Skip to content

Commit 301181f

Browse files
committed
remove migrations
1 parent ed60786 commit 301181f

436 files changed

Lines changed: 5289 additions & 20600 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/ci.yml‎

Lines changed: 0 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -215,41 +215,14 @@ jobs:
215215
- name: Build KeyLoad server and benchmark Docker images
216216
id: images
217217
run: node scripts/Features/BenchmarkComparisons/prepare-images.mjs
218-
- name: Build the genuine previous KeyLoad server image
219-
id: prior-images
220-
run: node scripts/Features/StorageRecovery/prepare-native5-server-image.mjs
221-
- name: Build the genuine epoch-six RPC1 KeyLoad server image
222-
id: rpc1-images
223-
run: node scripts/Features/ClusterRouting/prepare-rpc1-server-image.mjs
224-
- name: Build the genuine epoch-seven interface-three KeyLoad server image
225-
id: interface3-images
226-
run: node scripts/Features/ClusterRouting/prepare-interface3-server-image.mjs
227218
- name: Configure Docker image references
228219
shell: bash
229220
env:
230221
KEYLOAD_SERVER_IMAGE: ${{ steps.images.outputs.server-image }}
231222
KEYLOAD_RUNNER_IMAGE: ${{ steps.images.outputs.load-generator-image }}
232-
KEYLOAD_PRIOR_SERVER_IMAGE: ${{ steps.prior-images.outputs.prior-server-image }}
233-
KEYLOAD_PRIOR_IMAGE_RECEIPT: ${{ steps.prior-images.outputs.prior-image-receipt }}
234-
KEYLOAD_PRIOR_SERVER_MANIFEST: ${{ steps.prior-images.outputs.prior-server-manifest }}
235-
KEYLOAD_RPC1_SERVER_IMAGE: ${{ steps.rpc1-images.outputs.KEYLOAD_RPC1_SERVER_IMAGE }}
236-
KEYLOAD_RPC1_IMAGE_RECEIPT: ${{ steps.rpc1-images.outputs.KEYLOAD_RPC1_IMAGE_RECEIPT }}
237-
KEYLOAD_RPC1_SERVER_MANIFEST: ${{ steps.rpc1-images.outputs.KEYLOAD_RPC1_SERVER_MANIFEST }}
238-
KEYLOAD_INTERFACE3_SERVER_IMAGE: ${{ steps.interface3-images.outputs.KEYLOAD_INTERFACE3_SERVER_IMAGE }}
239-
KEYLOAD_INTERFACE3_IMAGE_RECEIPT: ${{ steps.interface3-images.outputs.KEYLOAD_INTERFACE3_IMAGE_RECEIPT }}
240-
KEYLOAD_INTERFACE3_SERVER_MANIFEST: ${{ steps.interface3-images.outputs.KEYLOAD_INTERFACE3_SERVER_MANIFEST }}
241-
KEYLOAD_INTERFACE3_SERVER_INVENTORY: ${{ steps.interface3-images.outputs.KEYLOAD_INTERFACE3_SERVER_INVENTORY }}
242-
KEYLOAD_INTERFACE3_SERVER_ARCHIVE: ${{ steps.interface3-images.outputs.KEYLOAD_INTERFACE3_SERVER_ARCHIVE }}
243223
run: |
244224
test -n "$KEYLOAD_SERVER_IMAGE" && test -n "$KEYLOAD_RUNNER_IMAGE"
245-
test -n "$KEYLOAD_PRIOR_SERVER_IMAGE" && test -n "$KEYLOAD_PRIOR_IMAGE_RECEIPT" && test -n "$KEYLOAD_PRIOR_SERVER_MANIFEST"
246-
test -n "$KEYLOAD_RPC1_SERVER_IMAGE" && test -n "$KEYLOAD_RPC1_IMAGE_RECEIPT" && test -n "$KEYLOAD_RPC1_SERVER_MANIFEST"
247-
test -n "$KEYLOAD_INTERFACE3_SERVER_IMAGE" && test -n "$KEYLOAD_INTERFACE3_IMAGE_RECEIPT" && test -n "$KEYLOAD_INTERFACE3_SERVER_MANIFEST"
248-
test -n "$KEYLOAD_INTERFACE3_SERVER_INVENTORY" && test -n "$KEYLOAD_INTERFACE3_SERVER_ARCHIVE"
249225
printf 'KeyLoad__ContainerImages__Server=%s\nBenchmarks__ContainerImages__LoadGenerator=%s\nKEYLOAD_IMAGE_RECEIPT=%s\n' "$KEYLOAD_SERVER_IMAGE" "$KEYLOAD_RUNNER_IMAGE" "$RUNNER_TEMP/keyload-images/image-receipt.json" >> "$GITHUB_ENV"
250-
printf 'KEYLOAD_PRIOR_SERVER_IMAGE=%s\nKEYLOAD_PRIOR_IMAGE_RECEIPT=%s\nKEYLOAD_PRIOR_SERVER_MANIFEST=%s\n' "$KEYLOAD_PRIOR_SERVER_IMAGE" "$KEYLOAD_PRIOR_IMAGE_RECEIPT" "$KEYLOAD_PRIOR_SERVER_MANIFEST" >> "$GITHUB_ENV"
251-
printf 'KEYLOAD_RPC1_SERVER_IMAGE=%s\nKEYLOAD_RPC1_IMAGE_RECEIPT=%s\nKEYLOAD_RPC1_SERVER_MANIFEST=%s\n' "$KEYLOAD_RPC1_SERVER_IMAGE" "$KEYLOAD_RPC1_IMAGE_RECEIPT" "$KEYLOAD_RPC1_SERVER_MANIFEST" >> "$GITHUB_ENV"
252-
printf 'KEYLOAD_INTERFACE3_SERVER_IMAGE=%s\nKEYLOAD_INTERFACE3_IMAGE_RECEIPT=%s\nKEYLOAD_INTERFACE3_SERVER_MANIFEST=%s\nKEYLOAD_INTERFACE3_SERVER_INVENTORY=%s\nKEYLOAD_INTERFACE3_SERVER_ARCHIVE=%s\n' "$KEYLOAD_INTERFACE3_SERVER_IMAGE" "$KEYLOAD_INTERFACE3_IMAGE_RECEIPT" "$KEYLOAD_INTERFACE3_SERVER_MANIFEST" "$KEYLOAD_INTERFACE3_SERVER_INVENTORY" "$KEYLOAD_INTERFACE3_SERVER_ARCHIVE" >> "$GITHUB_ENV"
253226
- name: Find Chrome for admin tests
254227
shell: bash
255228
run: |

