Skip to content

Commit 88ce19e

Browse files
committed
Remove redundant ANN reciprocal scan with native parity evidence
Preserve exact graph/options/distance/edge results in actual 128-row and 10000-row normal/scalar controls. Broader ANN normal cases passed 79/79; scalar cases passed 78/79 with the original default all-metric Euclidean build deadline failure retained. Full qualification and acceleration remain unclaimed. Include current requirements, native development receipts and exact-source CI cancellation status.
1 parent f5fe42f commit 88ce19e

18 files changed

Lines changed: 1349 additions & 24 deletions

‎docs/ADR/ADR-019-managed-ann.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -202,3 +202,12 @@ all strict/Aspire gates. A partial failed build cannot prove graph equivalence
202202
or speed. Migration is N/A: R1 remains an internal immutable candidate with no
203203
serialized/public contract; R2/R3 require separate accepted contracts. Rollback
204204
restores only the removed scan and helper.
205+
206+
Root's successful-control observation joins AC-ANN-018 before code: fixed v1
207+
SHA-256 framing covers the actual complete native IDs/revisions/levels and
208+
ordered adjacency plus entry point/maximum level. Build-only ticks/allocations
209+
are captured before independent snapshot/assertion/output; actual counters and
210+
fixed options are retained. Identical control/test source runs on the original
211+
and candidate in each native mode. Failed builds cannot supply a graph hash or
212+
equivalence baseline. This remains test-only evidence with no public or
213+
persistence contract, and does not qualify acceleration by itself.

‎docs/ADR/ADR-082-native-cqrs-streams.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -206,3 +206,13 @@ the live independent consumer, normal original captures, exact caller
206206
cancellation, early stream completion and genuine SDK/MCP revocation outcomes.
207207
Rollback removes the test-only context. This addition is diagnostic evidence,
208208
not proof of the old cancellation cause or completion of this ADR.
209+
210+
The accepted DIAG-006 implementation also observes failures at the original
211+
cleanup owner: each actual failure append notifies the same read-only lifecycle
212+
owner before later completion/fallback/join/disposal work mutates its states.
213+
This narrow optional feature-local callback covers captures, subscriber and
214+
independent-consumer owners and authority cleanup stages, without changing the
215+
shared failure observer, original ordering, tasks, exceptions or deadlines.
216+
Record observer failures without skipping native cleanup. Root freezes this
217+
ordering correction before private implementation and owns native regression
218+
evidence; dependency_closeout owns the guarded diagnostics packet correction.

‎docs/ADR/ADR-100-local-partition-query-merge.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,16 @@
33
Status: Accepted; implementation and qualification pending.
44
Date: 2026-10-05. Related work: KL-037 prerequisite only.
55

6+
The accepted TASK-DQUERY-CANCEL-OBSERVATION amendment implements
7+
AC-DQUERY-PREREQ-005 with an already-armed, owned native observation thread and
8+
the unchanged synchronous real ZoneTree query. Exact case/helper ownership,
9+
15-second observation/join bounds, original token/budget, no-result and healthy
10+
follow-up requirements are frozen in DistributedQueryExecution before code.
11+
Root owns review, joins and Aspire normal/scalar/full-gate evidence;
12+
dependency_closeout owns the private test packet. Preserve the earlier failed
13+
original report. No product boundary, data/wire format or migration changes;
14+
rollback may revert this test synchronization but cannot weaken its assertions.
15+
616
## Context
717

818
KL-037's original target requires query fan-out across logical shards. The

‎docs/ADR/ADR-103-scaled-fair-comparisons.md‎

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -72,10 +72,41 @@ Consumers retain the exact sidecar and authenticate its original artifact/provid
7272

7373
Worker owns feature-local AppHost Contracts/Observation/Processes roles, minimal composition/lifecycle joins, bounded parser/identity/native regressions and scale-only script consumers. Root owns durable feature/ADR freeze, source integration, actual Aspire native Linux/Docker qualification, CI/publication, receipts and commits. Private implementation may rely on the existing 45 engine + 10 Aspire + 25 CI packets as explicit predecessor source, never silently overwrite their bases. A reviewable patch and base/post manifests are required. No checkout edits, gates or Git by the worker.
7474

