Skip to content

Commit d3c86d8

Browse files
committed
Add bounded native read-cut leases and live index ownership preflight
Checkpoint all current source, tests, contracts and original qualification receipts. Full Release build, formatter and governance pass; 13 native read-cut Aspire development tests pass. NativeText WAL-length and fixture failures remain recorded and under repair; no full acceptance closure is claimed.
1 parent 5fa61f2 commit d3c86d8

42 files changed

Lines changed: 2133 additions & 20 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎docs/ADR/ADR-077-offline-native-data-epoch.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,16 @@ full acceptance instruction. Source and runtime qualification pending. Owner:
55
KeyLoad integration lead. Related REQ-STORAGE-007/021..024, AC-STORAGE-007 and
66
AC-EPOCH-001..006; EventStreams AC-EVENT-008/010, TimeSeries AC-SERIES-013/016.
77

8+
Private RF3 control preflight additionally consumes the existing Storage.IO
9+
regular-file primitive from AppHost under TASK-CRS-C1-APPHOST-REGULAR and
10+
AC-CRS-004 in NativeCqrsRequestV2. Root owns the internal AppHost friend and
11+
project-reference additions. Inspect/OpenWithIdentity binds bounded owner-file
12+
reads to a real regular native handle without following links or blocking on
13+
FIFO payloads. This adds only a trusted pre-start caller; the primitive's ABI,
14+
locking/error contract, database formats, stopped upgrade protocol and required
15+
Linux qualification remain unchanged. Rollback removes the private-control
16+
consumer after owned AppHost resources and readers have joined, never user data.
17+
818
## Problem and supported formats
919

1020
The exact previous executable at

‎docs/Features/ClientApi.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,15 @@
11
# ClientApi
22

3+
TASK-MCP-RF3-CATALOG-INVENTORY preserves REQ/AC-CLIENT-006 and AC-MCP-001.
4+
Luna query_wave owns the private McpCallerProtocol tool-count inventory and
5+
discovery assertions only if the actual current canonical tool names are absent.
6+
Derive the exact count/names from the real server operation catalog, retain
7+
bounded paging, uniqueness, schema and annotation checks, and independently
8+
compare the complete declared catalog. Original run37242346547 observed62 tools
9+
against the obsolete56-count oracle. Do not infer a passing discovery result
10+
from editing that count. Existing ADR-039 remains sufficient; root reviews the
11+
exact diff and runs the official MCP client through the actual Aspire RF3 gate.
12+
313
REQ-SQLC-003 / AC-SQLC-003P preserves AC-MCP-002/003 in the Accepted
414
[ADR-065 public/native oracle stage](../ADR/ADR-065-full-sql-client-compatibility.md).
515
UnitTests ClientApi canonical command/read/polymorphic corpus and NEW

‎docs/Features/ClusterRouting/NativeCqrsRequestV2.md‎

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -292,3 +292,36 @@ The32-arm limit includes every distinct observed, temporarily pending or retired
292292
Implementation order and ownership: cluster_wave Luna/high prepares only new Server/Features/ClusterRouting/RequestCqrsProbe* helpers as a private patch against the reviewed native phase interface; root owns NodeOptions, silo-only DI registration, AppHost validation/mount composition, fixture joins and combined gates. query_wave Luna/high prepares only new IntegrationTests/Features/ClusterRouting/RequestCqrsProbe* control helpers against these exact records; actual fault test entry points are a later bounded join after both helpers are reviewed. lifecycle_wave prepares the failed scalar18 original evidence bundle without source edits. Workers must not change shared files, public contracts, canonical data, credentials, thresholds, packages, tests of another scope, CI or Git state. Return base/post hashes and exact private patches; no shared build/test execution. Root reviews and integrates each bounded stage, runs the real Aspire caller and commits checkpoints with truthful pending RF3/Linux acceptance. Native migration control is excluded from this schema and retains its separately required native idle-migration join.
293293

