You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 301181f
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: AGENTS.md
+8Lines changed: 8 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -405,6 +405,7 @@ Local `AGENTS.md` files may tighten these values, but they must not loosen them
405
405
- Local rules and ADRs MUST NOT weaken `MCAF-ARCH-001`; they may only document stricter rules or a time-bounded migration to compliance.
406
406
- Prefer composition over inheritance unless inheritance is explicitly justified.
407
407
- Do not preserve obsolete, dead, duplicate, or replaced legacy code unless the user explicitly asks for a temporary compatibility path.
408
+
- Owner correction 2026-10-06 removes backward compatibility with unreleased development storage formats from the first-release scope. Implement and qualify one current native storage format; remove old-format readers, migration/probe executables, historical-format test preparation and their active acceptance gates instead of developing compatibility for an unfinished product. This explicitly supersedes earlier requirements to migrate native5/native6/native7 development epochs before the first release. Preserve current-format process recovery, backup/restore, RF3 correctness and strict rejection of unsupported or corrupt formats; a later released-format upgrade requires a separate owner-approved contract.
408
409
- When replacing an old implementation, remove the old code, tests, configuration, docs, and routing in the same change once the new path is proven.
409
410
- Do not leave compatibility shims, placeholder implementations, or fallback paths as a substitute for a complete migration.
410
411
- If a temporary transition path is unavoidable, document the reason, owner, scope, verification, and removal plan in the nearest ADR, feature doc, or local `AGENTS.md`.
@@ -523,3 +524,10 @@ A bounded website qualification candidate contains the20-project historical runt
523
524
## Final Benchmarks Website trigger, owner clarification 2026-10-06
524
525
525
526
- Benchmarks MUST finish with only a bounded dispatch of the separate Website workflow; it MUST NOT build, test or deploy the site itself. This supersedes Website's `workflow_run` completion subscription. Confine dispatch permission to that final trigger job, keep main/manual Website publication independent, and authenticate any supplied producer run through GitHub before bounded completion waiting and newest-ready selection. A trigger input is not metric provenance or permission to bypass website qualification.
527
+
528
+
## Super rule: owner-only migration and legacy authorization
529
+
530
+
- Owner correction 2026-10-06: KeyLoad is a new product. Do not implement or retain data, schema, storage-format, persisted-record, configuration or prior-KeyLoad-version migrations, legacy readers, compatibility shims, dual paths or fallbacks unless the owner directly requests that specific migration or legacy path.
531
+
- This prohibition is the highest project rule for migration/legacy scope and explicitly supersedes every earlier plan, ADR, feature requirement, acceptance gate, local policy and inferred authorization to maintain unreleased or previous KeyLoad implementations. A generic instruction to finish the product, an agent proposal or a recorded migration contract is not the owner's direct permission.
532
+
- Delete existing KeyLoad-owned migration and legacy implementations now, together with their exclusive tests, helpers, prior-binary/image preparation, configuration, routes, dependencies and active documentation/plan references. Do not preserve them as dead branches or deferred cleanup and do not replace them with a new migration mechanism.
533
+
- Implement and qualify the current product contract. Preserve current-format crash recovery, verified backup/restore, persisted authorization, strict unsupported/corrupt-version rejection and genuine Aspire RF3. Native Orleans activation movement and SQL interoperability with external clients are current product capabilities, not authorization for legacy KeyLoad code or data conversion.
Copy file name to clipboardExpand all lines: docs/ADR/ADR-001-partition-identity-affinity.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,21 +12,21 @@ Resolve one `AtomicPartitionId` from the server-validated tenant, database, `Tra
12
12
13
13
## Rationale, alternatives, consequences
14
14
15
-
This makes authorization, command routing, transaction scope, and idempotency agree. Per-resource independent identity would prevent required document/event/local-queue transactions; using a raw key string globally would leak state across domains. A partition-per-engine/grain model is also rejected because it couples logical cardinality to physical resources. Catalog binding and migration now become correctness-critical, and a split must preserve unique constraints and command/read tokens or reject the operation.
15
+
This makes authorization, command routing, transaction scope, and idempotency agree. Per-resource independent identity would prevent required document/event/local-queue transactions; using a raw key string globally would leak state across domains. A partition-per-engine/grain model is also rejected because it couples logical cardinality to physical resources. Catalog binding and physical movement are correctness-critical; movement must preserve unique constraints and command/read tokens or reject the operation.
16
16
17
17
## Related requirements
18
18
19
19
`REQ-DSTORE-004`/`AC-DSTORE-004`, `REQ-MSG-005`/`AC-MSG-005`, and `REQ-GRAPH-001`/`AC-GRAPH-001`; see [DocumentStorage](../Features/DocumentStorage.md), [Messaging](../Features/Messaging.md), and [GraphTraversal](../Features/GraphTraversal.md). Cluster routing and placement requirements remain in [ClusterRouting](../Features/ClusterRouting.md) and [ClusterReplication](../Features/ClusterReplication.md).
