Skip to content

Commit 556c13a

Browse files
committed
Qualify client and vectors and harden native RF3 fault flows
1 parent 55f3e17 commit 556c13a

37 files changed

Lines changed: 2507 additions & 94 deletions

File tree

‎README.md‎

Lines changed: 15 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -332,20 +332,21 @@ Discovery exposes static operation documentation. Each invocation checks current
332332

333333
> **KeyLoad is a development preview.** Try it, build with it and [tell us what breaks](https://github.com/managedcode/KeyLoad/issues), but don't trust it with production data yet.
334334
335-
The original 104-task plan has **12 accepted, 92 in progress and 0 pending**.
335+
The original 104-task plan has **14 accepted, 90 in progress and 0 pending**.
336336
Accepted: **KL-005** backup/restore, **KL-007** storage codecs, **KL-010**
337337
document CRUD/CAS, **KL-012** batch/idempotency, **KL-013** document-only filter/query,
338338
**KL-016** committed projection
339339
outbox, **KL-024** time-series ordering/idempotency and **KL-025** reference
340340
ranges/aggregates, **KL-022** graph storage, **KL-023** bounded graph traversal
341-
**KL-020** three-node replicated apply and **KL-026** retention, expiry and rollups.
341+
**KL-020** three-node replicated apply, **KL-026** retention, expiry and rollups,
342+
**KL-014** server/CLI and typed SDK outcomes, and **KL-027** canonical vectors
343+
and exact search.
342344
Each closure is bound to its original criteria and Linux
343345
operation evidence. Complete feature and cluster qualification remains open.
344-
KL-014 passed all 12 declared cases in each of the normal and scalar Linux
345-
task lanes in [run 37861333290](https://github.com/managedcode/KeyLoad/actions/runs/37861333290).
346-
Its current-source acceptance is reopened after one RF3 readiness failure in
347-
[run 37868406144](https://github.com/managedcode/KeyLoad/actions/runs/37868406144);
348-
that original failure remains retained.
346+
The [client acceptance record](docs/Features/ClientApi.md) and
347+
[vector acceptance record](docs/Features/Search.md) bind those original task
348+
criteria to their accepted source. Later changes require fresh qualification;
349+
complete solution, coverage, endurance and performance gates remain open.
349350

350351
Current source includes bounded same-partition relational INNER JOIN, multi-lane
351352
queue receive with independent leaf receipts, and shared SDK, MCP and SQL operations
@@ -356,15 +357,13 @@ records the actual source, test results and remaining acceptance gates.
356357

357358
The current source includes bounded public partition Transfer/Resume/Abort,
358359
receiver-issued native proofs, persisted cancellation and joined node-local
359-
storage ownership. The full Release build and formatter pass. Seventeen support
360-
flows pass locally in normal and scalar modes; movement and process cases require
361-
Linux because their fixed loopback listeners cannot bind on this macOS host.
362-
The preceding [Linux run](https://github.com/managedcode/KeyLoad/actions/runs/37875940598)
363-
passed all 172 cases across eight task lanes and all 275 recovery cases, while
364-
the full normal/scalar unit suites retained eight/one failures. Current-source
365-
public RF3, complete unit/recovery, fault and performance qualification remains
366-
open. Original source identities and results belong in the
367-
[qualification records](docs/implementation/status.json).
360+
storage ownership. It also includes real capture-pointer fault/recovery and
361+
erased-follower snapshot plus ordered-tail flows. The full Release build and
362+
formatter pass. Related bank, HTTP client, hybrid rank/Explain and native text
363+
process-recovery tests pass all 290 selected cases across normal and scalar
364+
modes locally. Fresh source-bound Linux public RF3, complete unit/recovery,
365+
fault and performance qualification remains open. Original source identities,
366+
failures and results belong in the [qualification records](docs/implementation/status.json).
368367

369368
Current source also includes an explicit bounded follower document read through
370369
the .NET SDK and MCP, with a selected replica, lag limit and fresh authorization.