75+
The accepted SCALE-016 native-root correction follows the documented cgroup-v2
76+
root semantics: CPU/memory maximum interfaces exist on non-root cgroups. Preserve
77+
all actual non-root ancestor minima, effective cpuset and verified hierarchy
78+
identity; terminate at the real root rather than requiring nonexistent root
79+
limits. Missing/malformed/unreadable required child observations remain explicit
80+
unqualified evidence. The independent actual Linux oracle and supported-envelope
81+
regression must expose that distinction. Root owns integration/original Linux
82+
gates; partition_pages owns the guarded repair. No sidecar or stored schema
83+
changes occur and rollback cannot fabricate limits or reduce complete cohorts.
84+
7585
## Accepted prerequisite: Aspire scale forwarding (REQ/AC-SCALE-014)
7686

7787
Introduce only the separate KeyLoadTests:ScaleProfile test-harness selector. TestSuiteSettings accepts one exact canonical scaled ID only for Suite=comparison, the exact /*/*/IsolatedNativeComparisonTests/* filter, present native Benchmarks:Target, matching Benchmarks:EvidenceProfile, disabled Benchmarks:Enabled, no direct Benchmarks:ScaleProfile and no workload overrides. Reject missing suite, other suites, unknown/blank/case-mismatched IDs or mixed modes before any resource creation. Existing direct Benchmarks:ScaleProfile plus a suite remains rejected.
7888

7989
run-workload passes --KeyLoadTests:ScaleProfile=<id> to the outer AppHost. Its owned runner alone receives Benchmarks__ScaleProfile=<id>; clear KeyLoadTests__ScaleProfile alongside KeyLoadTests__Suite so the harness selector does not leak into the nested native AppHost. IsolatedNativeCase reads the exact ordinary ComparisonWorkerSelection from the runner environment and passes --Benchmarks:ScaleProfile=<id> to its own nested resource-owning AppHost. Preserve exact evidence/source/native topology and all control behavior. IsolatedNativeCase uses exactly 140 minutes for the closed scale profile and its existing 60 minutes for controls; all original tasks/resources are still joined.
8090

8191
Worker owns the narrow TestSuiteSettings/TestSuiteResources/IsolatedNativeCase/run-workload joins and real Aspire model plus independent argument/environment regressions. This is a prerequisite repair to the accepted SCALE-014 path, not a new alternate test caller. Durable docs join before live implementation.
92+
93+
## Accepted stage 11: original teardown settlement, 2026-10-05
94+
95+
REQ/AC-SCALE-017 and TASK-SCALE-ORIGINAL-TEARDOWN repair the inspected existing
96+
IsolatedNativeTeardown path, which detached a pending task after 30 seconds and
97+
replaced or suppressed actual cleanup failures. Freeze the exact owner/order,
98+
original-task join, native fatal classification and primary/cleanup preservation
99+
contract in ScalingQualification before implementation. The collector joins from
100+
stage 10 use the same lifetime; the existing control success path/report schemas
101+
remain unchanged.
102+
103+
Implement in order: retain the original case failure; settle the original
104+
collector/capture and report writers; stop and dispose actual owners; delete data
105+
only after safe ownership release; write bounded safe categories; propagate the
106+
original ordered failures after all safely reachable stages. Keep 30 seconds as
107+
an escalation/failure threshold, never detached completion. Add genuine native
108+
Cases/Helpers regressions for pending settlement and simultaneous primary plus
109+
cleanup failures, and run them through the canonical Aspire comparison entry.
110+
ComparisonTests owns this code, partition_pages owns its private guarded packet,
111+
and root owns integration/gates/evidence/commit. There is no data or wire migration;
112+
rollback cannot convert an unfinished original task into a passing qualification.

