Skip to content

Commit 4c48909

Browse files
committed
fix: bind RF3 membership and native test package roots
Bind the actual flat authority options emitted by the six-node Aspire model and compose native pinned TUnit import paths for both package-root forms. Add whole-operation indexed process recovery, indexed backup/replay and SDK query-factory regressions with bounded cleanup and exact state oracles. Local full Release build, native formatter, governance, owning unit/scalar 10/10 each and real process recovery 2/2 pass with no source/image drift. Retain original Linux failures and pending complete RF3/coverage acceptance.
1 parent f38513b commit 4c48909

40 files changed

Lines changed: 2254 additions & 147 deletions

File tree

‎README.md‎

Lines changed: 30 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -333,46 +333,36 @@ Discovery exposes static operation documentation. Each invocation checks current
333333
> **KeyLoad is a development preview.** Try it, build with it and [tell us what breaks](https://github.com/managedcode/KeyLoad/issues), but don't trust it with production data yet.
334334
335335
The original 104-task plan has **3 fully accepted, 101 in progress and 0 pending**.
336-
KL-075 now has its first scaling source stage; six-node, open-loop, shard-skew,
337-
fanout, recovery and movement acceptance remains open. The joined stage has
338-
passed the local Release build with zero analyzer errors and warnings. The
339-
[original Linux run at 259a3fa5](https://github.com/managedcode/KeyLoad/actions/runs/37554329420/job/112576973966)
340-
passed normal and scalar **2,765/2,765**, recovery **235/235** and same-job native
341-
source/test-image identity verification, without skips. Later native codec and
342-
captured-envelope criteria now close **KL-007**, with all19 mapped cases passing
343-
in both modes and all33 owned source files bound to the original compiled images.
344-
Original document **KL-010 CRUD/CAS** and **KL-012 batch/idempotency** acceptance
345-
is also closed: unchanged product/test source is bound to original Linux reports
346-
and compiled PDBs, including100 retries in each of two real processes. Their
347-
five SDK/MCP/restart RF3 cases pass in both retained Linux reports and a fresh
348-
local native Aspire/Docker run. This does not qualify the full RF3 cohort.
349-
The newer cross-process ownership and read-cut regressions pass locally; their
350-
task acceptance remains open. The [newer original Linux run at 6816ae91](https://github.com/managedcode/KeyLoad/actions/runs/37560457057/job/112596312154)
351-
passed normal and scalar **2,767/2,767**, recovery **235/235** and same-job native
352-
source/test-image identity checks. Its RF3 job was canceled near the original
353-
60-minute aggregate budget without producing a completed RF3 report. That job
354-
now has 180 minutes, with individual scenario deadlines and gates unchanged.
355-
The [later Linux run at 57532cd5](https://github.com/managedcode/KeyLoad/actions/runs/37569205558/job/112623818966)
356-
passed normal and scalar **2,769/2,769**, recovery **235/235**, and same-job
357-
source/test-image checks. Its complete RF3 report records **131/141 passed,
358-
10 failed**, with bootstrap admission exhaustion, a specific missing ACK grant
359-
and separate startup/cancellation failures retained. The next source's Linux
360-
normal/scalar reports each pass **2,770/2,771**; the sole failure is a test
361-
expecting logger-selection rejection after image-provenance rejection, and
362-
recovery passes **235/235**. That fixture correction remains pending.
363-
Local Stage V fixes pass **99/99** owning unit operations in
364-
each mode and the two real RF3 admission cases. SDK backup and dispatch also
365-
pass their actual RF3 flows, including native archive restore and queue delivery,
366-
replay/conflict/denial checks. Full current-source Linux/RF3 remains open.
367-
All six unchanged native Aspire logger-control flows pass locally, including
368-
caller cancellation and original task settlement; these model/logger controls
369-
do not qualify Docker database execution. Six focused local Docker RF3 flows
370-
pass through the real SDK and official MCP clients, covering native schema
371-
discovery and autonomous saga timeout/replay. The owned image lifecycle also
372-
passes prepare, verify, cleanup and repeated cleanup. Full Linux RF3,
373-
functional coverage, scale and release qualification remain open. The
374-
[implementation status](docs/implementation/status.json) records each
375-
source and report boundary.
336+
The accepted tasks are **KL-007** storage codecs, **KL-010** document CRUD/CAS and
337+
**KL-012** batch/idempotency, each bound to its original Linux tests and compiled
338+
source, including real process retries and task-specific SDK/MCP RF3 operations.
339+
Their acceptance does not qualify the remaining features or the complete cluster.
340+
341+
The [latest completed Linux RF3 cohort](https://github.com/managedcode/KeyLoad/actions/runs/37578573276/job/112652868979)
342+
recorded **122/132**, with ten failed operations. Coverage collection and merge
343+
were skipped after that failure. The [same run's Linux verify job](https://github.com/managedcode/KeyLoad/actions/runs/37578573276/job/112652908001)
344+
passed normal and scalar **2,767/2,768** and recovery **235/235**, without skips.
345+
Its sole unit failure is an incorrect expected rejection in the C1 fixture; the
346+
correction passes locally and awaits fresh complete Linux verification.
347+
Local Stage V passed **99/99** owning unit
348+
operations in each mode and actual Aspire RF3 SDK/MCP admission, backup/restore
349+
and queue dispatch flows, in separately retained source/image cohorts.
350+
351+
Stage VI has joined whole-operation query-factory, indexed-document backup/dedup,
352+
scalar-index process-recovery and six-resource membership configuration work.
353+
A fresh isolated restore now selects all **264** package/version archives from
354+
NuGet.org with zero unresolved package/license inventory rows. The corrected
355+
compile-identity target passes actual native builds with both package-root forms
356+
and rejects a counterfeit defining import. The complete Release build and native
357+
formatter pass; owning native normal/scalar flows each pass **10/10**, and real
358+
indexed/idempotency process recovery passes **2/2**, without source/assembly drift
359+
or skips. These are focused local results; a new complete Linux run is required.
360+
Bounded Q2 relational INNER JOIN and a
361+
TUnit-owned fresh-image six-silo flow have frozen contracts and private source
362+
stages; neither is runtime-qualified yet. KL-075 scaling, full SQL/client protocol,
363+
complete Linux RF3, functional coverage, endurance and release gates remain open.
364+
The [implementation status](docs/implementation/status.json) retains original
365+
failures, source hashes and each qualification boundary.
376366

