from old then return new; elsif old.status='pending' and new.status='committed' and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest,new.policy_hash, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.policy_id, new.policy_generation,new.created_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest,old.policy_hash, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.policy_id, old.policy_generation,old.created_at) then return new; end if; raise exception 'policy mutation replay is immutable' using errcode='23514'; end $function$", - "name": "guard_policy_mutation_replay" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_result_membership() RETURNS trigger LANGUAGE plpgsql AS $function$ declare parent_created_at timestamptz; expected_count integer; current_count integer; begin select created_at, result_count into parent_created_at, expected_count from pre_submit_evidence_sets where id=new.evidence_set_id for key share; select count(*) into current_count from pre_submit_evidence_results where evidence_set_id=new.evidence_set_id; if parent_created_at is null or parent_created_at <> transaction_timestamp() or current_count >= expected_count then raise exception 'pre-submit evidence result membership is closed' using errcode='55000'; end if; return new; end; $function$", - "name": "guard_pre_submit_evidence_result_membership" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_results_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_results rows are immutable' using errcode='55000'; end; $function$", - "name": "guard_pre_submit_evidence_results_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_set_creation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.created_at is distinct from transaction_timestamp() then raise exception 'pre-submit evidence creation timestamp is invalid' using errcode='55000'; end if; return new; end; $function$", - "name": "guard_pre_submit_evidence_set_creation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_sets_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_sets rows are immutable' using errcode='55000'; end; $function$", - "name": "guard_pre_submit_evidence_sets_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_compensation_units() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('UPDATE','DELETE') then raise exception 'project compensation-unit lifecycle behavior is deferred' using errcode='55000'; end if; if new.status <> 'active' then raise exception 'project compensation units must begin active' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_project_compensation_units" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_create_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'INSERT' then if new.status <> 'pending' or new.committed_at is not null then raise exception 'project create reservation must begin pending' using errcode='23514'; end if; return new; elsif tg_op = 'DELETE' then raise exception 'project create reservations are immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, new.idempotency_key, new.request_digest, new.operation_id, new.project_id, new.operation_generation, new.created_at) is distinct from (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, old.idempotency_key, old.request_digest, old.operation_id, old.project_id, old.operation_generation, old.created_at) then raise exception 'invalid project create reservation transition' using errcode='23514'; end if; return new; end $function$", - "name": "guard_project_create_idempotency" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_attempt_update() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, new.pre_catalogue_version,new.pre_catalogue_schema_version, new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.provider_idempotency_key) is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, old.source_snapshot_hash,old.setup_run_id,old.setup_generation, old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, old.pre_catalogue_version,old.pre_catalogue_schema_version, old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, old.agent_identity,old.agent_version,old.instruction_version, old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; if new.reserved_at is distinct from old.reserved_at then raise exception 'compilation reservation timestamp is immutable'; end if; if new.provider_uncertain_at is distinct from old.provider_uncertain_at and not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then raise exception 'provider uncertainty timestamp is immutable'; end if; if new.accepted_at is distinct from old.accepted_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then raise exception 'accepted timestamp is immutable'; end if; if new.terminal_at is distinct from old.terminal_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then raise exception 'terminal timestamp is immutable'; end if; if row(new.persisted_at,new.persisted_compilation_id) is distinct from row(old.persisted_at,old.persisted_compilation_id) and not (old.status='provider_result_accepted' and new.status='compilation_persisted') then raise exception 'persisted custody is immutable'; end if; if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then raise exception 'accepted compilation result is immutable'; end if; if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or (old.status='provider_result_accepted' and new.status='compilation_persisted')) then raise exception 'invalid compilation attempt transition'; end if; return new; end $function$", - "name": "guard_project_guide_compilation_attempt_update" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_insert() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor_generation bigint; declare source_attempt project_guide_compilation_attempts%rowtype; begin select * into source_attempt from project_guide_compilation_attempts where id=new.attempt_id for update; if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash, new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) is distinct from row(source_attempt.project_id,source_attempt.guide_id, source_attempt.guide_version,source_attempt.source_snapshot_id, source_attempt.source_snapshot_hash,source_attempt.setup_run_id, source_attempt.setup_generation,source_attempt.canonical_input_hash, source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, source_attempt.agent_version,source_attempt.instruction_version, source_attempt.canonical_result::jsonb,source_attempt.result_hash, source_attempt.component_hashes::jsonb) then raise exception 'compilation does not match its accepted attempt'; end if; if not exists( select 1 from audit_events event join actor_profiles profile on profile.id=new.created_by_actor_profile_id join actor_identity_links link on link.id=new.created_via_identity_link_id and link.actor_profile_id=profile.id where event.id=new.authorization_decision_event_id and event.event_domain='authority' and event.event_type='SensitiveAuthorizationAllowed' and event.denial_code is null and event.actor_id=new.created_by_actor_profile_id and event.permission_id='project.guide_compilation.execute' and event.action_id='project.guide_compilation.execute' and event.project_id=new.project_id and event.resource_type='project_guide_compilation_attempt' and event.resource_id=new.attempt_id::text and event.after_facts->>'allowed'='true' and event.after_facts->>'resource_context_digest'= new.authorization_resource_context_digest and profile.actor_kind='service' and profile.status='active' and profile.service_identity='workstream.project.setup' and link.subject_kind='service' and link.status='active' and link.issuer='workstream-internal' and link.subject='workstream.project.setup' ) then raise exception 'compilation authorization evidence is invalid'; end if; if new.supersedes_compilation_id is null then return new; end if; select setup_generation into predecessor_generation from project_guide_compilations where id=new.supersedes_compilation_id and project_id=new.project_id and guide_id=new.guide_id; if predecessor_generation is null or predecessor_generation >= new.setup_generation then raise exception 'compilation generation must strictly advance'; end if; return new; end $function$", - "name": "guard_project_guide_compilation_insert" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_guide_policy_selection() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.status in ('active','superseded') and ( new.selected_review_policy_id is distinct from old.selected_review_policy_id or new.selected_review_policy_generation is distinct from old.selected_review_policy_generation or new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or new.selected_revision_policy_generation is distinct from old.selected_revision_policy_generation or new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash ) then raise exception 'active guide policy selection is immutable' using errcode='55000'; end if; return new; end $function$", - "name": "guard_project_guide_policy_selection" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_grant_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, new.qualification_snapshot_id,new.granted_by_actor_profile_id, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, old.qualification_snapshot_id,old.granted_by_actor_profile_id, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null or new.revoked_reason is null then raise exception 'invalid project-role grant history transition' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$", - "name": "guard_project_role_grant_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_project_role_snapshot_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; end $function$", - "name": "guard_project_role_snapshot_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_admission_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review admission records cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' and new.status <> 'pending' then raise exception 'review admission must begin pending' using errcode='23514'; end if; if tg_op='INSERT' then new.created_at := statement_timestamp(); end if; if tg_op='UPDATE' then if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.created_at) is distinct from (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.created_at) then raise exception 'review admission identity is immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' then raise exception 'invalid review admission transition' using errcode='23514'; end if; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review admission task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review admission checker lineage mismatch' using errcode='23514'; end if; if new.status='committed' and ( checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true) then raise exception 'review admission checker is not admissible' using errcode='23514'; end if; return new; end $function$", - "name": "guard_review_admission_record" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare actor_type text; policy_status text; begin if tg_op='DELETE' then raise exception 'review leases cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.status <> 'active' then raise exception 'review lease must begin active' using errcode='23514'; end if; new.claimed_at := statement_timestamp(); new.closed_at := null; new.close_reason := null; else if old.status <> 'active' then raise exception 'terminal review leases are immutable' using errcode='55000'; end if; if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, new.submission_version,new.reviewer_id, new.reviewer_contribution_policy_version_id,new.attempt_generation, new.claimed_at,new.expires_at) is distinct from (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, old.submission_version,old.reviewer_id, old.reviewer_contribution_policy_version_id,old.attempt_generation, old.claimed_at,old.expires_at) then raise exception 'review lease identity is immutable' using errcode='55000'; end if; if new.status='active' then raise exception 'review lease update must close attempt' using errcode='23514'; end if; end if; select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; if actor_type is distinct from 'human' then raise exception 'review lease reviewer must be human' using errcode='23514'; end if; if tg_op='INSERT' then select status into policy_status from contribution_policy_versions where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; if policy_status is distinct from 'published' then raise exception 'review lease policy version must be published' using errcode='23514'; end if; end if; return new; end $function$", - "name": "guard_review_lease" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review_policies rows are immutable' using errcode='55000'; end $function$", - "name": "guard_review_policies_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_review_queue_entry() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review queue entries cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.queue_state <> 'pending' then raise exception 'review queue must begin pending' using errcode='23514'; end if; new.first_queued_at := statement_timestamp(); new.available_since := new.first_queued_at; new.routing_generation := 1; new.lifecycle_generation := 1; new.created_at := new.first_queued_at; end if; if tg_op='UPDATE' then if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.first_queued_at,new.created_at) is distinct from (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.first_queued_at,old.created_at) then raise exception 'review queue identity is immutable' using errcode='55000'; end if; if old.queue_state='closed' and new.queue_state <> 'closed' then raise exception 'closed review queue entries cannot reopen' using errcode='23514'; end if; if new.routing_generation < old.routing_generation or new.lifecycle_generation < old.lifecycle_generation then raise exception 'review queue generations cannot decrease' using errcode='23514'; end if; end if; if new.preferred_reviewer_id is not null and not exists( select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' ) then raise exception 'preferred reviewer must be human' using errcode='23514'; end if; if tg_op='UPDATE' then return new; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review queue task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review queue checker lineage mismatch' using errcode='23514'; end if; if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true then raise exception 'review queue checker is not admissible' using errcode='23514'; end if; return new; end $function$", - "name": "guard_review_queue_entry" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_revision_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'revision_policies rows are immutable' using errcode='55000'; end $function$", - "name": "guard_revision_policies_immutable" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_service_identity_migration_evidence() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'service identity migration evidence is immutable' using errcode='55000'; end $function$", - "name": "guard_service_identity_migration_evidence" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_delete() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $function$", - "name": "guard_submission_bundle_admission_delete" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, old.put_operation_receipt_id, old.put_observation_receipt_id, old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, old.assignment_id, old.predecessor_submission_id, old.predecessor_submission_version, old.locked_policy_context_hash, old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, old.archive_byte_count, old.ready_at, old.created_at) is distinct from row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, new.put_operation_receipt_id, new.put_observation_receipt_id, new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, new.assignment_id, new.predecessor_submission_id, new.predecessor_submission_version, new.locked_policy_context_hash, new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, new.archive_byte_count, new.ready_at, new.created_at) then raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; end if; if old.status <> 'ready' or new.status not in ('consumed','stale') then raise exception 'invalid submission bundle admission transition' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_submission_bundle_admission_lineage" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_verified_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ declare matches integer; begin select count(*) into matches from submission_bundle_durable_intents intent join pre_submit_evidence_sets evidence on evidence.id=intent.pre_submit_evidence_set_id join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id join artifact_replicas replica on replica.id=attempt.replica_id join artifact_contents content on content.id=replica.content_id join artifact_verification_jobs job on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id join artifact_verification_receipts verification on verification.verification_job_id=job.id where intent.id=new.durable_intent_id and evidence.id=new.pre_submit_evidence_set_id and attempt.id=new.put_attempt_id and content.id=new.artifact_content_id and replica.id=new.verified_replica_id and verification.id=new.verification_receipt_id and attempt.producer_request_type='submission_bundle' and attempt.producer_type='actor_profile' and attempt.producer_ref=evidence.actor_profile_id and attempt.project_id=evidence.project_id and attempt.task_id=evidence.task_id and attempt.media_type='application/zip' and content.media_type='application/zip' and attempt.status='object_confirmed' and evidence.terminal_status='passed' and evidence.eligible and replica.verification_state='verified' and replica.availability_state='available' and replica.integrity_state='valid' and verification.outcome='verified' and verification.execution_generation=job.execution_generation and verification.observed_sha256=attempt.sha256 and verification.observed_sha256=content.sha256 and verification.observed_sha256=evidence.archive_sha256 and verification.observed_byte_count=attempt.byte_count and verification.observed_byte_count=content.byte_count and verification.observed_byte_count=evidence.archive_byte_count and new.actor_profile_id=evidence.actor_profile_id and new.identity_link_id=evidence.identity_link_id and new.project_id=evidence.project_id and new.task_id=evidence.task_id and new.assignment_id=evidence.assignment_id and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version and new.locked_policy_context_hash=evidence.locked_policy_context_hash and new.semantic_manifest_id=evidence.semantic_manifest_id and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 and new.archive_sha256=evidence.archive_sha256 and new.archive_byte_count=evidence.archive_byte_count and ((new.put_operation_receipt_id is not null and exists ( select 1 from artifact_operation_receipts receipt where receipt.id=new.put_operation_receipt_id and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id and receipt.outcome='stored_pending_verification')) or (new.put_observation_receipt_id is not null and exists ( select 1 from artifact_put_observation_receipts observation where observation.id=new.put_observation_receipt_id and observation.put_attempt_id=attempt.id and observation.outcome='observed_confirmed' and observation.observed_sha256=attempt.sha256 and observation.observed_byte_count=attempt.byte_count))); if matches <> 1 then raise exception 'submission bundle admission verified lineage mismatch' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_submission_bundle_admission_verified_lineage" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id for share; if request_type is distinct from 'submission_bundle' then raise exception 'submission bundle durable intent requires submission_bundle put attempt' using errcode='23514'; end if; return new; end; $function$", - "name": "guard_submission_bundle_durable_intent_put_attempt" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intents_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission_bundle_durable_intents rows are immutable' using errcode='55000'; end; $function$", - "name": "guard_submission_bundle_durable_intents_immutable" - }, - { - "arguments": "value jsonb", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_availability_is_safe(value jsonb) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='object' and (select count(*)=3 from jsonb_object_keys(value)) and value ?& array['availability','reference_ids','unavailable_reason'] and project_role_reference_array_is_safe(value->'reference_ids',false) and ( (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 and value->'unavailable_reason'='null'::jsonb) or (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) ) $function$", - "name": "project_role_availability_is_safe" - }, - { - "arguments": "value text", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_reason_is_safe(value text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE STRICT AS $function$ declare point integer; index integer; begin if octet_length(value) not between 1 and 500 or value <> btrim(value, (E' \\t\\n\\r\\f\\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)||chr(8239)||chr(8287)||chr(12288))) then return false; end if; for index in 1..char_length(value) loop point := ascii(substr(value,index,1)); if point between 0 and 31 or point between 127 and 159 or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then return false; end if; end loop; return true; end $function$", - "name": "project_role_reason_is_safe" - }, - { - "arguments": "value jsonb, uuid_only boolean", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_array_is_safe(value jsonb, uuid_only boolean) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 and not exists ( select 1 from jsonb_array_elements(value) item where jsonb_typeof(item)<>'string' or case when uuid_only then not (item #>> '{}') ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' else not project_role_reference_token_is_safe(item #>> '{}') end ) $function$", - "name": "project_role_reference_array_is_safe" - }, - { - "arguments": "value text", - "definition": "CREATE OR REPLACE FUNCTION public.project_role_reference_token_is_safe(value text) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 $function$", - "name": "project_role_reference_token_is_safe" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_approval_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.approval_action_id is not null and (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, new.approved_by_admin_role_grant_id,new.approval_scope_type, new.approval_scope_project_id,new.approval_action_id, new.approval_decision_event_id) is distinct from (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, old.approved_by_admin_role_grant_id,old.approval_scope_type, old.approval_scope_project_id,old.approval_action_id, old.approval_decision_event_id) then raise exception 'submission-policy approval provenance is immutable' using errcode='23514'; end if; return new; end $function$", - "name": "protect_submission_policy_approval_provenance" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_creation_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.created_by_service_identity, new.creation_scope_type,new.creation_scope_project_id, new.creation_action_id,new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.created_by_service_identity, old.creation_scope_type,old.creation_scope_project_id, old.creation_action_id,old.creation_decision_event_id) then raise exception 'submission-policy creation provenance is immutable' using errcode='23514'; end if; return new; end $function$", - "name": "protect_submission_policy_creation_provenance" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.protect_submission_policy_output_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.creation_scope_type, new.creation_scope_project_id,new.creation_action_id, new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.creation_scope_type, old.creation_scope_project_id,old.creation_action_id, old.creation_decision_event_id) then raise exception 'submission-policy output provenance is immutable' using errcode='23514'; end if; return new; end $function$", - "name": "protect_submission_policy_output_provenance" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_admin_role_grant_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'admin role grants are immutable' using errcode='55000'; end $function$", - "name": "reject_admin_role_grant_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_artifact_fact_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception '% rows are immutable', tg_table_name; end; $function$", - "name": "reject_artifact_fact_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_audit_event_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'audit events are append-only' using errcode = '55000'; end $function$", - "name": "reject_audit_event_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_control_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority control is immutable' using errcode='55000'; end $function$", - "name": "reject_authority_control_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_authority_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority idempotency records are immutable' using errcode='55000'; end $function$", - "name": "reject_authority_idempotency_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_contribution_policy_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'contribution policy persistence cannot be truncated' using errcode='55000'; end; $function$", - "name": "reject_contribution_policy_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_mutation_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide mutation custody is immutable' using errcode='55000'; end $function$", - "name": "reject_guide_mutation_idempotency_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_guide_source_snapshot_item_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide source snapshot items are immutable' using errcode='23514'; end $function$", - "name": "reject_guide_source_snapshot_item_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_pending_authority_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then raise exception 'pending authority idempotency cannot commit' using errcode='23514'; end if; return null; end $function$", - "name": "reject_pending_authority_idempotency" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_policy_mutation_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'policy mutation replay is immutable' using errcode='55000'; end $function$", - "name": "reject_policy_mutation_replay_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_project_create_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project create reservations are immutable' using errcode='55000'; end $function$", - "name": "reject_project_create_idempotency_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_project_guide_compilation_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compilation custody is append-only'; end $function$", - "name": "reject_project_guide_compilation_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_project_role_history_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $function$", - "name": "reject_project_role_history_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_review_lease_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review leases cannot be truncated' using errcode='55000'; end $function$", - "name": "reject_review_lease_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_review_queue_foundation_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review queue foundation cannot be truncated' using errcode='55000'; end $function$", - "name": "reject_review_queue_foundation_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'submission-policy replay rows cannot be deleted'; end if; if old.status = 'reserved' and new.status = 'pending' and old.service_identity = 'workstream.project.setup' and old.action_id = 'project.submission_artifact_policy.derive' and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.operation_id,new.project_id, new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, new.committed_pre_submit_policy_id,new.committed_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.operation_id,old.project_id, old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, old.committed_pre_submit_policy_id,old.committed_at) then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.request_digest, new.resource_context_digest,new.resource_context_json::text,new.operation_id, new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, new.setup_run_id,new.setup_generation,new.setup_task_id, new.correlation_id,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.request_digest, old.resource_context_digest,old.resource_context_json::text,old.operation_id, old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, old.setup_run_id,old.setup_generation,old.setup_task_id, old.correlation_id,old.created_at) then raise exception 'invalid submission-policy replay mutation'; end if; return new; end $function$", - "name": "reject_submission_policy_replay_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission-policy replay rows cannot be truncated'; end $function$", - "name": "reject_submission_policy_replay_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'guide sufficiency replay rows are append-only'; end if; if old.status = 'committed' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, new.setup_run_id,new.setup_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, old.setup_run_id,old.setup_generation,old.created_at) then raise exception 'invalid guide sufficiency replay mutation'; end if; return new; end $function$", - "name": "reject_sufficiency_replay_mutation" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide sufficiency replay rows are append-only'; end $function$", - "name": "reject_sufficiency_replay_truncate" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.require_human_actor_profile_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare referenced_id text; referenced_kind text; begin if tg_nargs <> 1 or tg_argv[0] is null or not (to_jsonb(new) ? tg_argv[0]) then raise exception 'human actor reference trigger is misconfigured' using errcode='55000'; end if; referenced_id := to_jsonb(new) ->> tg_argv[0]; if referenced_id is null then return new; end if; select profile.actor_kind into referenced_kind from public.actor_profiles profile where profile.id=referenced_id; if not found then return new; end if; if referenced_kind <> 'human' then raise exception 'actor reference must identify a human profile' using errcode='23514', constraint='require_human_actor_profile_reference'; end if; return new; end $function$", - "name": "require_human_actor_profile_reference" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.set_authority_audit_database_time() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.event_domain = 'authority' then if new.invalidation_cause_event_id is not null and not exists ( select 1 from audit_events where id = new.invalidation_cause_event_id and event_domain = 'authority' ) then raise exception 'invalid authority invalidation cause' using errcode = '23503'; end if; new.occurred_at = statement_timestamp(); else new.occurred_at = null; end if; return new; end $function$", - "name": "set_authority_audit_database_time" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_binding_history() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor artifact_bindings%rowtype; begin if new.scope_version = 1 then return new; end if; select * into predecessor from artifact_bindings where id = new.supersedes_binding_id; if not found or predecessor.project_id != new.project_id or predecessor.resource_type != new.resource_type or predecessor.resource_id != new.resource_id or predecessor.logical_role != new.logical_role or predecessor.scope_version + 1 != new.scope_version then raise exception 'artifact binding predecessor is invalid'; end if; return new; end; $function$", - "name": "validate_artifact_binding_history" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_recovery_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare source_row artifact_verification_jobs%rowtype; retry_row artifact_verification_jobs%rowtype; expected_parent text; begin if tg_op = 'DELETE' then raise exception 'artifact recovery attempts are append-only' using errcode='55000'; end if; if tg_op = 'UPDATE' and ( to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] is distinct from to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] ) then raise exception 'artifact recovery identity is immutable' using errcode='55000'; end if; select * into source_row from artifact_verification_jobs where id=new.source_verification_job_id; select * into retry_row from artifact_verification_jobs where id=new.retry_verification_job_id; if source_row.id is null or retry_row.id is null or source_row.status <> 'provider_unavailable' or source_row.terminal_result_code <> 'provider_unavailable' or source_row.terminal_at is null or source_row.next_run_at is not null or source_row.executor_id is not null or source_row.attempt_count < source_row.maximum_attempts or retry_row.parent_verification_job_id <> source_row.id or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id or retry_row.replica_id <> source_row.replica_id then raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; end if; if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) or (tg_op = 'UPDATE' and ( retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null )) then raise exception 'invalid artifact recovery retry state' using errcode='23514'; end if; select id into expected_parent from artifact_recovery_attempts where retry_verification_job_id=source_row.id; if new.parent_recovery_attempt_id is distinct from expected_parent then raise exception 'invalid artifact recovery parent chain' using errcode='23514'; end if; if not exists ( select 1 from audit_events where id=new.initiation_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryInitiated' ) then raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; end if; if new.terminal_audit_event_id is not null and not exists ( select 1 from audit_events where id=new.terminal_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryCompleted' ) then raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; end if; return new; end $function$", - "name": "validate_artifact_recovery_attempt" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_artifact_verification_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if ( old.parent_verification_job_id is not null or exists( select 1 from artifact_recovery_attempts where source_verification_job_id = old.id or retry_verification_job_id = old.id ) ) and ( old.originating_put_attempt_id is distinct from new.originating_put_attempt_id or old.replica_id is distinct from new.replica_id or old.parent_verification_job_id is distinct from new.parent_verification_job_id ) then raise exception 'artifact verification lineage is immutable' using errcode='55000'; end if; return new; end $function$", - "name": "validate_artifact_verification_lineage" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_bootstrap_authority_state() RETURNS trigger LANGUAGE plpgsql AS $function$ declare control authority_control%rowtype; bootstrap_count bigint; referenced_bootstrap boolean; begin select * into control from authority_control where id=1; if not found then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; select count(*) into bootstrap_count from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap'; referenced_bootstrap := exists( select 1 from admin_role_grants where id=control.bootstrap_grant_id and granted_by_system_principal='workstream:system:bootstrap' ); if (not control.bootstrap_completed and (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) or (control.bootstrap_completed and (control.bootstrap_grant_id is null or control.version <> 1 or bootstrap_count <> 1 or not referenced_bootstrap)) then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; return null; end $function$", - "name": "validate_bootstrap_authority_state" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_canonical_actor_link() RETURNS trigger LANGUAGE plpgsql AS $function$ declare profile_row actor_profiles%rowtype; link_count integer; begin if tg_table_name='actor_profiles' then select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; else select * into profile_row from actor_profiles where id=new.actor_profile_id; if not found or profile_row.actor_kind <> new.subject_kind then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; end if; return new; end $function$", - "name": "validate_canonical_actor_link" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_contribution_policy_graph() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists ( select 1 from contribution_policy_versions v where v.status in ('published','retired') and ( (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='accepted_submission') <> 1 or (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='completed_review') <> 1 or exists ( select 1 from contribution_rules r where r.contribution_policy_version_id=v.id and ( (r.compensation_mode='unpaid' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) <> 0) or (r.compensation_mode='compensated' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) not between 1 and 2) ) ) ) ) then raise exception 'published contribution policy graph is incomplete' using errcode='23514'; end if; if exists ( select 1 from contribution_policies p left join contribution_policy_versions v on v.id=p.current_published_version_id and v.contribution_policy_id=p.id and v.project_id=p.project_id where p.status='active' and (v.id is null or v.status <> 'published') ) then raise exception 'active contribution policy selector is invalid' using errcode='23514'; end if; return null; end; $function$", - "name": "validate_contribution_policy_graph" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation guide_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_resource text; product_generation integer; begin if tg_table_name='guide_mutation_idempotency_records' then select * into reservation from guide_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id in ('project.guide.create','project.guide.update') then select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, last_mutated_by_admin_role_grant_id,last_mutation_action_id, last_mutation_scope_type,last_mutation_scope_project_id, last_authorization_decision_event_id,project_id,id,mutation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from project_guides where id=reservation.resource_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,project_id,id,creation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from guide_source_snapshots where id=reservation.resource_id; end if; elsif tg_table_name='project_guides' then if tg_op='UPDATE' and (new.content_markdown is distinct from old.content_markdown or new.change_summary is distinct from old.change_summary) and (new.mutation_generation is not distinct from old.mutation_generation or new.last_authorization_decision_event_id is not distinct from old.last_authorization_decision_event_id) then raise exception 'guide content mutation requires fresh custody' using errcode='23514'; end if; if new.mutation_generation is null then if tg_op='INSERT' then raise exception 'new guides require mutation authority' using errcode='23514'; end if; return null; end if; actor_id:=new.last_mutated_by_actor_profile_id; link_id:=new.last_mutated_via_identity_link_id; grant_id:=new.last_mutated_by_admin_role_grant_id; action_value:=new.last_mutation_action_id; scope_type:=new.last_mutation_scope_type; scope_project:=new.last_mutation_scope_project_id; decision_id:=new.last_authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.mutation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id=new.last_mutation_action_id and operation_generation=new.mutation_generation and status='committed'; elsif tg_table_name='guide_source_snapshots' then if tg_op='UPDATE' and (new.project_id,new.guide_id,new.guide_version, new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) is distinct from (old.project_id,old.guide_id,old.guide_version, old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then raise exception 'guide source snapshot content is immutable' using errcode='23514'; end if; if new.creation_generation is null then raise exception 'new source snapshots require creation authority' using errcode='23514'; end if; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.creation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id='project.guide_source_snapshot.create' and operation_generation=new.creation_generation and status='committed'; else if new.authorization_action_id is null then return null; end if; actor_id:=new.authorized_by_actor_profile_id; link_id:=new.authorized_via_identity_link_id; grant_id:=new.authorized_by_admin_role_grant_id; action_value:=new.authorization_action_id; scope_type:=new.authorization_scope_type; scope_project:=new.authorization_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.source_snapshot_id; select * into reservation from guide_mutation_idempotency_records where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' and status='committed'; product_generation:=reservation.operation_generation; end if; if reservation.id is null or product_resource is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.resource_id is distinct from product_resource or reservation.operation_generation is distinct from product_generation or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'guide mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.guide.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'guide mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_guide_mutation_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_guide_source_snapshot_items() RETURNS trigger LANGUAGE plpgsql AS $function$ declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; begin select snapshot.manifest_json::jsonb->'items' into expected from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; if expected is null then raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; end if; select coalesce(jsonb_agg(jsonb_build_object( 'item_id',id,'item_order',item_order,'source_kind',source_kind, 'source_label',source_label,'ingestion_adapter',ingestion_adapter, 'media_type',media_type) order by item_order),'[]'::jsonb) into actual from guide_source_snapshot_items where source_snapshot_id=new.source_snapshot_id; if actual is distinct from expected then raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; end if; select r.* into reservation from guide_mutation_idempotency_records r join guide_source_snapshots s on s.id=r.resource_id where s.id=new.source_snapshot_id and r.action_id='project.guide_source_snapshot.create' and r.operation_generation=s.creation_generation and r.status='committed'; if reservation.id is null then raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_guide_source_snapshot_items" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_linked_authority_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare record_row authority_idempotency_records%rowtype; cause_row audit_events%rowtype; expected_permission text; expected_resource text; expected_invalidation_resource text; expected_invalidation_id text; valid_success boolean; begin if new.event_domain <> 'authority' then return new; end if; valid_success := new.event_type in ( 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', 'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued','ProjectRoleGrantRevoked', 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then if new.idempotency_reference is not null then raise exception 'invalid authority idempotency event' using errcode='23514'; end if; return new; end if; if new.idempotency_reference is null then raise exception 'authority event requires idempotency reference' using errcode='23514'; end if; select * into record_row from authority_idempotency_records where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; expected_permission := case record_row.operation when 'service_actor.create' then 'actor.service.provision' when 'admin_role_grant.issue' then 'admin_role.grant' when 'admin_role_grant.revoke' then 'admin_role.revoke' when 'project_role_grant.issue' then 'project.role_grant.manage' when 'project_role_grant.revoke' then 'project.role_grant.manage' when 'actor_profile.suspend' then 'actor.profile.suspend' when 'actor_profile.reactivate' then 'actor.profile.reactivate' when 'actor_profile.deactivate' then 'actor.profile.deactivate' when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; expected_resource := case when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' when record_row.operation like 'project_role_grant.%' then 'project_role_grant' else 'actor_identity_link' end; if new.permission_id <> expected_permission or new.resource_id is null then raise exception 'authority event does not match operation' using errcode='23514'; end if; if new.event_type='ProjectRoleQualificationSnapshotCaptured' then if record_row.operation <> 'project_role_grant.issue' or new.resource_type <> 'qualification_snapshot' or new.entity_type <> 'qualification_snapshot' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'qualification_snapshot' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or exists(select 1 from audit_events where idempotency_reference=record_row.id) then raise exception 'invalid project role qualification evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='ProjectRoleGrantIssued' then select * into cause_row from audit_events where idempotency_reference=record_row.id and event_type='ProjectRoleQualificationSnapshotCaptured'; if not found or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.matched_grant_id is distinct from new.matched_grant_id or new.resource_type <> 'project_role_grant' or new.entity_type <> 'project_role_grant' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null then raise exception 'invalid project role issue evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.revoke' and new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from 'actor_profile' or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.resource_type <> 'project_role_grant' or cause_row.target_ref_kind <> 'project_role_grant' or cause_row.target_ref_id is distinct from cause_row.resource_id or new.resource_type <> 'project_role_grant' or new.resource_id is distinct from cause_row.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from cause_row.resource_id or new.invalidation_target_kind <> 'project_role_grant' or new.invalidation_target_ref is distinct from cause_row.resource_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or new.before_facts::jsonb->>'effective' <> 'true' or new.after_facts::jsonb->>'effective' <> 'false' or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' or new.before_facts::jsonb->>'scope_type' <> 'project' or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then raise exception 'invalid project role revoke invalidation' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='AuthorityInvalidationRequested' then raise exception 'project role issue forbids invalidation' using errcode='23514'; elsif new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; expected_invalidation_resource := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then 'actor_profile' else expected_resource end; expected_invalidation_id := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then cause_row.target_actor_ref else cause_row.resource_id end; if not found or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.resource_type is distinct from expected_resource or new.resource_type is distinct from expected_invalidation_resource or new.resource_id is distinct from expected_invalidation_id or new.invalidation_target_kind is distinct from expected_invalidation_resource or new.invalidation_target_ref is distinct from expected_invalidation_id or cause_row.target_ref_kind is distinct from cause_row.resource_type or cause_row.target_ref_id is distinct from cause_row.resource_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": false}'::jsonb or new.after_facts::jsonb <> '{\"effective\": true}'::jsonb)) or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": true}'::jsonb or new.after_facts::jsonb <> '{\"effective\": false}'::jsonb)) or not ( (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then raise exception 'invalid linked authority cause' using errcode='23514'; end if; else if new.resource_type <> expected_resource or new.entity_type <> expected_resource or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or not ( (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then raise exception 'authority success event does not match operation' using errcode='23514'; end if; end if; return new; end $function$", - "name": "validate_linked_authority_event" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_policy_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_guide text; product_id text; product_generation integer; product_hash text; predecessor_id text; predecessor_hash text; selector_id text; selector_generation integer; selector_hash text; predecessor_valid boolean; begin if tg_table_name='policy_mutation_idempotency_records' then select * into reservation from policy_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id='project.review_policy.update' then select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_review_policy_id, g.selected_review_policy_generation,g.selected_review_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from review_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_revision_policy_id, g.selected_revision_policy_generation,g.selected_revision_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from revision_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; end if; else actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_id:=new.id; product_generation:=new.policy_generation; product_hash:=new.policy_hash; predecessor_id:=new.supersedes_policy_id; predecessor_hash:=new.predecessor_policy_hash; if tg_table_name='review_policies' then select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, g.selected_review_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; else select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, g.selected_revision_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; end if; select r.* into reservation from policy_mutation_idempotency_records r where r.policy_id=new.id and r.action_id=new.creation_action_id and r.policy_generation=new.policy_generation and r.status='committed'; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.guide_id is distinct from product_guide or reservation.policy_id is distinct from product_id or reservation.policy_generation is distinct from product_generation or reservation.policy_hash is distinct from product_hash or selector_id is distinct from product_id or selector_generation is distinct from product_generation or selector_hash is distinct from product_hash or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'policy mutation custody mismatch' using errcode='23514'; end if; if product_generation=1 then predecessor_valid:=predecessor_id is null and predecessor_hash is null; elsif reservation.action_id='project.review_policy.update' then select exists(select 1 from review_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; else select exists(select 1 from revision_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; end if; if predecessor_valid is not true then raise exception 'policy mutation lineage mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.review_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'policy mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_policy_mutation_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_project_create_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; evidence audit_events%rowtype; begin if tg_table_name = 'projects' then if tg_op = 'INSERT' and new.creation_action_id is null then raise exception 'new projects require creation authority' using errcode='23514'; end if; if new.creation_action_id is null then return null; end if; project_row := new; select * into reservation from project_create_idempotency_records where project_id=project_row.id and status='committed'; else select * into reservation from project_create_idempotency_records where id=new.id; if reservation.status <> 'committed' then raise exception 'pending project create reservation cannot commit' using errcode='23514'; end if; select * into project_row from projects where id=reservation.project_id; end if; if project_row.id is null or reservation.id is null or project_row.created_by_actor_profile_id is distinct from reservation.actor_profile_id or project_row.created_via_identity_link_id is distinct from reservation.identity_link_id or project_row.creation_action_id is distinct from reservation.action_id then raise exception 'project create custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=project_row.authorization_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from project_row.created_by_actor_profile_id or evidence.matched_grant_id is distinct from project_row.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.create' or evidence.action_id is distinct from 'project.create' or evidence.resource_type is distinct from 'project_create_operation' or evidence.resource_id is distinct from reservation.operation_id::text or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from project_row.id or evidence.after_facts->>'allowed' is distinct from 'true' or coalesce( evidence.after_facts->>'resource_context_digest' !~ '^sha256:[0-9a-f]{64}$', true ) then raise exception 'project create evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_project_create_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_review_active_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare queue_row review_queue_entries%rowtype; active_count integer; begin if tg_table_name='review_queue_entries' then queue_row := new; else select * into queue_row from review_queue_entries where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); end if; if not found and tg_table_name='review_leases' then raise exception 'review lease queue is missing' using errcode='23514'; end if; select count(*) into active_count from review_leases where review_queue_entry_id=queue_row.id and status='active'; if queue_row.queue_state='leased' then if queue_row.active_lease_id is null or active_count <> 1 or not exists( select 1 from review_leases where id=queue_row.active_lease_id and review_queue_entry_id=queue_row.id and status='active' ) then raise exception 'leased queue must identify its active lease' using errcode='23514'; end if; elsif queue_row.active_lease_id is not null or active_count <> 0 then raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; end if; return null; end $function$", - "name": "validate_review_active_lease" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_authority_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; action_value varchar; decision_id varchar; product_project varchar; product_id varchar; approval_outputs_valid boolean; begin if tg_table_name='submission_policy_mutation_idempotency_records' then if new.status='pending' then return null; end if; reservation:=new; select project_id,id, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_actor_profile_id else created_by_actor_profile_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_via_identity_link_id else created_via_identity_link_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_admin_role_grant_id else created_by_admin_role_grant_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then null else created_by_service_identity end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_action_id else creation_action_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_decision_event_id else creation_decision_event_id end into product_project,product_id,actor_id,link_id,grant_id,service_id, action_value,decision_id from submission_artifact_policies where id=reservation.committed_policy_id; if reservation.action_id='project.submission_artifact_policy.approve' then select exists( select 1 from submission_artifact_policies s join effective_project_submission_artifact_policies e on e.id=reservation.committed_effective_policy_id and e.submission_artifact_policy_id=s.id and e.submission_artifact_policy_hash=s.policy_hash join pre_submit_checker_policies p on p.id=reservation.committed_pre_submit_policy_id and p.project_id=e.project_id where s.id=reservation.committed_policy_id and s.id=reservation.policy_id and s.guide_id=reservation.guide_id and s.source_snapshot_id=reservation.source_snapshot_id and s.guide_version=reservation.resource_context_json->>'guide_version' and s.policy_hash=reservation.resource_context_json->>'policy_digest' and e.effective_policy_hash= reservation.resource_context_json->>'effective_output_digest' and p.compiled_bundle_hash= reservation.resource_context_json->>'compiled_pre_submit_output_digest' and e.project_id=reservation.project_id and e.guide_id=s.guide_id and p.guide_id=s.guide_id and e.guide_version=s.guide_version and p.guide_version=s.guide_version and e.source_snapshot_id=s.source_snapshot_id and p.source_snapshot_id=s.source_snapshot_id and e.source_snapshot_hash=s.source_snapshot_hash and p.source_snapshot_hash=s.source_snapshot_hash and e.submission_artifact_policy_id=reservation.committed_policy_id and p.effective_policy_id=e.id and p.effective_policy_hash=e.effective_policy_hash and e.created_by_actor_profile_id=reservation.actor_profile_id and p.created_by_actor_profile_id=reservation.actor_profile_id and e.created_via_identity_link_id=reservation.identity_link_id and p.created_via_identity_link_id=reservation.identity_link_id and e.created_by_admin_role_grant_id=grant_id and p.created_by_admin_role_grant_id=grant_id and e.creation_scope_project_id=reservation.project_id and p.creation_scope_project_id=reservation.project_id and e.creation_action_id=reservation.action_id and p.creation_action_id=reservation.action_id and e.creation_decision_event_id=decision_id and p.creation_decision_event_id=decision_id ) into approval_outputs_valid; if approval_outputs_valid is not true then raise exception 'submission-policy approval output custody mismatch' using errcode='23514'; end if; end if; elsif tg_table_name='submission_artifact_policies' then if new.creation_action_id is null and new.approval_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null or new.approved_by_actor_profile_id is not null or new.approved_via_identity_link_id is not null or new.approved_by_admin_role_grant_id is not null or new.approval_scope_type is not null or new.approval_scope_project_id is not null or new.approval_decision_event_id is not null then raise exception 'partial submission-policy provenance' using errcode='23514'; end if; return null; end if; if new.approval_action_id is not null then select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.approval_action_id and status='committed'; actor_id:=new.approved_by_actor_profile_id; link_id:=new.approved_via_identity_link_id; grant_id:=new.approved_by_admin_role_grant_id; service_id:=null; action_value:=new.approval_action_id; decision_id:=new.approval_decision_event_id; else select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=new.created_by_service_identity; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; end if; product_project:=new.project_id; product_id:=new.id; elsif tg_table_name='effective_project_submission_artifact_policies' then if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial effective-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_effective_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; else if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial pre-submit-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_pre_submit_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.committed_policy_id is distinct from product_id or reservation.service_identity is distinct from service_id then raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from product_id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy authorization evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_submission_policy_authority_custody" - }, - { - "arguments": "", - "definition": "CREATE OR REPLACE FUNCTION public.validate_submission_policy_creation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; begin if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial submission-policy creation provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; if reservation.id is null or reservation.actor_profile_id is distinct from new.created_by_actor_profile_id or reservation.identity_link_id is distinct from new.created_via_identity_link_id or reservation.service_identity is distinct from new.created_by_service_identity or reservation.project_id is distinct from new.project_id or reservation.policy_id is distinct from new.id or reservation.guide_id is distinct from new.guide_id or reservation.source_snapshot_id is distinct from new.source_snapshot_id or reservation.resource_context_json->>'guide_version' is distinct from new.guide_version then raise exception 'submission-policy creation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=new.creation_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from new.created_by_actor_profile_id or evidence.matched_grant_id is distinct from new.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from new.creation_action_id or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from new.id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy creation evidence mismatch' using errcode='23514'; end if; return null; end $function$", - "name": "validate_submission_policy_creation_custody" - } - ], - "sequences": [ - { - "cache_size": 1, - "cycle": false, - "data_type": "integer", - "increment_by": 1, - "is_called": false, - "last_value": 1, - "max_value": 2147483647, - "min_value": 1, - "name": "actor_profile_migration_state_id_seq", - "start_value": 1 - }, - { - "cache_size": 1, - "cycle": false, - "data_type": "smallint", - "increment_by": 1, - "is_called": false, - "last_value": 1, - "max_value": 32767, - "min_value": 1, - "name": "authority_control_id_seq", - "start_value": 1 - } - ], - "tables": [ - { - "force_row_security": false, - "kind": "r", - "name": "actor_identity_links", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "actor_profile_migration_state", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "actor_profiles", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "admin_role_grants", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "api_rate_control_counters", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_admission_charges", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_admission_scopes", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_bindings", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_contents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_operation_receipts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_put_attempt_charges", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_put_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_put_observation_receipts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_recovery_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_replicas", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_storage_namespaces", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_verification_jobs", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "artifact_verification_receipts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "audit_events", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "authority_control", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "authority_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "checker_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "checker_results", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "checker_runs", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_award_definitions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_policy_versions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "contribution_rules", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "effective_project_submission_artifact_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "evidence_items", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_artifact_bindings", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_artifact_incidents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_artifact_ingests", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extracted_contents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extraction_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extraction_retry_budgets", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_extraction_usages", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_format_classifications", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_snapshot_items", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_source_snapshots", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_sufficiency_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_sufficiency_report_source_usages", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "guide_sufficiency_reports", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "iso_4217_currency_codes", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "legacy_actor_identities", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "legacy_workflow_eligibility", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "outbox_events", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "payment_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "policy_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "pre_submit_checker_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "pre_submit_evidence_results", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "pre_submit_evidence_sets", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_compensation_adapter_bindings", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_compensation_units", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_create_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_guide_compilation_attempts", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_guide_compilations", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_guides", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_role_grants", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_role_qualification_snapshots", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "project_setup_runs", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "projects", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_admission_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_leases", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "review_queue_entries", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "revision_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_artifact_policies", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_bundle_admissions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_bundle_durable_intents", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submission_policy_mutation_idempotency_records", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "submissions", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "task_assignments", - "persistence": "p", - "row_security": false - }, - { - "force_row_security": false, - "kind": "r", - "name": "workstream_tasks", - "persistence": "p", - "row_security": false - } - ], - "triggers": [ - { - "definition": "CREATE TRIGGER actor_identity_link_history_guard BEFORE DELETE OR UPDATE ON actor_identity_links FOR EACH ROW EXECUTE FUNCTION guard_actor_identity_link_history()", - "enabled": "O", - "name": "actor_identity_link_history_guard", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER actor_identity_link_profile_guard AFTER INSERT OR UPDATE ON actor_identity_links DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", - "enabled": "O", - "name": "actor_identity_link_profile_guard", - "table_name": "actor_identity_links" - }, - { - "definition": "CREATE TRIGGER service_identity_migration_evidence_row_guard BEFORE DELETE OR UPDATE ON actor_profile_migration_state FOR EACH ROW EXECUTE FUNCTION guard_service_identity_migration_evidence()", - "enabled": "O", - "name": "service_identity_migration_evidence_row_guard", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CREATE TRIGGER service_identity_migration_evidence_truncate_guard BEFORE TRUNCATE ON actor_profile_migration_state FOR EACH STATEMENT EXECUTE FUNCTION guard_service_identity_migration_evidence()", - "enabled": "O", - "name": "service_identity_migration_evidence_truncate_guard", - "table_name": "actor_profile_migration_state" - }, - { - "definition": "CREATE TRIGGER actor_profile_history_guard BEFORE DELETE OR UPDATE ON actor_profiles FOR EACH ROW EXECUTE FUNCTION guard_actor_profile_history()", - "enabled": "O", - "name": "actor_profile_history_guard", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER actor_profile_link_guard AFTER INSERT OR UPDATE ON actor_profiles DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()", - "enabled": "O", - "name": "actor_profile_link_guard", - "table_name": "actor_profiles" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER admin_role_grants_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON admin_role_grants DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", - "enabled": "O", - "name": "admin_role_grants_bootstrap_invariant", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE TRIGGER admin_role_grants_guard BEFORE INSERT OR DELETE OR UPDATE ON admin_role_grants FOR EACH ROW EXECUTE FUNCTION guard_admin_role_grant()", - "enabled": "O", - "name": "admin_role_grants_guard", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE TRIGGER admin_role_grants_reject_truncate BEFORE TRUNCATE ON admin_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_admin_role_grant_truncate()", - "enabled": "O", - "name": "admin_role_grants_reject_truncate", - "table_name": "admin_role_grants" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER trg_artifact_binding_history AFTER INSERT ON artifact_bindings DEFERRABLE INITIALLY IMMEDIATE FOR EACH ROW EXECUTE FUNCTION validate_artifact_binding_history()", - "enabled": "O", - "name": "trg_artifact_binding_history", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE TRIGGER trg_artifact_bindings_immutable BEFORE DELETE OR UPDATE ON artifact_bindings FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_bindings_immutable", - "table_name": "artifact_bindings" - }, - { - "definition": "CREATE TRIGGER trg_artifact_contents_immutable BEFORE DELETE OR UPDATE ON artifact_contents FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_contents_immutable", - "table_name": "artifact_contents" - }, - { - "definition": "CREATE TRIGGER artifact_receipt_producer_reference BEFORE INSERT OR UPDATE OF put_attempt_id, guide_source_item_id, checker_run_id, logical_role ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION guard_artifact_receipt_producer_reference()", - "enabled": "O", - "name": "artifact_receipt_producer_reference", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE TRIGGER trg_artifact_operation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_operation_receipts_immutable", - "table_name": "artifact_operation_receipts" - }, - { - "definition": "CREATE TRIGGER trg_artifact_put_observation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_put_observation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_put_observation_receipts_immutable", - "table_name": "artifact_put_observation_receipts" - }, - { - "definition": "CREATE TRIGGER artifact_recovery_attempt_custody BEFORE INSERT OR DELETE OR UPDATE ON artifact_recovery_attempts FOR EACH ROW EXECUTE FUNCTION validate_artifact_recovery_attempt()", - "enabled": "O", - "name": "artifact_recovery_attempt_custody", - "table_name": "artifact_recovery_attempts" - }, - { - "definition": "CREATE TRIGGER trg_artifact_storage_namespaces_immutable BEFORE DELETE OR UPDATE ON artifact_storage_namespaces FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_storage_namespaces_immutable", - "table_name": "artifact_storage_namespaces" - }, - { - "definition": "CREATE TRIGGER artifact_verification_lineage_custody BEFORE UPDATE ON artifact_verification_jobs FOR EACH ROW EXECUTE FUNCTION validate_artifact_verification_lineage()", - "enabled": "O", - "name": "artifact_verification_lineage_custody", - "table_name": "artifact_verification_jobs" - }, - { - "definition": "CREATE TRIGGER trg_artifact_verification_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_verification_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()", - "enabled": "O", - "name": "trg_artifact_verification_receipts_immutable", - "table_name": "artifact_verification_receipts" - }, - { - "definition": "CREATE TRIGGER audit_events_reject_truncate BEFORE TRUNCATE ON audit_events FOR EACH STATEMENT EXECUTE FUNCTION reject_audit_event_mutation()", - "enabled": "O", - "name": "audit_events_reject_truncate", - "table_name": "audit_events" - }, - { - "definition": "CREATE TRIGGER audit_events_reject_update_delete BEFORE DELETE OR UPDATE ON audit_events FOR EACH ROW EXECUTE FUNCTION reject_audit_event_mutation()", - "enabled": "O", - "name": "audit_events_reject_update_delete", - "table_name": "audit_events" - }, - { - "definition": "CREATE TRIGGER audit_events_set_authority_time BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION set_authority_audit_database_time()", - "enabled": "O", - "name": "audit_events_set_authority_time", - "table_name": "audit_events" - }, - { - "definition": "CREATE TRIGGER audit_events_validate_idempotency BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION validate_linked_authority_event()", - "enabled": "O", - "name": "audit_events_validate_idempotency", - "table_name": "audit_events" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER authority_control_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON authority_control DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()", - "enabled": "O", - "name": "authority_control_bootstrap_invariant", - "table_name": "authority_control" - }, - { - "definition": "CREATE TRIGGER authority_control_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_control FOR EACH ROW EXECUTE FUNCTION guard_authority_control()", - "enabled": "O", - "name": "authority_control_guard", - "table_name": "authority_control" - }, - { - "definition": "CREATE TRIGGER authority_control_reject_truncate BEFORE TRUNCATE ON authority_control FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_control_truncate()", - "enabled": "O", - "name": "authority_control_reject_truncate", - "table_name": "authority_control" - }, - { - "definition": "CREATE TRIGGER authority_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_authority_idempotency_record()", - "enabled": "O", - "name": "authority_idempotency_guard", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER authority_idempotency_pending_guard AFTER INSERT OR UPDATE ON authority_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION reject_pending_authority_idempotency()", - "enabled": "O", - "name": "authority_idempotency_pending_guard", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE TRIGGER authority_idempotency_reject_truncate BEFORE TRUNCATE ON authority_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_idempotency_truncate()", - "enabled": "O", - "name": "authority_idempotency_reject_truncate", - "table_name": "authority_idempotency_records" - }, - { - "definition": "CREATE TRIGGER contribution_award_definitions_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_award_definitions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", - "enabled": "O", - "name": "contribution_award_definitions_content_guard", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_award_definitions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_award_definitions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_award_definitions_graph_guard", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE TRIGGER contribution_award_definitions_reject_truncate BEFORE TRUNCATE ON contribution_award_definitions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_award_definitions_reject_truncate", - "table_name": "contribution_award_definitions" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_policies_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_policies_graph_guard", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE TRIGGER contribution_policies_reject_truncate BEFORE TRUNCATE ON contribution_policies FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_policies_reject_truncate", - "table_name": "contribution_policies" - }, - { - "definition": "CREATE TRIGGER contribution_policy_versions_content_guard BEFORE DELETE OR UPDATE ON contribution_policy_versions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_version_content()", - "enabled": "O", - "name": "contribution_policy_versions_content_guard", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_policy_versions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policy_versions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_policy_versions_graph_guard", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE TRIGGER contribution_policy_versions_reject_truncate BEFORE TRUNCATE ON contribution_policy_versions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_policy_versions_reject_truncate", - "table_name": "contribution_policy_versions" - }, - { - "definition": "CREATE TRIGGER contribution_rules_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_rules FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()", - "enabled": "O", - "name": "contribution_rules_content_guard", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER contribution_rules_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_rules DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()", - "enabled": "O", - "name": "contribution_rules_graph_guard", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE TRIGGER contribution_rules_reject_truncate BEFORE TRUNCATE ON contribution_rules FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "contribution_rules_reject_truncate", - "table_name": "contribution_rules" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER effective_submission_policy_custody AFTER INSERT OR UPDATE ON effective_project_submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "effective_submission_policy_custody", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER effective_submission_policy_provenance_immutable BEFORE UPDATE ON effective_project_submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", - "enabled": "O", - "name": "effective_submission_policy_provenance_immutable", - "table_name": "effective_project_submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER guide_mutation_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON guide_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_guide_mutation_idempotency()", - "enabled": "O", - "name": "guide_mutation_idempotency_guard", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER guide_mutation_idempotency_reject_truncate BEFORE TRUNCATE ON guide_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_mutation_idempotency_truncate()", - "enabled": "O", - "name": "guide_mutation_idempotency_reject_truncate", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_reservation_custody AFTER INSERT OR UPDATE ON guide_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "guide_mutation_reservation_custody", - "table_name": "guide_mutation_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER guide_source_snapshot_items_custody AFTER INSERT ON guide_source_snapshot_items DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_source_snapshot_items()", - "enabled": "O", - "name": "guide_source_snapshot_items_custody", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE TRIGGER guide_source_snapshot_items_immutable BEFORE DELETE OR UPDATE OR TRUNCATE ON guide_source_snapshot_items FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_source_snapshot_item_mutation()", - "enabled": "O", - "name": "guide_source_snapshot_items_immutable", - "table_name": "guide_source_snapshot_items" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER source_snapshot_product_custody AFTER INSERT OR UPDATE ON