Skip to content

Commit 318391f

Browse files
committed
Verify ClusterRouting repairs and align current ADR contracts
1 parent 77409c7 commit 318391f

12 files changed

Lines changed: 214 additions & 68 deletions

‎AGENTS.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -531,6 +531,7 @@ A bounded website qualification candidate contains the20-project historical runt
531531
- Owner correction 2026-10-06: KeyLoad is a new product. Do not implement or retain data, schema, storage-format, persisted-record, configuration or prior-KeyLoad-version migrations, legacy readers, compatibility shims, dual paths or fallbacks unless the owner directly requests that specific migration or legacy path.
532532
- This prohibition is the highest project rule for migration/legacy scope and explicitly supersedes every earlier plan, ADR, feature requirement, acceptance gate, local policy and inferred authorization to maintain unreleased or previous KeyLoad implementations. A generic instruction to finish the product, an agent proposal or a recorded migration contract is not the owner's direct permission.
533533
- Delete existing KeyLoad-owned migration and legacy implementations now, together with their exclusive tests, helpers, prior-binary/image preparation, configuration, routes, dependencies and active documentation/plan references. Do not preserve them as dead branches or deferred cleanup and do not replace them with a new migration mechanism.
534+
- Owner clarification 2026-10-06 requires every ADR to describe the current product decision and implementation contract. Remove superseded KeyLoad implementation narratives, old-format preparation and retired-plan references from ADRs; preserve current requirements, strict rejection, authentic qualification limits and independently retained original evidence.
534535
- Implement and qualify the current product contract. Preserve current-format crash recovery, verified backup/restore, persisted authorization, strict unsupported/corrupt-version rejection and genuine Aspire RF3. Native Orleans activation movement and SQL interoperability with external clients are current product capabilities, not authorization for legacy KeyLoad code or data conversion.
535536

536537
## Build and Tests workflow filename, owner direction 2026-10-06

‎docs/ADR/ADR-068-native-benchmark-gate-repair.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ flowchart LR
2626

2727
AC-NGR-001 requires authenticated, bounded discovery followed by revalidation of the exact same own-repository workflow/source/attempt/job identity; only strict in-progress with a null result admits native setup. A queued response is not executing evidence. The original request bound is 120,000 ms; only after an exact queued response may one 60,000 ms stale-response window run at cancellation-aware 1,000 ms cadence, with at most 61 total captures. Mismatch, terminal/unknown state, exhaustion, cancellation, transport or parse failure rejects before allocation/timing; no reselection or workload retry occurs. AC-NGR-002 retains exact original/custom/system event metadata, a complete 55,378-item owned-stream oracle, foreign-resource noninterference and cleanup across genuine native one/two/three-node cases; empty tracing remains uncharacterized and must not be assumed empty. AC-NGR-003 retains SDK/advertised endpoint validation, genuine leader/follower routing, observed membership/copies/ACK, and no guessed leader, standalone substitute or measured write retry. AC-NGR-003D preserves the original thrown failure and emits only one failure-only line bounded to 4,096 bytes, at most three causes, eight frames per cause and 64-character identifiers; messages, stacks, paths, endpoints, credentials and payloads are excluded.
2828

29-
**AC-NGR-004 is the complete current publication predicate:** the authenticated source/run/attempt/job and uploaded archive must match the canonical 1,386-worker plan (330 controls, 264 scaled CRUD, 792 vector) and its required 2,530 unique regular-file evidence inputs (2,470 suite and 60 provider files), with exact paths, sizes and hashes, original archive bytes, and all source/provenance identities validated. Each slot is either a measured result, an authenticated explicit unsupported-topology disposition or an authenticated terminal workload failure with the required safe null report; failed, canceled, skipped, missing, mixed-cohort or unavailable evidence can never become numeric success. Native preflights, full source/normal/scalar/recovery/RF3, coverage, site/browser/freshness/provider gates remain separate required predicates. The TimeSeries family is separate and remains subject to its own ADR-050/059 scale-specific plan. AC-NGR-005 preserves the original failed case, timing and samples; only after an eligible exact resource-exhausted case and its session settle may one authenticated outbox-status read inspect at most 64 consumer heads, outside the measured clock. Unknown/unavailable remains unavailable; no quota, purge, retention or retry changes are implied. These criteria map to the current BenchmarkComparisons failure/null and Website selection contracts, not the retired NativeGateRepair plan.
29+
**AC-NGR-004 is the complete current publication predicate:** the authenticated source/run/attempt/job and uploaded archive must match the canonical 1,386-worker plan (330 controls, 264 scaled CRUD, 792 vector) and its required 2,530 unique regular-file evidence inputs (2,470 suite and 60 provider files), with exact paths, sizes and hashes, original archive bytes, and all source/provenance identities validated. Each slot is either a measured result, an authenticated explicit unsupported-topology disposition or an authenticated terminal workload failure with the required safe null report; failed, canceled, skipped, missing, mixed-cohort or unavailable evidence can never become numeric success. Native preflights, full source/normal/scalar/recovery/RF3, coverage, site/browser/freshness/provider gates remain separate required predicates. The TimeSeries family is separate and remains subject to its own ADR-050/059 scale-specific plan. AC-NGR-005 preserves the original failed case, timing and samples; only after an eligible exact resource-exhausted case and its session settle may one authenticated outbox-status read inspect at most 64 consumer heads, outside the measured clock. Unknown/unavailable remains unavailable; no quota, purge, retention or retry changes are implied. These criteria map to the current BenchmarkComparisons failure/null and Website selection contracts.
3030

