Skip to content

Commit 0ad6a96

Browse files
committed
Repair native physical-owner probe activation
Construct the existing internal PhysicalOwnerProbeEndpoint through its owning singleton factory with the same validated host dependencies. Retain the closed existing-event registration first-cause diagnostics and original bounded startup collector. Derive the original active-abort healthy receipt at index166 from the independently fixed source index165 and one fresh journal submission. Commit the complete requested current working-tree scope on main. Native compiler and analyzers report zero errors and warnings; the isolated owning Server factory build, repository governance and diff checks passed. Original failed six-owner startup and Darwin loopback setup receipts remain distinct from operation proof. Current full solution build, formatter, complete Linux normal/scalar/process and SDK/official-MCP Aspire RF3, fresh compiled-image census and numeric functional coverage remain mandatory pending canonical CI. Previous Stage46 full local PASS receipts retain their original source cohort. No task acceptance is promoted: 17 of104 done,87 in progress. Three independent feature workers continue.
1 parent ae1dbc8 commit 0ad6a96

14 files changed

Lines changed: 304 additions & 28 deletions

File tree

‎docs/ADR/ADR-088-remote-queue-transfers.md‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -465,3 +465,25 @@ Scope is supporting native Kestrel original-packet replay, not complete typed St
465465
Native source audit: RemoteDocumentEndpoint.ExecuteAsync verifies full original MAC before native envelope selection; RemoteTransferPeerEndpointExecution.ExecuteAsync invokes actual Shape.Require then replay.TryUse(original nonce) before address/expiry/native receiver execution. The first real successful endpoint submission causally admits both MAC and shape; duplicate unchanged bytes therefore exercise nonce refusal. ReadReplyAsync charges the original MaximumReplyBytes; actual native reply MAC is verified with the real live receiver's validated NodeOptions.PeerSecret, verification only, never signing a fabricated request. The decoded reply must bind original RequestId/nonce, exclusive Accept/original outcome shape and exact bytes of the independently stored B outcome.
466466