guide_source_snapshots DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "source_snapshot_product_custody", - "table_name": "guide_source_snapshots" - }, - { - "definition": "CREATE TRIGGER trg_sufficiency_replay_immutable BEFORE DELETE OR UPDATE ON guide_sufficiency_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_sufficiency_replay_mutation()", - "enabled": "O", - "name": "trg_sufficiency_replay_immutable", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_sufficiency_replay_no_truncate BEFORE TRUNCATE ON guide_sufficiency_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_sufficiency_replay_truncate()", - "enabled": "O", - "name": "trg_sufficiency_replay_no_truncate", - "table_name": "guide_sufficiency_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER iso_4217_currency_codes_immutable BEFORE INSERT OR DELETE OR UPDATE ON iso_4217_currency_codes FOR EACH ROW EXECUTE FUNCTION guard_iso_4217_currency_codes()", - "enabled": "O", - "name": "iso_4217_currency_codes_immutable", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "CREATE TRIGGER iso_4217_currency_codes_reject_truncate BEFORE TRUNCATE ON iso_4217_currency_codes FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "iso_4217_currency_codes_reject_truncate", - "table_name": "iso_4217_currency_codes" - }, - { - "definition": "CREATE TRIGGER outbox_events_custody BEFORE INSERT OR DELETE OR UPDATE ON outbox_events FOR EACH ROW EXECUTE FUNCTION guard_outbox_event()", - "enabled": "O", - "name": "outbox_events_custody", - "table_name": "outbox_events" - }, - { - "definition": "CREATE TRIGGER outbox_events_reject_truncate BEFORE TRUNCATE ON outbox_events FOR EACH STATEMENT EXECUTE FUNCTION guard_outbox_event()", - "enabled": "O", - "name": "outbox_events_reject_truncate", - "table_name": "outbox_events" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER policy_mutation_replay_custody AFTER INSERT OR UPDATE ON policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", - "enabled": "O", - "name": "policy_mutation_replay_custody", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER policy_mutation_replay_immutable BEFORE INSERT OR DELETE OR UPDATE ON policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_policy_mutation_replay()", - "enabled": "O", - "name": "policy_mutation_replay_immutable", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER policy_mutation_replay_reject_truncate BEFORE TRUNCATE ON policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_policy_mutation_replay_truncate()", - "enabled": "O", - "name": "policy_mutation_replay_reject_truncate", - "table_name": "policy_mutation_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER pre_submit_policy_custody AFTER INSERT OR UPDATE ON pre_submit_checker_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "pre_submit_policy_custody", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE TRIGGER pre_submit_policy_provenance_immutable BEFORE UPDATE ON pre_submit_checker_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()", - "enabled": "O", - "name": "pre_submit_policy_provenance_immutable", - "table_name": "pre_submit_checker_policies" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_results_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_results_immutable", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_results_membership BEFORE INSERT ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_result_membership()", - "enabled": "O", - "name": "pre_submit_evidence_results_membership", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_results_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_results FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_results_no_truncate", - "table_name": "pre_submit_evidence_results" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_sets_creation BEFORE INSERT ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_set_creation()", - "enabled": "O", - "name": "pre_submit_evidence_sets_creation", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_sets_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_sets_immutable", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE TRIGGER pre_submit_evidence_sets_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_sets FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()", - "enabled": "O", - "name": "pre_submit_evidence_sets_no_truncate", - "table_name": "pre_submit_evidence_sets" - }, - { - "definition": "CREATE TRIGGER project_compensation_binding_update_guard BEFORE UPDATE ON project_compensation_adapter_bindings FOR EACH ROW EXECUTE FUNCTION enforce_compensation_binding_lifecycle()", - "enabled": "O", - "name": "project_compensation_binding_update_guard", - "table_name": "project_compensation_adapter_bindings" - }, - { - "definition": "CREATE TRIGGER project_compensation_units_lifecycle_guard BEFORE INSERT OR DELETE OR UPDATE ON project_compensation_units FOR EACH ROW EXECUTE FUNCTION guard_project_compensation_units()", - "enabled": "O", - "name": "project_compensation_units_lifecycle_guard", - "table_name": "project_compensation_units" - }, - { - "definition": "CREATE TRIGGER project_compensation_units_reject_truncate BEFORE TRUNCATE ON project_compensation_units FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()", - "enabled": "O", - "name": "project_compensation_units_reject_truncate", - "table_name": "project_compensation_units" - }, - { - "definition": "CREATE TRIGGER project_create_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON project_create_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_project_create_idempotency()", - "enabled": "O", - "name": "project_create_idempotency_guard", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE TRIGGER project_create_idempotency_reject_truncate BEFORE TRUNCATE ON project_create_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_project_create_idempotency_truncate()", - "enabled": "O", - "name": "project_create_idempotency_reject_truncate", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER project_create_reservation_custody AFTER INSERT OR UPDATE ON project_create_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", - "enabled": "O", - "name": "project_create_reservation_custody", - "table_name": "project_create_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_compilation_attempt_delete BEFORE DELETE OR TRUNCATE ON project_guide_compilation_attempts FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", - "enabled": "O", - "name": "trg_compilation_attempt_delete", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE TRIGGER trg_compilation_attempt_update BEFORE UPDATE ON project_guide_compilation_attempts FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_attempt_update()", - "enabled": "O", - "name": "trg_compilation_attempt_update", - "table_name": "project_guide_compilation_attempts" - }, - { - "definition": "CREATE TRIGGER trg_compilation_insert BEFORE INSERT ON project_guide_compilations FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_insert()", - "enabled": "O", - "name": "trg_compilation_insert", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE TRIGGER trg_compilation_mutation BEFORE DELETE OR UPDATE OR TRUNCATE ON project_guide_compilations FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()", - "enabled": "O", - "name": "trg_compilation_mutation", - "table_name": "project_guide_compilations" - }, - { - "definition": "CREATE TRIGGER guide_lineage_lifecycle_guard BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_guide_lineage_and_lifecycle()", - "enabled": "O", - "name": "guide_lineage_lifecycle_guard", - "table_name": "project_guides" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER guide_mutation_product_custody AFTER INSERT OR UPDATE ON project_guides DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "guide_mutation_product_custody", - "table_name": "project_guides" - }, - { - "definition": "CREATE TRIGGER project_guides_policy_selection_immutable BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_project_guide_policy_selection()", - "enabled": "O", - "name": "project_guides_policy_selection_immutable", - "table_name": "project_guides" - }, - { - "definition": "CREATE TRIGGER trg_project_role_grants_history BEFORE INSERT OR DELETE OR UPDATE ON project_role_grants FOR EACH ROW EXECUTE FUNCTION guard_project_role_grant_history()", - "enabled": "O", - "name": "trg_project_role_grants_history", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE TRIGGER trg_project_role_grants_reject_truncate BEFORE TRUNCATE ON project_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", - "enabled": "O", - "name": "trg_project_role_grants_reject_truncate", - "table_name": "project_role_grants" - }, - { - "definition": "CREATE TRIGGER trg_project_role_qualification_snapshots_immutable BEFORE INSERT OR DELETE OR UPDATE ON project_role_qualification_snapshots FOR EACH ROW EXECUTE FUNCTION guard_project_role_snapshot_history()", - "enabled": "O", - "name": "trg_project_role_qualification_snapshots_immutable", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE TRIGGER trg_project_role_snapshots_reject_truncate BEFORE TRUNCATE ON project_role_qualification_snapshots FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()", - "enabled": "O", - "name": "trg_project_role_snapshots_reject_truncate", - "table_name": "project_role_qualification_snapshots" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER source_setup_run_custody AFTER INSERT OR UPDATE ON project_setup_runs DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()", - "enabled": "O", - "name": "source_setup_run_custody", - "table_name": "project_setup_runs" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER project_creation_custody AFTER INSERT OR UPDATE OF created_by_actor_profile_id, created_via_identity_link_id, created_by_admin_role_grant_id, creation_scope_type, creation_action_id, authorization_decision_event_id ON projects DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()", - "enabled": "O", - "name": "project_creation_custody", - "table_name": "projects" - }, - { - "definition": "CREATE TRIGGER review_admission_idempotency_records_reject_truncate BEFORE TRUNCATE ON review_admission_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", - "enabled": "O", - "name": "review_admission_idempotency_records_reject_truncate", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE TRIGGER review_admission_records_guard BEFORE INSERT OR DELETE OR UPDATE ON review_admission_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_review_admission_record()", - "enabled": "O", - "name": "review_admission_records_guard", - "table_name": "review_admission_idempotency_records" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER review_leases_active_lease_guard AFTER INSERT OR UPDATE ON review_leases DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", - "enabled": "O", - "name": "review_leases_active_lease_guard", - "table_name": "review_leases" - }, - { - "definition": "CREATE TRIGGER review_leases_guard BEFORE INSERT OR DELETE OR UPDATE ON review_leases FOR EACH ROW EXECUTE FUNCTION guard_review_lease()", - "enabled": "O", - "name": "review_leases_guard", - "table_name": "review_leases" - }, - { - "definition": "CREATE TRIGGER review_leases_reject_truncate BEFORE TRUNCATE ON review_leases FOR EACH STATEMENT EXECUTE FUNCTION reject_review_lease_truncate()", - "enabled": "O", - "name": "review_leases_reject_truncate", - "table_name": "review_leases" - }, - { - "definition": "CREATE TRIGGER review_policies_immutable BEFORE DELETE OR UPDATE ON review_policies FOR EACH ROW EXECUTE FUNCTION guard_review_policies_immutable()", - "enabled": "O", - "name": "review_policies_immutable", - "table_name": "review_policies" - }, - { - "definition": "CREATE TRIGGER review_policies_reject_truncate BEFORE TRUNCATE ON review_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_review_policies_immutable()", - "enabled": "O", - "name": "review_policies_reject_truncate", - "table_name": "review_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER review_policy_mutation_custody AFTER INSERT OR UPDATE ON review_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", - "enabled": "O", - "name": "review_policy_mutation_custody", - "table_name": "review_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER review_queue_entries_active_lease_guard AFTER INSERT OR UPDATE ON review_queue_entries DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()", - "enabled": "O", - "name": "review_queue_entries_active_lease_guard", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE TRIGGER review_queue_entries_guard BEFORE INSERT OR DELETE OR UPDATE ON review_queue_entries FOR EACH ROW EXECUTE FUNCTION guard_review_queue_entry()", - "enabled": "O", - "name": "review_queue_entries_guard", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE TRIGGER review_queue_entries_reject_truncate BEFORE TRUNCATE ON review_queue_entries FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()", - "enabled": "O", - "name": "review_queue_entries_reject_truncate", - "table_name": "review_queue_entries" - }, - { - "definition": "CREATE TRIGGER revision_policies_immutable BEFORE DELETE OR UPDATE ON revision_policies FOR EACH ROW EXECUTE FUNCTION guard_revision_policies_immutable()", - "enabled": "O", - "name": "revision_policies_immutable", - "table_name": "revision_policies" - }, - { - "definition": "CREATE TRIGGER revision_policies_reject_truncate BEFORE TRUNCATE ON revision_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_revision_policies_immutable()", - "enabled": "O", - "name": "revision_policies_reject_truncate", - "table_name": "revision_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER revision_policy_mutation_custody AFTER INSERT OR UPDATE ON revision_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()", - "enabled": "O", - "name": "revision_policy_mutation_custody", - "table_name": "revision_policies" - }, - { - "definition": "CREATE TRIGGER submission_policy_approval_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_approval_provenance()", - "enabled": "O", - "name": "submission_policy_approval_provenance_immutable", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER submission_policy_creation_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_creation_custody()", - "enabled": "O", - "name": "submission_policy_creation_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER submission_policy_creation_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_creation_provenance()", - "enabled": "O", - "name": "submission_policy_creation_provenance_immutable", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER submission_policy_product_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "submission_policy_product_custody", - "table_name": "submission_artifact_policies" - }, - { - "definition": "CREATE TRIGGER submission_bundle_admission_delete BEFORE DELETE OR TRUNCATE ON submission_bundle_admissions FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_admission_delete()", - "enabled": "O", - "name": "submission_bundle_admission_delete", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE TRIGGER submission_bundle_admission_lineage BEFORE UPDATE ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_lineage()", - "enabled": "O", - "name": "submission_bundle_admission_lineage", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE TRIGGER submission_bundle_admission_verified_lineage BEFORE INSERT ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_verified_lineage()", - "enabled": "O", - "name": "submission_bundle_admission_verified_lineage", - "table_name": "submission_bundle_admissions" - }, - { - "definition": "CREATE TRIGGER submission_bundle_durable_intent_put_attempt BEFORE INSERT ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intent_put_attempt()", - "enabled": "O", - "name": "submission_bundle_durable_intent_put_attempt", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE TRIGGER submission_bundle_durable_intents_immutable BEFORE DELETE OR UPDATE ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", - "enabled": "O", - "name": "submission_bundle_durable_intents_immutable", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE TRIGGER submission_bundle_durable_intents_no_truncate BEFORE TRUNCATE ON submission_bundle_durable_intents FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()", - "enabled": "O", - "name": "submission_bundle_durable_intents_no_truncate", - "table_name": "submission_bundle_durable_intents" - }, - { - "definition": "CREATE CONSTRAINT TRIGGER submission_policy_replay_custody AFTER INSERT OR UPDATE ON submission_policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW WHEN (new.status::text = 'committed'::text) EXECUTE FUNCTION validate_submission_policy_authority_custody()", - "enabled": "O", - "name": "submission_policy_replay_custody", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_submission_policy_replay_immutable BEFORE DELETE OR UPDATE ON submission_policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_submission_policy_replay_mutation()", - "enabled": "O", - "name": "trg_submission_policy_replay_immutable", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER trg_submission_policy_replay_no_truncate BEFORE TRUNCATE ON submission_policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_submission_policy_replay_truncate()", - "enabled": "O", - "name": "trg_submission_policy_replay_no_truncate", - "table_name": "submission_policy_mutation_idempotency_records" - }, - { - "definition": "CREATE TRIGGER submissions_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON submissions FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", - "enabled": "O", - "name": "submissions_contributor_human", - "table_name": "submissions" - }, - { - "definition": "CREATE TRIGGER task_assignments_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON task_assignments FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')", - "enabled": "O", - "name": "task_assignments_contributor_human", - "table_name": "task_assignments" - } - ], - "types": [] -} +{"acl":[{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"actor_identity_links","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"actor_profile_migration_state","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"actor_profiles","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"admin_role_grants","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"api_rate_control_counters","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_charges","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_admission_scopes","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_bindings","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_contents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_operation_receipts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempt_charges","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_put_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_put_observation_receipts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_recovery_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_replicas","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_storage_namespaces","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_jobs","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"artifact_verification_receipts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"audit_events","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"authority_control","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"authority_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"checker_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"checker_results","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"checker_runs","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_award_definitions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_policy_versions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"contribution_rules","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"effective_project_submission_artifact_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"evidence_items","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_bindings","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_incidents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_artifact_ingests","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extracted_contents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_retry_budgets","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_extraction_usages","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_format_classifications","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshot_items","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_source_snapshots","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_report_source_usages","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"guide_sufficiency_reports","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"iso_4217_currency_codes","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"legacy_actor_identities","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"legacy_workflow_eligibility","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"outbox_events","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"payment_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"policy_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"pre_submit_checker_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_results","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"pre_submit_evidence_sets","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_compensation_adapter_bindings","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_compensation_units","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_create_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilation_attempts","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_guide_compilations","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_guides","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_role_grants","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_role_qualification_snapshots","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"project_setup_runs","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"projects","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_admission_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_leases","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"review_queue_entries","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"revision_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_artifact_policies","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_admissions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_bundle_durable_intents","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submission_policy_mutation_idempotency_records","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"submissions","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"task_assignments","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"DELETE"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"INSERT"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"REFERENCES"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"SELECT"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"TRIGGER"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"TRUNCATE"},{"grantable":"false","kind":"relation","name":"workstream_tasks","principal":"owner","privilege":"UPDATE"},{"grantable":"false","kind":"routine","name":"authority_event_facts_are_safe(event_name text, before_state js","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_event_facts_are_safe(event_name text, before_state js","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_facts_are_safe(facts json)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_facts_are_safe(facts json)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_grant_facts_are_safe(facts json, roles text[], expect","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"authority_grant_facts_are_safe(facts json, roles text[], expect","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"enforce_compensation_binding_lifecycle()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"enforce_compensation_binding_lifecycle()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_identity_link_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_identity_link_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_profile_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_actor_profile_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_admin_role_grant()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_admin_role_grant()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_artifact_receipt_producer_reference()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_artifact_receipt_producer_reference()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_control()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_control()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_idempotency_record()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_authority_idempotency_record()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_children()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_children()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_version_content()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_contribution_policy_version_content()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_lineage_and_lifecycle()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_lineage_and_lifecycle()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_mutation_idempotency()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_guide_mutation_idempotency()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_iso_4217_currency_codes()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_iso_4217_currency_codes()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_outbox_event()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_outbox_event()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_policy_mutation_replay()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_policy_mutation_replay()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_result_membership()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_result_membership()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_results_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_results_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_set_creation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_set_creation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_sets_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_pre_submit_evidence_sets_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_compensation_units()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_compensation_units()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_create_idempotency()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_create_idempotency()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_attempt_update()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_attempt_update()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_insert()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_compilation_insert()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_policy_selection()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_guide_policy_selection()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_grant_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_grant_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_snapshot_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_project_role_snapshot_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_admission_record()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_admission_record()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_lease()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_lease()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_policies_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_policies_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_queue_entry()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_review_queue_entry()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_revision_policies_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_revision_policies_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_service_identity_migration_evidence()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_service_identity_migration_evidence()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_delete()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_delete()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_lineage()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_lineage()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_verified_lineage()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_admission_verified_lineage()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intent_put_attempt()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intent_put_attempt()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intents_immutable()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"guard_submission_bundle_durable_intents_immutable()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_availability_is_safe(value jsonb)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_availability_is_safe(value jsonb)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reason_is_safe(value text)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reason_is_safe(value text)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_array_is_safe(value jsonb, uuid_only boo","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_array_is_safe(value jsonb, uuid_only boo","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_token_is_safe(value text)","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"project_role_reference_token_is_safe(value text)","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_approval_provenance()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_approval_provenance()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_creation_provenance()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_creation_provenance()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_output_provenance()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"protect_submission_policy_output_provenance()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_admin_role_grant_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_admin_role_grant_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_artifact_fact_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_artifact_fact_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_audit_event_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_audit_event_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_control_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_control_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_idempotency_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_authority_idempotency_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_contribution_policy_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_contribution_policy_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_mutation_idempotency_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_mutation_idempotency_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_source_snapshot_item_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_guide_source_snapshot_item_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_pending_authority_idempotency()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_pending_authority_idempotency()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_policy_mutation_replay_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_policy_mutation_replay_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_create_idempotency_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_create_idempotency_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_guide_compilation_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_guide_compilation_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_role_history_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_project_role_history_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_lease_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_lease_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_queue_foundation_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_review_queue_foundation_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_submission_policy_replay_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_mutation()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_mutation()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_truncate()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"reject_sufficiency_replay_truncate()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"require_human_actor_profile_reference()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"require_human_actor_profile_reference()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"set_authority_audit_database_time()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"set_authority_audit_database_time()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_binding_history()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_binding_history()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_recovery_attempt()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_recovery_attempt()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_verification_lineage()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_artifact_verification_lineage()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_bootstrap_authority_state()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_bootstrap_authority_state()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_canonical_actor_link()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_canonical_actor_link()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_contribution_policy_graph()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_contribution_policy_graph()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_mutation_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_mutation_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_source_snapshot_items()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_guide_source_snapshot_items()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_linked_authority_event()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_linked_authority_event()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_policy_mutation_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_policy_mutation_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_project_create_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_project_create_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_review_active_lease()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_review_active_lease()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_authority_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_authority_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_creation_custody()","principal":"PUBLIC","privilege":"EXECUTE"},{"grantable":"false","kind":"routine","name":"validate_submission_policy_creation_custody()","principal":"owner","privilege":"EXECUTE"},{"grantable":"false","kind":"sequence","name":"actor_profile_migration_state_id_seq","principal":"owner","privilege":"USAGE"},{"grantable":"false","kind":"sequence","name":"authority_control_id_seq","principal":"owner","privilege":"USAGE"}],"auxiliary_objects":[],"columns":[{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"actor_identity_links"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"actor_identity_links"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"issuer","not_null":true,"ordinal":3,"table_name":"actor_identity_links"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"subject","not_null":true,"ordinal":4,"table_name":"actor_identity_links"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"subject_kind","not_null":true,"ordinal":5,"table_name":"actor_identity_links"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"actor_identity_links"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"linked_by","not_null":true,"ordinal":7,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"linked_at","not_null":true,"ordinal":8,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_verified_at","not_null":false,"ordinal":9,"table_name":"actor_identity_links"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by","not_null":false,"ordinal":10,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_at","not_null":false,"ordinal":11,"table_name":"actor_identity_links"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_reason","not_null":false,"ordinal":12,"table_name":"actor_identity_links"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_by","not_null":false,"ordinal":13,"table_name":"actor_identity_links"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_at","not_null":false,"ordinal":14,"table_name":"actor_identity_links"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivation_reason","not_null":false,"ordinal":15,"table_name":"actor_identity_links"},{"data_type":"integer","default_expression":"nextval('actor_profile_migration_state_id_seq'::regclass)","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"actor_profile_migration_state"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"schema_version","not_null":true,"ordinal":2,"table_name":"actor_profile_migration_state"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classified_count","not_null":true,"ordinal":3,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_row_set_sha256","not_null":true,"ordinal":4,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"manifest_sha256","not_null":false,"ordinal":5,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"envelope_sha256","not_null":false,"ordinal":6,"table_name":"actor_profile_migration_state"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"migrated_at","not_null":true,"ordinal":7,"table_name":"actor_profile_migration_state"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_mapped_count","not_null":true,"ordinal":8,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_source_row_set_sha256","not_null":true,"ordinal":9,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_manifest_sha256","not_null":false,"ordinal":10,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_envelope_sha256","not_null":false,"ordinal":11,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(76)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity_database_binding","not_null":true,"ordinal":12,"table_name":"actor_profile_migration_state"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"actor_profiles"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_kind","not_null":true,"ordinal":2,"table_name":"actor_profiles"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":3,"table_name":"actor_profiles"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provisioning_method","not_null":true,"ordinal":4,"table_name":"actor_profiles"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"display_name","not_null":false,"ordinal":5,"table_name":"actor_profiles"},{"data_type":"character varying(320)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contact_email","not_null":false,"ordinal":6,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":7,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":8,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":9,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_seen_at","not_null":false,"ordinal":10,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_by","not_null":false,"ordinal":11,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_at","not_null":false,"ordinal":12,"table_name":"actor_profiles"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspension_reason","not_null":false,"ordinal":13,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deactivated_by","not_null":false,"ordinal":14,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deactivated_at","not_null":false,"ordinal":15,"table_name":"actor_profiles"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deactivation_reason","not_null":false,"ordinal":16,"table_name":"actor_profiles"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity","not_null":false,"ordinal":17,"table_name":"actor_profiles"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_by","not_null":false,"ordinal":18,"table_name":"actor_profiles"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivated_at","not_null":false,"ordinal":19,"table_name":"actor_profiles"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reactivation_reason","not_null":false,"ordinal":20,"table_name":"actor_profiles"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_actor_profile_id","not_null":true,"ordinal":2,"table_name":"admin_role_grants"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"role","not_null":true,"ordinal":3,"table_name":"admin_role_grants"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":4,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_project_id","not_null":false,"ordinal":5,"table_name":"admin_role_grants"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"admin_role_grants"},{"data_type":"smallint","default_expression":"'1'::smallint","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":7,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_actor_profile_id","not_null":false,"ordinal":8,"table_name":"admin_role_grants"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_system_principal","not_null":false,"ordinal":9,"table_name":"admin_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_admin_role_grant_id","not_null":false,"ordinal":10,"table_name":"admin_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"grant_reason","not_null":true,"ordinal":11,"table_name":"admin_role_grants"},{"data_type":"timestamp with time zone","default_expression":"clock_timestamp()","generated_kind":"00","identity_kind":"00","name":"granted_at","not_null":true,"ordinal":12,"table_name":"admin_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_actor_profile_id","not_null":false,"ordinal":13,"table_name":"admin_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_admin_role_grant_id","not_null":false,"ordinal":14,"table_name":"admin_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_reason","not_null":false,"ordinal":15,"table_name":"admin_role_grants"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_at","not_null":false,"ordinal":16,"table_name":"admin_role_grants"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"control_scope","not_null":true,"ordinal":1,"table_name":"api_rate_control_counters"},{"data_type":"bytea","default_expression":"","generated_kind":"00","identity_kind":"00","name":"key_digest","not_null":true,"ordinal":2,"table_name":"api_rate_control_counters"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"window_started_at","not_null":true,"ordinal":3,"table_name":"api_rate_control_counters"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"window_expires_at","not_null":true,"ordinal":4,"table_name":"api_rate_control_counters"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_count","not_null":true,"ordinal":5,"table_name":"api_rate_control_counters"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":6,"table_name":"api_rate_control_counters"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_admission_charges"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":2,"table_name":"artifact_admission_charges"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_id","not_null":true,"ordinal":3,"table_name":"artifact_admission_charges"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":4,"table_name":"artifact_admission_charges"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":5,"table_name":"artifact_admission_charges"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_type","not_null":true,"ordinal":6,"table_name":"artifact_admission_charges"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_ref","not_null":true,"ordinal":7,"table_name":"artifact_admission_charges"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creating_operation_identity","not_null":true,"ordinal":8,"table_name":"artifact_admission_charges"},{"data_type":"character varying(20)","default_expression":"'provisional'::character varying","generated_kind":"00","identity_kind":"00","name":"state","not_null":true,"ordinal":9,"table_name":"artifact_admission_charges"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":10,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"reserved_at","not_null":true,"ordinal":11,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"completed_at","not_null":false,"ordinal":12,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"released_at","not_null":false,"ordinal":13,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"artifact_admission_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":15,"table_name":"artifact_admission_charges"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":1,"table_name":"artifact_admission_scopes"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_id","not_null":true,"ordinal":2,"table_name":"artifact_admission_scopes"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"limit_bytes","not_null":true,"ordinal":3,"table_name":"artifact_admission_scopes"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"counted_bytes","not_null":true,"ordinal":4,"table_name":"artifact_admission_scopes"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":5,"table_name":"artifact_admission_scopes"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":6,"table_name":"artifact_admission_scopes"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":7,"table_name":"artifact_admission_scopes"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"artifact_bindings"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_type","not_null":true,"ordinal":4,"table_name":"artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_id","not_null":true,"ordinal":5,"table_name":"artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":true,"ordinal":6,"table_name":"artifact_bindings"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_version","not_null":true,"ordinal":7,"table_name":"artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":8,"table_name":"artifact_bindings"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attribution_type","not_null":true,"ordinal":9,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_binding_id","not_null":false,"ordinal":10,"table_name":"artifact_bindings"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":11,"table_name":"artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_contents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":2,"table_name":"artifact_contents"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":3,"table_name":"artifact_contents"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":false,"ordinal":4,"table_name":"artifact_contents"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"normalized_display_name","not_null":false,"ordinal":5,"table_name":"artifact_contents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":6,"table_name":"artifact_contents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replica_id","not_null":true,"ordinal":2,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation","not_null":true,"ordinal":3,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":4,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":5,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(1024)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_object_ref","not_null":true,"ordinal":6,"table_name":"artifact_operation_receipts"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replayed","not_null":true,"ordinal":7,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome","not_null":true,"ordinal":8,"table_name":"artifact_operation_receipts"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_number","not_null":true,"ordinal":9,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":true,"ordinal":10,"table_name":"artifact_operation_receipts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"details","not_null":true,"ordinal":11,"table_name":"artifact_operation_receipts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":12,"table_name":"artifact_operation_receipts"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"contract_version","not_null":true,"ordinal":13,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":14,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_source_item_id","not_null":false,"ordinal":15,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_run_id","not_null":false,"ordinal":16,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":false,"ordinal":17,"table_name":"artifact_operation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_id","not_null":true,"ordinal":1,"table_name":"artifact_put_attempt_charges"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"charge_id","not_null":true,"ordinal":2,"table_name":"artifact_put_attempt_charges"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":3,"table_name":"artifact_put_attempt_charges"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_put_attempts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_request_type","not_null":true,"ordinal":2,"table_name":"artifact_put_attempts"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_type","not_null":true,"ordinal":3,"table_name":"artifact_put_attempts"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"producer_ref","not_null":true,"ordinal":4,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":5,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":false,"ordinal":6,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_source_item_id","not_null":false,"ordinal":7,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_run_id","not_null":false,"ordinal":8,"table_name":"artifact_put_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":false,"ordinal":9,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":10,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":11,"table_name":"artifact_put_attempts"},{"data_type":"character varying(255)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":true,"ordinal":12,"table_name":"artifact_put_attempts"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"storage_namespace_id","not_null":true,"ordinal":13,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_fingerprint","not_null":true,"ordinal":14,"table_name":"artifact_put_attempts"},{"data_type":"character varying(1024)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_target","not_null":true,"ordinal":15,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_identity","not_null":true,"ordinal":16,"table_name":"artifact_put_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":17,"table_name":"artifact_put_attempts"},{"data_type":"character varying(40)","default_expression":"'prepared'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":18,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"next_run_at","not_null":false,"ordinal":19,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"executor_id","not_null":false,"ordinal":20,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lease_expires_at","not_null":false,"ordinal":21,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":22,"table_name":"artifact_put_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_result_code","not_null":false,"ordinal":23,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replica_id","not_null":false,"ordinal":24,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"receipt_id","not_null":false,"ordinal":25,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":26,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"prepared_at","not_null":true,"ordinal":27,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":28,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":29,"table_name":"artifact_put_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":30,"table_name":"artifact_put_attempts"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"execution_mode","not_null":false,"ordinal":31,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"observation_count","not_null":true,"ordinal":32,"table_name":"artifact_put_attempts"},{"data_type":"bigint","default_expression":"'5'::bigint","generated_kind":"00","identity_kind":"00","name":"maximum_observations","not_null":true,"ordinal":33,"table_name":"artifact_put_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":2,"table_name":"artifact_put_observation_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":3,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome","not_null":true,"ordinal":4,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"expected_sha256","not_null":true,"ordinal":5,"table_name":"artifact_put_observation_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"expected_byte_count","not_null":true,"ordinal":6,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_sha256","not_null":false,"ordinal":7,"table_name":"artifact_put_observation_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_byte_count","not_null":false,"ordinal":8,"table_name":"artifact_put_observation_receipts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":9,"table_name":"artifact_put_observation_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requester_actor_profile_id","not_null":true,"ordinal":2,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requester_identity_link_id","not_null":true,"ordinal":3,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_request_id","not_null":true,"ordinal":4,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_correlation_id","not_null":true,"ordinal":5,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":6,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":false,"ordinal":7,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":false,"ordinal":8,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_verification_job_id","not_null":true,"ordinal":9,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retry_verification_job_id","not_null":true,"ordinal":10,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"parent_recovery_attempt_id","not_null":false,"ordinal":11,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"recovery_class","not_null":true,"ordinal":12,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(1000)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reason","not_null":true,"ordinal":13,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"client_idempotency_key","not_null":true,"ordinal":14,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":15,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(20)","default_expression":"'requested'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":16,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_result_code","not_null":false,"ordinal":17,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"initiation_audit_event_id","not_null":true,"ordinal":18,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_audit_event_id","not_null":false,"ordinal":19,"table_name":"artifact_recovery_attempts"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":20,"table_name":"artifact_recovery_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":21,"table_name":"artifact_recovery_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":22,"table_name":"artifact_recovery_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":false,"ordinal":23,"table_name":"artifact_recovery_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_replicas"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"artifact_replicas"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter","not_null":true,"ordinal":3,"table_name":"artifact_replicas"},{"data_type":"character varying(1024)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_object_ref","not_null":true,"ordinal":4,"table_name":"artifact_replicas"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verification_state","not_null":true,"ordinal":5,"table_name":"artifact_replicas"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"availability_state","not_null":true,"ordinal":6,"table_name":"artifact_replicas"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"integrity_state","not_null":true,"ordinal":7,"table_name":"artifact_replicas"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_reconciled_at","not_null":false,"ordinal":8,"table_name":"artifact_replicas"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":9,"table_name":"artifact_replicas"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":10,"table_name":"artifact_replicas"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"storage_namespace_id","not_null":true,"ordinal":11,"table_name":"artifact_replicas"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_fingerprint","not_null":true,"ordinal":12,"table_name":"artifact_replicas"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_profile","not_null":true,"ordinal":13,"table_name":"artifact_replicas"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"backend","not_null":true,"ordinal":2,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter","not_null":true,"ordinal":3,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_profile","not_null":true,"ordinal":4,"table_name":"artifact_storage_namespaces"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_descriptor","not_null":true,"ordinal":5,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"namespace_fingerprint","not_null":true,"ordinal":6,"table_name":"artifact_storage_namespaces"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"artifact_storage_namespaces"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"originating_put_attempt_id","not_null":true,"ordinal":2,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"replica_id","not_null":true,"ordinal":3,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(40)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"artifact_verification_jobs"},{"data_type":"integer","default_expression":"0","generated_kind":"00","identity_kind":"00","name":"attempt_count","not_null":true,"ordinal":5,"table_name":"artifact_verification_jobs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"maximum_attempts","not_null":true,"ordinal":6,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"next_run_at","not_null":false,"ordinal":7,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"executor_id","not_null":false,"ordinal":8,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lease_expires_at","not_null":false,"ordinal":9,"table_name":"artifact_verification_jobs"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":10,"table_name":"artifact_verification_jobs"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"cas_version","not_null":true,"ordinal":11,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_result_code","not_null":false,"ordinal":12,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":13,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":14,"table_name":"artifact_verification_jobs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":false,"ordinal":15,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"parent_verification_job_id","not_null":false,"ordinal":16,"table_name":"artifact_verification_jobs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verification_job_id","not_null":true,"ordinal":2,"table_name":"artifact_verification_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"execution_generation","not_null":true,"ordinal":3,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome","not_null":true,"ordinal":4,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_sha256","not_null":false,"ordinal":5,"table_name":"artifact_verification_receipts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_byte_count","not_null":false,"ordinal":6,"table_name":"artifact_verification_receipts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":false,"ordinal":7,"table_name":"artifact_verification_receipts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"audit_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"entity_type","not_null":true,"ordinal":2,"table_name":"audit_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"entity_id","not_null":true,"ordinal":3,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_type","not_null":true,"ordinal":4,"table_name":"audit_events"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"from_status","not_null":false,"ordinal":5,"table_name":"audit_events"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"to_status","not_null":false,"ordinal":6,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":7,"table_name":"audit_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_subject","not_null":false,"ordinal":8,"table_name":"audit_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_issuer","not_null":false,"ordinal":9,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_roles","not_null":true,"ordinal":10,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claim_snapshot","not_null":true,"ordinal":11,"table_name":"audit_events"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"auth_source","not_null":true,"ordinal":12,"table_name":"audit_events"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"is_dev_auth","not_null":true,"ordinal":13,"table_name":"audit_events"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reason","not_null":false,"ordinal":14,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_payload","not_null":true,"ordinal":15,"table_name":"audit_events"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"audit_events"},{"data_type":"character varying(24)","default_expression":"'legacy_lifecycle'::character varying","generated_kind":"00","identity_kind":"00","name":"event_domain","not_null":true,"ordinal":17,"table_name":"audit_events"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_version","not_null":false,"ordinal":18,"table_name":"audit_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"occurred_at","not_null":false,"ordinal":19,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_ref_kind","not_null":false,"ordinal":20,"table_name":"audit_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_id","not_null":false,"ordinal":21,"table_name":"audit_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":false,"ordinal":22,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_actor_ref_kind","not_null":false,"ordinal":23,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_actor_ref","not_null":false,"ordinal":24,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"matched_grant_id","not_null":false,"ordinal":25,"table_name":"audit_events"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"permission_id","not_null":false,"ordinal":26,"table_name":"audit_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":false,"ordinal":27,"table_name":"audit_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_type","not_null":false,"ordinal":28,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_id","not_null":false,"ordinal":29,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_ref_kind","not_null":false,"ordinal":30,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"target_ref_id","not_null":false,"ordinal":31,"table_name":"audit_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"denial_code","not_null":false,"ordinal":32,"table_name":"audit_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_reference","not_null":false,"ordinal":33,"table_name":"audit_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"invalidation_cause_event_id","not_null":false,"ordinal":34,"table_name":"audit_events"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"invalidation_target_kind","not_null":false,"ordinal":35,"table_name":"audit_events"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"invalidation_target_ref","not_null":false,"ordinal":36,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"before_facts","not_null":false,"ordinal":37,"table_name":"audit_events"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"after_facts","not_null":false,"ordinal":38,"table_name":"audit_events"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":false,"ordinal":39,"table_name":"audit_events"},{"data_type":"smallint","default_expression":"nextval('authority_control_id_seq'::regclass)","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"authority_control"},{"data_type":"boolean","default_expression":"false","generated_kind":"00","identity_kind":"00","name":"bootstrap_completed","not_null":true,"ordinal":2,"table_name":"authority_control"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bootstrap_grant_id","not_null":false,"ordinal":3,"table_name":"authority_control"},{"data_type":"smallint","default_expression":"'0'::smallint","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":4,"table_name":"authority_control"},{"data_type":"timestamp with time zone","default_expression":"clock_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":5,"table_name":"authority_control"},{"data_type":"timestamp with time zone","default_expression":"clock_timestamp()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":6,"table_name":"authority_control"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"authority_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":2,"table_name":"authority_idempotency_records"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_ref_kind","not_null":true,"ordinal":3,"table_name":"authority_idempotency_records"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_ref","not_null":true,"ordinal":4,"table_name":"authority_idempotency_records"},{"data_type":"character varying(48)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation","not_null":true,"ordinal":5,"table_name":"authority_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"authority_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":7,"table_name":"authority_idempotency_records"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_resource_type","not_null":false,"ordinal":8,"table_name":"authority_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_resource_id","not_null":false,"ordinal":9,"table_name":"authority_idempotency_records"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_resource_version","not_null":false,"ordinal":10,"table_name":"authority_idempotency_records"},{"data_type":"smallint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_http_status","not_null":false,"ordinal":11,"table_name":"authority_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":12,"table_name":"authority_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":13,"table_name":"authority_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"required_checkers","not_null":true,"ordinal":4,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_checkers","not_null":true,"ordinal":5,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"blocking_severities","not_null":true,"ordinal":6,"table_name":"checker_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":false,"ordinal":8,"table_name":"checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_body","not_null":false,"ordinal":9,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":10,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":11,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":12,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_id","not_null":true,"ordinal":13,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_hash","not_null":true,"ordinal":14,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_checker_policy_id","not_null":true,"ordinal":15,"table_name":"checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_checker_bundle_hash","not_null":true,"ordinal":16,"table_name":"checker_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":17,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_role","not_null":false,"ordinal":18,"table_name":"checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_actor","not_null":false,"ordinal":19,"table_name":"checker_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_at","not_null":false,"ordinal":20,"table_name":"checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":21,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":22,"table_name":"checker_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":23,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_by_role","not_null":false,"ordinal":24,"table_name":"checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_by_actor","not_null":false,"ordinal":25,"table_name":"checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersession_kind","not_null":false,"ordinal":26,"table_name":"checker_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersession_reason","not_null":false,"ordinal":27,"table_name":"checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_run_id","not_null":true,"ordinal":2,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":3,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":4,"table_name":"checker_results"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_name","not_null":true,"ordinal":5,"table_name":"checker_results"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"checker_results"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"severity","not_null":true,"ordinal":7,"table_name":"checker_results"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"blocks_review","not_null":true,"ordinal":8,"table_name":"checker_results"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"message","not_null":true,"ordinal":9,"table_name":"checker_results"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_message","not_null":false,"ordinal":10,"table_name":"checker_results"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_suggested_fix","not_null":false,"ordinal":11,"table_name":"checker_results"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_evidence_refs","not_null":true,"ordinal":12,"table_name":"checker_results"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_visible","not_null":true,"ordinal":13,"table_name":"checker_results"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"metadata","not_null":true,"ordinal":14,"table_name":"checker_results"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":15,"table_name":"checker_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":2,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":3,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":4,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"trigger_source","not_null":true,"ordinal":5,"table_name":"checker_runs"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"routing_recommendation","not_null":true,"ordinal":7,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"outcome_source","not_null":true,"ordinal":8,"table_name":"checker_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"triggered_by","not_null":true,"ordinal":9,"table_name":"checker_runs"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"triggered_by_subject","not_null":true,"ordinal":10,"table_name":"checker_runs"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"triggered_by_issuer","not_null":true,"ordinal":11,"table_name":"checker_runs"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"trigger_auth_source","not_null":true,"ordinal":12,"table_name":"checker_runs"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"trigger_reason","not_null":false,"ordinal":13,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"audit_event_id","not_null":false,"ordinal":14,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_number","not_null":true,"ordinal":15,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_checker_run_id","not_null":false,"ordinal":16,"table_name":"checker_runs"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"is_current_for_submission","not_null":true,"ordinal":17,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_version","not_null":true,"ordinal":18,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_payment_policy_version","not_null":true,"ordinal":19,"table_name":"checker_runs"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"package_hash","not_null":true,"ordinal":20,"table_name":"checker_runs"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_hash_manifest","not_null":true,"ordinal":21,"table_name":"checker_runs"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_manifest_hash","not_null":true,"ordinal":22,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"passed_count","not_null":true,"ordinal":23,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_count","not_null":true,"ordinal":24,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failed_count","not_null":true,"ordinal":25,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"blocking_count","not_null":true,"ordinal":26,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"queued_at","not_null":true,"ordinal":27,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"started_at","not_null":false,"ordinal":28,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"completed_at","not_null":false,"ordinal":29,"table_name":"checker_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_code","not_null":false,"ordinal":30,"table_name":"checker_runs"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_message","not_null":false,"ordinal":31,"table_name":"checker_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":32,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_id","not_null":false,"ordinal":33,"table_name":"checker_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_version","not_null":false,"ordinal":34,"table_name":"checker_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_hash","not_null":false,"ordinal":35,"table_name":"checker_runs"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_body","not_null":false,"ordinal":36,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_id","not_null":true,"ordinal":37,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_generation","not_null":true,"ordinal":38,"table_name":"checker_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_hash","not_null":true,"ordinal":39,"table_name":"checker_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_id","not_null":true,"ordinal":40,"table_name":"checker_runs"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_generation","not_null":true,"ordinal":41,"table_name":"checker_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_hash","not_null":true,"ordinal":42,"table_name":"checker_runs"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_rule_id","not_null":true,"ordinal":2,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_policy_version_id","not_null":true,"ordinal":3,"table_name":"contribution_award_definitions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":4,"table_name":"contribution_award_definitions"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_type","not_null":true,"ordinal":5,"table_name":"contribution_award_definitions"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instrument_type","not_null":true,"ordinal":6,"table_name":"contribution_award_definitions"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"unit_code","not_null":true,"ordinal":7,"table_name":"contribution_award_definitions"},{"data_type":"numeric","default_expression":"","generated_kind":"00","identity_kind":"00","name":"quantity","not_null":true,"ordinal":8,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter_binding_id","not_null":true,"ordinal":9,"table_name":"contribution_award_definitions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"contribution_policies"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"name","not_null":true,"ordinal":3,"table_name":"contribution_policies"},{"data_type":"character varying(16)","default_expression":"'draft'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"contribution_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"current_published_version_id","not_null":false,"ordinal":5,"table_name":"contribution_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":6,"table_name":"contribution_policies"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"contribution_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":8,"table_name":"contribution_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":9,"table_name":"contribution_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_policy_versions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_policy_id","not_null":true,"ordinal":2,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"contribution_policy_versions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"version_number","not_null":true,"ordinal":4,"table_name":"contribution_policy_versions"},{"data_type":"character varying(16)","default_expression":"'draft'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":6,"table_name":"contribution_policy_versions"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"published_by","not_null":false,"ordinal":8,"table_name":"contribution_policy_versions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"published_at","not_null":false,"ordinal":9,"table_name":"contribution_policy_versions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":10,"table_name":"contribution_policy_versions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":11,"table_name":"contribution_policy_versions"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"contribution_rules"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_policy_version_id","not_null":true,"ordinal":2,"table_name":"contribution_rules"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"contribution_rules"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contribution_type","not_null":true,"ordinal":4,"table_name":"contribution_rules"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compensation_mode","not_null":true,"ordinal":5,"table_name":"contribution_rules"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_artifact_policy_id","not_null":true,"ordinal":7,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_artifact_policy_hash","not_null":true,"ordinal":8,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":9,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"merge_algorithm_version","not_null":true,"ordinal":10,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy","not_null":true,"ordinal":11,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_hash","not_null":true,"ordinal":12,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":13,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_effective_policy_id","not_null":false,"ordinal":15,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":16,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":17,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":18,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":19,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":20,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":21,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":22,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_decision_event_id","not_null":false,"ordinal":23,"table_name":"effective_project_submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"evidence_items"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":2,"table_name":"evidence_items"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"type","not_null":true,"ordinal":3,"table_name":"evidence_items"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"label","not_null":true,"ordinal":4,"table_name":"evidence_items"},{"data_type":"character