3131
The benchmark source paths own current-job capture, target-specific diagnostics and comparison runner behavior. Unit tests cover real current source paths and native fixtures rather than fake executor or target behavior. Root owns workflow, schema, current cohort, Website, docs and final integration. The canonical current inventory is 330 control cells, 264 scaled cells, 792 vector cells across 11 targets; scaled profiles contain 100,000 and 1,000,000 records and applicable cells execute at least 100,000 measured operations. TimeSeries remains its separate family under ADR-050/059.
3232

‎docs/ADR/ADR-076-current-cohort-publication.md‎

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,7 @@ composite plan. The plan contains 330 control cells, two 132-cell CRUD profiles
1111
(100,000 and 1,000,000 records), and 24 vector profiles with 33 target/node
1212
cells each: 1,386 workers total. Applicable scaled workloads retain at least
1313
100,000 measured operations; vector profiles retain at least 100,000 measured
14-
queries. The 270-worker/277-file cohort belongs only to authentic historical
15-
receipts. It does not define current completeness or qualify current metrics.
14+
queries.
1615

1716
The current composite evidence inventory is derived from the canonical plan:
1817
2,470 suite files and 60 provider files (2,530 total), including every planned

‎docs/ADR/ADR-110-native-orleans-execution-primitives.md‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -154,6 +154,24 @@ RF3 bootstrap and verification complete. Both physical stores must already satis
154154
the current required reader contract before first journal admission; fresh stores
155155
are created with that contract and unsupported capabilities fail closed.
156156

157+
The REQ/AC-ORL-013 call graph copies every existing default-deny edge and admits
158+
the native RuntimeJournalClient's exact ReadCoreAsync and SendCommandAsync calls
159+
to IRequestGrain.ExecuteStreamAsync. Native JournaledStateManager suppresses
160+
ExecutionContext for its background work loop, so provider callbacks establish
161+
their immediate caller identity with the supported RunWithCurrentCallerAsync
162+
API around the complete native CQRS stream drain and restore it on every exit.
163+
The coordinator's concrete ExecuteJobAsync edge remains scoped to its actual
164+
saga effect; remove the unused manager wildcard and speculative concrete
165+
ProcessDueAsync provider allowance. TASK-ORL-JOURNAL-GRAPH-014 freezes exact
166+
Orleans client/Server registration ownership, ordered guarded private preparation,
167+
root join and verification in the RuntimeJournal contract. Preserve signed
168+
protected identity, fresh separately authorized request grains, backpressure and
169+
RF3 authority. Actual native scheduling/journal callbacks, duplicate dispatch,
170+
single saga/message effect, caller restoration, denied method/target and healthy
171+
follow-up controls run through Aspire after build/format. No coordinator wildcard
172+
or alternate database path is admitted; complete process, RF3 and Linux
173+
qualification remains required.
174+
157175
Native streamed-request telemetry join, 2026-10-06: TASK-ORL-TELEMETRY-STREAM-002
158176
in [RuntimeAdoption](../Features/ClusterRouting/RuntimeAdoption.md) freezes the
159177
REQ/AC-ORL-012 client propagation and exact native stream-start classification

‎docs/ADR/ADR-112-independent-website-publication.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -85,6 +85,10 @@ flowchart TD
8585
2. Selection contributor owns site-isolated-github capture/runs/contract; builder
8686
contributor owns site/Features/BenchmarkComparisons/build-site.mjs. Preserve
8787
exact original artifacts, bounded native calls and source closure.
88+
TASK-CURRENT-WEBSITE-EVENT-071 limits capture to current executor and REST
89+
selection/wait inputs. It removes event-file parsing and its exclusive probe,
90+
cap and fixtures, preserving REST workflow_runs and artifact.workflow_run
91+
provenance, actual authenticated capture and latest-selection operation flows.
8892
3. Qualification contributor owns SiteContent cases/helpers/contracts and current
8993
coverage/source inventory joins. Native file/Node/Chrome flows prove successful
9094
admission, absence, foreign executor, corrupt evidence and healthy follow-up.