‎AGENTS.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -405,6 +405,7 @@ Local `AGENTS.md` files may tighten these values, but they must not loosen them
405405
- Local rules and ADRs MUST NOT weaken `MCAF-ARCH-001`; they may only document stricter rules or a time-bounded migration to compliance.
406406
- Prefer composition over inheritance unless inheritance is explicitly justified.
407407
- Do not preserve obsolete, dead, duplicate, or replaced legacy code unless the user explicitly asks for a temporary compatibility path.
408+
- Owner correction 2026-10-06 removes backward compatibility with unreleased development storage formats from the first-release scope. Implement and qualify one current native storage format; remove old-format readers, migration/probe executables, historical-format test preparation and their active acceptance gates instead of developing compatibility for an unfinished product. This explicitly supersedes earlier requirements to migrate native5/native6/native7 development epochs before the first release. Preserve current-format process recovery, backup/restore, RF3 correctness and strict rejection of unsupported or corrupt formats; a later released-format upgrade requires a separate owner-approved contract.
408409
- When replacing an old implementation, remove the old code, tests, configuration, docs, and routing in the same change once the new path is proven.
409410
- Do not leave compatibility shims, placeholder implementations, or fallback paths as a substitute for a complete migration.
410411
- If a temporary transition path is unavoidable, document the reason, owner, scope, verification, and removal plan in the nearest ADR, feature doc, or local `AGENTS.md`.
@@ -523,3 +524,10 @@ A bounded website qualification candidate contains the20-project historical runt
523524
## Final Benchmarks Website trigger, owner clarification 2026-10-06
524525

