{
  "schema": 1,
  "sqlstate": "XX000",
  "condition_name": "internal_error",
  "sources": [
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.errcodes.18.6",
      "location": "lines 496-502",
      "path": "src/backend/utils/errcodes.txt",
      "sha256": "6e8de346643ba84aa3c9c6a73360acfc7b2dfb89162c06c08ce9bf5bcd5bbcba",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/utils/errcodes.txt"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.elog.18.6",
      "location": "lines 442-454",
      "path": "src/backend/utils/error/elog.c",
      "sha256": "766d30a426ba1d9597657bd46fb890da3e37e4ae53a83d1245bf082ed9433c33",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/utils/error/elog.c#L442-L454"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.nbtinsert.18.6",
      "location": "lines 754-766",
      "path": "src/backend/access/nbtree/nbtinsert.c",
      "sha256": "199671bec6b07b80100ea41632cef4b03a9525df75a2ede2b8fe155b637dcba7",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/access/nbtree/nbtinsert.c#L754-L766"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.dsm.18.6",
      "location": "lines 436-445",
      "path": "src/backend/storage/ipc/dsm.c",
      "sha256": "3ff99695b25e65764b6d0d2d5ddd8865984af6a434f9e903bcc33f0b7fc1dde8",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/storage/ipc/dsm.c#L436-L445"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.guc.18.6",
      "location": "lines 4964-4970",
      "path": "src/backend/utils/misc/guc.c",
      "sha256": "3021d40bb4e920a56fbc5e9452e32903a7364d7ce0aece65be70aa3c34c1274e",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/utils/misc/guc.c#L4964-L4970"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.uuid.18.6",
      "location": "lines 544-552",
      "path": "src/backend/utils/adt/uuid.c",
      "sha256": "64d3e8d22a87375b2b2b339bc9aec74f14f9b4996727c306ba1a0418e3fe0ffc",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/utils/adt/uuid.c#L544-L552"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.bufmask.18.6",
      "location": "lines 70-85",
      "path": "src/backend/access/common/bufmask.c",
      "sha256": "174b9f096b1c4b8f0cb75f45640b8c5cc94f101b21450e647e83e02f8e78d23d",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/access/common/bufmask.c#L70-L85"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "src.oat-hooks.18.6",
      "location": "lines 238-248",
      "path": "src/test/modules/test_oat_hooks/test_oat_hooks.c",
      "sha256": "8ee72c7930931969a7f447f55432f58b710f0949d6cfb2c1514f68fcdfb88438",
      "tag": "REL_18_6",
      "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/test/modules/test_oat_hooks/test_oat_hooks.c#L238-L248"
    },
    {
      "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
      "id": "doc.protocol.18",
      "location": "lines 6254-6290, severity fields",
      "path": "doc/src/sgml/protocol.sgml",
      "sha256": "745339e07ebbc2bb67d98b258e25772ada644ef26011e3cd6b3fcbb435235f89",
      "tag": "PG18-docs",
      "url": "https://www.postgresql.org/docs/18/protocol-error-fields.html"
    },
    {
      "commit": "313a720f95a3f41b59f853786b184f38f82172d9",
      "id": "doc.errcodes.8.1.4",
      "kind": "upstream_source",
      "location": "REL8_1_4 table rows 1313-1318",
      "path": "doc/src/sgml/errcodes.sgml",
      "release": "8.1.4",
      "sha256": "fdd6f5470b19970d3b60219a44e66b33193647975d346adfe2a98178f706b776",
      "url": "https://github.com/postgres/postgres/blob/313a720f95a3f41b59f853786b184f38f82172d9/doc/src/sgml/errcodes.sgml#L1313-L1318"
    },
    {
      "id": "manifest.XX000",
      "kind": "local_artifact",
      "location": "snapshots and definition_blobs entries for the XX000 definition",
      "sha256": "1727a275f336988ff96b4f9990a4ca253080f73fc5d316e7def165c8cf3708a8"
    },
    {
      "id": "case-manifest.XX000",
      "kind": "local_artifact",
      "location": "internal_error_safety_boundary",
      "sha256": "a3de1ad0d567c50db83967e9756adfb4b7dcdefb3a54efc2a9248191886fb325"
    },
    {
      "id": "runtime-raw.XX000.latest",
      "kind": "local_artifact",
      "location": "case_result for internal_error_safety_boundary",
      "sha256": "e7515f758483b38a16ce01952f7a09c978008d380d1ba93d7ecb63ea212caede"
    }
  ],
  "claims": [
    {
      "id": "identity.class-and-condition",
      "limits": "The generic class identity does not prove corruption or identify the subsystem.",
      "method": "Read the Class XX section, comment, and XX000 row in the frozen errcodes.txt snapshot.",
      "sources": [
        "src.errcodes.18.6"
      ],
      "statement": "XX000 is the internal_error condition in Class XX, Internal Error, whose source comment covers can't-happen conditions and software bugs."
