Skip to content

Commit 0235772

Browse files
committed
Assert fresh native RF3 readiness in interrupted request flows
1 parent 904d234 commit 0235772

6 files changed

Lines changed: 225 additions & 9 deletions

File tree

‎docs/ADR/ADR-082-native-cqrs-streams.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -377,3 +377,7 @@ REQ/AC-CRS-004/005 and REQ/AC-CRS-DIAG-004 retain the actual current-format thre
377377
Freeze a private failure-only stderr record at most256 UTF8 bytes, one record per original child, with exact prefix/version, actual phase enum ReadInput/ValidateRequest/OpenStore/ReadOutcome/DisposeStore/WriteReceipt, closed error-kind enum and optional existing KeyLoad ErrorCode or directly nested allowlisted native code1,2,5,9,11,13,16,20,22,24,28,35,40. No exception text/type name, path, identity, credentials, payload or arbitrary field. First initiating failure is frozen before store disposal; later cleanup cannot overwrite it. Original fatal exception priority and initiating plus output/disposal failure retention remain. Native V2 input/success receipt, failure exit2, stdin/receipt/capture bounds, deadlines, original task/lock joins and empty success stderr stay unchanged. Failure output never constitutes a success receipt.
378378

379379
The Integration oracle validates the exact closed record before including that static diagnostic in its failure; it continues to require exit0, exact canonical no-effect/majority outcomes and complete native child settlement. Existing real wrong-node/incarnation, malformed input and corrupt scoped-outcome/locator child flows assert the actual closed failure shape and phase, retain all joins/unchanged bytes, then perform their real healthy child/store continuation. This is mechanism evidence only; current scalar RF3 must rerun to expose its actual cause before any behavioral repair. Root owns review/join/build/native/Linux delivery. Rollback removes only these private observations and their regression amendments; product protocol, persistence, authorization and timebounds are unchanged.
380+
381+
### TASK-CRS-C1-FRESH-READINESS-ORACLE-002
382+
383+
REQ/AC-CRS-005, REQ/AC-CLIENT-004/005 and AC-CRS-FRESH-READINESS-002 retain full interrupted-submit/replay/conflict/healthy effect and original native RF3 receipt contracts. Root freezes the linked NativeCqrsRequestV2 source-backed advisory-cache distinction, joins the existing owned HTTP caller plus128-byte fixture bound and two actual one-shot readiness call sites, builds/formats and delivers for exact Linux SDK/official-MCP flows. The unchanged native readiness endpoint checks authenticated compatible-cohort and catalog admission; no cached status assertion becomes authority. Preserve before/after identity/applied/placement and every literal document/full receipt assertion. No poll, retry, timeout, product/cache/discovery, public data, package or topology change. Original source47 failed artifact remains immutable. Accepted test-oracle implementation contract; runtime qualification pending; rollback removes the coherent three-source amendment only. Root owns compilation/source join/Git; the three parallel feature agents continue independent parent implementation.

‎docs/Features/ClusterRouting/NativeCqrsRequestV2.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1038,3 +1038,11 @@ REQ/AC-CRS-004/005 and REQ/AC-CRS-DIAG-004 retain the actual current-format thre
10381038
Freeze a private failure-only stderr record at most256 UTF8 bytes, one record per original child, with exact prefix/version, actual phase enum ReadInput/ValidateRequest/OpenStore/ReadOutcome/DisposeStore/WriteReceipt, closed error-kind enum and optional existing KeyLoad ErrorCode or directly nested allowlisted native code1,2,5,9,11,13,16,20,22,24,28,35,40. No exception text/type name, path, identity, credentials, payload or arbitrary field. First initiating failure is frozen before store disposal; later cleanup cannot overwrite it. Original fatal exception priority and initiating plus output/disposal failure retention remain. Native V2 input/success receipt, failure exit2, stdin/receipt/capture bounds, deadlines, original task/lock joins and empty success stderr stay unchanged. Failure output never constitutes a success receipt.
10391039

