OpenSentience.orgUnboxed PatternsChapter 19 of 32 · Persistence and World

UP-019 · Persistence and World · STATED CHECKABLE RUNNABLE EXECUTED STAGED

Orthogonal Persistence

Whether a locus's state is in cache, RAM, disk or a remote node is an implementation choice below its semantic level.

Whether a locus's state is in cache, RAM, disk or a remote node is an implementation choice below its semantic level; code is identical for short-lived and long-lived state.
Standing
STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
Last checked
never run
Source
none — this record cites no check
Limit
Cites Atkinson & Morrison correctly and implements nothing. studbook is at the spec rung and its §10.2 blocker is open, so no system here has orthogonal persistence.
Next rung
in_tree — any implementation at all. studbook §10.2 (where confidentiality comes from) blocks it, and that is a ruling, not a build.
Why this page says STATED — the derivation, not the word
  • ✗ a witness is named
  • ✗ its evidence kind is one the ledger already uses
  • ✗ the witness path resolves in this tree
  • ✗ its rung is in_tree or above
  • ✗ a run is recorded for these exact bytes
  • ✓ no claim is cited that could be REFUTED
  • ✗ a counterexample is shipped (required once WITNESSED)
  • ✗ not staged on this site, so it cannot run from the page

WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.

Intent

Atkinson and Morrison's three principles: persistence is available for every type; lifetime is determined by reachability from durable roots; code is identical whether it operates on short-lived or long-lived state. A locus never decides whether it is 'in memory' — that decision belongs to the substrate, and the locus's semantics are unchanged by it.

Technical register

The term and the principles are Atkinson & Morrison's (PS-algol, Napier88; VLDB J. 4, 1995). In this stack the store that would realize them is studbook, at the spec rung with one unruled question (§10.2, where confidentiality comes from). The previous data layer was abandoned because Postgres stores a row but not why the row is that row, and nothing in its migration layer could refuse a row whose provenance did not check out. STATED; nothing implements it here.

Problem

Every application has a save path and a load path, and the bugs live between them: state that was in memory and not on disk, objects that persist by accident, serializers that lose the reason a value is what it is. The locus is made to care about its own storage, which is not a semantic question.

Solution

Give the substrate the persistence decision. Determine lifetime by reachability from declared roots. Keep one code path. Address content by hash so provenance is checkable. Rule the confidentiality question before holding anything with a user in it.

Real-world analogy

A library where every book is shelved by content and re-shelved as demand moves, and a reader who only ever asks for the book — never which stack it is on.

Structure — on the surface

compute surfacecacheRAMSSDremote nodeLsame code pathOne locus, four places its state might physically be. It never decides which.

An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.

The chapter in WRL — and the chain so far

Chapter 19 of 32 — the fragment _patterns/wrl/chain/orthogonal-persistence.wrl, sealed alone by wrl.js

; ORTHOGONAL PERSISTENCE — its OWN slow clock domain (every 3): the rotor persists between ticks without the
; locus asking to be saved; where the state physically lives between epochs is the runtime's business.
[pulser:op_clock](every 3){sig_out}
[spinner:op_locus](w=16, n=8, rotor=quarter_turn_z){sig_in, socket}
[orb:op_view]{pose}

[op_clock] --sig--> [op_locus]
[op_locus] --socket--> [op_view]

module + bench seal to → sem-2f7cb882544ba87c3d34a8d86297fe3104a73adf1a54ec4d0e0a9c0a8d5cb2d8

Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-66ce95db624331b0364… (the run inputs' own identity, computed by the forge)

No claims: the world runs on its clocks alone for 6 epochs.

Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (27.949s).

compute surfacesigsocketop_clock · Pulserop_clockpulserop_locus · Spinnerop_locusspinnerop_view · Orbop_vieworbThis chapter's world alone, before epoch 1. Reduced by TRVM's forge in 2.424s; the forge's id equals the seal above.
The Film, epoch by epoch (6)

epoch 1 · sha256:7bf5841e7510168668794baef7b46bf4fa604fa23f7165e928252c90df30c4de

FILM v0.7
t=1
spinner:op_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=op_view,config=fixed
orb:op_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=op_locus,fault=0
pulser:op_clock:mode=periodic,p=3,phase=0,armed=0,done=0,nf=1
wire:w__op_clock__op_locus:cur=0,nxt=0
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0

epoch 2 · sha256:2eeefc38f3b8ecbd72ec53dfbff232aac292548d520b9c91da810b224a66c4c2