varying(1000)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"uri","not_null":false,"ordinal":5,"table_name":"evidence_items"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"hash","not_null":false,"ordinal":6,"table_name":"evidence_items"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"size_bytes","not_null":false,"ordinal":7,"table_name":"evidence_items"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_at","not_null":false,"ordinal":8,"table_name":"evidence_items"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"metadata","not_null":true,"ordinal":9,"table_name":"evidence_items"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"evidence_items"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"guide_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":7,"table_name":"guide_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":8,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":9,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_id","not_null":true,"ordinal":10,"table_name":"guide_mutation_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_generation","not_null":true,"ordinal":11,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":12,"table_name":"guide_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":13,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":false,"ordinal":14,"table_name":"guide_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":15,"table_name":"guide_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":16,"table_name":"guide_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":4,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":5,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":true,"ordinal":6,"table_name":"guide_source_artifact_bindings"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":7,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":8,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":9,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"logical_role","not_null":true,"ordinal":10,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_binding_id","not_null":false,"ordinal":11,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service","not_null":true,"ordinal":12,"table_name":"guide_source_artifact_bindings"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":13,"table_name":"guide_source_artifact_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":2,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":3,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":4,"table_name":"guide_source_artifact_incidents"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":5,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"code","not_null":true,"ordinal":6,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_sha256","not_null":false,"ordinal":7,"table_name":"guide_source_artifact_incidents"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"observed_byte_count","not_null":false,"ordinal":8,"table_name":"guide_source_artifact_incidents"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bounded_facts","not_null":true,"ordinal":9,"table_name":"guide_source_artifact_incidents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"guide_source_artifact_incidents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":2,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":4,"table_name":"guide_source_artifact_ingests"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":5,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(255)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":true,"ordinal":6,"table_name":"guide_source_artifact_ingests"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"guide_source_artifact_ingests"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detected_format","not_null":true,"ordinal":3,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_name","not_null":true,"ordinal":4,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_version","not_null":true,"ordinal":5,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":6,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_sha256","not_null":true,"ordinal":7,"table_name":"guide_source_extracted_contents"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_byte_count","not_null":true,"ordinal":8,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":9,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_sha256","not_null":true,"ordinal":10,"table_name":"guide_source_extracted_contents"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_output","not_null":true,"ordinal":11,"table_name":"guide_source_extracted_contents"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"omission_facts","not_null":true,"ordinal":12,"table_name":"guide_source_extracted_contents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":13,"table_name":"guide_source_extracted_contents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":2,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":3,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification_id","not_null":true,"ordinal":4,"table_name":"guide_source_extraction_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":5,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detected_format","not_null":true,"ordinal":6,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_name","not_null":true,"ordinal":7,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extractor_version","not_null":true,"ordinal":8,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":9,"table_name":"guide_source_extraction_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_number","not_null":true,"ordinal":10,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":11,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_code","not_null":false,"ordinal":12,"table_name":"guide_source_extraction_attempts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bounded_facts","not_null":true,"ordinal":13,"table_name":"guide_source_extraction_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"guide_source_extraction_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":1,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":2,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification_id","not_null":true,"ordinal":3,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":4,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":5,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claimed_slots","not_null":true,"ordinal":6,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":8,"table_name":"guide_source_extraction_retry_budgets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extracted_content_id","not_null":true,"ordinal":2,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extraction_attempt_id","not_null":true,"ordinal":3,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_status","not_null":true,"ordinal":4,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":5,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":6,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":7,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":true,"ordinal":8,"table_name":"guide_source_extraction_usages"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":9,"table_name":"guide_source_extraction_usages"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"guide_source_extraction_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":2,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":3,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":4,"table_name":"guide_source_format_classifications"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":5,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"sha256","not_null":true,"ordinal":6,"table_name":"guide_source_format_classifications"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"byte_count","not_null":true,"ordinal":7,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(255)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":true,"ordinal":8,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detected_format","not_null":true,"ordinal":9,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detector_name","not_null":true,"ordinal":11,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"detector_version","not_null":true,"ordinal":12,"table_name":"guide_source_format_classifications"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification_facts","not_null":true,"ordinal":13,"table_name":"guide_source_format_classifications"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":14,"table_name":"guide_source_format_classifications"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":2,"table_name":"guide_source_snapshot_items"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"item_order","not_null":true,"ordinal":3,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_kind","not_null":true,"ordinal":4,"table_name":"guide_source_snapshot_items"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_label","not_null":true,"ordinal":5,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"ingestion_adapter","not_null":true,"ordinal":6,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"media_type","not_null":false,"ordinal":7,"table_name":"guide_source_snapshot_items"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":8,"table_name":"guide_source_snapshot_items"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"guide_source_snapshots"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"guide_source_snapshots"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"manifest_schema_version","not_null":true,"ordinal":5,"table_name":"guide_source_snapshots"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"manifest_json","not_null":true,"ordinal":6,"table_name":"guide_source_snapshots"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"bundle_hash","not_null":true,"ordinal":7,"table_name":"guide_source_snapshots"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"captured_by","not_null":true,"ordinal":8,"table_name":"guide_source_snapshots"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"captured_at","not_null":true,"ordinal":9,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":10,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":11,"table_name":"guide_source_snapshots"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":12,"table_name":"guide_source_snapshots"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":13,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":14,"table_name":"guide_source_snapshots"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":15,"table_name":"guide_source_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":16,"table_name":"guide_source_snapshots"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_generation","not_null":false,"ordinal":17,"table_name":"guide_source_snapshots"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":7,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":8,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":9,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":10,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":11,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"report_id","not_null":false,"ordinal":12,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":false,"ordinal":13,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":14,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":15,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":16,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":17,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":18,"table_name":"guide_sufficiency_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"report_id","not_null":true,"ordinal":2,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"item_order","not_null":true,"ordinal":3,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_item_id","not_null":true,"ordinal":4,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"binding_id","not_null":true,"ordinal":5,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_id","not_null":true,"ordinal":6,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extraction_usage_id","not_null":true,"ordinal":7,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extraction_attempt_id","not_null":true,"ordinal":8,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"extracted_content_id","not_null":true,"ordinal":9,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":true,"ordinal":10,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":11,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_output_sha256","not_null":true,"ordinal":12,"table_name":"guide_sufficiency_report_source_usages"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":7,"table_name":"guide_sufficiency_reports"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"findings","not_null":true,"ordinal":8,"table_name":"guide_sufficiency_reports"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"summary","not_null":false,"ordinal":9,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_name","not_null":false,"ordinal":10,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_version","not_null":false,"ordinal":11,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":12,"table_name":"guide_sufficiency_reports"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":13,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_role","not_null":false,"ordinal":14,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_actor","not_null":false,"ordinal":15,"table_name":"guide_sufficiency_reports"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_at","not_null":false,"ordinal":16,"table_name":"guide_sufficiency_reports"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"acknowledgement_note","not_null":false,"ordinal":17,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_setup_run_id","not_null":false,"ordinal":18,"table_name":"guide_sufficiency_reports"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":false,"ordinal":19,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_material_sha256","not_null":false,"ordinal":20,"table_name":"guide_sufficiency_reports"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_material_byte_count","not_null":false,"ordinal":21,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":22,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":23,"table_name":"guide_sufficiency_reports"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":24,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service_identity","not_null":false,"ordinal":25,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":26,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":27,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":28,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":29,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_actor_profile_id","not_null":false,"ordinal":30,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_via_identity_link_id","not_null":false,"ordinal":31,"table_name":"guide_sufficiency_reports"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warnings_acknowledged_by_admin_role_grant_id","not_null":false,"ordinal":32,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_scope_type","not_null":false,"ordinal":33,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_scope_project_id","not_null":false,"ordinal":34,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_action_id","not_null":false,"ordinal":35,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"warning_acknowledgement_decision_event_id","not_null":false,"ordinal":36,"table_name":"guide_sufficiency_reports"},{"data_type":"character varying(3)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"code","not_null":true,"ordinal":1,"table_name":"iso_4217_currency_codes"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":1,"table_name":"legacy_actor_identities"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_subject","not_null":true,"ordinal":2,"table_name":"legacy_actor_identities"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_issuer","not_null":true,"ordinal":3,"table_name":"legacy_actor_identities"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"display_name","not_null":false,"ordinal":4,"table_name":"legacy_actor_identities"},{"data_type":"character varying(320)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"email","not_null":false,"ordinal":5,"table_name":"legacy_actor_identities"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_seen_roles","not_null":true,"ordinal":6,"table_name":"legacy_actor_identities"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_claim_snapshot","not_null":true,"ordinal":7,"table_name":"legacy_actor_identities"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"auth_source","not_null":true,"ordinal":8,"table_name":"legacy_actor_identities"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"is_dev_auth","not_null":true,"ordinal":9,"table_name":"legacy_actor_identities"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"first_seen_at","not_null":true,"ordinal":10,"table_name":"legacy_actor_identities"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"last_seen_at","not_null":true,"ordinal":11,"table_name":"legacy_actor_identities"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":12,"table_name":"legacy_actor_identities"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_id","not_null":true,"ordinal":2,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"profile_type","not_null":true,"ordinal":3,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"legacy_workflow_eligibility"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"skill_tags","not_null":true,"ordinal":5,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_type","not_null":true,"ordinal":6,"table_name":"legacy_workflow_eligibility"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"scope_id","not_null":true,"ordinal":7,"table_name":"legacy_workflow_eligibility"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"profile_metadata","not_null":true,"ordinal":8,"table_name":"legacy_workflow_eligibility"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":9,"table_name":"legacy_workflow_eligibility"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":10,"table_name":"legacy_workflow_eligibility"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_id","not_null":true,"ordinal":1,"table_name":"outbox_events"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_type","not_null":true,"ordinal":2,"table_name":"outbox_events"},{"data_type":"smallint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"event_version","not_null":true,"ordinal":3,"table_name":"outbox_events"},{"data_type":"character varying(32)","default_expression":"'workstream'::character varying","generated_kind":"00","identity_kind":"00","name":"producer","not_null":true,"ordinal":4,"table_name":"outbox_events"},{"data_type":"character varying(64)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"aggregate_type","not_null":true,"ordinal":5,"table_name":"outbox_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"aggregate_id","not_null":true,"ordinal":6,"table_name":"outbox_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":7,"table_name":"outbox_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":true,"ordinal":8,"table_name":"outbox_events"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"causation_event_id","not_null":false,"ordinal":9,"table_name":"outbox_events"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":10,"table_name":"outbox_events"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payload","not_null":true,"ordinal":11,"table_name":"outbox_events"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payload_digest","not_null":true,"ordinal":12,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"occurred_at","not_null":true,"ordinal":13,"table_name":"outbox_events"},{"data_type":"character varying(16)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"delivery_state","not_null":true,"ordinal":14,"table_name":"outbox_events"},{"data_type":"integer","default_expression":"0","generated_kind":"00","identity_kind":"00","name":"attempt_count","not_null":true,"ordinal":15,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"next_attempt_at","not_null":false,"ordinal":16,"table_name":"outbox_events"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claim_owner","not_null":false,"ordinal":17,"table_name":"outbox_events"},{"data_type":"bigint","default_expression":"'0'::bigint","generated_kind":"00","identity_kind":"00","name":"claim_generation","not_null":true,"ordinal":18,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claimed_at","not_null":false,"ordinal":19,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"claim_expires_at","not_null":false,"ordinal":20,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_attempt_at","not_null":false,"ordinal":21,"table_name":"outbox_events"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_error_code","not_null":false,"ordinal":22,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"finalized_at","not_null":false,"ordinal":23,"table_name":"outbox_events"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archived_at","not_null":false,"ordinal":24,"table_name":"outbox_events"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"payment_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"payment_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"payment_policies"},{"data_type":"numeric(12,2)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"base_amount","not_null":false,"ordinal":4,"table_name":"payment_policies"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"currency","not_null":false,"ordinal":5,"table_name":"payment_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payout_type","not_null":false,"ordinal":6,"table_name":"payment_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revision_payment_rule","not_null":false,"ordinal":7,"table_name":"payment_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"rejection_payment_rule","not_null":false,"ordinal":8,"table_name":"payment_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"accepted_payment_rule","not_null":false,"ordinal":9,"table_name":"payment_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"payment_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":7,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":8,"table_name":"policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":9,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":10,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":11,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_id","not_null":true,"ordinal":12,"table_name":"policy_mutation_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_generation","not_null":true,"ordinal":13,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":14,"table_name":"policy_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":15,"table_name":"policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":17,"table_name":"policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_id","not_null":true,"ordinal":7,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_hash","not_null":true,"ordinal":8,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":9,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compiler_version","not_null":false,"ordinal":10,"table_name":"pre_submit_checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compiled_bundle","not_null":false,"ordinal":11,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"compiled_bundle_hash","not_null":false,"ordinal":12,"table_name":"pre_submit_checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_names","not_null":true,"ordinal":13,"table_name":"pre_submit_checker_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"checker_configs","not_null":true,"ordinal":14,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":15,"table_name":"pre_submit_checker_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_pre_submit_checker_policy_id","not_null":false,"ordinal":17,"table_name":"pre_submit_checker_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":18,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":19,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":20,"table_name":"pre_submit_checker_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":21,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":22,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":23,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":24,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_decision_event_id","not_null":false,"ordinal":25,"table_name":"pre_submit_checker_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"evidence_set_id","not_null":true,"ordinal":2,"table_name":"pre_submit_evidence_results"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_order","not_null":true,"ordinal":3,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(80)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"schema_version","not_null":true,"ordinal":4,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"dispatch_authority","not_null":true,"ordinal":5,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"definition_id","not_null":true,"ordinal":6,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"definition_version","not_null":true,"ordinal":7,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"public_name","not_null":true,"ordinal":8,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source","not_null":true,"ordinal":9,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"phase","not_null":true,"ordinal":10,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"classification","not_null":true,"ordinal":11,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"severity","not_null":true,"ordinal":12,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":13,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_code","not_null":false,"ordinal":14,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"message_code","not_null":true,"ordinal":15,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_plan_sha256","not_null":true,"ordinal":16,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"rule_instance_id","not_null":false,"ordinal":17,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_policy_sha256","not_null":true,"ordinal":18,"table_name":"pre_submit_evidence_results"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":19,"table_name":"pre_submit_evidence_results"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_identity","not_null":true,"ordinal":2,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":4,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":5,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":6,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assignment_id","not_null":true,"ordinal":7,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_id","not_null":false,"ordinal":8,"table_name":"pre_submit_evidence_sets"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_version","not_null":false,"ordinal":9,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"prepared_generation_id","not_null":true,"ordinal":10,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_sha256","not_null":true,"ordinal":11,"table_name":"pre_submit_evidence_sets"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_byte_count","not_null":true,"ordinal":12,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_id","not_null":true,"ordinal":13,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_sha256","not_null":true,"ordinal":14,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":15,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":16,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":17,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_sha256","not_null":true,"ordinal":18,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_sha256","not_null":true,"ordinal":19,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_policy_id","not_null":true,"ordinal":20,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_artifact_policy_sha256","not_null":true,"ordinal":21,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_policy_id","not_null":true,"ordinal":22,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_checker_policy_sha256","not_null":true,"ordinal":23,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_plan_sha256","not_null":true,"ordinal":24,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"catalogue_id","not_null":true,"ordinal":25,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(40)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"catalogue_version","not_null":true,"ordinal":26,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"catalogue_manifest_sha256","not_null":true,"ordinal":27,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"storage_scheme","not_null":true,"ordinal":28,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_status","not_null":true,"ordinal":29,"table_name":"pre_submit_evidence_sets"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"eligible","not_null":true,"ordinal":30,"table_name":"pre_submit_evidence_sets"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_count","not_null":true,"ordinal":31,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_manifest_sha256","not_null":true,"ordinal":32,"table_name":"pre_submit_evidence_sets"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":33,"table_name":"pre_submit_evidence_sets"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_policy_context_hash","not_null":true,"ordinal":34,"table_name":"pre_submit_evidence_sets"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instrument_type","not_null":true,"ordinal":3,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"adapter_actor_id","not_null":true,"ordinal":4,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"route_key","not_null":true,"ordinal":5,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":6,"table_name":"project_compensation_adapter_bindings"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"binding_lifecycle_version","not_null":true,"ordinal":7,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":8,"table_name":"project_compensation_adapter_bindings"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":9,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_by","not_null":false,"ordinal":10,"table_name":"project_compensation_adapter_bindings"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"suspended_at","not_null":false,"ordinal":11,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":12,"table_name":"project_compensation_adapter_bindings"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":13,"table_name":"project_compensation_adapter_bindings"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":1,"table_name":"project_compensation_units"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instrument_type","not_null":true,"ordinal":2,"table_name":"project_compensation_units"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"unit_code","not_null":true,"ordinal":3,"table_name":"project_compensation_units"},{"data_type":"character varying(3)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"iso_currency_code","not_null":false,"ordinal":4,"table_name":"project_compensation_units"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"project_compensation_units"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":6,"table_name":"project_compensation_units"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"project_compensation_units"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_by","not_null":false,"ordinal":8,"table_name":"project_compensation_units"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"retired_at","not_null":false,"ordinal":9,"table_name":"project_compensation_units"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":4,"table_name":"project_create_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":5,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":6,"table_name":"project_create_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":7,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":8,"table_name":"project_create_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_generation","not_null":true,"ordinal":9,"table_name":"project_create_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"project_create_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":11,"table_name":"project_create_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":12,"table_name":"project_create_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":true,"ordinal":7,"table_name":"project_guide_compilation_attempts"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":8,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_input_hash","not_null":true,"ordinal":9,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_material_hash","not_null":true,"ordinal":10,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_id","not_null":true,"ordinal":11,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_version","not_null":true,"ordinal":12,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_schema_version","not_null":true,"ordinal":13,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_manifest_hash","not_null":true,"ordinal":14,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_id","not_null":true,"ordinal":15,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_version","not_null":true,"ordinal":16,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_schema_version","not_null":true,"ordinal":17,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_manifest_hash","not_null":true,"ordinal":18,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_identity","not_null":true,"ordinal":19,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_version","not_null":true,"ordinal":20,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instruction_version","not_null":true,"ordinal":21,"table_name":"project_guide_compilation_attempts"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_idempotency_key","not_null":true,"ordinal":22,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":23,"table_name":"project_guide_compilation_attempts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_result","not_null":false,"ordinal":24,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_hash","not_null":false,"ordinal":25,"table_name":"project_guide_compilation_attempts"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"component_hashes","not_null":false,"ordinal":26,"table_name":"project_guide_compilation_attempts"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"failure_code","not_null":false,"ordinal":27,"table_name":"project_guide_compilation_attempts"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"persisted_compilation_id","not_null":false,"ordinal":28,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"reserved_at","not_null":true,"ordinal":29,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"provider_uncertain_at","not_null":false,"ordinal":30,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"accepted_at","not_null":false,"ordinal":31,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"terminal_at","not_null":false,"ordinal":32,"table_name":"project_guide_compilation_attempts"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"persisted_at","not_null":false,"ordinal":33,"table_name":"project_guide_compilation_attempts"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_guide_compilations"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_id","not_null":true,"ordinal":2,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":4,"table_name":"project_guide_compilations"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":5,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":6,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":7,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":true,"ordinal":8,"table_name":"project_guide_compilations"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":9,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_input_hash","not_null":true,"ordinal":10,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_material_hash","not_null":true,"ordinal":11,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_catalogue_manifest_hash","not_null":true,"ordinal":12,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_catalogue_manifest_hash","not_null":true,"ordinal":13,"table_name":"project_guide_compilations"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_identity","not_null":true,"ordinal":14,"table_name":"project_guide_compilations"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"agent_version","not_null":true,"ordinal":15,"table_name":"project_guide_compilations"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"instruction_version","not_null":true,"ordinal":16,"table_name":"project_guide_compilations"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"canonical_result","not_null":true,"ordinal":17,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"result_hash","not_null":true,"ordinal":18,"table_name":"project_guide_compilations"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"component_hashes","not_null":true,"ordinal":19,"table_name":"project_guide_compilations"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_compilation_id","not_null":false,"ordinal":20,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":true,"ordinal":21,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":true,"ordinal":22,"table_name":"project_guide_compilations"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service_identity","not_null":true,"ordinal":23,"table_name":"project_guide_compilations"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":true,"ordinal":24,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":true,"ordinal":25,"table_name":"project_guide_compilations"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_resource_context_digest","not_null":true,"ordinal":26,"table_name":"project_guide_compilations"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":27,"table_name":"project_guide_compilations"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_guides"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":3,"table_name":"project_guides"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":4,"table_name":"project_guides"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"content_markdown","not_null":true,"ordinal":5,"table_name":"project_guides"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by","not_null":false,"ordinal":6,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"effective_at","not_null":false,"ordinal":7,"table_name":"project_guides"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"change_summary","not_null":false,"ordinal":8,"table_name":"project_guides"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":9,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":10,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":11,"table_name":"project_guides"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":12,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutated_by_actor_profile_id","not_null":false,"ordinal":13,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutated_via_identity_link_id","not_null":false,"ordinal":14,"table_name":"project_guides"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutated_by_admin_role_grant_id","not_null":false,"ordinal":15,"table_name":"project_guides"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutation_scope_type","not_null":false,"ordinal":16,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutation_scope_project_id","not_null":false,"ordinal":17,"table_name":"project_guides"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_mutation_action_id","not_null":false,"ordinal":18,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"last_authorization_decision_event_id","not_null":false,"ordinal":19,"table_name":"project_guides"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"mutation_generation","not_null":false,"ordinal":20,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_review_policy_id","not_null":false,"ordinal":21,"table_name":"project_guides"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_review_policy_hash","not_null":false,"ordinal":22,"table_name":"project_guides"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_revision_policy_id","not_null":false,"ordinal":23,"table_name":"project_guides"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_revision_policy_hash","not_null":false,"ordinal":24,"table_name":"project_guides"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_review_policy_generation","not_null":false,"ordinal":25,"table_name":"project_guides"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"selected_revision_policy_generation","not_null":false,"ordinal":26,"table_name":"project_guides"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"project_role_grants"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"role","not_null":true,"ordinal":4,"table_name":"project_role_grants"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"project_role_grants"},{"data_type":"smallint","default_expression":"'1'::smallint","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":6,"table_name":"project_role_grants"},{"data_type":"character varying(16)","default_expression":"'manual'::character varying","generated_kind":"00","identity_kind":"00","name":"grant_method","not_null":true,"ordinal":7,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"qualification_snapshot_id","not_null":true,"ordinal":8,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_actor_profile_id","not_null":true,"ordinal":9,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"granted_by_admin_role_grant_id","not_null":true,"ordinal":10,"table_name":"project_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"grant_reason","not_null":true,"ordinal":11,"table_name":"project_role_grants"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"granted_at","not_null":true,"ordinal":12,"table_name":"project_role_grants"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_actor_profile_id","not_null":false,"ordinal":13,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_by_admin_role_grant_id","not_null":false,"ordinal":14,"table_name":"project_role_grants"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_reason","not_null":false,"ordinal":15,"table_name":"project_role_grants"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revoked_at","not_null":false,"ordinal":16,"table_name":"project_role_grants"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":3,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requested_role","not_null":true,"ordinal":4,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"skills_snapshot","not_null":true,"ordinal":5,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reputation_snapshot","not_null":true,"ordinal":6,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"prior_project_work_refs","not_null":true,"ordinal":7,"table_name":"project_role_qualification_snapshots"},{"data_type":"jsonb","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_expertise_refs","not_null":true,"ordinal":8,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"captured_by_actor_profile_id","not_null":true,"ordinal":9,"table_name":"project_role_qualification_snapshots"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"captured_by_admin_role_grant_id","not_null":true,"ordinal":10,"table_name":"project_role_qualification_snapshots"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"captured_at","not_null":true,"ordinal":11,"table_name":"project_role_qualification_snapshots"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"project_setup_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"project_setup_runs"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"project_setup_runs"},{"data_type":"character varying(155)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"celery_task_id","not_null":false,"ordinal":7,"table_name":"project_setup_runs"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":8,"table_name":"project_setup_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"current_step","not_null":true,"ordinal":9,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_sufficiency_report_id","not_null":false,"ordinal":10,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_submission_artifact_policy_id","not_null":false,"ordinal":11,"table_name":"project_setup_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_code","not_null":false,"ordinal":12,"table_name":"project_setup_runs"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_summary","not_null":false,"ordinal":13,"table_name":"project_setup_runs"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":14,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":15,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":16,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"started_at","not_null":false,"ordinal":17,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"finished_at","not_null":false,"ordinal":18,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"output_post_submit_checker_policy_id","not_null":false,"ordinal":19,"table_name":"project_setup_runs"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"post_submit_derivation_summary","not_null":false,"ordinal":20,"table_name":"project_setup_runs"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":21,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorized_by_actor_profile_id","not_null":false,"ordinal":22,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorized_via_identity_link_id","not_null":false,"ordinal":23,"table_name":"project_setup_runs"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorized_by_admin_role_grant_id","not_null":false,"ordinal":24,"table_name":"project_setup_runs"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_scope_type","not_null":false,"ordinal":25,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_scope_project_id","not_null":false,"ordinal":26,"table_name":"project_setup_runs"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_action_id","not_null":false,"ordinal":27,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":28,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"error_artifact_incident_id","not_null":false,"ordinal":29,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"continuation_verification_job_id","not_null":false,"ordinal":30,"table_name":"project_setup_runs"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"continuation_started_at","not_null":false,"ordinal":31,"table_name":"project_setup_runs"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"projects"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"name","not_null":true,"ordinal":2,"table_name":"projects"},{"data_type":"character varying(120)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"slug","not_null":true,"ordinal":3,"table_name":"projects"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"description","not_null":false,"ordinal":4,"table_name":"projects"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"projects"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":6,"table_name":"projects"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":7,"table_name":"projects"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":8,"table_name":"projects"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":9,"table_name":"projects"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":10,"table_name":"projects"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":11,"table_name":"projects"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":12,"table_name":"projects"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":13,"table_name":"projects"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":true,"ordinal":2,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":3,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":4,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":5,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":6,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":7,"table_name":"review_admission_idempotency_records"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":8,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"admitting_checker_run_id","not_null":true,"ordinal":9,"table_name":"review_admission_idempotency_records"},{"data_type":"character varying(16)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_queue_entry_id","not_null":false,"ordinal":11,"table_name":"review_admission_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":12,"table_name":"review_admission_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":13,"table_name":"review_admission_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_leases"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_queue_entry_id","not_null":true,"ordinal":2,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":3,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":4,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":5,"table_name":"review_leases"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":6,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reviewer_id","not_null":true,"ordinal":7,"table_name":"review_leases"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reviewer_contribution_policy_version_id","not_null":true,"ordinal":8,"table_name":"review_leases"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"attempt_generation","not_null":true,"ordinal":9,"table_name":"review_leases"},{"data_type":"character varying(16)","default_expression":"'active'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":10,"table_name":"review_leases"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"claimed_at","not_null":true,"ordinal":11,"table_name":"review_leases"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"expires_at","not_null":true,"ordinal":12,"table_name":"review_leases"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"closed_at","not_null":false,"ordinal":13,"table_name":"review_leases"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"close_reason","not_null":false,"ordinal":14,"table_name":"review_leases"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"review_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"review_policies"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"requires_second_review","not_null":true,"ordinal":4,"table_name":"review_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"allowed_decisions","not_null":true,"ordinal":5,"table_name":"review_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"minimum_finding_fields","not_null":true,"ordinal":6,"table_name":"review_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":7,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_generation","not_null":true,"ordinal":8,"table_name":"review_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":9,"table_name":"review_policies"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantics_status","not_null":true,"ordinal":10,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":11,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_preference_window_seconds","not_null":false,"ordinal":12,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"review_lease_duration_seconds","not_null":false,"ordinal":13,"table_name":"review_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"max_active_review_leases_per_reviewer","not_null":false,"ordinal":14,"table_name":"review_policies"},{"data_type":"boolean","default_expression":"","generated_kind":"00","identity_kind":"00","name":"self_review_allowed","not_null":false,"ordinal":15,"table_name":"review_policies"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reject_policy","not_null":false,"ordinal":16,"table_name":"review_policies"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"finding_evidence_requirement","not_null":false,"ordinal":17,"table_name":"review_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_policy_hash","not_null":false,"ordinal":18,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":19,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":20,"table_name":"review_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":21,"table_name":"review_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":22,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":23,"table_name":"review_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":24,"table_name":"review_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":25,"table_name":"review_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":3,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_id","not_null":true,"ordinal":4,"table_name":"review_queue_entries"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"submission_version","not_null":true,"ordinal":5,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"admitting_checker_run_id","not_null":true,"ordinal":6,"table_name":"review_queue_entries"},{"data_type":"character varying(16)","default_expression":"'pending'::character varying","generated_kind":"00","identity_kind":"00","name":"queue_state","not_null":true,"ordinal":7,"table_name":"review_queue_entries"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"routing_mode","not_null":true,"ordinal":8,"table_name":"review_queue_entries"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"routing_reason","not_null":true,"ordinal":9,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"first_queued_at","not_null":true,"ordinal":10,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"available_since","not_null":true,"ordinal":11,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"preferred_reviewer_id","not_null":false,"ordinal":12,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"preference_expires_at","not_null":false,"ordinal":13,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"closed_at","not_null":false,"ordinal":14,"table_name":"review_queue_entries"},{"data_type":"character varying(32)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"closed_reason","not_null":false,"ordinal":15,"table_name":"review_queue_entries"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"routing_generation","not_null":true,"ordinal":16,"table_name":"review_queue_entries"},{"data_type":"integer","default_expression":"1","generated_kind":"00","identity_kind":"00","name":"lifecycle_generation","not_null":true,"ordinal":17,"table_name":"review_queue_entries"},{"data_type":"timestamp with time zone","default_expression":"statement_timestamp()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":18,"table_name":"review_queue_entries"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"active_lease_id","not_null":false,"ordinal":19,"table_name":"review_queue_entries"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"revision_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":3,"table_name":"revision_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"max_revision_rounds","not_null":true,"ordinal":4,"table_name":"revision_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"revision_deadline_hours","not_null":true,"ordinal":5,"table_name":"revision_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"allowed_resubmission_states","not_null":true,"ordinal":6,"table_name":"revision_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"reviewer_reassignment_rule","not_null":false,"ordinal":7,"table_name":"revision_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":8,"table_name":"revision_policies"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_generation","not_null":true,"ordinal":9,"table_name":"revision_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":10,"table_name":"revision_policies"},{"data_type":"character varying(24)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantics_status","not_null":true,"ordinal":11,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":12,"table_name":"revision_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_policy_hash","not_null":false,"ordinal":13,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":14,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":15,"table_name":"revision_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":16,"table_name":"revision_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":17,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":18,"table_name":"revision_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":19,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"authorization_decision_event_id","not_null":false,"ordinal":20,"table_name":"revision_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":3,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_version","not_null":true,"ordinal":4,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":5,"table_name":"submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_hash","not_null":true,"ordinal":6,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_version","not_null":true,"ordinal":7,"table_name":"submission_artifact_policies"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"lifecycle_status","not_null":true,"ordinal":8,"table_name":"submission_artifact_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_body","not_null":true,"ordinal":9,"table_name":"submission_artifact_policies"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_hash","not_null":true,"ordinal":10,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"derivation_source","not_null":true,"ordinal":11,"table_name":"submission_artifact_policies"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_material_refs","not_null":true,"ordinal":12,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"derivation_agent_name","not_null":false,"ordinal":13,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"derivation_agent_version","not_null":false,"ordinal":14,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":15,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":16,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":17,"table_name":"submission_artifact_policies"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_role","not_null":false,"ordinal":18,"table_name":"submission_artifact_policies"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_actor","not_null":false,"ordinal":19,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_at","not_null":false,"ordinal":20,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_policy_id","not_null":false,"ordinal":21,"table_name":"submission_artifact_policies"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"superseded_at","not_null":false,"ordinal":22,"table_name":"submission_artifact_policies"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"change_summary","not_null":false,"ordinal":23,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_actor_profile_id","not_null":false,"ordinal":24,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_via_identity_link_id","not_null":false,"ordinal":25,"table_name":"submission_artifact_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_admin_role_grant_id","not_null":false,"ordinal":26,"table_name":"submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by_service_identity","not_null":false,"ordinal":27,"table_name":"submission_artifact_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_type","not_null":false,"ordinal":28,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_scope_project_id","not_null":false,"ordinal":29,"table_name":"submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_action_id","not_null":false,"ordinal":30,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"creation_decision_event_id","not_null":false,"ordinal":31,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_actor_profile_id","not_null":false,"ordinal":32,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_via_identity_link_id","not_null":false,"ordinal":33,"table_name":"submission_artifact_policies"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approved_by_admin_role_grant_id","not_null":false,"ordinal":34,"table_name":"submission_artifact_policies"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_scope_type","not_null":false,"ordinal":35,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_scope_project_id","not_null":false,"ordinal":36,"table_name":"submission_artifact_policies"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_action_id","not_null":false,"ordinal":37,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"approval_decision_event_id","not_null":false,"ordinal":38,"table_name":"submission_artifact_policies"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"durable_intent_id","not_null":true,"ordinal":2,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_evidence_set_id","not_null":true,"ordinal":3,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":4,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_content_id","not_null":true,"ordinal":5,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verified_replica_id","not_null":true,"ordinal":6,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"verification_receipt_id","not_null":true,"ordinal":7,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_operation_receipt_id","not_null":false,"ordinal":8,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_observation_receipt_id","not_null":false,"ordinal":9,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":10,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":11,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":12,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":13,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assignment_id","not_null":true,"ordinal":14,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_id","not_null":false,"ordinal":15,"table_name":"submission_bundle_admissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"predecessor_submission_version","not_null":false,"ordinal":16,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_policy_context_hash","not_null":true,"ordinal":17,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_id","not_null":true,"ordinal":18,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"semantic_manifest_sha256","not_null":true,"ordinal":19,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_sha256","not_null":true,"ordinal":20,"table_name":"submission_bundle_admissions"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"archive_byte_count","not_null":true,"ordinal":21,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(16)","default_expression":"'ready'::character varying","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":22,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"ready_at","not_null":true,"ordinal":23,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"consumed_at","not_null":false,"ordinal":24,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"consumed_by_submission_id","not_null":false,"ordinal":25,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"stale_at","not_null":false,"ordinal":26,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"stale_reason","not_null":false,"ordinal":27,"table_name":"submission_bundle_admissions"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":28,"table_name":"submission_bundle_admissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_bundle_durable_intents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"pre_submit_evidence_set_id","not_null":true,"ordinal":2,"table_name":"submission_bundle_durable_intents"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"put_attempt_id","not_null":true,"ordinal":3,"table_name":"submission_bundle_durable_intents"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":4,"table_name":"submission_bundle_durable_intents"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"actor_profile_id","not_null":true,"ordinal":2,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"identity_link_id","not_null":true,"ordinal":3,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"service_identity","not_null":false,"ordinal":4,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(160)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"action_id","not_null":true,"ordinal":5,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"idempotency_key","not_null":false,"ordinal":6,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"request_digest","not_null":true,"ordinal":7,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_digest","not_null":true,"ordinal":8,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"resource_context_json","not_null":true,"ordinal":9,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"operation_id","not_null":true,"ordinal":10,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":11,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"guide_id","not_null":true,"ordinal":12,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_snapshot_id","not_null":true,"ordinal":13,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"policy_id","not_null":true,"ordinal":14,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_run_id","not_null":false,"ordinal":15,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"bigint","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_generation","not_null":true,"ordinal":16,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"setup_task_id","not_null":false,"ordinal":17,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"uuid","default_expression":"","generated_kind":"00","identity_kind":"00","name":"correlation_id","not_null":false,"ordinal":18,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(16)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":19,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"response_json","not_null":false,"ordinal":20,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_policy_id","not_null":false,"ordinal":21,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_effective_policy_id","not_null":false,"ordinal":22,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_pre_submit_policy_id","not_null":false,"ordinal":23,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":24,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"committed_at","not_null":false,"ordinal":25,"table_name":"submission_policy_mutation_idempotency_records"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":2,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contributor_id","not_null":true,"ordinal":3,"table_name":"submissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"version","not_null":true,"ordinal":4,"table_name":"submissions"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":5,"table_name":"submissions"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"summary","not_null":true,"ordinal":6,"table_name":"submissions"},{"data_type":"character varying(1000)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"package_uri","not_null":false,"ordinal":7,"table_name":"submissions"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"package_hash","not_null":true,"ordinal":8,"table_name":"submissions"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"artifact_hash_manifest","not_null":true,"ordinal":9,"table_name":"submissions"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"worker_attestation","not_null":true,"ordinal":10,"table_name":"submissions"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_version","not_null":true,"ordinal":11,"table_name":"submissions"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_payment_policy_version","not_null":true,"ordinal":12,"table_name":"submissions"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"submitted_at","not_null":true,"ordinal":13,"table_name":"submissions"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_at","not_null":false,"ordinal":14,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"supersedes_submission_id","not_null":false,"ordinal":15,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_id","not_null":false,"ordinal":16,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_hash","not_null":false,"ordinal":17,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_id","not_null":false,"ordinal":18,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_hash","not_null":false,"ordinal":19,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_policy_id","not_null":false,"ordinal":20,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_bundle_hash","not_null":false,"ordinal":21,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_id","not_null":false,"ordinal":22,"table_name":"submissions"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_version","not_null":false,"ordinal":23,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_hash","not_null":false,"ordinal":24,"table_name":"submissions"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_body","not_null":false,"ordinal":25,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_id","not_null":true,"ordinal":26,"table_name":"submissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_generation","not_null":true,"ordinal":27,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_hash","not_null":true,"ordinal":28,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_id","not_null":true,"ordinal":29,"table_name":"submissions"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_generation","not_null":true,"ordinal":30,"table_name":"submissions"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_hash","not_null":true,"ordinal":31,"table_name":"submissions"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"task_assignments"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_id","not_null":true,"ordinal":2,"table_name":"task_assignments"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"contributor_id","not_null":true,"ordinal":3,"table_name":"task_assignments"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assigned_by","not_null":true,"ordinal":4,"table_name":"task_assignments"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"assigned_at","not_null":true,"ordinal":5,"table_name":"task_assignments"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"accepted_at","not_null":false,"ordinal":6,"table_name":"task_assignments"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"released_at","not_null":false,"ordinal":7,"table_name":"task_assignments"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":8,"table_name":"task_assignments"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"id","not_null":true,"ordinal":1,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"project_id","not_null":true,"ordinal":2,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_version","not_null":false,"ordinal":3,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_payment_policy_version","not_null":false,"ordinal":4,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_type","not_null":true,"ordinal":5,"table_name":"workstream_tasks"},{"data_type":"character varying(500)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_ref","not_null":false,"ordinal":6,"table_name":"workstream_tasks"},{"data_type":"character varying(128)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"source_payload_hash","not_null":false,"ordinal":7,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"import_batch_id","not_null":false,"ordinal":8,"table_name":"workstream_tasks"},{"data_type":"character varying(200)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"external_task_id","not_null":false,"ordinal":9,"table_name":"workstream_tasks"},{"data_type":"character varying(300)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"title","not_null":true,"ordinal":10,"table_name":"workstream_tasks"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"description","not_null":true,"ordinal":11,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"task_type","not_null":false,"ordinal":12,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"difficulty","not_null":false,"ordinal":13,"table_name":"workstream_tasks"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"skill_tags","not_null":true,"ordinal":14,"table_name":"workstream_tasks"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"estimated_time_minutes","not_null":false,"ordinal":15,"table_name":"workstream_tasks"},{"data_type":"numeric(12,2)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"base_amount","not_null":false,"ordinal":16,"table_name":"workstream_tasks"},{"data_type":"character varying(20)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"currency","not_null":false,"ordinal":17,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"payout_type","not_null":false,"ordinal":18,"table_name":"workstream_tasks"},{"data_type":"character varying(30)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"status","not_null":true,"ordinal":19,"table_name":"workstream_tasks"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"acceptance_criteria","not_null":false,"ordinal":20,"table_name":"workstream_tasks"},{"data_type":"text","default_expression":"","generated_kind":"00","identity_kind":"00","name":"rejection_criteria","not_null":false,"ordinal":21,"table_name":"workstream_tasks"},{"data_type":"timestamp with time zone","default_expression":"","generated_kind":"00","identity_kind":"00","name":"deadline_at","not_null":false,"ordinal":22,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"created_by","not_null":true,"ordinal":23,"table_name":"workstream_tasks"},{"data_type":"character varying(100)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"assigned_to","not_null":false,"ordinal":24,"table_name":"workstream_tasks"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"created_at","not_null":true,"ordinal":25,"table_name":"workstream_tasks"},{"data_type":"timestamp with time zone","default_expression":"now()","generated_kind":"00","identity_kind":"00","name":"updated_at","not_null":true,"ordinal":26,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_id","not_null":false,"ordinal":27,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_guide_source_snapshot_hash","not_null":false,"ordinal":28,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_id","not_null":false,"ordinal":29,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_effective_project_submission_artifact_policy_hash","not_null":false,"ordinal":30,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_policy_id","not_null":false,"ordinal":31,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_pre_submit_checker_bundle_hash","not_null":false,"ordinal":32,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_id","not_null":false,"ordinal":33,"table_name":"workstream_tasks"},{"data_type":"character varying(50)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_version","not_null":false,"ordinal":34,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_hash","not_null":false,"ordinal":35,"table_name":"workstream_tasks"},{"data_type":"json","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_post_submit_checker_policy_body","not_null":false,"ordinal":36,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_id","not_null":false,"ordinal":37,"table_name":"workstream_tasks"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_generation","not_null":false,"ordinal":38,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_review_policy_hash","not_null":false,"ordinal":39,"table_name":"workstream_tasks"},{"data_type":"character varying(36)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_id","not_null":false,"ordinal":40,"table_name":"workstream_tasks"},{"data_type":"integer","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_generation","not_null":false,"ordinal":41,"table_name":"workstream_tasks"},{"data_type":"character varying(71)","default_expression":"","generated_kind":"00","identity_kind":"00","name":"locked_revision_policy_hash","not_null":false,"ordinal":42,"table_name":"workstream_tasks"}],"constraints":[{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"actor_identity_link_profile_guard","table_name":"actor_identity_links"},{"definition":"CHECK (subject_kind::text = 'service'::text OR last_verified_at IS NOT NULL)","kind":"c","name":"ck_actor_identity_links_human_verified","table_name":"actor_identity_links"},{"definition":"CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_actor_identity_links_id_uuid","table_name":"actor_identity_links"},{"definition":"CHECK (length(btrim(issuer::text)) >= 1 AND length(btrim(issuer::text)) <= 200)","kind":"c","name":"ck_actor_identity_links_issuer","table_name":"actor_identity_links"},{"definition":"CHECK ((revoked_reason IS NULL OR revoked_reason::text = btrim(revoked_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(revoked_reason::text) >= 1 AND octet_length(revoked_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500))","kind":"c","name":"ck_actor_identity_links_lifecycle_reason_bounds","table_name":"actor_identity_links"},{"definition":"CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)","kind":"c","name":"ck_actor_identity_links_reactivation_fields","table_name":"actor_identity_links"},{"definition":"CHECK (status::text = 'active'::text AND revoked_by IS NULL AND revoked_at IS NULL AND revoked_reason IS NULL OR status::text = 'revoked'::text AND revoked_by IS NOT NULL AND revoked_at IS NOT NULL AND revoked_reason IS NOT NULL)","kind":"c","name":"ck_actor_identity_links_revocation_fields","table_name":"actor_identity_links"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'revoked']))","kind":"c","name":"ck_actor_identity_links_status","table_name":"actor_identity_links"},{"definition":"CHECK (length(btrim(subject::text)) >= 1 AND length(btrim(subject::text)) <= 200)","kind":"c","name":"ck_actor_identity_links_subject","table_name":"actor_identity_links"},{"definition":"CHECK (subject_kind::text = ANY (ARRAY['human', 'service']))","kind":"c","name":"ck_actor_identity_links_subject_kind","table_name":"actor_identity_links"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_actor_identity_links_actor_profile_id_actor_profiles","table_name":"actor_identity_links"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_actor_identity_links","table_name":"actor_identity_links"},{"definition":"UNIQUE (actor_profile_id)","kind":"u","name":"uq_actor_identity_links_actor_profile","table_name":"actor_identity_links"},{"definition":"UNIQUE (issuer, subject)","kind":"u","name":"uq_actor_identity_links_external_identity","table_name":"actor_identity_links"},{"definition":"UNIQUE (id, actor_profile_id)","kind":"u","name":"uq_actor_identity_links_id_profile","table_name":"actor_identity_links"},{"definition":"CHECK (classified_count = 0 AND manifest_sha256 IS NULL AND envelope_sha256 IS NULL OR classified_count > 0 AND manifest_sha256 IS NOT NULL AND envelope_sha256 IS NOT NULL)","kind":"c","name":"ck_actor_profile_migration_state_evidence","table_name":"actor_profile_migration_state"},{"definition":"CHECK (service_identity_mapped_count >= 0 AND service_identity_mapped_count <= 7 AND service_identity_source_row_set_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_database_binding::text ~ '^postgres-v1:[0-9a-f]{64}$'::text AND (service_identity_mapped_count = 0 AND service_identity_manifest_sha256 IS NULL AND service_identity_envelope_sha256 IS NULL OR service_identity_mapped_count >= 1 AND service_identity_mapped_count <= 7 AND service_identity_manifest_sha256::text ~ '^[0-9a-f]{64}$'::text AND service_identity_envelope_sha256::text ~ '^[0-9a-f]{64}$'::text))","kind":"c","name":"ck_actor_profile_migration_state_service_identity_evidence","table_name":"actor_profile_migration_state"},{"definition":"CHECK (id = 1 AND schema_version = 1 AND classified_count >= 0)","kind":"c","name":"ck_actor_profile_migration_state_singleton","table_name":"actor_profile_migration_state"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_actor_profile_migration_state","table_name":"actor_profile_migration_state"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"actor_profile_link_guard","table_name":"actor_profiles"},{"definition":"CHECK (actor_kind::text = ANY (ARRAY['human', 'service']))","kind":"c","name":"ck_actor_profiles_actor_kind","table_name":"actor_profiles"},{"definition":"CHECK (id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_actor_profiles_id_uuid","table_name":"actor_profiles"},{"definition":"CHECK (actor_kind::text = 'human'::text AND provisioning_method::text = 'automatic_first_access'::text OR actor_kind::text = 'service'::text AND provisioning_method::text = 'manual_service_provisioning'::text)","kind":"c","name":"ck_actor_profiles_kind_provisioning","table_name":"actor_profiles"},{"definition":"CHECK (actor_kind::text = 'human'::text AND service_identity IS NULL OR actor_kind::text = 'service'::text AND (service_identity::text = ANY (ARRAY['workstream.artifact.verifier', 'workstream.artifact.put_resolver', 'workstream.artifact.scheduler', 'workstream.artifact.binding', 'workstream.artifact.guide_reader', 'workstream.artifact.materializer', 'workstream.artifact.checker_output', 'workstream.project.setup', 'workstream.review.preference_expiry', 'workstream.review.lease_expiry', 'workstream.review.authority_invalidation_reconciliation', 'workstream.review.reconciliation', 'workstream.review.artifact_reference_reconciliation', 'workstream.review.projection'])))","kind":"c","name":"ck_actor_profiles_kind_service_identity","table_name":"actor_profiles"},{"definition":"CHECK (status::text = 'active'::text AND suspended_by IS NULL AND suspended_at IS NULL AND suspension_reason IS NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'suspended'::text AND suspended_by IS NOT NULL AND suspended_at IS NOT NULL AND suspension_reason IS NOT NULL AND deactivated_by IS NULL AND deactivated_at IS NULL AND deactivation_reason IS NULL OR status::text = 'deactivated'::text AND deactivated_by IS NOT NULL AND deactivated_at IS NOT NULL AND deactivation_reason IS NOT NULL)","kind":"c","name":"ck_actor_profiles_lifecycle_fields","table_name":"actor_profiles"},{"definition":"CHECK ((suspension_reason IS NULL OR suspension_reason::text = btrim(suspension_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(suspension_reason::text) >= 1 AND octet_length(suspension_reason::text) <= 500) AND (reactivation_reason IS NULL OR reactivation_reason::text = btrim(reactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(reactivation_reason::text) >= 1 AND octet_length(reactivation_reason::text) <= 500) AND (deactivation_reason IS NULL OR deactivation_reason::text = btrim(deactivation_reason::text, ((((((((((((((((((((((' '::text || chr(28)) || chr(29)) || chr(30)) || chr(31)) || chr(133)) || chr(160)) || chr(5760)) || chr(8192)) || chr(8193)) || chr(8194)) || chr(8195)) || chr(8196)) || chr(8197)) || chr(8198)) || chr(8199)) || chr(8200)) || chr(8201)) || chr(8202)) || chr(8232)) || chr(8233)) || chr(8239)) || chr(8287)) || chr(12288)) AND octet_length(deactivation_reason::text) >= 1 AND octet_length(deactivation_reason::text) <= 500))","kind":"c","name":"ck_actor_profiles_lifecycle_reason_bounds","table_name":"actor_profiles"},{"definition":"CHECK (provisioning_method::text = ANY (ARRAY['automatic_first_access', 'manual_service_provisioning']))","kind":"c","name":"ck_actor_profiles_provisioning_method","table_name":"actor_profiles"},{"definition":"CHECK (reactivated_by IS NULL AND reactivated_at IS NULL AND reactivation_reason IS NULL OR reactivated_by IS NOT NULL AND reactivated_at IS NOT NULL AND reactivation_reason IS NOT NULL)","kind":"c","name":"ck_actor_profiles_reactivation_fields","table_name":"actor_profiles"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'suspended', 'deactivated']))","kind":"c","name":"ck_actor_profiles_status","table_name":"actor_profiles"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_actor_profiles","table_name":"actor_profiles"},{"definition":"UNIQUE (service_identity)","kind":"u","name":"service_identity","table_name":"actor_profiles"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"admin_role_grants_bootstrap_invariant","table_name":"admin_role_grants"},{"definition":"CHECK (granted_by_system_principal::text = 'workstream:system:bootstrap'::text AND granted_by_actor_profile_id IS NULL AND granted_by_admin_role_grant_id IS NULL OR granted_by_system_principal IS NULL AND granted_by_actor_profile_id IS NOT NULL AND granted_by_admin_role_grant_id IS NOT NULL)","kind":"c","name":"ck_admin_role_grants_grant_attribution","table_name":"admin_role_grants"},{"definition":"CHECK (octet_length(grant_reason) >= 1 AND octet_length(grant_reason) <= 500)","kind":"c","name":"ck_admin_role_grants_grant_reason","table_name":"admin_role_grants"},{"definition":"CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND octet_length(revoked_reason) >= 1 AND octet_length(revoked_reason) <= 500 AND revoked_at IS NOT NULL)","kind":"c","name":"ck_admin_role_grants_lifecycle","table_name":"admin_role_grants"},{"definition":"CHECK (role::text = ANY (ARRAY['access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority']))","kind":"c","name":"ck_admin_role_grants_role","table_name":"admin_role_grants"},{"definition":"CHECK (scope_type::text = 'system'::text AND scope_project_id IS NULL OR scope_type::text = 'project'::text AND scope_project_id IS NOT NULL AND (role::text <> ALL (ARRAY['access_administrator', 'operator'])))","kind":"c","name":"ck_admin_role_grants_role_scope","table_name":"admin_role_grants"},{"definition":"CHECK (scope_type::text = ANY (ARRAY['system', 'project']))","kind":"c","name":"ck_admin_role_grants_scope_type","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_admin_role_grants_granted_by_actor_profile_id_actor_profiles","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_admin_role_grants_granted_by_admin_role_grant_id_adm_81e0","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_admin_role_grants_revoked_by_actor_profile_id_actor_profiles","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_admin_role_grants_revoked_by_admin_role_grant_id_adm_78b5","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_admin_role_grants_scope_project_id_projects","table_name":"admin_role_grants"},{"definition":"FOREIGN KEY (target_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_admin_role_grants_target_actor_profile_id_actor_profiles","table_name":"admin_role_grants"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_admin_role_grants","table_name":"admin_role_grants"},{"definition":"CHECK (octet_length(key_digest) = 32)","kind":"c","name":"ck_api_rate_control_counters_digest_length","table_name":"api_rate_control_counters"},{"definition":"CHECK (request_count >= 1 AND request_count <= '9223372036854775807'::bigint)","kind":"c","name":"ck_api_rate_control_counters_request_count","table_name":"api_rate_control_counters"},{"definition":"CHECK (control_scope::text = ANY (ARRAY['first_access', 'admin_mutation', 'authorization_read']))","kind":"c","name":"ck_api_rate_control_counters_scope_token","table_name":"api_rate_control_counters"},{"definition":"CHECK (window_started_at < window_expires_at)","kind":"c","name":"ck_api_rate_control_counters_window_order","table_name":"api_rate_control_counters"},{"definition":"PRIMARY KEY (control_scope, key_digest)","kind":"p","name":"pk_api_rate_control_counters","table_name":"api_rate_control_counters"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_artifact_admission_charges_byte_count_nonnegative","table_name":"artifact_admission_charges"},{"definition":"CHECK (cas_version >= 0)","kind":"c","name":"ck_artifact_admission_charges_cas_nonnegative","table_name":"artifact_admission_charges"},{"definition":"CHECK ((state::text = 'completed'::text) = (completed_at IS NOT NULL))","kind":"c","name":"ck_artifact_admission_charges_completed_timestamp","table_name":"artifact_admission_charges"},{"definition":"CHECK (creating_operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_admission_charges_operation_identity_shape","table_name":"artifact_admission_charges"},{"definition":"CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))","kind":"c","name":"ck_artifact_admission_charges_producer_type","table_name":"artifact_admission_charges"},{"definition":"CHECK ((state::text = 'released'::text) = (released_at IS NOT NULL))","kind":"c","name":"ck_artifact_admission_charges_released_timestamp","table_name":"artifact_admission_charges"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_admission_charges_sha256_shape","table_name":"artifact_admission_charges"},{"definition":"CHECK (state::text = ANY (ARRAY['provisional', 'completed', 'released']))","kind":"c","name":"ck_artifact_admission_charges_state","table_name":"artifact_admission_charges"},{"definition":"FOREIGN KEY (scope_type, scope_id) REFERENCES artifact_admission_scopes(scope_type, scope_id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_admission_charges_scope","table_name":"artifact_admission_charges"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_admission_charges","table_name":"artifact_admission_charges"},{"definition":"UNIQUE (scope_type, scope_id, sha256, byte_count)","kind":"u","name":"uq_artifact_admission_charge_scope_content","table_name":"artifact_admission_charges"},{"definition":"CHECK (cas_version >= 0)","kind":"c","name":"ck_artifact_admission_scopes_cas_nonnegative","table_name":"artifact_admission_scopes"},{"definition":"CHECK (counted_bytes >= 0 AND counted_bytes <= limit_bytes)","kind":"c","name":"ck_artifact_admission_scopes_counted_bytes_within_limit","table_name":"artifact_admission_scopes"},{"definition":"CHECK (limit_bytes > 0)","kind":"c","name":"ck_artifact_admission_scopes_limit_positive","table_name":"artifact_admission_scopes"},{"definition":"CHECK (octet_length(scope_id::text) >= 1 AND octet_length(scope_id::text) <= 120)","kind":"c","name":"ck_artifact_admission_scopes_scope_id_bounds","table_name":"artifact_admission_scopes"},{"definition":"CHECK (scope_type::text = ANY (ARRAY['deployment', 'project', 'producer', 'task']))","kind":"c","name":"ck_artifact_admission_scopes_scope_type","table_name":"artifact_admission_scopes"},{"definition":"PRIMARY KEY (scope_type, scope_id)","kind":"p","name":"pk_artifact_admission_scopes","table_name":"artifact_admission_scopes"},{"definition":"CHECK (scope_version > 0)","kind":"c","name":"ck_artifact_bindings_scope_version_positive","table_name":"artifact_bindings"},{"definition":"CHECK (scope_version = 1 AND supersedes_binding_id IS NULL OR scope_version > 1 AND supersedes_binding_id IS NOT NULL)","kind":"c","name":"ck_artifact_bindings_scope_version_predecessor","table_name":"artifact_bindings"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_bindings_content_id_artifact_contents","table_name":"artifact_bindings"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_bindings_project_id_projects","table_name":"artifact_bindings"},{"definition":"FOREIGN KEY (supersedes_binding_id) REFERENCES artifact_bindings(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_bindings_supersedes_binding_id_artifact_bindings","table_name":"artifact_bindings"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_bindings","table_name":"artifact_bindings"},{"definition":"TRIGGER DEFERRABLE","kind":"t","name":"trg_artifact_binding_history","table_name":"artifact_bindings"},{"definition":"UNIQUE (project_id, resource_type, resource_id, logical_role, scope_version)","kind":"u","name":"uq_artifact_binding_scope_version","table_name":"artifact_bindings"},{"definition":"UNIQUE (supersedes_binding_id)","kind":"u","name":"uq_artifact_binding_supersedes","table_name":"artifact_bindings"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_artifact_contents_byte_count_nonnegative","table_name":"artifact_contents"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_contents_sha256_shape","table_name":"artifact_contents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_contents","table_name":"artifact_contents"},{"definition":"UNIQUE (sha256, byte_count)","kind":"u","name":"uq_artifact_content_digest_size","table_name":"artifact_contents"},{"definition":"CHECK (attempt_number > 0)","kind":"c","name":"ck_artifact_operation_receipts_attempt_positive","table_name":"artifact_operation_receipts"},{"definition":"CHECK (contract_version = 2 AND put_attempt_id IS NOT NULL AND (guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND logical_role IS NULL OR guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR guide_source_item_id IS NULL AND checker_run_id IS NULL AND logical_role IS NULL))","kind":"c","name":"ck_artifact_operation_receipts_contract_producer_reference","table_name":"artifact_operation_receipts"},{"definition":"CHECK (operation::text = 'put'::text)","kind":"c","name":"ck_artifact_operation_receipts_operation","table_name":"artifact_operation_receipts"},{"definition":"CHECK (outcome::text = 'stored_pending_verification'::text)","kind":"c","name":"ck_artifact_operation_receipts_outcome","table_name":"artifact_operation_receipts"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_operation_receipts_request_digest_shape","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_operation_receipts_replica_id_artifact_replicas","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_receipt_checker_run","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_receipt_guide_item","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_receipt_put_attempt","table_name":"artifact_operation_receipts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_operation_receipts","table_name":"artifact_operation_receipts"},{"definition":"UNIQUE (put_attempt_id)","kind":"u","name":"uq_artifact_receipt_put_attempt","table_name":"artifact_operation_receipts"},{"definition":"FOREIGN KEY (attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempt_charges_attempt_id_artifact_put_b25d","table_name":"artifact_put_attempt_charges"},{"definition":"FOREIGN KEY (charge_id) REFERENCES artifact_admission_charges(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempt_charges_charge_id_artifact_admi_85a9","table_name":"artifact_put_attempt_charges"},{"definition":"PRIMARY KEY (attempt_id, charge_id)","kind":"p","name":"pk_artifact_put_attempt_charges","table_name":"artifact_put_attempt_charges"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_artifact_put_attempts_byte_count_nonnegative","table_name":"artifact_put_attempts"},{"definition":"CHECK (canonical_target::text ~ '^sha256/[0-9a-f]{2}/[0-9a-f]{62}$'::text)","kind":"c","name":"ck_artifact_put_attempts_canonical_target_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (execution_mode IS NULL OR (execution_mode::text = ANY (ARRAY['caller_put', 'observation'])))","kind":"c","name":"ck_artifact_put_attempts_execution_mode","table_name":"artifact_put_attempts"},{"definition":"CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))","kind":"c","name":"ck_artifact_put_attempts_executor_lease_pair","table_name":"artifact_put_attempts"},{"definition":"CHECK ((status::text = 'put_in_flight'::text) = (executor_id IS NOT NULL))","kind":"c","name":"ck_artifact_put_attempts_inflight_fence","table_name":"artifact_put_attempts"},{"definition":"CHECK (observation_count >= 0 AND maximum_observations > 0)","kind":"c","name":"ck_artifact_put_attempts_observation_counts","table_name":"artifact_put_attempts"},{"definition":"CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_attempts_operation_identity_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (status::text <> 'prepared'::text OR next_run_at IS NULL AND executor_id IS NULL AND lease_expires_at IS NULL AND execution_generation = 0 AND terminal_result_code IS NULL AND terminal_at IS NULL AND replica_id IS NULL AND receipt_id IS NULL)","kind":"c","name":"ck_artifact_put_attempts_prepared_execution_inactive","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_request_type::text = 'guide'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text OR producer_request_type::text = 'checker_output'::text AND producer_type::text = 'service_identity'::text AND producer_ref::text = 'workstream.artifact.checker_output'::text OR producer_request_type::text = 'submission_bundle'::text AND producer_type::text = 'actor_profile'::text AND producer_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_artifact_put_attempts_producer_identity","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_request_type::text = 'guide'::text AND guide_source_item_id IS NOT NULL AND checker_run_id IS NULL AND task_id IS NULL AND logical_role IS NULL OR producer_request_type::text = 'checker_output'::text AND guide_source_item_id IS NULL AND checker_run_id IS NOT NULL AND task_id IS NOT NULL AND octet_length(logical_role::text) >= 1 AND octet_length(logical_role::text) <= 100 OR producer_request_type::text = 'submission_bundle'::text AND guide_source_item_id IS NULL AND checker_run_id IS NULL AND task_id IS NOT NULL AND logical_role IS NULL)","kind":"c","name":"ck_artifact_put_attempts_producer_reference","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_request_type::text = ANY (ARRAY['guide', 'checker_output', 'submission_bundle']))","kind":"c","name":"ck_artifact_put_attempts_producer_request_type","table_name":"artifact_put_attempts"},{"definition":"CHECK (producer_type::text = ANY (ARRAY['actor_profile', 'service_identity']))","kind":"c","name":"ck_artifact_put_attempts_producer_type","table_name":"artifact_put_attempts"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_attempts_request_digest_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_attempts_sha256_shape","table_name":"artifact_put_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['prepared', 'put_in_flight', 'acknowledgement_unknown', 'object_confirmed', 'absent_replay_required', 'integrity_mismatch', 'provider_unavailable', 'conflict']))","kind":"c","name":"ck_artifact_put_attempts_status","table_name":"artifact_put_attempts"},{"definition":"CHECK (status::text <> 'provider_unavailable'::text OR observation_count >= maximum_observations AND next_run_at IS NULL AND terminal_at IS NOT NULL)","kind":"c","name":"ck_artifact_put_attempts_unavailable_exhausted","table_name":"artifact_put_attempts"},{"definition":"CHECK (execution_generation >= 0 AND cas_version >= 0)","kind":"c","name":"ck_artifact_put_attempts_versions_nonnegative","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_checker_run_id_checker_runs","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (guide_source_item_id) REFERENCES guide_source_snapshot_items(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_guide_source_item_id_guide_sou_e48c","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (storage_namespace_id, namespace_fingerprint) REFERENCES artifact_storage_namespaces(id, namespace_fingerprint) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_namespace_fingerprint","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_project_id_projects","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_receipt_id_artifact_operation_receipts","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_replica_id_artifact_replicas","table_name":"artifact_put_attempts"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_attempts_task_id_workstream_tasks","table_name":"artifact_put_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_put_attempts","table_name":"artifact_put_attempts"},{"definition":"UNIQUE (operation_identity)","kind":"u","name":"uq_artifact_put_attempt_operation","table_name":"artifact_put_attempts"},{"definition":"CHECK (expected_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_observation_receipts_expected_sha256","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (expected_byte_count >= 0)","kind":"c","name":"ck_artifact_put_observation_receipts_expected_size","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK ((outcome::text = ANY (ARRAY['observed_confirmed', 'observed_integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))","kind":"c","name":"ck_artifact_put_observation_receipts_observed_facts","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_put_observation_receipts_observed_sha256","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)","kind":"c","name":"ck_artifact_put_observation_receipts_observed_size","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (outcome::text = ANY (ARRAY['observed_confirmed', 'observed_missing', 'observed_integrity_mismatch', 'conflict']))","kind":"c","name":"ck_artifact_put_observation_receipts_outcome","table_name":"artifact_put_observation_receipts"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_put_observation_receipts_put_attempt_id_art_237d","table_name":"artifact_put_observation_receipts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_put_observation_receipts","table_name":"artifact_put_observation_receipts"},{"definition":"UNIQUE (put_attempt_id, execution_generation)","kind":"u","name":"uq_artifact_put_observation_fence","table_name":"artifact_put_observation_receipts"},{"definition":"CHECK (cas_version >= 0)","kind":"c","name":"ck_artifact_recovery_attempts_cas_nonnegative","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (source_verification_job_id::text <> retry_verification_job_id::text)","kind":"c","name":"ck_artifact_recovery_attempts_distinct_jobs","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (recovery_class::text = 'provider_observation'::text)","kind":"c","name":"ck_artifact_recovery_attempts_recovery_class","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_recovery_attempts_request_digest","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['requested', 'succeeded', 'failed']))","kind":"c","name":"ck_artifact_recovery_attempts_status","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (status::text = 'succeeded'::text AND terminal_result_code::text = 'verified'::text OR status::text = 'failed'::text AND (terminal_result_code::text = ANY (ARRAY['provider_unavailable', 'missing', 'integrity_mismatch', 'conflict'])) OR status::text = 'requested'::text)","kind":"c","name":"ck_artifact_recovery_attempts_terminal_result","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (status::text = 'requested'::text AND terminal_result_code IS NULL AND terminal_at IS NULL AND terminal_audit_event_id IS NULL OR (status::text = ANY (ARRAY['succeeded', 'failed'])) AND terminal_result_code IS NOT NULL AND terminal_at IS NOT NULL AND terminal_audit_event_id IS NOT NULL)","kind":"c","name":"ck_artifact_recovery_attempts_terminal_shape","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (initiation_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_initiation_audit_event_id_2af7","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (parent_recovery_attempt_id) REFERENCES artifact_recovery_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_parent_recovery_attempt_i_130d","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_project_id_projects","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (requester_actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_requester_actor_profile_i_77f5","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (requester_identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_requester_identity_link_i_3619","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (retry_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_retry_verification_job_id_b330","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (source_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_source_verification_job_i_5eac","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_submission_id_submissions","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_task_id_workstream_tasks","table_name":"artifact_recovery_attempts"},{"definition":"FOREIGN KEY (terminal_audit_event_id) REFERENCES audit_events(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_recovery_attempts_terminal_audit_event_id_a_47ab","table_name":"artifact_recovery_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_recovery_attempts","table_name":"artifact_recovery_attempts"},{"definition":"UNIQUE (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)","kind":"u","name":"uq_artifact_recovery_idempotency","table_name":"artifact_recovery_attempts"},{"definition":"UNIQUE (retry_verification_job_id)","kind":"u","name":"uq_artifact_recovery_retry_job","table_name":"artifact_recovery_attempts"},{"definition":"UNIQUE (source_verification_job_id)","kind":"u","name":"uq_artifact_recovery_source_job","table_name":"artifact_recovery_attempts"},{"definition":"CHECK (availability_state::text = ANY (ARRAY['unknown', 'available', 'unavailable']))","kind":"c","name":"ck_artifact_replicas_availability_state","table_name":"artifact_replicas"},{"definition":"CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_replicas_fingerprint_shape","table_name":"artifact_replicas"},{"definition":"CHECK (integrity_state::text = ANY (ARRAY['unknown', 'valid', 'invalid']))","kind":"c","name":"ck_artifact_replicas_integrity_state","table_name":"artifact_replicas"},{"definition":"CHECK (verification_state::text = ANY (ARRAY['pending', 'verified', 'missing', 'integrity_mismatch']))","kind":"c","name":"ck_artifact_replicas_verification_state","table_name":"artifact_replicas"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_replicas_content_id_artifact_contents","table_name":"artifact_replicas"},{"definition":"FOREIGN KEY (storage_namespace_id) REFERENCES artifact_storage_namespaces(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_replicas_storage_namespace_id_artifact_stor_d6cc","table_name":"artifact_replicas"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_replicas","table_name":"artifact_replicas"},{"definition":"UNIQUE (storage_namespace_id, provider_object_ref)","kind":"u","name":"uq_artifact_replica_provider_object","table_name":"artifact_replicas"},{"definition":"UNIQUE (id, content_id)","kind":"u","name":"uq_artifact_replicas_id_content","table_name":"artifact_replicas"},{"definition":"CHECK (namespace_fingerprint::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_storage_namespaces_fingerprint_shape","table_name":"artifact_storage_namespaces"},{"definition":"CHECK (id::text = 'primary'::text)","kind":"c","name":"ck_artifact_storage_namespaces_singleton_id","table_name":"artifact_storage_namespaces"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_storage_namespaces","table_name":"artifact_storage_namespaces"},{"definition":"UNIQUE (namespace_fingerprint)","kind":"u","name":"uq_artifact_storage_namespace_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"UNIQUE (id, namespace_fingerprint)","kind":"u","name":"uq_artifact_storage_namespace_id_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"CHECK (attempt_count >= 0 AND maximum_attempts > 0)","kind":"c","name":"ck_artifact_verification_jobs_attempts","table_name":"artifact_verification_jobs"},{"definition":"CHECK ((executor_id IS NULL) = (lease_expires_at IS NULL))","kind":"c","name":"ck_artifact_verification_jobs_fence_pair","table_name":"artifact_verification_jobs"},{"definition":"CHECK ((status::text = 'running'::text) = (executor_id IS NOT NULL))","kind":"c","name":"ck_artifact_verification_jobs_running_fence","table_name":"artifact_verification_jobs"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'running', 'verified', 'missing', 'integrity_mismatch', 'provider_unavailable', 'conflict']))","kind":"c","name":"ck_artifact_verification_jobs_status","table_name":"artifact_verification_jobs"},{"definition":"CHECK (status::text <> 'provider_unavailable'::text OR next_run_at IS NOT NULL AND terminal_at IS NULL AND attempt_count < maximum_attempts OR next_run_at IS NULL AND terminal_at IS NOT NULL AND attempt_count >= maximum_attempts)","kind":"c","name":"ck_artifact_verification_jobs_unavailable_retryability","table_name":"artifact_verification_jobs"},{"definition":"CHECK (execution_generation >= 0 AND cas_version >= 0)","kind":"c","name":"ck_artifact_verification_jobs_versions","table_name":"artifact_verification_jobs"},{"definition":"FOREIGN KEY (originating_put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_jobs_originating_put_attempt_i_3260","table_name":"artifact_verification_jobs"},{"definition":"FOREIGN KEY (replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_jobs_replica_id_artifact_replicas","table_name":"artifact_verification_jobs"},{"definition":"FOREIGN KEY (parent_verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_parent","table_name":"artifact_verification_jobs"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_verification_jobs","table_name":"artifact_verification_jobs"},{"definition":"UNIQUE (parent_verification_job_id)","kind":"u","name":"uq_artifact_verification_parent","table_name":"artifact_verification_jobs"},{"definition":"CHECK ((outcome::text = ANY (ARRAY['verified', 'integrity_mismatch'])) = (observed_sha256 IS NOT NULL AND observed_byte_count IS NOT NULL))","kind":"c","name":"ck_artifact_verification_receipts_observed_facts","table_name":"artifact_verification_receipts"},{"definition":"CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_artifact_verification_receipts_observed_sha256","table_name":"artifact_verification_receipts"},{"definition":"CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)","kind":"c","name":"ck_artifact_verification_receipts_observed_size","table_name":"artifact_verification_receipts"},{"definition":"CHECK (outcome::text = ANY (ARRAY['verified', 'missing', 'integrity_mismatch', 'conflict']))","kind":"c","name":"ck_artifact_verification_receipts_outcome","table_name":"artifact_verification_receipts"},{"definition":"FOREIGN KEY (verification_job_id) REFERENCES artifact_verification_jobs(id) ON DELETE RESTRICT","kind":"f","name":"fk_artifact_verification_receipts_verification_job_id_a_dabf","table_name":"artifact_verification_receipts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_artifact_verification_receipts","table_name":"artifact_verification_receipts"},{"definition":"UNIQUE (verification_job_id, execution_generation)","kind":"u","name":"uq_artifact_verification_fence","table_name":"artifact_verification_receipts"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND (entity_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'authorization_decision', 'authority_invalidation'])) AND entity_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text AND ((actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile'])) AND actor_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR actor_ref_kind::text = 'system_principal'::text AND actor_id::text = 'workstream:system:bootstrap'::text) AND (target_actor_ref IS NULL OR target_actor_ref_kind::text = 'actor_profile'::text AND target_actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (matched_grant_id IS NULL OR matched_grant_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (project_id IS NULL OR project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (resource_type IS NULL OR (resource_type::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'project', 'qualification_snapshot', 'project_role_grant', 'task', 'submission', 'review', 'contribution', 'compensation_award', 'compensation_delivery', 'operations', 'audit_event', 'project_create_operation', 'project_submission_artifact_policy_mutation', 'project_guide_compilation_attempt', 'project_guide_compilation_request']))) AND (resource_id IS NULL OR resource_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text) AND (target_ref_kind IS NULL OR (target_ref_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant', 'project'])) AND target_ref_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR target_ref_kind::text = 'permission_registry'::text AND (target_ref_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND (invalidation_target_kind IS NULL OR (invalidation_target_kind::text = ANY (ARRAY['actor_profile', 'actor_identity_link', 'admin_role_grant', 'qualification_snapshot', 'project_role_grant'])) AND invalidation_target_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text OR invalidation_target_kind::text = 'permission_registry'::text AND (invalidation_target_ref::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.request', 'project.guide_compilation.execute']))) AND ((entity_type::text <> ALL (ARRAY['authorization_decision', 'authority_invalidation'])) OR entity_id::text = id::text) AND (resource_type::text <> 'project'::text OR resource_id IS NULL OR project_id IS NOT NULL AND resource_id::text = project_id::text))","kind":"c","name":"ck_audit_events_authority_privacy_bounds","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR reason IS NOT NULL AND (event_type::text = 'ActorProfileProvisioned'::text AND reason = 'automatic_first_access'::text OR event_type::text = 'ServiceActorProvisioned'::text AND reason = 'manual_service_provisioning'::text OR event_type::text = 'ActorIdentityLinked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkRevoked'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorIdentityLinkReactivated'::text AND reason = 'identity_lifecycle_change'::text OR event_type::text = 'ActorProfileSuspended'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'ActorProfileReactivated'::text AND reason = 'administrative_correction'::text OR event_type::text = 'ActorProfileDeactivated'::text AND (reason = ANY (ARRAY['security_response', 'administrative_correction'])) OR event_type::text = 'InitialAccessAdministratorBootstrapped'::text AND reason = 'initial_access_bootstrap'::text OR event_type::text = 'AdminRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'AdminRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'AdminRoleGrantIssueDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'LastAccessAdministratorOperationDenied'::text AND reason = 'authorization_policy_denial'::text OR event_type::text = 'ProjectRoleQualificationSnapshotCaptured'::text AND reason = 'qualification_evidence_captured'::text OR event_type::text = 'ProjectRoleGrantIssued'::text AND reason = 'authority_assignment'::text OR event_type::text = 'ProjectRoleGrantRevoked'::text AND reason = 'authority_revocation'::text OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'SensitiveAuthorizationDenied'::text AND reason = 'authorization_evaluation'::text OR event_type::text = 'AuthorityInvalidationRequested'::text AND reason = 'authority_state_changed'::text) AND (permission_id IS NULL OR (permission_id::text = ANY (ARRAY['actor.profile.read_self', 'actor.profile.update_self', 'actor.profile.read_any', 'actor.profile.suspend', 'actor.profile.reactivate', 'actor.profile.deactivate', 'actor.identity_link.read', 'actor.identity_link.revoke', 'actor.identity_link.reactivate', 'actor.service.provision', 'admin_role.read', 'admin_role.grant', 'admin_role.revoke', 'project.create', 'project.read', 'project.update', 'project.archive', 'project.guide.manage', 'project.effective_policy.manage', 'project.task.manage', 'project.review_policy.manage', 'project.role_grant.read', 'project.role_grant.manage', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'task.queue.read', 'task.claim', 'submission.create', 'submission.read_own', 'submission.read_for_review', 'review.queue.read', 'review.queue.inspect', 'review.claim', 'review.release', 'review.decline_preference', 'review.decision', 'review.lease.force_release', 'review.chain.read', 'contribution.read_self', 'contribution.read_project', 'compensation.policy.manage', 'compensation.adapter_binding.manage', 'compensation.award.read', 'compensation.delivery.reconcile', 'operations.status.read', 'operations.timer.run', 'operations.reconcile.run', 'operations.outbox.retry', 'operations.projection.rebuild', 'audit.read', 'audit.export', 'operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.guide_compilation.execute', 'project.guide_compilation.request']))) AND (denial_code IS NULL OR (denial_code::text = ANY (ARRAY['required_scope_missing', 'unsupported_subject_kind', 'service_actor_not_provisioned', 'identity_link_revoked', 'actor_suspended', 'actor_deactivated', 'permission_not_granted', 'scope_not_authorized', 'self_grant_forbidden', 'self_role_revoke_forbidden', 'resource_guard_denied', 'actor_not_found', 'grant_not_found', 'resource_not_found', 'actor_already_suspended', 'actor_not_suspended', 'actor_deactivated_terminal', 'last_access_administrator', 'admin_role_grant_exists', 'project_role_grant_exists', 'identity_link_conflict', 'project_role_grant_already_revoked', 'project_role_grant_replay_state_changed', 'identity_link_already_revoked', 'identity_link_not_revoked', 'resource_project_mismatch', 'idempotency_mismatch', 'invalid_role_scope', 'invalid_project_role', 'qualification_snapshot_invalid']))))","kind":"c","name":"ck_audit_events_authority_registries","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR (event_type::text = ANY (ARRAY['ActorProfileProvisioned', 'ServiceActorProvisioned', 'ActorIdentityLinked', 'ActorIdentityLinkRevoked', 'ActorIdentityLinkReactivated', 'ActorProfileSuspended', 'ActorProfileReactivated', 'ActorProfileDeactivated', 'InitialAccessAdministratorBootstrapped', 'AdminRoleGrantIssued', 'AdminRoleGrantRevoked', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied', 'ProjectRoleQualificationSnapshotCaptured', 'ProjectRoleGrantIssued', 'ProjectRoleGrantReplaced', 'ProjectRoleGrantRevoked', 'SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested'])))","kind":"c","name":"ck_audit_events_authority_tokens","table_name":"audit_events"},{"definition":"CHECK (event_domain::text = 'legacy_lifecycle'::text AND action_id IS NULL OR event_domain::text = 'authority'::text AND (action_id IS NULL OR (event_type::text = ANY (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied'])) AND permission_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)) AND (permission_id IS NULL OR (permission_id::text <> ALL (ARRAY['operations.task.start_override', 'operations.submission_gate.repair', 'operations.checker.retry', 'artifact.binding.read', 'artifact.replica.read', 'artifact.receipt.read', 'artifact.verification_job.read', 'artifact.verification_job.retry', 'artifact.recovery_attempt.read', 'artifact.audit.read', 'artifact.guide_source.ingest', 'artifact.binding.create', 'artifact.review_packet.materialize', 'artifact.verification.execute', 'artifact.pending_work.scan', 'artifact.put_attempt.resolve', 'artifact.guide_source.read', 'artifact.checker_input.materialize', 'artifact.checker_output.write', 'review.queue.override', 'project.setup_diagnostic.read', 'project.effective_policy.read', 'project.guide_compilation.request', 'project.guide_compilation.execute'])) OR action_id IS NOT NULL AND (action_id::text = 'actor.profile.read_self'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'actor.profile.update_self'::text AND permission_id::text = 'actor.profile.update_self'::text OR action_id::text = 'operations.task.start_override'::text AND permission_id::text = 'operations.task.start_override'::text OR action_id::text = 'operations.submission_gate.repair'::text AND permission_id::text = 'operations.submission_gate.repair'::text OR action_id::text = 'operations.checker.retry'::text AND permission_id::text = 'operations.checker.retry'::text OR action_id::text = 'submission.create'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.queue.read'::text AND permission_id::text = 'review.queue.read'::text OR action_id::text = 'review.queue.inspect'::text AND permission_id::text = 'review.queue.inspect'::text OR action_id::text = 'review.claim'::text AND permission_id::text = 'review.claim'::text OR action_id::text = 'review.release'::text AND permission_id::text = 'review.release'::text OR action_id::text = 'review.decline_preference'::text AND permission_id::text = 'review.decline_preference'::text OR action_id::text = 'review.preference_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.lease_expiry.run'::text AND permission_id::text = 'operations.timer.run'::text OR action_id::text = 'review.context.read'::text AND permission_id::text = 'submission.read_for_review'::text OR action_id::text = 'review.chain.read'::text AND permission_id::text = 'review.chain.read'::text OR action_id::text = 'review.finding_evidence.ingest'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.decision'::text AND permission_id::text = 'review.decision'::text OR action_id::text = 'review.finding_response_evidence.ingest'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'review.lease.force_release'::text AND permission_id::text = 'review.lease.force_release'::text OR action_id::text = 'review.queue.routing.override'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.routing.correct'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.queue.close'::text AND permission_id::text = 'review.queue.override'::text OR action_id::text = 'review.reconcile.run'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.artifact_reference.reconcile'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.projection.rebuild'::text AND permission_id::text = 'operations.projection.rebuild'::text OR action_id::text = 'review.revision_context.repair'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_obligation.close'::text AND permission_id::text = 'project.task.manage'::text OR action_id::text = 'review.revision_context.legacy_close'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'review.lifecycle.activation.manage'::text AND permission_id::text = 'operations.reconcile.run'::text OR action_id::text = 'artifact.binding.read'::text AND permission_id::text = 'artifact.binding.read'::text OR action_id::text = 'artifact.replica.read'::text AND permission_id::text = 'artifact.replica.read'::text OR action_id::text = 'artifact.receipt.read'::text AND permission_id::text = 'artifact.receipt.read'::text OR action_id::text = 'artifact.verification_job.read'::text AND permission_id::text = 'artifact.verification_job.read'::text OR action_id::text = 'artifact.verification_job.retry'::text AND permission_id::text = 'artifact.verification_job.retry'::text OR action_id::text = 'artifact.recovery_attempt.read'::text AND permission_id::text = 'artifact.recovery_attempt.read'::text OR action_id::text = 'artifact.audit.read'::text AND permission_id::text = 'artifact.audit.read'::text OR action_id::text = 'operations.artifact_storage_admission.read'::text AND permission_id::text = 'operations.status.read'::text OR action_id::text = 'artifact.guide_source.ingest'::text AND permission_id::text = 'artifact.guide_source.ingest'::text OR action_id::text = 'artifact.submission_bundle.prepare'::text AND permission_id::text = 'submission.create'::text OR action_id::text = 'artifact.review_packet.materialize'::text AND permission_id::text = 'artifact.review_packet.materialize'::text OR action_id::text = 'artifact.review_evidence.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.guide_source.read'::text AND permission_id::text = 'artifact.guide_source.read'::text OR action_id::text = 'artifact.guide_source.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.submission.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.checker_output.binding.create'::text AND permission_id::text = 'artifact.binding.create'::text OR action_id::text = 'artifact.verification.execute'::text AND permission_id::text = 'artifact.verification.execute'::text OR action_id::text = 'artifact.pending_work.scan'::text AND permission_id::text = 'artifact.pending_work.scan'::text OR action_id::text = 'artifact.put_attempt.resolve'::text AND permission_id::text = 'artifact.put_attempt.resolve'::text OR action_id::text = 'artifact.pre_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.post_submit.checker_input.materialize'::text AND permission_id::text = 'artifact.checker_input.materialize'::text OR action_id::text = 'artifact.checker_output.write'::text AND permission_id::text = 'artifact.checker_output.write'::text OR action_id::text = 'authorization.permission_catalogue.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'authorization.admin_role_definitions.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.list'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'actor.admin_role_grant_history.read'::text AND permission_id::text = 'admin_role.read'::text OR action_id::text = 'admin_role_grant.issue'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'admin_role_grant.revoke'::text AND permission_id::text = 'admin_role.revoke'::text OR action_id::text = 'admin_role_grant.bootstrap'::text AND permission_id::text = 'admin_role.grant'::text OR action_id::text = 'actor.profile.read'::text AND permission_id::text = 'actor.profile.read_any'::text OR action_id::text = 'actor.profile.suspend'::text AND permission_id::text = 'actor.profile.suspend'::text OR action_id::text = 'actor.profile.reactivate'::text AND permission_id::text = 'actor.profile.reactivate'::text OR action_id::text = 'actor.profile.deactivate'::text AND permission_id::text = 'actor.profile.deactivate'::text OR action_id::text = 'actor.identity_link.read'::text AND permission_id::text = 'actor.identity_link.read'::text OR action_id::text = 'actor.identity_link.revoke'::text AND permission_id::text = 'actor.identity_link.revoke'::text OR action_id::text = 'actor.identity_link.reactivate'::text AND permission_id::text = 'actor.identity_link.reactivate'::text OR action_id::text = 'actor.service.provision'::text AND permission_id::text = 'actor.service.provision'::text OR action_id::text = 'project.contributor_candidate.list'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.list'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.read'::text AND permission_id::text = 'project.role_grant.read'::text OR action_id::text = 'project_role_grant.issue'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project_role_grant.revoke'::text AND permission_id::text = 'project.role_grant.manage'::text OR action_id::text = 'project.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'actor.authorization_context.read'::text AND permission_id::text = 'actor.profile.read_self'::text OR action_id::text = 'project.setup_run.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.list'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.guide_sufficiency_report.read'::text AND permission_id::text = 'project.setup_diagnostic.read'::text OR action_id::text = 'project.submission_artifact_policy.list'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.post_submit_checker_policy_setup.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.effective_submission_artifact_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.pre_submit_checker_policy.read'::text AND permission_id::text = 'project.effective_policy.read'::text OR action_id::text = 'project.active_guide.read'::text AND permission_id::text = 'project.read'::text OR action_id::text = 'project.create'::text AND permission_id::text = 'project.create'::text OR action_id::text = 'project.guide.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_source_snapshot.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.review_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.revision_policy.update'::text AND permission_id::text = 'project.review_policy.manage'::text OR action_id::text = 'project.guide_sufficiency_report.create'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_sufficiency.run'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide_compilation.execute'::text AND permission_id::text = 'project.guide_compilation.execute'::text OR action_id::text = 'project.guide_compilation.request'::text AND permission_id::text = 'project.guide_compilation.request'::text OR action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.submission_artifact_policy.create'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.update'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.submission_artifact_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.approve'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.correction.request'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.post_submit_checker_policy.derive'::text AND permission_id::text = 'project.effective_policy.manage'::text OR action_id::text = 'project.setup_run.update'::text AND permission_id::text = 'project.guide.manage'::text OR action_id::text = 'project.guide.activate'::text AND permission_id::text = 'project.guide.manage'::text)))","kind":"c","name":"ck_audit_events_authorization_action_evidence","table_name":"audit_events"},{"definition":"CHECK (event_domain::text = 'legacy_lifecycle'::text AND event_version IS NULL AND occurred_at IS NULL AND actor_ref_kind IS NULL AND request_id IS NULL AND correlation_id IS NULL AND target_actor_ref_kind IS NULL AND target_actor_ref IS NULL AND matched_grant_id IS NULL AND permission_id IS NULL AND project_id IS NULL AND resource_type IS NULL AND resource_id IS NULL AND target_ref_kind IS NULL AND target_ref_id IS NULL AND denial_code IS NULL AND idempotency_reference IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND invalidation_target_ref IS NULL AND before_facts IS NULL AND after_facts IS NULL AND external_subject IS NOT NULL AND external_issuer IS NOT NULL OR event_domain::text = 'authority'::text AND event_version = 1 AND occurred_at IS NOT NULL AND (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal'])) AND request_id IS NOT NULL AND correlation_id IS NOT NULL AND from_status IS NULL AND to_status IS NULL AND reason IS NOT NULL AND external_subject IS NULL AND external_issuer IS NULL AND actor_roles::jsonb = '[]'::jsonb AND claim_snapshot::jsonb = '{}'::jsonb AND auth_source::text = 'local_authority'::text AND is_dev_auth = false AND event_payload::jsonb = '{}'::jsonb)","kind":"c","name":"ck_audit_events_domain_shape","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR (before_facts IS NULL OR octet_length(before_facts::text) <= 4096) AND (after_facts IS NULL OR octet_length(after_facts::text) <= 4096) AND COALESCE(authority_event_facts_are_safe(event_type::text, before_facts, after_facts, project_id::text), false))","kind":"c","name":"ck_audit_events_fact_bounds","table_name":"audit_events"},{"definition":"CHECK (event_domain::text <> 'authority'::text OR (event_type::text <> ALL (ARRAY['SensitiveAuthorizationAllowed', 'SensitiveAuthorizationDenied', 'AuthorityInvalidationRequested', 'AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) OR (event_type::text = ANY (ARRAY['AdminRoleGrantIssueDenied', 'LastAccessAdministratorOperationDenied'])) AND denial_code IS NOT NULL OR event_type::text = 'SensitiveAuthorizationAllowed'::text AND permission_id IS NOT NULL AND denial_code IS NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL OR event_type::text = 'SensitiveAuthorizationDenied'::text AND permission_id IS NOT NULL AND denial_code IS NOT NULL AND invalidation_cause_event_id IS NULL AND invalidation_target_kind IS NULL AND idempotency_reference IS NULL OR event_type::text = 'AuthorityInvalidationRequested'::text AND invalidation_cause_event_id IS NOT NULL AND invalidation_target_kind IS NOT NULL AND denial_code IS NULL)","kind":"c","name":"ck_audit_events_foundation_shapes","table_name":"audit_events"},{"definition":"CHECK ((target_actor_ref_kind IS NULL) = (target_actor_ref IS NULL) AND (resource_type IS NOT NULL OR resource_id IS NULL) AND (target_ref_kind IS NULL) = (target_ref_id IS NULL) AND (invalidation_target_kind IS NULL) = (invalidation_target_ref IS NULL) AND (invalidation_cause_event_id IS NULL OR invalidation_cause_event_id::text <> id::text))","kind":"c","name":"ck_audit_events_reference_pairs","table_name":"audit_events"},{"definition":"FOREIGN KEY (idempotency_reference, actor_ref_kind, actor_id) REFERENCES authority_idempotency_records(id, actor_ref_kind, actor_ref) NOT VALID","kind":"f","name":"fk_audit_events_authority_idempotency","table_name":"audit_events"},{"definition":"FOREIGN KEY (invalidation_cause_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_audit_events_invalidation_cause","table_name":"audit_events"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_audit_events","table_name":"audit_events"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"authority_control_bootstrap_invariant","table_name":"authority_control"},{"definition":"CHECK (bootstrap_completed = false AND bootstrap_grant_id IS NULL AND version = 0 OR bootstrap_completed = true AND bootstrap_grant_id IS NOT NULL AND version = 1)","kind":"c","name":"ck_authority_control_bootstrap_state","table_name":"authority_control"},{"definition":"CHECK (id = 1)","kind":"c","name":"ck_authority_control_singleton","table_name":"authority_control"},{"definition":"FOREIGN KEY (bootstrap_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_authority_control_bootstrap_grant_id_admin_role_grants","table_name":"authority_control"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_authority_control","table_name":"authority_control"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"authority_idempotency_pending_guard","table_name":"authority_idempotency_records"},{"definition":"CHECK (actor_ref_kind::text = ANY (ARRAY['legacy_actor', 'actor_profile', 'system_principal']))","kind":"c","name":"ck_authority_idempotency_records_actor_kind","table_name":"authority_idempotency_records"},{"definition":"CHECK (actor_ref_kind::text = 'system_principal'::text AND actor_ref::text = 'workstream:system:bootstrap'::text OR actor_ref_kind::text <> 'system_principal'::text AND actor_ref::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_authority_idempotency_records_actor_reference","table_name":"authority_idempotency_records"},{"definition":"CHECK (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'admin_role_grant.revoke', 'project_role_grant.issue', 'project_role_grant.revoke', 'actor_profile.suspend', 'actor_profile.reactivate', 'actor_profile.deactivate', 'actor_identity_link.revoke', 'actor_identity_link.reactivate']))","kind":"c","name":"ck_authority_idempotency_records_operation","table_name":"authority_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_authority_idempotency_records_request_digest","table_name":"authority_idempotency_records"},{"definition":"CHECK (response_http_status IS NULL OR (operation::text = ANY (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 201 OR (operation::text <> ALL (ARRAY['service_actor.create', 'admin_role_grant.issue', 'project_role_grant.issue'])) AND response_http_status = 200)","kind":"c","name":"ck_authority_idempotency_records_response_status","table_name":"authority_idempotency_records"},{"definition":"CHECK (operation::text = 'service_actor.create'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'admin_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'admin_role_grant'::text) OR operation::text ~~ 'project_role_grant.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'project_role_grant'::text) OR operation::text ~~ 'actor_profile.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_profile'::text) OR operation::text ~~ 'actor_identity_link.%'::text AND (response_resource_type IS NULL OR response_resource_type::text = 'actor_identity_link'::text))","kind":"c","name":"ck_authority_idempotency_records_response_type","table_name":"authority_idempotency_records"},{"definition":"CHECK (response_resource_version IS NULL OR response_resource_version > 0)","kind":"c","name":"ck_authority_idempotency_records_response_version","table_name":"authority_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND response_resource_type IS NULL AND response_resource_id IS NULL AND response_resource_version IS NULL AND response_http_status IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_resource_type IS NOT NULL AND response_resource_id IS NOT NULL AND response_http_status IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_authority_idempotency_records_state_shape","table_name":"authority_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_authority_idempotency_records_status","table_name":"authority_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_authority_idempotency_records","table_name":"authority_idempotency_records"},{"definition":"UNIQUE (id, actor_ref_kind, actor_ref)","kind":"u","name":"uq_authority_idempotency_records_actor_reference","table_name":"authority_idempotency_records"},{"definition":"UNIQUE (actor_ref_kind, actor_ref, operation, idempotency_key)","kind":"u","name":"uq_authority_idempotency_records_replay_namespace","table_name":"authority_idempotency_records"},{"definition":"CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)","kind":"c","name":"ck_checker_policies_approval_provenance","table_name":"checker_policies"},{"definition":"CHECK (lifecycle_status::text <> 'superseded'::text OR superseded_at IS NOT NULL AND (superseded_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND superseded_by_actor IS NOT NULL AND (supersession_kind::text = ANY (ARRAY['correction_requested', 'upstream_policy_changed'])) AND supersession_reason IS NOT NULL AND length(btrim(supersession_reason)) > 0)","kind":"c","name":"ck_checker_policies_correction_provenance","table_name":"checker_policies"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['compiled', 'approved', 'superseded']))","kind":"c","name":"ck_checker_policies_lifecycle_status","table_name":"checker_policies"},{"definition":"CHECK (policy_hash IS NULL OR policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_checker_policies_policy_hash_shape","table_name":"checker_policies"},{"definition":"FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_checker_policies_effective_policy_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_checker_policies_guide_id_project_guides","table_name":"checker_policies"},{"definition":"FOREIGN KEY (pre_submit_checker_policy_id, pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)","kind":"f","name":"fk_checker_policies_pre_submit_checker_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_checker_policies_project_guide","table_name":"checker_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_checker_policies_project_id_projects","table_name":"checker_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_checker_policies_source_snapshot_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES checker_policies(id)","kind":"f","name":"fk_checker_policies_supersedes_policy_id","table_name":"checker_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_checker_policies","table_name":"checker_policies"},{"definition":"UNIQUE (id, guide_version, policy_hash)","kind":"u","name":"uq_checker_policies_id_version_hash","table_name":"checker_policies"},{"definition":"FOREIGN KEY (checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_checker_results_checker_run_id_checker_runs","table_name":"checker_results"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_checker_results_submission_id_submissions","table_name":"checker_results"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_checker_results_task_id_workstream_tasks","table_name":"checker_results"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_checker_results","table_name":"checker_results"},{"definition":"CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)","kind":"c","name":"ck_checker_runs_post_submit_policy_lock_complete","table_name":"checker_runs"},{"definition":"FOREIGN KEY (audit_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_checker_runs_audit_event_id_audit_events","table_name":"checker_runs"},{"definition":"FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)","kind":"f","name":"fk_checker_runs_locked_post_submit_policy_hash","table_name":"checker_runs"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_checker_runs_submission_id_submissions","table_name":"checker_runs"},{"definition":"FOREIGN KEY (submission_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES submissions(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"f","name":"fk_checker_runs_submission_locked_post_submit_policy_hash","table_name":"checker_runs"},{"definition":"FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_checker_runs_submission_version","table_name":"checker_runs"},{"definition":"FOREIGN KEY (supersedes_checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_checker_runs_supersedes_checker_run_id_checker_runs","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_checker_runs_task_id_workstream_tasks","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)","kind":"f","name":"fk_checker_runs_task_locked_guide","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)","kind":"f","name":"fk_checker_runs_task_locked_payment_policy","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","kind":"f","name":"fk_checker_runs_task_locked_review_policy","table_name":"checker_runs"},{"definition":"FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","kind":"f","name":"fk_checker_runs_task_locked_revision_policy","table_name":"checker_runs"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_checker_runs","table_name":"checker_runs"},{"definition":"UNIQUE (submission_id, attempt_number)","kind":"u","name":"uq_checker_runs_submission_attempt","table_name":"checker_runs"},{"definition":"CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))","kind":"c","name":"ck_contribution_award_definitions_contribution_type","table_name":"contribution_award_definitions"},{"definition":"CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))","kind":"c","name":"ck_contribution_award_definitions_instrument_type","table_name":"contribution_award_definitions"},{"definition":"CHECK (instrument_type::text <> 'project_points'::text OR scale(quantity) = 0)","kind":"c","name":"ck_contribution_award_definitions_project_points_whole","table_name":"contribution_award_definitions"},{"definition":"CHECK (quantity > 0::numeric AND quantity < '100000000000000000000'::numeric AND scale(quantity) >= 0 AND scale(quantity) <= 18)","kind":"c","name":"ck_contribution_award_definitions_quantity_exact_bounds","table_name":"contribution_award_definitions"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_award_definitions_graph_guard","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (adapter_binding_id, project_id, instrument_type) REFERENCES project_compensation_adapter_bindings(id, project_id, instrument_type)","kind":"f","name":"fk_contribution_award_definition_binding","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_award_definition_project","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (contribution_rule_id, contribution_policy_version_id, project_id, contribution_type) REFERENCES contribution_rules(id, contribution_policy_version_id, project_id, contribution_type)","kind":"f","name":"fk_contribution_award_definition_rule","table_name":"contribution_award_definitions"},{"definition":"FOREIGN KEY (project_id, instrument_type, unit_code) REFERENCES project_compensation_units(project_id, instrument_type, unit_code)","kind":"f","name":"fk_contribution_award_definition_unit","table_name":"contribution_award_definitions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_award_definitions","table_name":"contribution_award_definitions"},{"definition":"UNIQUE (contribution_rule_id, instrument_type)","kind":"u","name":"uq_contribution_award_definition_instrument","table_name":"contribution_award_definitions"},{"definition":"CHECK (status::text = 'draft'::text AND current_published_version_id IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'active'::text AND current_published_version_id IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND current_published_version_id IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)","kind":"c","name":"ck_contribution_policies_lifecycle_shape","table_name":"contribution_policies"},{"definition":"CHECK (char_length(btrim(name::text)) >= 1 AND char_length(btrim(name::text)) <= 200)","kind":"c","name":"ck_contribution_policies_name","table_name":"contribution_policies"},{"definition":"CHECK (retired_at IS NULL OR retired_at >= created_at)","kind":"c","name":"ck_contribution_policies_retirement_timestamp","table_name":"contribution_policies"},{"definition":"CHECK (status::text = ANY (ARRAY['draft', 'active', 'retired']))","kind":"c","name":"ck_contribution_policies_status","table_name":"contribution_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_policies_graph_guard","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_created_by","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (current_published_version_id, id, project_id) REFERENCES contribution_policy_versions(id, contribution_policy_id, project_id) DEFERRABLE INITIALLY DEFERRED","kind":"f","name":"fk_contribution_policy_current_version","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_policy_project","table_name":"contribution_policies"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_retired_by","table_name":"contribution_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_policies","table_name":"contribution_policies"},{"definition":"UNIQUE (id, project_id)","kind":"u","name":"uq_contribution_policy_ownership","table_name":"contribution_policies"},{"definition":"CHECK (status::text = 'draft'::text AND published_by IS NULL AND published_at IS NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'published'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND published_by IS NOT NULL AND published_at IS NOT NULL AND retired_by IS NOT NULL AND retired_at IS NOT NULL)","kind":"c","name":"ck_contribution_policy_versions_lifecycle_shape","table_name":"contribution_policy_versions"},{"definition":"CHECK ((published_at IS NULL OR published_at >= created_at) AND (retired_at IS NULL OR retired_at >= published_at))","kind":"c","name":"ck_contribution_policy_versions_lifecycle_timestamps","table_name":"contribution_policy_versions"},{"definition":"CHECK (status::text = ANY (ARRAY['draft', 'published', 'retired']))","kind":"c","name":"ck_contribution_policy_versions_status","table_name":"contribution_policy_versions"},{"definition":"CHECK (version_number > 0)","kind":"c","name":"ck_contribution_policy_versions_version_number_positive","table_name":"contribution_policy_versions"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_policy_versions_graph_guard","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_version_created_by","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (contribution_policy_id, project_id) REFERENCES contribution_policies(id, project_id)","kind":"f","name":"fk_contribution_policy_version_policy","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_policy_version_project","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (published_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_version_published_by","table_name":"contribution_policy_versions"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_contribution_policy_version_retired_by","table_name":"contribution_policy_versions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_policy_versions","table_name":"contribution_policy_versions"},{"definition":"UNIQUE (contribution_policy_id, version_number)","kind":"u","name":"uq_contribution_policy_version_number","table_name":"contribution_policy_versions"},{"definition":"UNIQUE (id, contribution_policy_id, project_id)","kind":"u","name":"uq_contribution_policy_version_ownership","table_name":"contribution_policy_versions"},{"definition":"UNIQUE (id, project_id)","kind":"u","name":"uq_contribution_policy_version_project","table_name":"contribution_policy_versions"},{"definition":"CHECK (compensation_mode::text = ANY (ARRAY['unpaid', 'compensated']))","kind":"c","name":"ck_contribution_rules_compensation_mode","table_name":"contribution_rules"},{"definition":"CHECK (contribution_type::text = ANY (ARRAY['accepted_submission', 'completed_review']))","kind":"c","name":"ck_contribution_rules_contribution_type","table_name":"contribution_rules"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"contribution_rules_graph_guard","table_name":"contribution_rules"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_contribution_rule_project","table_name":"contribution_rules"},{"definition":"FOREIGN KEY (contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)","kind":"f","name":"fk_contribution_rule_version","table_name":"contribution_rules"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_contribution_rules","table_name":"contribution_rules"},{"definition":"UNIQUE (id, contribution_policy_version_id, project_id, contribution_type)","kind":"u","name":"uq_contribution_rule_ownership","table_name":"contribution_rules"},{"definition":"UNIQUE (contribution_policy_version_id, contribution_type)","kind":"u","name":"uq_contribution_rule_type","table_name":"contribution_rules"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['approved', 'superseded']))","kind":"c","name":"ck_effective_project_submission_artifact_policies_ck_ef_7be7","table_name":"effective_project_submission_artifact_policies"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)","kind":"c","name":"ck_effective_project_submission_artifact_policies_ck_ef_bd4e","table_name":"effective_project_submission_artifact_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"effective_submission_policy_custody","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_effective_policy_creation_actor","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_effective_policy_creation_decision","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_effective_policy_creation_grant","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_effective_policy_creation_link","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_effective_policy_creation_project","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_effective_project_submission_artifact_policies_project_guide","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_effective_psap_guide","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_effective_psap_project","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_effective_psap_source_snapshot_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (submission_artifact_policy_id, submission_artifact_policy_hash) REFERENCES submission_artifact_policies(id, policy_hash)","kind":"f","name":"fk_effective_psap_submission_policy_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (supersedes_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)","kind":"f","name":"fk_effective_psap_supersedes","table_name":"effective_project_submission_artifact_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_effective_project_submission_artifact_policies","table_name":"effective_project_submission_artifact_policies"},{"definition":"UNIQUE (id, effective_policy_hash)","kind":"u","name":"uq_effective_project_submission_artifact_policies_id_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_evidence_items_submission_id_submissions","table_name":"evidence_items"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_evidence_items","table_name":"evidence_items"},{"definition":"CHECK (operation_generation > 0)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_6506","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL AND setup_run_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_9402","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create']))","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_action","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_b397","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_e32d","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_guide_mutation_idempotency_records_ck_guide_mutation_status","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_actor_profile_id__2ee3","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_identity_link_id__3ddf","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_project_id_projects","table_name":"guide_mutation_idempotency_records"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_guide_mutation_idempotency_records_setup_run_id_proj_7dc3","table_name":"guide_mutation_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"guide_mutation_reservation_custody","table_name":"guide_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_mutation_idempotency_records","table_name":"guide_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_guide_mutation_operation_identity","table_name":"guide_mutation_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, action_id, idempotency_key)","kind":"u","name":"uq_guide_mutation_replay_namespace","table_name":"guide_mutation_idempotency_records"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_guide_source_artifact_bindings_ck_guide_bindings_gen_b5fe","table_name":"guide_source_artifact_bindings"},{"definition":"CHECK (logical_role::text = 'guide_source_original'::text)","kind":"c","name":"ck_guide_source_artifact_bindings_ck_guide_bindings_role","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (source_item_id, source_snapshot_id) REFERENCES guide_source_snapshot_items(id, source_snapshot_id)","kind":"f","name":"fk_guide_bindings_exact_item","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (project_setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)","kind":"f","name":"fk_guide_bindings_exact_setup_generation","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (source_snapshot_id, project_id, guide_id) REFERENCES guide_source_snapshots(id, project_id, guide_id)","kind":"f","name":"fk_guide_bindings_exact_snapshot","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (verified_replica_id, content_id) REFERENCES artifact_replicas(id, content_id)","kind":"f","name":"fk_guide_bindings_verified_replica_content","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_guide_source_artifact_bindings_content_id_artifact_contents","table_name":"guide_source_artifact_bindings"},{"definition":"FOREIGN KEY (supersedes_binding_id) REFERENCES guide_source_artifact_bindings(id) ON DELETE RESTRICT","kind":"f","name":"fk_guide_source_artifact_bindings_supersedes_binding_id_bfa2","table_name":"guide_source_artifact_bindings"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_artifact_bindings","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (id, content_id, verified_replica_id, setup_generation)","kind":"u","name":"uq_guide_bindings_exact_read","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (id, content_id, setup_generation)","kind":"u","name":"uq_guide_bindings_extraction_attempt_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (id, content_id, source_item_id, project_setup_run_id, setup_generation)","kind":"u","name":"uq_guide_bindings_extraction_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (source_item_id, setup_generation)","kind":"u","name":"uq_guide_bindings_item_generation","table_name":"guide_source_artifact_bindings"},{"definition":"UNIQUE (supersedes_binding_id)","kind":"u","name":"uq_guide_bindings_supersedes","table_name":"guide_source_artifact_bindings"},{"definition":"CHECK (code::text = ANY (ARRAY['missing', 'changed', 'truncated', 'unavailable', 'stale', 'conflict']))","kind":"c","name":"ck_guide_source_artifact_incidents_ck_guide_incidents_code","table_name":"guide_source_artifact_incidents"},{"definition":"CHECK (observed_sha256 IS NULL OR observed_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_artifact_incidents_ck_guide_source_arti_621b","table_name":"guide_source_artifact_incidents"},{"definition":"CHECK (observed_byte_count IS NULL OR observed_byte_count >= 0)","kind":"c","name":"ck_guide_source_artifact_incidents_ck_guide_source_arti_92fa","table_name":"guide_source_artifact_incidents"},{"definition":"FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)","kind":"f","name":"fk_guide_incidents_exact_binding","table_name":"guide_source_artifact_incidents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_artifact_incidents","table_name":"guide_source_artifact_incidents"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_guide_source_artifact_ingests_ck_guide_source_artifa_2958","table_name":"guide_source_artifact_ingests"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_artifact_ingests_ck_guide_source_artifa_64cb","table_name":"guide_source_artifact_ingests"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_source_artifact_ingests_actor_profile_id_actor_22c1","table_name":"guide_source_artifact_ingests"},{"definition":"FOREIGN KEY (source_item_id) REFERENCES guide_source_snapshot_items(id)","kind":"f","name":"fk_guide_source_artifact_ingests_source_item_id_guide_s_7ba9","table_name":"guide_source_artifact_ingests"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_artifact_ingests","table_name":"guide_source_artifact_ingests"},{"definition":"UNIQUE (source_item_id)","kind":"u","name":"uq_guide_source_artifact_ingests_source_item_id","table_name":"guide_source_artifact_ingests"},{"definition":"CHECK (output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_1b91","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (octet_length(canonical_output) <= 4194304)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_54b5","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (source_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_988f","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (status::text = 'extracted'::text)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_a759","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (source_byte_count >= 0)","kind":"c","name":"ck_guide_source_extracted_contents_ck_guide_extracted_c_fb79","table_name":"guide_source_extracted_contents"},{"definition":"FOREIGN KEY (content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_guide_source_extracted_contents_content_id_artifact_contents","table_name":"guide_source_extracted_contents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_extracted_contents","table_name":"guide_source_extracted_contents"},{"definition":"UNIQUE (id, content_id)","kind":"u","name":"uq_guide_extracted_contents_exact_usage","table_name":"guide_source_extracted_contents"},{"definition":"UNIQUE (content_id, detected_format, extractor_name, extractor_version, policy_version)","kind":"u","name":"uq_guide_extracted_contents_identity","table_name":"guide_source_extracted_contents"},{"definition":"CHECK (attempt_number > 0)","kind":"c","name":"ck_guide_source_extraction_attempts_ck_guide_extraction_3927","table_name":"guide_source_extraction_attempts"},{"definition":"CHECK ((status::text = 'extracted'::text) = (error_code IS NULL))","kind":"c","name":"ck_guide_source_extraction_attempts_ck_guide_extraction_940d","table_name":"guide_source_extraction_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['extracted', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded', 'parser_failure', 'cancelled', 'artifact_incident']))","kind":"c","name":"ck_guide_source_extraction_attempts_ck_guide_extraction_ff6d","table_name":"guide_source_extraction_attempts"},{"definition":"FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_attempts_exact_binding","table_name":"guide_source_extraction_attempts"},{"definition":"FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_attempts_exact_classification","table_name":"guide_source_extraction_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"UNIQUE (binding_id, policy_version, attempt_number)","kind":"u","name":"uq_guide_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"UNIQUE (id, binding_id, content_id, setup_generation, status)","kind":"u","name":"uq_guide_extraction_attempts_exact_usage","table_name":"guide_source_extraction_attempts"},{"definition":"CHECK (claimed_slots >= 1 AND claimed_slots <= 2)","kind":"c","name":"ck_guide_source_extraction_retry_budgets_ck_guide_extra_99c3","table_name":"guide_source_extraction_retry_budgets"},{"definition":"FOREIGN KEY (binding_id, content_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_retry_budgets_exact_binding","table_name":"guide_source_extraction_retry_budgets"},{"definition":"FOREIGN KEY (classification_id, binding_id, content_id, setup_generation) REFERENCES guide_source_format_classifications(id, binding_id, content_id, setup_generation)","kind":"f","name":"fk_guide_extraction_retry_budgets_exact_classification","table_name":"guide_source_extraction_retry_budgets"},{"definition":"PRIMARY KEY (binding_id)","kind":"p","name":"pk_guide_source_extraction_retry_budgets","table_name":"guide_source_extraction_retry_budgets"},{"definition":"CHECK (attempt_status::text = 'extracted'::text)","kind":"c","name":"ck_guide_source_extraction_usages_ck_guide_extraction_u_a2fd","table_name":"guide_source_extraction_usages"},{"definition":"FOREIGN KEY (extraction_attempt_id, binding_id, content_id, setup_generation, attempt_status) REFERENCES guide_source_extraction_attempts(id, binding_id, content_id, setup_generation, status)","kind":"f","name":"fk_guide_extraction_usages_exact_attempt","table_name":"guide_source_extraction_usages"},{"definition":"FOREIGN KEY (binding_id, content_id, source_item_id, project_setup_run_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, source_item_id, project_setup_run_id, setup_generation)","kind":"f","name":"fk_guide_extraction_usages_exact_binding","table_name":"guide_source_extraction_usages"},{"definition":"FOREIGN KEY (extracted_content_id, content_id) REFERENCES guide_source_extracted_contents(id, content_id)","kind":"f","name":"fk_guide_extraction_usages_exact_content","table_name":"guide_source_extraction_usages"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"UNIQUE (binding_id, extracted_content_id)","kind":"u","name":"uq_guide_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"UNIQUE (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)","kind":"u","name":"uq_guide_extraction_usages_exact_provenance","table_name":"guide_source_extraction_usages"},{"definition":"CHECK (status::text = ANY (ARRAY['classified', 'unsupported', 'ambiguous', 'malformed', 'limit_exceeded']))","kind":"c","name":"ck_guide_source_format_classifications_ck_guide_classif_8737","table_name":"guide_source_format_classifications"},{"definition":"CHECK (sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_source_format_classifications_ck_guide_source__0dd2","table_name":"guide_source_format_classifications"},{"definition":"CHECK (byte_count >= 0)","kind":"c","name":"ck_guide_source_format_classifications_ck_guide_source__7235","table_name":"guide_source_format_classifications"},{"definition":"FOREIGN KEY (binding_id, content_id, verified_replica_id, setup_generation) REFERENCES guide_source_artifact_bindings(id, content_id, verified_replica_id, setup_generation)","kind":"f","name":"fk_guide_classifications_exact_binding","table_name":"guide_source_format_classifications"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_format_classifications","table_name":"guide_source_format_classifications"},{"definition":"UNIQUE (binding_id)","kind":"u","name":"uq_guide_classifications_binding","table_name":"guide_source_format_classifications"},{"definition":"UNIQUE (id, binding_id, content_id, setup_generation)","kind":"u","name":"uq_guide_classifications_extraction_lineage","table_name":"guide_source_format_classifications"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_gssi_source_snapshot","table_name":"guide_source_snapshot_items"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"guide_source_snapshot_items_custody","table_name":"guide_source_snapshot_items"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_snapshot_items","table_name":"guide_source_snapshot_items"},{"definition":"UNIQUE (id, source_snapshot_id)","kind":"u","name":"uq_guide_source_snapshot_items_exact_lineage","table_name":"guide_source_snapshot_items"},{"definition":"UNIQUE (source_snapshot_id, item_order)","kind":"u","name":"uq_guide_source_snapshot_items_snapshot_order","table_name":"guide_source_snapshot_items"},{"definition":"CHECK (creation_generation IS NULL AND created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR creation_generation > 0 AND created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (creation_scope_type::text = 'system'::text AND creation_scope_project_id IS NULL OR creation_scope_type::text = 'project'::text AND creation_scope_project_id::text = project_id::text) AND creation_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_guide_source_snapshots_source_snapshot_creation_auth_2f3e","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_source_snapshots_created_actor","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_guide_source_snapshots_created_admin_grant","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_guide_source_snapshots_created_decision","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_guide_source_snapshots_created_identity_link","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_guide_source_snapshots_guide_id_project_guides","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_guide_source_snapshots_project_guide","table_name":"guide_source_snapshots"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_source_snapshots_project_id_projects","table_name":"guide_source_snapshots"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_source_snapshots","table_name":"guide_source_snapshots"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"source_snapshot_product_custody","table_name":"guide_source_snapshots"},{"definition":"UNIQUE (id, project_id, guide_id)","kind":"u","name":"uq_guide_source_snapshots_exact_lineage","table_name":"guide_source_snapshots"},{"definition":"UNIQUE (id, bundle_hash)","kind":"u","name":"uq_guide_source_snapshots_id_hash","table_name":"guide_source_snapshots"},{"definition":"UNIQUE (project_id, guide_version, bundle_hash)","kind":"u","name":"uq_guide_source_snapshots_project_version_hash","table_name":"guide_source_snapshots"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_1033","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_177a","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run', 'project.guide_sufficiency.warnings.acknowledge']))","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_6651","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_87dd","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND (action_id::text = 'project.guide_sufficiency.run'::text AND (setup_run_id IS NOT NULL OR report_id IS NOT NULL) OR action_id::text <> 'project.guide_sufficiency.run'::text AND report_id IS NOT NULL))","kind":"c","name":"ck_guide_sufficiency_mutation_idempotency_records_ck_su_e7f6","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_actor_16d8","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_guide_1d2b","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_ident_2378","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_proje_7f82","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_repor_48c3","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_setup_7059","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_guide_sufficiency_mutation_idempotency_records_sourc_9985","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_sufficiency_mutation_idempotency_records","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_sufficiency_mutation_operation_identity","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, idempotency_key)","kind":"u","name":"uq_sufficiency_mutation_replay_namespace","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_guide_sufficiency_report_source_usages_ck_sufficienc_2983","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CHECK (canonical_output_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_sufficiency_report_source_usages_ck_sufficienc_8148","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CHECK (item_order >= 0)","kind":"c","name":"ck_guide_sufficiency_report_source_usages_ck_sufficienc_eb12","table_name":"guide_sufficiency_report_source_usages"},{"definition":"FOREIGN KEY (report_id) REFERENCES guide_sufficiency_reports(id) ON DELETE CASCADE","kind":"f","name":"fk_guide_sufficiency_report_source_usages_report_id_gui_1d57","table_name":"guide_sufficiency_report_source_usages"},{"definition":"FOREIGN KEY (extraction_usage_id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation) REFERENCES guide_source_extraction_usages(id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)","kind":"f","name":"fk_sufficiency_report_source_usage_exact_extraction","table_name":"guide_sufficiency_report_source_usages"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_sufficiency_report_source_usages","table_name":"guide_sufficiency_report_source_usages"},{"definition":"UNIQUE (report_id, extraction_usage_id)","kind":"u","name":"uq_sufficiency_report_extraction_usage","table_name":"guide_sufficiency_report_source_usages"},{"definition":"UNIQUE (report_id, item_order)","kind":"u","name":"uq_sufficiency_report_item_order","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CHECK (warnings_acknowledged_by_actor_profile_id IS NULL AND warnings_acknowledged_via_identity_link_id IS NULL AND warnings_acknowledged_by_admin_role_grant_id IS NULL AND warning_acknowledgement_scope_type IS NULL AND warning_acknowledgement_scope_project_id IS NULL AND warning_acknowledgement_action_id IS NULL AND warning_acknowledgement_decision_event_id IS NULL OR warnings_acknowledged_by_actor_profile_id IS NOT NULL AND warnings_acknowledged_via_identity_link_id IS NOT NULL AND warnings_acknowledged_by_admin_role_grant_id IS NOT NULL AND (warning_acknowledgement_scope_type::text = ANY (ARRAY['system', 'project'])) AND warning_acknowledgement_scope_project_id IS NOT NULL AND warning_acknowledgement_action_id::text = 'project.guide_sufficiency.warnings.acknowledge'::text AND warning_acknowledgement_decision_event_id IS NOT NULL)","kind":"c","name":"ck_guide_sufficiency_ack_authority_shape","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.guide_sufficiency_report.create', 'project.guide_sufficiency.run'])) AND authorization_decision_event_id IS NOT NULL AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.guide_sufficiency.run'::text AND project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL))","kind":"c","name":"ck_guide_sufficiency_creation_authority_shape","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (agent_material_byte_count IS NULL OR agent_material_byte_count >= 0)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_31bb","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (setup_generation IS NULL OR setup_generation > 0)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_3e43","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (project_setup_run_id IS NULL AND setup_generation IS NULL AND agent_material_sha256 IS NULL AND agent_material_byte_count IS NULL OR project_setup_run_id IS NOT NULL AND setup_generation IS NOT NULL AND agent_material_sha256 IS NOT NULL AND agent_material_byte_count IS NOT NULL)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_4640","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (status::text = ANY (ARRAY['passed', 'blocked', 'passed_with_warnings']))","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_841c","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (agent_material_sha256 IS NULL OR agent_material_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_guide_sufficiency_reports_ck_guide_sufficiency_repor_b3ec","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_guide_sufficiency_reports_guide_id_project_guides","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_guide_sufficiency_reports_project_guide","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_guide_sufficiency_reports_project_id_projects","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_guide_sufficiency_reports_source_snapshot_hash","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warnings_acknowledged_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_suff_ack_actor","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warning_acknowledgement_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_suff_ack_decision","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warnings_acknowledged_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_suff_ack_grant","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warnings_acknowledged_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_suff_ack_link","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (warning_acknowledgement_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_suff_ack_project","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_suff_create_actor","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_suff_create_decision","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_suff_create_grant","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_suff_create_link","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_suff_create_project","table_name":"guide_sufficiency_reports"},{"definition":"FOREIGN KEY (project_setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_sufficiency_reports_setup_run","table_name":"guide_sufficiency_reports"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_guide_sufficiency_reports","table_name":"guide_sufficiency_reports"},{"definition":"CHECK (code::text ~ '^[A-Z]{3}$'::text)","kind":"c","name":"ck_iso_4217_currency_codes_code","table_name":"iso_4217_currency_codes"},{"definition":"PRIMARY KEY (code)","kind":"p","name":"pk_iso_4217_currency_codes","table_name":"iso_4217_currency_codes"},{"definition":"PRIMARY KEY (actor_id)","kind":"p","name":"pk_legacy_actor_identities","table_name":"legacy_actor_identities"},{"definition":"UNIQUE (external_issuer, external_subject)","kind":"u","name":"uq_legacy_actor_identities_external_identity","table_name":"legacy_actor_identities"},{"definition":"CHECK (profile_type::text = ANY (ARRAY['worker', 'reviewer', 'admin', 'project_manager', 'project_owner']))","kind":"c","name":"ck_legacy_workflow_eligibility_profile_type","table_name":"legacy_workflow_eligibility"},{"definition":"CHECK (status::text = ANY (ARRAY['observed', 'active', 'disabled']))","kind":"c","name":"ck_legacy_workflow_eligibility_status","table_name":"legacy_workflow_eligibility"},{"definition":"FOREIGN KEY (actor_id) REFERENCES legacy_actor_identities(actor_id)","kind":"f","name":"fk_legacy_workflow_eligibility_actor_id_legacy_actor_identities","table_name":"legacy_workflow_eligibility"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_legacy_workflow_eligibility","table_name":"legacy_workflow_eligibility"},{"definition":"UNIQUE (actor_id, profile_type, scope_type, scope_id)","kind":"u","name":"uq_legacy_workflow_eligibility_actor_type_scope","table_name":"legacy_workflow_eligibility"},{"definition":"CHECK (aggregate_type::text ~ '^[a-z][a-z0-9_]{0,63}$'::text)","kind":"c","name":"ck_outbox_events_aggregate_type","table_name":"outbox_events"},{"definition":"CHECK (claim_owner IS NULL OR claim_owner::text ~ '^[A-Za-z0-9._:-]{1,120}$'::text)","kind":"c","name":"ck_outbox_events_claim_owner","table_name":"outbox_events"},{"definition":"CHECK (correlation_id::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)","kind":"c","name":"ck_outbox_events_correlation_id","table_name":"outbox_events"},{"definition":"CHECK (attempt_count >= 0 AND claim_generation >= 0 AND attempt_count = claim_generation)","kind":"c","name":"ck_outbox_events_delivery_counters","table_name":"outbox_events"},{"definition":"CHECK (delivery_state::text = ANY (ARRAY['pending', 'claimed', 'retryable', 'acknowledged', 'dead_letter', 'cancelled']))","kind":"c","name":"ck_outbox_events_delivery_state","table_name":"outbox_events"},{"definition":"CHECK (delivery_state::text = 'pending'::text AND attempt_count = 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NULL AND last_error_code IS NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'claimed'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NOT NULL AND claimed_at IS NOT NULL AND claim_expires_at IS NOT NULL AND last_attempt_at = claimed_at AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'retryable'::text AND attempt_count > 0 AND next_attempt_at IS NOT NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NULL AND archived_at IS NULL OR delivery_state::text = 'acknowledged'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'dead_letter'::text AND attempt_count > 0 AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND last_attempt_at IS NOT NULL AND last_error_code IS NOT NULL AND finalized_at IS NOT NULL OR delivery_state::text = 'cancelled'::text AND next_attempt_at IS NULL AND claim_owner IS NULL AND claimed_at IS NULL AND claim_expires_at IS NULL AND finalized_at IS NOT NULL AND (attempt_count = 0 AND last_attempt_at IS NULL AND last_error_code IS NULL OR attempt_count > 0 AND last_attempt_at IS NOT NULL))","kind":"c","name":"ck_outbox_events_delivery_state_shape","table_name":"outbox_events"},{"definition":"CHECK ((next_attempt_at IS NULL OR next_attempt_at >= occurred_at) AND (claimed_at IS NULL OR claimed_at >= occurred_at) AND (last_attempt_at IS NULL OR last_attempt_at >= occurred_at) AND (claim_expires_at IS NULL OR claim_expires_at > claimed_at) AND (finalized_at IS NULL OR finalized_at >= occurred_at) AND (finalized_at IS NULL OR last_attempt_at IS NULL OR finalized_at >= last_attempt_at) AND (archived_at IS NULL OR archived_at >= finalized_at))","kind":"c","name":"ck_outbox_events_delivery_timestamps","table_name":"outbox_events"},{"definition":"CHECK (last_error_code IS NULL OR last_error_code::text ~ '^[A-Z][A-Z0-9_]{0,79}$'::text)","kind":"c","name":"ck_outbox_events_error_code","table_name":"outbox_events"},{"definition":"CHECK (event_type::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,127}$'::text)","kind":"c","name":"ck_outbox_events_event_type","table_name":"outbox_events"},{"definition":"CHECK (event_version >= 1 AND event_version <= 32767)","kind":"c","name":"ck_outbox_events_event_version","table_name":"outbox_events"},{"definition":"CHECK (idempotency_key::text ~ '^[A-Za-z0-9._:-]{1,200}$'::text)","kind":"c","name":"ck_outbox_events_idempotency_key","table_name":"outbox_events"},{"definition":"CHECK (payload_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_outbox_events_payload_digest","table_name":"outbox_events"},{"definition":"CHECK (jsonb_typeof(payload) = 'object'::text AND octet_length(payload::text) <= 262144)","kind":"c","name":"ck_outbox_events_payload_shape","table_name":"outbox_events"},{"definition":"CHECK (producer::text = 'workstream'::text)","kind":"c","name":"ck_outbox_events_producer","table_name":"outbox_events"},{"definition":"CHECK (project_id::text ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'::text)","kind":"c","name":"ck_outbox_events_project_id","table_name":"outbox_events"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_outbox_events_project_id_projects","table_name":"outbox_events"},{"definition":"PRIMARY KEY (event_id)","kind":"p","name":"pk_outbox_events","table_name":"outbox_events"},{"definition":"UNIQUE (idempotency_key)","kind":"u","name":"uq_outbox_events_idempotency_key","table_name":"outbox_events"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_payment_policies_project_guide","table_name":"payment_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_payment_policies_project_id_projects","table_name":"payment_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_payment_policies","table_name":"payment_policies"},{"definition":"UNIQUE (project_id, guide_version)","kind":"u","name":"uq_payment_policies_project_version","table_name":"payment_policies"},{"definition":"CHECK (status::text = 'pending'::text AND response_json IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_26aa","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_595e","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.review_policy.update', 'project.revision_policy.update']))","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_7f7f","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (policy_generation > 0)","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_8b22","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_policy_mutation_idempotency_records_ck_policy_mutati_dc05","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_actor_profile_id_41c2","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_guide_id_project_guides","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_identity_link_id_b806","table_name":"policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_policy_mutation_idempotency_records_project_id_projects","table_name":"policy_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_policy_mutation_idempotency_records","table_name":"policy_mutation_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"policy_mutation_replay_custody","table_name":"policy_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_policy_mutation_operation_identity","table_name":"policy_mutation_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, action_id, idempotency_key)","kind":"u","name":"uq_policy_mutation_replay_namespace","table_name":"policy_mutation_idempotency_records"},{"definition":"CHECK (lifecycle_status::text <> 'compiled'::text OR compiler_version IS NOT NULL AND compiled_bundle IS NOT NULL AND compiled_bundle_hash IS NOT NULL AND compiled_bundle_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_checker_policies_ck_pre_submit_checker_po_5010","table_name":"pre_submit_checker_policies"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['pending_compilation', 'compiled', 'superseded']))","kind":"c","name":"ck_pre_submit_checker_policies_ck_pre_submit_checker_po_a935","table_name":"pre_submit_checker_policies"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_action_id::text = 'project.submission_artifact_policy.approve'::text AND creation_decision_event_id IS NOT NULL)","kind":"c","name":"ck_pre_submit_checker_policies_ck_pre_submit_policy_aut_90fc","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (effective_policy_id, effective_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_pre_submit_checker_policies_effective_hash","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_pre_submit_checker_policies_guide","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_pre_submit_checker_policies_project","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_pre_submit_checker_policies_project_guide","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_pre_submit_checker_policies_source_snapshot_hash","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (supersedes_pre_submit_checker_policy_id) REFERENCES pre_submit_checker_policies(id)","kind":"f","name":"fk_pre_submit_checker_policies_supersedes","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_pre_submit_policy_creation_actor","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_pre_submit_policy_creation_decision","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_pre_submit_policy_creation_grant","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_pre_submit_policy_creation_link","table_name":"pre_submit_checker_policies"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_pre_submit_policy_creation_project","table_name":"pre_submit_checker_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_pre_submit_checker_policies","table_name":"pre_submit_checker_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"pre_submit_policy_custody","table_name":"pre_submit_checker_policies"},{"definition":"UNIQUE (id, compiled_bundle_hash)","kind":"u","name":"uq_pre_submit_checker_policies_id_compiled_bundle_hash","table_name":"pre_submit_checker_policies"},{"definition":"CHECK (classification::text = ANY (ARRAY['mandatory_security', 'mandatory_integrity', 'mandatory_accountability', 'advisory']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_cla_b0de","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (classification::text = 'advisory'::text AND severity::text = 'warning'::text OR classification::text <> 'advisory'::text AND severity::text = 'blocking'::text)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_cla_f04e","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (result_order >= 0)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_order","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (phase::text = ANY (ARRAY['custody', 'identity', 'materialization', 'default_policy', 'project_policy']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_phase","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_plan_sha256","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (locked_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_pol_cef4","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (phase::text = 'project_policy'::text AND rule_instance_id IS NOT NULL AND rule_instance_id::text ~ '^sha256:[0-9a-f]{64}$'::text OR phase::text <> 'project_policy'::text AND rule_instance_id IS NULL)","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_rul_321f","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (severity::text = ANY (ARRAY['blocking', 'warning']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_severity","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (status::text = ANY (ARRAY['passed', 'warning', 'advisory_disabled', 'dependency_not_run', 'failed']))","kind":"c","name":"ck_pre_submit_evidence_results_ck_pre_submit_result_status","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (status::text = 'failed'::text AND failure_code IS NOT NULL OR status::text <> 'failed'::text AND failure_code IS NULL)","kind":"c","name":"ck_pre_submit_evidence_results_result_failure_shape","table_name":"pre_submit_evidence_results"},{"definition":"FOREIGN KEY (evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_results_evidence_set_id_pre_subm_096e","table_name":"pre_submit_evidence_results"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_pre_submit_evidence_results","table_name":"pre_submit_evidence_results"},{"definition":"UNIQUE (evidence_set_id, definition_id)","kind":"u","name":"uq_pre_submit_result_definition","table_name":"pre_submit_evidence_results"},{"definition":"UNIQUE (evidence_set_id, result_order)","kind":"u","name":"uq_pre_submit_result_order","table_name":"pre_submit_evidence_results"},{"definition":"CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arch_8e95","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (archive_byte_count >= 0)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_archive_size","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_artifact_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_arti_16f8","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (catalogue_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_cata_ffcb","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_checker_policy_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_chec_765d","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_guide_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_guide_sha256","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_mani_7268","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (operation_identity::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_oper_f617","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (effective_plan_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_plan_sha256","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (predecessor_submission_id IS NULL AND predecessor_submission_version IS NULL OR predecessor_submission_id IS NOT NULL AND predecessor_submission_version IS NOT NULL)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_pred_bd87","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (result_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_resu_0b46","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (result_count > 0)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_result_count","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (source_snapshot_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_sour_982b","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (terminal_status::text = 'passed'::text AND eligible OR terminal_status::text = 'blocked'::text AND NOT eligible)","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stat_1ae6","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (storage_scheme::text = ANY (ARRAY['local', 's3']))","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_stor_022c","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (terminal_status::text = ANY (ARRAY['passed', 'blocked']))","kind":"c","name":"ck_pre_submit_evidence_sets_ck_pre_submit_evidence_term_a512","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_pre_submit_evidence_sets_policy_context_sha256","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (assignment_id, task_id, actor_profile_id) REFERENCES task_assignments(id, task_id, contributor_id)","kind":"f","name":"fk_pre_submit_evidence_assignment","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (guide_id, project_id, guide_version) REFERENCES project_guides(id, project_id, version)","kind":"f","name":"fk_pre_submit_evidence_guide_lineage","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (identity_link_id, actor_profile_id) REFERENCES actor_identity_links(id, actor_profile_id)","kind":"f","name":"fk_pre_submit_evidence_identity_actor","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (predecessor_submission_id, task_id, predecessor_submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_pre_submit_evidence_predecessor","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_actor_profile_id_actor_profiles","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_assignment_id_task_assignments","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_effective_policy_id_effecti_6a99","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_guide_id_project_guides","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_identity_link_id_actor_iden_5cef","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_pre_submit_policy_id_pre_su_c77f","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_predecessor_submission_id_s_6ec2","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_project_id_projects","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_source_snapshot_id_guide_so_1667","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_pre_submit_evidence_sets_task_id_workstream_tasks","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, effective_policy_id, locked_artifact_policy_sha256) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","kind":"f","name":"fk_pre_submit_evidence_task_artifact_policy","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, pre_submit_policy_id, locked_checker_policy_sha256) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","kind":"f","name":"fk_pre_submit_evidence_task_checker_policy","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, guide_version) REFERENCES workstream_tasks(id, locked_guide_version)","kind":"f","name":"fk_pre_submit_evidence_task_guide","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, project_id) REFERENCES workstream_tasks(id, project_id)","kind":"f","name":"fk_pre_submit_evidence_task_project","table_name":"pre_submit_evidence_sets"},{"definition":"FOREIGN KEY (task_id, source_snapshot_id, source_snapshot_sha256) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","kind":"f","name":"fk_pre_submit_evidence_task_source_snapshot","table_name":"pre_submit_evidence_sets"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_pre_submit_evidence_sets","table_name":"pre_submit_evidence_sets"},{"definition":"UNIQUE (operation_identity)","kind":"u","name":"uq_pre_submit_evidence_operation","table_name":"pre_submit_evidence_sets"},{"definition":"CHECK (binding_lifecycle_version > 0)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_1870","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_3372","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (route_key::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,119}$'::text)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_6958","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (status::text = 'active'::text AND binding_lifecycle_version = 1 AND suspended_by IS NULL AND suspended_at IS NULL AND retired_by IS NULL AND retired_at IS NULL)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_95ba","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK ((suspended_at IS NULL OR suspended_at >= created_at) AND (retired_at IS NULL OR retired_at >= created_at) AND (retired_at IS NULL OR suspended_at IS NULL OR retired_at >= suspended_at))","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_ade1","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'suspended', 'retired']))","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_da73","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (route_key::text !~~ '%..%'::text)","kind":"c","name":"ck_project_compensation_adapter_bindings_ck_project_com_f32d","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (adapter_actor_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_adapter_actor","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_created_by","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_compensation_binding_project","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_retired_by","table_name":"project_compensation_adapter_bindings"},{"definition":"FOREIGN KEY (suspended_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_compensation_binding_suspended_by","table_name":"project_compensation_adapter_bindings"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_compensation_adapter_bindings","table_name":"project_compensation_adapter_bindings"},{"definition":"UNIQUE (id, project_id, instrument_type)","kind":"u","name":"uq_compensation_binding_ownership","table_name":"project_compensation_adapter_bindings"},{"definition":"CHECK (instrument_type::text = ANY (ARRAY['money', 'project_points']))","kind":"c","name":"ck_project_compensation_units_instrument_type","table_name":"project_compensation_units"},{"definition":"CHECK (status::text = 'active'::text AND retired_by IS NULL AND retired_at IS NULL OR status::text = 'retired'::text AND retired_by IS NOT NULL AND retired_at IS NOT NULL)","kind":"c","name":"ck_project_compensation_units_lifecycle_shape","table_name":"project_compensation_units"},{"definition":"CHECK (retired_at IS NULL OR retired_at >= created_at)","kind":"c","name":"ck_project_compensation_units_retirement_time","table_name":"project_compensation_units"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'retired']))","kind":"c","name":"ck_project_compensation_units_status","table_name":"project_compensation_units"},{"definition":"CHECK (instrument_type::text = 'money'::text AND iso_currency_code IS NOT NULL AND unit_code::text = iso_currency_code::text OR instrument_type::text = 'project_points'::text AND iso_currency_code IS NULL AND unit_code::text ~ '^[A-Za-z][A-Za-z0-9._:-]{0,31}$'::text)","kind":"c","name":"ck_project_compensation_units_unit_identity","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (created_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_compensation_unit_created_by","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (iso_currency_code) REFERENCES iso_4217_currency_codes(code)","kind":"f","name":"fk_project_compensation_unit_iso_currency","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_compensation_unit_project","table_name":"project_compensation_units"},{"definition":"FOREIGN KEY (retired_by) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_compensation_unit_retired_by","table_name":"project_compensation_units"},{"definition":"PRIMARY KEY (project_id, instrument_type, unit_code)","kind":"p","name":"pk_project_compensation_units","table_name":"project_compensation_units"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_0a41","table_name":"project_create_idempotency_records"},{"definition":"CHECK (operation_generation = 1)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_100d","table_name":"project_create_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND committed_at IS NULL OR status::text = 'committed'::text AND committed_at IS NOT NULL)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_3aa0","table_name":"project_create_idempotency_records"},{"definition":"CHECK (action_id::text = 'project.create'::text)","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_action","table_name":"project_create_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_project_create_idempotency_records_ck_project_create_status","table_name":"project_create_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_create_idempotency_records_actor_profile_id__ebb1","table_name":"project_create_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_create_idempotency_records_identity_link_id__ddce","table_name":"project_create_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_create_idempotency_records","table_name":"project_create_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"project_create_reservation_custody","table_name":"project_create_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_project_create_operation_identity","table_name":"project_create_idempotency_records"},{"definition":"UNIQUE (project_id)","kind":"u","name":"uq_project_create_project_identity","table_name":"project_create_idempotency_records"},{"definition":"UNIQUE (actor_profile_id, action_id, idempotency_key)","kind":"u","name":"uq_project_create_replay_namespace","table_name":"project_create_idempotency_records"},{"definition":"CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_00d8","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (component_hashes IS NULL OR json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_31c4","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (status::text = 'compilation_reserved'::text AND provider_uncertain_at IS NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_provider_uncertain'::text AND provider_uncertain_at IS NOT NULL AND accepted_at IS NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'provider_result_accepted'::text AND accepted_at IS NOT NULL AND terminal_at IS NULL AND persisted_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NULL OR status::text = 'compilation_persisted'::text AND accepted_at IS NOT NULL AND persisted_at IS NOT NULL AND terminal_at IS NULL AND canonical_result IS NOT NULL AND result_hash IS NOT NULL AND component_hashes IS NOT NULL AND failure_code IS NULL AND persisted_compilation_id IS NOT NULL OR status::text = 'compilation_invalid_terminal'::text AND terminal_at IS NOT NULL AND accepted_at IS NULL AND persisted_at IS NULL AND canonical_result IS NULL AND result_hash IS NULL AND component_hashes IS NULL AND persisted_compilation_id IS NULL AND (failure_code::text = ANY (ARRAY['schema_invalid', 'unsafe_text', 'hash_mismatch', 'context_mismatch'])))","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_444c","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_513e","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (canonical_result IS NULL OR octet_length(canonical_result::text) <= 4194304)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_6057","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (result_hash IS NULL OR result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_6609","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (status::text = ANY (ARRAY['compilation_reserved', 'compilation_provider_uncertain', 'provider_result_accepted', 'compilation_invalid_terminal', 'compilation_persisted']))","kind":"c","name":"ck_project_guide_compilation_attempts_ck_compilation_at_6c82","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (persisted_compilation_id, id) REFERENCES project_guide_compilations(id, attempt_id)","kind":"f","name":"fk_compilation_attempt_exact_persisted_compilation","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (setup_run_id, project_id, guide_id, source_snapshot_id, setup_generation) REFERENCES project_setup_runs(id, project_id, guide_id, source_snapshot_id, setup_generation)","kind":"f","name":"fk_compilation_attempt_exact_setup","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_compilation_attempt_snapshot_hash","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_project_guide_compilation_attempts_guide_id_project_guides","table_name":"project_guide_compilation_attempts"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_guide_compilation_attempts_project_id_projects","table_name":"project_guide_compilation_attempts"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_guide_compilation_attempts","table_name":"project_guide_compilation_attempts"},{"definition":"UNIQUE (provider_idempotency_key)","kind":"u","name":"uq_compilation_attempt_provider_key","table_name":"project_guide_compilation_attempts"},{"definition":"UNIQUE (setup_run_id, setup_generation)","kind":"u","name":"uq_compilation_attempt_setup_generation","table_name":"project_guide_compilation_attempts"},{"definition":"CHECK (setup_generation > 0 AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_action_id::text = 'project.guide_compilation.execute'::text)","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_8a51","table_name":"project_guide_compilations"},{"definition":"CHECK (source_snapshot_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND canonical_input_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND guide_material_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND pre_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND post_catalogue_manifest_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND result_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_9cd9","table_name":"project_guide_compilations"},{"definition":"CHECK (authorization_resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_d554","table_name":"project_guide_compilations"},{"definition":"CHECK (octet_length(canonical_result::text) <= 4194304 AND json_typeof(component_hashes) = 'object'::text AND component_hashes::jsonb = jsonb_build_object('sufficiency_hash', component_hashes ->> 'sufficiency_hash'::text, 'artifact_policy_hash', component_hashes ->> 'artifact_policy_hash'::text, 'requirement_inventory_hash', component_hashes ->> 'requirement_inventory_hash'::text, 'pre_submit_hash', component_hashes ->> 'pre_submit_hash'::text, 'post_submit_hash', component_hashes ->> 'post_submit_hash'::text, 'capability_suggestions_hash', component_hashes ->> 'capability_suggestions_hash'::text, 'setup_notes_hash', component_hashes ->> 'setup_notes_hash'::text) AND COALESCE((component_hashes ->> 'sufficiency_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'artifact_policy_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'requirement_inventory_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'pre_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'post_submit_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'capability_suggestions_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false) AND COALESCE((component_hashes ->> 'setup_notes_hash'::text) ~ '^sha256:[0-9a-f]{64}$'::text, false))","kind":"c","name":"ck_project_guide_compilations_ck_project_guide_compilat_dafe","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (supersedes_compilation_id, project_id, guide_id) REFERENCES project_guide_compilations(id, project_id, guide_id)","kind":"f","name":"fk_project_guide_compilation_predecessor","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (attempt_id) REFERENCES project_guide_compilation_attempts(id)","kind":"f","name":"fk_project_guide_compilations_attempt_id_project_guide__0e94","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_project_guide_compilations_authorization_decision_ev_42ad","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_guide_compilations_created_by_actor_profile__953f","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_guide_compilations_created_via_identity_link_b250","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_project_guide_compilations_guide_id_project_guides","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_guide_compilations_project_id_projects","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_project_guide_compilations_setup_run_id_project_setup_runs","table_name":"project_guide_compilations"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_project_guide_compilations_source_snapshot_id_guide__033a","table_name":"project_guide_compilations"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_guide_compilations","table_name":"project_guide_compilations"},{"definition":"UNIQUE (attempt_id)","kind":"u","name":"uq_project_guide_compilation_attempt","table_name":"project_guide_compilations"},{"definition":"UNIQUE (id, attempt_id)","kind":"u","name":"uq_project_guide_compilation_id_attempt","table_name":"project_guide_compilations"},{"definition":"UNIQUE (supersedes_compilation_id)","kind":"u","name":"uq_project_guide_compilation_predecessor","table_name":"project_guide_compilations"},{"definition":"UNIQUE (id, project_id, guide_id)","kind":"u","name":"uq_project_guide_compilation_scope","table_name":"project_guide_compilations"},{"definition":"CHECK ((status::text <> ALL (ARRAY['active', 'superseded'])) OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL AND selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL)","kind":"c","name":"ck_project_guides_active_policy_selection_required","table_name":"project_guides"},{"definition":"CHECK (mutation_generation IS NULL AND last_mutated_by_actor_profile_id IS NULL AND last_mutated_via_identity_link_id IS NULL AND last_mutated_by_admin_role_grant_id IS NULL AND last_mutation_scope_type IS NULL AND last_mutation_scope_project_id IS NULL AND last_mutation_action_id IS NULL AND last_authorization_decision_event_id IS NULL OR mutation_generation > 0 AND last_mutated_by_actor_profile_id IS NOT NULL AND last_mutated_via_identity_link_id IS NOT NULL AND last_mutated_by_admin_role_grant_id IS NOT NULL AND (last_mutation_scope_type::text = ANY (ARRAY['system', 'project'])) AND (last_mutation_scope_type::text = 'system'::text AND last_mutation_scope_project_id IS NULL OR last_mutation_scope_type::text = 'project'::text AND last_mutation_scope_project_id::text = project_id::text) AND (last_mutation_action_id::text = ANY (ARRAY['project.guide.create', 'project.guide.update', 'project.guide_source_snapshot.create'])) AND last_authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_project_guides_guide_mutation_authority_shape","table_name":"project_guides"},{"definition":"CHECK ((selected_review_policy_id IS NULL AND selected_review_policy_generation IS NULL AND selected_review_policy_hash IS NULL OR selected_review_policy_id IS NOT NULL AND selected_review_policy_generation IS NOT NULL AND selected_review_policy_hash IS NOT NULL) AND (selected_revision_policy_id IS NULL AND selected_revision_policy_generation IS NULL AND selected_revision_policy_hash IS NULL OR selected_revision_policy_id IS NOT NULL AND selected_revision_policy_generation IS NOT NULL AND selected_revision_policy_hash IS NOT NULL))","kind":"c","name":"ck_project_guides_policy_selection_shape","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_mutated_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_guides_last_mutated_actor","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_mutated_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_guides_last_mutated_admin_grant","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_project_guides_last_mutated_decision","table_name":"project_guides"},{"definition":"FOREIGN KEY (last_mutated_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_guides_last_mutated_identity_link","table_name":"project_guides"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_guides_project_id_projects","table_name":"project_guides"},{"definition":"FOREIGN KEY (project_id, version, selected_review_policy_id, selected_review_policy_generation, selected_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_project_guides_selected_review_policy","table_name":"project_guides"},{"definition":"FOREIGN KEY (project_id, version, selected_revision_policy_id, selected_revision_policy_generation, selected_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_project_guides_selected_revision_policy","table_name":"project_guides"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"guide_mutation_product_custody","table_name":"project_guides"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_guides","table_name":"project_guides"},{"definition":"UNIQUE (id, project_id, version)","kind":"u","name":"uq_project_guides_id_project_version","table_name":"project_guides"},{"definition":"UNIQUE (project_id, version)","kind":"u","name":"uq_project_guides_project_version","table_name":"project_guides"},{"definition":"CHECK (grant_method::text = 'manual'::text)","kind":"c","name":"ck_project_role_grants_grant_method","table_name":"project_role_grants"},{"definition":"CHECK (status::text = 'active'::text AND version = 1 AND revoked_by_actor_profile_id IS NULL AND revoked_by_admin_role_grant_id IS NULL AND revoked_reason IS NULL AND revoked_at IS NULL OR status::text = 'revoked'::text AND version = 2 AND revoked_by_actor_profile_id IS NOT NULL AND revoked_by_admin_role_grant_id IS NOT NULL AND revoked_reason IS NOT NULL AND revoked_at IS NOT NULL)","kind":"c","name":"ck_project_role_grants_lifecycle","table_name":"project_role_grants"},{"definition":"CHECK (project_role_reason_is_safe(grant_reason) AND (revoked_reason IS NULL OR project_role_reason_is_safe(revoked_reason)))","kind":"c","name":"ck_project_role_grants_reason","table_name":"project_role_grants"},{"definition":"CHECK (role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))","kind":"c","name":"ck_project_role_grants_role","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_grants_actor_profile_id_actor_profiles","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (granted_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_grants_granted_by_actor_profile_id_acto_c240","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (granted_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_role_grants_granted_by_admin_role_grant_id_a_71d7","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_role_grants_project_id_projects","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (revoked_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_grants_revoked_by_actor_profile_id_acto_a5dd","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (revoked_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_role_grants_revoked_by_admin_role_grant_id_a_aa4d","table_name":"project_role_grants"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_role_grants","table_name":"project_role_grants"},{"definition":"FOREIGN KEY (qualification_snapshot_id, actor_profile_id, project_id, role) REFERENCES project_role_qualification_snapshots(id, actor_profile_id, project_id, requested_role) ON DELETE RESTRICT","kind":"f","name":"qualification_ownership","table_name":"project_role_grants"},{"definition":"CHECK (project_role_availability_is_safe(skills_snapshot) AND project_role_availability_is_safe(reputation_snapshot))","kind":"c","name":"ck_project_role_qualification_snapshots_availability","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (project_role_reference_array_is_safe(external_expertise_refs, false))","kind":"c","name":"ck_project_role_qualification_snapshots_external_expertise_refs","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (project_role_reference_array_is_safe(prior_project_work_refs, true))","kind":"c","name":"ck_project_role_qualification_snapshots_prior_work_refs","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (requested_role::text = ANY (ARRAY['submitter', 'reviewer', 'adjudicator']))","kind":"c","name":"ck_project_role_qualification_snapshots_role","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_qualification_snapshots_actor_profile_i_aedc","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (captured_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_role_qualification_snapshots_captured_by_act_ab57","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (captured_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_role_qualification_snapshots_captured_by_adm_c8b8","table_name":"project_role_qualification_snapshots"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_role_qualification_snapshots_project_id_projects","table_name":"project_role_qualification_snapshots"},{"definition":"UNIQUE (id, actor_profile_id, project_id, requested_role)","kind":"u","name":"grant_reference","table_name":"project_role_qualification_snapshots"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_role_qualification_snapshots","table_name":"project_role_qualification_snapshots"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_project_setup_runs_ck_project_setup_runs_generation_positive","table_name":"project_setup_runs"},{"definition":"CHECK (status::text = ANY (ARRAY['queued', 'dispatch_pending', 'enqueue_failed', 'enqueue_identity_mismatch', 'running_sufficiency_agent', 'sufficiency_blocked', 'running_policy_derivation_agent', 'policy_draft_ready', 'running_post_submit_derivation_agent', 'post_submit_setup_blocked', 'post_submit_policy_compiled', 'setup_blocked', 'failed']))","kind":"c","name":"ck_project_setup_runs_ck_project_setup_runs_status","table_name":"project_setup_runs"},{"definition":"CHECK (authorized_by_actor_profile_id IS NULL AND authorized_via_identity_link_id IS NULL AND authorized_by_admin_role_grant_id IS NULL AND authorization_scope_type IS NULL AND authorization_scope_project_id IS NULL AND authorization_action_id IS NULL AND authorization_decision_event_id IS NULL OR authorized_by_actor_profile_id IS NOT NULL AND authorized_via_identity_link_id IS NOT NULL AND authorized_by_admin_role_grant_id IS NOT NULL AND (authorization_scope_type::text = ANY (ARRAY['system', 'project'])) AND (authorization_scope_type::text = 'system'::text AND authorization_scope_project_id IS NULL OR authorization_scope_type::text = 'project'::text AND authorization_scope_project_id::text = project_id::text) AND authorization_action_id::text = 'project.guide_source_snapshot.create'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_project_setup_runs_setup_run_authority_shape","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (error_artifact_incident_id) REFERENCES guide_source_artifact_incidents(id)","kind":"f","name":"fk_project_setup_runs_artifact_incident","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorized_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_project_setup_runs_authorized_actor","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorized_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_project_setup_runs_authorized_admin_grant","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_project_setup_runs_authorized_decision","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (authorized_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_project_setup_runs_authorized_identity_link","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (continuation_verification_job_id) REFERENCES artifact_verification_jobs(id)","kind":"f","name":"fk_project_setup_runs_continuation_verification_job","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_project_setup_runs_guide_id_project_guides","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (output_post_submit_checker_policy_id) REFERENCES checker_policies(id)","kind":"f","name":"fk_project_setup_runs_post_submit_checker_policy","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_project_setup_runs_project_guide","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_project_setup_runs_project_id_projects","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_project_setup_runs_source_snapshot_hash","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_project_setup_runs_source_snapshot_id_guide_source_snapshots","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (output_submission_artifact_policy_id) REFERENCES submission_artifact_policies(id)","kind":"f","name":"fk_project_setup_runs_submission_artifact_policy","table_name":"project_setup_runs"},{"definition":"FOREIGN KEY (output_sufficiency_report_id) REFERENCES guide_sufficiency_reports(id)","kind":"f","name":"fk_project_setup_runs_sufficiency_report","table_name":"project_setup_runs"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_project_setup_runs","table_name":"project_setup_runs"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"source_setup_run_custody","table_name":"project_setup_runs"},{"definition":"UNIQUE (id, project_id, guide_id, source_snapshot_id, setup_generation)","kind":"u","name":"uq_project_setup_runs_exact_generation","table_name":"project_setup_runs"},{"definition":"UNIQUE (guide_id, setup_generation)","kind":"u","name":"uq_project_setup_runs_guide_generation","table_name":"project_setup_runs"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND creation_scope_type IS NULL AND creation_action_id IS NULL AND authorization_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND creation_scope_type::text = 'system'::text AND creation_action_id::text = 'project.create'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_projects_creation_authority_shape","table_name":"projects"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_projects_creation_actor","table_name":"projects"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_projects_creation_admin_grant","table_name":"projects"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_projects_creation_decision","table_name":"projects"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_projects_creation_identity_link","table_name":"projects"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_projects","table_name":"projects"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"project_creation_custody","table_name":"projects"},{"definition":"UNIQUE (slug)","kind":"u","name":"uq_projects_slug","table_name":"projects"},{"definition":"CHECK (submission_version > 0)","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_2b6d","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (status::text = 'pending'::text AND review_queue_entry_id IS NULL AND committed_at IS NULL OR status::text = 'committed'::text AND review_queue_entry_id IS NOT NULL AND committed_at IS NOT NULL)","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_4cd5","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_88bf","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['pending', 'committed']))","kind":"c","name":"ck_review_admission_idempotency_records_ck_review_admis_b8b8","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_review_admission_checker","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)","kind":"f","name":"fk_review_admission_committed_queue","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_admission_project","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (review_queue_entry_id) REFERENCES review_queue_entries(id)","kind":"f","name":"fk_review_admission_queue","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_review_admission_submission","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_review_admission_submission_lineage","table_name":"review_admission_idempotency_records"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_review_admission_task","table_name":"review_admission_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_admission_idempotency_records","table_name":"review_admission_idempotency_records"},{"definition":"UNIQUE (admitting_checker_run_id)","kind":"u","name":"uq_review_admission_checker_run","table_name":"review_admission_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_review_admission_operation","table_name":"review_admission_idempotency_records"},{"definition":"UNIQUE (idempotency_key)","kind":"u","name":"uq_review_admission_replay_key","table_name":"review_admission_idempotency_records"},{"definition":"CHECK (attempt_generation > 0)","kind":"c","name":"ck_review_leases_attempt_generation_positive","table_name":"review_leases"},{"definition":"CHECK (closed_at IS NULL OR closed_at >= claimed_at)","kind":"c","name":"ck_review_leases_closure_after_claim","table_name":"review_leases"},{"definition":"CHECK (expires_at > claimed_at)","kind":"c","name":"ck_review_leases_expiry_after_claim","table_name":"review_leases"},{"definition":"CHECK (status::text = 'active'::text AND closed_at IS NULL AND close_reason IS NULL OR status::text = 'consumed'::text AND closed_at IS NOT NULL AND close_reason::text = 'review_recorded'::text OR status::text = 'released'::text AND closed_at IS NOT NULL AND close_reason::text = 'manual_release'::text OR status::text = 'expired'::text AND closed_at IS NOT NULL AND close_reason::text = 'lease_expired'::text OR status::text = 'revoked'::text AND closed_at IS NOT NULL AND (close_reason::text = ANY (ARRAY['grant_revoked', 'admin_override'])))","kind":"c","name":"ck_review_leases_lifecycle_shape","table_name":"review_leases"},{"definition":"CHECK (status::text = ANY (ARRAY['active', 'consumed', 'released', 'expired', 'revoked']))","kind":"c","name":"ck_review_leases_status","table_name":"review_leases"},{"definition":"FOREIGN KEY (reviewer_contribution_policy_version_id, project_id) REFERENCES contribution_policy_versions(id, project_id)","kind":"f","name":"fk_review_lease_policy_version","table_name":"review_leases"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_lease_project","table_name":"review_leases"},{"definition":"FOREIGN KEY (review_queue_entry_id, project_id, task_id, submission_id, submission_version) REFERENCES review_queue_entries(id, project_id, task_id, submission_id, submission_version)","kind":"f","name":"fk_review_lease_queue_lineage","table_name":"review_leases"},{"definition":"FOREIGN KEY (reviewer_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_review_lease_reviewer","table_name":"review_leases"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_review_lease_submission","table_name":"review_leases"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_review_lease_task","table_name":"review_leases"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_leases","table_name":"review_leases"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"review_leases_active_lease_guard","table_name":"review_leases"},{"definition":"UNIQUE (review_queue_entry_id, attempt_generation)","kind":"u","name":"uq_review_lease_attempt","table_name":"review_leases"},{"definition":"UNIQUE (review_queue_entry_id, id)","kind":"u","name":"uq_review_lease_queue_identity","table_name":"review_leases"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.review_policy.update'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_review_policies_review_policy_authority_shape","table_name":"review_policies"},{"definition":"CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))","kind":"c","name":"ck_review_policies_review_policy_identity_shape","table_name":"review_policies"},{"definition":"CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)","kind":"c","name":"ck_review_policies_review_policy_predecessor_shape","table_name":"review_policies"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR review_preference_window_seconds > 0 AND review_lease_duration_seconds > 0 AND max_active_review_leases_per_reviewer = 1 AND self_review_allowed = false AND reject_policy::text = 'close_task'::text AND (finding_evidence_requirement::text = ANY (ARRAY['optional', 'required_for_blocking', 'required_for_all'])))","kind":"c","name":"ck_review_policies_review_policy_semantics_shape","table_name":"review_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_review_policies_actor_profile","table_name":"review_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_review_policies_admin_grant","table_name":"review_policies"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_review_policies_decision_event","table_name":"review_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_review_policies_identity_link","table_name":"review_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_review_policies_project_guide","table_name":"review_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_policies_project_id_projects","table_name":"review_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES review_policies(id)","kind":"f","name":"fk_review_policies_supersedes","table_name":"review_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_policies","table_name":"review_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"review_policy_mutation_custody","table_name":"review_policies"},{"definition":"UNIQUE (project_id, guide_version, policy_generation)","kind":"u","name":"uq_review_policies_project_version_generation","table_name":"review_policies"},{"definition":"UNIQUE (id, policy_generation, policy_hash)","kind":"u","name":"uq_review_policy_lineage","table_name":"review_policies"},{"definition":"UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)","kind":"u","name":"uq_review_policy_scoped_lineage","table_name":"review_policies"},{"definition":"CHECK (available_since >= first_queued_at)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_availab_d484","table_name":"review_queue_entries"},{"definition":"CHECK (routing_generation > 0 AND lifecycle_generation > 0)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_generat_38b7","table_name":"review_queue_entries"},{"definition":"CHECK (queue_state::text = 'pending'::text AND active_lease_id IS NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'leased'::text AND active_lease_id IS NOT NULL AND closed_at IS NULL AND closed_reason IS NULL OR queue_state::text = 'closed'::text AND active_lease_id IS NULL AND closed_at IS NOT NULL AND (closed_reason::text = ANY (ARRAY['review_recorded', 'task_closed', 'admin_cancelled'])) AND closed_at >= first_queued_at)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_lifecycle_shape","table_name":"review_queue_entries"},{"definition":"CHECK (queue_state::text = ANY (ARRAY['pending', 'leased', 'closed']))","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_queue_state","table_name":"review_queue_entries"},{"definition":"CHECK (routing_mode::text = ANY (ARRAY['open', 'preferred']))","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_routing_mode","table_name":"review_queue_entries"},{"definition":"CHECK (routing_reason::text = ANY (ARRAY['first_submission', 'revision_return', 'admin_assignment']))","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_routing_reason","table_name":"review_queue_entries"},{"definition":"CHECK (routing_mode::text = 'open'::text AND preferred_reviewer_id IS NULL AND preference_expires_at IS NULL OR routing_mode::text = 'preferred'::text AND preferred_reviewer_id IS NOT NULL AND preference_expires_at IS NOT NULL AND preference_expires_at > first_queued_at)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_routing_shape","table_name":"review_queue_entries"},{"definition":"CHECK (submission_version > 0)","kind":"c","name":"ck_review_queue_entries_ck_review_queue_entries_submiss_2f6b","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (active_lease_id, id) REFERENCES review_leases(id, review_queue_entry_id) DEFERRABLE INITIALLY DEFERRED","kind":"f","name":"fk_review_queue_active_lease","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (admitting_checker_run_id) REFERENCES checker_runs(id)","kind":"f","name":"fk_review_queue_checker","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (preferred_reviewer_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_review_queue_preferred_reviewer","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_review_queue_project","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_review_queue_submission","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (submission_id, task_id, submission_version) REFERENCES submissions(id, task_id, version)","kind":"f","name":"fk_review_queue_submission_lineage","table_name":"review_queue_entries"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_review_queue_task","table_name":"review_queue_entries"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_review_queue_entries","table_name":"review_queue_entries"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"review_queue_entries_active_lease_guard","table_name":"review_queue_entries"},{"definition":"UNIQUE (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)","kind":"u","name":"uq_review_queue_admission_identity","table_name":"review_queue_entries"},{"definition":"UNIQUE (id, project_id, task_id, submission_id, submission_version)","kind":"u","name":"uq_review_queue_lease_lineage","table_name":"review_queue_entries"},{"definition":"UNIQUE (submission_id)","kind":"u","name":"uq_review_queue_submission","table_name":"review_queue_entries"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND created_by_admin_role_grant_id IS NOT NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) AND creation_action_id::text = 'project.revision_policy.update'::text AND authorization_decision_event_id IS NOT NULL)","kind":"c","name":"ck_revision_policies_revision_policy_authority_shape","table_name":"revision_policies"},{"definition":"CHECK (policy_generation > 0 AND policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND (semantics_status::text = ANY (ARRAY['complete', 'legacy_incomplete'])))","kind":"c","name":"ck_revision_policies_revision_policy_identity_shape","table_name":"revision_policies"},{"definition":"CHECK (supersedes_policy_id IS NULL AND predecessor_policy_hash IS NULL AND policy_generation = 1 OR supersedes_policy_id IS NOT NULL AND predecessor_policy_hash::text ~ '^sha256:[0-9a-f]{64}$'::text AND policy_generation > 1 OR semantics_status::text = 'legacy_incomplete'::text)","kind":"c","name":"ck_revision_policies_revision_policy_predecessor_shape","table_name":"revision_policies"},{"definition":"CHECK (semantics_status::text = 'legacy_incomplete'::text OR max_revision_rounds > 0 AND revision_deadline_hours > 0)","kind":"c","name":"ck_revision_policies_revision_policy_semantics_shape","table_name":"revision_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_revision_policies_actor_profile","table_name":"revision_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_revision_policies_admin_grant","table_name":"revision_policies"},{"definition":"FOREIGN KEY (authorization_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_revision_policies_decision_event","table_name":"revision_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_revision_policies_identity_link","table_name":"revision_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_revision_policies_project_guide","table_name":"revision_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_revision_policies_project_id_projects","table_name":"revision_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES revision_policies(id)","kind":"f","name":"fk_revision_policies_supersedes","table_name":"revision_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_revision_policies","table_name":"revision_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"revision_policy_mutation_custody","table_name":"revision_policies"},{"definition":"UNIQUE (project_id, guide_version, policy_generation)","kind":"u","name":"uq_revision_policies_project_version_generation","table_name":"revision_policies"},{"definition":"UNIQUE (id, policy_generation, policy_hash)","kind":"u","name":"uq_revision_policy_lineage","table_name":"revision_policies"},{"definition":"UNIQUE (project_id, guide_version, id, policy_generation, policy_hash)","kind":"u","name":"uq_revision_policy_scoped_lineage","table_name":"revision_policies"},{"definition":"CHECK (lifecycle_status::text = ANY (ARRAY['draft', 'approved', 'superseded']))","kind":"c","name":"ck_submission_artifact_policies_ck_submission_artifact__20ca","table_name":"submission_artifact_policies"},{"definition":"CHECK (lifecycle_status::text <> 'approved'::text OR (approved_by_role::text = ANY (ARRAY['admin', 'project_manager'])) AND approved_by_actor IS NOT NULL AND approved_at IS NOT NULL)","kind":"c","name":"ck_submission_artifact_policies_ck_submission_artifact__52ca","table_name":"submission_artifact_policies"},{"definition":"CHECK (approved_by_actor_profile_id IS NULL AND approved_via_identity_link_id IS NULL AND approved_by_admin_role_grant_id IS NULL AND approval_scope_type IS NULL AND approval_scope_project_id IS NULL AND approval_action_id IS NULL AND approval_decision_event_id IS NULL OR approved_by_actor_profile_id IS NOT NULL AND approved_via_identity_link_id IS NOT NULL AND approved_by_admin_role_grant_id IS NOT NULL AND approval_scope_type IS NOT NULL AND approval_action_id IS NOT NULL AND (approval_scope_type::text = ANY (ARRAY['system', 'project'])) AND approval_scope_project_id IS NOT NULL AND approval_scope_project_id::text = project_id::text AND approval_action_id::text = 'project.submission_artifact_policy.approve'::text AND approval_decision_event_id IS NOT NULL)","kind":"c","name":"ck_submission_artifact_policies_ck_submission_policy_ap_0e4d","table_name":"submission_artifact_policies"},{"definition":"CHECK (created_by_actor_profile_id IS NULL AND created_via_identity_link_id IS NULL AND created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NULL AND creation_scope_type IS NULL AND creation_scope_project_id IS NULL AND creation_action_id IS NULL AND creation_decision_event_id IS NULL OR created_by_actor_profile_id IS NOT NULL AND created_via_identity_link_id IS NOT NULL AND creation_scope_type IS NOT NULL AND creation_action_id IS NOT NULL AND creation_scope_project_id IS NOT NULL AND creation_scope_project_id::text = project_id::text AND creation_decision_event_id IS NOT NULL AND (creation_action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update'])) AND (created_by_admin_role_grant_id IS NOT NULL AND created_by_service_identity IS NULL AND (creation_scope_type::text = ANY (ARRAY['system', 'project'])) OR created_by_admin_role_grant_id IS NULL AND created_by_service_identity IS NOT NULL AND created_by_service_identity::text = 'workstream.project.setup'::text AND creation_scope_type::text = 'service'::text AND creation_action_id::text = 'project.submission_artifact_policy.derive'::text))","kind":"c","name":"ck_submission_artifact_policies_ck_submission_policy_cr_0629","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (supersedes_policy_id) REFERENCES submission_artifact_policies(id)","kind":"f","name":"fk_sap_supersedes_policy","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_submission_artifact_policies_guide_id_project_guides","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id, guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_submission_artifact_policies_project_guide","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_artifact_policies_project_id_projects","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (source_snapshot_id, source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_submission_artifact_policies_source_snapshot_hash","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approved_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submission_policy_approval_actor","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approval_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_submission_policy_approval_decision","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approved_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_submission_policy_approval_grant","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approved_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_submission_policy_approval_link","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (approval_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_policy_approval_project","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submission_policy_creation_actor","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_decision_event_id) REFERENCES audit_events(id)","kind":"f","name":"fk_submission_policy_creation_decision","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (created_by_admin_role_grant_id) REFERENCES admin_role_grants(id)","kind":"f","name":"fk_submission_policy_creation_grant","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (created_via_identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_submission_policy_creation_link","table_name":"submission_artifact_policies"},{"definition":"FOREIGN KEY (creation_scope_project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_policy_creation_project","table_name":"submission_artifact_policies"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_artifact_policies","table_name":"submission_artifact_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"submission_policy_creation_custody","table_name":"submission_artifact_policies"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"submission_policy_product_custody","table_name":"submission_artifact_policies"},{"definition":"UNIQUE (id, policy_hash)","kind":"u","name":"uq_submission_artifact_policies_id_hash","table_name":"submission_artifact_policies"},{"definition":"UNIQUE (project_id, guide_version, policy_version)","kind":"u","name":"uq_submission_artifact_policies_project_version_policy","table_name":"submission_artifact_policies"},{"definition":"CHECK (archive_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_bundle_admissions_archive_sha256","table_name":"submission_bundle_admissions"},{"definition":"CHECK (archive_byte_count >= 0)","kind":"c","name":"ck_submission_bundle_admissions_archive_size","table_name":"submission_bundle_admissions"},{"definition":"CHECK (semantic_manifest_sha256::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_bundle_admissions_manifest_sha256","table_name":"submission_bundle_admissions"},{"definition":"CHECK (locked_policy_context_hash::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_bundle_admissions_policy_context_hash","table_name":"submission_bundle_admissions"},{"definition":"CHECK ((predecessor_submission_id IS NULL) = (predecessor_submission_version IS NULL))","kind":"c","name":"ck_submission_bundle_admissions_predecessor_shape","table_name":"submission_bundle_admissions"},{"definition":"CHECK (status::text = ANY (ARRAY['ready', 'consumed', 'stale']))","kind":"c","name":"ck_submission_bundle_admissions_status","table_name":"submission_bundle_admissions"},{"definition":"CHECK (status::text = 'ready'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'consumed'::text AND consumed_at IS NOT NULL AND consumed_by_submission_id IS NOT NULL AND stale_at IS NULL AND stale_reason IS NULL OR status::text = 'stale'::text AND consumed_at IS NULL AND consumed_by_submission_id IS NULL AND stale_at IS NOT NULL AND octet_length(stale_reason::text) >= 1 AND octet_length(stale_reason::text) <= 500)","kind":"c","name":"ck_submission_bundle_admissions_terminal_shape","table_name":"submission_bundle_admissions"},{"definition":"CHECK (((put_operation_receipt_id IS NOT NULL)::integer + (put_observation_receipt_id IS NOT NULL)::integer) = 1)","kind":"c","name":"ck_submission_bundle_admissions_write_receipt_shape","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_actor_profile_id_actor_profiles","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (artifact_content_id) REFERENCES artifact_contents(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_artifact_content_id_art_12c8","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (assignment_id) REFERENCES task_assignments(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_assignment_id_task_assignments","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (consumed_by_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_consumed_by_submission__2b23","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (durable_intent_id) REFERENCES submission_bundle_durable_intents(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_durable_intent_id_submi_102c","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_identity_link_id_actor__d29d","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_pre_submit_evidence_set_a752","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (predecessor_submission_id) REFERENCES submissions(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_predecessor_submission__242d","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_project_id_projects","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_put_attempt_id_artifact_bbc3","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (put_observation_receipt_id) REFERENCES artifact_put_observation_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_put_observation_receipt_5136","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (put_operation_receipt_id) REFERENCES artifact_operation_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_put_operation_receipt_i_9602","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_task_id_workstream_tasks","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (verification_receipt_id) REFERENCES artifact_verification_receipts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_verification_receipt_id_0ea1","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (verified_replica_id) REFERENCES artifact_replicas(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_admissions_verified_replica_id_art_3a4e","table_name":"submission_bundle_admissions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_bundle_admissions","table_name":"submission_bundle_admissions"},{"definition":"UNIQUE (pre_submit_evidence_set_id)","kind":"u","name":"uq_submission_bundle_admission_evidence","table_name":"submission_bundle_admissions"},{"definition":"UNIQUE (durable_intent_id)","kind":"u","name":"uq_submission_bundle_admission_intent","table_name":"submission_bundle_admissions"},{"definition":"UNIQUE (verification_receipt_id)","kind":"u","name":"uq_submission_bundle_admission_verification","table_name":"submission_bundle_admissions"},{"definition":"FOREIGN KEY (pre_submit_evidence_set_id) REFERENCES pre_submit_evidence_sets(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_durable_intents_pre_submit_evidenc_c406","table_name":"submission_bundle_durable_intents"},{"definition":"FOREIGN KEY (put_attempt_id) REFERENCES artifact_put_attempts(id) ON DELETE RESTRICT","kind":"f","name":"fk_submission_bundle_durable_intents_put_attempt_id_art_b4e4","table_name":"submission_bundle_durable_intents"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_bundle_durable_intents","table_name":"submission_bundle_durable_intents"},{"definition":"UNIQUE (pre_submit_evidence_set_id)","kind":"u","name":"uq_submission_bundle_intent_evidence","table_name":"submission_bundle_durable_intents"},{"definition":"UNIQUE (put_attempt_id)","kind":"u","name":"uq_submission_bundle_intent_put_attempt","table_name":"submission_bundle_durable_intents"},{"definition":"CHECK (request_digest::text ~ '^sha256:[0-9a-f]{64}$'::text AND resource_context_digest::text ~ '^sha256:[0-9a-f]{64}$'::text)","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_0119","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (action_id::text = ANY (ARRAY['project.submission_artifact_policy.create', 'project.submission_artifact_policy.derive', 'project.submission_artifact_policy.update', 'project.submission_artifact_policy.approve']))","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_0dbe","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (setup_generation > 0)","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_2b53","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK ((status::text = ANY (ARRAY['reserved', 'pending'])) AND response_json IS NULL AND committed_at IS NULL AND committed_policy_id IS NULL AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL OR status::text = 'committed'::text AND response_json IS NOT NULL AND committed_at IS NOT NULL AND committed_policy_id IS NOT NULL AND (action_id::text = 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NOT NULL AND committed_pre_submit_policy_id IS NOT NULL OR action_id::text <> 'project.submission_artifact_policy.approve'::text AND committed_effective_policy_id IS NULL AND committed_pre_submit_policy_id IS NULL))","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_58d4","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (status::text = ANY (ARRAY['reserved', 'pending', 'committed']))","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_a824","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (service_identity