    },
    {
      "id": "dispatch.default-internal",
      "limits": "Later errcode() construction can replace the initial value; the mapping is not a diagnosis of corruption.",
      "method": "Read the default sqlerrcode selection in errstart() in the fixed source.",
      "sources": [
        "src.elog.18.6"
      ],
      "statement": "Without a later explicit code, an ERROR or higher level is initialized with ERRCODE_INTERNAL_ERROR, while WARNING starts with ERRCODE_WARNING and lower levels with ERRCODE_SUCCESSFUL_COMPLETION."
    },
    {
      "id": "paths.explicit-internal",
      "limits": "These are distinct source paths with different preconditions and severities; they do not establish that a generic XX000 occurrence came from any one of them.",
      "method": "Read each errcode(ERRCODE_INTERNAL_ERROR) branch and its surrounding invariant or service diagnostic.",
      "sources": [
        "src.nbtinsert.18.6",
        "src.dsm.18.6",
        "src.guc.18.6",
        "src.uuid.18.6"
      ],
      "statement": "The fixed 18.6 source contains explicit XX000 paths for btree tuple rechecking, invalid dynamic shared-memory control state, configuration parameter redefinition, and strong-random UUID generation failure."
    },
    {
      "id": "paths.default-elog",
      "limits": "The source example is a diagnostic invariant check; a real occurrence requires the exact runtime path and environment.",
      "method": "Read the bufmask elog call and the error-stack default mapping.",
      "sources": [
        "src.bufmask.18.6",
        "src.elog.18.6"
      ],
      "statement": "A default elog(ERROR, ...) path such as the invalid-page check starts with XX000 through the generic severity mapping when it supplies no explicit SQLSTATE."
    },
    {
      "id": "paths.severity-separation",
      "limits": "The OAT hook is test-module code and does not represent normal production internal-error behavior.",
      "method": "Read each ereport level alongside its explicit errcode and compare the protocol severity contract.",
      "sources": [
        "src.dsm.18.6",
        "src.nbtinsert.18.6",
        "src.guc.18.6",
        "src.uuid.18.6",
        "src.oat-hooks.18.6"
      ],
      "statement": "An explicit XX000 does not force one wire severity: the shared-memory path is FATAL, several paths are ERROR, and the access-control hook can carry XX000 at NOTICE."
    },
    {
      "id": "protocol.severity-fields",
      "limits": "Severity is a wire property and must be interpreted with transaction and connection state.",
      "method": "Read the official PostgreSQL 18 Error and Notice Message Fields table.",
      "sources": [
        "doc.protocol.18"
      ],
      "statement": "The protocol distinguishes ERROR/FATAL/PANIC severities in error messages from WARNING/NOTICE/DEBUG/INFO/LOG severities in notice messages, with localized S and nonlocalized V fields."
    },
    {
      "id": "diagnosis.no-corruption-inference",
      "limits": "This is an evidence boundary, not a claim that corruption is impossible when XX000 occurs.",
      "method": "Compare the broad Class XX comment and the distinct source paths and messages.",
      "sources": [
        "src.errcodes.18.6",
        "src.nbtinsert.18.6",
        "src.bufmask.18.6",
        "src.dsm.18.6"
      ],
      "statement": "XX000 alone is insufficient to diagnose data or index corruption; the exact message, source path, severity, and surrounding evidence are required."
    },
    {
      "id": "runtime.safety-boundary",
      "limits": "This is not runtime proof of an XX000 occurrence; it records that fault or corruption injection was outside the accepted test boundary.",
      "method": "Read the stable case contract and both target summaries/raw records, retaining source_confirmed_only and not_applicable.",
      "sources": [
        "case-manifest.XX000",
        "runtime-raw.XX000.latest",
        "runtime.XX000-debug-latest.latest",
        "runtime.XX000-debug-pg10.pg10"
      ],
      "statement": "The internal_error_safety_boundary case is recorded as not_applicable on PostgreSQL 18.6 and 10.21 because no safe deterministic SQL trigger was used."
    },
    {
      "id": "versions.catalogue-boundary",
      "limits": "The pre-9.0 source set is locked through 8.4.22 but candidate source gaps remain for 7.0–7.3; the observed condition-name and class-title changes are not exact implementation introduction dates.",
      "method": "Read the manifest snapshot and the same-tag REL8_1_4 errcodes.sgml row for the code; the generated per-code record is derived from those entries.",
      "sources": [
        "manifest.XX000",
        "doc.errcodes.8.1.4"
      ],
      "statement": "The locked catalogue records XX000 in the 7.4–8.4.22 pre-9.0 formal sources, every listed formal snapshot from 9.0.23 through 18.6, and 19beta3. The same-tag REL8_1_4 errcodes.sgml row already lists XX000 as internal_error, confirming that condition-name observation by 8.1.4. The class title changes between the 9.0 header and 9.1 text definitions; candidate source gaps remain for 7.0–7.3. These are presence boundaries, not exact implementation introduction dates."
