Observed today while running agents against the NewOffice reference scan: the original project.rux (a benchmark reference that every workflow treats as read-only) was silently migrated v10→v11→v12 during the day, because ProjectDB migrates on open unconditionally (libs/reusex/src/core/ProjectDB.cpp:268) — including for purely-reading commands (rux info, rux analyze quality, trajectory renders). WAL checkpointing on connection close also rewrites the main file even for SELECT-only sessions.
Consequences:
- Reference/benchmark datasets change hash and mtime under readers, breaking reproducibility ("same input" is no longer the same file).
- A dataset opened once with a newer build is no longer readable by an older build (schema is a one-way door), without the user ever asking for a write.
Proposal (pick one or combine):
- Read-only open mode (
SQLITE_OPEN_READONLY + skip migration) used automatically by read-only commands (info, log, get, analyze, render, export, the Python bindings already claim read-only) — migration then happens only on commands that write.
- Or: migrate lazily only when a write is attempted, never on open.
- At minimum: log at
warn when an open migrates the schema, so mutation of an input is visible (STANDARDS §5 — today it is silent).
Marker: the NewOffice reference at /home/mephisto/repos/NewOffice/project.rux now reports schema 12 with three migrations applied 2026-09-10 while under read-only workloads only. PRAGMA integrity_check is ok; migrations are additive, so no data loss this time.
Observed today while running agents against the NewOffice reference scan: the original
project.rux(a benchmark reference that every workflow treats as read-only) was silently migrated v10→v11→v12 during the day, becauseProjectDBmigrates on open unconditionally (libs/reusex/src/core/ProjectDB.cpp:268) — including for purely-reading commands (rux info,rux analyze quality, trajectory renders). WAL checkpointing on connection close also rewrites the main file even for SELECT-only sessions.Consequences:
Proposal (pick one or combine):
SQLITE_OPEN_READONLY+ skip migration) used automatically by read-only commands (info,log,get,analyze,render,export, the Python bindings already claim read-only) — migration then happens only on commands that write.warnwhen an open migrates the schema, so mutation of an input is visible (STANDARDS §5 — today it is silent).Marker: the NewOffice reference at /home/mephisto/repos/NewOffice/project.rux now reports schema 12 with three migrations applied 2026-09-10 while under read-only workloads only.
PRAGMA integrity_checkis ok; migrations are additive, so no data loss this time.