294294
TASK-CRS-C1-CONTROL-REBASE, accepted 2026-10-05, continues the same frozen control contract after the owner's feature-layout migration. Review the existing private Server, IntegrationTests and AppHost packets before preparing replacements; preserve their verified work rather than duplicating it. Cluster worker owns only Server probe helpers, lifecycle worker now owns only IntegrationTests probe control helpers, and query worker owns only AppHost probe helpers. Place pure models and contracts under the canonical slice Models/Contracts folders and executable responsibilities under their actual feature-local folders. Preserve every schema, quota, permission, native-phase, lifetime, retirement, image and provenance requirement above. The rebased packets remain private until root has reviewed their complete diffs and base/post inventory. Shared options, registration, hosting, fault-test entry points, gates and Git actions remain root-owned; the rebased helper source alone does not qualify a real RF3 fault.
295+
296+
TASK-CRS-C1-CONTROL-UNIT maps the private-control portion of AC-CRS-004 to new
297+
RequestCqrsProbeCodecTests and RequestCqrsProbeRecordFileTests in the ClusterRouting
298+
unit slice. Exercise the actual source-generated private codec with all four
299+
valid kinds, write/read arm exclusivity and every selected phase/action; reject
300+
unknown/duplicate/case-changed fields, integer enums, null/missing values,
301+
invalid IDs/principal bounds, invalid UTF-8, truncated/trailing/nested data and
302+
record byte excess. Exactly8192 bytes of a valid record plus legal whitespace
303+
is accepted,8193 is rejected. File cases use actual owned0600 regular files and
304+
the existing native no-follow file API; linked/nonregular files are rejected
305+
without opening or blocking on their payload. Preserve original fixed safe
306+
errors and controlled private-canary absence from error text. No fake grain,
307+
silo, provider, caller authority, image or GitHub metadata is created. These
308+
mechanism controls prove private metadata/file bounds only; actual native
309+
phase, public privacy, producer settlement and RF3 scenarios remain mandatory.
310+
Cluster worker owns only the new unit Cases/Helpers/Models files as a private
311+
patch against the reviewed Server R4 helper packet. Root integrates dependencies,
312+
executes the actual Aspire caller, preserves originals and commits the stage.
313+
314+
TASK-CRS-C1-APPHOST-REGULAR closes the private owner-file opening portion of
315+
AC-CRS-004 under ADR-077's existing regular-file contract. AppHost preflight
316+
must use the existing OfflineRegularFile.Inspect/OpenWithIdentity primitive for
317+
each owner.json, retaining the inspected native identity through bounded reading.
318+
Reject nonregular/link inputs before payload reading, enforce0600 and1..8192
319+
bytes, read exactly the inspected length and reject any trailing growth. Keep
320+
the fixed safe AppHost configuration error, strict owner schema, private root
321+
and image validations unchanged. No new OS binding, shared-mode workaround,
322+
public endpoint, canonical record or persisted format is introduced. Root owns
323+
the internal AppHost friend/project-reference join and all composition changes.
324+
Query worker revises only its six private AppHost helper files from the reviewed
325+
R2 packet, with original base/post hashes, without checkout writes or gates.
326+
Actual no-follow/FIFO mechanisms and complete Aspire/RF3/Linux gates remain
327+
required; static source repair does not qualify a started topology.

‎docs/Features/Messaging/DueCoordination.md‎

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,32 @@ UTC due arithmetic, caller/creator checks, occurrence identities, queue limits
66
and atomic transitions remain the authority. No separate durable due index or
77
storage-format transition is introduced.
88

9+
TASK-DUE-RF3-AUTH-ORACLES preserves REQ/AC-DUE-002/003/004 and
10+
REQ/AC-JOBS-004/005 after original run37242346547 at5fa61f2. Luna lifecycle_wave
11+
owns a private overlay of DueFaultRf3SeedWriter, DueNoQuorumRf3Run,
12+
RecurringSagaRf3Support, RecurringSchedulePolicyRf3Tests and
13+
DueRecurringRf3Assertions, plus a feature-local pure creator model and identity
14+
writer if required. Root owns these docs, source joins and all gates.
15+
Configure the leader/cold-wave schedule and saga using a real persisted scoped
16+
principal/API key created by the private profile administrator. The administrator
17+
may configure resources and identity; it must not substitute for the retained
18+
schedule/saga creator or receive an authorization bypass. Bind the exact three
19+
queue scopes, required capabilities and actual payload/header policies and
20+
field grants; preserve every canonical identity, deadline, replay and cold/fault
21+
assertion. Keep credentials only in the private owned fixture, never a receipt.
22+
For the no-quorum case, keep the restricted creator for all database work and
23+
use the existing profile administrator only for the restored/survivor Status
24+
topology assertions. Preserve exact leader, voter, caught-up and single-effect
25+
checks. Protected schedule redaction paths are JSON pointers: the independent
26+
oracle is payload:/secret and headers:/secret, with unchanged projected bodies,
27+
ordered paths, cross-client parity and no-disclosure checks. No product change,
28+
new fault, clock, role supplied by a client, corpus/timing reduction or weakened
29+
assertion is authorized. Existing ADR-092/094 remain sufficient; no new wire,
30+
storage, trust boundary or topology is introduced. Implement setup authority,
31+
restricted-work/admin-status separation, then exact projection oracles; review
32+
all base/post hashes before root joins and runs serialized Aspire RF3. Source
33+
and compiler success alone do not close these criteria or the full118-case gate.
34+
935
TASK-DUE-RF3-C adds the genuine no-quorum public recurrence gate for AC-DUE-003.
1036
TASK-DUE-RF3-BUILD preserves AC-DUE-002/003/004 and ADR-094 while making the
1137
existing S1 and S2 Messaging RF3 fixtures compile under the unchanged repository

