Skip to content

Commit 876c523

Browse files
committed
Repair native recovery and RF3 lifecycle evidence
Fix native FTS crash dispatch and preserve the materializer terminal fault in its real recovery flow. Isolate six heavyweight ANN correctness flows through native TUnit scheduling without changing bodies or production budgets. Keep RF3 capture consumers alive through join, capture actual official MCP schemas, correct query and graph fixture oracles, and complete the scoped comparison-helper transfer. Release build, full native format and governance pass. Native process recovery passes235/235 with no skips or source/assembly drift. Complete normal/scalar, delivered-source Linux RF3 and functional coverage remain open; coverage producer/workflow contracts are accepted preparation only.
1 parent 06b9bb8 commit 876c523

52 files changed

Lines changed: 1221 additions & 99 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎README.md‎

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -335,9 +335,12 @@ Discovery exposes static operation documentation. Each invocation checks current
335335
The original 104-task plan has **0 fully accepted, 104 in progress and 0 pending**.
336336
KL-075 now has its first scaling source stage; six-node, open-loop, shard-skew,
337337
fanout, recovery and movement acceptance remains open. The joined stage has
338-
compiler/analyzer failures under repair. The earlier local full unit suite passed
339-
**3,490 of 3,492 tests**, with two failures and no skips; this does not qualify
340-
the later source. The [original Linux source788 run](docs/implementation/runtime-qualification-37349838022.json)
338+
passed the local Release build with zero analyzer errors and warnings. The current
339+
native process-recovery suite passed **235/235**, with no skips. The latest full
340+
uninstrumented unit report, before the ANN test-scheduling correction, passed
341+
**2,762/2,763**, with one ANN construction deadline failure and no skips.
342+
Complete normal/scalar reruns and delivered-source Linux qualification remain
343+
open. The [original Linux source788 run](docs/implementation/runtime-qualification-37349838022.json)
341344
passes the official MCP SDK guidance case but fails the complete RF3 and release
342345
gates. [Checkpoint evidence](docs/implementation/partition-runtime-development-2026-10-05.json)
343346
keeps those failures and the remaining scalar, recovery, RF3 and scale gates explicit.

‎docs/ADR/ADR-007-replica-consensus-bootstrap.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,6 +83,21 @@ faults have source-review evidence only unless an exact original runtime receipt
8383
proves their execution; no forced fatal failure or successful settlement is
8484
invented.
8585

86+
TASK-REP-MATERIALIZER-FAULT-ORACLE implements AC-REP-002/004/051 in the existing
87+
real ZoneTree lifecycle case and fixture. Preserve production fault propagation:
88+
JournalFlushed failure fences the waiter with RecoveryRequired, while repeated
89+
memoized disposal observes the same original UnknownWriteOutcome after terminal
90+
cleanup. Verify the borrowed protocol gate, physical owner closure and committed
91+
prefix reopen. Only the exact already-asserted terminal exception may be
92+
acknowledged by fixture cleanup; every other scenario or cleanup failure remains
93+
visible. Implement the test oracle, then its narrow fixture acknowledgment, review
94+
the normal/faulted paths, and run native recovery before exact-source Linux
95+
qualification. Root owns contract/integration; the recovery worker owns only
96+
ReplicaMaterializerLifecycleTests.cs and ReplicaMaterializerLifecycleFixture.cs
97+
under RecoveryTests/Features/ClusterReplication. No production, format, dependency
98+
or topology change is involved; reverting the test correction preserves every
99+
durable cut. Existing process-kill proof does not qualify power-loss or RF3.
100+
86101
Local development execution, when useful, uses the canonical Aspire-owned test
87102
entry and is labeled development evidence. Only exact-source Linux GitHub
88103
Recovery/RF3 jobs qualify delivered behavior. No test-only result or historical

‎docs/ADR/ADR-019-managed-ann.md‎

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,17 @@ Status: Accepted for the bounded first-party managed HNSW candidate stage on 202
44

