{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"layer_decay_and_expiration_management__computer_science","trajectory_id":"R","attempt_index":0,"archetype_slug":"layer_decay_and_expiration_management","domain_slug":"computer_science","decision":"CANDIDATE","problem_id":"obsolete_ci_artifact_registry_accumulation","causal_lever_id":"dependency_gated_artifact_lifecycle_disposition","proposal":{"problem":"CI build artifacts and immutable container images accumulate in software registries and remain discoverable or deployable after supersession. This increases storage, search burden, and the chance of using obsolete artifacts, while indiscriminate deletion can break rollback, provenance, incident reconstruction, or release holds.","actors_substrate":["release engineers and service owners","security, compliance, and incident-response teams","artifact registries containing versioned binaries, images, manifests, and metadata","deployment, rollback, and provenance systems referencing artifacts"],"observable_state":"Per artifact: identity, creation and last-access times, superseding release, deployment/reference count, retention class, hold status, storage tier, lifecycle state, restore-test result, and deletion record; system-level measures include active bytes, stale-artifact search exposure, restore success, and blocked dangling-reference deletions.","consequence":"Superseded artifacts remain authoritative-looking and costly, or cleanup removes artifacts still required by deployments, rollback, audit, or investigation.","affected_objective":"Keep registry storage and obsolete-artifact exposure bounded without sacrificing deployability, rollback, provenance, compliance, or incident reconstruction.","structural_mapping":[{"archetype_element":"sequential deposits","domain_realization":"Each CI run or release deposits a new versioned binary, image, manifest, or provenance bundle while earlier versions remain.","claim_kind":"INFERENCE"},{"archetype_element":"changed active usefulness","domain_realization":"Artifacts lose routine deployment value after supersession but may retain rollback, forensic, contractual, or evidentiary value.","claim_kind":"INFERENCE"},{"archetype_element":"stale layers mistaken for current","domain_realization":"Unmarked superseded versions can remain searchable or selectable beside approved releases.","claim_kind":"HYPOTHESIS"},{"archetype_element":"dependency-sensitive removal","domain_realization":"Deployments, manifests, rollback procedures, attestations, or external consumers may still reference an apparently old artifact.","claim_kind":"INFERENCE"},{"archetype_element":"differentiated expiration outcomes","domain_realization":"An artifact can remain hot, move to cold storage, be compacted, enter quarantine, or be destroyed rather than facing a keep/delete binary.","claim_kind":"INFERENCE"},{"archetype_element":"exception-governed bounded stack","domain_realization":"Retention classes and release or legal holds override ordinary expiry, while periodic revalidation prevents exceptions from silently becoming permanent.","claim_kind":"HYPOTHESIS"}],"component_map":[{"component":"layer_inventory_and_identity_map","status":"direct","domain_realization":"Digest-resolved catalog of artifacts, manifests, tags, and provenance bundles."},{"component":"deposition_order_and_age_index","status":"direct","domain_realization":"Build/release creation time and sequence index."},{"component":"retention_policy_matrix","status":"direct","domain_realization":"Artifact-class-to-retention and disposition table."},{"component":"decay_function_or_aging_rule","status":"adapted","domain_realization":"Age discounts routine value but cannot override holds or live dependencies."},{"component":"expiration_trigger_definition","status":"direct","domain_realization":"Class TTL or supersession-plus-inactivity makes an artifact eligible for review."},{"component":"layer_value_and_risk_score","status":"adapted","domain_realization":"Ranking combines access, reconstruction cost, vulnerability exposure, provenance, and rollback value."},{"component":"dependency_and_reconstruction_check","status":"direct","domain_realization":"Inbound-reference and rollback/rebuild check before disposition."},{"component":"pruning_or_archival_pathway","status":"direct","domain_realization":"Retain, refresh metadata, tier, quarantine, or destroy."},{"component":"preservation_exception_register","status":"direct","domain_realization":"Named rollback, investigation, historical, and evidentiary exceptions."