You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 50d2a50
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: README.md
+3-2Lines changed: 3 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -332,7 +332,7 @@ Discovery exposes static operation documentation. Each invocation checks current
332
332
333
333
> **KeyLoad is a development preview.** Try it, build with it and [tell us what breaks](https://github.com/managedcode/KeyLoad/issues), but don't trust it with production data yet.
334
334
335
-
The original 104-task plan has **16 accepted, 88 in progress and 0 pending**.
335
+
The original 104-task plan has **17 accepted, 87 in progress and 0 pending**.
Copy file name to clipboardExpand all lines: docs/ADR/ADR-007-replica-consensus-bootstrap.md
+7Lines changed: 7 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -112,3 +112,10 @@ flowchart LR
112
112
Materializer[Materializer borrows gate] --> Drain[Apply drain without gate disposal]
113
113
Drain --> Owner[Physical log owner disposes after consensus drain]
114
114
```
115
+
116
+
117
+
## TASK-KL035-INSTALL-BOUNDARY-003: actual descriptor limit and original cancelled admission
118
+
119
+
REQ/AC-REP-004 and original architecture KL035 atomic snapshot installation require an explicit install boundary, independent of existing GC cancellation/log read limits. ReplicaSnapshotInstallBoundaryTests.ActualSnapshotCeilingOrOriginalCancelledInstallPreservesWholeCutThenSameTransferAndColdTailAreHealthy uses the existing real CrashHost SnapshotChunkAcknowledged producer, actual killed/readers-joined native source/target and original partial descriptor. After the same genuine image is fully copied, one source argument validates an exact image-length-minus-one receiver ceiling with valid smaller chunk bounds; the other calls real materializer InstallCheckpointAsync with its original already-cancelled caller token. Exact Validation or original OCE/token must retain full canonical+replica records/positions/hardstate/native local identity/read generation and private image/manifest lengths+SHA. The SAME valid descriptor then installs snapshot4, applies retained tail5, preserves complete ordered original receipts, joins actual materializer/node/source and cold reopens full literal healthy state. This cancellation is before apply ownership; no in-flight IO rollback is claimed. No fixture/threshold/product limit/deadline/retry/provider/format/authority change.
120
+
121
+
The existing49 task objects remain unchanged. Root must compile and obtain genuine native typed argument expansion/UID/PDB source-image records before adding this class to the Recovery selector; two source Arguments are not native census or passing outcomes. Existing full-suite/fault/coverage/Linux RF3 gates remain mandatory, and process recovery cannot qualify power-loss/endurance. Shared heavyweight fixture ownership remains untouched.
Copy file name to clipboardExpand all lines: docs/ADR/ADR-106-partition-owner-movement.md
+28Lines changed: 28 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1543,3 +1543,31 @@ Additional hard evidence needed in authored test: actual SourceBeginAbort native
1543
1543
Ownership proposed: existing Core contracts/effects unchanged. Orleans private phase enum, existing TransferDataObservedExecution, IPartitionMovementParent and PartitionMoveParentExecution callback construction. Server private phase/closed JSON/marker whitelist, Runtime.Parent, Orchestrator/PageContinuation/NativeStep callback plumbing, ParentTransferPageReader actual Close failure observation, ReceiverCleanup existing source join boundary. Feature-local integration case/trial/producer/cut assertions reuse original seed/wave/native snapshots/receipt models. Root sole live/compiler/Git. Root reviewed/froze this exact contract a8d5f144 and authorized private implementation; original ready31 source checkpoint unaffected.
1544
1544
1545
1545
Source implementation/automated case: `PartitionMovementTransferCloseRf3Tests.ActualOpenThenOriginalCallerCancellationRecordsCloseFailureBeforeFreshAbortJoinsSourceAndColdSdkMcpQ1IsHealthy`. Current private source only; no compiled UID/runtime outcome. All original limits/deadlines/defaults/current auth/bytes/receipts unchanged, original required normal/scalar Unit/Recovery/Docker RF3 gates retained. Future native embedded SafeDetail finite bound and other unqualified whole-stage criteria remain OPEN.
1546
+
1547
+
1548
+
# TASK-KL036-RECEIVER-ISSUE-FAILOVER-WHOLE-001
1549
+
1550
+
REQ-MOVE-PARENT-RECEIVER-ISSUE-FAILOVER-001 maps existing REQ-MOVE-PARENT-002/004 and retained original receiver issue/packet/proof authority to actual RF3 read failover after Issue ACK and before Observe. AC-MOVE-PARENT-RECEIVER-ISSUE-FAILOVER-001 requires two genuine SDK/MCP/Q1 six-owner cases, one receiver stopped and all three receivers stopped; actual ACK/native issuer row/outcome/current read proof are authority, identity-only markers are timing observations only. Preserve first original signed packet, source proof/checkpoint ACK, body/grant/nonce/absolute expiry/original receiver first epoch, current persisted same-subject admin and work. Existing FirstVoter original effect send is unchanged. No replacement issuer/effect packet, body, nonce, expiry, optional trust flag, guessed result, retry or new dispatcher.