377367
Functional coverage excludes load/comparison runs and admits complete operation
378368
flows only. The current Query profile binds exactly 25 named cases and 103 source

‎docs/ADR/ADR-004-committed-read-views.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,15 @@ EventStreams `REQ-EVENT-001..003`/`AC-MP-005`, QueryExecution `REQ-QUERY-001..00
2222
4. Validate current cursor versions and invalidate stale bindings explicitly. Reject unsupported cursors with a stable error rather than translating them or guessing their cut.
2323
5. GitHub CI runs real-store TUnit, process recovery, and RF3 client reads across leader changes; root owns the common cut/token contract and joins feature-specific tests.
2424

25+
TASK-CUT-DOCUMENT-INDEX-SCAN maps REQ-CUT-005 /
26+
AC-CUT-DOCUMENT-INDEX-SCAN-001 in
27+
[NativeReadCuts](../Features/StorageRecovery/NativeReadCuts.md). The bounded real
28+
document/index scan, concurrent atomic writer, joined failure cleanup, reopen and
29+
healthy follow-up are test-only completion of the existing gate contract. Root
30+
owns integration and exact-source qualification; the worker's exact private
31+
ownership and ordered implementation are frozen in that feature document.
32+
Snapshot/segment-movement performance and complete KL-004 acceptance stay open.
33+
2534
Dependencies: [ADR-001](ADR-001-partition-identity-affinity.md), [ADR-003](ADR-003-durability-ack-barrier.md), [ADR-005](ADR-005-canonical-keyspace-codec.md), [ADR-006](ADR-006-strict-derived-indexes.md), and [ADR-010](ADR-010-query-budgets-security.md). Stop on any ambiguity about visibility, cut translation, or cancellation lifetime; do not claim read-your-writes or global ordering beyond the verified contract.
2635