‎docs/ADR/ADR-106-partition-owner-movement.md‎

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -173,3 +173,51 @@ qualify it. Native membership CAS, persisted authority, schema/byte limits and
173173
public data-admission closure remain unchanged. Root owns the join and gates;
174174
Luna lifecycle_wave owns only the guarded implementation/test packet. There is
175175
no data/wire migration; rollback disables the new profile.
176+
177+
## Accepted six-generation oracle and native parameter handoff, 2026-10-05
178+
179+
REQ/AC-MEMBERSHIP-008 in PartitionTransfer closes the source oracle gap before
180+
implementation. The already-generated B physical ID/incarnation and secret are
181+
the same named Aspire ParameterResources used by the actual six-container model
182+
and resolved privately through native GetValueAsync in its owned test wave.
183+
No independently generated verifier credential, identity or membership provider
184+
is permitted. Decode the secret only within an owned joined/zeroed lifetime.
185+
186+
The profile-only membership health reply carries a bounded closed fingerprint
187+
and counts derived from one actual native ReadAll call per node, including B's
188+
real proxy path. Its domain-separated length-framed SHA256 binds the six exact
189+
current Active SiloAddress generations without exposing addresses or row data.
190+
The independent integration oracle authenticates discovery from all six actual
191+
nodes using the shared A ClusterId and each distinct group incarnation/key,
192+
computes the expected active-generation digest, and compares all six native-view
193+
health responses. Boolean readiness alone does not prove this acceptance.
194+
195+
Implement in order: same-resource AppHost handoff; bounded native view digest and
196+
closed health reply; six-node signed-discovery verifier; actual Aspire oracle
197+
and negative native controls; strict build/format and original exact-source Linux
198+
RF3 evidence. All code remains inside ClusterRouting responsibility folders.
199+
Existing three-node discovery helper, persisted membership, native CAS, MAC and
200+
serializer identities, wire caps, public closure, failover and original task
201+
teardown stay unchanged. Root owns integration/evidence; lifecycle_wave owns the
202+
guarded source/test packet. The additive health shape is confined to the new
203+
membership-only profile. Rollback disables that profile; Stage 1B data readiness
204+
and physical movement acceptance remain unqualified.
205+
206+
## Accepted native authority route and provider ownership, 2026-10-05
207+
208+
REQ/AC-MEMBERSHIP-009 and TASK-MOVE-1A repair two inspected source gaps before
209+
integration: the authority handler was not mapped, and externally registered
210+
disposable instances had no actual disposal owner. The exact native POST route,
211+
provider-owned factory/type registration, handler/DNS/call joins before endpoint
212+
credentials/gates and owner CTS disposal, failure preservation and negative
213+
admission contracts are frozen in PartitionTransfer before code.
214+
215+
Implement in order: map the existing handler once in server composition; register
216+
its exact owner and endpoint with native DI ownership; preserve existing silo
217+
close/join then Kestrel stop/join then root-provider disposal; add native
218+
composition/lifecycle regressions and execute the existing actual six-container
219+
Aspire startup/authentication/teardown flow. lifecycle_wave owns the private
220+
guarded ServerConfiguration/transport/test correction; root owns source review,
221+
integration, strict checks, original Linux RF3 evidence and commit. No wire/data
222+
migration or public database opening occurs. Rollback disables the new profile;
223+
an unmapped route or undisposed owner cannot be reported as delivered membership.

‎docs/Features/BenchmarkComparisons/ScalingQualification.md‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,10 +81,57 @@ Consumers retain the exact sidecar and authenticate its original artifact/provid
8181

8282
Worker owns feature-local AppHost Contracts/Observation/Processes roles, minimal composition/lifecycle joins, bounded parser/identity/native regressions and scale-only script consumers. Root owns durable feature/ADR freeze, source integration, actual Aspire native Linux/Docker qualification, CI/publication, receipts and commits. Private implementation may rely on the existing 45 engine + 10 Aspire + 25 CI packets as explicit predecessor source, never silently overwrite their bases. A reviewable patch and base/post manifests are required. No checkout edits, gates or Git by the worker.
8383

84+
REQ/AC-SCALE-016's native cgroup-v2 walk must honor the actual hierarchy root:
85+
the kernel defines `cpu.max` and `memory.max` only on non-root cgroups. Walk
86+
every admitted non-root ancestor and retain its minimum effective limits; stop
87+
at the verified real hierarchy root without inventing missing root limit files.
88+
Observe the actual effective cpuset and supported hierarchy/controller identity.
89+
An unreadable, malformed or missing required non-root observation still makes
90+
evidence unqualified; it is never silently replaced by `max`. The independent
91+
native Linux oracle must use the same documented root semantics without copying
92+
the production parser. A supported Linux envelope test must assert its actual
93+
value instead of conditionally omitting a null result. This source correction
94+
changes no sidecar schema, workload, bounds or qualification requirements.
95+
8496
## Accepted prerequisite: Aspire scale forwarding (REQ/AC-SCALE-014)
8597

8698
Introduce only the separate KeyLoadTests:ScaleProfile test-harness selector. TestSuiteSettings accepts one exact canonical scaled ID only for Suite=comparison, the exact /*/*/IsolatedNativeComparisonTests/* filter, present native Benchmarks:Target, matching Benchmarks:EvidenceProfile, disabled Benchmarks:Enabled, no direct Benchmarks:ScaleProfile and no workload overrides. Reject missing suite, other suites, unknown/blank/case-mismatched IDs or mixed modes before any resource creation. Existing direct Benchmarks:ScaleProfile plus a suite remains rejected.
8799