‎docs/ADR/ADR-017-ownership-session-tokens.md‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -314,3 +314,16 @@ Stages/ownership: IntegrationTests ClusterReplication Serialization declares the
314314
### TASK-KL021-FOLLOWER-CANCELLATION-ORACLE-003
315315

316316
REQ/AC-FOLLOWERREAD-001..005 use the canonical DocumentStorage contract for the actual held four-transport cancellation oracle. Require original caller cancellation/no value, actual canceled exception-token boolean for official SDK linked-token ownership, exact Cancelled for direct SDK and conservative UnknownWriteOutcome for Q1 SDK CALL, joined native producer and complete literal healthy continuation. TUnit must not introspect a disposed linked CancellationTokenSource by structural token equality. Product transport/errors/token lifetime, signed authorization, request/store/replica boundaries, all budgets and required suites remain unchanged. Root freezes docs before the guarded two-source correction, builds/formats, runs existing real partial-body SQL/client flows and qualifies actual current Linux RF3 originals. Source-only changes do not close KL021 or the independent initialize/namespace failures; original failed reports remain retained.
317+
318+
319+
## KL035 genuinely empty follower installation contract
320+
321+
TASK-KL035-EMPTY-FOLLOWER-001 implements architecture KL035 and REQ-REP-004/005, AC-REP-004/005. The retained-directory scenario remains unchanged. An additive EmptyReplicaSnapshotRf3Tests operation uses the existing inspected Docker SIGKILL/settled readers and same Aspire restart owner. Before erasure it exclusively opens actual stopped node ownership and canonical/replica owner/WAL/metadata files and rejects links/foreign roots. Only database, replica and snapshots within that fixture-owned follower bind mount are erased; actual bootstrap membership, root, profile, immutable configured incarnation and voter cohort stay owned by the same fixture.
322+
323+
AC-KL035-EMPTY-001: the two surviving voters produce forty independently literal documents and a published native snapshot, followed by one actual later acknowledged tail command. The receiving node must apply at least that original token position and have an installed read generation. A genuinely empty ZoneTree canonical store receives its newly created native NodeId under ZoneTreeIdentityFile.Open, rather than copying another node's identity; configured incarnation stays exact and the new local NodeId must survive the later cold restart.
324+
325+
AC-KL035-EMPTY-002: after public SDK/official MCP verification, kill that exact follower again and reopen only its native stopped replica store. Require non-null complete ReplicaHardState snapshot, positive index strictly before the original tail position, matching incarnation and checksum/length of its actual immutable image, committed/last positions covering the tail, and the actual retained tail ReplicaEntry with the original command ID and compatible term. Successful forwarded reads or snapshot-file existence alone cannot pass this criterion.
326+
327+
AC-KL035-EMPTY-003: real SDK and official MCP assert every complete literal document, original full commit/subscription-processing/projection result and receipt, actual source event and change records, subscription checkpoint, outbox/consumer state and inbox deduplication. Fresh cut positions must be monotone; server-created current cursors are consumed through actual continuation to the complete empty tail and are never replaced with old/fabricated cursor bytes. A principal/key genuinely persisted before erase with an unrelated resource grant is denied without value/disclosure; an administrator then reads the complete healthy document. A subsequent real update uses the same token scope, increases position without a +1 assumption, and retains original command replay after that later commit.
328+
329+
Implementation order: retain shared original producer state/internal methods; additive stopped storage owner and native inspection; complete SDK/MCP assertions; new real RF3 case. Exact slice ownership is tests/KeyLoad.IntegrationTests/Features/ClusterReplication/{Cases,Helpers,Assertions}, existing ClientApi official SDK helper borrowed; no shared fixture or production changes. Dependencies are ADR035/036/017, original persisted-policy/ZoneTree/replica APIs and native ADR117 entry. Rollback removes the additive case/helpers and restores internal helper visibility only; no persisted format or public contract changes. Root alone joins/builds/discovers/qualifies the exact new source in Linux. Existing interrupted/corrupt install, checksum, atomic cut, ordered-tail and recovery-path/GC tests remain mandatory; no deadline expansion, new retry, generated snapshot/proof/raw insert, single-node replacement or power-loss/endurance/performance claim. Source-authored assertions are not runtime qualification.

‎docs/ADR/ADR-063-bounded-database-phase-profiling.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,3 +33,10 @@ REQ-RESOURCE-003/004 map to AC-DBPROF-001..004 for preserving real phase ownersh
3333
Core diagnostics owns the bank/schema/arithmetic; producer feature owners add scalar scopes only at the original operation boundaries; Server owns private capture and lifecycle. Root owns project wiring, central options, AppHost fixture, shared schemas and integration. Tests use actual banks, ZoneTree/store operations, original tasks and Aspire resources; no fake clock/provider is used where the contract requires actual time or native state.
3434