525526
- Benchmarks MUST finish with only a bounded dispatch of the separate Website workflow; it MUST NOT build, test or deploy the site itself. This supersedes Website's `workflow_run` completion subscription. Confine dispatch permission to that final trigger job, keep main/manual Website publication independent, and authenticate any supplied producer run through GitHub before bounded completion waiting and newest-ready selection. A trigger input is not metric provenance or permission to bypass website qualification.
527+
528+
## Super rule: owner-only migration and legacy authorization
529+
530+
- Owner correction 2026-10-06: KeyLoad is a new product. Do not implement or retain data, schema, storage-format, persisted-record, configuration or prior-KeyLoad-version migrations, legacy readers, compatibility shims, dual paths or fallbacks unless the owner directly requests that specific migration or legacy path.
531+
- This prohibition is the highest project rule for migration/legacy scope and explicitly supersedes every earlier plan, ADR, feature requirement, acceptance gate, local policy and inferred authorization to maintain unreleased or previous KeyLoad implementations. A generic instruction to finish the product, an agent proposal or a recorded migration contract is not the owner's direct permission.
532+
- Delete existing KeyLoad-owned migration and legacy implementations now, together with their exclusive tests, helpers, prior-binary/image preparation, configuration, routes, dependencies and active documentation/plan references. Do not preserve them as dead branches or deferred cleanup and do not replace them with a new migration mechanism.
533+
- Implement and qualify the current product contract. Preserve current-format crash recovery, verified backup/restore, persisted authorization, strict unsupported/corrupt-version rejection and genuine Aspire RF3. Native Orleans activation movement and SQL interoperability with external clients are current product capabilities, not authorization for legacy KeyLoad code or data conversion.

‎docs/ADR/ADR-001-partition-identity-affinity.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,21 +12,21 @@ Resolve one `AtomicPartitionId` from the server-validated tenant, database, `Tra
1212

1313
## Rationale, alternatives, consequences
1414

15-
This makes authorization, command routing, transaction scope, and idempotency agree. Per-resource independent identity would prevent required document/event/local-queue transactions; using a raw key string globally would leak state across domains. A partition-per-engine/grain model is also rejected because it couples logical cardinality to physical resources. Catalog binding and migration now become correctness-critical, and a split must preserve unique constraints and command/read tokens or reject the operation.
15+
This makes authorization, command routing, transaction scope, and idempotency agree. Per-resource independent identity would prevent required document/event/local-queue transactions; using a raw key string globally would leak state across domains. A partition-per-engine/grain model is also rejected because it couples logical cardinality to physical resources. Catalog binding and physical movement are correctness-critical; movement must preserve unique constraints and command/read tokens or reject the operation.
1616

1717
## Related requirements
1818

1919
`REQ-DSTORE-004`/`AC-DSTORE-004`, `REQ-MSG-005`/`AC-MSG-005`, and `REQ-GRAPH-001`/`AC-GRAPH-001`; see [DocumentStorage](../Features/DocumentStorage.md), [Messaging](../Features/Messaging.md), and [GraphTraversal](../Features/GraphTraversal.md). Cluster routing and placement requirements remain in [ClusterRouting](../Features/ClusterRouting.md) and [ClusterReplication](../Features/ClusterReplication.md).
2020

2121
## Implementation contract
2222

23-
1. Freeze canonical identity fields, catalog binding validation, compatibility fixtures, and token lineage before changing routing.
23+
1. Freeze canonical identity fields, catalog binding validation, movement fixtures, and token lineage before changing routing.
2424
2. Add real tests for cross-domain key reuse, valid shared resources, authorization, stable command scope, and split/movement boundaries.
2525
3. Implement in `src/KeyLoad.Abstractions/Features/ClusterRouting/` and `src/KeyLoad.Core/Features/ClusterRouting/`; route via the owning Orleans request/partition grains. Preserve the current node-local `PartitionHost` ownership of stores and locks.
26-
4. Migration imports old isolated-domain mappings explicitly; reject ambiguous bindings. Rollout keeps old routing until a verified catalog/ownership epoch is active. Rollback returns to the old owner only with a complete committed cut and fenced epoch.
26+
4. Create resources under the canonical catalog binding and reject ambiguous or absent bindings. A physical move fences the current owner, publishes only after a verified catalog/ownership epoch and complete committed cut, and returns to that owner on rollback only while its state remains complete and fenced.
2727
5. GitHub Actions must run TUnit, recovery, and Aspire RF3 through .NET and MCP SDKs; compare stable outcomes across failover and movement. Root owns shared resolver/contracts; worker joins only after exact tests and changed paths are reported.
2828