467467
Expected original endpoint refusal is observed through a task that awaits the actual held producer and retains its actual KeyLoadException object; only exact Unauthenticated is an expected negative witness, every other failure is rethrown into the original cleanup ledger. No catch changes the HTTP response: the original middleware task still throws to the unchanged endpoint owner. The observed settlement task is tracked/joined under the same shutdown owner; raw original task completion is independently required before any root disposal. Public original SDK terminal must be UnknownWriteOutcome with null value, and fresh SAME-ID replay observes B without effects. A missing/mismatching endpoint refusal, successful unexpected original reply, extra native rows or unjoined task fails the test, with original lifetime unchanged.
468+
469+
470+
### TASK-KL094-REGISTRATION-FIRST-CAUSE-025 — bounded original registration discriminator
471+
472+
REQ-XFER-REGISTRATION-DIAGNOSTIC-001 / AC-XFER-REGISTRATION-DIAGNOSTIC-001 add only closed current stage/category and the original linked deadline/stopping cancellation flags to existing registration Event1004. Native controller retains MembershipPrerequisite, TargetProbes, Authentication, MembershipRevalidation, Registration or DirectoryVerification immediately before its existing work, under its existing lock. The same lock captures failure stage and actual monotonic cancellation flags. Domain/Cancellation/Protocol/Unexpected classification exposes no exception text, payload, credentials, request/owner/nonce IDs or new public/configuration/schema surface. Existing error code semantics remain exact.
473+
474+
Worker preserves the original exception identity and combines a genuine logging failure through ServerFailureObserver; original disposal and all native task/collector/root joins remain unchanged. No new IO/read/event/poll/retry/auth attempt, altered readiness predicate, token, ExecutionLifetime, clock, default, quota, signal wait or successful-operation behavior is introduced. Six-resource capture retains immutable original pre-cleanup evidence separately from later cleanup terminals.
475+
476+
Original R59 failed before operations with six pre-cleanup Running/Healthy resources and database health503. Existing1004 UnknownWriteOutcome alone cannot distinguish actual denied Register from a prerequisite deadline; later DurableJobs errors do not establish cause. The signal-only membership prerequisite may wait after a null observation without a later signal, but whether R59 took that path is UNKNOWN. The actual original failure remains retained.
477+
478+
Whole-operation gate is the unchanged zero-argument RemoteTransferDistinctOwnerTests.ActualDistinctOwnersRetainAcceptReceiptAcrossTwoColdRestartsAndBDoesNotResurrectAcknowledgedMessage with original cap1, twelve-minute cancellation, same physical owners and complete SDK/official MCP/Q1 receipts/models/two-cold/ACK/healthy continuation. A discriminator is diagnosis evidence only; it is not transfer acceptance, UID or PASS. Fresh exact-source Linux qualification and all original KL094 gates remain OPEN. ADR088/106/125 govern original transfer, prerequisite ownership and bounded connection execution.
479+
480+
The original passive first-failure classifier also recognizes the exact existing PhysicalOwnerRegistrationWorker[1004] owner/event at its unchanged Warning level. It charges the same original observed lines and retains the same six first-context, twelve tail and1024-byte per-line bounds. No generic warning, fabricated failure, additional subscription/read/task, resource state change or product telemetry is introduced. Later noise cannot displace that original first record.
481+
482+
483+
## TASK-KL094-PHYSICAL-PROBE-DI-OWNER-026
484+
485+
REQ-XFER-PROBE-DI-001: The actual receiver host owns one PhysicalOwnerProbeEndpoint singleton through an explicit composition factory calling its existing internal constructor. Resolve the same centrally validated node/routing/membership IOptions, actual receiver/work owner and TimeProvider from that host. Preserve existing native signed probe validation, admission, current persisted administrator reads, response, original token/deadline and joined singleton disposal. No public constructor, alternate endpoint/dispatcher, trust flag or readiness change is introduced.
486+
487+
AC-XFER-PROBE-DI-001: Actual original R65 Server assembly and Microsoft DI activation reject the previous implementation-type registration with InvalidOperationException because it has zero public constructors. The scoped factory must permit the original protected six-owner public transfer operation to reach its genuine signed receiver and pass full source/target state, SDK/official MCP/Q1, original receipt replay, two same-volume cold and ACK/no-resurrection oracles. The existing ActualDistinctOwnersRetainAcceptReceiptAcrossTwoColdRestartsAndBDoesNotResurrectAcknowledgedMessage case and all its original capacity/deadline/assertions remain unchanged. Native activation evidence alone does not qualify the RF3 operation or establish the full original R65 exception chain.
488+
489+
Implementation: Server/ClusterRouting/Hosting/PhysicalOwnerRegistrationServices.cs only; keep Transport/PhysicalOwnerProbeEndpoint.cs and all receiver security/work/cleanup bodies unchanged. Diagnostics predecessor is TASK-KL094-REGISTRATION-FIRST-CAUSE-025. Rollback restores only the registration factory, preserving diagnostics and original evidence. Exact-source Linux RF3 qualification remains OPEN.