3535
Qualification requires enabled full source checks and exact-source Linux unit/scalar/recovery/RF3 tests, real private capture verification, and repeated matched on/off profiles at current 100,000- and 1,000,000-record workloads where applicable. Existing BenchmarkComparisons current cohort, coverage and publication gates remain separate and mandatory. Source compilation does not establish measured overhead or benefit. Keep the ADR Accepted until every mapped implementation and evidence gate passes.
36+
37+
38+
### TASK-DBPROF-INVALID-RESERVATION-ORACLE-001
39+
40+
REQ-RESOURCE-003/004 and AC-DBPROF-002 map `DatabasePhaseExecutionOptionsTests.StandaloneBclBoundaryRejectsBeforeEnabledOrDisabledCounterReservation` to actual BCL invalid stripe/CAS rejection with exact ArgumentOutOfRangeException.ParamName in BOTH enabled and disabled modes. Each measured rejected construction independently remains below the unchanged MinimumStripeCounterBytes counter-array lower bound. Runtime exception allocation need not be identical between modes; authentic eb0 normal4,-1 observed1088 versus1336 bytes, which does not establish counter reservation or a product defect. Preserve that failed original and every existing invalid-input case. No threshold growth, added prewarming, retry, skip or product/configuration change is permitted.
41+
42+
After both real rejected constructions, centrally bound valid disabled/enabled banks execute native Begin/End and RecordBusy and capture concrete counters: disabled remains empty/unavailable; enabled records exactly one completed scope and one admission rejection in the actual phase, with unchanged quality and detached cumulative capture. This is the invalid-to-healthy bank subflow only, not production startup, RF3, measured overhead or full AC qualification. ADR-063/113 retain the original ownership and fixed bounds. Root owns guarded join and fresh native normal/scalar/full required gates; this source-only oracle correction is unexecuted.

‎docs/ADR/ADR-099-physical-shard-catalog.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -102,3 +102,12 @@ R206's actual native TUnit/Aspire Docker RF3 mismatch case passed every retained
102102
denial, corrected-wave and exact SDK/MCP state assertion. PhysicalShardCatalog
103103
records its original source/assembly-bound TRX identity. This local fixture
104104
proof does not close complete current-source Linux RF3 or other shard criteria.
105+
106+
107+
### First native replica prerequisite before catalog authentication
108+
109+
TASK-KL036-CATALOG-STARTUP-READY-001 implements REQ-SCAT-003 / AC-SCAT-003 and the same native startup boundary required by KL036's complete public-parent RF3 flows. Inside the existing catalog InitializeAsync ExecutionLifetime, owning TimeProvider and linked original cancellation, await local attached transport, an actual configured observed leader, positive durable term/committed prefix, locally applied committed prefix, and fresh authenticated compatible RF3 cohort. A local leader must additionally pass the existing native IsLeaderAsync committed-current-term readiness check. A follower's observed prefix is only a prerequisite, never a claimed current-term quorum proof. The immediately following original unique-grain authentication and fresh real quorum barrier remain unchanged and decisive; any subsequent leadership loss fails through that original boundary. No authentication/read request is retried, no deadline is reset, no capacity/window/limit/default is added, and startup remains closed on cancellation, poison, incompatible/missing cohort or catalog mismatch.
110+
111+
Native replica transport attaches and starts election/heartbeat maintenance during GrainService.Init before built.StartAsync returns. Early configured-peer discovery is independent of catalog and runtime-journal admission; native election/critical heartbeat commits the first readiness entry through the existing node-local materializer. Consequently this wait does not depend on the catalog admission it precedes. It observes only native owner state and uses its existing centrally validated heartbeat cadence. It does not infer readiness from a Running container, Orleans membership, directory registration or fixture metadata.
112+
113+
Automated operation regressions are the existing genuine two-RF3 public-parent linked-model SDK/official MCP/Q1 A→B→A/cold flow, all four expired-retire cancellation whole flows and the parent capacity whole flow. They each must actually reach the database operation after all six owned servers start; existing catalog mismatch/denied/corrected-wave cases remain mandatory. No getter-only fixture or separate dispatcher is introduced. Source55f normal/scalar all six RF3 cases failed before DB flow: node4/5 original logs show QuorumRead NoLeader during catalog authentication, node6 fails compatible-cohort admission. Missing initial native prerequisite is a source-backed ordering defect; successful execution of this correction remains unobserved and must not be inferred from those failed originals. Full normal/scalar/Linux RF3 qualification remains open, as does the separate same-sealed late-retire MissingAuthority proof.

0 commit comments

Comments
 (0)