55
The accepted 2026-10-05 test-resource stage is REQ/AC-ANN-013 in
66
[ManagedAnn](../Features/Search/ManagedAnn.md). Root freezes/reviews/joins; a Luna
7-
worker adds only the named Search test resource and native keyed TUnit attributes
8-
on the specified five heavyweight fixture methods. Test bodies, corpus sizes,
9-
product execution budgets and global runner concurrency remain unchanged. Verify
10-
the private base/post packet, full strict build/format/governance, Aspire normal
7+
worker changes only native TUnit attributes on the specified six heavyweight
8+
fixture methods to unkeyed `[NotInParallel]`, as refined on 2026-10-07. The
9+
unused named Search test-resource helper is removed. Only those six flows are
10+
globally isolated within their TUnit process; there is no assembly-wide
11+
serialization. Test bodies, corpus sizes, explicit concurrency tests, product
12+
execution budgets and global runner settings remain unchanged. Verify
13+
the private base/post packet, full strict build/format/governance, native TUnit normal
1114
and scalar suites and exact-source Linux originals before any qualification
12-
claim. Rollback removes only the resource key and attributes; there is no data,
15+
claim. The unchanged full R111 failure and focused pass indicate scheduling
16+
sensitivity without proving the failure's cause. Rollback restores only the
17+
prior test scheduling; there is no data,
1318
dependency, public API or production admission change.
1419

1520
## Context and decision

‎docs/ADR/ADR-033-code-quality.md‎

Lines changed: 82 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -78,13 +78,17 @@ format, dependency, public API or topology changes belong to this quality stage.
7878
## Complete functional unit contributor partition
7979

8080
TASK-CQ-FUNCTIONAL-UNIT-INVENTORY-043 implements REQ-CQ-009 and AC-CQ-018/020/021.
81-
Keep ordinary unit and scalar suites complete, unfiltered and without coverage.
82-
Collect functional unit coverage separately through five bounded positive
83-
selector groups in each mode, with one exact current case inventory. Every
84-
allowed case belongs to exactly one group; classify every excluded BDN, load,
85-
stress, performance or comparison case explicitly. Namespace membership alone
86-
does not authorize a contributor. Bind the inventory to current test sources,
87-
the same Release compiler-input/DLL/PDB/MVID identities and actual native TRX.
81+
Keep ordinary unit and scalar suites complete, unfiltered and without coverage
82+
after the authorized physical transfer leaves their assemblies free of benchmark
83+
and comparison cases. Those checks stay with the Benchmarks-owned projects and
84+
workflow. Collect functional unit coverage separately through five bounded
85+
positive selector groups in each mode, with one exact post-transfer current case
86+
inventory. Every permitted functional case belongs to exactly one group;
87+
classify any residual nonfunctional cross-slice case explicitly and record the
88+
new owner for moved benchmark cases without duplicating selector inventories.
89+
Namespace membership alone does not authorize a contributor. Bind the inventory
90+
to current test sources, the same Release compiler-input/DLL/PDB/MVID identities
91+
and actual native TRX.
8892