IS NULL AND idempotency_key IS NOT NULL AND setup_run_id IS NULL AND setup_task_id IS NULL AND correlation_id IS NULL OR service_identity IS NOT NULL AND service_identity::text = 'workstream.project.setup'::text AND idempotency_key IS NULL AND action_id::text = 'project.submission_artifact_policy.derive'::text AND setup_run_id IS NOT NULL AND setup_task_id IS NOT NULL AND correlation_id IS NOT NULL)","kind":"c","name":"ck_submission_policy_mutation_idempotency_records_ck_su_b357","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (actor_profile_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_actor_f5bb","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (committed_effective_policy_id) REFERENCES effective_project_submission_artifact_policies(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_commi_4fa6","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (committed_policy_id) REFERENCES submission_artifact_policies(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_commi_571a","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (committed_pre_submit_policy_id) REFERENCES pre_submit_checker_policies(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_commi_baa9","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (guide_id) REFERENCES project_guides(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_guide_ed8d","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (identity_link_id) REFERENCES actor_identity_links(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_ident_2567","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_proje_442a","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (setup_run_id) REFERENCES project_setup_runs(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_setup_a102","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"FOREIGN KEY (source_snapshot_id) REFERENCES guide_source_snapshots(id)","kind":"f","name":"fk_submission_policy_mutation_idempotency_records_sourc_536e","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submission_policy_mutation_idempotency_records","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"TRIGGER DEFERRABLE INITIALLY DEFERRED","kind":"t","name":"submission_policy_replay_custody","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"UNIQUE (operation_id)","kind":"u","name":"uq_submission_policy_operation_identity","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CHECK (locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)","kind":"c","name":"ck_submissions_post_submit_policy_lock_complete","table_name":"submissions"},{"definition":"FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_submissions_contributor_id_actor_profiles","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_submissions_locked_effective_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)","kind":"f","name":"fk_submissions_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)","kind":"f","name":"fk_submissions_locked_pre_submit_checker_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_submissions_locked_source_snapshot_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (supersedes_submission_id) REFERENCES submissions(id)","kind":"f","name":"fk_submissions_supersedes_submission_id_submissions","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_submissions_task_id_workstream_tasks","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES workstream_tasks(id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","kind":"f","name":"fk_submissions_task_locked_effective_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_guide_version) REFERENCES workstream_tasks(id, locked_guide_version)","kind":"f","name":"fk_submissions_task_locked_guide","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_payment_policy_version) REFERENCES workstream_tasks(id, locked_payment_policy_version)","kind":"f","name":"fk_submissions_task_locked_payment_policy","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES workstream_tasks(id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"f","name":"fk_submissions_task_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES workstream_tasks(id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","kind":"f","name":"fk_submissions_task_locked_pre_submit_checker_hash","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES workstream_tasks(id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","kind":"f","name":"fk_submissions_task_locked_review_policy","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES workstream_tasks(id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","kind":"f","name":"fk_submissions_task_locked_revision_policy","table_name":"submissions"},{"definition":"FOREIGN KEY (task_id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES workstream_tasks(id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","kind":"f","name":"fk_submissions_task_locked_source_snapshot_hash","table_name":"submissions"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_submissions","table_name":"submissions"},{"definition":"UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"u","name":"uq_submissions_id_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"UNIQUE (id, task_id, version)","kind":"u","name":"uq_submissions_id_task_version","table_name":"submissions"},{"definition":"UNIQUE (id, version)","kind":"u","name":"uq_submissions_id_version","table_name":"submissions"},{"definition":"UNIQUE (task_id, version)","kind":"u","name":"uq_submissions_task_version","table_name":"submissions"},{"definition":"FOREIGN KEY (contributor_id) REFERENCES actor_profiles(id)","kind":"f","name":"fk_task_assignments_contributor_id_actor_profiles","table_name":"task_assignments"},{"definition":"FOREIGN KEY (task_id) REFERENCES workstream_tasks(id)","kind":"f","name":"fk_task_assignments_task_id_workstream_tasks","table_name":"task_assignments"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_task_assignments","table_name":"task_assignments"},{"definition":"UNIQUE (id, task_id, contributor_id)","kind":"u","name":"uq_task_assignments_id_task_contributor","table_name":"task_assignments"},{"definition":"CHECK (status::text = 'draft'::text OR locked_post_submit_checker_policy_id IS NOT NULL AND locked_post_submit_checker_policy_version IS NOT NULL AND locked_post_submit_checker_policy_hash IS NOT NULL AND locked_post_submit_checker_policy_body IS NOT NULL)","kind":"c","name":"ck_workstream_tasks_post_submit_policy_lock_complete","table_name":"workstream_tasks"},{"definition":"CHECK (status::text = 'draft'::text OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)","kind":"c","name":"ck_workstream_tasks_review_revision_policy_lock_required","table_name":"workstream_tasks"},{"definition":"CHECK (locked_review_policy_id IS NULL AND locked_review_policy_generation IS NULL AND locked_review_policy_hash IS NULL AND locked_revision_policy_id IS NULL AND locked_revision_policy_generation IS NULL AND locked_revision_policy_hash IS NULL OR locked_review_policy_id IS NOT NULL AND locked_review_policy_generation IS NOT NULL AND locked_review_policy_hash IS NOT NULL AND locked_revision_policy_id IS NOT NULL AND locked_revision_policy_generation IS NOT NULL AND locked_revision_policy_hash IS NOT NULL)","kind":"c","name":"ck_workstream_tasks_review_revision_policy_lock_shape","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash) REFERENCES effective_project_submission_artifact_policies(id, effective_policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_guide_version) REFERENCES project_guides(project_id, version)","kind":"f","name":"fk_workstream_tasks_locked_guide","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_payment_policy_version) REFERENCES payment_policies(project_id, guide_version)","kind":"f","name":"fk_workstream_tasks_locked_payment_policy","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash) REFERENCES checker_policies(id, guide_version, policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash) REFERENCES pre_submit_checker_policies(id, compiled_bundle_hash)","kind":"f","name":"fk_workstream_tasks_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_guide_version, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash) REFERENCES review_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_review_policy","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id, locked_guide_version, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash) REFERENCES revision_policies(project_id, guide_version, id, policy_generation, policy_hash)","kind":"f","name":"fk_workstream_tasks_locked_revision_policy","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash) REFERENCES guide_source_snapshots(id, bundle_hash)","kind":"f","name":"fk_workstream_tasks_locked_source_snapshot_hash","table_name":"workstream_tasks"},{"definition":"FOREIGN KEY (project_id) REFERENCES projects(id)","kind":"f","name":"fk_workstream_tasks_project_id_projects","table_name":"workstream_tasks"},{"definition":"PRIMARY KEY (id)","kind":"p","name":"pk_workstream_tasks","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_guide_version)","kind":"u","name":"uq_workstream_tasks_id_locked_guide","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_payment_policy_version)","kind":"u","name":"uq_workstream_tasks_id_locked_payment_policy","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_review_policy","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_revision_policy","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","kind":"u","name":"uq_workstream_tasks_id_locked_source_snapshot_hash","table_name":"workstream_tasks"},{"definition":"UNIQUE (id, project_id)","kind":"u","name":"uq_workstream_tasks_id_project","table_name":"workstream_tasks"}],"format":"workstream-v01-schema-manifest-1","indexes":[{"definition":"CREATE INDEX ix_actor_identity_links_issuer_subject_status ON public.actor_identity_links USING btree (issuer, subject, status)","name":"ix_actor_identity_links_issuer_subject_status","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX pk_actor_identity_links ON public.actor_identity_links USING btree (id)","name":"pk_actor_identity_links","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX uq_actor_identity_links_actor_profile ON public.actor_identity_links USING btree (actor_profile_id)","name":"uq_actor_identity_links_actor_profile","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX uq_actor_identity_links_external_identity ON public.actor_identity_links USING btree (issuer, subject)","name":"uq_actor_identity_links_external_identity","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX uq_actor_identity_links_id_profile ON public.actor_identity_links USING btree (id, actor_profile_id)","name":"uq_actor_identity_links_id_profile","table_name":"actor_identity_links"},{"definition":"CREATE UNIQUE INDEX pk_actor_profile_migration_state ON public.actor_profile_migration_state USING btree (id)","name":"pk_actor_profile_migration_state","table_name":"actor_profile_migration_state"},{"definition":"CREATE INDEX ix_actor_profiles_last_seen_at ON public.actor_profiles USING btree (last_seen_at)","name":"ix_actor_profiles_last_seen_at","table_name":"actor_profiles"},{"definition":"CREATE INDEX ix_actor_profiles_status_actor_kind ON public.actor_profiles USING btree (status, actor_kind)","name":"ix_actor_profiles_status_actor_kind","table_name":"actor_profiles"},{"definition":"CREATE UNIQUE INDEX pk_actor_profiles ON public.actor_profiles USING btree (id)","name":"pk_actor_profiles","table_name":"actor_profiles"},{"definition":"CREATE UNIQUE INDEX service_identity ON public.actor_profiles USING btree (service_identity)","name":"service_identity","table_name":"actor_profiles"},{"definition":"CREATE INDEX ix_admin_role_grants_effective_candidate ON public.admin_role_grants USING btree (target_actor_profile_id, status, scope_type, scope_project_id)","name":"ix_admin_role_grants_effective_candidate","table_name":"admin_role_grants"},{"definition":"CREATE INDEX ix_admin_role_grants_final_access_admin ON public.admin_role_grants USING btree (role, status) WHERE (((role)::text = 'access_administrator'::text) AND ((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))","name":"ix_admin_role_grants_final_access_admin","table_name":"admin_role_grants"},{"definition":"CREATE INDEX ix_admin_role_grants_history ON public.admin_role_grants USING btree (target_actor_profile_id, granted_at, id)","name":"ix_admin_role_grants_history","table_name":"admin_role_grants"},{"definition":"CREATE UNIQUE INDEX pk_admin_role_grants ON public.admin_role_grants USING btree (id)","name":"pk_admin_role_grants","table_name":"admin_role_grants"},{"definition":"CREATE UNIQUE INDEX uq_admin_role_grants_active_project ON public.admin_role_grants USING btree (target_actor_profile_id, role, scope_project_id) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'project'::text))","name":"uq_admin_role_grants_active_project","table_name":"admin_role_grants"},{"definition":"CREATE UNIQUE INDEX uq_admin_role_grants_active_system ON public.admin_role_grants USING btree (target_actor_profile_id, role) WHERE (((status)::text = 'active'::text) AND ((scope_type)::text = 'system'::text))","name":"uq_admin_role_grants_active_system","table_name":"admin_role_grants"},{"definition":"CREATE INDEX ix_api_rate_control_counters_window_expires_at ON public.api_rate_control_counters USING btree (window_expires_at)","name":"ix_api_rate_control_counters_window_expires_at","table_name":"api_rate_control_counters"},{"definition":"CREATE UNIQUE INDEX pk_api_rate_control_counters ON public.api_rate_control_counters USING btree (control_scope, key_digest)","name":"pk_api_rate_control_counters","table_name":"api_rate_control_counters"},{"definition":"CREATE UNIQUE INDEX pk_artifact_admission_charges ON public.artifact_admission_charges USING btree (id)","name":"pk_artifact_admission_charges","table_name":"artifact_admission_charges"},{"definition":"CREATE UNIQUE INDEX uq_artifact_admission_charge_scope_content ON public.artifact_admission_charges USING btree (scope_type, scope_id, sha256, byte_count)","name":"uq_artifact_admission_charge_scope_content","table_name":"artifact_admission_charges"},{"definition":"CREATE UNIQUE INDEX pk_artifact_admission_scopes ON public.artifact_admission_scopes USING btree (scope_type, scope_id)","name":"pk_artifact_admission_scopes","table_name":"artifact_admission_scopes"},{"definition":"CREATE INDEX ix_artifact_bindings_content_id ON public.artifact_bindings USING btree (content_id)","name":"ix_artifact_bindings_content_id","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_bindings_project_id ON public.artifact_bindings USING btree (project_id)","name":"ix_artifact_bindings_project_id","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_bindings_scope ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version DESC)","name":"ix_artifact_bindings_scope","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_bindings_supersedes_binding_id ON public.artifact_bindings USING btree (supersedes_binding_id)","name":"ix_artifact_bindings_supersedes_binding_id","table_name":"artifact_bindings"},{"definition":"CREATE UNIQUE INDEX pk_artifact_bindings ON public.artifact_bindings USING btree (id)","name":"pk_artifact_bindings","table_name":"artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_artifact_binding_scope_version ON public.artifact_bindings USING btree (project_id, resource_type, resource_id, logical_role, scope_version)","name":"uq_artifact_binding_scope_version","table_name":"artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_artifact_binding_supersedes ON public.artifact_bindings USING btree (supersedes_binding_id)","name":"uq_artifact_binding_supersedes","table_name":"artifact_bindings"},{"definition":"CREATE INDEX ix_artifact_contents_sha256 ON public.artifact_contents USING btree (sha256)","name":"ix_artifact_contents_sha256","table_name":"artifact_contents"},{"definition":"CREATE UNIQUE INDEX pk_artifact_contents ON public.artifact_contents USING btree (id)","name":"pk_artifact_contents","table_name":"artifact_contents"},{"definition":"CREATE UNIQUE INDEX uq_artifact_content_digest_size ON public.artifact_contents USING btree (sha256, byte_count)","name":"uq_artifact_content_digest_size","table_name":"artifact_contents"},{"definition":"CREATE INDEX ix_artifact_operation_receipts_put_attempt_id ON public.artifact_operation_receipts USING btree (put_attempt_id)","name":"ix_artifact_operation_receipts_put_attempt_id","table_name":"artifact_operation_receipts"},{"definition":"CREATE INDEX ix_artifact_operation_receipts_replica_id ON public.artifact_operation_receipts USING btree (replica_id)","name":"ix_artifact_operation_receipts_replica_id","table_name":"artifact_operation_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_operation_receipts ON public.artifact_operation_receipts USING btree (id)","name":"pk_artifact_operation_receipts","table_name":"artifact_operation_receipts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_receipt_put_attempt ON public.artifact_operation_receipts USING btree (put_attempt_id)","name":"uq_artifact_receipt_put_attempt","table_name":"artifact_operation_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_put_attempt_charges ON public.artifact_put_attempt_charges USING btree (attempt_id, charge_id)","name":"pk_artifact_put_attempt_charges","table_name":"artifact_put_attempt_charges"},{"definition":"CREATE INDEX ix_artifact_put_attempts_checker_run_id ON public.artifact_put_attempts USING btree (checker_run_id)","name":"ix_artifact_put_attempts_checker_run_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_guide_source_item_id ON public.artifact_put_attempts USING btree (guide_source_item_id)","name":"ix_artifact_put_attempts_guide_source_item_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_next_run_at ON public.artifact_put_attempts USING btree (next_run_at)","name":"ix_artifact_put_attempts_next_run_at","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_project_id ON public.artifact_put_attempts USING btree (project_id)","name":"ix_artifact_put_attempts_project_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_receipt_id ON public.artifact_put_attempts USING btree (receipt_id)","name":"ix_artifact_put_attempts_receipt_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_replica_id ON public.artifact_put_attempts USING btree (replica_id)","name":"ix_artifact_put_attempts_replica_id","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_status ON public.artifact_put_attempts USING btree (status)","name":"ix_artifact_put_attempts_status","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_attempts_task_id ON public.artifact_put_attempts USING btree (task_id)","name":"ix_artifact_put_attempts_task_id","table_name":"artifact_put_attempts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_put_attempts ON public.artifact_put_attempts USING btree (id)","name":"pk_artifact_put_attempts","table_name":"artifact_put_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_put_attempt_operation ON public.artifact_put_attempts USING btree (operation_identity)","name":"uq_artifact_put_attempt_operation","table_name":"artifact_put_attempts"},{"definition":"CREATE INDEX ix_artifact_put_observation_receipts_put_attempt_id ON public.artifact_put_observation_receipts USING btree (put_attempt_id)","name":"ix_artifact_put_observation_receipts_put_attempt_id","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_put_observation_receipts ON public.artifact_put_observation_receipts USING btree (id)","name":"pk_artifact_put_observation_receipts","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_put_observation_fence ON public.artifact_put_observation_receipts USING btree (put_attempt_id, execution_generation)","name":"uq_artifact_put_observation_fence","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_parent_recovery_attempt_id ON public.artifact_recovery_attempts USING btree (parent_recovery_attempt_id)","name":"ix_artifact_recovery_attempts_parent_recovery_attempt_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_project_id ON public.artifact_recovery_attempts USING btree (project_id)","name":"ix_artifact_recovery_attempts_project_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_requester_actor_profile_id ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id)","name":"ix_artifact_recovery_attempts_requester_actor_profile_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_submission_id ON public.artifact_recovery_attempts USING btree (submission_id)","name":"ix_artifact_recovery_attempts_submission_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_recovery_attempts_task_id ON public.artifact_recovery_attempts USING btree (task_id)","name":"ix_artifact_recovery_attempts_task_id","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_recovery_attempts ON public.artifact_recovery_attempts USING btree (id)","name":"pk_artifact_recovery_attempts","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_recovery_idempotency ON public.artifact_recovery_attempts USING btree (requester_actor_profile_id, source_verification_job_id, recovery_class, client_idempotency_key)","name":"uq_artifact_recovery_idempotency","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_recovery_retry_job ON public.artifact_recovery_attempts USING btree (retry_verification_job_id)","name":"uq_artifact_recovery_retry_job","table_name":"artifact_recovery_attempts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_recovery_source_job ON public.artifact_recovery_attempts USING btree (source_verification_job_id)","name":"uq_artifact_recovery_source_job","table_name":"artifact_recovery_attempts"},{"definition":"CREATE INDEX ix_artifact_replicas_content_id ON public.artifact_replicas USING btree (content_id)","name":"ix_artifact_replicas_content_id","table_name":"artifact_replicas"},{"definition":"CREATE INDEX ix_artifact_replicas_storage_namespace_id ON public.artifact_replicas USING btree (storage_namespace_id)","name":"ix_artifact_replicas_storage_namespace_id","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX pk_artifact_replicas ON public.artifact_replicas USING btree (id)","name":"pk_artifact_replicas","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX uq_artifact_replica_provider_object ON public.artifact_replicas USING btree (storage_namespace_id, provider_object_ref)","name":"uq_artifact_replica_provider_object","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX uq_artifact_replicas_id_content ON public.artifact_replicas USING btree (id, content_id)","name":"uq_artifact_replicas_id_content","table_name":"artifact_replicas"},{"definition":"CREATE UNIQUE INDEX pk_artifact_storage_namespaces ON public.artifact_storage_namespaces USING btree (id)","name":"pk_artifact_storage_namespaces","table_name":"artifact_storage_namespaces"},{"definition":"CREATE UNIQUE INDEX uq_artifact_storage_namespace_fingerprint ON public.artifact_storage_namespaces USING btree (namespace_fingerprint)","name":"uq_artifact_storage_namespace_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"CREATE UNIQUE INDEX uq_artifact_storage_namespace_id_fingerprint ON public.artifact_storage_namespaces USING btree (id, namespace_fingerprint)","name":"uq_artifact_storage_namespace_id_fingerprint","table_name":"artifact_storage_namespaces"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_next_run_at ON public.artifact_verification_jobs USING btree (next_run_at)","name":"ix_artifact_verification_jobs_next_run_at","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_originating_put_attempt_id ON public.artifact_verification_jobs USING btree (originating_put_attempt_id)","name":"ix_artifact_verification_jobs_originating_put_attempt_id","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_parent_verification_job_id ON public.artifact_verification_jobs USING btree (parent_verification_job_id)","name":"ix_artifact_verification_jobs_parent_verification_job_id","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_replica_id ON public.artifact_verification_jobs USING btree (replica_id)","name":"ix_artifact_verification_jobs_replica_id","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_jobs_status ON public.artifact_verification_jobs USING btree (status)","name":"ix_artifact_verification_jobs_status","table_name":"artifact_verification_jobs"},{"definition":"CREATE UNIQUE INDEX pk_artifact_verification_jobs ON public.artifact_verification_jobs USING btree (id)","name":"pk_artifact_verification_jobs","table_name":"artifact_verification_jobs"},{"definition":"CREATE UNIQUE INDEX uq_artifact_verification_initial_origin ON public.artifact_verification_jobs USING btree (originating_put_attempt_id) WHERE (parent_verification_job_id IS NULL)","name":"uq_artifact_verification_initial_origin","table_name":"artifact_verification_jobs"},{"definition":"CREATE UNIQUE INDEX uq_artifact_verification_parent ON public.artifact_verification_jobs USING btree (parent_verification_job_id)","name":"uq_artifact_verification_parent","table_name":"artifact_verification_jobs"},{"definition":"CREATE INDEX ix_artifact_verification_receipts_verification_job_id ON public.artifact_verification_receipts USING btree (verification_job_id)","name":"ix_artifact_verification_receipts_verification_job_id","table_name":"artifact_verification_receipts"},{"definition":"CREATE UNIQUE INDEX pk_artifact_verification_receipts ON public.artifact_verification_receipts USING btree (id)","name":"pk_artifact_verification_receipts","table_name":"artifact_verification_receipts"},{"definition":"CREATE UNIQUE INDEX uq_artifact_verification_fence ON public.artifact_verification_receipts USING btree (verification_job_id, execution_generation)","name":"uq_artifact_verification_fence","table_name":"artifact_verification_receipts"},{"definition":"CREATE INDEX ix_audit_events_actor_id ON public.audit_events USING btree (actor_id)","name":"ix_audit_events_actor_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_actor_ref ON public.audit_events USING btree (actor_ref_kind, actor_id)","name":"ix_audit_events_actor_ref","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_correlation_id ON public.audit_events USING btree (correlation_id)","name":"ix_audit_events_correlation_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_entity_id ON public.audit_events USING btree (entity_id)","name":"ix_audit_events_entity_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_entity_type ON public.audit_events USING btree (entity_type)","name":"ix_audit_events_entity_type","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_event_type ON public.audit_events USING btree (event_type)","name":"ix_audit_events_event_type","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_occurred_at ON public.audit_events USING btree (occurred_at)","name":"ix_audit_events_occurred_at","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_project_id ON public.audit_events USING btree (project_id)","name":"ix_audit_events_project_id","table_name":"audit_events"},{"definition":"CREATE INDEX ix_audit_events_request_id ON public.audit_events USING btree (request_id)","name":"ix_audit_events_request_id","table_name":"audit_events"},{"definition":"CREATE UNIQUE INDEX pk_audit_events ON public.audit_events USING btree (id)","name":"pk_audit_events","table_name":"audit_events"},{"definition":"CREATE UNIQUE INDEX pk_authority_control ON public.authority_control USING btree (id)","name":"pk_authority_control","table_name":"authority_control"},{"definition":"CREATE UNIQUE INDEX pk_authority_idempotency_records ON public.authority_idempotency_records USING btree (id)","name":"pk_authority_idempotency_records","table_name":"authority_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_authority_idempotency_records_actor_reference ON public.authority_idempotency_records USING btree (id, actor_ref_kind, actor_ref)","name":"uq_authority_idempotency_records_actor_reference","table_name":"authority_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_authority_idempotency_records_replay_namespace ON public.authority_idempotency_records USING btree (actor_ref_kind, actor_ref, operation, idempotency_key)","name":"uq_authority_idempotency_records_replay_namespace","table_name":"authority_idempotency_records"},{"definition":"CREATE INDEX ix_checker_policies_effective_policy_hash ON public.checker_policies USING btree (effective_policy_hash)","name":"ix_checker_policies_effective_policy_hash","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_effective_policy_id ON public.checker_policies USING btree (effective_policy_id)","name":"ix_checker_policies_effective_policy_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_guide_id ON public.checker_policies USING btree (guide_id)","name":"ix_checker_policies_guide_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_pre_submit_checker_bundle_hash ON public.checker_policies USING btree (pre_submit_checker_bundle_hash)","name":"ix_checker_policies_pre_submit_checker_bundle_hash","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_pre_submit_checker_policy_id ON public.checker_policies USING btree (pre_submit_checker_policy_id)","name":"ix_checker_policies_pre_submit_checker_policy_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_project_id ON public.checker_policies USING btree (project_id)","name":"ix_checker_policies_project_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_source_snapshot_id ON public.checker_policies USING btree (source_snapshot_id)","name":"ix_checker_policies_source_snapshot_id","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_policies_supersedes_policy_id ON public.checker_policies USING btree (supersedes_policy_id)","name":"ix_checker_policies_supersedes_policy_id","table_name":"checker_policies"},{"definition":"CREATE UNIQUE INDEX pk_checker_policies ON public.checker_policies USING btree (id)","name":"pk_checker_policies","table_name":"checker_policies"},{"definition":"CREATE UNIQUE INDEX uq_checker_policies_current_project_version ON public.checker_policies USING btree (project_id, guide_version) WHERE ((lifecycle_status)::text = ANY (ARRAY['compiled', 'approved']))","name":"uq_checker_policies_current_project_version","table_name":"checker_policies"},{"definition":"CREATE UNIQUE INDEX uq_checker_policies_id_version_hash ON public.checker_policies USING btree (id, guide_version, policy_hash)","name":"uq_checker_policies_id_version_hash","table_name":"checker_policies"},{"definition":"CREATE INDEX ix_checker_results_checker_name ON public.checker_results USING btree (checker_name)","name":"ix_checker_results_checker_name","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_checker_run_id ON public.checker_results USING btree (checker_run_id)","name":"ix_checker_results_checker_run_id","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_submission_id ON public.checker_results USING btree (submission_id)","name":"ix_checker_results_submission_id","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_task_id ON public.checker_results USING btree (task_id)","name":"ix_checker_results_task_id","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_results_worker_visible ON public.checker_results USING btree (worker_visible)","name":"ix_checker_results_worker_visible","table_name":"checker_results"},{"definition":"CREATE UNIQUE INDEX pk_checker_results ON public.checker_results USING btree (id)","name":"pk_checker_results","table_name":"checker_results"},{"definition":"CREATE INDEX ix_checker_runs_audit_event_id ON public.checker_runs USING btree (audit_event_id)","name":"ix_checker_runs_audit_event_id","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_locked_post_submit_policy_hash ON public.checker_runs USING btree (locked_post_submit_checker_policy_hash)","name":"ix_checker_runs_locked_post_submit_policy_hash","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_routing_recommendation ON public.checker_runs USING btree (routing_recommendation)","name":"ix_checker_runs_routing_recommendation","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_status ON public.checker_runs USING btree (status)","name":"ix_checker_runs_status","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_submission_id ON public.checker_runs USING btree (submission_id)","name":"ix_checker_runs_submission_id","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_supersedes_checker_run_id ON public.checker_runs USING btree (supersedes_checker_run_id)","name":"ix_checker_runs_supersedes_checker_run_id","table_name":"checker_runs"},{"definition":"CREATE INDEX ix_checker_runs_task_id ON public.checker_runs USING btree (task_id)","name":"ix_checker_runs_task_id","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX pk_checker_runs ON public.checker_runs USING btree (id)","name":"pk_checker_runs","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX uq_checker_runs_current_per_submission ON public.checker_runs USING btree (submission_id) WHERE (is_current_for_submission = true)","name":"uq_checker_runs_current_per_submission","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX uq_checker_runs_submission_attempt ON public.checker_runs USING btree (submission_id, attempt_number)","name":"uq_checker_runs_submission_attempt","table_name":"checker_runs"},{"definition":"CREATE UNIQUE INDEX pk_contribution_award_definitions ON public.contribution_award_definitions USING btree (id)","name":"pk_contribution_award_definitions","table_name":"contribution_award_definitions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_award_definition_instrument ON public.contribution_award_definitions USING btree (contribution_rule_id, instrument_type)","name":"uq_contribution_award_definition_instrument","table_name":"contribution_award_definitions"},{"definition":"CREATE UNIQUE INDEX pk_contribution_policies ON public.contribution_policies USING btree (id)","name":"pk_contribution_policies","table_name":"contribution_policies"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_active_project ON public.contribution_policies USING btree (project_id) WHERE ((status)::text = 'active'::text)","name":"uq_contribution_policy_active_project","table_name":"contribution_policies"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_ownership ON public.contribution_policies USING btree (id, project_id)","name":"uq_contribution_policy_ownership","table_name":"contribution_policies"},{"definition":"CREATE UNIQUE INDEX pk_contribution_policy_versions ON public.contribution_policy_versions USING btree (id)","name":"pk_contribution_policy_versions","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_version_number ON public.contribution_policy_versions USING btree (contribution_policy_id, version_number)","name":"uq_contribution_policy_version_number","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_version_ownership ON public.contribution_policy_versions USING btree (id, contribution_policy_id, project_id)","name":"uq_contribution_policy_version_ownership","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX uq_contribution_policy_version_project ON public.contribution_policy_versions USING btree (id, project_id)","name":"uq_contribution_policy_version_project","table_name":"contribution_policy_versions"},{"definition":"CREATE UNIQUE INDEX pk_contribution_rules ON public.contribution_rules USING btree (id)","name":"pk_contribution_rules","table_name":"contribution_rules"},{"definition":"CREATE UNIQUE INDEX uq_contribution_rule_ownership ON public.contribution_rules USING btree (id, contribution_policy_version_id, project_id, contribution_type)","name":"uq_contribution_rule_ownership","table_name":"contribution_rules"},{"definition":"CREATE UNIQUE INDEX uq_contribution_rule_type ON public.contribution_rules USING btree (contribution_policy_version_id, contribution_type)","name":"uq_contribution_rule_type","table_name":"contribution_rules"},{"definition":"CREATE INDEX ix_effective_psap_effective_hash ON public.effective_project_submission_artifact_policies USING btree (effective_policy_hash)","name":"ix_effective_psap_effective_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_guide ON public.effective_project_submission_artifact_policies USING btree (guide_id)","name":"ix_effective_psap_guide","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_lifecycle ON public.effective_project_submission_artifact_policies USING btree (lifecycle_status)","name":"ix_effective_psap_lifecycle","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_project ON public.effective_project_submission_artifact_policies USING btree (project_id)","name":"ix_effective_psap_project","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_source_snapshot ON public.effective_project_submission_artifact_policies USING btree (source_snapshot_id)","name":"ix_effective_psap_source_snapshot","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_effective_psap_submission_policy ON public.effective_project_submission_artifact_policies USING btree (submission_artifact_policy_id)","name":"ix_effective_psap_submission_policy","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX pk_effective_project_submission_artifact_policies ON public.effective_project_submission_artifact_policies USING btree (id)","name":"pk_effective_project_submission_artifact_policies","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX uq_effective_project_submission_artifact_policies_id_hash ON public.effective_project_submission_artifact_policies USING btree (id, effective_policy_hash)","name":"uq_effective_project_submission_artifact_policies_id_hash","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE INDEX ix_evidence_items_submission_id ON public.evidence_items USING btree (submission_id)","name":"ix_evidence_items_submission_id","table_name":"evidence_items"},{"definition":"CREATE INDEX ix_evidence_items_type ON public.evidence_items USING btree (type)","name":"ix_evidence_items_type","table_name":"evidence_items"},{"definition":"CREATE UNIQUE INDEX pk_evidence_items ON public.evidence_items USING btree (id)","name":"pk_evidence_items","table_name":"evidence_items"},{"definition":"CREATE UNIQUE INDEX pk_guide_mutation_idempotency_records ON public.guide_mutation_idempotency_records USING btree (id)","name":"pk_guide_mutation_idempotency_records","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_guide_mutation_operation_identity ON public.guide_mutation_idempotency_records USING btree (operation_id)","name":"uq_guide_mutation_operation_identity","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_guide_mutation_replay_namespace ON public.guide_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)","name":"uq_guide_mutation_replay_namespace","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_content_id ON public.guide_source_artifact_bindings USING btree (content_id)","name":"ix_guide_source_artifact_bindings_content_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_guide_id ON public.guide_source_artifact_bindings USING btree (guide_id)","name":"ix_guide_source_artifact_bindings_guide_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_project_id ON public.guide_source_artifact_bindings USING btree (project_id)","name":"ix_guide_source_artifact_bindings_project_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_project_setup_run_id ON public.guide_source_artifact_bindings USING btree (project_setup_run_id)","name":"ix_guide_source_artifact_bindings_project_setup_run_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_source_item_id ON public.guide_source_artifact_bindings USING btree (source_item_id)","name":"ix_guide_source_artifact_bindings_source_item_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_source_snapshot_id ON public.guide_source_artifact_bindings USING btree (source_snapshot_id)","name":"ix_guide_source_artifact_bindings_source_snapshot_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_supersedes_binding_id ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)","name":"ix_guide_source_artifact_bindings_supersedes_binding_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_bindings_verified_replica_id ON public.guide_source_artifact_bindings USING btree (verified_replica_id)","name":"ix_guide_source_artifact_bindings_verified_replica_id","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_artifact_bindings ON public.guide_source_artifact_bindings USING btree (id)","name":"pk_guide_source_artifact_bindings","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_exact_read ON public.guide_source_artifact_bindings USING btree (id, content_id, verified_replica_id, setup_generation)","name":"uq_guide_bindings_exact_read","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_extraction_attempt_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, setup_generation)","name":"uq_guide_bindings_extraction_attempt_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_extraction_lineage ON public.guide_source_artifact_bindings USING btree (id, content_id, source_item_id, project_setup_run_id, setup_generation)","name":"uq_guide_bindings_extraction_lineage","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_item_generation ON public.guide_source_artifact_bindings USING btree (source_item_id, setup_generation)","name":"uq_guide_bindings_item_generation","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE UNIQUE INDEX uq_guide_bindings_supersedes ON public.guide_source_artifact_bindings USING btree (supersedes_binding_id)","name":"uq_guide_bindings_supersedes","table_name":"guide_source_artifact_bindings"},{"definition":"CREATE INDEX ix_guide_source_artifact_incidents_binding_id ON public.guide_source_artifact_incidents USING btree (binding_id)","name":"ix_guide_source_artifact_incidents_binding_id","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE INDEX ix_guide_source_artifact_incidents_content_id ON public.guide_source_artifact_incidents USING btree (content_id)","name":"ix_guide_source_artifact_incidents_content_id","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE INDEX ix_guide_source_artifact_incidents_verified_replica_id ON public.guide_source_artifact_incidents USING btree (verified_replica_id)","name":"ix_guide_source_artifact_incidents_verified_replica_id","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_artifact_incidents ON public.guide_source_artifact_incidents USING btree (id)","name":"pk_guide_source_artifact_incidents","table_name":"guide_source_artifact_incidents"},{"definition":"CREATE INDEX ix_guide_source_artifact_ingests_actor_profile_id ON public.guide_source_artifact_ingests USING btree (actor_profile_id)","name":"ix_guide_source_artifact_ingests_actor_profile_id","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE UNIQUE INDEX ix_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)","name":"ix_guide_source_artifact_ingests_source_item_id","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_artifact_ingests ON public.guide_source_artifact_ingests USING btree (id)","name":"pk_guide_source_artifact_ingests","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_artifact_ingests_source_item_id ON public.guide_source_artifact_ingests USING btree (source_item_id)","name":"uq_guide_source_artifact_ingests_source_item_id","table_name":"guide_source_artifact_ingests"},{"definition":"CREATE INDEX ix_guide_source_extracted_contents_content_id ON public.guide_source_extracted_contents USING btree (content_id)","name":"ix_guide_source_extracted_contents_content_id","table_name":"guide_source_extracted_contents"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extracted_contents ON public.guide_source_extracted_contents USING btree (id)","name":"pk_guide_source_extracted_contents","table_name":"guide_source_extracted_contents"},{"definition":"CREATE UNIQUE INDEX uq_guide_extracted_contents_exact_usage ON public.guide_source_extracted_contents USING btree (id, content_id)","name":"uq_guide_extracted_contents_exact_usage","table_name":"guide_source_extracted_contents"},{"definition":"CREATE UNIQUE INDEX uq_guide_extracted_contents_identity ON public.guide_source_extracted_contents USING btree (content_id, detected_format, extractor_name, extractor_version, policy_version)","name":"uq_guide_extracted_contents_identity","table_name":"guide_source_extracted_contents"},{"definition":"CREATE INDEX ix_guide_source_extraction_attempts_binding_id ON public.guide_source_extraction_attempts USING btree (binding_id)","name":"ix_guide_source_extraction_attempts_binding_id","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE INDEX ix_guide_source_extraction_attempts_content_id ON public.guide_source_extraction_attempts USING btree (content_id)","name":"ix_guide_source_extraction_attempts_content_id","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extraction_attempts ON public.guide_source_extraction_attempts USING btree (id)","name":"pk_guide_source_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_attempts ON public.guide_source_extraction_attempts USING btree (binding_id, policy_version, attempt_number)","name":"uq_guide_extraction_attempts","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_attempts_exact_usage ON public.guide_source_extraction_attempts USING btree (id, binding_id, content_id, setup_generation, status)","name":"uq_guide_extraction_attempts_exact_usage","table_name":"guide_source_extraction_attempts"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extraction_retry_budgets ON public.guide_source_extraction_retry_budgets USING btree (binding_id)","name":"pk_guide_source_extraction_retry_budgets","table_name":"guide_source_extraction_retry_budgets"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_binding_id ON public.guide_source_extraction_usages USING btree (binding_id)","name":"ix_guide_source_extraction_usages_binding_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_content_id ON public.guide_source_extraction_usages USING btree (content_id)","name":"ix_guide_source_extraction_usages_content_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_extracted_content_id ON public.guide_source_extraction_usages USING btree (extracted_content_id)","name":"ix_guide_source_extraction_usages_extracted_content_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_project_setup_run_id ON public.guide_source_extraction_usages USING btree (project_setup_run_id)","name":"ix_guide_source_extraction_usages_project_setup_run_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_extraction_usages_source_item_id ON public.guide_source_extraction_usages USING btree (source_item_id)","name":"ix_guide_source_extraction_usages_source_item_id","table_name":"guide_source_extraction_usages"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_extraction_usages ON public.guide_source_extraction_usages USING btree (id)","name":"pk_guide_source_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_usages ON public.guide_source_extraction_usages USING btree (binding_id, extracted_content_id)","name":"uq_guide_extraction_usages","table_name":"guide_source_extraction_usages"},{"definition":"CREATE UNIQUE INDEX uq_guide_extraction_usages_exact_provenance ON public.guide_source_extraction_usages USING btree (id, source_item_id, binding_id, content_id, extraction_attempt_id, extracted_content_id, project_setup_run_id, setup_generation)","name":"uq_guide_extraction_usages_exact_provenance","table_name":"guide_source_extraction_usages"},{"definition":"CREATE INDEX ix_guide_source_format_classifications_binding_id ON public.guide_source_format_classifications USING btree (binding_id)","name":"ix_guide_source_format_classifications_binding_id","table_name":"guide_source_format_classifications"},{"definition":"CREATE INDEX ix_guide_source_format_classifications_content_id ON public.guide_source_format_classifications USING btree (content_id)","name":"ix_guide_source_format_classifications_content_id","table_name":"guide_source_format_classifications"},{"definition":"CREATE INDEX ix_guide_source_format_classifications_verified_replica_id ON public.guide_source_format_classifications USING btree (verified_replica_id)","name":"ix_guide_source_format_classifications_verified_replica_id","table_name":"guide_source_format_classifications"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_format_classifications ON public.guide_source_format_classifications USING btree (id)","name":"pk_guide_source_format_classifications","table_name":"guide_source_format_classifications"},{"definition":"CREATE UNIQUE INDEX uq_guide_classifications_binding ON public.guide_source_format_classifications USING btree (binding_id)","name":"uq_guide_classifications_binding","table_name":"guide_source_format_classifications"},{"definition":"CREATE UNIQUE INDEX uq_guide_classifications_extraction_lineage ON public.guide_source_format_classifications USING btree (id, binding_id, content_id, setup_generation)","name":"uq_guide_classifications_extraction_lineage","table_name":"guide_source_format_classifications"},{"definition":"CREATE INDEX ix_guide_source_snapshot_items_source_snapshot_id ON public.guide_source_snapshot_items USING btree (source_snapshot_id)","name":"ix_guide_source_snapshot_items_source_snapshot_id","table_name":"guide_source_snapshot_items"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_snapshot_items ON public.guide_source_snapshot_items USING btree (id)","name":"pk_guide_source_snapshot_items","table_name":"guide_source_snapshot_items"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshot_items_exact_lineage ON public.guide_source_snapshot_items USING btree (id, source_snapshot_id)","name":"uq_guide_source_snapshot_items_exact_lineage","table_name":"guide_source_snapshot_items"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshot_items_snapshot_order ON public.guide_source_snapshot_items USING btree (source_snapshot_id, item_order)","name":"uq_guide_source_snapshot_items_snapshot_order","table_name":"guide_source_snapshot_items"},{"definition":"CREATE INDEX ix_guide_source_snapshots_bundle_hash ON public.guide_source_snapshots USING btree (bundle_hash)","name":"ix_guide_source_snapshots_bundle_hash","table_name":"guide_source_snapshots"},{"definition":"CREATE INDEX ix_guide_source_snapshots_guide_id ON public.guide_source_snapshots USING btree (guide_id)","name":"ix_guide_source_snapshots_guide_id","table_name":"guide_source_snapshots"},{"definition":"CREATE INDEX ix_guide_source_snapshots_project_id ON public.guide_source_snapshots USING btree (project_id)","name":"ix_guide_source_snapshots_project_id","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX pk_guide_source_snapshots ON public.guide_source_snapshots USING btree (id)","name":"pk_guide_source_snapshots","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshots_exact_lineage ON public.guide_source_snapshots USING btree (id, project_id, guide_id)","name":"uq_guide_source_snapshots_exact_lineage","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshots_id_hash ON public.guide_source_snapshots USING btree (id, bundle_hash)","name":"uq_guide_source_snapshots_id_hash","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX uq_guide_source_snapshots_project_version_hash ON public.guide_source_snapshots USING btree (project_id, guide_version, bundle_hash)","name":"uq_guide_source_snapshots_project_version_hash","table_name":"guide_source_snapshots"},{"definition":"CREATE UNIQUE INDEX pk_guide_sufficiency_mutation_idempotency_records ON public.guide_sufficiency_mutation_idempotency_records USING btree (id)","name":"pk_guide_sufficiency_mutation_idempotency_records","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_mutation_operation_identity ON public.guide_sufficiency_mutation_idempotency_records USING btree (operation_id)","name":"uq_sufficiency_mutation_operation_identity","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_mutation_replay_namespace ON public.guide_sufficiency_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key)","name":"uq_sufficiency_mutation_replay_namespace","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_sufficiency_report_source_usage_report_id ON public.guide_sufficiency_report_source_usages USING btree (report_id)","name":"ix_sufficiency_report_source_usage_report_id","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE UNIQUE INDEX pk_guide_sufficiency_report_source_usages ON public.guide_sufficiency_report_source_usages USING btree (id)","name":"pk_guide_sufficiency_report_source_usages","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_report_extraction_usage ON public.guide_sufficiency_report_source_usages USING btree (report_id, extraction_usage_id)","name":"uq_sufficiency_report_extraction_usage","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE UNIQUE INDEX uq_sufficiency_report_item_order ON public.guide_sufficiency_report_source_usages USING btree (report_id, item_order)","name":"uq_sufficiency_report_item_order","table_name":"guide_sufficiency_report_source_usages"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_guide_id ON public.guide_sufficiency_reports USING btree (guide_id)","name":"ix_guide_sufficiency_reports_guide_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_project_id ON public.guide_sufficiency_reports USING btree (project_id)","name":"ix_guide_sufficiency_reports_project_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_project_setup_run_id ON public.guide_sufficiency_reports USING btree (project_setup_run_id)","name":"ix_guide_sufficiency_reports_project_setup_run_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_source_snapshot_id ON public.guide_sufficiency_reports USING btree (source_snapshot_id)","name":"ix_guide_sufficiency_reports_source_snapshot_id","table_name":"guide_sufficiency_reports"},{"definition":"CREATE INDEX ix_guide_sufficiency_reports_status ON public.guide_sufficiency_reports USING btree (status)","name":"ix_guide_sufficiency_reports_status","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX pk_guide_sufficiency_reports ON public.guide_sufficiency_reports USING btree (id)","name":"pk_guide_sufficiency_reports","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX uq_guide_sufficiency_reports_diagnostic_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NULL)","name":"uq_guide_sufficiency_reports_diagnostic_snapshot","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX uq_guide_sufficiency_reports_verified_snapshot ON public.guide_sufficiency_reports USING btree (source_snapshot_id) WHERE (project_setup_run_id IS NOT NULL)","name":"uq_guide_sufficiency_reports_verified_snapshot","table_name":"guide_sufficiency_reports"},{"definition":"CREATE UNIQUE INDEX pk_iso_4217_currency_codes ON public.iso_4217_currency_codes USING btree (code)","name":"pk_iso_4217_currency_codes","table_name":"iso_4217_currency_codes"},{"definition":"CREATE UNIQUE INDEX pk_legacy_actor_identities ON public.legacy_actor_identities USING btree (actor_id)","name":"pk_legacy_actor_identities","table_name":"legacy_actor_identities"},{"definition":"CREATE UNIQUE INDEX uq_legacy_actor_identities_external_identity ON public.legacy_actor_identities USING btree (external_issuer, external_subject)","name":"uq_legacy_actor_identities_external_identity","table_name":"legacy_actor_identities"},{"definition":"CREATE INDEX ix_legacy_workflow_eligibility_actor_id ON public.legacy_workflow_eligibility USING btree (actor_id)","name":"ix_legacy_workflow_eligibility_actor_id","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE INDEX ix_legacy_workflow_eligibility_profile_type ON public.legacy_workflow_eligibility USING btree (profile_type)","name":"ix_legacy_workflow_eligibility_profile_type","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE INDEX ix_legacy_workflow_eligibility_status ON public.legacy_workflow_eligibility USING btree (status)","name":"ix_legacy_workflow_eligibility_status","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE UNIQUE INDEX pk_legacy_workflow_eligibility ON public.legacy_workflow_eligibility USING btree (id)","name":"pk_legacy_workflow_eligibility","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE UNIQUE INDEX uq_legacy_workflow_eligibility_actor_type_scope ON public.legacy_workflow_eligibility USING btree (actor_id, profile_type, scope_type, scope_id)","name":"uq_legacy_workflow_eligibility_actor_type_scope","table_name":"legacy_workflow_eligibility"},{"definition":"CREATE INDEX ix_outbox_events_aggregate ON public.outbox_events USING btree (aggregate_type, aggregate_id, occurred_at, event_id)","name":"ix_outbox_events_aggregate","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_eligible ON public.outbox_events USING btree (event_type, delivery_state, next_attempt_at, occurred_at, event_id) WHERE ((delivery_state)::text = ANY (ARRAY['pending', 'retryable']))","name":"ix_outbox_events_eligible","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_expired_claims ON public.outbox_events USING btree (claim_expires_at, event_id) WHERE ((delivery_state)::text = 'claimed'::text)","name":"ix_outbox_events_expired_claims","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_project_drain ON public.outbox_events USING btree (project_id, delivery_state, occurred_at, event_id)","name":"ix_outbox_events_project_drain","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_outbox_events_retention ON public.outbox_events USING btree (finalized_at, event_id) WHERE (((delivery_state)::text = ANY (ARRAY['acknowledged', 'dead_letter', 'cancelled'])) AND (archived_at IS NULL))","name":"ix_outbox_events_retention","table_name":"outbox_events"},{"definition":"CREATE UNIQUE INDEX pk_outbox_events ON public.outbox_events USING btree (event_id)","name":"pk_outbox_events","table_name":"outbox_events"},{"definition":"CREATE UNIQUE INDEX uq_outbox_events_idempotency_key ON public.outbox_events USING btree (idempotency_key)","name":"uq_outbox_events_idempotency_key","table_name":"outbox_events"},{"definition":"CREATE INDEX ix_payment_policies_project_id ON public.payment_policies USING btree (project_id)","name":"ix_payment_policies_project_id","table_name":"payment_policies"},{"definition":"CREATE UNIQUE INDEX pk_payment_policies ON public.payment_policies USING btree (id)","name":"pk_payment_policies","table_name":"payment_policies"},{"definition":"CREATE UNIQUE INDEX uq_payment_policies_project_version ON public.payment_policies USING btree (project_id, guide_version)","name":"uq_payment_policies_project_version","table_name":"payment_policies"},{"definition":"CREATE INDEX ix_policy_mutation_custody_lookup ON public.policy_mutation_idempotency_records USING btree (policy_id, action_id, policy_generation, status)","name":"ix_policy_mutation_custody_lookup","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX pk_policy_mutation_idempotency_records ON public.policy_mutation_idempotency_records USING btree (id)","name":"pk_policy_mutation_idempotency_records","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_policy_mutation_operation_identity ON public.policy_mutation_idempotency_records USING btree (operation_id)","name":"uq_policy_mutation_operation_identity","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_policy_mutation_replay_namespace ON public.policy_mutation_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)","name":"uq_policy_mutation_replay_namespace","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_pre_submit_checker_compiled_hash ON public.pre_submit_checker_policies USING btree (compiled_bundle_hash)","name":"ix_pre_submit_checker_compiled_hash","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_effective ON public.pre_submit_checker_policies USING btree (effective_policy_id)","name":"ix_pre_submit_checker_effective","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_effective_hash ON public.pre_submit_checker_policies USING btree (effective_policy_hash)","name":"ix_pre_submit_checker_effective_hash","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_guide ON public.pre_submit_checker_policies USING btree (guide_id)","name":"ix_pre_submit_checker_guide","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_lifecycle ON public.pre_submit_checker_policies USING btree (lifecycle_status)","name":"ix_pre_submit_checker_lifecycle","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_project ON public.pre_submit_checker_policies USING btree (project_id)","name":"ix_pre_submit_checker_project","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_checker_source_snapshot ON public.pre_submit_checker_policies USING btree (source_snapshot_id)","name":"ix_pre_submit_checker_source_snapshot","table_name":"pre_submit_checker_policies"},{"definition":"CREATE UNIQUE INDEX pk_pre_submit_checker_policies ON public.pre_submit_checker_policies USING btree (id)","name":"pk_pre_submit_checker_policies","table_name":"pre_submit_checker_policies"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_checker_policies_id_compiled_bundle_hash ON public.pre_submit_checker_policies USING btree (id, compiled_bundle_hash)","name":"uq_pre_submit_checker_policies_id_compiled_bundle_hash","table_name":"pre_submit_checker_policies"},{"definition":"CREATE INDEX ix_pre_submit_evidence_results_evidence_set_id ON public.pre_submit_evidence_results USING btree (evidence_set_id)","name":"ix_pre_submit_evidence_results_evidence_set_id","table_name":"pre_submit_evidence_results"},{"definition":"CREATE UNIQUE INDEX pk_pre_submit_evidence_results ON public.pre_submit_evidence_results USING btree (id)","name":"pk_pre_submit_evidence_results","table_name":"pre_submit_evidence_results"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_result_definition ON public.pre_submit_evidence_results USING btree (evidence_set_id, definition_id)","name":"uq_pre_submit_result_definition","table_name":"pre_submit_evidence_results"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_result_order ON public.pre_submit_evidence_results USING btree (evidence_set_id, result_order)","name":"uq_pre_submit_result_order","table_name":"pre_submit_evidence_results"},{"definition":"CREATE INDEX ix_pre_submit_evidence_sets_actor_profile_id ON public.pre_submit_evidence_sets USING btree (actor_profile_id)","name":"ix_pre_submit_evidence_sets_actor_profile_id","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE INDEX ix_pre_submit_evidence_sets_project_id ON public.pre_submit_evidence_sets USING btree (project_id)","name":"ix_pre_submit_evidence_sets_project_id","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE INDEX ix_pre_submit_evidence_sets_task_id ON public.pre_submit_evidence_sets USING btree (task_id)","name":"ix_pre_submit_evidence_sets_task_id","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE UNIQUE INDEX pk_pre_submit_evidence_sets ON public.pre_submit_evidence_sets USING btree (id)","name":"pk_pre_submit_evidence_sets","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE UNIQUE INDEX uq_pre_submit_evidence_operation ON public.pre_submit_evidence_sets USING btree (operation_identity)","name":"uq_pre_submit_evidence_operation","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE INDEX ix_compensation_binding_adapter_actor ON public.project_compensation_adapter_bindings USING btree (adapter_actor_id, status, id)","name":"ix_compensation_binding_adapter_actor","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX pk_project_compensation_adapter_bindings ON public.project_compensation_adapter_bindings USING btree (id)","name":"pk_project_compensation_adapter_bindings","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX uq_compensation_binding_active_project_instrument ON public.project_compensation_adapter_bindings USING btree (project_id, instrument_type) WHERE ((status)::text = 'active'::text)","name":"uq_compensation_binding_active_project_instrument","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX uq_compensation_binding_ownership ON public.project_compensation_adapter_bindings USING btree (id, project_id, instrument_type)","name":"uq_compensation_binding_ownership","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE UNIQUE INDEX pk_project_compensation_units ON public.project_compensation_units USING btree (project_id, instrument_type, unit_code)","name":"pk_project_compensation_units","table_name":"project_compensation_units"},{"definition":"CREATE UNIQUE INDEX pk_project_create_idempotency_records ON public.project_create_idempotency_records USING btree (id)","name":"pk_project_create_idempotency_records","table_name":"project_create_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_project_create_operation_identity ON public.project_create_idempotency_records USING btree (operation_id)","name":"uq_project_create_operation_identity","table_name":"project_create_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_project_create_project_identity ON public.project_create_idempotency_records USING btree (project_id)","name":"uq_project_create_project_identity","table_name":"project_create_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_project_create_replay_namespace ON public.project_create_idempotency_records USING btree (actor_profile_id, action_id, idempotency_key)","name":"uq_project_create_replay_namespace","table_name":"project_create_idempotency_records"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_guide_id ON public.project_guide_compilation_attempts USING btree (guide_id)","name":"ix_project_guide_compilation_attempts_guide_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_project_id ON public.project_guide_compilation_attempts USING btree (project_id)","name":"ix_project_guide_compilation_attempts_project_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_setup_run_id ON public.project_guide_compilation_attempts USING btree (setup_run_id)","name":"ix_project_guide_compilation_attempts_setup_run_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilation_attempts_source_snapshot_id ON public.project_guide_compilation_attempts USING btree (source_snapshot_id)","name":"ix_project_guide_compilation_attempts_source_snapshot_id","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE UNIQUE INDEX pk_project_guide_compilation_attempts ON public.project_guide_compilation_attempts USING btree (id)","name":"pk_project_guide_compilation_attempts","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE UNIQUE INDEX uq_compilation_attempt_provider_key ON public.project_guide_compilation_attempts USING btree (provider_idempotency_key)","name":"uq_compilation_attempt_provider_key","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE UNIQUE INDEX uq_compilation_attempt_setup_generation ON public.project_guide_compilation_attempts USING btree (setup_run_id, setup_generation)","name":"uq_compilation_attempt_setup_generation","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE INDEX ix_project_guide_compilations_guide_id ON public.project_guide_compilations USING btree (guide_id)","name":"ix_project_guide_compilations_guide_id","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guide_compilations_project_id ON public.project_guide_compilations USING btree (project_id)","name":"ix_project_guide_compilations_project_id","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guide_compilations_setup_run_id ON public.project_guide_compilations USING btree (setup_run_id)","name":"ix_project_guide_compilations_setup_run_id","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guide_compilations_source_snapshot_id ON public.project_guide_compilations USING btree (source_snapshot_id)","name":"ix_project_guide_compilations_source_snapshot_id","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX pk_project_guide_compilations ON public.project_guide_compilations USING btree (id)","name":"pk_project_guide_compilations","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_attempt ON public.project_guide_compilations USING btree (attempt_id)","name":"uq_project_guide_compilation_attempt","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_id_attempt ON public.project_guide_compilations USING btree (id, attempt_id)","name":"uq_project_guide_compilation_id_attempt","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_predecessor ON public.project_guide_compilations USING btree (supersedes_compilation_id)","name":"uq_project_guide_compilation_predecessor","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_root ON public.project_guide_compilations USING btree (project_id, guide_id) WHERE (supersedes_compilation_id IS NULL)","name":"uq_project_guide_compilation_root","table_name":"project_guide_compilations"},{"definition":"CREATE UNIQUE INDEX uq_project_guide_compilation_scope ON public.project_guide_compilations USING btree (id, project_id, guide_id)","name":"uq_project_guide_compilation_scope","table_name":"project_guide_compilations"},{"definition":"CREATE INDEX ix_project_guides_project_id ON public.project_guides USING btree (project_id)","name":"ix_project_guides_project_id","table_name":"project_guides"},{"definition":"CREATE INDEX ix_project_guides_status ON public.project_guides USING btree (status)","name":"ix_project_guides_status","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX pk_project_guides ON public.project_guides USING btree (id)","name":"pk_project_guides","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX uq_project_guides_id_project_version ON public.project_guides USING btree (id, project_id, version)","name":"uq_project_guides_id_project_version","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX uq_project_guides_one_active_per_project ON public.project_guides USING btree (project_id) WHERE ((status)::text = 'active'::text)","name":"uq_project_guides_one_active_per_project","table_name":"project_guides"},{"definition":"CREATE UNIQUE INDEX uq_project_guides_project_version ON public.project_guides USING btree (project_id, version)","name":"uq_project_guides_project_version","table_name":"project_guides"},{"definition":"CREATE INDEX ix_project_role_grants_actor_role_status ON public.project_role_grants USING btree (actor_profile_id, role, status)","name":"ix_project_role_grants_actor_role_status","table_name":"project_role_grants"},{"definition":"CREATE INDEX ix_project_role_grants_project_actor_role_status ON public.project_role_grants USING btree (project_id, actor_profile_id, role, status)","name":"ix_project_role_grants_project_actor_role_status","table_name":"project_role_grants"},{"definition":"CREATE UNIQUE INDEX pk_project_role_grants ON public.project_role_grants USING btree (id)","name":"pk_project_role_grants","table_name":"project_role_grants"},{"definition":"CREATE UNIQUE INDEX uq_project_role_grants_active_exact_role ON public.project_role_grants USING btree (project_id, actor_profile_id, role) WHERE ((status)::text = 'active'::text)","name":"uq_project_role_grants_active_exact_role","table_name":"project_role_grants"},{"definition":"CREATE UNIQUE INDEX grant_reference ON public.project_role_qualification_snapshots USING btree (id, actor_profile_id, project_id, requested_role)","name":"grant_reference","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE INDEX ix_project_role_qualification_snapshots_history ON public.project_role_qualification_snapshots USING btree (project_id, actor_profile_id, requested_role, captured_at)","name":"ix_project_role_qualification_snapshots_history","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE UNIQUE INDEX pk_project_role_qualification_snapshots ON public.project_role_qualification_snapshots USING btree (id)","name":"pk_project_role_qualification_snapshots","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE INDEX ix_project_setup_runs_celery_task_id ON public.project_setup_runs USING btree (celery_task_id)","name":"ix_project_setup_runs_celery_task_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_continuation_verification_job_id ON public.project_setup_runs USING btree (continuation_verification_job_id)","name":"ix_project_setup_runs_continuation_verification_job_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_error_artifact_incident_id ON public.project_setup_runs USING btree (error_artifact_incident_id)","name":"ix_project_setup_runs_error_artifact_incident_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_guide_id ON public.project_setup_runs USING btree (guide_id)","name":"ix_project_setup_runs_guide_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_output_post_submit_checker_policy_id ON public.project_setup_runs USING btree (output_post_submit_checker_policy_id)","name":"ix_project_setup_runs_output_post_submit_checker_policy_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_output_submission_artifact_policy_id ON public.project_setup_runs USING btree (output_submission_artifact_policy_id)","name":"ix_project_setup_runs_output_submission_artifact_policy_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_output_sufficiency_report_id ON public.project_setup_runs USING btree (output_sufficiency_report_id)","name":"ix_project_setup_runs_output_sufficiency_report_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_project_id ON public.project_setup_runs USING btree (project_id)","name":"ix_project_setup_runs_project_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_source_snapshot_id ON public.project_setup_runs USING btree (source_snapshot_id)","name":"ix_project_setup_runs_source_snapshot_id","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_project_setup_runs_status ON public.project_setup_runs USING btree (status)","name":"ix_project_setup_runs_status","table_name":"project_setup_runs"},{"definition":"CREATE UNIQUE INDEX pk_project_setup_runs ON public.project_setup_runs USING btree (id)","name":"pk_project_setup_runs","table_name":"project_setup_runs"},{"definition":"CREATE UNIQUE INDEX uq_project_setup_runs_exact_generation ON public.project_setup_runs USING btree (id, project_id, guide_id, source_snapshot_id, setup_generation)","name":"uq_project_setup_runs_exact_generation","table_name":"project_setup_runs"},{"definition":"CREATE UNIQUE INDEX uq_project_setup_runs_guide_generation ON public.project_setup_runs USING btree (guide_id, setup_generation)","name":"uq_project_setup_runs_guide_generation","table_name":"project_setup_runs"},{"definition":"CREATE INDEX ix_projects_slug ON public.projects USING btree (slug)","name":"ix_projects_slug","table_name":"projects"},{"definition":"CREATE INDEX ix_projects_status ON public.projects USING btree (status)","name":"ix_projects_status","table_name":"projects"},{"definition":"CREATE UNIQUE INDEX pk_projects ON public.projects USING btree (id)","name":"pk_projects","table_name":"projects"},{"definition":"CREATE UNIQUE INDEX uq_projects_slug ON public.projects USING btree (slug)","name":"uq_projects_slug","table_name":"projects"},{"definition":"CREATE INDEX ix_review_admission_submission ON public.review_admission_idempotency_records USING btree (submission_id, status, created_at, id)","name":"ix_review_admission_submission","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX pk_review_admission_idempotency_records ON public.review_admission_idempotency_records USING btree (id)","name":"pk_review_admission_idempotency_records","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_review_admission_checker_run ON public.review_admission_idempotency_records USING btree (admitting_checker_run_id)","name":"uq_review_admission_checker_run","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_review_admission_operation ON public.review_admission_idempotency_records USING btree (operation_id)","name":"uq_review_admission_operation","table_name":"review_admission_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_review_admission_replay_key ON public.review_admission_idempotency_records USING btree (idempotency_key)","name":"uq_review_admission_replay_key","table_name":"review_admission_idempotency_records"},{"definition":"CREATE INDEX ix_review_lease_expiry ON public.review_leases USING btree (status, expires_at, id)","name":"ix_review_lease_expiry","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX pk_review_leases ON public.review_leases USING btree (id)","name":"pk_review_leases","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_active_queue ON public.review_leases USING btree (review_queue_entry_id) WHERE ((status)::text = 'active'::text)","name":"uq_review_lease_active_queue","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_active_reviewer ON public.review_leases USING btree (reviewer_id) WHERE ((status)::text = 'active'::text)","name":"uq_review_lease_active_reviewer","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_attempt ON public.review_leases USING btree (review_queue_entry_id, attempt_generation)","name":"uq_review_lease_attempt","table_name":"review_leases"},{"definition":"CREATE UNIQUE INDEX uq_review_lease_queue_identity ON public.review_leases USING btree (review_queue_entry_id, id)","name":"uq_review_lease_queue_identity","table_name":"review_leases"},{"definition":"CREATE INDEX ix_review_policies_project_id ON public.review_policies USING btree (project_id)","name":"ix_review_policies_project_id","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX pk_review_policies ON public.review_policies USING btree (id)","name":"pk_review_policies","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX uq_review_policies_project_version_generation ON public.review_policies USING btree (project_id, guide_version, policy_generation)","name":"uq_review_policies_project_version_generation","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX uq_review_policy_lineage ON public.review_policies USING btree (id, policy_generation, policy_hash)","name":"uq_review_policy_lineage","table_name":"review_policies"},{"definition":"CREATE UNIQUE INDEX uq_review_policy_scoped_lineage ON public.review_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)","name":"uq_review_policy_scoped_lineage","table_name":"review_policies"},{"definition":"CREATE INDEX ix_review_queue_preference ON public.review_queue_entries USING btree (preferred_reviewer_id, queue_state, preference_expires_at, id)","name":"ix_review_queue_preference","table_name":"review_queue_entries"},{"definition":"CREATE INDEX ix_review_queue_selection ON public.review_queue_entries USING btree (project_id, queue_state, routing_mode, first_queued_at, id)","name":"ix_review_queue_selection","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX pk_review_queue_entries ON public.review_queue_entries USING btree (id)","name":"pk_review_queue_entries","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX uq_review_queue_admission_identity ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version, admitting_checker_run_id)","name":"uq_review_queue_admission_identity","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX uq_review_queue_lease_lineage ON public.review_queue_entries USING btree (id, project_id, task_id, submission_id, submission_version)","name":"uq_review_queue_lease_lineage","table_name":"review_queue_entries"},{"definition":"CREATE UNIQUE INDEX uq_review_queue_submission ON public.review_queue_entries USING btree (submission_id)","name":"uq_review_queue_submission","table_name":"review_queue_entries"},{"definition":"CREATE INDEX ix_revision_policies_project_id ON public.revision_policies USING btree (project_id)","name":"ix_revision_policies_project_id","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX pk_revision_policies ON public.revision_policies USING btree (id)","name":"pk_revision_policies","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX uq_revision_policies_project_version_generation ON public.revision_policies USING btree (project_id, guide_version, policy_generation)","name":"uq_revision_policies_project_version_generation","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX uq_revision_policy_lineage ON public.revision_policies USING btree (id, policy_generation, policy_hash)","name":"uq_revision_policy_lineage","table_name":"revision_policies"},{"definition":"CREATE UNIQUE INDEX uq_revision_policy_scoped_lineage ON public.revision_policies USING btree (project_id, guide_version, id, policy_generation, policy_hash)","name":"uq_revision_policy_scoped_lineage","table_name":"revision_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_guide_id ON public.submission_artifact_policies USING btree (guide_id)","name":"ix_submission_artifact_policies_guide_id","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_lifecycle_status ON public.submission_artifact_policies USING btree (lifecycle_status)","name":"ix_submission_artifact_policies_lifecycle_status","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_policy_hash ON public.submission_artifact_policies USING btree (policy_hash)","name":"ix_submission_artifact_policies_policy_hash","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_project_id ON public.submission_artifact_policies USING btree (project_id)","name":"ix_submission_artifact_policies_project_id","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_artifact_policies_source_snapshot_id