Skip to content

Commit 745f4e3

Browse files
committed
Repair native roster contracts and retain official MCP initialization diagnostics
1 parent f3d7feb commit 745f4e3

25 files changed

Lines changed: 305 additions & 60 deletions

File tree

‎docs/ADR/ADR-008-backup-log-retention.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,3 +83,5 @@ flowchart LR
8383
D --> E[Atomic new identity pair and paused authority reset]
8484
E --> F[Joined owner then target publication]
8585
```
86+
87+
TASK-KL042-ROSTER-ORIGIN-NATIVE-ANALYZER-002 preserves REQ-BACKUP-ROSTER-RESTORE-001 and AC-BACKUP-ROSTER-RESTORE-001/002 after original source f3d7feb2/run37946644265 failed CA1819 and CA1062. The new unqualified generated-origin digest uses bounded ReadOnlyMemory<byte> at unchanged field Id5; compare its span against exact SHA256 without exposing a mutable array property. Validate actual public reference parameters before native key/identity matching. This is the current new metadata contract, with no format fallback, migration or acceptance claim. Existing genuine restore, first-write/replay, corrupt/missing-origin refusal, exact repair and cold/second-restore flows remain required. Root owns the source repair, coherent integration and fresh original Linux compiler/format/native operation evidence; rollback is confined to this still-unqualified origin contract.

‎docs/ADR/ADR-039-official-mcp-agent-api.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -500,3 +500,8 @@ REQ-CLIENT-006 / AC-MCP-001/003/007 map to the independently frozen movement enu
500500
## Accepted native MCP failure diagnostic contract
501501

502502
TASK-MCP-PIPELINE-DIAG-001 implements REQ/AC-MCP-PIPELINE-DIAG-001 through the [exact ClientApi ownership/privacy/stages/tests](../Features/ClientApi.md#task-mcp-pipeline-diag-001--owning-native-failure-evidence). At the original two catches, event5 publishes only closed stage/ErrorCode/actual method category; preserve original first failure and diagnostic failures in their native ledger. Missing request method reports Other. Root owns integration/docs/CI/Git; whole-task owner obtains actual original failing-branch evidence and repairs its proven cause. Contract→source→coherent Linux compilation/native discovery→actual branch observation→complete official SDK normal/scalar-caller RF3 outcomes/cleanup. No negotiation/schema/payload/data/quota/retry/fallback changes. Rollback removes observation only; source diagnostics do not establish causality, runtime branch coverage or acceptance. ADR remains Accepted.
503+
504+
505+
## Accepted official SDK initialization evidence
506+
507+
TASK-MCP-NATIVE-SDK-INIT-DIAG-001 implements REQ/AC-MCP-NATIVE-SDK-INIT-DIAG-001 under the [ClientApi exact contract](../Features/ClientApi.md#task-mcp-native-sdk-init-diag-001--official-caller-failure-classification). The native pinned CreateAsync ILoggerFactory carries only the native LogSendingRequestFailed integer ErrorCode to a caller-owned maximum8-event closed observation. No formatter/message/state strings/exception/Data/body/header/private identity are inspected or published. Factory recording starts only around actual CreateAsync, stops before operations, outputs only on failure, and is disposed after joined native session/transport/HTTP owners. Original failure remains first with observation/write/cleanup errors separately retained. No new protocol/parser/options/deadline/retry/fallback/production semantics. Existing real unsupported initialization→healthy official two-operation flow gains full native SDK result parity; original held/no-quorum failures still require native branch evidence. Contract→verified exact official source→private guarded packet→root join/Linux build/native census→actual original branch classification→proven owner repair→full normal/scalar RF3 qualification. Root owns join/Git/CI; KL021 worker owns private diagnostics/evidence. Rollback removes observation/parity only. Event absence is unclassified, never inferred timeout. Source review and supporting regression do not qualify the original cause; ADR remains Accepted.

‎docs/Features/BackupRestore.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -398,3 +398,5 @@ flowchart LR
398398
D --> E[Atomic new identity pair and paused authority reset]
399399
E --> F[Joined owner then target publication]
400400
```
401+
402+
TASK-KL042-ROSTER-ORIGIN-NATIVE-ANALYZER-002 preserves REQ-BACKUP-ROSTER-RESTORE-001 and AC-BACKUP-ROSTER-RESTORE-001/002 after original source f3d7feb2/run37946644265 failed CA1819 and CA1062. The new unqualified generated-origin digest uses bounded ReadOnlyMemory<byte> at unchanged field Id5; compare its span against exact SHA256 without exposing a mutable array property. Validate actual public reference parameters before native key/identity matching. This is the current new metadata contract, with no format fallback, migration or acceptance claim. Existing genuine restore, first-write/replay, corrupt/missing-origin refusal, exact repair and cold/second-restore flows remain required. Root owns the source repair, coherent integration and fresh original Linux compiler/format/native operation evidence; rollback is confined to this still-unqualified origin contract.