20
20
21
21
## Implementation contract
22
22
23
-
1. Freeze canonical identity fields, catalog binding validation, compatibility fixtures, and token lineage before changing routing.
23
+
1. Freeze canonical identity fields, catalog binding validation, movement fixtures, and token lineage before changing routing.
24
24
2. Add real tests for cross-domain key reuse, valid shared resources, authorization, stable command scope, and split/movement boundaries.
25
25
3. Implement in `src/KeyLoad.Abstractions/Features/ClusterRouting/` and `src/KeyLoad.Core/Features/ClusterRouting/`; route via the owning Orleans request/partition grains. Preserve the current node-local `PartitionHost` ownership of stores and locks.
26
-
4.Migration imports old isolated-domain mappings explicitly; reject ambiguous bindings. Rollout keeps old routing until a verified catalog/ownership epoch is active. Rollback returns to the old owner only with a complete committed cut and fenced epoch.
26
+
4.Create resources under the canonical catalog binding and reject ambiguous or absent bindings. A physical move fences the current owner, publishes only after a verified catalog/ownership epoch and complete committed cut, and returns to that owner on rollback only while its state remains complete and fenced.
27
27
5. GitHub Actions must run TUnit, recovery, and Aspire RF3 through .NET and MCP SDKs; compare stable outcomes across failover and movement. Root owns shared resolver/contracts; worker joins only after exact tests and changed paths are reported.
28
28
29
-
Dependencies: [ADR-002](ADR-002-command-idempotency.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), [ADR-007](ADR-007-replica-consensus-bootstrap.md), [ADR-016](ADR-016-atomic-physical-placement.md), and [ADR-017](ADR-017-migration-tokens.md). Verification: named catalog tests plus the repository GitHub CI matrix; no local test qualification. Stop if a source binding, token lineage, or multi-resource atomic scope is ambiguous; do not add a physical-placement shortcut.
29
+
Dependencies: [ADR-002](ADR-002-command-idempotency.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), [ADR-007](ADR-007-replica-consensus-bootstrap.md), and [ADR-016](ADR-016-atomic-physical-placement.md). Verification: named catalog tests plus the repository GitHub CI matrix; no local test qualification. Stop if a source binding, token lineage, or multi-resource atomic scope is ambiguous; do not add a physical-placement shortcut.
Copy file name to clipboardExpand all lines: docs/ADR/ADR-002-command-idempotency.md
+24-31Lines changed: 24 additions & 31 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,10 +19,10 @@ Persisting command identity with effects resolves lost responses across process
19
19
1. Freeze command fingerprint inputs, principal/scope binding, error replay, and retention horizon before changing envelopes.
20
20
2. Add TUnit tests for same-ID/same-content replay, same-ID/changed-content conflict, lost response after commit, precondition failure replay, and unrelated principal/partition scope.
21
21
3. Keep shared command/request/outcome contracts in the existing `src/KeyLoad.Abstractions/Contracts.cs` building block and dispatch/persisted outcome handling in `src/KeyLoad.Core/DatabaseEngine.cs`; feature-specific mutation logic remains in its canonical owning `Features/<SliceName>/` directory. Do not create a separate CommandExecution slice or project.
22
-
4.This ADR authorizes no outcome-format migration, compatibility reader, dual-format read/write path, or legacy fallback. If an existing persisted outcome requires an upgrade, stop until [ADR-011](ADR-011-format-upgrades.md) is Accepted with the concrete format version, migration mode, and rollback boundary. Any temporary compatibility transition additionally requires a documented reason, owner, exact scope, verification, and removal date. Until then, unknown formats fail closed.
22
+
4.The current outcomeformat has one canonical reader and writer. Unknown, malformed, or unsupported outcomes fail closed without rewrite or alternate-key lookup.
23
23
5. GitHub qualification is TUnit, real process recovery, and RF3 SDK outcomes after leader change. Root owns shared command contracts; feature owners join with fingerprint vectors and named test evidence.
24
24
25
-
Dependencies: [ADR-001](ADR-001-partition-identity-affinity.md), [ADR-003](ADR-003-durability-ack-barrier.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), [ADR-011](ADR-011-format-upgrades.md), and [ADR-016](ADR-016-atomic-physical-placement.md). Stop if canonical fingerprint or dedup expiry behavior is not specified. Do not infer exactly-once handler execution or include an external API call in the database transaction.
25
+
Dependencies: [ADR-001](ADR-001-partition-identity-affinity.md), [ADR-003](ADR-003-durability-ack-barrier.md), [ADR-004](ADR-004-committed-read-views.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), and [ADR-016](ADR-016-atomic-physical-placement.md). Stop if canonical fingerprint or dedup expiry behavior is not specified. Do not infer exactly-once handler execution or include an external API call in the database transaction.
0 commit comments