1551
+
1552
+
Closed private phases append ParentReceiverIssueAcknowledged (Orleans11/Server16) and ParentReceiverIssueObserved (Orleans12/Server17), after existing Close phases. They are emitted ONLY for actual first StagePage ordinal0, from the same original c1-authenticated parent ingress callback constructed by PartitionMoveParentExecution. The first follows successful IssueReceiverFirstAsync completion (real native own result ACK) and precedes existing ObserveExistingAsync. The second follows successful canonical receiver witness checkpoint ACK returned by ObserveExistingAsync, before original first effect dispatch. Callback uses original native context/token and joins the existing primary/cleanup failure ledger. Closed arm is original nonempty MoveId, no ReadKind, Hold, existing persisted c1 principal. No marker includes page/proof/signature/grant/body or confers execution authority. No change to GrainReadKind reserved ClusterBackupOwner/WaitForAnnIndex.
1553
+
1554
+
One receiver case: genuine first StagePage Issue ACK; stop same original node4; release ACK; original QueryReceiverIssueAsync retries only its existing READ voter loop, not effect. Require observed proof checkpoint boundary; restart exact node4 resource under unchanged original expiry/token; release for original FIRST effect send. Actual retained witness must decode authenticated native reply from node5 (node4 absent; node6 was not needed), exact issuer original identity/row/native successful own outcome/read cut/ACK. Genuine complete transfer then SDK/official MCP/Q1 original receipt/model replay and true cold. If original expiry/token preempts restart or execution, retain actual failure, no extension.
1555
+
1556
+
All receiver case: stop node4/node5/node6 after actual Issue ACK, then release. No successful receiver proof boundary may occur. Require original public UnknownWriteOutcome from actual unavailable observation; no original effect result or receiver witness checkpoint, original pending/grant/canonical signed packet and active/outstanding quota retained. Restore all same resources. Fresh persisted-admin Resume is OBSERVATION ONLY: it can ACK actual original issuance proof, but native original StagePage outcome is absent and must return RecoveryRequired; it MUST NOT dispatch/reissue/renew original effect. Exact native issuer row/outcome/body/grant/nonce/expiry remain unchanged and no StagePage effect appears. Then genuine target-first Abort/native disposal of original pending grant, Aborted replay, fresh MoveId complete healthy SDK/MCP/Q1 and true cold. All failures/cancellations/producers/arms/readers/resources joined with original deadline; no resource stop substitutes for a held observation.
1557
+
1558
+
REQ-MOVE-PARENT-OUTCOME-RETURNED-ERROR-001 / AC-MOVE-PARENT-OUTCOME-RETURNED-ERROR-001 freeze owning KeyLoad producer correction. EndpointOutcomeOperations currently normalizes thrown errors only, preserves an obsolete special detail, and returns native MissingDurableOutcome detail untouched. Strict verifier allows only Unavailable. Normalize ONLY terminal.Error non-null SafeDetail to existing Unavailable before unchanged RequireValue then envelope/serialization/MAC. Preserve code and payload (malformed nonempty error payload still rejected), success byte semantics and original native diagnostics. Missing actual outcome remains RecoveryRequired; never synthesize OperationResult/receipt, clear pending or discharge quota. Genuine all-loss→restored Resume→retained unknown→Abort/fresh healthy case covers returned error; malformed signed result and arbitrary enum/payload remain strict failures under existing owning native suites.
1559
+
1560
+
Ownership: Orleans private phase enum/PartitionMoveParentExecution callback closed set; Server private phase/JSON/records, NativeStep/PhaseRunner/ReceiverProofRunner borrowed callback, EndpointOutcomeOperations strict producer; feature/ADR appendices; seven Integration responsibility files. No Core persisted/public protocol/format/alias/Id or config/default/time/limit change. Source-first root review/join/build/native discovery/full mandatory Linux normal/scalar Unit/Recovery/RF3 remain OPEN. All prior immutable artifacts retained. Future embedded native SafeDetail upper bound remains OPEN and unrelated.
1561
+
1562
+
Automated source-only mapping: `PartitionMovementReceiverIssueFailoverRf3Tests.ActualIssueAckReadFailoverRetainsOriginalAuthorityAndColdSdkMcpQ1HealthyContinuation` with genuine OneReceiver/AllReceivers arguments. Native UID/runtime and complete-frame frame criterion are OPEN.