‎docs/Features/ClientApi.md‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -962,3 +962,16 @@ REQ-MCP-PIPELINE-DIAG-001 / AC-MCP-PIPELINE-DIAG-001 require failure-only native
962962
Pinned official SDK2.2.0/explicit2026-07-28 uses server/discover; a helper named Initialize does not establish a different original method. Existing outgoing replacement behavior remains unchanged. This observation does not prove the original connection cause or repair negotiation. Exact ownership: src/KeyLoad.Server/Features/ClientApi/Transport/McpSessionPipeline.cs, Contracts/McpPipelineFailureStage.cs, Contracts/McpPipelineMethodCategory.cs, Diagnostics/McpPipelineFailureDiagnostic.cs. Frontend N/A; no public endpoint/protocol/schema/catalog/persisted format/provider/quota/deadline/retry/fallback/cancellation change. ADR: [ADR-039](../ADR/ADR-039-official-mcp-agent-api.md).
963963

964964
Root freezes/joins/docs/CI/Git; KL-021 whole-task owner obtains actual catch execution evidence, repairs only a proven owning cause, and retains genuine official SDK/MCP healthy/refusal/cancellation/full receipt/cold cases. Ordered stages: contract; coherent source; Linux build/format/native discovery; original source/image-bound native failing-branch observation; proven repair; complete normal/scalar-caller RF3. Existing unsupported-protocol/healthy flows do not themselves prove catch coverage. No getters/metadata/synthetic PASS qualify. Rollback removes only observation while original native failure/cleanup remain. Actual native branch coverage, compilation and Linux results are OPEN.
965+
966+
967+
## TASK-MCP-NATIVE-SDK-INIT-DIAG-001 — official caller failure classification
968+
969+
REQ-MCP-NATIVE-SDK-INIT-DIAG-001 / AC-MCP-NATIVE-SDK-INIT-DIAG-001 refine REQ-CLIENT-006 and AC-MCP-001/003/005/007. During the actual pinned official SDK2.2.0 McpClient.CreateAsync only, a caller-owned ILoggerFactory accepts only category ModelContextProtocol.Client.McpClient, Warning, EventId.Name LogSendingRequestFailed, and its native integer ErrorCode state entry. Capture at most8 closed RemoteRpcError/category+numeric-code events; saturation is explicit. Never invoke the formatter, inspect/retain arbitrary messages, EndpointName, Method, RequestId, exception/Data, state strings, payload/body/header/principal/credentials, or enable Trace. Unknown events/state shapes are ignored; no synthetic cause is substituted. An observed event proves a native RPC error; absent events do not prove timeout or success. The same actual native client/options/transport/token execute unchanged.
970+
971+
Exact official source at commit6fa3825973949a9c4f0cd8af344e15a8db09dc35: McpClient.Methods.cs CreateAsync passes ILoggerFactory into McpClientImpl; McpClientImpl.cs creates ILogger<McpClient> and supplies it to McpSessionHandler. McpSessionHandler.cs logs LogSendingRequestFailed with integer errorCode at704–707 before raising its native remote protocol exception, and1186–1187 define its Warning structured event. Native .NET10 LoggerMessageAttribute.EventName defaults to the method name. Existing pinned2026-07-28/native five-second discovery probe and60-second initialization budget are unchanged.
972+
973+