10401040
The Integration oracle validates the exact closed record before including that static diagnostic in its failure; it continues to require exit0, exact canonical no-effect/majority outcomes and complete native child settlement. Existing real wrong-node/incarnation, malformed input and corrupt scoped-outcome/locator child flows assert the actual closed failure shape and phase, retain all joins/unchanged bytes, then perform their real healthy child/store continuation. This is mechanism evidence only; current scalar RF3 must rerun to expose its actual cause before any behavioral repair. Root owns review/join/build/native/Linux delivery. Rollback removes only these private observations and their regression amendments; product protocol, persistence, authorization and timebounds are unchanged.
1041+
1042+
### TASK-CRS-C1-FRESH-READINESS-ORACLE-002 (frozen before code)
1043+
1044+
REQ/AC-CRS-005 and REQ/AC-CLIENT-004/005 require actual healthy routed continuation after interrupted submit, complete same-ID replay/conflict, literal document revision/content and native RF3 receipts. Original source47 run37868406144/attempt1/job113620545601 passed11/12 KL014 cases; SdkSubmitReturnedCancellationReusesCommittedReceipt failed its after.RoutingReady assertion after the healthy commit returned. The source contract makes NodeStatus.RoutingReady a synchronous fresh-observation cache snapshot; actual discovery expires/removes observations before a bounded refresh. This source distinction does not establish the precise original runtime interleaving, and a cached boolean cannot prove current request admission.
1045+
1046+
AC-CRS-FRESH-READINESS-002 replaces only the two advisory before/after boolean assertions with one actual GET health/ready at each same boundary through the already owned SDK HttpClient. Require HTTP200 and the exact two-field JSON object status=ready/voters=3, bounded to128 body bytes with original response/body disposal. That native endpoint independently executes existing compatible-cohort and catalog admission. Any non200, malformed/extra/missing field, oversized body, cancellation or disposal failure fails the whole case. Do not poll, retry, sleep, extend any deadline, change product/cache/discovery behavior or infer readiness from a prior snapshot. The original before/after incarnation/node/applied and placement comparisons, full immutable receipts, changed-content denial, minimum-token SDK/official-MCP reads, complete literal state and original receipt replay all remain mandatory.
1047+
1048+
Root owns IntegrationTests ClusterRouting Helpers/RequestCqrsRf3Callers.cs (the original owned native HTTP operation), Contracts/RequestCqrsRf3Protocol.cs (fixture-only128-byte bound), Assertions/RequestCqrsFaultReplayContinuation.cs (two call sites) and the unchanged exact FaultSubmit/Returned SDK/MCP whole cases. Existing ADR082 owns this test-only observation contract; no new public schema, provider, trust boundary, storage or runtime implementation. Freeze, join, native build/format and exact original Linux normal/scalar task cases precede current closure. Preserve original failed artifact11589298518 SHA25635d4bffaeed1db10fcc365af728b60c1515fec33ada040a5f4cdf069ced5b688; rollback removes this coherent oracle amendment, never admits the failed original. Scope remains open until those genuine current-source RF3 flows pass.

