Skip to content

Commit 58567d3

Browse files
committed
Checkpoint all current KeyLoad implementation changes
1 parent 27bae8d commit 58567d3

115 files changed

Lines changed: 4054 additions & 421 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎docs/ADR/ADR-090-graph-search.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,11 @@ Implementation contract:
3737
5. G2 implements SQL equivalence and actual .NET/official MCP RF3 fault cases
3838
before complete task closure. Keep Linux source/run/job/artifact evidence;
3939
build or development subset success is not whole-task qualification.
40+
Its frozen Q1.Search.v1 statement grammar, dedicated SqlGraphSearchRequest,
41+
exact lowering, rejection/parameter rules and same-executor ownership are in
42+
GraphRetrieval's G2 contract. Root owns wire admission and public adapters;
43+
lifecycle_wave owns the bounded QueryExecution parser, manifest profile and
44+
mapped real-store lowering/parity tests. Scalar QueryPage stays unchanged.
4045

4146
No persisted data converter, automatic store migration, dependency change or
4247
physical placement change is involved. Nodes lacking the application capability
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
# ADR-091: epoch7 interpretation fence
2+
3+
Status: Accepted, 2026-10-04. Owner: root integration; implementation worker:
4+
Luna query_wave. Related tasks KL-043/019/094/097/100 and
5+
[REQ/AC-EPOCH7-001 through006](../Features/StorageRecovery/Epoch7.md).
6+
7+
New canonical transfer, saga and projection-lineage records must never be read
8+
by an engine that can ignore their interpretation. RPC fencing alone cannot
9+
prevent offline rollback from exposing protected derived vectors. Increment the
10+
strict data epoch to7 and native checkpoint to5; admit exactly the new serving
11+
format. Preserve stable native contract aliases/IDs and WAL4 framing.
12+
13+
Choose one explicit stopped-copy converter with exact migration-only native5
14+
and native6 profiles and a native7 writer. This preserves the existing source5
15+
acceptance obligations without retaining an obsolete serving path or writer.
16+
Reject automatic migration and in-place header changes because they cannot
17+
prove full-node/current-image authority or preserve an independent rollback copy.
18+
19+
The feature specification is the canonical implementation contract: ordered
20+
stages, exact role-folder ownership, root protocol/AppHost join points, source
21+
inventory/receipt revision, immutable prior5/prior6 tests, bounded crash/retry
22+
verification and all-stopped RF3 rollout/rollback. No live conversion is executed
23+
without explicit scope for the particular user stores. Implementation remains
24+
Accepted until mapped real process, SDK/MCP RF3 and exact-source Linux evidence
25+
exists. Missing probe artifacts fail the gate and must not skip tests.
26+
27+
```mermaid
28+
flowchart TB
29+
Contract[New persisted interpretation] --> Data[Strict epoch7 admission]
30+
Contract --> Peer[Capability3 and signed-purpose fence]
31+
Prior[Exact old binaries] --> Reject[Old readers reject native7]
32+
Source[Stopped5 or6 with complete authority] --> Copy[Separate verified7 copy]
33+
Copy --> RF3[Start only homogeneous verified RF3]
34+
```

‎docs/Features/ClusterRouting/NativeCqrsRequestV2.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
1-
# Native CQRS request RPC v2
1+
# Native CQRS stream contract v2
2+
3+
The active epoch7 admission contract is [ADR-091](../../ADR/ADR-091-epoch7-interpretation-fence.md): application RequestInterfaceVersion3 and signed data-epoch7-rpc3 purposes admit the new feature cohort, while native stream shapes, v2 aliases/Ids and KLT2 framing remain frozen. The epoch6/rpc2 pins recorded below describe the prior C1 stage and do not authorize a mixed epoch6/7 deployment. Cancellation/shutdown/unavailable cohort fixtures now run without parallel contention, preserving every native RPC/TTL bound and failure oracle after the original Linux5-failure report.
24

35
Status: root implementation contract accepted, 2026-10-04; C1 implementation and regression fixtures are authored. The unchanged six C0 Aspire oracles also passed with published Communication10.2.9. C1 product qualification remains required; authored fault fixtures and local mechanism results do not close it. Canonical slice: ClusterRouting; parent [NativeCqrs](NativeCqrs.md). Decision: [ADR-082](../../ADR/ADR-082-native-cqrs-streams.md). Related slices: ClusterReplication, ClientApi, Authorization, ResourceExecution and StorageRecovery.
46

‎docs/Features/Messaging/RecurringSaga.md‎

Lines changed: 32 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,11 @@ destination queue; both queues must share the exact atomic partition.
6969