8993
Ordered stages: root freezes this contract and owning feature; a Luna worker
9094
prepares guarded source and meaningful merge-operation regressions; root joins,
@@ -98,3 +102,74 @@ Root owns workflow, inventory, identity and report joins. Roll out one coherent
98102
strict descriptor/validator/CI checkpoint; rollback restores that checkpoint's
99103
source/configuration pair, without an alternate reader or reduced qualification.
100104
No numeric coverage or module closure follows from preparing an inventory.
105+
106+
107+
A separate post-descriptor regression invokes the native merge entry point in
108+
`ProductAdmission` mode against the actual generated Product descriptor and TRX
109+
receipts. Product and admission modes share path/tool/bounds checks and
110+
`Read-FcNativeProductPlan`; admission emits only a bounded validation result and
111+
does not invoke collectors, merge reports or write coverage outputs. The
112+
regression admits original evidence, rejects a controlled modified copy only
113+
for its expected validation failure, verifies original bytes remain unchanged,
114+
and admits the originals again. It uses no authored TRX. Ordinary full unit/scalar
115+
operations do not claim to perform this separate admission regression.
116+
117+
The Product descriptor also binds successful full normal and scalar unit
118+
`unitCensus` runs from the same evidence cohort and Release build. Both run with
119+
coverage disabled and bind original TRX/report hashes, exact identities and
120+
source locations, the captured source-manifest digest and test-image receipt.
121+
Normal/scalar census identity sets must agree with each other and with the exact
122+
current functional inventory. In each mode, its five instrumented groups are
123+
disjoint and their union equals both that mode's census and the inventory, with
124+
zero failed/skipped cases. Census files are bounded validation inputs only, never
125+
coverage merge inputs/counts. Product and ProductAdmission both revalidate the
126+
same descriptor/census through `Read-FcNativeProductPlan`; native merge
127+
execution remains unchanged.
128+
129+
Each inventory case also records the original native TUnit `lineNumber` and
130+
`endLineNumber` alongside its exact current source path/hash. Require positive,
131+
ordered line bounds within that source file; both census reports and every
132+
instrumented report must match this exact method/argument source range. Missing
133+
or mismatched ranges reject rather than falling back to path-only ownership.
134+
135+
136+
The descriptor producer takes `-UnitRunStatusPath` pointing to
137+
`functional-coverage.unit-run-status.v1.json` inside the same evidence root,
138+
replacing the former single unit/scalar exit-code parameters. Its strict schema
139+
is `schemaVersion:1`, `sourceRevision`, `sourceManifestSha256`, and `runs`; each
140+
run has exactly `id`, `suite`, `filter`, `coverageEnabled`, `exitCode`, and
141+
`resultsDirectory`. Require exactly twelve unique runs: `unit-census`,
142+
`unit-scalar-census`, `unit-functional-01` through `unit-functional-05`, and
143+
`unit-scalar-functional-01` through `unit-scalar-functional-05`. The two census
144+
filters are empty and coverage is false; each coverage filter equals its exact
145+
inventory selector and coverage is true. Each results directory equals its run
146+
ID and is confined to the evidence root. Capture each integer exit code from
147+
the original native TUnit process; all twelve must be zero. Recovery/RF3 retain their
148+
explicit existing exit-code inputs. Require current source/image parity and
149+
original bounded native reports for every row; the status file alone cannot
150+
prove successful execution. Read at most 64 KiB, within the configured manifest
151+
limit, and reject unknown, duplicate, missing, skipped or malformed entries.
152+
No alternate directory discovery or prior unit-status schema is accepted.
153+
The fixed 64 KiB bound accommodates ten ASCII selectors of at most 4,096
154+
characters and the twelve closed metadata rows. Keep the per-selector bound,
155+
exact schema and configured manifest limit; the former 16 KiB aggregate cannot
156+
represent every admitted selector set. This is a private evidence-format bound,
157+
not a change to operation deadlines, test outcomes or coverage thresholds.
158+
159+
Bind `unitRunStatus` and per-unit/scalar/census `statusId`, consuming all twelve
160+
rows once with exact directory confinement; recovery/RF3 inputs stay separate.
161+
The existing `NativeCoverageMergeTests` case uses new CodeQuality/Helpers
162+
`NativeCoverageProductEvidenceRejection.cs` and
163+
`NativeCoverageProductEvidenceFiles.cs` for its required post-descriptor phase.
164+
Set `KEYLOAD_NATIVE_PRODUCT_ADMISSION_REQUIRED=true` and
165+
`KEYLOAD_NATIVE_PRODUCT_DESCRIPTOR_PATH` together; missing, inconsistent or
166+
invalid required inputs fail. CI validates the bounded
167+
`native-product-admission-phase.v1.json` receipt after the complete native
168+
admit/controlled-denial/immutability/re-admit/cleanup flow. Both absent selects
169+
only ordinary real backup/restore and cannot qualify the separate phase.
170+
171+
TASK-CQ-FUNCTIONAL-UNIT-INVENTORY-043 joins temporary-directory creation to the existing observed admission/cleanup lifetime: the caller retains the exact owned path before creation and attempts bounded cleanup even when creation fails. Check copied native TRX/descriptor bytes against their own format bounds and the configured per-file bound before writing. Preserve original native failure, all cleanup errors, the existing whole-operation case and the required post-descriptor receipt. No runtime fault proof is inferred from source review.
172+
173+
TASK-CQ-FUNCTIONAL-UNIT-INVENTORY-043 inventory validation preserves native multi-case declaring classes and byte-preserving benchmark transfer namespaces. Distinct declaring classes still obey the frozen positive selector identity contract. The exact physical ComparisonTests source path/hash establishes moved-case ownership; preserved UnitTests namespaces are not functional coverage authority. Case identities remain unique and all functional census/positive-group parity and exclusion checks remain mandatory.
174+
175+
The 2026-10-07 report-display amendment to TASK-CQ-FUNCTIONAL-UNIT-INVENTORY-043 records the declared CLR `className` from original TRX separately from exact original MTP `nativeReportClassName` on each functional inventory row. Native TUnit tree selectors use the former; fixture display suffixes remain untouched in the latter. The linked CodeQuality contract freezes the extra field's bounds, one-to-one report/TRX/source joins, unchanged moved-case shape and mandatory successful census/group parity. Ordered stages are contract freeze, private two-script producer repair and native draft reconciliation, one coherent inventory/producer/workflow join, strict build/format/parser checks, and original complete Linux coverage plus ProductAdmission qualification. Root owns integration; the Luna worker owns only `functional-coverage.native-merge.contributors.ps1` and `functional-coverage.native-merge.functional-report.ps1` within the existing stage. Rollback removes the coherent amendment without introducing a fallback alias reader. Public APIs, persisted formats, dependencies and all existing thresholds are unchanged; failed draft evidence remains unqualified.