REQ/AC-MOVE-PARENT-RECEIVER-ISSUE-INGRESS-ADJUNCT-001: the ephemeral private native probe may admit exactly one linked ParentReceiverIssueObserved arm for a genuine released ParentReceiverIssueAcknowledged claim. Existing SourceArmId/SourceRequestId must match the actual original c1 ingress request/MoveId and native observed/released primary markers. Original single claim, current admission/gate quotas, options, clock, caller token and producer lifetime remain unchanged. Separate immutable arm ID/release cannot reuse the primary release. Wrong/missing/duplicate links, altered subjects/commands/request IDs, wrong source phase, changed target/partition/read kind or bytes fail closed. No public/persisted format or trust/effect-routing change.
1568
+
1569
+
Source implementation owns RequestCqrsReceiverIssueAdjunct; the existing arm validator/claim selector/observer/claim records compose it. Actual producer disposal writes both original primary and selected adjunct markers under one original failure ledger and lifecycle drain; fixture retires the linked arm before its still-active primary. No returned proof or marker synthesizes native authority. The first ACK callback only follows actual Issue completion; the second only follows actual canonical receiver witness checkpoint ACK. Nonprobe paths retain the original effect send and no waits.
1570
+
1571
+
Automated whole-flow source binding: PartitionMovementReceiverIssueFailoverRf3Tests.ActualIssueAckReadFailoverRetainsOriginalAuthorityAndColdSdkMcpQ1HealthyContinuation(bool allReceivers), authored Arguments(false) and Arguments(true). One-loss compares independently signed still-running node5 discovery with the retained original signed receiver reply, its native issuer row/own StoredOutcome/receipt/cut before original node4 first dispatch; true cold follows. All-loss restores the exact three existing kill receipts before the standard six-stop/18-lock snapshot, authenticates original retained proof via observation-only Resume, requires missing original effect RecoveryRequired/value-null/Unavailable with charged state, then genuine old-grant AbortDisposition and fresh movement/full SDK/MCP/Q1/cold model/receipt replay. Legitimate control proof ACK journal changes are distinct from business/effect/grant mutations. Original 60s grant/parent 12m deadline/defaults remain untouched; actual expiry/restart/setup/refusal failures remain failures.
1572
+
1573
+
Qualification OPEN: exact source compiler/analyzers, fresh native typed bool case IDs/image binding, native normal/scalar strict actual-vs-malformed transport/identity suites, all mandatory process recovery and Docker Aspire RF3 runs, invalid-adjunct genuine negative-flow qualification, movement final Install-frame legal/+1 evidence and future native embedded outcome detail capacity bound. Source guards/self-review are not runtime PASS or whole KL036 closure.
Copy file name to clipboardExpand all lines: docs/ADR/ADR-117-native-tunit-ci-entry.md
+7Lines changed: 7 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -231,3 +231,10 @@ AC-KL035-PUBLISHED-REPAIR-001 maps to those four existing cases and feature-loca
231
231
## TASK-KL036-COMPLETE-SOURCE-ADMISSION-001 — native Linux expectations
232
232
233
233
The KL-036 selected scope preserves every original34 case declaration and adds the real operational capacity, retained native-page failure and original Close/SourceBeginAbort whole flows, for37 source-declared cases per profile. ADR-106 owns their REQ/AC and execution contracts; ADR-117 owns native invocation and original-report reconciliation. This is an admission expectation, not discovered UID/count or a passing result. Exact-source Linux native discovery, normal/scalar execution and all mandatory full suites remain open. The other nine task objects and all original selectors/case declarations remain intact.
234
+
235
+
236
+
## TASK-KL015-C1-NATIVE-CAUSE-001 — bounded original failure classification
237
+
238
+
REQ-C1-OUTCOME-NATIVE-CAUSE-001: the original C1 inspector must retain its first OpenStore failure and identify known native database, serializer and runtime causes using only closed enum labels and already allowed numeric codes. AC-C1-OUTCOME-NATIVE-CAUSE-001: unwrap only original AggregateException first members and TypeInitializationException/TargetInvocationException inner causes, within the unchanged16-level ceiling; preserve original phase, primary failure, native exit, all resource joins and the256-byte canonical stderr contract. Emit no exception message, stack, path, class-name string, caller data or credential. Unknown causes remain Other and remain failures.
239
+
240
+
AC-C1-OUTCOME-NATIVE-CAUSE-002: the existing real child-process wrong-node/wrong-incarnation flow must return OpenStore/KeyLoad/TokenInvalidated, release the original owner and then read the original literal outcome through the healthy child. All existing malformed-input, scoped-outcome, disposal and RF3 persisted-revocation whole flows remain mandatory. New labels are diagnostic evidence only, never proof of an absent outcome or a reason to accept failed inspection. ADR-117 owns native execution/report evidence; AC-CRS-005 retains request isolation and persisted authorization. No public/persisted/storage/package/topology boundary changes; no additional ADR is required. Rollback removes the added classification/assertions only. Fresh current-source Linux build, normal/scalar process and real RF3 results remain OPEN.
0 commit comments