FILM v0.7
t=2
spinner:op_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=op_view,config=fixed
orb:op_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=op_locus,fault=0
pulser:op_clock:mode=periodic,p=3,phase=0,armed=0,done=0,nf=3
wire:w__op_clock__op_locus:cur=0,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0

epoch 3 · sha256:2758e7e95ae9fa34f69b0f5e900c9ac7549f09864cb05313bb1126fa426d2d5c

FILM v0.7
t=3
spinner:op_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=op_view,config=fixed
orb:op_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00b5,0000,0000,00b5,controller=op_locus,fault=0
pulser:op_clock:mode=periodic,p=3,phase=0,armed=0,done=0,nf=2
wire:w__op_clock__op_locus:cur=1,nxt=0
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0

epoch 4 · sha256:d7533821cdffef91f32cffb7e31d58755aeb3d7c076dc6f162ac48ea6b89f459

FILM v0.7
t=4
spinner:op_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=op_view,config=fixed
orb:op_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00b5,0000,0000,00b5,controller=op_locus,fault=0
pulser:op_clock:mode=periodic,p=3,phase=0,armed=0,done=0,nf=1
wire:w__op_clock__op_locus:cur=0,nxt=0
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0

epoch 5 · sha256:480b51586e6e1d3e9f0b2322390b5565b78a1f0d1ac1e62ec48a3b6ec694082f

FILM v0.7
t=5
spinner:op_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=op_view,config=fixed
orb:op_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00b5,0000,0000,00b5,controller=op_locus,fault=0
pulser:op_clock:mode=periodic,p=3,phase=0,armed=0,done=0,nf=3
wire:w__op_clock__op_locus:cur=0,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0

epoch 6 · sha256:7c3662e20f95a2735f8242f76aee66b69fef6295a060825249120a3dc205b427

FILM v0.7
t=6
spinner:op_locus:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=op_view,config=fixed
orb:op_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,0000,00ff,controller=op_locus,fault=0
pulser:op_clock:mode=periodic,p=3,phase=0,armed=0,done=0,nf=2
wire:w__op_clock__op_locus:cur=1,nxt=0
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0

Composes with the 18 chapters before it

The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-f9b5f214740e3305d2dd179ab23bc883c799c6aa6c320c4588f854f98732d231: 74 objects, 67 edges (was 71 / 65; every earlier object and edge is still present — checked, or the build refuses).

How to read this board

Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.

shapeisand so
a clock; the only source of signalEvery signal on the board starts at one of these. Nothing else can make one.
a pass-through, so signal can travelOne arrives, any number leave — a relay that fans out is the board's router.
a sink; signal arrives and stopsIt latches what reached it and passes nothing on. A door is where a path ends.
rotation: takes signal, drives a poseThe only object on the board that holds a value a claim can rewrite — and only if its config says configurable.
the thing that gets movedIt is driven, never driving: an orb is what you watch to see whether anything happened.
not a WRL role — the book's own drawing of the receipts in the epoch's FilmIt counts what the run admitted, and turns red on a Rejected outcome.
SignalWiresignal: a sig_out to a sig_inLegal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves.
SocketControlcontrol: a socket to a poseLegal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal.

Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.