‎docs/implementation/status.json‎

Lines changed: 182 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -226,12 +226,12 @@
226226
},
227227
"currentBuild": {
228228
"command": "dotnet build KeyLoad.slnx --no-restore --configuration Release --verbosity normal --disable-build-servers",
229-
"msbuildDebugDirectory": "/private/tmp/keyload-current-r832-kl008-native-unit-image-oracle-full-build-20261009-msbuild-debug",
229+
"msbuildDebugDirectory": "/private/tmp/keyload-r835-c1-fresh-native-readiness-full-build-20261009-msbuild-debug",
230230
"nativeExitCode": 0,
231231
"buildCompletedSuccessfully": true,
232-
"elapsedSeconds": 121.766,
233-
"log": "/private/tmp/keyload-current-r832-kl008-native-unit-image-oracle-full-build-20261009.log",
234-
"logSha256": "23ff2653090a47c96f151957349404aede7a9e98dda0a529bfa3de3f8a369d58",
232+
"elapsedSeconds": 122.536,
233+
"log": "/private/tmp/keyload-r835-c1-fresh-native-readiness-full-build-20261009.log",
234+
"logSha256": "97a25422f7d4924a003e986ce59637c39525b62ff45c97d5674aeeffbb85f8d1",
235235
"inputCount": 5337,
236236
"inputDrift": [],
237237
"uniqueErrors": [],
@@ -248,8 +248,8 @@
248248
"minimal"
249249
],
250250
"nativeExitCode": 0,
251-
"elapsedSeconds": 99.497,
252-
"log": "/private/tmp/keyload-current-r832-final-native-format-20261009.log",
251+
"elapsedSeconds": 94.499,
252+
"log": "/private/tmp/keyload-r835-c1-fresh-native-readiness-format-20261009.log",
253253
"logSha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
254254
"inputCount": 5337,
255255
"inputDrift": [],
@@ -37317,6 +37317,173 @@
3731737317
"KL-014 current-source original RoutingReady=false failure must be resolved and receive fresh exact task receipts; prior f80 originals remain immutable",
3731837318
"Complete product coverage/endurance/power-loss/performance remain open"
3731937319
]
37320+
},
37321+
"stageXXXIIIOriginalDevelopment": {
37322+
"sourceCheckoutBeforeCommit": "904d234c1c652626057673fd5fa127d924dd25f5",
37323+
"task": "TASK-CRS-C1-FRESH-READINESS-ORACLE-002",
37324+
"acceptance": "AC-CRS-FRESH-READINESS-002",
37325+
"implementation": "Two original whole-flow boundaries now execute one native health/ready call each, with HTTP200, exact status=ready/voters=3, 128-byte admission and original disposal; advisory cache snapshots no longer substitute for admission.",
37326+
"preserved": "Original unique authenticated SDK/MCP request, complete literal effect and RF3 receipts, retry/conflict, incarnation/node/applied/placement checks, all deadlines, node-local ownership and mandatory suites.",
37327+
"originalFailedBuild": {
37328+
"logPath": "/private/tmp/keyload-r834-c1-fresh-native-readiness-full-build-20261009.log",
37329+
"logSha256": "ae9f5019e05592fd19521da93055c2a9262c8fb2efbb7abd549e66a4cf2cb8bf",
37330+
"nativeExitCode": 1,
37331+
"cause": "Two KLD0001 diagnostics for protocol key literals; repaired with named fixture constants before the passing build."
37332+
},
37333+
"currentFullBuild": {
37334+
"command": "dotnet build KeyLoad.slnx --no-restore --configuration Release --verbosity normal --disable-build-servers",
37335+
"msbuildDebugDirectory": "/private/tmp/keyload-r835-c1-fresh-native-readiness-full-build-20261009-msbuild-debug",
37336+
"nativeExitCode": 0,
37337+
"buildCompletedSuccessfully": true,
37338+
"elapsedSeconds": 122.536,
37339+
"log": "/private/tmp/keyload-r835-c1-fresh-native-readiness-full-build-20261009.log",
37340+
"logSha256": "97a25422f7d4924a003e986ce59637c39525b62ff45c97d5674aeeffbb85f8d1",
37341+
"inputCount": 5337,
37342+
"inputDrift": [],
37343+
"uniqueErrors": [],
37344+
"qualification": "local development; source drift invalidates exact-current-source qualification"
37345+
},
37346+
"currentFullFormatter": {
37347+
"commandArgs": [
37348+
"dotnet",
37349+
"format",
37350+
"KeyLoad.slnx",
37351+
"--no-restore",
37352+
"--verify-no-changes",
37353+
"--verbosity",
37354+
"minimal"
37355+
],
37356+
"nativeExitCode": 0,
37357+
"elapsedSeconds": 94.499,
37358+
"log": "/private/tmp/keyload-r835-c1-fresh-native-readiness-format-20261009.log",
37359+
"logSha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
37360+
"inputCount": 5337,
37361+
"inputDrift": [],
37362+
"qualification": "native local source-bound formatter verification, not functional or Linux proof"
37363+
},
37364+
"relatedNativeWholeFlows": {
37365+
"normal20": {
37366+
"receiptPath": "/private/tmp/keyload-r835-related-storage-vector-normal20-20261009-receipt.json",
37367+
"receiptSha256": "9229528514fc0d5ea3ca4a9c1a1af856a6a147618187ac2199bf066477e2afe3",
37368+
"nativeExitCode": 0,
37369+
"elapsedSeconds": 6.884,
37370+
"originalTrxSha256": "95046d0a800527815fb0930e98824920d57882701ab4843d7dd8bdd56730e467",
37371+
"counts": {
37372+
"total": "54",
37373+
"executed": "54",
37374+
"passed": "54",
37375+
"failed": "0",
37376+
"error": "0",
37377+
"timeout": "0",
37378+
"aborted": "0",
37379+
"inconclusive": "0",
37380+
"passedButRunAborted": "0",
37381+
"notRunnable": "0",
37382+
"notExecuted": "0",
37383+
"disconnected": "0",
37384+
"warning": "0",