‎docs/ADR/ADR-034-cluster-comparisons.md‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -151,3 +151,31 @@ Keep original measurement artifacts immutable; no legacy reader, previous-format
151151
path, alternate topology, weaker bound or host-process fallback is authorized.
152152
Source implementation, local development and a pushed commit alone do not mark
153153
this decision Implemented or establish a performance winner.
154+
155+
## Exact clean source checkout regression
156+
157+
TASK-BC-SOURCE-001 implements REQ-BC-SOURCE-001 / AC-BC-SOURCE-001 in the owning
158+
feature and retains AC-IMAGE-006. Native `verifySourceCheckout` must reject
159+
unignored untracked files as well as tracked changes before Dockerfile checks,
160+
Docker/registry allocation, receipts and GitHub outputs. Use Git's existing
161+
porcelain status with `--untracked-files=all`, retaining repository ignore rules,
162+
revision equality, bounded child execution and the existing exact diagnostics.
163+
164+
Ordered stages: root freezes this contract; a Luna worker adds the real
165+
`SourceCheckoutIdentityTests.CleanSourceIdentityRejectsUntrackedInputAndRecoversWithoutChangingHead`
166+
operation and its `TemporaryGitCheckout` fixture under
167+
`KeyLoad.ComparisonTests/Features/BenchmarkComparisons/UnitContracts/{Cases,Fixtures}`;
168+
root reviews and joins the minimal `prepare-images.mjs` change, builds the
169+
solution, then verifies this case through Aspire in Benchmarks and retains the
170+
original native Git/image results. A real committed temporary checkout must
171+
admit, reject an added untracked source only for the expected dirty diagnostic,
172+
recover after removing that owned file, and preserve HEAD/tracked bytes. A
173+
generated ignored file remains admissible. Existing genuine image export/import
174+
and preflight gates remain mandatory; no Git-only result establishes image
175+
identity or GitHub qualification.
176+
177+
No schema migration or rollout path is introduced. If qualification fails, fix
178+
the narrow source/check pair while retaining original evidence; do not keep an
179+
alternate permissive reader. Root owns docs, integration, source evidence and
180+
delivery; worker edits are confined to the three owned paths. No dependency,
181+
Dockerfile, RF3, receipt-field or public operation change is authorized here.