Ownership: IntegrationTests ClientApi Diagnostics/NativeMcpInitializeLogObservation.cs owns the bounded caller factory/logger; Helpers/McpOfficialClient.cs owns true CreateAsync start/stop and joins its factory cleanup after native session/transport/HTTP settlement; Diagnostics/McpInitializeHttpObservation.cs writes safe native SDK evidence alongside existing HTTP evidence only on original failure. Original error remains first; diagnostic observation/write/cleanup faults join without masking it. Successful calls emit no diagnostic output; recording stops before real operation calls. The factory remains a stopped silent owner until the native session drains. No public API, storage format, dependency version, production logger, negotiation, parser, topology, resource admission, deadline, retry or fallback change. Frontend N/A.
974+
975+
Existing actual Aspire RF3 McpDiscoveryTests.AcMcp003UnsupportedOfficialProtocolRejectsThenCurrentCallerExecutes retains exact unsupported-version HTTP400 then true fresh current-revision connection and two genuine MCP operations, strengthened by full native SDK capability-result parity. This operation flow exercises failed initialization→joined cleanup→healthy official connection/operation, not logger DTO/property assertions. Original KL021 held Grant(SqlSdk) and lost-quorum(SqlSdk) initialization failures additionally require exact-source normal/scalar original logs and native error events; ordinary unsupported handshake regression does not establish remote-RPC event coverage.
976+
977+
Ordered stages: contract before source; exact native API/source verification; private guarded source review; root join/build/format/native census; original failed-branch diagnostics; repair only proven owning cause; complete genuine SDK/MCP healthy/refusal/receipt/cold RF3 flows and original Linux artifacts. Root solely owns live integration/Git/CI; whole KL021 worker owns private source and evidence audit. Rollback removes this caller observation and parity enhancement together without changing native failures/options/cleanup. ADR: [ADR-039](../ADR/ADR-039-official-mcp-agent-api.md); qualification and event coverage remain OPEN.

‎docs/Features/CodeQuality.md‎

Lines changed: 22 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -20,21 +20,22 @@ checkout changes. Unavailable code fixes require an owning-source repair, not a
2020
suppression. Recheck after repairs; fail on remaining errors/warnings or workspace
2121
load failures. Informational/hidden suggestions are advisory and require review.
2222

23-
REQ-CQ-ROS-003 / AC-CQ-ROS-003: retain the canonical final format, strict Release
24-
solution build and mapped native TUnit/Aspire operation regressions. Roslynk
25-
diagnostics supplement these gates; they do not qualify runtime behavior, RF3,
26-
coverage or exact-source Linux delivery. New behavioral defects need complete-flow
27-
regressions in their owning slices. No product dependency, runtime protocol,
28-
storage format or database topology is changed by installing this development tool.
23+
REQ-CQ-ROS-003 / AC-CQ-ROS-003: retain the canonical final format and strict Release
24+
solution build for preserving source repairs. The owner clarified this task on
25+
2026-10-09 as Roslynk code-quality inspection and fixes only; do not execute test
26+
suites or expand this task into behavioral regression work. Runtime/RF3/coverage
27+
qualification is N/A to this scoped inspection and remains open in its owning
28+
workstreams. No product dependency, runtime protocol, storage format or database
29+
topology is changed by installing this development tool.
2930

