## 1. Schema And Migration - [x] 1.1 Add migration marker and SQLite/PostgreSQL schema for Docker query provenance, immutable manifests/layers, experiment authority, query/repository/selection/target/binding relations, and finding-layer attribution - [x] 1.2 Register required columns, keys, foreign keys, indexes, integer-width conversions, constraints, migration quiescence checks, and idempotent validation - [x] 1.3 Add legacy first-inserter provenance seeding that is explicitly ineligible for fresh experiment coverage ## 2. Configuration And Selection - [x] 2.1 Add strict side-effect-free Docker image-depth and experiment configuration validation with exact ordered-query/config/selector hashes - [x] 2.2 Remove the hidden three-image clamp and implement deterministic distinct graph selection through rank ten while preserving first-three semantics - [x] 2.3 Add production configuration for the disabled collection rollout and the pinned 61-query, up-to-10-fresh-repository, 10-image, 1,200-target experiment ## 3. Discovery Provenance - [x] 3.1 Persist main-pass query-to-repository provenance and stable search rank atomically with each Docker discovery page - [x] 3.2 Persist retry-pass provenance with the original query/policy evidence under retry lease fencing - [x] 3.3 Require one complete pinned deep pass, then freeze each of all 61 queries with its exact zero-to-ten eligible unseen repository count without historical substitution ## 4. Cohort And Holds - [x] 4.1 Implement deterministic sparse round-robin cohort planning, one deep-probe choice per nonempty query, immutable desired/actual count hashes, and serialized unique-target capacity accounting - [x] 4.2 Generate and validate an explicit experiment hold manifest for non-cohort unresolved Docker anchors - [x] 4.3 Apply/release experiment-owned cold events through existing fence-aware APIs without changing independently fenced targets - [x] 4.4 Hold newly observed non-cohort anchors under the activated reviewed experiment policy ## 5. Resolver And Scheduling - [x] 5.1 Add a dedicated fenced experiment resolver lane ordered by repository round and query ordinal - [x] 5.2 Persist selected immutable targets, ranks/reasons, manifest identity, and ordered layer descriptors atomically with resolver completion - [x] 5.3 Reject or replace conflicts with done, failed, quarantined, or independently cold immutable targets without implicit reactivation - [x] 5.4 Bind experiment targets atomically to scan reservations and dispatch breadth, ranks 2-3, then ranks 4-10 round-robin - [x] 5.5 Fail closed to held state on query/config/selector drift, capacity conflict, stale token, or non-PostgreSQL authority ## 6. Evidence And Reporting - [x] 6.1 Associate exact Docker finding layer digests with all matching base/top manifest positions during atomic result ingestion - [x] 6.2 Add a secret-safe aggregate experiment report separating physical totals from per-query attribution and ranks 1-3 from ranks 4-10 - [x] 6.3 Report deduplicated findings/credentials, frozen and current verification outcomes, marginal minimum-rank yield, scan duration/errors, overlap, coverage, and unattributed findings ## 7. Verification - [x] 7.1 Add focused unit tests for strict configuration, side-effect ordering, rank 4-10 selection, deduplication, and deterministic tie breaks - [x] 7.2 Add schema/migration and PostgreSQL integration tests for provenance atomicity, fair planning, global cap concurrency, hold/reactivation fencing, resolver completion, reservation binding, and ingestion - [x] 7.3 Add reporting and secret-sentinel tests for shared attribution, rank boundaries, marginal identity yield, layer positions, retries, and unattributed evidence - [x] 7.4 Run focused tests, PostgreSQL integration, broad relevant suites, strict OpenSpec validation, and independent review ## 8. Controlled Rollout - [x] 8.1 Canonically stop runtime, apply the additive migration with experiment disabled, and restart to collect fresh provenance - [x] 8.2 Verify one complete fresh observation pass for every query, then canonically stop and generate/review the cohort and hold manifest - [x] 8.3 Activate the frozen experiment, restart canonically, and verify PostgreSQL/pipeline/auth/worker health, fair cohort dispatch, capacity ceiling, leases, retries, restart counters, and bytecode absence - [x] 8.4 Leave the experiment running toward drain/report while keeping non-cohort rows reversibly cold for a later reviewed decision