‎docs/ADR/ADR-106-partition-owner-movement.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1905,3 +1905,9 @@ flowchart LR
19051905
```
19061906

19071907
Phase2 ancestry: the actual joined independent literal matrix now has68 families, including queue-order; cleanup has69 families plus its terminal iteration (70). This successor preserves Phase2 names exactly and uses strict fixed terminal236/abort source165/target71 totals. Historical source059 failed records remain unchanged evidence; they are not current qualification.
1908+
1909+
### TASK-KL036-ABORT-HEALTHY-RECEIPT-001
1910+
1911+
REQ-PMOVE-001 / AC-PMOVE-001 retain the complete independently specified abort ledger and healthy continuation. After the existing fixed source165/target71 assertions and genuine cold reopen, one previously unseen healthy command occupies native replica index166. ControlledPartitionMovementAbortHealthy's old146 oracle belongs to the retired smaller cleanup ledger. The same constant drives both the complete expected CommitReceipt and unchanged native LastIndex assertion; neither expected value may come from the actual outcome or production family count.
1912+
1913+
Implementation order: freeze this ADR and the PartitionTransfer feature append; root native preview/apply of only the existing HealthyReplicaIndex literal; native compiler/analyzers and unchanged source/identity inventory review; canonical delivered-source Linux normal/scalar whole original active-abort and child-cut cases, then the existing process/RF3/coverage gates. Preserve every full receipt/image/model/authority check, original argument, cancellation/deadline and joined resource/reader cleanup. The original Linux1c28e false receipt assertions and local macOS pre-body loopback refusal remain original failed cohorts. No production implementation, public contract, storage format, family, topology, limit, selector or legacy compatibility changes. This test-oracle amendment is source-present until authentic whole-flow results exist; it cannot mark the ADR or KL036 fully qualified.

‎docs/Features/ClusterRouting.md‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -439,3 +439,25 @@ Ownership: Integration ClusterRouting Models/RequestCqrsLifecycleSnapshot and ex
439439

440440
### TASK-KL015-ORIGINAL-OUTCOME-ASSERTION-OWNERSHIP-002
441441
The coherent R75 Release build found KLD0031: the scenario lifecycle owner contains203 code lines against200. Move only its original SDK/MCP denied-outcome join and exact held-request-ID assertion into the existing authority assertion owner. The lifecycle owner continues to await that SAME original task at the SAME JoinOriginalDenied stage before retiring the arm or performing final no-effect reads; preserve every null-owner failure, original error, token, deadline and literal state assertion. Existing ADR125 and the above acceptance contract suffice because no runtime, public or persisted contract changes. Fresh compiler, normal/scalar and genuine Linux RF3 results remain required; this responsibility change does not explain the original cancellation failure.
442+
443+
444+
### TASK-KL094-REGISTRATION-FIRST-CAUSE-025 — bounded original registration discriminator
445+
446+
REQ-XFER-REGISTRATION-DIAGNOSTIC-001 / AC-XFER-REGISTRATION-DIAGNOSTIC-001 add only closed current stage/category and the original linked deadline/stopping cancellation flags to existing registration Event1004. Native controller retains MembershipPrerequisite, TargetProbes, Authentication, MembershipRevalidation, Registration or DirectoryVerification immediately before its existing work, under its existing lock. The same lock captures failure stage and actual monotonic cancellation flags. Domain/Cancellation/Protocol/Unexpected classification exposes no exception text, payload, credentials, request/owner/nonce IDs or new public/configuration/schema surface. Existing error code semantics remain exact.
447+
448+
Worker preserves the original exception identity and combines a genuine logging failure through ServerFailureObserver; original disposal and all native task/collector/root joins remain unchanged. No new IO/read/event/poll/retry/auth attempt, altered readiness predicate, token, ExecutionLifetime, clock, default, quota, signal wait or successful-operation behavior is introduced. Six-resource capture retains immutable original pre-cleanup evidence separately from later cleanup terminals.
449+
450+
Original R59 failed before operations with six pre-cleanup Running/Healthy resources and database health503. Existing1004 UnknownWriteOutcome alone cannot distinguish actual denied Register from a prerequisite deadline; later DurableJobs errors do not establish cause. The signal-only membership prerequisite may wait after a null observation without a later signal, but whether R59 took that path is UNKNOWN. The actual original failure remains retained.
451+
452+
Whole-operation gate is the unchanged zero-argument RemoteTransferDistinctOwnerTests.ActualDistinctOwnersRetainAcceptReceiptAcrossTwoColdRestartsAndBDoesNotResurrectAcknowledgedMessage with original cap1, twelve-minute cancellation, same physical owners and complete SDK/official MCP/Q1 receipts/models/two-cold/ACK/healthy continuation. A discriminator is diagnosis evidence only; it is not transfer acceptance, UID or PASS. Fresh exact-source Linux qualification and all original KL094 gates remain OPEN. ADR088/106/125 govern original transfer, prerequisite ownership and bounded connection execution.
453+
454+
The original passive first-failure classifier also recognizes the exact existing PhysicalOwnerRegistrationWorker[1004] owner/event at its unchanged Warning level. It charges the same original observed lines and retains the same six first-context, twelve tail and1024-byte per-line bounds. No generic warning, fabricated failure, additional subscription/read/task, resource state change or product telemetry is introduced. Later noise cannot displace that original first record.
455+
456+
457+
## TASK-KL094-PHYSICAL-PROBE-DI-OWNER-026
458+
459+
REQ-XFER-PROBE-DI-001: The actual receiver host owns one PhysicalOwnerProbeEndpoint singleton through an explicit composition factory calling its existing internal constructor. Resolve the same centrally validated node/routing/membership IOptions, actual receiver/work owner and TimeProvider from that host. Preserve existing native signed probe validation, admission, current persisted administrator reads, response, original token/deadline and joined singleton disposal. No public constructor, alternate endpoint/dispatcher, trust flag or readiness change is introduced.
460+
461+
AC-XFER-PROBE-DI-001: Actual original R65 Server assembly and Microsoft DI activation reject the previous implementation-type registration with InvalidOperationException because it has zero public constructors. The scoped factory must permit the original protected six-owner public transfer operation to reach its genuine signed receiver and pass full source/target state, SDK/official MCP/Q1, original receipt replay, two same-volume cold and ACK/no-resurrection oracles. The existing ActualDistinctOwnersRetainAcceptReceiptAcrossTwoColdRestartsAndBDoesNotResurrectAcknowledgedMessage case and all its original capacity/deadline/assertions remain unchanged. Native activation evidence alone does not qualify the RF3 operation or establish the full original R65 exception chain.
462+
463+
Implementation: Server/ClusterRouting/Hosting/PhysicalOwnerRegistrationServices.cs only; keep Transport/PhysicalOwnerProbeEndpoint.cs and all receiver security/work/cleanup bodies unchanged. Diagnostics predecessor is TASK-KL094-REGISTRATION-FIRST-CAUSE-025. Rollback restores only the registration factory, preserving diagnostics and original evidence. Exact-source Linux RF3 qualification remains OPEN.

‎docs/Features/ClusterRouting/PartitionTransfer.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2113,3 +2113,9 @@ flowchart LR
21132113
```
21142114

