On this page
Owner: Origo Engineering
Last updated: 2026-04-14
Slice/version reference: S49
Purpose and scope
Runtime and operator reference for how Origo declares late-arrival policy and projection time semantics.
Scope covers the late-arrival registry, source-family timing modes, projection time modes, winner-selection rules, and the authoritative evidence surfaces for rejection and supersession truth.
This is a runtime reference. The authoritative machine contract is contracts/canonical-late-arrival-v1.json.
Authoritative surfaces
Machine-readable registry:
contracts/canonical-late-arrival-v1.json
Supporting contracts:
contracts/canonical-source-timestamp-semantics-v1.json
contracts/governance/event-sourcing.json
contracts/governance/observability-day-zero.json
Runtime evidence:
origo/events/runtime_audit.py
origo/query/bitcoin_mempool_boundary.py
Core rules
Projection time authority is singular and machine-readable.
Projection time-mode taxonomy is closed to:
event_time
ingestion_time
Current data-serving projections stay event_time.
In current Origo, event_time means bucket/window semantics and record timestamp semantics.
Operational progression remains separate:
stream_sequence
projector checkpoints
projector watermarks
last_source_event_time_utc
last_ingested_at_utc
Late-arrival windows never auto-widen.
Outside-window rejection must fail loud and land on an authoritative evidence surface.
In-window aligned supersession is a required named surface, but the aligned bucket replacement mechanism is still not runtime-enabled today.
Source-family timing modes
Exchange trades (binance, okx, bybit)
lateness semantics mode: clock_lag
current accepted window: partition open until terminal proof
outside-window evidence: runtime-audit rejection
ETF and FRED
lateness semantics mode: publication_delay
current accepted window: observation-day partition open until terminal proof
outside-window evidence: runtime-audit rejection
Bitcoin blockchain-derived families
lateness semantics mode: availability_boundary
current accepted window: block-height or partition availability until terminal proof
consensus time remains user-visible event time, but it is not the monotonic late-write gate
Bitcoin mempool
lateness semantics mode: availability_boundary
current accepted window: capture boundary availability only
outside-window evidence: query boundary error from mempool boundary enforcement
Projection semantics
native
time mode: event_time
winner selection: identity passthrough, no bucket competition
exchange aligned_1s
time mode: event_time
event-time scope: bucket/window semantics only
winner selection: source-offset order within bucket
ETF and FRED aligned_1s
time mode: event_time
event-time scope: bucket/window semantics only
winner selection: latest_ingested_at_utc, then source offset, then event_id
Bitcoin-derived aligned_1s
time mode: event_time
event-time scope: bucket/window semantics only
winner selection: source_event_time_utc, then source offset, then event_id
Bitcoin stream aligned_1s
time mode: event_time
event-time scope: bucket/window semantics only
winner selection: dataset-specific source-offset order within bucket
Operator-visible evidence
Runtime-audit rejection event:
Runtime-audit supersession event:
late_arrival_supersession
Mempool boundary errors remain user-visible query evidence for pre-boundary requests.
Grafana remains derived-only and must render those surfaces rather than invent a second timing authority.