2736
```mermaid

‎docs/ADR/ADR-074-aspire-owned-test-entry.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -299,3 +299,11 @@ The identity crossing start/readiness is the actual pre-start verifier return:
299299
VerifyModelAsync returns it to a WaveStartup local, then the same value supplies
300300
started-container checks. Early ReadAsync selects the validated reference only.
301301
Keep existing caller maps; no ambient state or extra identity carrier is needed.
302+
303+
The direct TUnit ownership in ADR-117 is refined by Accepted
304+
[ADR-119](ADR-119-tunit-owned-local-membership-image.md) for an explicit local
305+
six-silo membership image. Its TUnit case owns the existing Aspire prerequisite
306+
and exact-tag cleanup; no outer test runner executes. The typed selection does
307+
not mutate global environment or erase GitHub provenance. Preserve original
308+
producer bounds, all six actual container checks, 18 locks, SDK/MCP flow and Linux
309+
qualification gates. Implementation and native runtime proof are pending.

‎docs/ADR/ADR-106-partition-owner-movement.md‎

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -256,3 +256,32 @@ Aspire testing resumes the normal AppHost entry point; absence of an explicit
256256
StartAsync call is not a guarantee that resources never start. Joined application
257257
disposal and owned-root cleanup remain mandatory. The real homogeneous image,
258258
six-silo startup, membership and public fail-closed cases still qualify runtime.
259+
260+
261+
## Accepted TASK-MEMBERSHIP-FLAT-CONFIG refinement (2026-10-07)
262+
263+
Related AC-MEMBERSHIP-001/002/006 and AC-MEMBERSHIP-CONFIG-001 in
264+
ClusterRouting/PartitionTransfer. Original Linux run37569205558 source57532
265+
fails before health because its AppHost emits nested TrustedGroup keys while the
266+
unchanged native settings/binder/strict validator owns flat property names.
267+
Freeze the single supported flat names before source correction. No dual-format
268+
acceptance, migration, secret/trust change or old-format compatibility is added.
269+
270+
Ordered stages: root freezes this contract; Luna privately changes only AppHost
271+
Features/ClusterRouting/Resources/TwoRf3ClusterResources.cs key constants and
272+
matching feature-local UnitTests whole model/binding regressions; root verifies
273+
source guards, joins, builds, executes native normal/scalar and the genuine
274+
six-silo Aspire Docker SDK/MCP scenario, then commits/pushes. Every original
275+
membership/readiness/admission/identity/cleanup gate remains mandatory. Preserve
276+
the three-node local profile and all authority/proxy server validation.
277+
278+
Rollback restores only those current-stage key/test changes while retaining
279+
original failure artifacts. There is no persisted rollout; the corrected
280+
AppHost emits the existing settings shape. Source integration and exact-source
281+
Linux/runtime qualification remain open; do not mark this ADR Implemented.
282+
283+
The Accepted [ADR-119](ADR-119-tunit-owned-local-membership-image.md) refinement
284+
assigns TASK-MEMBERSHIP-TUNIT-LOCAL-IMAGE and AC-MEMBERSHIP-001/002/006 local image
285+
ownership/proof to the TUnit case, existing Aspire prerequisite and exact-tag
286+
cleanup. It changes no membership or database ownership protocol; the strict
287+
GitHub route and original Linux gates remain mandatory and unqualified here.

‎docs/ADR/ADR-117-native-tunit-ci-entry.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,3 +17,10 @@ Current stage evidence: [NativeTUnitVerification](../Features/TestInfrastructure
1717
TASK-TUNIT-ENTRY-005 implements REQ/AC-TUNIT-ENTRY-004 from NativeTUnitEntry by changing only the bounded aggregate `docker-rf3` job timeout from 60 to 180 minutes in `.github/workflows/build-and-tests.yml`. The complete same-image coverage cohort requires two full uninstrumented unit censuses, ten positive instrumented groups, native recovery/RF3 and strict descriptor/product admission, alongside the required RF3 suite and build. The observed unchanged local full unit census lasted 19 minutes 28 seconds; that failed development run informs scheduling and provides no acceptance or coverage evidence.
