-- Verdict integrity (see docs/changes/2026-10-03_17-21_verdict-no-late-results-plan.md). -- -- ip_queue.checking_started_at: when the address entered the "checking" state. -- The aggregation window (checking_window_seconds) is counted from here, not -- from assigned_at, which also covers floating-IP association, the settle -- pause and the self-check. NULL on rows that predate this migration; the -- orchestrator falls back to assigned_at for them. -- -- checks.recorded_at: when control-api last wrote the row, by its own clock. -- checked_at comes from the probing machine's clock, so it cannot be compared -- reliably with aggregated_at. Existing rows get created_at (their first -- write); a later overwrite is not recoverable. -- -- checks.after_verdict: 1 when the row was written after the address's -- verdict (checked_at later than aggregated_at). Set here for existing data -- only; new writes after the verdict are rejected, so it stays 0 afterwards. ALTER TABLE ip_queue ADD COLUMN checking_started_at TIMESTAMP; ALTER TABLE checks ADD COLUMN recorded_at TIMESTAMP; UPDATE checks SET recorded_at = created_at; ALTER TABLE checks ADD COLUMN after_verdict INTEGER NOT NULL DEFAULT 0; UPDATE checks SET after_verdict = 1 WHERE EXISTS ( SELECT 1 FROM ip_queue q WHERE q.registry_id = checks.registry_id AND q.cycle_id = checks.cycle_id AND q.aggregated_at IS NOT NULL AND julianday(checks.checked_at) > julianday(q.aggregated_at) );