‎docs/Features/BenchmarkComparisons.md‎

Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1443,3 +1443,62 @@ rejection, unchanged inputs and a healthy follow-up. Static actionlint and YAML
14431443
graph review verify infrastructure; a genuine final dispatch and separate
14441444
workflow_dispatch Website/Pages run supply provider evidence. Ordered tasks and
14451445
ownership are in ADR-112 TASK-WEB-TRIGGER-001..003.
1446+
1447+
### Current Website capture source closure
1448+
1449+
TASK-CURRENT-WEBSITE-EVENT-071 implements REQ/AC-BC-WEB-001/002/004/006/007 and
1450+
AC-BC-FAIL-019 using only trusted push/manual executor admission, bounded
1451+
authenticated optional-run waiting and current REST producer selection. Capture
1452+
has no event-file input or event-payload parser/probe; remove their exclusive
1453+
fixtures and cap. REST workflow_runs paging and artifact.workflow_run provenance
1454+
remain separate mandatory authority checks, including rejection of unsupported
1455+
producer-list events. No API/archive/request bound or coverage threshold changes.
1456+
1457+
The source packet owns site-isolated-github-context.mjs, the parser-only cap in
1458+
site-isolated-github-contract.mjs, SiteIsolatedGitHubNodeProgram and its fields,
1459+
Website executor cases, and producer-selection cases/fixtures. Keep the two
1460+
latest-selection whole flows under current AC-BC-WEB-002 ownership; keep actual
1461+
authenticated AcPipe003 capture, no mutation and healthy follow-up, exact-source
1462+
freshness, full source inventories and native Node/Chrome coverage. Root owns
1463+
policy/docs, shared source closure, joins, canonical gates and Git. Preparation
1464+
must account for the separately reviewed current archive-source packet before
1465+
joining overlapping files; source review is not Linux or Pages evidence.
1466+
1467+
### Current archive consumer closure
1468+
1469+
TASK-CURRENT-ARCHIVE-IMPLEMENTATION-070-CONSUMERS implements
1470+
REQ/AC-BC-CURRENT-001..004 and REQ/AC-BC-WEB-002/004/006/007 alongside
1471+
TASK-CURRENT-WEBSITE-EVENT-071. The current dependency manifest contains exactly
1472+
80 source paths. QualifySite/action.yml must validate that exact current list and
1473+
remove the deleted historical-contract path from its closed allowlist; preserve
1474+
all remaining regular-path, byte/hash, archive, source, coverage and freshness
1475+
checks. Root alone joins the composite-action change.
1476+
1477+
Keep SiteOptionalBenchmarkSelectionTests as the mandatory Aspire-owned native
1478+
Website preparation gate. Its Cases and Processes own complete push/manual
1479+
admission, CI/foreign-path/unsupported-executor rejection, unchanged controlled
1480+
inputs, healthy follow-up and strict optional-argument flows using the production
1481+
context API. Delete HistoricalBenchmarkContractTests,
1482+
SiteHistoricalEligibilityNodeProgram, SiteOptionalBenchmarkSelectionTokens and
1483+
their eleven SiteOptionalRetained JSON metadata fixtures. They are exclusive
1484+
old-plan code inputs, not immutable original measurement artifacts. Current
1485+
authenticated producer capture, optional unavailability, newest-ready selection,
1486+
strict selected-evidence rejection and healthy follow-up remain owned by the
1487+
current SiteTests under AC-BC-WEB-002 and AC-BC-FAIL-019/020.
1488+
1489+
The exact unit modifications are Cases/SiteOptionalBenchmarkSelectionTests.cs
1490+
and Processes/SiteOptionalBenchmarkSelectionNodeProgram.cs,
1491+
SiteOptionalBenchmarkSelectionNodeProcess.cs and SiteWebsiteAdmissionNodeProgram.cs
1492+
under Features/BenchmarkComparisons. Remove the unused fixture-directory
1493+
argument. SiteIsolatedInventory and its real SiteTests callers must use current
1494+
no-argument inventory functions; delete its unused Files helper. Do not retain
1495+
ignored source/revision parameters as compatibility shims. Preserve the current
1496+
1,386-worker/2,530-input contract and separate source authentication.
1497+
1498+
Read the owning policies before preparation. Coding agents prepare only guarded
1499+
private packets; root owns docs/policy, serialized joins, exact coverage/source
1500+
inventories, canonical build/format, Aspire unit/SiteTests and Git. Join the
1501+
archive packet before the dependent event packet, verify every live base hash,
1502+
then run the full ordinary unit suite separately from functional coverage.
1503+
Required exact-source Linux website/browser/provider gates remain open until
1504+
their original evidence exists. Deletion is not a passing qualification result.

0 commit comments

Comments
 (0)