29-
Dependencies: [ADR-002](ADR-002-command-idempotency.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), [ADR-007](ADR-007-replica-consensus-bootstrap.md), [ADR-016](ADR-016-atomic-physical-placement.md), and [ADR-017](ADR-017-migration-tokens.md). Verification: named catalog tests plus the repository GitHub CI matrix; no local test qualification. Stop if a source binding, token lineage, or multi-resource atomic scope is ambiguous; do not add a physical-placement shortcut.
29+
Dependencies: [ADR-002](ADR-002-command-idempotency.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), [ADR-007](ADR-007-replica-consensus-bootstrap.md), and [ADR-016](ADR-016-atomic-physical-placement.md). Verification: named catalog tests plus the repository GitHub CI matrix; no local test qualification. Stop if a source binding, token lineage, or multi-resource atomic scope is ambiguous; do not add a physical-placement shortcut.
3030

3131
```mermaid
3232
flowchart LR

‎docs/ADR/ADR-002-command-idempotency.md‎

Lines changed: 24 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -19,10 +19,10 @@ Persisting command identity with effects resolves lost responses across process
1919
1. Freeze command fingerprint inputs, principal/scope binding, error replay, and retention horizon before changing envelopes.
2020
2. Add TUnit tests for same-ID/same-content replay, same-ID/changed-content conflict, lost response after commit, precondition failure replay, and unrelated principal/partition scope.
2121
3. Keep shared command/request/outcome contracts in the existing `src/KeyLoad.Abstractions/Contracts.cs` building block and dispatch/persisted outcome handling in `src/KeyLoad.Core/DatabaseEngine.cs`; feature-specific mutation logic remains in its canonical owning `Features/<SliceName>/` directory. Do not create a separate CommandExecution slice or project.
22-
4. This ADR authorizes no outcome-format migration, compatibility reader, dual-format read/write path, or legacy fallback. If an existing persisted outcome requires an upgrade, stop until [ADR-011](ADR-011-format-upgrades.md) is Accepted with the concrete format version, migration mode, and rollback boundary. Any temporary compatibility transition additionally requires a documented reason, owner, exact scope, verification, and removal date. Until then, unknown formats fail closed.
22+
4. The current outcome format has one canonical reader and writer. Unknown, malformed, or unsupported outcomes fail closed without rewrite or alternate-key lookup.
2323
5. GitHub qualification is TUnit, real process recovery, and RF3 SDK outcomes after leader change. Root owns shared command contracts; feature owners join with fingerprint vectors and named test evidence.
2424

25-
Dependencies: [ADR-001](ADR-001-partition-identity-affinity.md), [ADR-003](ADR-003-durability-ack-barrier.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), [ADR-011](ADR-011-format-upgrades.md), and [ADR-016](ADR-016-atomic-physical-placement.md). Stop if canonical fingerprint or dedup expiry behavior is not specified. Do not infer exactly-once handler execution or include an external API call in the database transaction.
25+
Dependencies: [ADR-001](ADR-001-partition-identity-affinity.md), [ADR-003](ADR-003-durability-ack-barrier.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), and [ADR-016](ADR-016-atomic-physical-placement.md). Stop if canonical fingerprint or dedup expiry behavior is not specified. Do not infer exactly-once handler execution or include an external API call in the database transaction.
2626

2727
## TASK-DSTORE-COMMAND-100-RESTART implementation contract
2828

@@ -32,18 +32,16 @@ UnitTests/Features/DocumentStorage. Root freezes the literal error, document,
3232
revision and outbox oracles; query_wave owns only the new cases/helpers. This
3333
stage changes no outcome format, canonical key or public API. Current source
3434
uses principal/command keys and partition-bearing fingerprints; independent
35-
resolved-partition identity remains an explicit implementation gap. The Accepted
36-
decision above is unchanged. Root must define the exact upgrade and public
37-
resolution contract under ADR-011 before repairing that separate gap. Tests of
38-
principal isolation must not stand in for partition isolation.
35+
resolved-partition identity remains an explicit implementation gap. The accepted identity decision remains unchanged. Tests of principal isolation
36+
must not stand in for partition isolation.
3937

4038
Current command outcomes have no automatic TTL or purge implementation. A
4139
matching authorized retry resolves its retained canonical outcome in the same
4240
store incarnation. This does not promise a finite minimum retention period,
4341
eternal replay after explicit store/record removal, or replay across a changed
4442
incarnation; an existing outcome from another incarnation is TokenInvalidated.
45-
Adding expiry, purge, a minimum temporal horizon or an outcome-format change
46-
requires its own accepted policy and migration contract before implementation.
43+
Expiry, purge, a minimum temporal horizon, and outcome-format changes require
44+
a separately accepted current-product contract before implementation.
4745

4846
REQ-DSTORE-006 / AC-DSTORE-006 and original KL-012 require two actual CrashHost
4947
processes over one owned native ZoneTree store. The first commits one authorized
@@ -87,28 +85,23 @@ flowchart LR
8785
Effects --> Commit[Ordered commit]
8886
```
8987