‎docs/ADR/ADR-039-official-mcp-agent-api.md‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -298,3 +298,24 @@ request cannot pin that cut. No fake transport, direct-store proof, fixture chan
298298
new provider or runtime contract. This adds no persisted/public format change;
299299
rollback removes only these tests/helper overload together. A failure or blocked
300300
cluster does not qualify the EventStreams capability.
301+
302+
## Native official-client schema evidence
303+
304+
TASK-MCP-NATIVE-SCHEMA-EVIDENCE supports existing REQ/AC-CLIENT-006 and AC-MCP-001.
305+
Root freezes the bounded diagnostics contract in ClientApi. A Luna worker owns
306+
only new `IntegrationTests/Features/ClientApi/Helpers/NativeMcpSchemaEvidence.cs`
307+
and additive capture calls in existing `McpDiscoveryTests`,
308+
`GraphIncomingMcpSchemaTests` and `PartitionQueryMcpSchemaTests`. Root reviews,
309+
joins, builds and executes those unchanged assertion flows through actual Aspire
310+
Docker RF3 and the official C# MCP client, then retains original GitHub artifacts.
311+
312+
Capture only the three exact tool input schemas before the existing assertions:
313+
at most 64 KiB UTF-8 per object, with at most 1 KiB safe name/context/filename/size/
314+
SHA-256 sidecar. Use the existing repository-root helper and unique owned files
315+
under uploaded `artifacts/qualification/mcp-schema-evidence/`; reject unknown
316+
names, invalid objects, excess size and failed writes. No credential, caller
317+
payload, private catalog, production logger, alternate schema or synthetic
318+
response is introduced. Public API, persistence and dependencies are unchanged.
319+
Original failed assertions remain failures. Fix their owning schema/oracle only
320+
after actual payload evidence establishes the defect; no compatibility reader
321+
or permissive integer/nullability fallback is authorized.

‎docs/ADR/ADR-074-aspire-owned-test-entry.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,17 @@ and rejection, transferred discovery inventory, solution build, formatter,
3232
governance and Aspire functional suites. Failed gates remain open; reverting
3333
this boundary requires owner direction.
3434

35+
TASK-TEST-PIPELINE-EXCLUSIVE-HELPERS completes that ownership boundary without
36+
behavior changes. Move the byte-identical benchmark-only
37+
`TestOrchestrationConfigurationKeys.cs` and `WorkflowDatabaseGroups.cs` into
38+
ComparisonTests `Features/BenchmarkComparisons/UnitContracts/Contracts/` and
39+
`UnitContracts/Models/` respectively, preserving their namespaces. Remove their
40+
two linked Compile entries from `KeyLoad.ComparisonTests.csproj`; the SDK includes
41+
the new owned paths. Keep the genuinely shared `TestElapsedClock` link. Root owns
42+
contract, join, solution build and evidence; a Luna worker owns only those two
43+
file relocations and the comparison project change. No new tests are needed for
44+
a byte-preserving move; retain existing discovery/assertions and required gates.
45+
3546
## Decision and boundaries
3647

3748
`KeyLoad.AppHost --KeyLoadTests:Suite=<suite>` composes one actual Aspire

‎docs/ADR/ADR-078-native-full-text-projection.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -218,3 +218,20 @@ records the full Release build and formatter, actual Aspire native unit26/26 and
218218
process-recovery10/10 results, source/binary/report hashes, and the real package
219219
signature check. These bounded filtered development suites do not qualify the
220220
complete Linux/RF3 release gates or close KL-029/039/097.
221+
222+
## Native-text recovery dispatch correction
223+
224+
TASK-FTS-RECOVERY-DISPATCH implements the existing REQ/AC-FTS-003/004/005
225+
process-cut contract. The private CrashHost protocol has exactly five arguments:
226+
canonical source directory, receipt path, native fault stage, replacement flag,
227+
and mode. `NativeTextCrashScenario.TryRunAsync` reads the mode from the end of
228+
that array before the ordinary commit-stage fallback. The former forward index
229+
missed the native mode and sent the receipt path into commit-stage parsing.
230+
231+
Root freezes this protocol, repairs only that index in the owning CrashHost
232+
Search helper, reviews it, builds current Release source and runs all ten existing
233+
first/replacement native-cut cases through Aspire recovery. Their real kill,
234+
complete canonical digest/bytes, recognized cleanup, rebuild and healthy search
235+
oracles remain unchanged. No package, canonical format, public operation,
236+
migration or alternate dispatcher is introduced. Retain original failed and
237+
passing native receipts; local execution alone does not close Linux/RF3 gates.

0 commit comments

Comments
 (0)