3031
TASK-CQ-ROS-001 maps these criteria to actual local tool/MCP operations (explicit
3132
manual-evidence exception for developer installation, no source-text tests),
32-
compiler diagnostics, canonical build/format and the affected existing TUnit
33-
suites. The lead owns root configuration, policy/docs and final integration;
33+
compiler diagnostics and canonical build/format. The lead owns root
34+
configuration, policy/docs and final integration;
3435
read-only workers inspect upstream APIs and the ordered ten-skill quality baseline.
3536
Ordered stages are pin/install/configure; load/diagnose; assign preserving repairs
36-
and meaningful regressions by finding; join/freeze source; format/build and run
37-
mapped suites; record actual results. Baseline findings and generated reports stay
37+
by finding; join/freeze source; format/build; record actual results. Baseline
38+
findings and generated reports stay
3839
in ignored artifacts or temporary storage. Delivery qualification remains open
3940
until the required original Linux evidence exists. Rollback removes only this
4041
local tool entry and MCP configuration, retaining product repairs and unrelated work.
@@ -46,9 +47,19 @@ flowchart LR
4647
MCP --> Workspace[Loaded KeyLoad solution]
4748
Workspace --> Findings[Compiler and analyzer findings]
4849
Findings --> Repair[Reviewed preserving source fixes]
49-
Repair --> Gates[Canonical format build and native tests]
50+
Repair --> Gates[Canonical format and build]
5051
```
5152

53+
Local Roslynk inspection on2026-10-09 loaded all27/27 projects to Ready and
54+
rechecked the solution with compiler errors, warnings and analyzers included.
55+
The initial27 errors were repaired; the recheck reported zero errors and zero
56+
warnings. Informational/hidden suggestions remain advisory, including existing
57+
namespace/folder differences and intentionally unused fluent assertion results;
58+
this result does not claim every style suggestion has been eliminated. The
59+
owner-scoped follow-up performs formatting and compilation only, without test
60+
execution or additional runtime qualification. Original diagnostic reports are
61+
kept outside the checkout.
62+
5263
TASK-CQ-UNIT64-010 implements the owner's 2026-10-06 rule-specific correction:
5364
REQ-CQ-006 / AC-CQ-008 now require KLD0032 at an executable-unit boundary of64
5465
code lines. File400, aggregate type200, nesting3, token/trivia counting,

‎docs/implementation/status.json‎

Lines changed: 41 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -210,7 +210,7 @@
210210
"localMovedContractTestsPassed": 27,
211211
"compiledUnitBenchmarkTypes": 0,
212212
"compiledComparisonBenchmarkTypes": 588,
213-
"verificationStage": "stage42_native_roster_restore_origin_source_joined_claimed_cleanup_style_build_failure_repaired_fresh_linux_qualification_pending",
213+
"verificationStage": "stage43_native_roster_analyzer_repairs_and_official_sdk_initialization_diagnostics_source_joined_fresh_linux_qualification_pending",
214214
"remaining": [
215215
"Delivered exact-current-source Linux complete normal/scalar/recovery/fullRF3 with original same-job source/image identities",
216216
"Complete current normal/scalar/recovery and genuine RF3 Linux qualification; native selection discovery passed, retain original failed and repaired cohorts separately.",
@@ -41288,6 +41288,46 @@
4128841288
"KL-001 clean Linux archive/license/source/native audit"
4128941289
],
4129041290
"nativeUidAndImageAdmission": "pending actual source-bound native census and receipts; no authored method counts promoted"
41291+
},
41292+
"stageXLIIDeliveredCommit": "f3d7feb24e173cdc0b2fae94be7ec441372c0851",
41293+
"stageXLIIDeliveredRemoteVerified": true,
41294+
"stageXLIIIOriginalDevelopment": {
41295+
"sourceBase": "f3d7feb24e173cdc0b2fae94be7ec441372c0851",
41296+