21152115
Phase2 ancestry: the actual joined independent literal matrix now has68 families, including queue-order; cleanup has69 families plus its terminal iteration (70). This successor preserves Phase2 names exactly and uses strict fixed terminal236/abort source165/target71 totals. Historical source059 failed records remain unchanged evidence; they are not current qualification.
2116+
2117+
### TASK-KL036-ABORT-HEALTHY-RECEIPT-001
2118+
2119+
REQ-PMOVE-001 / AC-PMOVE-001 and TASK-KL036-INDEPENDENT-CLEANUP-COUNT-001 require the original cold abort to retain every original model, outcome, receipt, owner and image, then accept one fresh healthy document command. The independently frozen abort source ledger ends at165; the actual existing native journal admits exactly one unseen command at the next index. Therefore the independent complete healthy CommitReceipt and subsequent fixed LastIndex oracle must expect166. The original fixture still expects146 from the retired smaller cleanup ledger. Original Linux source1c28e/run38054816445 reached that exact full-receipt assertion and failed in normal/scalar; those originals remain failures. The current local same-case attempt failed before the operation body on macOS loopback binding, so it neither reproduces the receipt failure nor qualifies the repair.
2120+
2121+
Freeze this feature/ADR106 contract before changing only ControlledPartitionMovementAbortHealthy.HealthyReplicaIndex from146 to166. Do not obtain the expected index from the observed receipt, journal position or production inventory. Keep the fixed independent165/71 predecessor assertions and every complete serialized receipt field, native replay bytes, no-extra-entry checks, raw image/store position, cold reopen, document result, authority and original child-cut argument/deadline/cleanup assertion. Root owns the native guarded patch and delivered-source Linux normal/scalar/process/RF3 verification; the transfer/read/session owners continue independently. No production API, counter, family, quota, timeout, topology, source identity, alias, field ID or selector changes. ADR106's existing ownership and oracle contract applies; reversal removes only this undelivered test-oracle repair. Compiler/source review is separate from original whole-flow PASS and task acceptance.

