# Content temporarily unavailable
# Temporal persistence v2

The implemented design preserves native `Temporal.Instant` and
`Temporal.PlainDate` values through the existing SQLite query pipeline. It keeps
SQL filtering and index use, reconstructs native values, then uses the existing
residual filtering, ordering and pagination stages.

The grammar is:

```text
supported value × carrier × operation × legal history × execution boundary
```

Its selected rules are concrete:

- Use registered global Temporal constructors for brand validation and native
  reconstruction. Preserve both kind and value; reject missing constructors and
  other Temporal kinds. Strings remain strings.
- Encode native values consistently across rows, nested data, metadata and replay.
  Escape an ordinary record's marker field without moving its other JSON fields.
- Separate lossless canonical text from sortable keys. Instant keys retain
  nanoseconds; PlainDate keys preserve ISO chronological order across calendars
  and signed years. Equality additionally retains kind and calendar text.
- Share reference/literal representations between runtime SQL and persisted
  indexes. Exact equality and correlated IN membership remain safe under NOT.
  Coalesce retains both representations; existing SQL fallbacks and final cleanup
  remain. Ordered comparisons require compatible same-kind operands.
- Preserve action validation, durable rollback, wrapper receipts/FIFO and the
  publication-before-durability boundary. Reuse existing oracle owners.
- Retain the narrower remote-subset wire domain and reject permanent input
  errors before retry admission. Multiprocess native-value support is not added.

The wrapper oracle exposed an additional receiving boundary: Collection index
metadata previously JSON-cloned native literals into strings and gave distinct
Temporal literals the same signature. The implementation now preserves native
literals while copying the expression structure and includes kind/text in the
signature. Its test observes metadata, emitted SQL and actual index use.

The original implementation failed 33 targeted expanded witnesses before the final routing and scalar-index additions. A deliberately
wrong lexical-order implementation fails eight cases while still reconstructing
native values correctly. The routing witnesses also catch a request that becomes remote during hydration; valid requests now dispatch exactly once. Small and large membership indexes retain SQLite compatibility. The repaired affected suite reports **471 passed,
1 existing TODO, 0 failed**. TypeScript and lint pass; lint retains existing
require-await warnings. Full results, source hashes and the oracle audit are in
[evidence](v2-evidence.md).

Old data may be replaced, as the user specified. This additive implementation
does not automatically erase it: existing schema-version/reset options can
replace already-damaged caches. Empty objects cannot reveal their former type,
and older readers cannot interpret the new native encoding.

The claim is bounded to the reached paths and histories. Engine-native
constructors, native mobile/browser runs, multiprocess row transport,
truncate/delete histories with native values and arbitrary Temporal operations
remain unproved. Independently held-out range evidence and formal model checking are absent; host behavior and untested schedules remain a decomposition limit. Index-plan checks establish index use, not a latency guarantee.

The detailed [model](v2-model.md) preserves the initial frozen rules and explicitly
dated implementation discoveries. [Process](v2-process.md) records reconstruction,
ablation, controls and the projection map. No new lifecycle model or generic
codec framework was introduced.