ON public.submission_artifact_policies USING btree (source_snapshot_id)","name":"ix_submission_artifact_policies_source_snapshot_id","table_name":"submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX pk_submission_artifact_policies ON public.submission_artifact_policies USING btree (id)","name":"pk_submission_artifact_policies","table_name":"submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX uq_submission_artifact_policies_id_hash ON public.submission_artifact_policies USING btree (id, policy_hash)","name":"uq_submission_artifact_policies_id_hash","table_name":"submission_artifact_policies"},{"definition":"CREATE UNIQUE INDEX uq_submission_artifact_policies_project_version_policy ON public.submission_artifact_policies USING btree (project_id, guide_version, policy_version)","name":"uq_submission_artifact_policies_project_version_policy","table_name":"submission_artifact_policies"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_actor_profile_id ON public.submission_bundle_admissions USING btree (actor_profile_id)","name":"ix_submission_bundle_admissions_actor_profile_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_artifact_content_id ON public.submission_bundle_admissions USING btree (artifact_content_id)","name":"ix_submission_bundle_admissions_artifact_content_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_pre_submit_evidence_set_id ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)","name":"ix_submission_bundle_admissions_pre_submit_evidence_set_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_project_id ON public.submission_bundle_admissions USING btree (project_id)","name":"ix_submission_bundle_admissions_project_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_status ON public.submission_bundle_admissions USING btree (status)","name":"ix_submission_bundle_admissions_status","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_admissions_task_id ON public.submission_bundle_admissions USING btree (task_id)","name":"ix_submission_bundle_admissions_task_id","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX pk_submission_bundle_admissions ON public.submission_bundle_admissions USING btree (id)","name":"pk_submission_bundle_admissions","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_consumer ON public.submission_bundle_admissions USING btree (consumed_by_submission_id) WHERE (consumed_by_submission_id IS NOT NULL)","name":"uq_submission_bundle_admission_consumer","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_evidence ON public.submission_bundle_admissions USING btree (pre_submit_evidence_set_id)","name":"uq_submission_bundle_admission_evidence","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_intent ON public.submission_bundle_admissions USING btree (durable_intent_id)","name":"uq_submission_bundle_admission_intent","table_name":"submission_bundle_admissions"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_admission_verification ON public.submission_bundle_admissions USING btree (verification_receipt_id)","name":"uq_submission_bundle_admission_verification","table_name":"submission_bundle_admissions"},{"definition":"CREATE INDEX ix_submission_bundle_durable_intents_pre_submit_evidence_set_id ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)","name":"ix_submission_bundle_durable_intents_pre_submit_evidence_set_id","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE INDEX ix_submission_bundle_durable_intents_put_attempt_id ON public.submission_bundle_durable_intents USING btree (put_attempt_id)","name":"ix_submission_bundle_durable_intents_put_attempt_id","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX pk_submission_bundle_durable_intents ON public.submission_bundle_durable_intents USING btree (id)","name":"pk_submission_bundle_durable_intents","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_intent_evidence ON public.submission_bundle_durable_intents USING btree (pre_submit_evidence_set_id)","name":"uq_submission_bundle_intent_evidence","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX uq_submission_bundle_intent_put_attempt ON public.submission_bundle_durable_intents USING btree (put_attempt_id)","name":"uq_submission_bundle_intent_put_attempt","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE UNIQUE INDEX pk_submission_policy_mutation_idempotency_records ON public.submission_policy_mutation_idempotency_records USING btree (id)","name":"pk_submission_policy_mutation_idempotency_records","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_committed_policy_action ON public.submission_policy_mutation_idempotency_records USING btree (committed_policy_id, action_id) WHERE ((status)::text = 'committed'::text)","name":"uq_submission_policy_committed_policy_action","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_human_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, idempotency_key) WHERE (service_identity IS NULL)","name":"uq_submission_policy_human_replay_namespace","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_operation_identity ON public.submission_policy_mutation_idempotency_records USING btree (operation_id)","name":"uq_submission_policy_operation_identity","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE UNIQUE INDEX uq_submission_policy_service_replay_namespace ON public.submission_policy_mutation_idempotency_records USING btree (actor_profile_id, setup_run_id, setup_generation, setup_task_id, correlation_id, action_id) WHERE (service_identity IS NOT NULL)","name":"uq_submission_policy_service_replay_namespace","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE INDEX ix_submissions_contributor_id ON public.submissions USING btree (contributor_id)","name":"ix_submissions_contributor_id","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_effective_policy_hash ON public.submissions USING btree (locked_effective_project_submission_artifact_policy_hash)","name":"ix_submissions_locked_effective_policy_hash","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_post_submit_policy_hash ON public.submissions USING btree (locked_post_submit_checker_policy_hash)","name":"ix_submissions_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_pre_submit_checker_hash ON public.submissions USING btree (locked_pre_submit_checker_bundle_hash)","name":"ix_submissions_locked_pre_submit_checker_hash","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_locked_source_snapshot ON public.submissions USING btree (locked_guide_source_snapshot_id)","name":"ix_submissions_locked_source_snapshot","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_status ON public.submissions USING btree (status)","name":"ix_submissions_status","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_supersedes_submission_id ON public.submissions USING btree (supersedes_submission_id)","name":"ix_submissions_supersedes_submission_id","table_name":"submissions"},{"definition":"CREATE INDEX ix_submissions_task_id ON public.submissions USING btree (task_id)","name":"ix_submissions_task_id","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX pk_submissions ON public.submissions USING btree (id)","name":"pk_submissions","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_id_locked_post_submit_policy_hash ON public.submissions USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","name":"uq_submissions_id_locked_post_submit_policy_hash","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_id_task_version ON public.submissions USING btree (id, task_id, version)","name":"uq_submissions_id_task_version","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_id_version ON public.submissions USING btree (id, version)","name":"uq_submissions_id_version","table_name":"submissions"},{"definition":"CREATE UNIQUE INDEX uq_submissions_task_version ON public.submissions USING btree (task_id, version)","name":"uq_submissions_task_version","table_name":"submissions"},{"definition":"CREATE INDEX ix_task_assignments_contributor_id ON public.task_assignments USING btree (contributor_id)","name":"ix_task_assignments_contributor_id","table_name":"task_assignments"},{"definition":"CREATE INDEX ix_task_assignments_status ON public.task_assignments USING btree (status)","name":"ix_task_assignments_status","table_name":"task_assignments"},{"definition":"CREATE INDEX ix_task_assignments_task_id ON public.task_assignments USING btree (task_id)","name":"ix_task_assignments_task_id","table_name":"task_assignments"},{"definition":"CREATE UNIQUE INDEX pk_task_assignments ON public.task_assignments USING btree (id)","name":"pk_task_assignments","table_name":"task_assignments"},{"definition":"CREATE UNIQUE INDEX uq_task_assignments_id_task_contributor ON public.task_assignments USING btree (id, task_id, contributor_id)","name":"uq_task_assignments_id_task_contributor","table_name":"task_assignments"},{"definition":"CREATE UNIQUE INDEX uq_task_assignments_one_active_per_task ON public.task_assignments USING btree (task_id) WHERE ((status)::text = 'active'::text)","name":"uq_task_assignments_one_active_per_task","table_name":"task_assignments"},{"definition":"CREATE INDEX ix_workstream_tasks_assigned_to ON public.workstream_tasks USING btree (assigned_to)","name":"ix_workstream_tasks_assigned_to","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_effective_policy_hash ON public.workstream_tasks USING btree (locked_effective_project_submission_artifact_policy_hash)","name":"ix_workstream_tasks_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (locked_post_submit_checker_policy_hash)","name":"ix_workstream_tasks_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (locked_pre_submit_checker_bundle_hash)","name":"ix_workstream_tasks_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_locked_source_snapshot ON public.workstream_tasks USING btree (locked_guide_source_snapshot_id)","name":"ix_workstream_tasks_locked_source_snapshot","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_project_id ON public.workstream_tasks USING btree (project_id)","name":"ix_workstream_tasks_project_id","table_name":"workstream_tasks"},{"definition":"CREATE INDEX ix_workstream_tasks_status ON public.workstream_tasks USING btree (status)","name":"ix_workstream_tasks_status","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX pk_workstream_tasks ON public.workstream_tasks USING btree (id)","name":"pk_workstream_tasks","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_effective_policy_hash ON public.workstream_tasks USING btree (id, locked_effective_project_submission_artifact_policy_id, locked_effective_project_submission_artifact_policy_hash)","name":"uq_workstream_tasks_id_locked_effective_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_guide ON public.workstream_tasks USING btree (id, locked_guide_version)","name":"uq_workstream_tasks_id_locked_guide","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_payment_policy ON public.workstream_tasks USING btree (id, locked_payment_policy_version)","name":"uq_workstream_tasks_id_locked_payment_policy","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_post_submit_policy_hash ON public.workstream_tasks USING btree (id, locked_post_submit_checker_policy_id, locked_post_submit_checker_policy_version, locked_post_submit_checker_policy_hash)","name":"uq_workstream_tasks_id_locked_post_submit_policy_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_pre_submit_checker_hash ON public.workstream_tasks USING btree (id, locked_pre_submit_checker_policy_id, locked_pre_submit_checker_bundle_hash)","name":"uq_workstream_tasks_id_locked_pre_submit_checker_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_review_policy ON public.workstream_tasks USING btree (id, locked_review_policy_id, locked_review_policy_generation, locked_review_policy_hash)","name":"uq_workstream_tasks_id_locked_review_policy","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_revision_policy ON public.workstream_tasks USING btree (id, locked_revision_policy_id, locked_revision_policy_generation, locked_revision_policy_hash)","name":"uq_workstream_tasks_id_locked_revision_policy","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_locked_source_snapshot_hash ON public.workstream_tasks USING btree (id, locked_guide_source_snapshot_id, locked_guide_source_snapshot_hash)","name":"uq_workstream_tasks_id_locked_source_snapshot_hash","table_name":"workstream_tasks"},{"definition":"CREATE UNIQUE INDEX uq_workstream_tasks_id_project ON public.workstream_tasks USING btree (id, project_id)","name":"uq_workstream_tasks_id_project","table_name":"workstream_tasks"}],"policies":[],"reference_rows":{"actor_profile_migration_state":[{"classified_count":0,"envelope_sha256":null,"id":1,"manifest_sha256":null,"migrated_at":"2026-08-11T08:18:03.063940+00:00","schema_version":1,"service_identity_database_binding":"postgres-v1:aa1108b4a868ca4330673d1bbe499d99c330d196994696d89e56cf09bfc3c93e","service_identity_envelope_sha256":null,"service_identity_manifest_sha256":null,"service_identity_mapped_count":0,"service_identity_source_row_set_sha256":"4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945","source_row_set_sha256":"4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945"}],"authority_control":[{"bootstrap_completed":false,"bootstrap_grant_id":null,"created_at":"2026-08-11T08:18:13.474128+00:00","id":1,"updated_at":"2026-08-11T08:18:13.474148+00:00","version":0}],"iso_4217_currency_codes":[{"code":"AED"},{"code":"AFN"},{"code":"ALL"},{"code":"AMD"},{"code":"AOA"},{"code":"ARS"},{"code":"AUD"},{"code":"AWG"},{"code":"AZN"},{"code":"BAM"},{"code":"BBD"},{"code":"BDT"},{"code":"BHD"},{"code":"BIF"},{"code":"BMD"},{"code":"BND"},{"code":"BOB"},{"code":"BOV"},{"code":"BRL"},{"code":"BSD"},{"code":"BTN"},{"code":"BWP"},{"code":"BYN"},{"code":"BZD"},{"code":"CAD"},{"code":"CDF"},{"code":"CHE"},{"code":"CHF"},{"code":"CHW"},{"code":"CLF"},{"code":"CLP"},{"code":"CNY"},{"code":"COP"},{"code":"COU"},{"code":"CRC"},{"code":"CUP"},{"code":"CVE"},{"code":"CZK"},{"code":"DJF"},{"code":"DKK"},{"code":"DOP"},{"code":"DZD"},{"code":"EGP"},{"code":"ERN"},{"code":"ETB"},{"code":"EUR"},{"code":"FJD"},{"code":"FKP"},{"code":"GBP"},{"code":"GEL"},{"code":"GHS"},{"code":"GIP"},{"code":"GMD"},{"code":"GNF"},{"code":"GTQ"},{"code":"GYD"},{"code":"HKD"},{"code":"HNL"},{"code":"HTG"},{"code":"HUF"},{"code":"IDR"},{"code":"ILS"},{"code":"INR"},{"code":"IQD"},{"code":"IRR"},{"code":"ISK"},{"code":"JMD"},{"code":"JOD"},{"code":"JPY"},{"code":"KES"},{"code":"KGS"},{"code":"KHR"},{"code":"KMF"},{"code":"KPW"},{"code":"KRW"},{"code":"KWD"},{"code":"KYD"},{"code":"KZT"},{"code":"LAK"},{"code":"LBP"},{"code":"LKR"},{"code":"LRD"},{"code":"LSL"},{"code":"LYD"},{"code":"MAD"},{"code":"MDL"},{"code":"MGA"},{"code":"MKD"},{"code":"MMK"},{"code":"MNT"},{"code":"MOP"},{"code":"MRU"},{"code":"MUR"},{"code":"MVR"},{"code":"MWK"},{"code":"MXN"},{"code":"MXV"},{"code":"MYR"},{"code":"MZN"},{"code":"NAD"},{"code":"NGN"},{"code":"NIO"},{"code":"NOK"},{"code":"NPR"},{"code":"NZD"},{"code":"OMR"},{"code":"PAB"},{"code":"PEN"},{"code":"PGK"},{"code":"PHP"},{"code":"PKR"},{"code":"PLN"},{"code":"PYG"},{"code":"QAR"},{"code":"RON"},{"code":"RSD"},{"code":"RUB"},{"code":"RWF"},{"code":"SAR"},{"code":"SBD"},{"code":"SCR"},{"code":"SDG"},{"code":"SEK"},{"code":"SGD"},{"code":"SHP"},{"code":"SLE"},{"code":"SOS"},{"code":"SRD"},{"code":"SSP"},{"code":"STN"},{"code":"SVC"},{"code":"SYP"},{"code":"SZL"},{"code":"THB"},{"code":"TJS"},{"code":"TMT"},{"code":"TND"},{"code":"TOP"},{"code":"TRY"},{"code":"TTD"},{"code":"TWD"},{"code":"TZS"},{"code":"UAH"},{"code":"UGX"},{"code":"USD"},{"code":"USN"},{"code":"UYI"},{"code":"UYU"},{"code":"UYW"},{"code":"UZS"},{"code":"VED"},{"code":"VES"},{"code":"VND"},{"code":"VUV"},{"code":"WST"},{"code":"XAD"},{"code":"XAF"},{"code":"XAG"},{"code":"XAU"},{"code":"XBA"},{"code":"XBB"},{"code":"XBC"},{"code":"XBD"},{"code":"XCD"},{"code":"XCG"},{"code":"XDR"},{"code":"XOF"},{"code":"XPD"},{"code":"XPF"},{"code":"XPT"},{"code":"XSU"},{"code":"XTS"},{"code":"XUA"},{"code":"XXX"},{"code":"YER"},{"code":"ZAR"},{"code":"ZMW"},{"code":"ZWG"}]},"routines":[{"arguments":"event_name text, before_state json, after_state json, envelope_project_id text","definition":"CREATE OR REPLACE FUNCTION public.authority_event_facts_are_safe(event_name text, before_state json, after_state json, envelope_project_id text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE AS $function$ begin if not (event_name='AuthorityInvalidationRequested' and before_state is not null and after_state is not null and coalesce(before_state::jsonb ? 'future_obligation', false) and coalesce(after_state::jsonb ? 'future_obligation', false)) and ((before_state is not null and not authority_facts_are_safe(before_state)) or (after_state is not null and not authority_facts_are_safe(after_state))) then return false; end if; case event_name when 'ActorProfileProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"human\",\"provisioning_method\":\"automatic_first_access\"}'::jsonb; when 'ServiceActorProvisioned' then return before_state is null and after_state::jsonb = '{\"status\":\"active\",\"subject_kind\":\"service\",\"provisioning_method\":\"manual_service_provisioning\"}'::jsonb; when 'ActorIdentityLinked' then return before_state is null and after_state::jsonb in ( '{\"status\":\"active\",\"subject_kind\":\"human\"}'::jsonb, '{\"status\":\"active\",\"subject_kind\":\"service\"}'::jsonb); when 'ActorIdentityLinkRevoked' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"revoked\"}'::jsonb; when 'ActorIdentityLinkReactivated' then return before_state::jsonb='{\"status\":\"revoked\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileSuspended' then return before_state::jsonb='{\"status\":\"active\"}'::jsonb and after_state::jsonb='{\"status\":\"suspended\"}'::jsonb; when 'ActorProfileReactivated' then return before_state::jsonb='{\"status\":\"suspended\"}'::jsonb and after_state::jsonb='{\"status\":\"active\"}'::jsonb; when 'ActorProfileDeactivated' then return before_state::jsonb in ('{\"status\":\"active\"}'::jsonb,'{\"status\":\"suspended\"}'::jsonb) and after_state::jsonb='{\"status\":\"deactivated\"}'::jsonb; when 'InitialAccessAdministratorBootstrapped' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator'],'active',true,null); when 'AdminRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['access_administrator','operator','project_manager','finance_authority','audit_authority'],'active',true,envelope_project_id); when 'ProjectRoleGrantIssued' then return before_state is null and authority_grant_facts_are_safe(after_state,array['submitter','reviewer','adjudicator'],'active',true,envelope_project_id); when 'AdminRoleGrantRevoked','ProjectRoleGrantRevoked' then return authority_grant_facts_are_safe(before_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'active',true,envelope_project_id) and authority_grant_facts_are_safe(after_state, case when event_name='AdminRoleGrantRevoked' then array['access_administrator','operator','project_manager','finance_authority','audit_authority'] else array['submitter','reviewer','adjudicator'] end, 'revoked',false,envelope_project_id) and before_state->>'role'=after_state->>'role' and before_state->>'scope_type'=after_state->>'scope_type' and coalesce(before_state->>'scope_id','')=coalesce(after_state->>'scope_id',''); when 'ProjectRoleQualificationSnapshotCaptured' then return before_state is null and after_state::jsonb='{\"status\":\"captured\"}'::jsonb; when 'AdminRoleGrantIssueDenied','LastAccessAdministratorOperationDenied' then return before_state is null and after_state is null; when 'SensitiveAuthorizationAllowed' then return before_state is null and ( after_state::jsonb = '{\"allowed\": true}'::jsonb or ( after_state::jsonb->'allowed' = 'true'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'SensitiveAuthorizationDenied' then return before_state is null and ( after_state::jsonb = '{\"allowed\": false}'::jsonb or ( after_state::jsonb->'allowed' = 'false'::jsonb and after_state::jsonb ? 'resource_context_digest' and (select count(*) from json_each(after_state)) = 2 ) ); when 'AuthorityInvalidationRequested' then return (before_state::jsonb = '{\"effective\": true}'::jsonb and after_state::jsonb = '{\"effective\": false}'::jsonb) or (before_state::jsonb = '{\"effective\": false}'::jsonb and after_state::jsonb = '{\"effective\": true}'::jsonb) or ( jsonb_typeof(before_state::jsonb)='object' and jsonb_typeof(after_state::jsonb)='object' and (select count(*) from jsonb_object_keys(before_state::jsonb))=5 and (select count(*) from jsonb_object_keys(after_state::jsonb))=5 and before_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and after_state::jsonb ?& array['effective','role','scope_type','scope_id','future_obligation'] and before_state::jsonb->'effective'='true'::jsonb and after_state::jsonb->'effective'='false'::jsonb and jsonb_typeof(before_state::jsonb->'role')='string' and jsonb_typeof(before_state::jsonb->'scope_type')='string' and jsonb_typeof(before_state::jsonb->'scope_id')='string' and jsonb_typeof(before_state::jsonb->'future_obligation')='string' and (before_state::jsonb - 'effective')=(after_state::jsonb - 'effective') and before_state::jsonb->>'scope_type'='project' and before_state::jsonb->>'scope_id'=envelope_project_id and ((before_state::jsonb->>'role'='submitter' and before_state::jsonb->>'future_obligation'='auth13_assignment') or (before_state::jsonb->>'role'='reviewer' and before_state::jsonb->>'future_obligation'='rev_reviewer_obligation') or (before_state::jsonb->>'role'='adjudicator' and before_state::jsonb->>'future_obligation'='none')) ); else return false; end case; end $function$","name":"authority_event_facts_are_safe"},{"arguments":"facts json","definition":"CREATE OR REPLACE FUNCTION public.authority_facts_are_safe(facts json) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select json_typeof(facts) = 'object' and (select count(*) = count(distinct key) and count(*) <= 8 from json_each(facts)) and not exists ( select 1 from json_each(facts) item where item.key not in ( 'status', 'subject_kind', 'provisioning_method', 'role', 'scope_type', 'scope_id', 'effective', 'allowed', 'resource_context_digest' ) or case item.key when 'status' then item.value #>> '{}' not in ( 'active', 'suspended', 'deactivated', 'revoked', 'captured' ) when 'subject_kind' then item.value #>> '{}' not in ('human', 'service') when 'provisioning_method' then item.value #>> '{}' not in ( 'automatic_first_access', 'manual_service_provisioning' ) when 'role' then item.value #>> '{}' not in ( 'access_administrator', 'operator', 'project_manager', 'finance_authority', 'audit_authority', 'submitter', 'reviewer', 'both' ) when 'scope_type' then item.value #>> '{}' not in ('system', 'project') when 'scope_id' then (item.value #>> '{}') !~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' when 'effective' then json_typeof(item.value) <> 'boolean' when 'allowed' then json_typeof(item.value) <> 'boolean' when 'resource_context_digest' then (item.value #>> '{}') !~ '^sha256:[0-9a-f]{64}$' else true end ) $function$","name":"authority_facts_are_safe"},{"arguments":"facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text","definition":"CREATE OR REPLACE FUNCTION public.authority_grant_facts_are_safe(facts json, roles text[], expected_status text, expected_effective boolean, envelope_project_id text) RETURNS boolean LANGUAGE sql IMMUTABLE AS $function$ select authority_facts_are_safe(facts) and facts->>'role' = any(roles) and facts->>'status' = expected_status and (facts->>'effective')::boolean = expected_effective and ( ( facts->>'scope_type' = 'system' and envelope_project_id is null and not facts::jsonb ? 'scope_id' and facts->>'role' not in ('submitter', 'reviewer', 'both') and (select count(*) from json_each(facts)) = 4 ) or ( facts->>'scope_type' = 'project' and envelope_project_id is not null and facts->>'scope_id' = envelope_project_id and facts->>'role' not in ('access_administrator', 'operator') and (select count(*) from json_each(facts)) = 5 ) ) $function$","name":"authority_grant_facts_are_safe"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.enforce_compensation_binding_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compensation_binding_updates_deferred'; return new; end; $function$","name":"enforce_compensation_binding_lifecycle"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_actor_identity_link_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor identity links are immutable history' using errcode='55000'; end if; if (new.id,new.actor_profile_id,new.issuer,new.subject,new.subject_kind,new.linked_by,new.linked_at) is distinct from (old.id,old.actor_profile_id,old.issuer,old.subject,old.subject_kind,old.linked_by,old.linked_at) then raise exception 'actor identity link anchor is immutable' using errcode='55000'; end if; if new.status=old.status and (new.revoked_by,new.revoked_at,new.revoked_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.revoked_by,old.revoked_at,old.revoked_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'identity link attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='revoked' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid identity link revocation attribution' using errcode='23514'; end if; if old.status='revoked' and new.status='active' and ((new.revoked_by,new.revoked_at,new.revoked_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason)) then raise exception 'invalid identity link reactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status='revoked') or (old.status='revoked' and new.status='active')) then raise exception 'invalid identity link lifecycle transition' using errcode='23514'; end if; return new; end $function$","name":"guard_actor_identity_link_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_actor_profile_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' then raise exception 'actor profiles are immutable history' using errcode='55000'; end if; if (new.id,new.actor_kind,new.provisioning_method,new.created_by,new.created_at) is distinct from (old.id,old.actor_kind,old.provisioning_method,old.created_by,old.created_at) then raise exception 'actor profile identity is immutable' using errcode='55000'; end if; if old.status='deactivated' and new.status <> 'deactivated' then raise exception 'deactivated actor is terminal' using errcode='23514'; end if; if new.status = old.status and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason, new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason, old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'actor lifecycle attribution requires a transition' using errcode='23514'; end if; if old.status='active' and new.status='suspended' and (new.reactivated_by,new.reactivated_at,new.reactivation_reason,new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason,old.deactivated_by,old.deactivated_at,old.deactivation_reason) then raise exception 'invalid actor suspension attribution' using errcode='23514'; end if; if old.status='suspended' and new.status='active' and ((new.suspended_by,new.suspended_at,new.suspension_reason) is distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (null,null,null) or (new.reactivated_by,new.reactivated_at,new.reactivation_reason) is not distinct from (old.reactivated_by,old.reactivated_at,old.reactivation_reason) or (new.deactivated_by,new.deactivated_at,new.deactivation_reason) is distinct from (old.deactivated_by,old.deactivated_at,old.deactivation_reason)) then raise exception 'invalid actor reactivation attribution' using errcode='23514'; end if; if new.status='deactivated' and old.status in ('active','suspended') and (new.suspended_by,new.suspended_at,new.suspension_reason,new.reactivated_by,new.reactivated_at,new.reactivation_reason) is distinct from (old.suspended_by,old.suspended_at,old.suspension_reason,old.reactivated_by,old.reactivated_at,old.reactivation_reason) then raise exception 'invalid actor deactivation attribution' using errcode='23514'; end if; if new.status <> old.status and not ( (old.status='active' and new.status in ('suspended','deactivated')) or (old.status='suspended' and new.status in ('active','deactivated'))) then raise exception 'invalid actor lifecycle transition' using errcode='23514'; end if; new.updated_at = statement_timestamp(); return new; end $function$","name":"guard_actor_profile_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_admin_role_grant() RETURNS trigger LANGUAGE plpgsql AS $function$ declare target_kind text; authorizer admin_role_grants%rowtype; bootstrap_done boolean; begin if tg_op='DELETE' then raise exception 'admin role grants are immutable' using errcode='55000'; end if; if tg_op='INSERT' then select actor_kind into target_kind from actor_profiles where id=new.target_actor_profile_id; if target_kind is distinct from 'human' then raise exception 'admin role target must be human' using errcode='23514'; end if; new.granted_at := clock_timestamp(); if new.granted_by_system_principal is not null then if new.role <> 'access_administrator' or new.scope_type <> 'system' then raise exception 'invalid bootstrap grant' using errcode='23514'; end if; select bootstrap_completed into bootstrap_done from authority_control where id=1 for update; if bootstrap_done is distinct from false or exists(select 1 from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap') then raise exception 'bootstrap already completed' using errcode='23514'; end if; else select * into authorizer from admin_role_grants where id=new.granted_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.granted_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin grant attribution' using errcode='23514'; end if; end if; return new; end if; if old.status <> 'active' or old.version <> 1 or new.status <> 'revoked' or new.version <> 2 or (new.id,new.target_actor_profile_id,new.role,new.scope_type,new.scope_project_id, new.granted_by_actor_profile_id,new.granted_by_system_principal, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.target_actor_profile_id,old.role,old.scope_type,old.scope_project_id, old.granted_by_actor_profile_id,old.granted_by_system_principal, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) then raise exception 'invalid admin role grant transition' using errcode='23514'; end if; select * into authorizer from admin_role_grants where id=new.revoked_by_admin_role_grant_id; if not found or authorizer.target_actor_profile_id <> new.revoked_by_actor_profile_id or authorizer.role <> 'access_administrator' or authorizer.scope_type <> 'system' or authorizer.status <> 'active' then raise exception 'invalid admin revoke attribution' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$","name":"guard_admin_role_grant"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_artifact_receipt_producer_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id; if request_type is null or (request_type = 'guide' and not ( new.guide_source_item_id is not null and new.checker_run_id is null and new.logical_role is null)) or (request_type = 'checker_output' and not ( new.guide_source_item_id is null and new.checker_run_id is not null and octet_length(new.logical_role) between 1 and 100)) or (request_type = 'submission_bundle' and not ( new.guide_source_item_id is null and new.checker_run_id is null and new.logical_role is null)) then raise exception 'artifact receipt producer reference mismatch' using errcode='23514'; end if; return new; end; $function$","name":"guard_artifact_receipt_producer_reference"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_authority_control() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('INSERT','DELETE') then raise exception 'authority control is immutable' using errcode='55000'; end if; if old.id <> 1 or old.bootstrap_completed or old.version <> 0 or new.id <> 1 or not new.bootstrap_completed or new.version <> 1 or new.bootstrap_grant_id is null or new.created_at is distinct from old.created_at then raise exception 'invalid authority control transition' using errcode='23514'; end if; new.updated_at := clock_timestamp(); return new; end $function$","name":"guard_authority_control"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_authority_idempotency_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare success_count integer; invalidation_count integer; success_id text; qualification_row audit_events%rowtype; success_row audit_events%rowtype; grant_row project_role_grants%rowtype; snapshot_row project_role_qualification_snapshots%rowtype; begin if tg_op = 'INSERT' then if new.status <> 'pending' then raise exception 'idempotency must begin pending' using errcode='23514'; end if; new.created_at := statement_timestamp(); new.committed_at := null; return new; elsif tg_op = 'DELETE' then raise exception 'authority idempotency records are immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.idempotency_key,new.actor_ref_kind,new.actor_ref,new.operation, new.request_digest,new.created_at) is distinct from (old.id,old.idempotency_key,old.actor_ref_kind,old.actor_ref,old.operation, old.request_digest,old.created_at) then raise exception 'invalid authority idempotency transition' using errcode='23514'; end if; select count(*), min(id) into success_count, success_id from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type <> 'AuthorityInvalidationRequested'; select count(*) into invalidation_count from audit_events where event_domain='authority' and idempotency_reference=new.id and event_type='AuthorityInvalidationRequested'; if new.operation='project_role_grant.issue' then if success_count <> 2 or invalidation_count <> 0 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured') <> 1 or (select count(*) from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued') <> 1 then raise exception 'project role issue evidence pair required' using errcode='23514'; end if; select * into qualification_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleQualificationSnapshotCaptured'; select * into success_row from audit_events where idempotency_reference=new.id and event_type='ProjectRoleGrantIssued'; select * into grant_row from project_role_grants where id=success_row.resource_id::uuid; select * into snapshot_row from project_role_qualification_snapshots where id=qualification_row.resource_id::uuid; if not found or grant_row.id is null or snapshot_row.id is null or grant_row.qualification_snapshot_id <> snapshot_row.id or grant_row.project_id <> snapshot_row.project_id or grant_row.actor_profile_id <> snapshot_row.actor_profile_id or grant_row.role <> snapshot_row.requested_role or qualification_row.project_id is distinct from grant_row.project_id or success_row.project_id is distinct from grant_row.project_id or qualification_row.target_actor_ref is distinct from grant_row.actor_profile_id or success_row.target_actor_ref is distinct from grant_row.actor_profile_id or qualification_row.request_id is distinct from success_row.request_id or qualification_row.correlation_id is distinct from success_row.correlation_id or qualification_row.actor_ref_kind is distinct from success_row.actor_ref_kind or qualification_row.actor_id is distinct from success_row.actor_id or qualification_row.permission_id is distinct from success_row.permission_id or qualification_row.matched_grant_id is distinct from success_row.matched_grant_id then raise exception 'project role issue evidence mismatch' using errcode='23514'; end if; else if success_count <> 1 or invalidation_count <> 1 then raise exception 'authority evidence pair required' using errcode='23514'; end if; select * into success_row from audit_events where id=success_id; end if; if success_row.resource_type <> new.response_resource_type or success_row.resource_id <> new.response_resource_id::text then raise exception 'authority response does not match evidence' using errcode='23514'; end if; new.committed_at := statement_timestamp(); return new; end $function$","name":"guard_authority_idempotency_record"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_contribution_policy_children() RETURNS trigger LANGUAGE plpgsql AS $function$ declare old_parent_status text; declare new_parent_status text; begin if tg_op in ('UPDATE','DELETE') then select status into old_parent_status from contribution_policy_versions where id=old.contribution_policy_version_id for update; end if; if tg_op in ('INSERT','UPDATE') then select status into new_parent_status from contribution_policy_versions where id=new.contribution_policy_version_id for update; end if; if old_parent_status in ('published','retired') or new_parent_status in ('published','retired') then raise exception 'published contribution policy rules and definitions are immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$","name":"guard_contribution_policy_children"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_contribution_policy_version_content() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='DELETE' and old.status in ('published','retired') then raise exception 'published contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='retired' then raise exception 'retired contribution policy versions are immutable' using errcode='55000'; end if; if tg_op='UPDATE' and old.status='published' and not ( new.status='retired' and new.id=old.id and new.contribution_policy_id=old.contribution_policy_id and new.project_id=old.project_id and new.version_number=old.version_number and new.created_by=old.created_by and new.created_at=old.created_at and new.published_by=old.published_by and new.published_at=old.published_at and new.retired_by is not null and new.retired_at is not null ) then raise exception 'published contribution policy version content is immutable' using errcode='55000'; end if; return case when tg_op='DELETE' then old else new end; end; $function$","name":"guard_contribution_policy_version_content"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_guide_lineage_and_lifecycle() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if (new.id,new.project_id,new.version) is distinct from (old.id,old.project_id,old.version) then raise exception 'guide identity and lineage are immutable' using errcode='23514'; end if; if (new.status,new.approved_by,new.effective_at,new.superseded_at) is distinct from (old.status,old.approved_by,old.effective_at,old.superseded_at) then raise exception 'guide lifecycle mutation requires activation authority' using errcode='23514'; end if; return new; end $function$","name":"guard_guide_lineage_and_lifecycle"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_guide_mutation_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'guide mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'guide mutation custody is immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status<>'pending' or new.status<>'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id,new.idempotency_key, new.request_digest,new.resource_context_digest,new.operation_id,new.project_id,new.resource_id, new.operation_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id,old.idempotency_key, old.request_digest,old.resource_context_digest,old.operation_id,old.project_id,old.resource_id, old.operation_generation,old.created_at) then raise exception 'invalid guide mutation custody transition' using errcode='23514'; end if; return new; end $function$","name":"guard_guide_mutation_idempotency"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_iso_4217_currency_codes() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'ISO 4217 currency-code registry is migration-owned and immutable' using errcode='55000'; end; $function$","name":"guard_iso_4217_currency_codes"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_outbox_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare event_time timestamptz; begin if tg_op = 'TRUNCATE' then raise exception 'outbox events cannot be truncated' using errcode='55000'; elsif tg_op = 'DELETE' then raise exception 'outbox events cannot be deleted' using errcode='55000'; elsif tg_op = 'INSERT' then event_time := statement_timestamp(); new.producer := 'workstream'; new.occurred_at := event_time; new.delivery_state := 'pending'; new.attempt_count := 0; new.next_attempt_at := event_time; new.claim_owner := null; new.claim_generation := 0; new.claimed_at := null; new.claim_expires_at := null; new.last_attempt_at := null; new.last_error_code := null; new.finalized_at := null; new.archived_at := null; return new; end if; if (new.event_id, new.event_type, new.event_version, new.producer, new.aggregate_type, new.aggregate_id, new.project_id, new.correlation_id, new.causation_event_id, new.idempotency_key, new.payload, new.payload_digest, new.occurred_at) is distinct from (old.event_id, old.event_type, old.event_version, old.producer, old.aggregate_type, old.aggregate_id, old.project_id, old.correlation_id, old.causation_event_id, old.idempotency_key, old.payload, old.payload_digest, old.occurred_at) then raise exception 'outbox event envelope is immutable' using errcode='55000'; end if; if new.attempt_count < old.attempt_count or new.claim_generation < old.claim_generation or new.attempt_count <> new.claim_generation then raise exception 'outbox counters cannot regress' using errcode='23514'; end if; if old.archived_at is not null and (new.delivery_state, new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.delivery_state, old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'archived outbox event is closed' using errcode='55000'; end if; if old.delivery_state in ('pending', 'retryable') and new.delivery_state = 'claimed' then if new.attempt_count <> old.attempt_count + 1 or new.claim_generation <> old.claim_generation + 1 or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox claim generation must increment once' using errcode='23514'; end if; elsif old.delivery_state = 'claimed' and new.delivery_state in ('retryable','acknowledged','dead_letter','cancelled') then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at then raise exception 'outbox outcome cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state = 'dead_letter' and new.delivery_state = 'retryable' and old.archived_at is null then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox requeue cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = 'cancelled' then if new.attempt_count <> old.attempt_count or new.claim_generation <> old.claim_generation or new.last_attempt_at is distinct from old.last_attempt_at or new.last_error_code is distinct from old.last_error_code then raise exception 'outbox cancellation cannot change claim generation' using errcode='23514'; end if; elsif old.delivery_state in ('pending','retryable') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at, new.archived_at) is distinct from (old.attempt_count, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at, old.archived_at) then raise exception 'outbox eligibility update changed unrelated state' using errcode='23514'; end if; elsif old.delivery_state in ('acknowledged','dead_letter','cancelled') and new.delivery_state = old.delivery_state then if (new.attempt_count, new.next_attempt_at, new.claim_owner, new.claim_generation, new.claimed_at, new.claim_expires_at, new.last_attempt_at, new.last_error_code, new.finalized_at) is distinct from (old.attempt_count, old.next_attempt_at, old.claim_owner, old.claim_generation, old.claimed_at, old.claim_expires_at, old.last_attempt_at, old.last_error_code, old.finalized_at) or (old.archived_at is not null and new.archived_at is distinct from old.archived_at) or (old.archived_at is null and new.archived_at is null) then raise exception 'terminal outbox event permits archival only' using errcode='23514'; end if; else raise exception 'illegal outbox delivery transition' using errcode='23514'; end if; return new; end $function$","name":"guard_outbox_event"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_policy_mutation_replay() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then if new.status<>'pending' then raise exception 'policy mutation must begin pending' using errcode='23514'; end if; return new; elsif tg_op='DELETE' then raise exception 'policy mutation replay is immutable' using errcode='55000'; elsif new is not distinct from old then return new; elsif old.status='pending' and new.status='committed' and (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest,new.policy_hash, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.policy_id, new.policy_generation,new.created_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest,old.policy_hash, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.policy_id, old.policy_generation,old.created_at) then return new; end if; raise exception 'policy mutation replay is immutable' using errcode='23514'; end $function$","name":"guard_policy_mutation_replay"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_result_membership() RETURNS trigger LANGUAGE plpgsql AS $function$ declare parent_created_at timestamptz; expected_count integer; current_count integer; begin select created_at, result_count into parent_created_at, expected_count from pre_submit_evidence_sets where id=new.evidence_set_id for key share; select count(*) into current_count from pre_submit_evidence_results where evidence_set_id=new.evidence_set_id; if parent_created_at is null or parent_created_at <> transaction_timestamp() or current_count >= expected_count then raise exception 'pre-submit evidence result membership is closed' using errcode='55000'; end if; return new; end; $function$","name":"guard_pre_submit_evidence_result_membership"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_results_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_results rows are immutable' using errcode='55000'; end; $function$","name":"guard_pre_submit_evidence_results_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_set_creation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.created_at is distinct from transaction_timestamp() then raise exception 'pre-submit evidence creation timestamp is invalid' using errcode='55000'; end if; return new; end; $function$","name":"guard_pre_submit_evidence_set_creation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_pre_submit_evidence_sets_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'pre_submit_evidence_sets rows are immutable' using errcode='55000'; end; $function$","name":"guard_pre_submit_evidence_sets_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_compensation_units() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op in ('UPDATE','DELETE') then raise exception 'project compensation-unit lifecycle behavior is deferred' using errcode='55000'; end if; if new.status <> 'active' then raise exception 'project compensation units must begin active' using errcode='23514'; end if; return new; end; $function$","name":"guard_project_compensation_units"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_create_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'INSERT' then if new.status <> 'pending' or new.committed_at is not null then raise exception 'project create reservation must begin pending' using errcode='23514'; end if; return new; elsif tg_op = 'DELETE' then raise exception 'project create reservations are immutable' using errcode='55000'; end if; if new is not distinct from old then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id, new.actor_profile_id, new.identity_link_id, new.action_id, new.idempotency_key, new.request_digest, new.operation_id, new.project_id, new.operation_generation, new.created_at) is distinct from (old.id, old.actor_profile_id, old.identity_link_id, old.action_id, old.idempotency_key, old.request_digest, old.operation_id, old.project_id, old.operation_generation, old.created_at) then raise exception 'invalid project create reservation transition' using errcode='23514'; end if; return new; end $function$","name":"guard_project_create_idempotency"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_attempt_update() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash,new.pre_catalogue_id, new.pre_catalogue_version,new.pre_catalogue_schema_version, new.pre_catalogue_manifest_hash,new.post_catalogue_id,new.post_catalogue_version, new.post_catalogue_schema_version,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.provider_idempotency_key) is distinct from row(old.project_id,old.guide_id,old.guide_version,old.source_snapshot_id, old.source_snapshot_hash,old.setup_run_id,old.setup_generation, old.canonical_input_hash,old.guide_material_hash,old.pre_catalogue_id, old.pre_catalogue_version,old.pre_catalogue_schema_version, old.pre_catalogue_manifest_hash,old.post_catalogue_id,old.post_catalogue_version, old.post_catalogue_schema_version,old.post_catalogue_manifest_hash, old.agent_identity,old.agent_version,old.instruction_version, old.provider_idempotency_key) then raise exception 'compilation attempt identity is immutable'; end if; if old.status in ('compilation_persisted','compilation_invalid_terminal') then raise exception 'terminal compilation attempt is immutable'; end if; if new.reserved_at is distinct from old.reserved_at then raise exception 'compilation reservation timestamp is immutable'; end if; if new.provider_uncertain_at is distinct from old.provider_uncertain_at and not (old.status='compilation_reserved' and new.status='compilation_provider_uncertain') then raise exception 'provider uncertainty timestamp is immutable'; end if; if new.accepted_at is distinct from old.accepted_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='provider_result_accepted') then raise exception 'accepted timestamp is immutable'; end if; if new.terminal_at is distinct from old.terminal_at and not (old.status in ('compilation_reserved','compilation_provider_uncertain') and new.status='compilation_invalid_terminal') then raise exception 'terminal timestamp is immutable'; end if; if row(new.persisted_at,new.persisted_compilation_id) is distinct from row(old.persisted_at,old.persisted_compilation_id) and not (old.status='provider_result_accepted' and new.status='compilation_persisted') then raise exception 'persisted custody is immutable'; end if; if old.status='provider_result_accepted' and row(new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb,new.accepted_at) is distinct from row(old.canonical_result::jsonb,old.result_hash,old.component_hashes::jsonb,old.accepted_at) then raise exception 'accepted compilation result is immutable'; end if; if not ((old.status='compilation_reserved' and new.status in ('compilation_provider_uncertain','provider_result_accepted','compilation_invalid_terminal')) or (old.status='compilation_provider_uncertain' and new.status in ('provider_result_accepted','compilation_invalid_terminal')) or (old.status='provider_result_accepted' and new.status='compilation_persisted')) then raise exception 'invalid compilation attempt transition'; end if; return new; end $function$","name":"guard_project_guide_compilation_attempt_update"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_guide_compilation_insert() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor_generation bigint; declare source_attempt project_guide_compilation_attempts%rowtype; begin select * into source_attempt from project_guide_compilation_attempts where id=new.attempt_id for update; if source_attempt.id is null or source_attempt.status <> 'provider_result_accepted' or row(new.project_id,new.guide_id,new.guide_version,new.source_snapshot_id, new.source_snapshot_hash,new.setup_run_id,new.setup_generation, new.canonical_input_hash,new.guide_material_hash, new.pre_catalogue_manifest_hash,new.post_catalogue_manifest_hash, new.agent_identity,new.agent_version,new.instruction_version, new.canonical_result::jsonb,new.result_hash,new.component_hashes::jsonb) is distinct from row(source_attempt.project_id,source_attempt.guide_id, source_attempt.guide_version,source_attempt.source_snapshot_id, source_attempt.source_snapshot_hash,source_attempt.setup_run_id, source_attempt.setup_generation,source_attempt.canonical_input_hash, source_attempt.guide_material_hash,source_attempt.pre_catalogue_manifest_hash, source_attempt.post_catalogue_manifest_hash,source_attempt.agent_identity, source_attempt.agent_version,source_attempt.instruction_version, source_attempt.canonical_result::jsonb,source_attempt.result_hash, source_attempt.component_hashes::jsonb) then raise exception 'compilation does not match its accepted attempt'; end if; if not exists( select 1 from audit_events event join actor_profiles profile on profile.id=new.created_by_actor_profile_id join actor_identity_links link on link.id=new.created_via_identity_link_id and link.actor_profile_id=profile.id where event.id=new.authorization_decision_event_id and event.event_domain='authority' and event.event_type='SensitiveAuthorizationAllowed' and event.denial_code is null and event.actor_id=new.created_by_actor_profile_id and event.permission_id='project.guide_compilation.execute' and event.action_id='project.guide_compilation.execute' and event.project_id=new.project_id and event.resource_type='project_guide_compilation_attempt' and event.resource_id=new.attempt_id::text and event.after_facts->>'allowed'='true' and event.after_facts->>'resource_context_digest'= new.authorization_resource_context_digest and profile.actor_kind='service' and profile.status='active' and profile.service_identity='workstream.project.setup' and link.subject_kind='service' and link.status='active' and link.issuer='workstream-internal' and link.subject='workstream.project.setup' ) then raise exception 'compilation authorization evidence is invalid'; end if; if new.supersedes_compilation_id is null then return new; end if; select setup_generation into predecessor_generation from project_guide_compilations where id=new.supersedes_compilation_id and project_id=new.project_id and guide_id=new.guide_id; if predecessor_generation is null or predecessor_generation >= new.setup_generation then raise exception 'compilation generation must strictly advance'; end if; return new; end $function$","name":"guard_project_guide_compilation_insert"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_guide_policy_selection() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.status in ('active','superseded') and ( new.selected_review_policy_id is distinct from old.selected_review_policy_id or new.selected_review_policy_generation is distinct from old.selected_review_policy_generation or new.selected_review_policy_hash is distinct from old.selected_review_policy_hash or new.selected_revision_policy_id is distinct from old.selected_revision_policy_id or new.selected_revision_policy_generation is distinct from old.selected_revision_policy_generation or new.selected_revision_policy_hash is distinct from old.selected_revision_policy_hash ) then raise exception 'active guide policy selection is immutable' using errcode='55000'; end if; return new; end $function$","name":"guard_project_guide_policy_selection"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_role_grant_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.granted_at := clock_timestamp(); return new; end if; if tg_op='DELETE' then raise exception 'project-role grants are immutable history' using errcode='55000'; end if; if (new.id,new.project_id,new.actor_profile_id,new.role,new.grant_method, new.qualification_snapshot_id,new.granted_by_actor_profile_id, new.granted_by_admin_role_grant_id,new.grant_reason,new.granted_at) is distinct from (old.id,old.project_id,old.actor_profile_id,old.role,old.grant_method, old.qualification_snapshot_id,old.granted_by_actor_profile_id, old.granted_by_admin_role_grant_id,old.grant_reason,old.granted_at) or old.status<>'active' or old.version<>1 or new.status<>'revoked' or new.version<>2 or new.revoked_by_actor_profile_id is null or new.revoked_by_admin_role_grant_id is null or new.revoked_reason is null then raise exception 'invalid project-role grant history transition' using errcode='23514'; end if; new.revoked_at := clock_timestamp(); return new; end $function$","name":"guard_project_role_grant_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_project_role_snapshot_history() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op='INSERT' then new.captured_at := clock_timestamp(); return new; end if; raise exception 'project-role qualification snapshots are immutable' using errcode='55000'; end $function$","name":"guard_project_role_snapshot_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_admission_record() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review admission records cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' and new.status <> 'pending' then raise exception 'review admission must begin pending' using errcode='23514'; end if; if tg_op='INSERT' then new.created_at := statement_timestamp(); end if; if tg_op='UPDATE' then if (new.id,new.idempotency_key,new.operation_id,new.request_digest,new.project_id, new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.created_at) is distinct from (old.id,old.idempotency_key,old.operation_id,old.request_digest,old.project_id, old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.created_at) then raise exception 'review admission identity is immutable' using errcode='55000'; end if; if old.status <> 'pending' or new.status <> 'committed' then raise exception 'invalid review admission transition' using errcode='23514'; end if; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review admission task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review admission checker lineage mismatch' using errcode='23514'; end if; if new.status='committed' and ( checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true) then raise exception 'review admission checker is not admissible' using errcode='23514'; end if; return new; end $function$","name":"guard_review_admission_record"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare actor_type text; policy_status text; begin if tg_op='DELETE' then raise exception 'review leases cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.status <> 'active' then raise exception 'review lease must begin active' using errcode='23514'; end if; new.claimed_at := statement_timestamp(); new.closed_at := null; new.close_reason := null; else if old.status <> 'active' then raise exception 'terminal review leases are immutable' using errcode='55000'; end if; if (new.id,new.review_queue_entry_id,new.project_id,new.task_id,new.submission_id, new.submission_version,new.reviewer_id, new.reviewer_contribution_policy_version_id,new.attempt_generation, new.claimed_at,new.expires_at) is distinct from (old.id,old.review_queue_entry_id,old.project_id,old.task_id,old.submission_id, old.submission_version,old.reviewer_id, old.reviewer_contribution_policy_version_id,old.attempt_generation, old.claimed_at,old.expires_at) then raise exception 'review lease identity is immutable' using errcode='55000'; end if; if new.status='active' then raise exception 'review lease update must close attempt' using errcode='23514'; end if; end if; select actor_kind into actor_type from actor_profiles where id=new.reviewer_id; if actor_type is distinct from 'human' then raise exception 'review lease reviewer must be human' using errcode='23514'; end if; if tg_op='INSERT' then select status into policy_status from contribution_policy_versions where id=new.reviewer_contribution_policy_version_id and project_id=new.project_id; if policy_status is distinct from 'published' then raise exception 'review lease policy version must be published' using errcode='23514'; end if; end if; return new; end $function$","name":"guard_review_lease"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review_policies rows are immutable' using errcode='55000'; end $function$","name":"guard_review_policies_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_review_queue_entry() RETURNS trigger LANGUAGE plpgsql AS $function$ declare task_project text; checker_row checker_runs%rowtype; begin if tg_op='DELETE' then raise exception 'review queue entries cannot be deleted' using errcode='55000'; end if; if tg_op='INSERT' then if new.queue_state <> 'pending' then raise exception 'review queue must begin pending' using errcode='23514'; end if; new.first_queued_at := statement_timestamp(); new.available_since := new.first_queued_at; new.routing_generation := 1; new.lifecycle_generation := 1; new.created_at := new.first_queued_at; end if; if tg_op='UPDATE' then if (new.id,new.project_id,new.task_id,new.submission_id,new.submission_version, new.admitting_checker_run_id,new.first_queued_at,new.created_at) is distinct from (old.id,old.project_id,old.task_id,old.submission_id,old.submission_version, old.admitting_checker_run_id,old.first_queued_at,old.created_at) then raise exception 'review queue identity is immutable' using errcode='55000'; end if; if old.queue_state='closed' and new.queue_state <> 'closed' then raise exception 'closed review queue entries cannot reopen' using errcode='23514'; end if; if new.routing_generation < old.routing_generation or new.lifecycle_generation < old.lifecycle_generation then raise exception 'review queue generations cannot decrease' using errcode='23514'; end if; end if; if new.preferred_reviewer_id is not null and not exists( select 1 from actor_profiles where id=new.preferred_reviewer_id and actor_kind='human' ) then raise exception 'preferred reviewer must be human' using errcode='23514'; end if; if tg_op='UPDATE' then return new; end if; select project_id into task_project from workstream_tasks where id=new.task_id; if task_project is null or task_project <> new.project_id then raise exception 'review queue task project mismatch' using errcode='23514'; end if; select * into checker_row from checker_runs where id=new.admitting_checker_run_id; if not found or checker_row.task_id <> new.task_id or checker_row.submission_id <> new.submission_id or checker_row.submission_version <> new.submission_version then raise exception 'review queue checker lineage mismatch' using errcode='23514'; end if; if checker_row.status <> 'completed' or checker_row.routing_recommendation <> 'allow_review' or checker_row.is_current_for_submission is not true then raise exception 'review queue checker is not admissible' using errcode='23514'; end if; return new; end $function$","name":"guard_review_queue_entry"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_revision_policies_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'revision_policies rows are immutable' using errcode='55000'; end $function$","name":"guard_revision_policies_immutable"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_service_identity_migration_evidence() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'service identity migration evidence is immutable' using errcode='55000'; end $function$","name":"guard_service_identity_migration_evidence"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_delete() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission bundle admissions cannot be removed' using errcode='55000'; end; $function$","name":"guard_submission_bundle_admission_delete"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if row(old.durable_intent_id, old.pre_submit_evidence_set_id, old.put_attempt_id, old.artifact_content_id, old.verified_replica_id, old.verification_receipt_id, old.put_operation_receipt_id, old.put_observation_receipt_id, old.actor_profile_id, old.identity_link_id, old.project_id, old.task_id, old.assignment_id, old.predecessor_submission_id, old.predecessor_submission_version, old.locked_policy_context_hash, old.semantic_manifest_id, old.semantic_manifest_sha256, old.archive_sha256, old.archive_byte_count, old.ready_at, old.created_at) is distinct from row(new.durable_intent_id, new.pre_submit_evidence_set_id, new.put_attempt_id, new.artifact_content_id, new.verified_replica_id, new.verification_receipt_id, new.put_operation_receipt_id, new.put_observation_receipt_id, new.actor_profile_id, new.identity_link_id, new.project_id, new.task_id, new.assignment_id, new.predecessor_submission_id, new.predecessor_submission_version, new.locked_policy_context_hash, new.semantic_manifest_id, new.semantic_manifest_sha256, new.archive_sha256, new.archive_byte_count, new.ready_at, new.created_at) then raise exception 'submission bundle admission lineage is immutable' using errcode='55000'; end if; if old.status <> 'ready' or new.status not in ('consumed','stale') then raise exception 'invalid submission bundle admission transition' using errcode='23514'; end if; return new; end; $function$","name":"guard_submission_bundle_admission_lineage"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_admission_verified_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ declare matches integer; begin select count(*) into matches from submission_bundle_durable_intents intent join pre_submit_evidence_sets evidence on evidence.id=intent.pre_submit_evidence_set_id join artifact_put_attempts attempt on attempt.id=intent.put_attempt_id join artifact_replicas replica on replica.id=attempt.replica_id join artifact_contents content on content.id=replica.content_id join artifact_verification_jobs job on job.originating_put_attempt_id=attempt.id and job.replica_id=replica.id join artifact_verification_receipts verification on verification.verification_job_id=job.id where intent.id=new.durable_intent_id and evidence.id=new.pre_submit_evidence_set_id and attempt.id=new.put_attempt_id and content.id=new.artifact_content_id and replica.id=new.verified_replica_id and verification.id=new.verification_receipt_id and attempt.producer_request_type='submission_bundle' and attempt.producer_type='actor_profile' and attempt.producer_ref=evidence.actor_profile_id and attempt.project_id=evidence.project_id and attempt.task_id=evidence.task_id and attempt.media_type='application/zip' and content.media_type='application/zip' and attempt.status='object_confirmed' and evidence.terminal_status='passed' and evidence.eligible and replica.verification_state='verified' and replica.availability_state='available' and replica.integrity_state='valid' and verification.outcome='verified' and verification.execution_generation=job.execution_generation and verification.observed_sha256=attempt.sha256 and verification.observed_sha256=content.sha256 and verification.observed_sha256=evidence.archive_sha256 and verification.observed_byte_count=attempt.byte_count and verification.observed_byte_count=content.byte_count and verification.observed_byte_count=evidence.archive_byte_count and new.actor_profile_id=evidence.actor_profile_id and new.identity_link_id=evidence.identity_link_id and new.project_id=evidence.project_id and new.task_id=evidence.task_id and new.assignment_id=evidence.assignment_id and new.predecessor_submission_id is not distinct from evidence.predecessor_submission_id and new.predecessor_submission_version is not distinct from evidence.predecessor_submission_version and new.locked_policy_context_hash=evidence.locked_policy_context_hash and new.semantic_manifest_id=evidence.semantic_manifest_id and new.semantic_manifest_sha256=evidence.semantic_manifest_sha256 and new.archive_sha256=evidence.archive_sha256 and new.archive_byte_count=evidence.archive_byte_count and ((new.put_operation_receipt_id is not null and exists ( select 1 from artifact_operation_receipts receipt where receipt.id=new.put_operation_receipt_id and receipt.put_attempt_id=attempt.id and receipt.replica_id=replica.id and receipt.outcome='stored_pending_verification')) or (new.put_observation_receipt_id is not null and exists ( select 1 from artifact_put_observation_receipts observation where observation.id=new.put_observation_receipt_id and observation.put_attempt_id=attempt.id and observation.outcome='observed_confirmed' and observation.observed_sha256=attempt.sha256 and observation.observed_byte_count=attempt.byte_count))); if matches <> 1 then raise exception 'submission bundle admission verified lineage mismatch' using errcode='23514'; end if; return new; end; $function$","name":"guard_submission_bundle_admission_verified_lineage"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intent_put_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare request_type text; begin select producer_request_type into request_type from artifact_put_attempts where id = new.put_attempt_id for share; if request_type is distinct from 'submission_bundle' then raise exception 'submission bundle durable intent requires submission_bundle put attempt' using errcode='23514'; end if; return new; end; $function$","name":"guard_submission_bundle_durable_intent_put_attempt"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.guard_submission_bundle_durable_intents_immutable() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission_bundle_durable_intents rows are immutable' using errcode='55000'; end; $function$","name":"guard_submission_bundle_durable_intents_immutable"},{"arguments":"value jsonb","definition":"CREATE OR REPLACE FUNCTION public.project_role_availability_is_safe(value jsonb) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='object' and (select count(*)=3 from jsonb_object_keys(value)) and value ?