    }
  ],
  "messages": [
    {
      "hint_template": "This may be because of a non-immutable index expression.",
      "id": "message.index-refind",
      "limits": "The message belongs to the UNIQUE_CHECK_EXISTING btree path and carries a relation/constraint context.",
      "primary_template": "failed to re-find tuple within index \"%s\"",
      "severity_source": "explicit ERROR",
      "sources": [
        "src.nbtinsert.18.6"
      ],
      "sqlstate": "XX000"
    },
    {
      "id": "message.dsm-fatal",
      "limits": "This path terminates the backend session; it is not a generic client-side error template.",
      "primary_template": "dynamic shared memory control segment is not valid",
      "severity_source": "explicit FATAL",
      "sources": [
        "src.dsm.18.6"
      ],
      "sqlstate": "XX000"
    },
    {
      "id": "message.guc",
      "limits": "The template belongs to the custom GUC placeholder invariant path.",
      "primary_template": "attempt to redefine parameter \"%s\"",
      "severity_source": "explicit ERROR",
      "sources": [
        "src.guc.18.6"
      ],
      "sqlstate": "XX000"
    },
    {
      "id": "message.uuid",
      "limits": "The message reports failure of the strong-random provider in the UUID path.",
      "primary_template": "could not generate random values",
      "severity_source": "explicit ERROR",
      "sources": [
        "src.uuid.18.6"
      ],
      "sqlstate": "XX000"
    },
    {
      "id": "message.bufmask-default",
      "limits": "The XX000 code is supplied by the default mapping because this elog call has no explicit errcode.",
      "primary_template": "invalid page pd_lower %u pd_upper %u pd_special %u",
      "severity_source": "default elog(ERROR)",
      "sources": [
        "src.bufmask.18.6",
        "src.elog.18.6"
      ],
      "sqlstate": "XX000"
    },
    {
      "id": "message.oat-notice",
      "limits": "This is a test-module hook diagnostic demonstrating severity/code separation, not a production internal-error occurrence.",
      "primary_template": "in %s: %s %s %s [%s]",
      "severity_source": "explicit NOTICE",
      "sources": [
        "src.oat-hooks.18.6"
      ],
      "sqlstate": "XX000"
    }
  ],
  "usage_evidence": [
    {
      "evidence_ids": [
        "identity.class-and-condition",
        "src.errcodes.18.6"
      ],
      "scope": "directory_definition",
      "status": "definition_only"
    },
    {
      "evidence_ids": [
        "dispatch.default-internal",
        "paths.default-elog",
        "src.elog.18.6",
        "src.bufmask.18.6"
      ],
      "scope": "default_internal_mapping",
      "status": "source_path_confirmed"
    },
    {
      "evidence_ids": [
        "paths.explicit-internal",
        "paths.severity-separation",
        "src.nbtinsert.18.6",
        "src.dsm.18.6",
        "src.guc.18.6",
        "src.uuid.18.6",
        "src.oat-hooks.18.6"
      ],
      "scope": "explicit_internal_paths",
      "status": "source_path_confirmed"
    },
    {
      "evidence_ids": [
        "protocol.severity-fields",
        "diagnosis.no-corruption-inference",
        "doc.protocol.18"
      ],
      "scope": "severity_and_diagnosis",
      "status": "source_path_confirmed"
    },
    {
      "evidence_ids": [
        "runtime.safety-boundary",
        "runtime.XX000-debug-latest.latest",
        "runtime.XX000-debug-pg10.pg10"
      ],
      "notes": "The records intentionally mark the natural trigger not_applicable; no XX000 occurrence was observed.",
      "scope": "representative_runtime",
      "status": "unknown"
    },
    {
      "evidence_ids": [
        "versions.catalogue-boundary",
        "manifest.XX000",
        "doc.errcodes.8.1.4"
      ],
      "scope": "version_presence",
      "status": "definition_only"
    }
  ],
  "runtime": [
    {
      "cases": [
        "internal_error_safety_boundary"
      ],
      "id": "runtime.XX000-debug-latest.latest",
      "limits": "No internal-error path was executed.",
      "reason": "source_confirmed_only",
      "run_id": "XX000-debug-latest",
      "server_version": "18.6 (Homebrew)",
      "server_version_num": 180006,
      "status": "not_applicable",
      "target": "latest"
    },
    {
      "cases": [
        "internal_error_safety_boundary"
      ],
      "id": "runtime.XX000-debug-pg10.pg10",
      "image": "postgres@sha256:b2baf8998630663d21370da06387c950e587071bdd307ee34e661cdcc7442bcc",
      "limits": "No internal-error path was executed.",
      "reason": "source_confirmed_only",
      "run_id": "XX000-debug-pg10",
      "server_version": "10.21 (Debian 10.21-1.pgdg90+1)",
      "server_version_num": 100021,
      "status": "not_applicable",
      "target": "pg10"
    }
  ]
}