‎docs/Features/CodeQuality.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2112,3 +2112,9 @@ REQ-CQ-009 and AC-CQ-018/019/039 govern the source-only successor of TASK-ASD-NA
21122112
The 2026-10-10 Stage46 local build passed with zero errors/warnings and unchanged 6835 source inputs. Actual MTP discovery observed all 3297 cases and the canonical compiled-image observer verified all 1706 declared Unit source files. Both actual four-case ANN executions passed, normal and scalar, against the same final image with native50, observed overlap4 and unchanged source/image/entry inputs. These results cover exact native physical read bytes, the one-byte-below refusal without mutation, bounded lookahead without a partial result and the original real deadline followed by healthy capture. Fresh group rediscovery, delivered-source Linux/RF3 execution and numeric functional coverage are separate evidence; earlier 12 discoveries retain their original cohort. The FeedLiveRf3Cold startup-order repair is source-present and runtime qualification remains pending. Root owns integration and original receipts; the independent feature owners continue without waiting for this metadata checkpoint. No whole-task promotion follows.
21132113

21142114
Stage46 final local checkpoint: canonical full verify-no-changes passed without source drift; the guarded four-row inventory joined at SHA256 6ce9df3553af4690458a95125696a4a775d860a76ab102910ef52ddb5edeecb9 and the unchanged canonical native-census validator admitted all3297 current cases against actual1706 compiled-source declarations. No case/group/selector membership changed and no fresh12-group execution or numeric coverage is claimed. Both original ANN operation profiles passed4/4; the cold all-three restart repair still requires the complete original Linux RF3 flows. See TEST-PIPELINE-001.currentStageXLVIDevelopment for original build, formatter, discovery, image and TRX receipt hashes.
2115+
2116+
### TASK-CQ-CURRENT-STAGE47-LINUX-JOIN-001
2117+
2118+
REQ-CQ-009 and AC-CQ-018/019/039 preserve the exact source/image qualification boundary for the guarded Stage47 owner repair. The owning physical-probe registration explicitly constructs the existing internal endpoint with the same validated native dependencies; the preceding existing-event discriminator preserves original diagnostic bounds and no credentials or caller payloads. The active-abort healthy oracle derives index166 from the independently fixed original source index165 and one genuine next Submit, retaining the complete literal receipt and cold state assertions. ClusterRouting/PartitionTransfer, RemoteTransfers and ADR-088/106/125 hold the feature contracts.
2119+
2120+
Native compiler/analyzers report zero errors/warnings after all joined source edits. The isolated owning Server factory compilation passed0/0; the original six-owner R65 startup failure, exact native DI internal-constructor refusal and deliberately incomplete post-factory diagnosis retain separate original receipts. The local original active-abort test failed before the operation body on Darwin address binding; it is not receipt or operation proof. Stage46 full build/formatter, actual3297 census and ANN4+4 original local successes remain their own immutable source cohort. Stage47 changes no test declaration, classification, group or selector inventory, but its current full solution build/formatter, fresh compiled-image census and required Linux normal/scalar/process/SDK/MCP RF3 must run against delivered source through the existing canonical workflow. No gate is removed or promoted, no task closes, and numeric functional coverage remains unmeasured. Root owns the complete requested source commit/push and current evidence; the three independent feature workers continue implementation and complete operation tests.

0 commit comments

Comments
 (0)