‎docs/Features/Messaging/RecurringSaga.md‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,22 @@ Root accepts S1 on 2026-10-04 for KL-100 under
55
durable schedules, stable occurrences, saga CAS and atomic timeout messages;
66
general workflow replay or external exactly-once execution is not advertised.
77

8+
TASK-JOBS-RF3-PROJECTED-DELIVERY preserves REQ/AC-JOBS-003/004/005 and
9+
AC-DUE-003 after original run37242346547. Luna query_wave owns only private
10+
SagaTimeoutRf3Assertions and DueSagaRf3Assertions, plus only their two receive
11+
helper callsites in SagaTimeoutRf3Tests and SagaDueRf3Tests to pass the actual
12+
already-owned identity.Secret for the no-disclosure oracle. The existing creator has
13+
protected field use/write grants but lacks read permission; receiving a timeout
14+
must therefore return the independently expected empty payload/header objects,
15+
while retaining exact request/message identity, one delivery, lease metadata,
16+
ACK/replay parity and the empty subsequent receive. Add direct no-disclosure
17+
checks on the official MCP receive reply for the protected payload/header and
18+
credential; preserve all existing projected inspection and one-transition
19+
checks. Do not grant new read authority, weaken field policies, change product
20+
projection or omit the receipt/lease oracle. Existing ADR-092/094 suffice since
21+
this corrects the fixture's contradictory read expectation only. Root reviews,
22+
joins and runs the actual Aspire RF3 clients before recording runtime evidence.
23+
824
## Frozen S1 contracts
925

1026
Generated native v1 records use sequential IDs from0 and feature-owned literal

‎docs/Features/Messaging/RemoteTransfers.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,14 @@
11
# RemoteTransfers within Messaging
22

3+
TASK-XFER-RF3-RECEIPT-VALUE preserves REQ/AC-XFER-002/003/005 after original
4+
run37242346547. Luna query_wave owns only the SDK/official MCP ACK comparison
5+
inside RemoteTransfersRf3Tests. Compare every field of both independently
6+
deserialized public receipts using the existing canonical public JSON serializer;
7+
ImmutableArray backing-array identity is not receipt-value equality. Preserve
8+
command IDs, mutation count/content, token, exact duplicate replay, target ACK
9+
and empty-receive checks. No production, public wire or native format change;
10+
existing ADRs suffice. Root owns integration and actual Aspire RF3 verification.
11+
312
Root accepts the KL-094 implementation contract on 2026-10-04.
413
Decision: [ADR-088](../../ADR/ADR-088-remote-queue-transfers.md).
514
Scope is durable queue-to-queue outputs within one tenant/database and the same

‎docs/Features/Search/GraphRetrieval.md‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,29 @@ the same-partition exact branch of KL-056. [ADR-090](../../ADR/ADR-090-graph-sea
55
implements architecture sections26.2–26.4. This contract retains the original
66
SQL, distributed ranking, performance and RF3 qualification requirements.
77

8+
TASK-GSEARCH-RF3-RANK-FAILOVER preserves REQ/AC-GSEARCH-003/006 and ADR-090
9+
after original run37242346547. Luna cluster_wave owns only a private overlay of
10+
GraphSearchRf3Tests, SqlGraphSearchRf3Tests, GraphSearchRf3LeaderLossTests and
11+
a feature-local bounded survivor-status helper if needed. Preserve exact corpus,
12+
policy, projected results, expansion, public SDK/official MCP parity and faults.
13+
The independent graph branch sorts shortest hops then full EntityRef and feeds
14+
one-based ordinal ranks to weightedRrfV1. Equal-hop alpha and beta therefore
15+
contribute1/(60+1) and1/(60+2); adding one-hop delta precedes two-hop gamma,
16+
giving ranks3 and4. Do not use hop distance as the final fused ordinal rank.
17+
Derive the SQL fixture's complete expected order from its declared corpus, never
18+
from production ranking output. Before the single post-leader-loss mutation,
19+
use both real surviving administrator SDK Status calls under the existing finite
20+
eventual-observation contract to witness a successful current quorum, compatible
21+
RF3 routing and an agreeing non-null survivor leader. Keep the continuously
22+
running voter identities and existing scoped kill/restart/catch-up assertions.
23+
This witness is test ordering, not a product retry or an authorization repair:
24+
original report says OwnershipLost and does not establish its root cause.
25+
Issue one unchanged mutation/command only after the witness; never turn an
26+
uncertain outcome into a new-ID retry or swallow the actual write error.
27+
Root owns joins, verification and the exact original evidence. Existing ADR-090
28+
and cluster fault contract suffice; no new public/data/topology contract.
29+
Private review and compiler success cannot close the required real RF3 gate.
30+
831
## Versioned public contract
932