7070
Persisted SchedulerManage plus relevant QueuePublish grants are required for
7171
configuration/cancellation/emission/saga writes; root adds the next unused
72-
Capability bit. All payload/header write grants apply. Emission additionally
72+
Capability bit. All payload/header write grants apply. Explicit persisted
73+
scheduler/publish capabilities are required even for a cluster
74+
administrator, using the existing policy evaluator with its administrator bypass
75+
disabled for these checks. This applies to both caller and retained creator.
76+
Emission additionally
7377
reloads the original creator and its CURRENT scheduler/data/field/header-use
7478
authority before using retained templates; a revoked creator cannot emit jobs.
7579
Timeout similarly rechecks the persisted saga creator and source field-use plus
@@ -87,6 +91,23 @@ JSON/default arrays, input bytes and same-partition scope before writes. Read
8791
inspection uses one Clock-based ReadExecutionBudget, current principal, and
8892
cancellation; never return partial lists or invented timing guarantees.
8993

94+
Inspection DTOs are `InspectRecurringScheduleRequest(Lane,ScheduleId)` and
95+
`RecurringScheduleInspection(Definition,Revision,Generation,NextOrdinal,
96+
Cancelled,Redacted,RedactedFields)`. Definition payload and headers are projected
97+
under their respective current policies, with distinct payload/header redacted
98+
paths. `InspectSagaRequest(Lane,SagaId)` returns
99+
`SagaInspection(Lane,SagaId,Revision,Phase,StateJson,Deadline,Redacted,
100+
RedactedFields)`, projecting StateJson and omitting the raw timeout template.
101+
Neither reply exposes persisted creator identity. Public Core
102+
`InspectRecurringSchedule`/`InspectSaga` take principalId, Lane, Guid and final
103+
optional CancellationToken and return nullable replies. Root owns their
104+
HTTP/SDK/official MCP adapters. SchedulerManage is appended at bit37; existing
105+
numeric capability values remain frozen and prior All grants gain no implicit bit.
106+
The public reads are `/v1/queues/schedules/inspect` and
107+
`/v1/queues/sagas/inspect`, .NET `InspectRecurringScheduleAsync` and
108+
`InspectSagaAsync`, and MCP `keyload_schedule_inspect` and `keyload_saga_inspect`.
109+
Each reuses the native separate request grain and existing bounded read transport.
110+
90111
## Requirements, acceptance and stages
91112

92113
| Requirement | Acceptance and automated mapping |
@@ -106,6 +127,16 @@ the coherent stage. S2 freezes the periodic coordinator/fair due-index and real
106127
process/RF3 failure contract before implementation. Root records all original
107128
Linux acceptance and source/run/job/artifact results before complete KL-100 closure.
108129

130+
After S1 source handoff, Luna cluster_wave owns new IntegrationTests Messaging
131+
Cases/Helpers for S1 public mutation and inspection parity over the existing
132+
genuine Aspire RF3 fixture: SDK/official MCP configure, emit/catch-up/CAS,
133+
unknown-response replay, timeout atomicity, current creator revocation and
134+
redacted inspection. These qualify the canonical S1 transitions, not autonomous
135+
S2 scheduling. The same worker may add the already-required F1 RemoteTransfers
136+
public intent/accept/receipt/complete and repeated target acceptance oracles.
137+
Do not change shared fixtures/topology, manufacture failures, bypass discovered
138+
endpoints, weaken outcomes or run gates. Root owns combined execution and faults.
139+
109140
No dependency or automatic migration is introduced. New persisted contracts need
110141
the epoch7 old-reader rejection/explicit stopped-copy upgrade workstream before
111142
delivery; rollback never opens these stores using an unaware reader. Interactive

‎docs/Features/Search/GraphRetrieval.md‎

Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,10 @@ statistics remain the complete authorized corpus. Traversal never applies that
5959
endpoint predicate to intermediate vertices. Retriever produces only visible
6060
Search.Collection endpoints, sorted by shortest hops then full EntityRef;
6161
missing branches contribute zero and duplicate paths never amplify score.
62+
Zero-weight branches still validate their request and execute their current
63+
authorization and bounded read work, but contribute no candidates or score to
64+
fusion. A zero-weight-only retriever therefore produces no hits; it does not
65+
bypass GraphRead, seed visibility, label-use checks or shared resource bounds.
6266
Current edge authority is persisted GraphRead; edge label policy applies when
6367
Labels is non-null, using exactly the `label` field-use path, including empty
6468
label arrays. Expansion excludes all selected-hit EntityRefs from its context
@@ -94,6 +98,71 @@ rejects unsupported graph requests, never silently drops an operator. Interactiv
9498
UI N/A: this is a SDK/SQL/MCP database capability. Current evidence is source
9599
implementation in progress; no runtime or performance qualification is claimed.
96100