37385+
"completed": "0",
37386+
"inProgress": "0",
37387+
"pending": "0"
37388+
},
37389+
"sourceInputs": 5338,
37390+
"assemblyInputs": 553,
37391+
"sourceDrift": [],
37392+
"assemblyDrift": [],
37393+
"maximumParallelTests": 20,
37394+
"actualChildResourceUsage": {
37395+
"userCpuSeconds": 3.884585,
37396+
"systemCpuSeconds": 1.579283,
37397+
"childMaximumResidentBytesDarwin": 323862528,
37398+
"logicalCpuCount": 12,
37399+
"qualification": "actual operating-system child usage; no RF3 or benchmark inference"
37400+
},
37401+
"scope": "actual native 54 whole storage/vector operations; does not execute the changed RF3 readiness helper"
37402+
},
37403+
"scalar20": {
37404+
"receiptPath": "/private/tmp/keyload-r835-related-storage-vector-scalar20-20261009-receipt.json",
37405+
"receiptSha256": "e6c78e41cc2e8d1ddf03c3fc4f4c579e47477ecb3c4ccc70c567e59b64fc46ce",
37406+
"nativeExitCode": 0,
37407+
"elapsedSeconds": 7.909,
37408+
"originalTrxSha256": "9632ee84ec54cd3eb1c7aa602fc05575c5f594eda3a3818d5e5eac7ea18d009c",
37409+
"counts": {
37410+
"total": "54",
37411+
"executed": "54",
37412+
"passed": "54",
37413+
"failed": "0",
37414+
"error": "0",
37415+
"timeout": "0",
37416+
"aborted": "0",
37417+
"inconclusive": "0",
37418+
"passedButRunAborted": "0",
37419+
"notRunnable": "0",
37420+
"notExecuted": "0",
37421+
"disconnected": "0",
37422+
"warning": "0",
37423+
"completed": "0",
37424+
"inProgress": "0",
37425+
"pending": "0"
37426+
},
37427+
"sourceInputs": 5338,
37428+
"assemblyInputs": 553,
37429+
"sourceDrift": [],
37430+
"assemblyDrift": [],
37431+
"maximumParallelTests": 20,
37432+
"actualChildResourceUsage": {
37433+
"userCpuSeconds": 6.281072,
37434+
"systemCpuSeconds": 1.608818,
37435+
"childMaximumResidentBytesDarwin": 333856768,
37436+
"logicalCpuCount": 12,
37437+
"qualification": "actual operating-system child usage; no RF3 or benchmark inference"
37438+
},
37439+
"scope": "actual native 54 whole storage/vector operations; does not execute the changed RF3 readiness helper"
37440+
}
37441+
},
37442+
"nativeOverlap": {
37443+
"scope": "original local 54 whole-operation TRX intervals; no Linux or throughput promotion",
37444+
"lanes": [
37445+
{
37446+
"lane": "normal20",
37447+
"cases": 54,
37448+
"peakOverlappingActualNativeCaseIntervals": 17
37449+
},
37450+
{
37451+
"lane": "scalar20",
37452+
"cases": 54,
37453+
"peakOverlappingActualNativeCaseIntervals": 18
37454+
}
37455+
]
37456+
},
37457+
"sourceManifestOriginals": [
37458+
{
37459+
"path": "/private/tmp/keyload-r835-c1-fresh-native-readiness-source-20261009/functional-coverage.production-source-manifest.json",
37460+
"sha256": "2ab49b8559b665126bd409cf0e08c68f6cd6c15cc059d1a309ccad753548efee",
37461+
"length": 1368488
37462+
},
37463+
{
37464+
"path": "/private/tmp/keyload-r835-c1-fresh-native-readiness-source-20261009/functional-coverage.test-image.recovery.json",
37465+
"sha256": "da9107518a312357110864ce8563773faf1adef64030f8c73f1c1292b4d857f1",
37466+
"length": 97340
37467+
},
37468+
{
37469+
"path": "/private/tmp/keyload-r835-c1-fresh-native-readiness-source-20261009/functional-coverage.test-image.rf3.json",
37470+
"sha256": "bef02f684df32679cfa3900057fe855470cf189b3a5e7ad96f5c3f6bd08fa15b",
37471+
"length": 352775
37472+
},
37473+
{
37474+
"path": "/private/tmp/keyload-r835-c1-fresh-native-readiness-source-20261009/functional-coverage.test-image.unit.json",
37475+
"sha256": "d26f11fad209c4e2b8b7c90e429cc5e948fad30261869102ea9c37bc95136c3d",
37476+
"length": 1080536
37477+
}
37478+
],
37479+
"sourcePrepareExitCode": 0,
37480+
"sourceVerifyExitCode": 0,
37481+
"fullProductCoverage": null,
37482+
"qualification": "local source-bound development only; exact current Linux whole RF3 readiness flows pending",
37483+
"remaining": [
37484+
"Fresh exact-source Linux normal/scalar KL014 whole SDK/official-MCP RF3 cases",
37485+
"Complete current unit/recovery/RF3, functional coverage, endurance, power-loss and representative performance gates"
37486+
]
3732037487
}
3732137488
},
3732237489
"TIME-PROVIDER-001": {
@@ -40250,7 +40417,15 @@
4025040417
"receiptPath": "/private/tmp/keyload-47-kl014-normal-original-20261009/authenticity-and-original-failures.json",
4025140418
"receiptSha256": "6313568de6d5992ddf553bfd2f9704600b7b7827bdab580921537ff2cab153d4"
4025240419
},
40253-
"remaining": "Investigate native RoutingReady false observation after healthy committed continuation; fresh exact-source normal/scalar flows required."
40420+
"remaining": "Fresh exact-source normal/scalar Linux whole RF3 cases must validate the one-shot native readiness observation; original source47 failed artifact and historical f80 acceptance remain immutable.",
40421+
"currentRepair": {
40422+
"task": "TASK-CRS-C1-FRESH-READINESS-ORACLE-002",
40423+
"acceptance": "AC-CRS-FRESH-READINESS-002",
40424+
"developmentStage": "TEST-PIPELINE-001.stageXXXIIIOriginalDevelopment",
40425+
"localBuildPassed": true,
40426+
"localFormatterPassed": true,
40427+
"currentLinuxRf3Qualified": false
40428+
}
4025440429
}
4025540430
}
4025640431
},