compute surfaceI · The LocusII · CompositionIII · ProgressIV · Persistence and Worldal_locus · Spinneral_locusspinneral_view · Orbal_vieworbal_world · Pulseral_worldpulsercb_fixed · Spinnercb_fixedspinnercb_gate · Doorcb_gatedoorcb_in · Relaycb_inrelaycb_view · Orbcb_vieworbcc_carrier · Doorcc_carrierdoorcc_grant · Relaycc_grantrelaycm_in · Relaycm_inrelaycm_locus0 · Doorcm_locus0doorcm_locus1 · Doorcm_locus1doorcm_locus2 · Doorcm_locus2doorcm_locus3 · Doorcm_locus3doorcm_slot0 · Relaycm_slot0relaycm_slot1 · Relaycm_slot1relaycm_slot2 · Relaycm_slot2relaycm_slot3 · Relaycm_slot3relayct_in · Relayct_inrelayct_locus · Spinnerct_locusspinnerct_view · Orbct_vieworbdb_clock · Pulserdb_clockpulserdb_locus · Spinnerdb_locusspinnerdb_view · Orbdb_vieworbis_id · Orbis_idorbis_in · Relayis_inrelayis_seal · Spinneris_sealspinnerlc_core · Relaylc_corerelaylc_locus · Spinnerlc_locusspinnerlc_machine · Relaylc_machinerelaylc_thread · Relaylc_threadrelaylc_view · Orblc_vieworbop_clock · Pulserop_clockpulserop_locus · Spinnerop_locusspinnerop_view · Orbop_vieworbpj_artifact · Spinnerpj_artifactspinnerpj_in · Relaypj_inrelaypj_view_a · Orbpj_view_aorbpj_view_b · Orbpj_view_borbpp_homeA · Relaypp_homeArelaypp_homeB · Relaypp_homeBrelaypp_in · Relaypp_inrelaypp_locus · Spinnerpp_locusspinnerpp_view · Orbpp_vieworbpq_a · Relaypq_arelaypq_b · Relaypq_brelaypq_clock · Pulserpq_clockpulserpq_done · Doorpq_donedoorpu_admitted · Orbpu_admittedorbpu_busy · Pulserpu_busypulserpu_hop0 · Relaypu_hop0relaypu_hop1 · Relaypu_hop1relaypu_hop2 · Relaypu_hop2relaypu_locus · Spinnerpu_locusspinnerpu_progress · Pulserpu_progresspulserpu_sink · Doorpu_sinkdoorrb_record · Orbrb_recordorbrd_in · Relayrd_inrelayrd_real · Spinnerrd_realspinnerrd_view · Orbrd_vieworbrj_join · Doorrj_joindoorrj_r · Relayrj_rrelaysm_in · Relaysm_inrelaysm_inside · Spinnersm_insidespinnersm_outside_a · Orbsm_outside_aorbsm_outside_b · Orbsm_outside_borbso_in · Relayso_inrelayso_pose · Orbso_poseorbso_rotor · Spinnerso_rotorspinnertv_a · Orbtv_aorbtv_b · Orbtv_borbtv_fixed · Spinnertv_fixedspinnertv_in · Relaytv_inrelaytv_open · Spinnertv_openspinner

The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.

Syntax — quoted from the tree at build time

Why the previous data layer went (studbook §2) studbook/docs/spec/README.md:37

   one pass with a certificate at every step. Postgres stores a row. It does not store
   *why the row is that row*, and nothing in the migration layer could refuse a row whose

What has to be ruled first (studbook §10) studbook/docs/spec/README.md:260

## 10. What has to be ruled before implementation starts

Forces

Orthogonal persistence hides a cost model: a remote node is not RAM. Reachability-based lifetime needs a garbage collector that understands durability. And a content-addressed store makes persistence honest and access control hard — the open ruling that blocks studbook.

Applicability

Durable agents, worlds that must survive their machines, any system whose 'persistence layer' is currently a source of bugs.

Transformations

Preserving
  • moving state between tiers
  • garbage-collecting what no root reaches
Refusing
  • a save() the locus must call
  • a persistent type distinct from a transient one
  • holding user data before §10.2 is ruled

A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.

Consequences

The locus stops asking where it lives. The cost is a substrate that must be built with the same care as the language — and, here, has not been built.

Failure mode it answers

Location Leak — Encoding physical placement into identity when placement is not semantic.

Witness

No witness. This pattern is STATED — the tree has no check for its invariant.

Counterexample

No counterexample shipped (required only when WITNESSED).

What to take away

  1. from the animationThe locus moved through four tiers and its code path never changed.
  2. from the syntaxThe spec's own header says: no implementation, do not build from this yet.
  3. from the literatureType orthogonality, persistence by reachability, persistence independence — credit Atkinson & Morrison, whose term this is.
  4. from the witnessSTATED at the spec rung; the studbook §10.2 ruling is the blocker and is published as one.

Prior art — and what is not claimed

workrelationwhat it shareswhere it differs
Atkinson & Morrison — type orthogonality, persistence by reachability, persistence independence (PS-algol, Napier88; VLDB J. 4, 1995)terminology precedentthe name and all three of its principlesnone. The term is theirs and the content is theirs

Novelty not claimed. Nothing. This chapter exists to cite Atkinson & Morrison correctly and to record that studbook is at the spec rung and nothing here implements it.

Realizations in the tree

Relations with other patterns

Continuity Through Reconstruction STATED · Three Sizes of World STATED