},{"component":"deletion_audit_and_rollback_window","status":"direct","domain_realization":"Audited soft deletion followed by a bounded recovery period."},{"component":"resource_budget_and_storage_tier","status":"direct","domain_realization":"Registry byte budget and hot, warm, cold, or archive tiers."},{"component":"review_cadence_and_revalidation_loop","status":"direct","domain_realization":"Periodic policy, hold, restore, and exception review."},{"component":"legal_hold_or_compliance_override","status":"direct","domain_realization":"Release freeze, investigation, or legal hold blocks destruction."},{"component":"hot_warm_cold_access_state","status":"direct","domain_realization":"Tier state based on approved deployment and retrieval needs."},{"component":"orphan_layer_detection","status":"direct","domain_realization":"Artifact with no known live inbound reference or reconstruction duty."},{"component":"supersession_marker","status":"direct","domain_realization":"Metadata points from obsolete tags or versions to the approved successor."},{"component":"layer_compaction_candidate_flag","status":"adapted","domain_realization":"Flag redundant bundles or shared blobs for safe deduplication/repacking."},{"component":"rehydration_or_restore_procedure","status":"direct","domain_realization":"Retrieve, verify, and reconnect an archived artifact to registry and deployment tooling."},{"component":"deletion_impact_estimate","status":"direct","domain_realization":"Estimate affected services, rollback loss, rebuild cost, and compliance impact."},{"component":"stale_context_detector","status":"adapted","domain_realization":"Detect superseded, unapproved, vulnerable, or metadata-inconsistent artifacts."}],"mechanism_dispositions":[{"slug":"age_weighted_value_score","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Use only to rank review candidates; dependencies, holds, and policy remain vetoes.","counterfactual_removal":"Review becomes less efficiently prioritized, but deletion safety remains intact."},{"slug":"archive_restore_test","disposition":"selected_load_bearing","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Exercise sampled retrieval, digest verification, manifest resolution, and test deployment across age bands.","counterfactual_removal":"Archival recoverability becomes assumed rather than demonstrated, undermining rollback viability."},{"slug":"cache_eviction_rule","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Access recency is unsafe as the governing artifact-retention rule and cache capacity is not the target problem.","counterfactual_removal":"No proposed causal step changes."},{"slug":"dependency_safe_delete_check","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Trace known registry, deployment, rollback, provenance, and external references; incomplete visibility forces review.","counterfactual_removal":"Cleanup can delete live dependencies, hard-gating safe use."},{"slug":"lifecycle_storage_tiering_policy","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Demote retained artifacts by access need while preserving digest and provenance.","counterfactual_removal":"The system must choose costly active retention or earlier deletion."},{"slug":"log_rotation_and_cleanup_job","disposition":"incompatible","contribution_type":"NONE","adaptation_or_rejection":"Generational file rotation is content-blind and does not model independently referenced artifacts.","counterfactual_removal":"No proposed causal step changes."},{"slug":"retention_schedule","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Define class-specific minima, maxima, actions, exceptions, and holds.","counterfactual_removal":"Disposition lacks consistent authority and exception handling."},{"slug":"soft_delete_quarantine_window","disposition":"selected_load_bearing","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Hide candidates before destruction and size recovery windows by impact.","counterfactual_removal":"A mistaken automated decision becomes immediately irreversible."},{"slug":"stale_layer_detection_dashboard","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Expose identity-resolved stale and superseded candidates without acting on them.","counterfactual_removal":"Candidates remain harder to discover and ownership is less visible."},{"slug":"time_to_live_ttl_policy","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"TTL creates review eligibility, never unconditional destruction; renewal requires evidence of need.","counterfactual_removal":"Expiry initiation returns to irregular manual sweeps."