& array['availability','reference_ids','unavailable_reason'] and project_role_reference_array_is_safe(value->'reference_ids',false) and ( (value->>'availability'='available' and jsonb_array_length(value->'reference_ids')>0 and value->'unavailable_reason'='null'::jsonb) or (value->>'availability'='unavailable' and jsonb_array_length(value->'reference_ids')=0 and value->>'unavailable_reason' in ('not_collected','source_unavailable','no_record')) ) $function$","name":"project_role_availability_is_safe"},{"arguments":"value text","definition":"CREATE OR REPLACE FUNCTION public.project_role_reason_is_safe(value text) RETURNS boolean LANGUAGE plpgsql IMMUTABLE STRICT AS $function$ declare point integer; index integer; begin if octet_length(value) not between 1 and 500 or value <> btrim(value, (E' \\t\\n\\r\\f\\013'||chr(28)||chr(29)||chr(30)||chr(31)||chr(133)||chr(160)||chr(5760)||chr(8192)||chr(8193)||chr(8194)||chr(8195)||chr(8196)||chr(8197)||chr(8198)||chr(8199)||chr(8200)||chr(8201)||chr(8202)||chr(8232)||chr(8233)||chr(8239)||chr(8287)||chr(12288))) then return false; end if; for index in 1..char_length(value) loop point := ascii(substr(value,index,1)); if point between 0 and 31 or point between 127 and 159 or point in (173,1536,1537,1538,1539,1757,1807,6068,6069,6070,6071,6072,6073,6158,8203,8204,8205,8206,8207,8234,8235,8236,8237,8238,8288,8289,8290,8291,8292,8293,8294,8295,8296,8297,8298,8299,8300,8301,8302,8303,65279) then return false; end if; end loop; return true; end $function$","name":"project_role_reason_is_safe"},{"arguments":"value jsonb, uuid_only boolean","definition":"CREATE OR REPLACE FUNCTION public.project_role_reference_array_is_safe(value jsonb, uuid_only boolean) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select jsonb_typeof(value)='array' and jsonb_array_length(value)<=20 and not exists ( select 1 from jsonb_array_elements(value) item where jsonb_typeof(item)<>'string' or case when uuid_only then not (item #>> '{}') ~ '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$' else not project_role_reference_token_is_safe(item #>> '{}') end ) $function$","name":"project_role_reference_array_is_safe"},{"arguments":"value text","definition":"CREATE OR REPLACE FUNCTION public.project_role_reference_token_is_safe(value text) RETURNS boolean LANGUAGE sql IMMUTABLE STRICT AS $function$ select value ~ '^[A-Za-z0-9][A-Za-z0-9._:/-]{0,119}$' and strpos(value, '://')=0 $function$","name":"project_role_reference_token_is_safe"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.protect_submission_policy_approval_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.approval_action_id is not null and (new.approved_by_actor_profile_id,new.approved_via_identity_link_id, new.approved_by_admin_role_grant_id,new.approval_scope_type, new.approval_scope_project_id,new.approval_action_id, new.approval_decision_event_id) is distinct from (old.approved_by_actor_profile_id,old.approved_via_identity_link_id, old.approved_by_admin_role_grant_id,old.approval_scope_type, old.approval_scope_project_id,old.approval_action_id, old.approval_decision_event_id) then raise exception 'submission-policy approval provenance is immutable' using errcode='23514'; end if; return new; end $function$","name":"protect_submission_policy_approval_provenance"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.protect_submission_policy_creation_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.created_by_service_identity, new.creation_scope_type,new.creation_scope_project_id, new.creation_action_id,new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.created_by_service_identity, old.creation_scope_type,old.creation_scope_project_id, old.creation_action_id,old.creation_decision_event_id) then raise exception 'submission-policy creation provenance is immutable' using errcode='23514'; end if; return new; end $function$","name":"protect_submission_policy_creation_provenance"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.protect_submission_policy_output_provenance() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if old.creation_action_id is not null and (new.created_by_actor_profile_id,new.created_via_identity_link_id, new.created_by_admin_role_grant_id,new.creation_scope_type, new.creation_scope_project_id,new.creation_action_id, new.creation_decision_event_id) is distinct from (old.created_by_actor_profile_id,old.created_via_identity_link_id, old.created_by_admin_role_grant_id,old.creation_scope_type, old.creation_scope_project_id,old.creation_action_id, old.creation_decision_event_id) then raise exception 'submission-policy output provenance is immutable' using errcode='23514'; end if; return new; end $function$","name":"protect_submission_policy_output_provenance"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_admin_role_grant_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'admin role grants are immutable' using errcode='55000'; end $function$","name":"reject_admin_role_grant_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_artifact_fact_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception '% rows are immutable', tg_table_name; end; $function$","name":"reject_artifact_fact_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_audit_event_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'audit events are append-only' using errcode = '55000'; end $function$","name":"reject_audit_event_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_authority_control_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority control is immutable' using errcode='55000'; end $function$","name":"reject_authority_control_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_authority_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'authority idempotency records are immutable' using errcode='55000'; end $function$","name":"reject_authority_idempotency_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_contribution_policy_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'contribution policy persistence cannot be truncated' using errcode='55000'; end; $function$","name":"reject_contribution_policy_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_guide_mutation_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide mutation custody is immutable' using errcode='55000'; end $function$","name":"reject_guide_mutation_idempotency_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_guide_source_snapshot_item_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide source snapshot items are immutable' using errcode='23514'; end $function$","name":"reject_guide_source_snapshot_item_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_pending_authority_idempotency() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists(select 1 from authority_idempotency_records where id=new.id and status='pending') then raise exception 'pending authority idempotency cannot commit' using errcode='23514'; end if; return null; end $function$","name":"reject_pending_authority_idempotency"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_policy_mutation_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'policy mutation replay is immutable' using errcode='55000'; end $function$","name":"reject_policy_mutation_replay_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_project_create_idempotency_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project create reservations are immutable' using errcode='55000'; end $function$","name":"reject_project_create_idempotency_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_project_guide_compilation_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'compilation custody is append-only'; end $function$","name":"reject_project_guide_compilation_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_project_role_history_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'project-role history cannot be truncated' using errcode='55000'; end $function$","name":"reject_project_role_history_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_review_lease_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review leases cannot be truncated' using errcode='55000'; end $function$","name":"reject_review_lease_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_review_queue_foundation_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'review queue foundation cannot be truncated' using errcode='55000'; end $function$","name":"reject_review_queue_foundation_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'submission-policy replay rows cannot be deleted'; end if; if old.status = 'reserved' and new.status = 'pending' and old.service_identity = 'workstream.project.setup' and old.action_id = 'project.submission_artifact_policy.derive' and (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.operation_id,new.project_id, new.guide_id,new.source_snapshot_id,new.policy_id,new.setup_run_id, new.setup_generation,new.setup_task_id,new.correlation_id,new.created_at, new.response_json::text,new.committed_policy_id,new.committed_effective_policy_id, new.committed_pre_submit_policy_id,new.committed_at) is not distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.operation_id,old.project_id, old.guide_id,old.source_snapshot_id,old.policy_id,old.setup_run_id, old.setup_generation,old.setup_task_id,old.correlation_id,old.created_at, old.response_json::text,old.committed_policy_id,old.committed_effective_policy_id, old.committed_pre_submit_policy_id,old.committed_at) then return new; end if; if old.status <> 'pending' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.service_identity, new.action_id,new.idempotency_key,new.request_digest, new.resource_context_digest,new.resource_context_json::text,new.operation_id, new.project_id,new.guide_id,new.source_snapshot_id,new.policy_id, new.setup_run_id,new.setup_generation,new.setup_task_id, new.correlation_id,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.service_identity, old.action_id,old.idempotency_key,old.request_digest, old.resource_context_digest,old.resource_context_json::text,old.operation_id, old.project_id,old.guide_id,old.source_snapshot_id,old.policy_id, old.setup_run_id,old.setup_generation,old.setup_task_id, old.correlation_id,old.created_at) then raise exception 'invalid submission-policy replay mutation'; end if; return new; end $function$","name":"reject_submission_policy_replay_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_submission_policy_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'submission-policy replay rows cannot be truncated'; end $function$","name":"reject_submission_policy_replay_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_mutation() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if tg_op = 'DELETE' then raise exception 'guide sufficiency replay rows are append-only'; end if; if old.status = 'committed' or new.status <> 'committed' or (new.id,new.actor_profile_id,new.identity_link_id,new.action_id, new.idempotency_key,new.request_digest, new.resource_context_digest, new.operation_id,new.project_id,new.guide_id,new.source_snapshot_id, new.setup_run_id,new.setup_generation,new.created_at) is distinct from (old.id,old.actor_profile_id,old.identity_link_id,old.action_id, old.idempotency_key,old.request_digest, old.resource_context_digest, old.operation_id,old.project_id,old.guide_id,old.source_snapshot_id, old.setup_run_id,old.setup_generation,old.created_at) then raise exception 'invalid guide sufficiency replay mutation'; end if; return new; end $function$","name":"reject_sufficiency_replay_mutation"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.reject_sufficiency_replay_truncate() RETURNS trigger LANGUAGE plpgsql AS $function$ begin raise exception 'guide sufficiency replay rows are append-only'; end $function$","name":"reject_sufficiency_replay_truncate"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.require_human_actor_profile_reference() RETURNS trigger LANGUAGE plpgsql AS $function$ declare referenced_id text; referenced_kind text; begin if tg_nargs <> 1 or tg_argv[0] is null or not (to_jsonb(new) ? tg_argv[0]) then raise exception 'human actor reference trigger is misconfigured' using errcode='55000'; end if; referenced_id := to_jsonb(new) ->> tg_argv[0]; if referenced_id is null then return new; end if; select profile.actor_kind into referenced_kind from public.actor_profiles profile where profile.id=referenced_id; if not found then return new; end if; if referenced_kind <> 'human' then raise exception 'actor reference must identify a human profile' using errcode='23514', constraint='require_human_actor_profile_reference'; end if; return new; end $function$","name":"require_human_actor_profile_reference"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.set_authority_audit_database_time() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if new.event_domain = 'authority' then if new.invalidation_cause_event_id is not null and not exists ( select 1 from audit_events where id = new.invalidation_cause_event_id and event_domain = 'authority' ) then raise exception 'invalid authority invalidation cause' using errcode = '23503'; end if; new.occurred_at = statement_timestamp(); else new.occurred_at = null; end if; return new; end $function$","name":"set_authority_audit_database_time"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_artifact_binding_history() RETURNS trigger LANGUAGE plpgsql AS $function$ declare predecessor artifact_bindings%rowtype; begin if new.scope_version = 1 then return new; end if; select * into predecessor from artifact_bindings where id = new.supersedes_binding_id; if not found or predecessor.project_id != new.project_id or predecessor.resource_type != new.resource_type or predecessor.resource_id != new.resource_id or predecessor.logical_role != new.logical_role or predecessor.scope_version + 1 != new.scope_version then raise exception 'artifact binding predecessor is invalid'; end if; return new; end; $function$","name":"validate_artifact_binding_history"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_artifact_recovery_attempt() RETURNS trigger LANGUAGE plpgsql AS $function$ declare source_row artifact_verification_jobs%rowtype; retry_row artifact_verification_jobs%rowtype; expected_parent text; begin if tg_op = 'DELETE' then raise exception 'artifact recovery attempts are append-only' using errcode='55000'; end if; if tg_op = 'UPDATE' and ( to_jsonb(new) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] is distinct from to_jsonb(old) - array['status','terminal_result_code','terminal_audit_event_id', 'terminal_at','cas_version','updated_at'] ) then raise exception 'artifact recovery identity is immutable' using errcode='55000'; end if; select * into source_row from artifact_verification_jobs where id=new.source_verification_job_id; select * into retry_row from artifact_verification_jobs where id=new.retry_verification_job_id; if source_row.id is null or retry_row.id is null or source_row.status <> 'provider_unavailable' or source_row.terminal_result_code <> 'provider_unavailable' or source_row.terminal_at is null or source_row.next_run_at is not null or source_row.executor_id is not null or source_row.attempt_count < source_row.maximum_attempts or retry_row.parent_verification_job_id <> source_row.id or retry_row.originating_put_attempt_id <> source_row.originating_put_attempt_id or retry_row.replica_id <> source_row.replica_id then raise exception 'invalid artifact recovery verification lineage' using errcode='23514'; end if; if (tg_op = 'INSERT' and (retry_row.status <> 'pending' or retry_row.attempt_count <> 0)) or (tg_op = 'UPDATE' and ( retry_row.status <> new.terminal_result_code or retry_row.terminal_at is null )) then raise exception 'invalid artifact recovery retry state' using errcode='23514'; end if; select id into expected_parent from artifact_recovery_attempts where retry_verification_job_id=source_row.id; if new.parent_recovery_attempt_id is distinct from expected_parent then raise exception 'invalid artifact recovery parent chain' using errcode='23514'; end if; if not exists ( select 1 from audit_events where id=new.initiation_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryInitiated' ) then raise exception 'invalid artifact recovery initiation audit' using errcode='23514'; end if; if new.terminal_audit_event_id is not null and not exists ( select 1 from audit_events where id=new.terminal_audit_event_id and entity_type='artifact_recovery_attempt' and entity_id=new.id and event_type='ArtifactRecoveryCompleted' ) then raise exception 'invalid artifact recovery terminal audit' using errcode='23514'; end if; return new; end $function$","name":"validate_artifact_recovery_attempt"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_artifact_verification_lineage() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if ( old.parent_verification_job_id is not null or exists( select 1 from artifact_recovery_attempts where source_verification_job_id = old.id or retry_verification_job_id = old.id ) ) and ( old.originating_put_attempt_id is distinct from new.originating_put_attempt_id or old.replica_id is distinct from new.replica_id or old.parent_verification_job_id is distinct from new.parent_verification_job_id ) then raise exception 'artifact verification lineage is immutable' using errcode='55000'; end if; return new; end $function$","name":"validate_artifact_verification_lineage"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_bootstrap_authority_state() RETURNS trigger LANGUAGE plpgsql AS $function$ declare control authority_control%rowtype; bootstrap_count bigint; referenced_bootstrap boolean; begin select * into control from authority_control where id=1; if not found then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; select count(*) into bootstrap_count from admin_role_grants where granted_by_system_principal='workstream:system:bootstrap'; referenced_bootstrap := exists( select 1 from admin_role_grants where id=control.bootstrap_grant_id and granted_by_system_principal='workstream:system:bootstrap' ); if (not control.bootstrap_completed and (control.bootstrap_grant_id is not null or control.version <> 0 or bootstrap_count <> 0)) or (control.bootstrap_completed and (control.bootstrap_grant_id is null or control.version <> 1 or bootstrap_count <> 1 or not referenced_bootstrap)) then raise exception 'bootstrap grant/control invariant violated' using errcode='23514'; end if; return null; end $function$","name":"validate_bootstrap_authority_state"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_canonical_actor_link() RETURNS trigger LANGUAGE plpgsql AS $function$ declare profile_row actor_profiles%rowtype; link_count integer; begin if tg_table_name='actor_profiles' then select count(*) into link_count from actor_identity_links where actor_profile_id=new.id; if link_count <> 1 then raise exception 'actor profile requires exactly one identity link' using errcode='23514'; end if; if not exists(select 1 from actor_identity_links where actor_profile_id=new.id and subject_kind=new.actor_kind) then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; else select * into profile_row from actor_profiles where id=new.actor_profile_id; if not found or profile_row.actor_kind <> new.subject_kind then raise exception 'actor and identity kind mismatch' using errcode='23514'; end if; end if; return new; end $function$","name":"validate_canonical_actor_link"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_contribution_policy_graph() RETURNS trigger LANGUAGE plpgsql AS $function$ begin if exists ( select 1 from contribution_policy_versions v where v.status in ('published','retired') and ( (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='accepted_submission') <> 1 or (select count(*) from contribution_rules r where r.contribution_policy_version_id=v.id and r.contribution_type='completed_review') <> 1 or exists ( select 1 from contribution_rules r where r.contribution_policy_version_id=v.id and ( (r.compensation_mode='unpaid' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) <> 0) or (r.compensation_mode='compensated' and (select count(*) from contribution_award_definitions d where d.contribution_rule_id=r.id) not between 1 and 2) ) ) ) ) then raise exception 'published contribution policy graph is incomplete' using errcode='23514'; end if; if exists ( select 1 from contribution_policies p left join contribution_policy_versions v on v.id=p.current_published_version_id and v.contribution_policy_id=p.id and v.project_id=p.project_id where p.status='active' and (v.id is null or v.status <> 'published') ) then raise exception 'active contribution policy selector is invalid' using errcode='23514'; end if; return null; end; $function$","name":"validate_contribution_policy_graph"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_guide_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation guide_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_resource text; product_generation integer; begin if tg_table_name='guide_mutation_idempotency_records' then select * into reservation from guide_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending guide mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id in ('project.guide.create','project.guide.update') then select last_mutated_by_actor_profile_id,last_mutated_via_identity_link_id, last_mutated_by_admin_role_grant_id,last_mutation_action_id, last_mutation_scope_type,last_mutation_scope_project_id, last_authorization_decision_event_id,project_id,id,mutation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from project_guides where id=reservation.resource_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,project_id,id,creation_generation into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_resource,product_generation from guide_source_snapshots where id=reservation.resource_id; end if; elsif tg_table_name='project_guides' then if tg_op='UPDATE' and (new.content_markdown is distinct from old.content_markdown or new.change_summary is distinct from old.change_summary) and (new.mutation_generation is not distinct from old.mutation_generation or new.last_authorization_decision_event_id is not distinct from old.last_authorization_decision_event_id) then raise exception 'guide content mutation requires fresh custody' using errcode='23514'; end if; if new.mutation_generation is null then if tg_op='INSERT' then raise exception 'new guides require mutation authority' using errcode='23514'; end if; return null; end if; actor_id:=new.last_mutated_by_actor_profile_id; link_id:=new.last_mutated_via_identity_link_id; grant_id:=new.last_mutated_by_admin_role_grant_id; action_value:=new.last_mutation_action_id; scope_type:=new.last_mutation_scope_type; scope_project:=new.last_mutation_scope_project_id; decision_id:=new.last_authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.mutation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id=new.last_mutation_action_id and operation_generation=new.mutation_generation and status='committed'; elsif tg_table_name='guide_source_snapshots' then if tg_op='UPDATE' and (new.project_id,new.guide_id,new.guide_version, new.manifest_schema_version,new.manifest_json::jsonb,new.bundle_hash,new.captured_by) is distinct from (old.project_id,old.guide_id,old.guide_version, old.manifest_schema_version,old.manifest_json::jsonb,old.bundle_hash,old.captured_by) then raise exception 'guide source snapshot content is immutable' using errcode='23514'; end if; if new.creation_generation is null then raise exception 'new source snapshots require creation authority' using errcode='23514'; end if; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.id; product_generation:=new.creation_generation; select * into reservation from guide_mutation_idempotency_records where resource_id=new.id and action_id='project.guide_source_snapshot.create' and operation_generation=new.creation_generation and status='committed'; else if new.authorization_action_id is null then return null; end if; actor_id:=new.authorized_by_actor_profile_id; link_id:=new.authorized_via_identity_link_id; grant_id:=new.authorized_by_admin_role_grant_id; action_value:=new.authorization_action_id; scope_type:=new.authorization_scope_type; scope_project:=new.authorization_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_resource:=new.source_snapshot_id; select * into reservation from guide_mutation_idempotency_records where setup_run_id=new.id and action_id='project.guide_source_snapshot.create' and status='committed'; product_generation:=reservation.operation_generation; end if; if reservation.id is null or product_resource is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.resource_id is distinct from product_resource or reservation.operation_generation is distinct from product_generation or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'guide mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.guide.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'guide mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_guide_mutation_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_guide_source_snapshot_items() RETURNS trigger LANGUAGE plpgsql AS $function$ declare expected jsonb; actual jsonb; reservation guide_mutation_idempotency_records%rowtype; begin select snapshot.manifest_json::jsonb->'items' into expected from guide_source_snapshots snapshot where snapshot.id=new.source_snapshot_id; if expected is null then raise exception 'guide source snapshot item parent is unavailable' using errcode='23514'; end if; select coalesce(jsonb_agg(jsonb_build_object( 'item_id',id,'item_order',item_order,'source_kind',source_kind, 'source_label',source_label,'ingestion_adapter',ingestion_adapter, 'media_type',media_type) order by item_order),'[]'::jsonb) into actual from guide_source_snapshot_items where source_snapshot_id=new.source_snapshot_id; if actual is distinct from expected then raise exception 'guide source snapshot items do not match manifest' using errcode='23514'; end if; select r.* into reservation from guide_mutation_idempotency_records r join guide_source_snapshots s on s.id=r.resource_id where s.id=new.source_snapshot_id and r.action_id='project.guide_source_snapshot.create' and r.operation_generation=s.creation_generation and r.status='committed'; if reservation.id is null then raise exception 'guide source snapshot item custody mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_guide_source_snapshot_items"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_linked_authority_event() RETURNS trigger LANGUAGE plpgsql AS $function$ declare record_row authority_idempotency_records%rowtype; cause_row audit_events%rowtype; expected_permission text; expected_resource text; expected_invalidation_resource text; expected_invalidation_id text; valid_success boolean; begin if new.event_domain <> 'authority' then return new; end if; valid_success := new.event_type in ( 'ServiceActorProvisioned','AdminRoleGrantIssued','AdminRoleGrantRevoked', 'ProjectRoleQualificationSnapshotCaptured','ProjectRoleGrantIssued','ProjectRoleGrantRevoked', 'ActorProfileSuspended','ActorProfileReactivated','ActorProfileDeactivated', 'ActorIdentityLinkRevoked','ActorIdentityLinkReactivated'); if not valid_success and new.event_type <> 'AuthorityInvalidationRequested' then if new.idempotency_reference is not null then raise exception 'invalid authority idempotency event' using errcode='23514'; end if; return new; end if; if new.idempotency_reference is null then raise exception 'authority event requires idempotency reference' using errcode='23514'; end if; select * into record_row from authority_idempotency_records where id=new.idempotency_reference and actor_ref_kind=new.actor_ref_kind and actor_ref=new.actor_id; if not found then raise exception 'invalid authority idempotency reference' using errcode='23503'; end if; if record_row.status <> 'pending' then raise exception 'committed authority idempotency is closed' using errcode='23514'; end if; expected_permission := case record_row.operation when 'service_actor.create' then 'actor.service.provision' when 'admin_role_grant.issue' then 'admin_role.grant' when 'admin_role_grant.revoke' then 'admin_role.revoke' when 'project_role_grant.issue' then 'project.role_grant.manage' when 'project_role_grant.revoke' then 'project.role_grant.manage' when 'actor_profile.suspend' then 'actor.profile.suspend' when 'actor_profile.reactivate' then 'actor.profile.reactivate' when 'actor_profile.deactivate' then 'actor.profile.deactivate' when 'actor_identity_link.revoke' then 'actor.identity_link.revoke' when 'actor_identity_link.reactivate' then 'actor.identity_link.reactivate' end; expected_resource := case when record_row.operation='service_actor.create' or record_row.operation like 'actor_profile.%' then 'actor_profile' when record_row.operation like 'admin_role_grant.%' then 'admin_role_grant' when record_row.operation like 'project_role_grant.%' then 'project_role_grant' else 'actor_identity_link' end; if new.permission_id <> expected_permission or new.resource_id is null then raise exception 'authority event does not match operation' using errcode='23514'; end if; if new.event_type='ProjectRoleQualificationSnapshotCaptured' then if record_row.operation <> 'project_role_grant.issue' or new.resource_type <> 'qualification_snapshot' or new.entity_type <> 'qualification_snapshot' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'qualification_snapshot' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or exists(select 1 from audit_events where idempotency_reference=record_row.id) then raise exception 'invalid project role qualification evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='ProjectRoleGrantIssued' then select * into cause_row from audit_events where idempotency_reference=record_row.id and event_type='ProjectRoleQualificationSnapshotCaptured'; if not found or (select count(*) from audit_events where idempotency_reference=record_row.id) <> 1 or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.matched_grant_id is distinct from new.matched_grant_id or new.resource_type <> 'project_role_grant' or new.entity_type <> 'project_role_grant' or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null then raise exception 'invalid project role issue evidence' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.revoke' and new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; if not found or cause_row.event_type <> 'ProjectRoleGrantRevoked' or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or cause_row.target_actor_ref_kind is distinct from 'actor_profile' or cause_row.target_actor_ref_kind is distinct from new.target_actor_ref_kind or cause_row.target_actor_ref is distinct from new.target_actor_ref or cause_row.resource_type <> 'project_role_grant' or cause_row.target_ref_kind <> 'project_role_grant' or cause_row.target_ref_id is distinct from cause_row.resource_id or new.resource_type <> 'project_role_grant' or new.resource_id is distinct from cause_row.resource_id or new.target_ref_kind is distinct from 'project_role_grant' or new.target_ref_id is distinct from cause_row.resource_id or new.invalidation_target_kind <> 'project_role_grant' or new.invalidation_target_ref is distinct from cause_row.resource_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or new.before_facts::jsonb->>'effective' <> 'true' or new.after_facts::jsonb->>'effective' <> 'false' or new.before_facts::jsonb->>'role' not in ('submitter','reviewer','adjudicator') or new.before_facts::jsonb->>'role' is distinct from new.after_facts::jsonb->>'role' or new.before_facts::jsonb->>'scope_type' <> 'project' or new.before_facts::jsonb->>'scope_id' is distinct from new.project_id or new.before_facts::jsonb->>'scope_id' is distinct from new.after_facts::jsonb->>'scope_id' or new.before_facts::jsonb->>'future_obligation' is distinct from new.after_facts::jsonb->>'future_obligation' or (new.before_facts::jsonb->>'role'='submitter' and new.before_facts::jsonb->>'future_obligation'<>'auth13_assignment') or (new.before_facts::jsonb->>'role'='reviewer' and new.before_facts::jsonb->>'future_obligation'<>'rev_reviewer_obligation') or (new.before_facts::jsonb->>'role'='adjudicator' and new.before_facts::jsonb->>'future_obligation'<>'none') then raise exception 'invalid project role revoke invalidation' using errcode='23514'; end if; elsif record_row.operation='project_role_grant.issue' and new.event_type='AuthorityInvalidationRequested' then raise exception 'project role issue forbids invalidation' using errcode='23514'; elsif new.event_type='AuthorityInvalidationRequested' then select * into cause_row from audit_events where id=new.invalidation_cause_event_id; expected_invalidation_resource := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then 'actor_profile' else expected_resource end; expected_invalidation_id := case when record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') then cause_row.target_actor_ref else cause_row.resource_id end; if not found or cause_row.idempotency_reference is distinct from record_row.id or cause_row.actor_ref_kind is distinct from new.actor_ref_kind or cause_row.actor_id is distinct from new.actor_id or cause_row.permission_id is distinct from new.permission_id or cause_row.resource_type is distinct from expected_resource or new.resource_type is distinct from expected_invalidation_resource or new.resource_id is distinct from expected_invalidation_id or new.invalidation_target_kind is distinct from expected_invalidation_resource or new.invalidation_target_ref is distinct from expected_invalidation_id or cause_row.target_ref_kind is distinct from cause_row.resource_type or cause_row.target_ref_id is distinct from cause_row.resource_id or cause_row.request_id is distinct from new.request_id or cause_row.correlation_id is distinct from new.correlation_id or cause_row.project_id is distinct from new.project_id or new.entity_type <> 'authority_invalidation' or new.entity_id <> new.id or (record_row.operation in ('admin_role_grant.issue','admin_role_grant.revoke','actor_identity_link.revoke','actor_identity_link.reactivate') and (cause_row.target_actor_ref_kind <> 'actor_profile' or cause_row.target_actor_ref is null)) or (record_row.operation in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": false}'::jsonb or new.after_facts::jsonb <> '{\"effective\": true}'::jsonb)) or (record_row.operation not in ('admin_role_grant.issue','actor_profile.reactivate','actor_identity_link.reactivate') and (new.before_facts::jsonb <> '{\"effective\": true}'::jsonb or new.after_facts::jsonb <> '{\"effective\": false}'::jsonb)) or not ( (record_row.operation='service_actor.create' and cause_row.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and cause_row.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and cause_row.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and cause_row.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and cause_row.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and cause_row.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and cause_row.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and cause_row.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and cause_row.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and cause_row.event_type='ActorIdentityLinkReactivated')) then raise exception 'invalid linked authority cause' using errcode='23514'; end if; else if new.resource_type <> expected_resource or new.entity_type <> expected_resource or new.entity_id <> new.resource_id or new.target_ref_kind is distinct from expected_resource or new.target_ref_id is distinct from new.resource_id or new.invalidation_cause_event_id is not null or new.invalidation_target_kind is not null or new.invalidation_target_ref is not null or not ( (record_row.operation='service_actor.create' and new.event_type='ServiceActorProvisioned') or (record_row.operation='admin_role_grant.issue' and new.event_type='AdminRoleGrantIssued') or (record_row.operation='admin_role_grant.revoke' and new.event_type='AdminRoleGrantRevoked') or (record_row.operation='project_role_grant.issue' and new.event_type in ('ProjectRoleGrantIssued')) or (record_row.operation='project_role_grant.revoke' and new.event_type='ProjectRoleGrantRevoked') or (record_row.operation='actor_profile.suspend' and new.event_type='ActorProfileSuspended') or (record_row.operation='actor_profile.reactivate' and new.event_type='ActorProfileReactivated') or (record_row.operation='actor_profile.deactivate' and new.event_type='ActorProfileDeactivated') or (record_row.operation='actor_identity_link.revoke' and new.event_type='ActorIdentityLinkRevoked') or (record_row.operation='actor_identity_link.reactivate' and new.event_type='ActorIdentityLinkReactivated')) then raise exception 'authority success event does not match operation' using errcode='23514'; end if; end if; return new; end $function$","name":"validate_linked_authority_event"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_policy_mutation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id text; link_id text; grant_id uuid; action_value text; scope_type text; scope_project text; decision_id text; product_project text; product_guide text; product_id text; product_generation integer; product_hash text; predecessor_id text; predecessor_hash text; selector_id text; selector_generation integer; selector_hash text; predecessor_valid boolean; begin if tg_table_name='policy_mutation_idempotency_records' then select * into reservation from policy_mutation_idempotency_records where id=new.id; if reservation.status<>'committed' then raise exception 'pending policy mutation custody cannot commit' using errcode='23514'; end if; if reservation.action_id='project.review_policy.update' then select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_review_policy_id, g.selected_review_policy_generation,g.selected_review_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from review_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; else select created_by_actor_profile_id,created_via_identity_link_id, created_by_admin_role_grant_id,creation_action_id, creation_scope_type,creation_scope_project_id, authorization_decision_event_id,p.project_id,g.id,p.id, p.policy_generation,p.policy_hash,p.supersedes_policy_id, p.predecessor_policy_hash,g.selected_revision_policy_id, g.selected_revision_policy_generation,g.selected_revision_policy_hash into actor_id,link_id,grant_id,action_value,scope_type,scope_project, decision_id,product_project,product_guide,product_id,product_generation, product_hash,predecessor_id,predecessor_hash,selector_id, selector_generation,selector_hash from revision_policies p join project_guides g on g.project_id=p.project_id and g.version=p.guide_version where p.id=reservation.policy_id and g.id=reservation.guide_id; end if; else actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; action_value:=new.creation_action_id; scope_type:=new.creation_scope_type; scope_project:=new.creation_scope_project_id; decision_id:=new.authorization_decision_event_id; product_project:=new.project_id; product_id:=new.id; product_generation:=new.policy_generation; product_hash:=new.policy_hash; predecessor_id:=new.supersedes_policy_id; predecessor_hash:=new.predecessor_policy_hash; if tg_table_name='review_policies' then select g.id,g.selected_review_policy_id,g.selected_review_policy_generation, g.selected_review_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; else select g.id,g.selected_revision_policy_id,g.selected_revision_policy_generation, g.selected_revision_policy_hash into product_guide,selector_id,selector_generation,selector_hash from project_guides g where g.project_id=new.project_id and g.version=new.guide_version; end if; select r.* into reservation from policy_mutation_idempotency_records r where r.policy_id=new.id and r.action_id=new.creation_action_id and r.policy_generation=new.policy_generation and r.status='committed'; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.guide_id is distinct from product_guide or reservation.policy_id is distinct from product_id or reservation.policy_generation is distinct from product_generation or reservation.policy_hash is distinct from product_hash or selector_id is distinct from product_id or selector_generation is distinct from product_generation or selector_hash is distinct from product_hash or scope_type not in ('system','project') or (scope_type='project' and scope_project is distinct from product_project) or (scope_type='system' and scope_project is not null) then raise exception 'policy mutation custody mismatch' using errcode='23514'; end if; if product_generation=1 then predecessor_valid:=predecessor_id is null and predecessor_hash is null; elsif reservation.action_id='project.review_policy.update' then select exists(select 1 from review_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; else select exists(select 1 from revision_policies prior where prior.id=predecessor_id and prior.project_id=product_project and prior.guide_version=(select version from project_guides where id=product_guide) and prior.policy_generation=product_generation-1 and prior.policy_hash=predecessor_hash) into predecessor_valid; end if; if predecessor_valid is not true then raise exception 'policy mutation lineage mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.review_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project' or evidence.resource_id is distinct from product_project or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from product_project or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'policy mutation evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_policy_mutation_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_project_create_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare project_row projects%rowtype; reservation project_create_idempotency_records%rowtype; evidence audit_events%rowtype; begin if tg_table_name = 'projects' then if tg_op = 'INSERT' and new.creation_action_id is null then raise exception 'new projects require creation authority' using errcode='23514'; end if; if new.creation_action_id is null then return null; end if; project_row := new; select * into reservation from project_create_idempotency_records where project_id=project_row.id and status='committed'; else select * into reservation from project_create_idempotency_records where id=new.id; if reservation.status <> 'committed' then raise exception 'pending project create reservation cannot commit' using errcode='23514'; end if; select * into project_row from projects where id=reservation.project_id; end if; if project_row.id is null or reservation.id is null or project_row.created_by_actor_profile_id is distinct from reservation.actor_profile_id or project_row.created_via_identity_link_id is distinct from reservation.identity_link_id or project_row.creation_action_id is distinct from reservation.action_id then raise exception 'project create custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=project_row.authorization_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from project_row.created_by_actor_profile_id or evidence.matched_grant_id is distinct from project_row.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.create' or evidence.action_id is distinct from 'project.create' or evidence.resource_type is distinct from 'project_create_operation' or evidence.resource_id is distinct from reservation.operation_id::text or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from project_row.id or evidence.after_facts->>'allowed' is distinct from 'true' or coalesce( evidence.after_facts->>'resource_context_digest' !~ '^sha256:[0-9a-f]{64}$', true ) then raise exception 'project create evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_project_create_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_review_active_lease() RETURNS trigger LANGUAGE plpgsql AS $function$ declare queue_row review_queue_entries%rowtype; active_count integer; begin if tg_table_name='review_queue_entries' then queue_row := new; else select * into queue_row from review_queue_entries where id=coalesce(new.review_queue_entry_id,old.review_queue_entry_id); end if; if not found and tg_table_name='review_leases' then raise exception 'review lease queue is missing' using errcode='23514'; end if; select count(*) into active_count from review_leases where review_queue_entry_id=queue_row.id and status='active'; if queue_row.queue_state='leased' then if queue_row.active_lease_id is null or active_count <> 1 or not exists( select 1 from review_leases where id=queue_row.active_lease_id and review_queue_entry_id=queue_row.id and status='active' ) then raise exception 'leased queue must identify its active lease' using errcode='23514'; end if; elsif queue_row.active_lease_id is not null or active_count <> 0 then raise exception 'non-leased queue cannot retain an active lease' using errcode='23514'; end if; return null; end $function$","name":"validate_review_active_lease"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_submission_policy_authority_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; actor_id varchar; link_id varchar; grant_id uuid; service_id varchar; action_value varchar; decision_id varchar; product_project varchar; product_id varchar; approval_outputs_valid boolean; begin if tg_table_name='submission_policy_mutation_idempotency_records' then if new.status='pending' then return null; end if; reservation:=new; select project_id,id, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_actor_profile_id else created_by_actor_profile_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_via_identity_link_id else created_via_identity_link_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approved_by_admin_role_grant_id else created_by_admin_role_grant_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then null else created_by_service_identity end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_action_id else creation_action_id end, case when reservation.action_id='project.submission_artifact_policy.approve' then approval_decision_event_id else creation_decision_event_id end into product_project,product_id,actor_id,link_id,grant_id,service_id, action_value,decision_id from submission_artifact_policies where id=reservation.committed_policy_id; if reservation.action_id='project.submission_artifact_policy.approve' then select exists( select 1 from submission_artifact_policies s join effective_project_submission_artifact_policies e on e.id=reservation.committed_effective_policy_id and e.submission_artifact_policy_id=s.id and e.submission_artifact_policy_hash=s.policy_hash join pre_submit_checker_policies p on p.id=reservation.committed_pre_submit_policy_id and p.project_id=e.project_id where s.id=reservation.committed_policy_id and s.id=reservation.policy_id and s.guide_id=reservation.guide_id and s.source_snapshot_id=reservation.source_snapshot_id and s.guide_version=reservation.resource_context_json->>'guide_version' and s.policy_hash=reservation.resource_context_json->>'policy_digest' and e.effective_policy_hash= reservation.resource_context_json->>'effective_output_digest' and p.compiled_bundle_hash= reservation.resource_context_json->>'compiled_pre_submit_output_digest' and e.project_id=reservation.project_id and e.guide_id=s.guide_id and p.guide_id=s.guide_id and e.guide_version=s.guide_version and p.guide_version=s.guide_version and e.source_snapshot_id=s.source_snapshot_id and p.source_snapshot_id=s.source_snapshot_id and e.source_snapshot_hash=s.source_snapshot_hash and p.source_snapshot_hash=s.source_snapshot_hash and e.submission_artifact_policy_id=reservation.committed_policy_id and p.effective_policy_id=e.id and p.effective_policy_hash=e.effective_policy_hash and e.created_by_actor_profile_id=reservation.actor_profile_id and p.created_by_actor_profile_id=reservation.actor_profile_id and e.created_via_identity_link_id=reservation.identity_link_id and p.created_via_identity_link_id=reservation.identity_link_id and e.created_by_admin_role_grant_id=grant_id and p.created_by_admin_role_grant_id=grant_id and e.creation_scope_project_id=reservation.project_id and p.creation_scope_project_id=reservation.project_id and e.creation_action_id=reservation.action_id and p.creation_action_id=reservation.action_id and e.creation_decision_event_id=decision_id and p.creation_decision_event_id=decision_id ) into approval_outputs_valid; if approval_outputs_valid is not true then raise exception 'submission-policy approval output custody mismatch' using errcode='23514'; end if; end if; elsif tg_table_name='submission_artifact_policies' then if new.creation_action_id is null and new.approval_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null or new.approved_by_actor_profile_id is not null or new.approved_via_identity_link_id is not null or new.approved_by_admin_role_grant_id is not null or new.approval_scope_type is not null or new.approval_scope_project_id is not null or new.approval_decision_event_id is not null then raise exception 'partial submission-policy provenance' using errcode='23514'; end if; return null; end if; if new.approval_action_id is not null then select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.approval_action_id and status='committed'; actor_id:=new.approved_by_actor_profile_id; link_id:=new.approved_via_identity_link_id; grant_id:=new.approved_by_admin_role_grant_id; service_id:=null; action_value:=new.approval_action_id; decision_id:=new.approval_decision_event_id; else select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=new.created_by_service_identity; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; end if; product_project:=new.project_id; product_id:=new.id; elsif tg_table_name='effective_project_submission_artifact_policies' then if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial effective-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_effective_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; else if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial pre-submit-policy provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_pre_submit_policy_id=new.id and status='committed'; actor_id:=new.created_by_actor_profile_id; link_id:=new.created_via_identity_link_id; grant_id:=new.created_by_admin_role_grant_id; service_id:=null; action_value:=new.creation_action_id; decision_id:=new.creation_decision_event_id; product_project:=new.project_id; product_id:=reservation.committed_policy_id; end if; if reservation.id is null or product_id is null or reservation.actor_profile_id is distinct from actor_id or reservation.identity_link_id is distinct from link_id or reservation.action_id is distinct from action_value or reservation.project_id is distinct from product_project or reservation.committed_policy_id is distinct from product_id or reservation.service_identity is distinct from service_id then raise exception 'submission-policy mutation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=decision_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from actor_id or evidence.matched_grant_id is distinct from grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from action_value or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from product_id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy authorization evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_submission_policy_authority_custody"},{"arguments":"","definition":"CREATE OR REPLACE FUNCTION public.validate_submission_policy_creation_custody() RETURNS trigger LANGUAGE plpgsql AS $function$ declare reservation submission_policy_mutation_idempotency_records%rowtype; evidence audit_events%rowtype; begin if new.creation_action_id is null then if new.created_by_actor_profile_id is not null or new.created_via_identity_link_id is not null or new.created_by_admin_role_grant_id is not null or new.created_by_service_identity is not null or new.creation_scope_type is not null or new.creation_scope_project_id is not null or new.creation_decision_event_id is not null then raise exception 'partial submission-policy creation provenance' using errcode='23514'; end if; return null; end if; select * into reservation from submission_policy_mutation_idempotency_records where committed_policy_id=new.id and action_id=new.creation_action_id and status='committed'; if reservation.id is null or reservation.actor_profile_id is distinct from new.created_by_actor_profile_id or reservation.identity_link_id is distinct from new.created_via_identity_link_id or reservation.service_identity is distinct from new.created_by_service_identity or reservation.project_id is distinct from new.project_id or reservation.policy_id is distinct from new.id or reservation.guide_id is distinct from new.guide_id or reservation.source_snapshot_id is distinct from new.source_snapshot_id or reservation.resource_context_json->>'guide_version' is distinct from new.guide_version then raise exception 'submission-policy creation custody mismatch' using errcode='23514'; end if; select * into evidence from audit_events where id=new.creation_decision_event_id; if evidence.id is null or evidence.event_domain is distinct from 'authority' or evidence.event_type is distinct from 'SensitiveAuthorizationAllowed' or evidence.denial_code is not null or evidence.actor_ref_kind is distinct from 'actor_profile' or evidence.actor_id is distinct from new.created_by_actor_profile_id or evidence.matched_grant_id is distinct from new.created_by_admin_role_grant_id::text or evidence.permission_id is distinct from 'project.effective_policy.manage' or evidence.action_id is distinct from new.creation_action_id or evidence.resource_type is distinct from 'project_submission_artifact_policy_mutation' or evidence.resource_id is distinct from new.id or evidence.project_id is distinct from reservation.project_id or evidence.target_ref_kind is distinct from 'project' or evidence.target_ref_id is distinct from reservation.project_id or evidence.after_facts->>'allowed' is distinct from 'true' or evidence.after_facts->>'resource_context_digest' is distinct from reservation.resource_context_digest then raise exception 'submission-policy creation evidence mismatch' using errcode='23514'; end if; return null; end $function$","name":"validate_submission_policy_creation_custody"}],"sequences":[{"cache_size":1,"cycle":false,"data_type":"integer","increment_by":1,"is_called":false,"last_value":1,"max_value":2147483647,"min_value":1,"name":"actor_profile_migration_state_id_seq","start_value":1},{"cache_size":1,"cycle":false,"data_type":"smallint","increment_by":1,"is_called":false,"last_value":1,"max_value":32767,"min_value":1,"name":"authority_control_id_seq","start_value":1}],"tables":[{"force_row_security":false,"kind":"r","name":"actor_identity_links","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"actor_profile_migration_state","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"actor_profiles","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"admin_role_grants","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"api_rate_control_counters","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_admission_charges","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_admission_scopes","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_bindings","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_contents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_operation_receipts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_put_attempt_charges","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_put_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_put_observation_receipts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_recovery_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_replicas","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_storage_namespaces","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_verification_jobs","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"artifact_verification_receipts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"audit_events","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"authority_control","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"authority_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"checker_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"checker_results","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"checker_runs","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_award_definitions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_policy_versions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"contribution_rules","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"effective_project_submission_artifact_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"evidence_items","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_artifact_bindings","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_artifact_incidents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_artifact_ingests","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extracted_contents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extraction_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extraction_retry_budgets","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_extraction_usages","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_format_classifications","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_snapshot_items","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_source_snapshots","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_sufficiency_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_sufficiency_report_source_usages","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"guide_sufficiency_reports","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"iso_4217_currency_codes","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"legacy_actor_identities","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"legacy_workflow_eligibility","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"outbox_events","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"payment_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"policy_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"pre_submit_checker_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"pre_submit_evidence_results","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"pre_submit_evidence_sets","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_compensation_adapter_bindings","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_compensation_units","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_create_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_guide_compilation_attempts","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_guide_compilations","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_guides","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_role_grants","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_role_qualification_snapshots","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"project_setup_runs","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"projects","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_admission_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_leases","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"review_queue_entries","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"revision_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_artifact_policies","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_bundle_admissions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_bundle_durable_intents","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submission_policy_mutation_idempotency_records","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"submissions","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"task_assignments","persistence":"p","row_security":false},{"force_row_security":false,"kind":"r","name":"workstream_tasks","persistence":"p","row_security":false}],"triggers":[{"definition":"CREATE TRIGGER actor_identity_link_history_guard BEFORE DELETE OR UPDATE ON actor_identity_links FOR EACH ROW EXECUTE FUNCTION guard_actor_identity_link_history()","enabled":"O","name":"actor_identity_link_history_guard","table_name":"actor_identity_links"},{"definition":"CREATE CONSTRAINT TRIGGER actor_identity_link_profile_guard AFTER INSERT OR UPDATE ON actor_identity_links DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()","enabled":"O","name":"actor_identity_link_profile_guard","table_name":"actor_identity_links"},{"definition":"CREATE TRIGGER service_identity_migration_evidence_row_guard BEFORE DELETE OR UPDATE ON actor_profile_migration_state FOR EACH ROW EXECUTE FUNCTION guard_service_identity_migration_evidence()","enabled":"O","name":"service_identity_migration_evidence_row_guard","table_name":"actor_profile_migration_state"},{"definition":"CREATE TRIGGER service_identity_migration_evidence_truncate_guard BEFORE TRUNCATE ON actor_profile_migration_state FOR EACH STATEMENT EXECUTE FUNCTION guard_service_identity_migration_evidence()","enabled":"O","name":"service_identity_migration_evidence_truncate_guard","table_name":"actor_profile_migration_state"},{"definition":"CREATE TRIGGER actor_profile_history_guard BEFORE DELETE OR UPDATE ON actor_profiles FOR EACH ROW EXECUTE FUNCTION guard_actor_profile_history()","enabled":"O","name":"actor_profile_history_guard","table_name":"actor_profiles"},{"definition":"CREATE CONSTRAINT TRIGGER actor_profile_link_guard AFTER INSERT OR UPDATE ON actor_profiles DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_canonical_actor_link()","enabled":"O","name":"actor_profile_link_guard","table_name":"actor_profiles"},{"definition":"CREATE CONSTRAINT TRIGGER admin_role_grants_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON admin_role_grants DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()","enabled":"O","name":"admin_role_grants_bootstrap_invariant","table_name":"admin_role_grants"},{"definition":"CREATE TRIGGER admin_role_grants_guard BEFORE INSERT OR DELETE OR UPDATE ON admin_role_grants FOR EACH ROW EXECUTE FUNCTION guard_admin_role_grant()","enabled":"O","name":"admin_role_grants_guard","table_name":"admin_role_grants"},{"definition":"CREATE TRIGGER admin_role_grants_reject_truncate BEFORE TRUNCATE ON admin_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_admin_role_grant_truncate()","enabled":"O","name":"admin_role_grants_reject_truncate","table_name":"admin_role_grants"},{"definition":"CREATE CONSTRAINT TRIGGER trg_artifact_binding_history AFTER INSERT ON artifact_bindings DEFERRABLE INITIALLY IMMEDIATE FOR EACH ROW EXECUTE FUNCTION validate_artifact_binding_history()","enabled":"O","name":"trg_artifact_binding_history","table_name":"artifact_bindings"},{"definition":"CREATE TRIGGER trg_artifact_bindings_immutable BEFORE DELETE OR UPDATE ON artifact_bindings FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_bindings_immutable","table_name":"artifact_bindings"},{"definition":"CREATE TRIGGER trg_artifact_contents_immutable BEFORE DELETE OR UPDATE ON artifact_contents FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_contents_immutable","table_name":"artifact_contents"},{"definition":"CREATE TRIGGER artifact_receipt_producer_reference BEFORE INSERT OR UPDATE OF put_attempt_id, guide_source_item_id, checker_run_id, logical_role ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION guard_artifact_receipt_producer_reference()","enabled":"O","name":"artifact_receipt_producer_reference","table_name":"artifact_operation_receipts"},{"definition":"CREATE TRIGGER trg_artifact_operation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_operation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_operation_receipts_immutable","table_name":"artifact_operation_receipts"},{"definition":"CREATE TRIGGER trg_artifact_put_observation_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_put_observation_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_put_observation_receipts_immutable","table_name":"artifact_put_observation_receipts"},{"definition":"CREATE TRIGGER artifact_recovery_attempt_custody BEFORE INSERT OR DELETE OR UPDATE ON artifact_recovery_attempts FOR EACH ROW EXECUTE FUNCTION validate_artifact_recovery_attempt()","enabled":"O","name":"artifact_recovery_attempt_custody","table_name":"artifact_recovery_attempts"},{"definition":"CREATE TRIGGER trg_artifact_storage_namespaces_immutable BEFORE DELETE OR UPDATE ON artifact_storage_namespaces FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_storage_namespaces_immutable","table_name":"artifact_storage_namespaces"},{"definition":"CREATE TRIGGER artifact_verification_lineage_custody BEFORE UPDATE ON artifact_verification_jobs FOR EACH ROW EXECUTE FUNCTION validate_artifact_verification_lineage()","enabled":"O","name":"artifact_verification_lineage_custody","table_name":"artifact_verification_jobs"},{"definition":"CREATE TRIGGER trg_artifact_verification_receipts_immutable BEFORE DELETE OR UPDATE ON artifact_verification_receipts FOR EACH ROW EXECUTE FUNCTION reject_artifact_fact_mutation()","enabled":"O","name":"trg_artifact_verification_receipts_immutable","table_name":"artifact_verification_receipts"},{"definition":"CREATE TRIGGER audit_events_reject_truncate BEFORE TRUNCATE ON audit_events FOR EACH STATEMENT EXECUTE FUNCTION reject_audit_event_mutation()","enabled":"O","name":"audit_events_reject_truncate","table_name":"audit_events"},{"definition":"CREATE TRIGGER audit_events_reject_update_delete BEFORE DELETE OR UPDATE ON audit_events FOR EACH ROW EXECUTE FUNCTION reject_audit_event_mutation()","enabled":"O","name":"audit_events_reject_update_delete","table_name":"audit_events"},{"definition":"CREATE TRIGGER audit_events_set_authority_time BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION set_authority_audit_database_time()","enabled":"O","name":"audit_events_set_authority_time","table_name":"audit_events"},{"definition":"CREATE TRIGGER audit_events_validate_idempotency BEFORE INSERT ON audit_events FOR EACH ROW EXECUTE FUNCTION validate_linked_authority_event()","enabled":"O","name":"audit_events_validate_idempotency","table_name":"audit_events"},{"definition":"CREATE CONSTRAINT TRIGGER authority_control_bootstrap_invariant AFTER INSERT OR DELETE OR UPDATE ON authority_control DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_bootstrap_authority_state()","enabled":"O","name":"authority_control_bootstrap_invariant","table_name":"authority_control"},{"definition":"CREATE TRIGGER authority_control_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_control FOR EACH ROW EXECUTE FUNCTION guard_authority_control()","enabled":"O","name":"authority_control_guard","table_name":"authority_control"},{"definition":"CREATE TRIGGER authority_control_reject_truncate BEFORE TRUNCATE ON authority_control FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_control_truncate()","enabled":"O","name":"authority_control_reject_truncate","table_name":"authority_control"},{"definition":"CREATE TRIGGER authority_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON authority_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_authority_idempotency_record()","enabled":"O","name":"authority_idempotency_guard","table_name":"authority_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER authority_idempotency_pending_guard AFTER INSERT OR UPDATE ON authority_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION reject_pending_authority_idempotency()","enabled":"O","name":"authority_idempotency_pending_guard","table_name":"authority_idempotency_records"},{"definition":"CREATE TRIGGER authority_idempotency_reject_truncate BEFORE TRUNCATE ON authority_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_authority_idempotency_truncate()","enabled":"O","name":"authority_idempotency_reject_truncate","table_name":"authority_idempotency_records"},{"definition":"CREATE TRIGGER contribution_award_definitions_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_award_definitions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()","enabled":"O","name":"contribution_award_definitions_content_guard","table_name":"contribution_award_definitions"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_award_definitions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_award_definitions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_award_definitions_graph_guard","table_name":"contribution_award_definitions"},{"definition":"CREATE TRIGGER contribution_award_definitions_reject_truncate BEFORE TRUNCATE ON contribution_award_definitions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_award_definitions_reject_truncate","table_name":"contribution_award_definitions"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_policies_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_policies_graph_guard","table_name":"contribution_policies"},{"definition":"CREATE TRIGGER contribution_policies_reject_truncate BEFORE TRUNCATE ON contribution_policies FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_policies_reject_truncate","table_name":"contribution_policies"},{"definition":"CREATE TRIGGER contribution_policy_versions_content_guard BEFORE DELETE OR UPDATE ON contribution_policy_versions FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_version_content()","enabled":"O","name":"contribution_policy_versions_content_guard","table_name":"contribution_policy_versions"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_policy_versions_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_policy_versions DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_policy_versions_graph_guard","table_name":"contribution_policy_versions"},{"definition":"CREATE TRIGGER contribution_policy_versions_reject_truncate BEFORE TRUNCATE ON contribution_policy_versions FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_policy_versions_reject_truncate","table_name":"contribution_policy_versions"},{"definition":"CREATE TRIGGER contribution_rules_content_guard BEFORE INSERT OR DELETE OR UPDATE ON contribution_rules FOR EACH ROW EXECUTE FUNCTION guard_contribution_policy_children()","enabled":"O","name":"contribution_rules_content_guard","table_name":"contribution_rules"},{"definition":"CREATE CONSTRAINT TRIGGER contribution_rules_graph_guard AFTER INSERT OR DELETE OR UPDATE ON contribution_rules DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_contribution_policy_graph()","enabled":"O","name":"contribution_rules_graph_guard","table_name":"contribution_rules"},{"definition":"CREATE TRIGGER contribution_rules_reject_truncate BEFORE TRUNCATE ON contribution_rules FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"contribution_rules_reject_truncate","table_name":"contribution_rules"},{"definition":"CREATE CONSTRAINT TRIGGER effective_submission_policy_custody AFTER INSERT OR UPDATE ON effective_project_submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"effective_submission_policy_custody","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE TRIGGER effective_submission_policy_provenance_immutable BEFORE UPDATE ON effective_project_submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()","enabled":"O","name":"effective_submission_policy_provenance_immutable","table_name":"effective_project_submission_artifact_policies"},{"definition":"CREATE TRIGGER guide_mutation_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON guide_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_guide_mutation_idempotency()","enabled":"O","name":"guide_mutation_idempotency_guard","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE TRIGGER guide_mutation_idempotency_reject_truncate BEFORE TRUNCATE ON guide_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_mutation_idempotency_truncate()","enabled":"O","name":"guide_mutation_idempotency_reject_truncate","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER guide_mutation_reservation_custody AFTER INSERT OR UPDATE ON guide_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"guide_mutation_reservation_custody","table_name":"guide_mutation_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER guide_source_snapshot_items_custody AFTER INSERT ON guide_source_snapshot_items DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_source_snapshot_items()","enabled":"O","name":"guide_source_snapshot_items_custody","table_name":"guide_source_snapshot_items"},{"definition":"CREATE TRIGGER guide_source_snapshot_items_immutable BEFORE DELETE OR UPDATE OR TRUNCATE ON guide_source_snapshot_items FOR EACH STATEMENT EXECUTE FUNCTION reject_guide_source_snapshot_item_mutation()","enabled":"O","name":"guide_source_snapshot_items_immutable","table_name":"guide_source_snapshot_items"},{"definition":"CREATE CONSTRAINT TRIGGER source_snapshot_product_custody AFTER INSERT OR UPDATE ON guide_source_snapshots DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"source_snapshot_product_custody","table_name":"guide_source_snapshots"},{"definition":"CREATE TRIGGER trg_sufficiency_replay_immutable BEFORE DELETE OR UPDATE ON guide_sufficiency_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_sufficiency_replay_mutation()","enabled":"O","name":"trg_sufficiency_replay_immutable","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE TRIGGER trg_sufficiency_replay_no_truncate BEFORE TRUNCATE ON guide_sufficiency_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_sufficiency_replay_truncate()","enabled":"O","name":"trg_sufficiency_replay_no_truncate","table_name":"guide_sufficiency_mutation_idempotency_records"},{"definition":"CREATE TRIGGER iso_4217_currency_codes_immutable BEFORE INSERT OR DELETE OR UPDATE ON iso_4217_currency_codes FOR EACH ROW EXECUTE FUNCTION guard_iso_4217_currency_codes()","enabled":"O","name":"iso_4217_currency_codes_immutable","table_name":"iso_4217_currency_codes"},{"definition":"CREATE TRIGGER iso_4217_currency_codes_reject_truncate BEFORE TRUNCATE ON iso_4217_currency_codes FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"iso_4217_currency_codes_reject_truncate","table_name":"iso_4217_currency_codes"},{"definition":"CREATE TRIGGER outbox_events_custody BEFORE INSERT OR DELETE OR UPDATE ON outbox_events FOR EACH ROW EXECUTE FUNCTION guard_outbox_event()","enabled":"O","name":"outbox_events_custody","table_name":"outbox_events"},{"definition":"CREATE TRIGGER outbox_events_reject_truncate BEFORE TRUNCATE ON outbox_events FOR EACH STATEMENT EXECUTE FUNCTION guard_outbox_event()","enabled":"O","name":"outbox_events_reject_truncate","table_name":"outbox_events"},{"definition":"CREATE CONSTRAINT TRIGGER policy_mutation_replay_custody AFTER INSERT OR UPDATE ON policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()","enabled":"O","name":"policy_mutation_replay_custody","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER policy_mutation_replay_immutable BEFORE INSERT OR DELETE OR UPDATE ON policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_policy_mutation_replay()","enabled":"O","name":"policy_mutation_replay_immutable","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER policy_mutation_replay_reject_truncate BEFORE TRUNCATE ON policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_policy_mutation_replay_truncate()","enabled":"O","name":"policy_mutation_replay_reject_truncate","table_name":"policy_mutation_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER pre_submit_policy_custody AFTER INSERT OR UPDATE ON pre_submit_checker_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"pre_submit_policy_custody","table_name":"pre_submit_checker_policies"},{"definition":"CREATE TRIGGER pre_submit_policy_provenance_immutable BEFORE UPDATE ON pre_submit_checker_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_output_provenance()","enabled":"O","name":"pre_submit_policy_provenance_immutable","table_name":"pre_submit_checker_policies"},{"definition":"CREATE TRIGGER pre_submit_evidence_results_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()","enabled":"O","name":"pre_submit_evidence_results_immutable","table_name":"pre_submit_evidence_results"},{"definition":"CREATE TRIGGER pre_submit_evidence_results_membership BEFORE INSERT ON pre_submit_evidence_results FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_result_membership()","enabled":"O","name":"pre_submit_evidence_results_membership","table_name":"pre_submit_evidence_results"},{"definition":"CREATE TRIGGER pre_submit_evidence_results_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_results FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_results_immutable()","enabled":"O","name":"pre_submit_evidence_results_no_truncate","table_name":"pre_submit_evidence_results"},{"definition":"CREATE TRIGGER pre_submit_evidence_sets_creation BEFORE INSERT ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_set_creation()","enabled":"O","name":"pre_submit_evidence_sets_creation","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE TRIGGER pre_submit_evidence_sets_immutable BEFORE DELETE OR UPDATE ON pre_submit_evidence_sets FOR EACH ROW EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()","enabled":"O","name":"pre_submit_evidence_sets_immutable","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE TRIGGER pre_submit_evidence_sets_no_truncate BEFORE TRUNCATE ON pre_submit_evidence_sets FOR EACH STATEMENT EXECUTE FUNCTION guard_pre_submit_evidence_sets_immutable()","enabled":"O","name":"pre_submit_evidence_sets_no_truncate","table_name":"pre_submit_evidence_sets"},{"definition":"CREATE TRIGGER project_compensation_binding_update_guard BEFORE UPDATE ON project_compensation_adapter_bindings FOR EACH ROW EXECUTE FUNCTION enforce_compensation_binding_lifecycle()","enabled":"O","name":"project_compensation_binding_update_guard","table_name":"project_compensation_adapter_bindings"},{"definition":"CREATE TRIGGER project_compensation_units_lifecycle_guard BEFORE INSERT OR DELETE OR UPDATE ON project_compensation_units FOR EACH ROW EXECUTE FUNCTION guard_project_compensation_units()","enabled":"O","name":"project_compensation_units_lifecycle_guard","table_name":"project_compensation_units"},{"definition":"CREATE TRIGGER project_compensation_units_reject_truncate BEFORE TRUNCATE ON project_compensation_units FOR EACH STATEMENT EXECUTE FUNCTION reject_contribution_policy_truncate()","enabled":"O","name":"project_compensation_units_reject_truncate","table_name":"project_compensation_units"},{"definition":"CREATE TRIGGER project_create_idempotency_guard BEFORE INSERT OR DELETE OR UPDATE ON project_create_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_project_create_idempotency()","enabled":"O","name":"project_create_idempotency_guard","table_name":"project_create_idempotency_records"},{"definition":"CREATE TRIGGER project_create_idempotency_reject_truncate BEFORE TRUNCATE ON project_create_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_project_create_idempotency_truncate()","enabled":"O","name":"project_create_idempotency_reject_truncate","table_name":"project_create_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER project_create_reservation_custody AFTER INSERT OR UPDATE ON project_create_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()","enabled":"O","name":"project_create_reservation_custody","table_name":"project_create_idempotency_records"},{"definition":"CREATE TRIGGER trg_compilation_attempt_delete BEFORE DELETE OR TRUNCATE ON project_guide_compilation_attempts FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()","enabled":"O","name":"trg_compilation_attempt_delete","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE TRIGGER trg_compilation_attempt_update BEFORE UPDATE ON project_guide_compilation_attempts FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_attempt_update()","enabled":"O","name":"trg_compilation_attempt_update","table_name":"project_guide_compilation_attempts"},{"definition":"CREATE TRIGGER trg_compilation_insert BEFORE INSERT ON project_guide_compilations FOR EACH ROW EXECUTE FUNCTION guard_project_guide_compilation_insert()","enabled":"O","name":"trg_compilation_insert","table_name":"project_guide_compilations"},{"definition":"CREATE TRIGGER trg_compilation_mutation BEFORE DELETE OR UPDATE OR TRUNCATE ON project_guide_compilations FOR EACH STATEMENT EXECUTE FUNCTION reject_project_guide_compilation_mutation()","enabled":"O","name":"trg_compilation_mutation","table_name":"project_guide_compilations"},{"definition":"CREATE TRIGGER guide_lineage_lifecycle_guard BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_guide_lineage_and_lifecycle()","enabled":"O","name":"guide_lineage_lifecycle_guard","table_name":"project_guides"},{"definition":"CREATE CONSTRAINT TRIGGER guide_mutation_product_custody AFTER INSERT OR UPDATE ON project_guides DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"guide_mutation_product_custody","table_name":"project_guides"},{"definition":"CREATE TRIGGER project_guides_policy_selection_immutable BEFORE UPDATE ON project_guides FOR EACH ROW EXECUTE FUNCTION guard_project_guide_policy_selection()","enabled":"O","name":"project_guides_policy_selection_immutable","table_name":"project_guides"},{"definition":"CREATE TRIGGER trg_project_role_grants_history BEFORE INSERT OR DELETE OR UPDATE ON project_role_grants FOR EACH ROW EXECUTE FUNCTION guard_project_role_grant_history()","enabled":"O","name":"trg_project_role_grants_history","table_name":"project_role_grants"},{"definition":"CREATE TRIGGER trg_project_role_grants_reject_truncate BEFORE TRUNCATE ON project_role_grants FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()","enabled":"O","name":"trg_project_role_grants_reject_truncate","table_name":"project_role_grants"},{"definition":"CREATE TRIGGER trg_project_role_qualification_snapshots_immutable BEFORE INSERT OR DELETE OR UPDATE ON project_role_qualification_snapshots FOR EACH ROW EXECUTE FUNCTION guard_project_role_snapshot_history()","enabled":"O","name":"trg_project_role_qualification_snapshots_immutable","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE TRIGGER trg_project_role_snapshots_reject_truncate BEFORE TRUNCATE ON project_role_qualification_snapshots FOR EACH STATEMENT EXECUTE FUNCTION reject_project_role_history_truncate()","enabled":"O","name":"trg_project_role_snapshots_reject_truncate","table_name":"project_role_qualification_snapshots"},{"definition":"CREATE CONSTRAINT TRIGGER source_setup_run_custody AFTER INSERT OR UPDATE ON project_setup_runs DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_guide_mutation_custody()","enabled":"O","name":"source_setup_run_custody","table_name":"project_setup_runs"},{"definition":"CREATE CONSTRAINT TRIGGER project_creation_custody AFTER INSERT OR UPDATE OF created_by_actor_profile_id, created_via_identity_link_id, created_by_admin_role_grant_id, creation_scope_type, creation_action_id, authorization_decision_event_id ON projects DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_project_create_custody()","enabled":"O","name":"project_creation_custody","table_name":"projects"},{"definition":"CREATE TRIGGER review_admission_idempotency_records_reject_truncate BEFORE TRUNCATE ON review_admission_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()","enabled":"O","name":"review_admission_idempotency_records_reject_truncate","table_name":"review_admission_idempotency_records"},{"definition":"CREATE TRIGGER review_admission_records_guard BEFORE INSERT OR DELETE OR UPDATE ON review_admission_idempotency_records FOR EACH ROW EXECUTE FUNCTION guard_review_admission_record()","enabled":"O","name":"review_admission_records_guard","table_name":"review_admission_idempotency_records"},{"definition":"CREATE CONSTRAINT TRIGGER review_leases_active_lease_guard AFTER INSERT OR UPDATE ON review_leases DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()","enabled":"O","name":"review_leases_active_lease_guard","table_name":"review_leases"},{"definition":"CREATE TRIGGER review_leases_guard BEFORE INSERT OR DELETE OR UPDATE ON review_leases FOR EACH ROW EXECUTE FUNCTION guard_review_lease()","enabled":"O","name":"review_leases_guard","table_name":"review_leases"},{"definition":"CREATE TRIGGER review_leases_reject_truncate BEFORE TRUNCATE ON review_leases FOR EACH STATEMENT EXECUTE FUNCTION reject_review_lease_truncate()","enabled":"O","name":"review_leases_reject_truncate","table_name":"review_leases"},{"definition":"CREATE TRIGGER review_policies_immutable BEFORE DELETE OR UPDATE ON review_policies FOR EACH ROW EXECUTE FUNCTION guard_review_policies_immutable()","enabled":"O","name":"review_policies_immutable","table_name":"review_policies"},{"definition":"CREATE TRIGGER review_policies_reject_truncate BEFORE TRUNCATE ON review_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_review_policies_immutable()","enabled":"O","name":"review_policies_reject_truncate","table_name":"review_policies"},{"definition":"CREATE CONSTRAINT TRIGGER review_policy_mutation_custody AFTER INSERT OR UPDATE ON review_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()","enabled":"O","name":"review_policy_mutation_custody","table_name":"review_policies"},{"definition":"CREATE CONSTRAINT TRIGGER review_queue_entries_active_lease_guard AFTER INSERT OR UPDATE ON review_queue_entries DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_review_active_lease()","enabled":"O","name":"review_queue_entries_active_lease_guard","table_name":"review_queue_entries"},{"definition":"CREATE TRIGGER review_queue_entries_guard BEFORE INSERT OR DELETE OR UPDATE ON review_queue_entries FOR EACH ROW EXECUTE FUNCTION guard_review_queue_entry()","enabled":"O","name":"review_queue_entries_guard","table_name":"review_queue_entries"},{"definition":"CREATE TRIGGER review_queue_entries_reject_truncate BEFORE TRUNCATE ON review_queue_entries FOR EACH STATEMENT EXECUTE FUNCTION reject_review_queue_foundation_truncate()","enabled":"O","name":"review_queue_entries_reject_truncate","table_name":"review_queue_entries"},{"definition":"CREATE TRIGGER revision_policies_immutable BEFORE DELETE OR UPDATE ON revision_policies FOR EACH ROW EXECUTE FUNCTION guard_revision_policies_immutable()","enabled":"O","name":"revision_policies_immutable","table_name":"revision_policies"},{"definition":"CREATE TRIGGER revision_policies_reject_truncate BEFORE TRUNCATE ON revision_policies FOR EACH STATEMENT EXECUTE FUNCTION guard_revision_policies_immutable()","enabled":"O","name":"revision_policies_reject_truncate","table_name":"revision_policies"},{"definition":"CREATE CONSTRAINT TRIGGER revision_policy_mutation_custody AFTER INSERT OR UPDATE ON revision_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_policy_mutation_custody()","enabled":"O","name":"revision_policy_mutation_custody","table_name":"revision_policies"},{"definition":"CREATE TRIGGER submission_policy_approval_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_approval_provenance()","enabled":"O","name":"submission_policy_approval_provenance_immutable","table_name":"submission_artifact_policies"},{"definition":"CREATE CONSTRAINT TRIGGER submission_policy_creation_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_creation_custody()","enabled":"O","name":"submission_policy_creation_custody","table_name":"submission_artifact_policies"},{"definition":"CREATE TRIGGER submission_policy_creation_provenance_immutable BEFORE UPDATE ON submission_artifact_policies FOR EACH ROW EXECUTE FUNCTION protect_submission_policy_creation_provenance()","enabled":"O","name":"submission_policy_creation_provenance_immutable","table_name":"submission_artifact_policies"},{"definition":"CREATE CONSTRAINT TRIGGER submission_policy_product_custody AFTER INSERT OR UPDATE ON submission_artifact_policies DEFERRABLE INITIALLY DEFERRED FOR EACH ROW EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"submission_policy_product_custody","table_name":"submission_artifact_policies"},{"definition":"CREATE TRIGGER submission_bundle_admission_delete BEFORE DELETE OR TRUNCATE ON submission_bundle_admissions FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_admission_delete()","enabled":"O","name":"submission_bundle_admission_delete","table_name":"submission_bundle_admissions"},{"definition":"CREATE TRIGGER submission_bundle_admission_lineage BEFORE UPDATE ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_lineage()","enabled":"O","name":"submission_bundle_admission_lineage","table_name":"submission_bundle_admissions"},{"definition":"CREATE TRIGGER submission_bundle_admission_verified_lineage BEFORE INSERT ON submission_bundle_admissions FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_admission_verified_lineage()","enabled":"O","name":"submission_bundle_admission_verified_lineage","table_name":"submission_bundle_admissions"},{"definition":"CREATE TRIGGER submission_bundle_durable_intent_put_attempt BEFORE INSERT ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intent_put_attempt()","enabled":"O","name":"submission_bundle_durable_intent_put_attempt","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE TRIGGER submission_bundle_durable_intents_immutable BEFORE DELETE OR UPDATE ON submission_bundle_durable_intents FOR EACH ROW EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()","enabled":"O","name":"submission_bundle_durable_intents_immutable","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE TRIGGER submission_bundle_durable_intents_no_truncate BEFORE TRUNCATE ON submission_bundle_durable_intents FOR EACH STATEMENT EXECUTE FUNCTION guard_submission_bundle_durable_intents_immutable()","enabled":"O","name":"submission_bundle_durable_intents_no_truncate","table_name":"submission_bundle_durable_intents"},{"definition":"CREATE CONSTRAINT TRIGGER submission_policy_replay_custody AFTER INSERT OR UPDATE ON submission_policy_mutation_idempotency_records DEFERRABLE INITIALLY DEFERRED FOR EACH ROW WHEN (new.status::text = 'committed'::text) EXECUTE FUNCTION validate_submission_policy_authority_custody()","enabled":"O","name":"submission_policy_replay_custody","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER trg_submission_policy_replay_immutable BEFORE DELETE OR UPDATE ON submission_policy_mutation_idempotency_records FOR EACH ROW EXECUTE FUNCTION reject_submission_policy_replay_mutation()","enabled":"O","name":"trg_submission_policy_replay_immutable","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER trg_submission_policy_replay_no_truncate BEFORE TRUNCATE ON submission_policy_mutation_idempotency_records FOR EACH STATEMENT EXECUTE FUNCTION reject_submission_policy_replay_truncate()","enabled":"O","name":"trg_submission_policy_replay_no_truncate","table_name":"submission_policy_mutation_idempotency_records"},{"definition":"CREATE TRIGGER submissions_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON submissions FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')","enabled":"O","name":"submissions_contributor_human","table_name":"submissions"},{"definition":"CREATE TRIGGER task_assignments_contributor_human BEFORE INSERT OR UPDATE OF contributor_id ON task_assignments FOR EACH ROW EXECUTE FUNCTION require_human_actor_profile_reference('contributor_id')","enabled":"O","name":"task_assignments_contributor_human","table_name":"task_assignments"}],"types":[]} diff --git a/backend/scripts/schema_baseline_manifest.py b/backend/scripts/schema_baseline_manifest.py index da0eab4f6..0c7cc7d6f 100644 --- a/backend/scripts/schema_baseline_manifest.py +++ b/backend/scripts/schema_baseline_manifest.py @@ -234,8 +234,8 @@ async def build_manifest(database_url: str) -> dict[str, Any]: def canonical_bytes(manifest: dict[str, Any]) -> bytes: - """Serialize a manifest deterministically.""" - return (json.dumps(manifest, indent=2, sort_keys=True) + "\n").encode() + """Serialize a manifest as compact deterministic machine evidence.""" + return (json.dumps(manifest, separators=(",", ":"), sort_keys=True) + "\n").encode() async def _run(args: argparse.Namespace) -> None: diff --git a/backend/tests/test_alembic.py b/backend/tests/test_alembic.py index 186f2e7e2..7df879883 100644 --- a/backend/tests/test_alembic.py +++ b/backend/tests/test_alembic.py @@ -120,6 +120,16 @@ def test_manifest_covers_every_required_object_class() -> None: assert manifest["auxiliary_objects"] == [] +@pytest.mark.parametrize( + "name", ("v01_pre_reset_source_manifest.json", "v01_baseline_manifest.json") +) +def test_committed_schema_manifests_are_compact_canonical_json(name: str) -> None: + path = _manifest_path().with_name(name) + payload = path.read_bytes() + assert payload == canonical_bytes(json.loads(payload)) + assert payload.count(b"\n") == 1 + + def test_source_to_baseline_delta_is_exactly_the_approved_sequence_repair() -> None: baseline_dir = _manifest_path().parent source = json.loads((baseline_dir / "v01_pre_reset_source_manifest.json").read_text())