1033
G1 adds an explicit `GraphSearchRequest` and `GraphSearchResult`; it does not

‎docs/Features/Search/OnlineGenerationLifetime.md‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,36 @@ replacement task. Any observation deadline cancels that source, resumes its
5050
actual posting barrier and joins the original task before disposing the lease
5151
or projection; a second timeout-abandoned wait is not cleanup evidence.
5252

53+
TASK-LEASE-LIVE-PREFLIGHT, accepted 2026-10-05, refines AC-LEASE-001/002/003
54+
after the actual unfiltered Aspire unit61b failure. Capacity preflight currently
55+
hash-opens the existing published WAL while its native index still owns that
56+
file; replacement therefore fails before reaching its posting barrier. Inside
57+
the existing physical gate, capture only the manager's at-most-three actual
58+
generation references. An exact manager-owned, published generation with a
59+
still-open native index receives a bounded live ownership/layout/size preflight
60+
without reopening native payload files. Verify its root, leaf, source-node and
61+
scope against the retained verified generation and owner/manifest metadata;
62+
reject unknown, linked, nonregular or foreign paths and retain all file, depth,
63+
generation and aggregate-byte ceilings. Runtime generation references cannot
64+
be supplied by a caller, inferred from a sharing exception, or substituted with
65+
an arbitrary trusted-leaf list. Every other generation keeps the complete
66+
existing checksum validation. Closed publication, reopen, retirement, deletion
67+
and restart retain full inventory checks; no format or provider sharing mode
68+
changes. Native mutation/census ownership remains in the physical gate, while
69+
manager admission is never held across callbacks or awaited work.
70+
71+
Query worker owns only a private patch for the consumed NativeTextProjectionLifecycle,
72+
NativeTextFiles/NativeTextGenerationFiles capacity join and feature-local live
73+
preflight helpers, plus the real Search overlap regressions. Root reviews the
74+
exact live-object provenance and every cold validation call before applying it.
75+
Keep the existing corpora, deadlines, byte/file limits, native provider and
76+
old-reader/result assertions. Cleanup resumes the actual barrier even if old
77+
lease disposal fails, cancels and joins the original replacement task, then
78+
reports every distinct failure. Exercise real published-reader replacement,
79+
invalidation, unknown-path denial and closed/restart corruption controls through
80+
the actual Aspire caller. This source repair does not qualify L1, L2 or RF3;
81+
full suites and exact-source Linux evidence remain required.
82+
5383
Frontend/new SDK/MCP syntax N/A: unchanged public search surfaces consume this
5484
manager. Migration N/A: no canonical record or persisted index format changes.
5585
Rollback stops the capable node and rebuilds disposable indexes; no canonical

‎docs/Features/StorageRecovery/NativeReadCuts.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,15 @@ An elapsed-budget error reported after successful cleanup must not retain a
3737
closed handle. Scalar cut construction precedes native iterator creation, so a
3838
failed allocation cannot lose an iterator created just before attachment.
3939

40+
TASK-CUT-ELAPSED-IDENTITY preserves AC-CUT-002/003 after the original Aspire
41+
read-cut69 run (12/13 passed). An elapsed limit is one lease-lifetime failure;
42+
observing that same expired limit during traversal and joined disposal must
43+
retain the same exception identity instead of manufacturing two independent
44+
failures. Independent native, callback and cleanup failures remain separate.
45+
Root owns the minimal Work helper repair and the unchanged idle-expiry test;
46+
the required oracle remains exactly BudgetExceeded, released admission and a
47+
healthy following real native lease. No timeout, bound or assertion is weakened.
48+
4049
TASK-CUT-R2-FAILURE-JOIN refines AC-CUT-003 before joining the private L2-A
4150
packet. Luna query_wave owns only read-cut Lifecycle cleanup/disposal and new
4251
StorageRecovery test helpers/cases in its private overlay. A synchronous cleanup

0 commit comments

Comments
 (0)