},{"slug":"tombstone_or_deletion_marker","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Preserve digest identity, deletion reason, time, and successor while references and replicas converge.","counterfactual_removal":"Deletion becomes ambiguous and stale replicas or tags may revive obsolete artifacts."}],"causal_chain":["Inventory and mark superseded or context-stale artifacts.","Apply retention classes, expiry eligibility, exceptions, and holds.","Rank eligible artifacts without letting the score override policy.","Block candidates with live dependencies or unresolved reconstruction needs.","Tier or archive retained history; quarantine deletion candidates and publish tombstones.","Destroy only after the rollback window, while recording the decision and periodically proving archive restoration."],"baseline":"Teams retain artifacts indefinitely until quotas or bills force manual bulk cleanup, using age, tag, or last-access filters with inconsistent exceptions.","nearest_rival":"Registry garbage collection based only on untagged status or fixed age; it bounds storage more simply but does not govern holds, external dependencies, restoration, or stale discoverability.","authority_safety":{"affected_parties":["service owners relying on deployment or rollback","release and registry operators","security and incident-response teams","compliance, legal, and audit stakeholders","external consumers holding artifact digests"],"decision_authority":"The registry owner executes policy approved by release engineering and security; compliance or legal authorities control applicable holds, and service owners review unresolved dependencies.","authorized_first_step":"Run a 30-day pilot in one nonproduction registry namespace on at most 500 superseded artifacts: inventory and score all, archive a sample, quarantine only dependency-clear candidates, perform restore tests, and prohibit hard deletion.","excluded_actions":["hard-delete production artifacts during the pilot","override a legal, investigation, or release hold","treat low access or low score as proof of orphanhood","delete when dependency visibility is incomplete","claim sampled restore success proves all archives recoverable"],"halt_rollback":"Halt on any missed live reference, failed digest/fidelity check, restore failure above the preset tolerance, or attempted deployment of a quarantined artifact; restore quarantined artifacts, remove lifecycle automation, and preserve audit records for review."}},"negative_tests":{"strongest_counterevidence":"The proposal weakens if registry measurement shows nearly all bytes belong to current required artifacts, existing garbage collection already preserves all rollback and provenance obligations, or obsolete artifacts cannot be discovered or deployed.","analogy_break":"Artifact blobs may be shared across manifests and referenced externally by digest; apparent age or local orphanhood therefore does not reliably represent value or removability.","failure_condition":"The design fails if reference discovery cannot bound hidden consumers, holds cannot reliably veto destruction, or cold-tier restoration cannot meet the agreed recovery objective.","problem_falsifier":"Reject the diagnosed problem if a bounded inventory finds no material accumulation of superseded artifacts, no stale-selection incidents or exposure, and no meaningful storage, search, maintenance, or retention conflict.","intervention_falsifier":"Reject the intervention if, versus age-only cleanup, the pilot does not reduce active stale bytes or obsolete discoverability, or produces more missed dependencies, unrecoverable archives, policy violations, or operator effort than the preset acceptance bounds.","risks":["Composite scores create false precision or encode biased weights.","Incomplete dependency graphs misclassify externally referenced artifacts as orphans.","Quarantine conflicts with immediate erasure obligations.","Tiering increases retrieval delay and cost during rollback.","Tombstones and exception holds can themselves accumulate indefinitely.","Staleness inference may demote a valid but rarely used release."]},"null_rationale":null,"classification":{"candidate_kind":"MECHANISM_COMPOSITION","prior_art_status":"UNSEARCHED","evidence_maturity":"HYPOTHESIS"},"revision_change_log":{"revision_kind":"ORIGINAL","prior_problem_id":null,"prior_causal_lever_id":null,"problem_changed":false,"causal_lever_changed":false,"conceptual_changes":[],"operational_changes":[],"repairs_addressed":[]},"confidence":0.87,"generator_notes":"Closed-book structural inference from the supplied packet; empirical prevalence, thresholds, and pilot acceptance bounds remain hypotheses to be specified before execution."}