1818

1919
Stages are: freeze the linked requirement; join the workflow together with its source-bound native coverage producer and qualified unit inventory; parse the actual YAML/PowerShell; execute the original complete Linux job; retain all original exits, TRX, source/image hashes and coverage admission receipts. Root owns final integration and the agent's private workflow overlay. Every individual native deadline, bounded operation, coverage threshold, no-skip and fail-closed publication contract remains unchanged. Rollback removes the scheduling amendment and its overlay without admitting partial evidence. This amendment is Accepted, with complete Linux runtime qualification pending.
20+
21+
[ADR-119](ADR-119-tunit-owned-local-membership-image.md) defines the Accepted
22+
REQ/AC-TUNIT-ENTRY-005 local membership prerequisite refinement. Native selection
23+
passes arguments only; the TUnit case removes the recursive runner, executes the
24+
existing Aspire image prerequisite, passes typed identity without environment
25+
mutation, and joins final exact-tag cleanup after the actual six-silo wave. Root
26+
freezes/joins; Luna prepares guarded source. Implementation and runtime pending.
Lines changed: 86 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,86 @@
1+
# ADR-119: TUnit-owned local membership image
2+
3+
Status: Accepted; implementation and native runtime qualification pending.
4+
5+
Feature contracts: TestInfrastructure REQ/AC-TEST-015, NativeTUnitEntry
6+
REQ/AC-TUNIT-ENTRY-005 and ClusterRouting/PartitionTransfer
7+
AC-MEMBERSHIP-001/002/006. This refines ADR-074/117 prerequisite ownership and
8+
ADR-106 six-silo membership. No public database, dependency, persistence or
9+
membership protocol changes are authorized.
10+
11+
The native caller selects `Suite=rf3`, a nonblank bounded filter and
12+
`LocalRf3Image:Enabled=true`. Initially the only supported owned-image filter is
13+
`/*/*/TwoRf3MembershipProfileTests/*`; reject other filters instead of silently
14+
running an unowned local topology. `scripts/Features/TestInfrastructure/run-tests.mjs`
15+
only validates selection and passes bounded JSON through
16+
`KEYLOAD_TUNIT_LOCAL_RF3_IMAGE_ARGUMENTS`. It never starts Aspire or Docker.
17+
Reject mixed native coverage/comparison/protocol selectors and GitHub receipt,
18+
revision or actions identity; do not erase provenance to admit local mode.
19+
20+
The membership TUnit case owns a `LocalRf3ImageTestSession` followed by a
21+
`TwoRf3MembershipWave`, in that disposal order. The session reads the explicit
22+
native preparation arguments and creates the existing testing builder for the
23+
RF3 suite/filter/local-image prerequisite. Read the original validated runner
24+
configuration, remove the recursive runner before building or starting, and run
25+
only `LocalRf3ImagePrerequisite` to its original successful exit. Reuse
26+
`LocalRf3ImageExecution`, the original source snapshot producer/verifier and
27+
`LocalRf3ImageCleanup`; do not create another image implementation. Capture the
28+
canonical reference/tag/receipt as a typed selection, verify its actual current
29+
receipt/config ID, and pass it explicitly to the wave. Never mutate process-global
30+
environment or fabricate a registry digest for a Docker config ID.
31+
32+
With no owned-local selection, preserve the existing authenticated GitHub image
33+
path. A selected malformed local identity fails before cluster startup without a
34+
GitHub fallback. AppHost's `TwoRf3ClusterResources` uses the existing
35+
`LocalDevelopmentContainerImage` branch for all six fixed names and preserves
36+
all current ephemeral/no-benchmark/no-probe/no-cohort gates. Every child builder
37+
receives only the original validated local selector arguments. The existing
38+
strict GitHub digest oracle remains unchanged.
39+
40+
Extend `LocalRf3ImageIdentity` with explicit expected-name overloads, preserving
41+