101+
## G2: versioned SQL SEARCH profile
102+
103+
This is a bounded Q1.Search.v1 profile of the shared SQL language, not full SQL
104+
conformance or a SQL client connection protocol. The dedicated typed
105+
`SqlGraphSearchRequest(Version, QueryRequest Query)` uses native IDs0/1 and alias
106+
`keyload.contract.sql-graph-search-request.v1`. Version must be1, Cursor must be
107+
null and AllowFullScan must be explicitly true. Root joins the native read kind,
108+
HTTP `/v1/query/search`, SDK `SearchSqlAsync` and official MCP
109+
`keyload_query_search`; all return the existing GraphSearchResult. Current
110+
application capability3 admits it. Existing scalar QueryPage is unchanged.
111+
112+
The complete accepted statement order is:
113+
114+
```text
115+
SEARCH FROM collection
116+
[TEXT field MATCH string-or-@parameter [WEIGHT number]]
117+
[VECTOR field MATCH @parameter SPACE (id, dimension, metric, model, version)
118+
[WEIGHT number]]
119+
[SCOPE GRAPH graph SEEDS ((collection, id), ...)
120+
DEPTH integer VERTICES integer EDGES integer [LABELS (value, ...)]]
121+
[RETRIEVE GRAPH graph SEEDS ((collection, id), ...)
122+
DEPTH integer VERTICES integer EDGES integer [LABELS (value, ...)]
123+
[WEIGHT number]]
124+
[EXPAND GRAPH graph DEPTH integer VERTICES integer EDGES integer
125+
[LABELS (value, ...)]]
126+
[ALLOW IDS (value, ...)] [LIMIT integer] [FUSION integer]
127+
```
128+
129+
Collection/field/graph/space identifiers follow current bounded SQL identifier
130+
rules; seed IDs, label/allowed-ID values and MATCH text accept quoted strings or
131+
named JSON string parameters. Seed collection is an identifier in the same
132+
request partition. Vector MATCH is a named JSON array of finite float-compatible
133+
numbers, with exact supplied space dimension and defined VectorMetric. Empty
134+
LABELS/ALLOW IDS retain the direct API's empty-set semantics; empty/default seed
135+
sets reject. Weights default1, limit10, fusion60; walk caps are explicit. At least
136+
one graph operator is required; graph-only retrieval is valid. Duplicate,
137+
reordered, unknown clauses, missing/wrong-kind parameters, nonfinite/overflow
138+
numbers, unsupported cursor/version and trailing tokens reject Validation.
139+
No clause can be silently ignored or manufacture a different identity scope.
140+
141+
Use the existing bounded tokenizer/token cursor and named constants, preserve
142+
their whole-SQL token/depth/byte limits, and cap JSON parameters/the complete
143+
request before building arrays. Parser output is exactly GraphSearchRequest;
144+
the final G1 validation remains authoritative. Execute solely through
145+
SearchEngine.GraphSearchAsync with the original principal and cancellation.
146+
There is no second traversal implementation, extra store read or SQL-specific
147+
authorization path. Manifest ReadProfiles adds `graph-search-v1`, while its Q1
148+
baseline and honest scalar conformance inventory remain unchanged.
149+
150+
AC-GSEARCH-006 maps G2 syntax and real-store direct/SQL equivalence to new
151+
`SqlGraphSearchParserTests`, `SqlGraphSearchParityTests` and
152+
`SqlGraphSearchRejectionTests` in QueryExecution/Cases with Helpers fixtures.
153+
Cover all operator combinations, multi-seed/different-collection intermediates,
154+
empty labels/allowlist, zero weights, exact lowering and invalid parameter/budget
155+
cases. Root extends genuine Aspire RF3 SDK/official MCP parity with policy,
156+
write and fault changes before closing the criterion. Public UI N/A.
157+
158+
Root freezes this contract/ADR and owns public adapters/capability/central docs.
159+
Luna lifecycle_wave owns new Abstractions QueryExecution SQL-search DTO, Query
160+
QueryExecution parser/validation/executor/manifest profile joins and mapped new
161+
Unit QueryExecution tests, preserving G1 source and unrelated SQL behavior.
162+
It escalates unsupported grammar or public contract changes rather than inventing
163+
fallback syntax. Root reviews/builds/runs actual Aspire gates and commits the
164+
verified stage while other feature workers continue.
165+
97166
```mermaid
98167
flowchart LR
99168
Request[Versioned graph operators] --> Cut[One authorized read cut]

‎docs/Features/StorageRecovery.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,10 @@ JSON stay unchanged. UI/SDK/MCP schema work N/A: no new wire operation.
2727

2828
## Native data epoch and explicit offline copy upgrade
2929

30+
The active next-epoch interpretation and conversion contract is
31+
[epoch7](StorageRecovery/Epoch7.md), under ADR-091. The native5-to6 receipts
32+
below remain truthful historical evidence and do not qualify the new format.
33+
3034
[ADR-077](../ADR/ADR-077-offline-native-data-epoch.md) freezes KL-043's supported
3135
native5 -> separate native6 transition. Source is authored and root-reviewed;
3236
provider and RecoveryTests development Release builds passed with zero warnings

0 commit comments

Comments
 (0)