"originalLinux": {
41297+
"run": 37946644265,
41298+
"attempt": 1,
41299+
"job": 113874581546,
41300+
"log": "/private/tmp/keyload-original-f3d7feb2-full-build-job-v1.log",
41301+
"sha256": "e6fa5495d886ac0022cc62e66f8ebbc9c66cf5ae1af9d15abed287c9381a6522",
41302+
"uniqueDiagnostics": [
41303+
"CA1819 native roster origin byte-array property",
41304+
"CA1062 four native roster serialization reference-argument guards"
41305+
],
41306+
"uniqueDiagnosticCount": 5,
41307+
"outcome": "solution build failed before native functional execution"
41308+
},
41309+
"nativeSdkInitializationSourceJoinReceipt": "/private/tmp/keyload-r905-kl021-native-sdk-initialization-diagnostic-source-joined-20261009.json",
41310+
"nativeSdkInitializationSourceJoinReceiptSha256": "b3577fe359a063424f250317c14569abf4f9e9878a0eb42711dd719a2390d4f0",
41311+
"nativeSdkInitializationSourcePaths": 6,
41312+
"nativeRosterRepair": "Preserve current unqualified generated origin field ID 5 with ReadOnlyMemory<byte>, exact SHA256 comparison through Span, public reference guards, and the existing complete restore/write/replay/cold/refusal cases. Preserve concurrently authored Roslynk source repairs; no old-format reader or migration.",
41313+
"qualification": "source integration only; original failed Linux diagnostics retained, no fresh compiler or native runtime result admitted",
41314+
"actualOriginal104Tasks": {
41315+
"done": 17,
41316+
"in_progress": 87,
41317+
"pending": 0
41318+
},
41319+
"nativeOrdinaryParallelism": 50,
41320+
"heavyRf3Parallelism": 1,
41321+
"actual50OverlapQualified": false,
41322+
"concurrentDevelopmentTooling": "Authorized Roslynk source repairs and native logger semantic rename are preserved. This caller opened the absolute KeyLoad.slnx: all 27 projects loaded, no load diagnostics. Subsequent native status is Building27/27, and the diagnostic observation has not produced a result. This is not a clean-workspace, compiler, runtime, coverage or exact-source Linux claim.",
41323+
"remainingWholeTaskImplementation": [
41324+
"KL-042 coherent native cluster restore, bounded capture, joined cold restart, stable-operation CLI interruption/resume",
41325+
"KL-036 rejected replica-frame observation and complete genuine cleanup matrix",
41326+
"KL-021 fresh original official SDK initialization evidence and all native operation routes",
41327+
"KL-001 clean Linux published archive/license/source/native dependency audit"
41328+
],
41329+
"nativeUidAndImageAdmission": "pending actual source-bound native census and original DLL/PDB/image/report receipts; no authored method counts or tool diagnostics promoted",
41330+
"nativeSdkInitializationPostJoinRename": "Concurrent authorized Roslynk inspection renamed NativeMcpInitializeLogObservation and its compiled references after original six-path join R905; original immutable receipt retained, current full-scope checkpoint retains the semantic rename."
4129141331
}
4129241332
},
4129341333
"TIME-PROVIDER-001": {

‎src/KeyLoad.Abstractions/Features/BackupRestore/Contracts/AtomicPartitionRosterRestoreOrigin.cs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ public sealed record AtomicPartitionRosterRestoreOrigin(
1515
[property: Orleans.Id(AtomicPartitionRosterRestoreOriginFields.SourceIncarnation)] Guid SourceIncarnation,
1616
[property: Orleans.Id(AtomicPartitionRosterRestoreOriginFields.RestoredIncarnation)] Guid RestoredIncarnation,
1717
[property: Orleans.Id(AtomicPartitionRosterRestoreOriginFields.AppliedUpperBound)] long AppliedUpperBound,
18-
[property: Orleans.Id(AtomicPartitionRosterRestoreOriginFields.EntryDigest)] byte[] EntryDigest);
18+
[property: Orleans.Id(AtomicPartitionRosterRestoreOriginFields.EntryDigest)] ReadOnlyMemory<byte> EntryDigest);
1919

2020
internal static class AtomicPartitionRosterRestoreOriginFields
2121
{

0 commit comments

Comments
 (0)