ordinary three-node wrappers. Validate the exact distinct nonempty expected set,
42+
all matching model nodes and repository/tag/no-digest annotations before start.
43+
After the unchanged six-node healthy barrier, inspect the actual six
44+
`ContainerNameAnnotation` names through the existing native Docker helper and
45+
require the exact receipt-owned image config ID and configured reference on each.
46+
Preserve the existing six-member Orleans view, two three-voter groups and actual
47+
SDK/official MCP no-dispatch operations through nodes 1 and 4.
48+
49+
Stages and ownership:
50+
1. Root freezes this contract and its feature/ADR links before source work.
51+
2. Luna unpack_atomicity prepares guarded source under AppHost
52+
Features/ClusterRouting/Resources/TwoRf3ClusterResources.cs; IntegrationTests
53+
Features/ClusterReplication/Fixtures/LocalRf3ImageTestSession.cs and cohesive
54+
feature-local helpers as needed, Helpers/LocalRf3ImageSelection.cs and
55+
LocalRf3ImageIdentity.cs; ClusterRouting/Helpers/TwoRf3MembershipWave.cs,
56+
Cases/TwoRf3MembershipProfileTests.cs and applicable model negatives; and the
57+
native selection script plus UnitTests/TestInfrastructure native selection
58+
whole-process regressions. Root owns shared composition and final joins.
59+
3. Root reviews every source/contract guard, compiles with published packages,
60+
and runs native positive and negative selections. Actual local preparation,
61+
six started containers, membership, SDK/MCP rejection and full cleanup must be
62+
observed in the original TUnit case. Model-only checks cannot qualify runtime.
63+
4. Commit/push and retain exact-source original Linux qualification separately.
64+
65+
Keep the existing 15-minute case/start deadline, 60-second wave cleanup, producer
66+
snapshot admission of 20,000 files/512 MiB and existing image cleanup policy.
67+
Join preparation output readers and application stop/disposal. After wave stop,
68+
application disposal and all 18 exclusive lock checks, invoke exact-tag image
69+
cleanup and settle its original process/readers. Preserve primary and cleanup
70+
failures together. Never force-remove/prune images, delete another invocation,
71+
skip lock errors or weaken the SDK/MCP no-effect oracle.
72+
73+
AC-TUNIT-ENTRY-005 maps to the actual membership case plus native selection and
74+
model admission regressions: accepted selection executes the complete flow;
75+
missing/partial/mixed/GitHub selectors and unsupported filters fail closed before
76+
startup; changed source/image identity fails without fallback; original cleanup
77+
refuses a still-referenced image and removes only its own unused tag. Existing
78+
canonical producer/cleanup whole-operation tests remain mandatory. No new test
79+
may merely inspect a field/getter or duplicate source logic.
80+
81+
Frontend: N/A, test orchestration only. Public contracts: N/A, no server API
82+
change. The image and receipt are disposable local development artifacts. A
83+
failed stage retains original evidence and removes only successfully settled
84+
owned resources. Rollback is an ordinary source revert of this explicit local
85+
refinement, preserving ADR-117 direct TUnit and the strict GitHub route. No data
86+
migration, legacy support, widened deadline or qualification bypass is introduced.

‎docs/ADR/README.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -152,5 +152,6 @@ flowchart LR
152152
| [ADR-114: verified backup artifact publication](ADR-114-verified-artifact-publication.md) | Accepted |
153153
| [ADR-115: TimeProvider ownership](ADR-115-time-provider.md) | Accepted |
154154
| [ADR-116: one current format before the first release](ADR-116-first-release-current-format.md) | Accepted |
155-
155+
| [ADR-117: native TUnit CI entry](ADR-117-native-tunit-ci-entry.md) | Accepted |
156156
| [ADR-118: bounded typed-row INNER JOIN](ADR-118-bounded-relational-inner-join.md) | Accepted |
157+
| [ADR-119: TUnit-owned local membership image](ADR-119-tunit-owned-local-membership-image.md) | Accepted |

0 commit comments

Comments
 (0)