90-
## Accepted scoped-key completion, 2026-10-05
88+
## Accepted scoped command-outcome contract, 2026-10-05
9189

9290
REQ/AC-DSTORE-009 and TASK-DSTORE-SCOPED-OUTCOMES-001..004 in
93-
[DocumentStorage](../Features/DocumentStorage.md) now freeze the independent
94-
full-partition identity missing from the earlier test-only matrix. The exact
95-
[ADR-011 outcome-v2 matrix](ADR-011-format-upgrades.md) accepts cold homogeneous
96-
writes to scoped v2 keys while retaining and validating original native outcome
97-
bytes. Existing fingerprint/authorization/incarnation/error/atomicity semantics
98-
remain required. Remove public principal/ID-only result/key access; every active
99-
lookup carries its original normalized operation. No SDK/HTTP/MCP endpoint
100-
replacement is needed because none exposes that removed Core API.
101-
102-
Ordered stages and exact file/test ownership are in the feature contract. Root
103-
joins its contract before Luna implements Core keys/locator inventory and the
104-
existing commit/resolution path, then updates all actual callers and adds real
105-
unit/scalar/prior-process/restart/RF3 scenarios. Root reviews, qualifies and
106-
delivers the full joined stage. Wrong/missing locator, contradictory scope,
107-
same-scope old/new duplicates and malformed frames fail closed without rewrite.
108-
Unknown prior scope blocks ambiguous reuse, never hash-derived backfill. New
109-
Unknown failures have a distinct explicit nonmovable v2 identity and cannot
110-
install an old-key barrier over a prior Global/Partition success; every new
111-
write is v2, with bounded point resolution and no shared reservation protocol.
112-
After the first v2 write recover forward; a legacy-only downgrade requires the
113-
verified full pre-upgrade backup and explicit accepted data-loss scope. The
114-
accepted contract does not close any original KL-012 acceptance gate by itself.
91+
[DocumentStorage](../Features/DocumentStorage.md) freeze the complete atomic
92+
partition identity in persisted command-outcome lookup. Current command writes
93+
use the accepted outcome representation; every lookup is bound to its normalized
94+
operation, authenticated principal, and complete partition scope. Public
95+
principal/ID-only result or key access is not an accepted path.
96+
97+
The current contract rejects a missing or contradictory locator, malformed
98+
record, duplicate scoped identity, or unsupported outcome without rewriting
99+
persisted bytes, searching an alternate key, or deriving identity from a hash.
100+
The current `Unknown` scope represents a normalized operation that failed before
101+
partition resolution. Its matching, freshly authorized retry replays only that
102+
same failed operation; it never invents partition authority or permits effects.
103+
Unknown scope values and contradictory identities fail closed. New commands use the
104+
canonical current identity and outcome representation. Ordered source ownership
105+
and the real unit, scalar, process-recovery, restart, and RF3 cases remain mapped
106+
in the feature contract; root owns shared joins and actual qualification. This
107+
section records the current behavior contract and does not claim gate completion.

0 commit comments

Comments
 (0)