‎tests/KeyLoad.IntegrationTests/Features/ClusterRouting/Assertions/RequestCqrsFaultReplayContinuation.cs‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,7 @@ private static async Task HealthyContinuationAsync(RequestCqrsRf3Callers callers
5050
await Assert.That(placement.Partition).IsEqualTo(reference.Partition);
5151
var before = await McpCallerAssertions.SdkSuccessAsync(await administrator.StatusAsync(cancellationToken)
5252
.ConfigureAwait(false)).ConfigureAwait(false);
53+
await callers.AssertFreshRoutingReadyAsync(cancellationToken).ConfigureAwait(false);
5354
await Assert.That(before.Incarnation).IsEqualTo(placement.Incarnation);
5455
await Assert.That(originalReceipt.Token.Incarnation).IsEqualTo(placement.Incarnation);
5556
await Assert.That(originalReceipt.Token.AtomicPartitionId).IsEqualTo(reference.Partition.AtomicPartitionId);
@@ -69,10 +70,9 @@ await Assert.That(JsonDefaults.Serialize(healthyReceipt.Mutations[MutationIndex]
6970
.SequenceEqual(JsonDefaults.Serialize(mutation))).IsTrue();
7071
var after = await McpCallerAssertions.SdkSuccessAsync(await administrator.StatusAsync(cancellationToken)
7172
.ConfigureAwait(false)).ConfigureAwait(false);
73+
await callers.AssertFreshRoutingReadyAsync(cancellationToken).ConfigureAwait(false);
7274
await Assert.That(after.Incarnation).IsEqualTo(placement.Incarnation);
7375
await Assert.That(after.NodeId).IsEqualTo(before.NodeId);
74-
await Assert.That(before.RoutingReady).IsTrue();
75-
await Assert.That(after.RoutingReady).IsTrue();
7676
var currentPlacement = await McpCallerAssertions.SdkSuccessAsync(await administrator.ReadAtomicPartitionPlacementAsync(
7777
new(PlacementVersion, reference.Partition), cancellationToken).ConfigureAwait(false)).ConfigureAwait(false);
7878
await Assert.That(JsonDefaults.Serialize(currentPlacement).SequenceEqual(JsonDefaults.Serialize(placement))).IsTrue();

‎tests/KeyLoad.IntegrationTests/Features/ClusterRouting/Contracts/RequestCqrsRf3Protocol.cs‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,11 @@ internal static class RequestCqrsRf3Protocol
1818
internal const string FollowerLossScenario = "cluster-routing-c1-compatible-follower-loss";
1919
internal const string ReadyPath = "health/ready";
2020
internal static readonly Uri ReadyUri = new(ReadyPath, UriKind.Relative);
21+
internal const int ReadyReplyMaximumBytes = 128;
22+
internal const int ReadyReplyPropertyCount = 2;
23+
internal const string ReadyReplyStatusProperty = "status";
24+
internal const string ReadyReplyVotersProperty = "voters";
25+
internal const string ReadyReplyExpectedStatus = "ready";
2126
internal const int NodeCount = 3;
2227
internal const int CurrentMajority = 2;
2328
internal const int ApplicationProtocolVersion = 4;

0 commit comments

Comments
 (0)