88100
run-workload passes --KeyLoadTests:ScaleProfile=<id> to the outer AppHost. Its owned runner alone receives Benchmarks__ScaleProfile=<id>; clear KeyLoadTests__ScaleProfile alongside KeyLoadTests__Suite so the harness selector does not leak into the nested native AppHost. IsolatedNativeCase reads the exact ordinary ComparisonWorkerSelection from the runner environment and passes --Benchmarks:ScaleProfile=<id> to its own nested resource-owning AppHost. Preserve exact evidence/source/native topology and all control behavior. IsolatedNativeCase uses exactly 140 minutes for the closed scale profile and its existing 60 minutes for controls; all original tasks/resources are still joined.
89101

90102
Worker owns the narrow TestSuiteSettings/TestSuiteResources/IsolatedNativeCase/run-workload joins and real Aspire model plus independent argument/environment regressions. This is a prerequisite repair to the accepted SCALE-014 path, not a new alternate test caller. Durable docs join before live implementation.
103+
104+
## Accepted original teardown settlement (REQ/AC-SCALE-017)
105+
106+
REQ-SCALE-017 requires the actual isolated AppHost owner to settle every original
107+
collector, capture, report-write, application-stop and disposal operation before
108+
releasing its dependencies or deleting its owned data. This applies to controls
109+
and scaled runs; successful workload results and control report schemas are
110+
unchanged. The existing 30-second teardown limit is a recorded failure threshold,
111+
not permission to detach the task with a continuation. After that threshold,
112+
request cancellation or escalation through the original owner's supported API
113+
where available, retain the threshold failure, and ultimately await that same
114+
original task. Do not start a replacement operation, use an uncancellable shadow
115+
task, or dispose an owner while its observation/writer still uses it.
116+
117+
AC-SCALE-017 requires genuine native lifecycle regressions to prove that cleanup
118+
does not pass an unfinished original operation, and that cancellation and failure
119+
paths settle the original process/readers/capture before directory deletion.
120+
Retain the actual workload primary exception and each actual cleanup exception
121+
object, including nested aggregates and original cancellation tokens; do not
122+
flatten, replace them with a category string, or suppress them when a primary
123+
failure exists. Cleanup continues through all safely reachable stages. At final
124+
propagation, one original failure retains its stack, multiple failures retain
125+
ordered primary then cleanup objects, and native ManagedCode fatal classification
126+
remains visible and takes priority. The receipt contains only the existing safe
127+
stage categories and primary-presence flag, never exception text or payloads.
128+
129+
TASK-SCALE-ORIGINAL-TEARDOWN is owned by ComparisonTests BenchmarkComparisons
130+
Helpers (`IsolatedNativeCase`, `IsolatedNativeTeardown` and populated settlement
131+
helpers), with Cases/Helpers for real native regressions. The resource collector
132+
joins from SCALE-016 participate in this same lifetime. Root owns the pre-code
133+
contract, review, Aspire execution, original evidence and commits; partition_pages
134+
owns the private guarded implementation packet. No change to provider topology,
135+
measurement timing, ACK/durability, source provenance or publication eligibility
136+
is authorized. Rollback may revert the repair but cannot claim successful
137+
settlement or qualification for a detached original task.

‎docs/Features/ClusterRouting/NativeCqrsRequestV2.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -820,6 +820,21 @@ extend deadlines or change the parser, artifact schema or success conditions.
820820
The diagnostics owner may expose a read-only lifecycle snapshot of its native
821821
cleanup owner; no alternate collector or inferred task state is permitted.
822822

823+
The existing native cleanup owners must notify this same lifecycle evidence
824+
owner immediately when an actual operation first appends a failure, before the
825+
next resource completion, fallback cancellation, join, retry or disposal changes
826+
the observed state. This includes each of the three resource completions,
827+
bounded capture drain, fallback/capture join, observer and independent-consumer
828+
close/join, and each actual authority cleanup stage. A snapshot taken only after
829+
an entire failing cleanup owner returns is not first-failure evidence. Use an
830+
optional feature-local read-only observation callback and closed cleanup-stage
831+
labels; keep the original tasks, operation order, joins, failures and deadlines.
832+
An observation failure is itself retained and must not prevent safely reachable
833+
native cleanup stages. Do not change the shared ServerFailureObserver, add a
834+
second collector or filter native cancellation. The terminal snapshot remains
835+
after all original joins; actual callback timing and bounded context are part of
836+
the native diagnostics regressions, not proof of the old CI initiating cause.
837+
823838
TASK-CRS-DIAG-FIRST-FAILURE first freezes this contract and ADR-082, then
824839
privately implements bounded feature-local lifecycle helpers and read-only
825840
joins in the existing diagnostics scope, cleanup, subscriber observer,

0 commit comments

Comments
 (0)