# 信任邊界

了解讓 KuraDB 對消費端保持唯讀、對內保持一致的不變條件。

## 信任邊界與不變條件

### 讀取面

- HTTP API 只註冊 GET route；不得以 mutation endpoint 繞過 ingestion。
- MCP 只暴露兩個唯讀 tool：`list_rag` 與 `search_rag`；沒有任何 tool 會寫入 SQLite 或快取。
- HTTP listener 綁定 `127.0.0.1`，且 `/mcp` 只在啟動時已啟用 `remote` 才掛載。
- API response 會暴露 source、chunk 與 content，但不暴露內部 ID、score、hit count 或 total。

### 寫入路徑

- 內容寫入必須經過 watcher → parser → `databaseHandler.Upsert` → SQLite；`internal/database` 以外的層不寫入 `file_data`。
- Daemon 是唯一寫入者。`kura mcp` 開啟相同資料庫，但不註冊 query cache 寫入 hook，也不啟動 watcher 或 embedder。
- 圖片及其他被略過的 binary format 不會進入文字 embedding pipeline。

### 資料不變條件

- Keyword 與 semantic read 必須排除 `dismiss = TRUE` 的 row。
- Embedding 必須符合 process-wide `openai.Dim()`（512 維）。預載 `global.db` 時會略過其他大小的 query cache row；chunk 向量在載入時不檢查長度，搜尋時會略過長度與 query 不同的向量。
- 新註冊的資料庫只能在重新啟動後使用。
