Skip to content

Commit e8d1a9e

Browse files
committed
Repair native recovery fixtures and retain bounded startup diagnostics
Preserve all current authorized source changes; qualification runs in GitHub Actions.
1 parent 323d604 commit e8d1a9e

13 files changed

Lines changed: 2076 additions & 85 deletions

‎docs/Features/ClusterReplication.md‎

Lines changed: 27 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -57,9 +57,10 @@ each source canonical/replica owner, journal and metadata holder keeps the actua
5757
combined wait pending until released. Existing source snapshot import and private
5858
transfer crash cases remain the primary regression and retain all assertions.
5959

60-
The two permanent-holder elapsed checks retain their five-second lower and
61-
six-second upper observation bounds. Run only those individual wall-clock
62-
measurement cases with TUnit's keyless method-level `NotInParallel`, which the
60+
The two permanent-holder elapsed checks and StorageRecovery's two missing-required-
61+
file arguments retain their five-second lower and six-second upper observation
62+
bounds. Run only those individual wall-clock measurement cases with TUnit's
63+
keyless method-level `NotInParallel`, which the
6364
pinned1.72.10 package documents as exclusive execution. Exact Windows evidence
6465
shows the failed check overlapped74 distinct cases with16 active at peak; timer
6566
or continuation delay is a supported inference, without a threadpool trace.
@@ -69,6 +70,29 @@ This is intrinsic readiness timing qualification, not a loaded-system latency
6970
claim. Source review, native case discovery and full exact-SHA CI must verify
7071
that the same bounds and all original crash cases remain.
7172

73+
TASK-RUNTIME-MAC-FIXTURE-W6 refines AC-REP-004 / AC-STORAGE-012 after
74+
exact323d60499 / CI37044499074. All11 new macOS readiness cases fail during
75+
construction at ReplicaSnapshotFiles.RejectLinks' reparse-point rejection,
76+
before snapshot-data or readiness predicates. The fixture allocates an unresolved
77+
system temp path; macOS temp aliases are the source-supported cause, while the
78+
native report does not expose that run's exact TMPDIR. Reuse CrashHost's existing
79+
ReplicaFixturePaths.NewDirectory for the fresh owned root, as other real replica
80+
fixtures already do. It resolves existing directory ancestors using native .NET
81+
ResolveLinkTarget before the private root is created; production RejectLinks
82+
remains unchanged and fail-closed. Preserve one root, shared incarnation, both
83+
target stores and required source stores, closure order, actual exclusive holders,
84+
waits/assertions and owned cleanup. No second resolver, guard bypass, dependency,
85+
public contract or persistence migration is introduced. The worker owns only
86+
ReplicaFileReadinessStores; root owns contract/diff/evidence integration. All11
87+
formerly red native cases plus original snapshot/tail/process recovery across
88+
three OSes are the regression matrix. AC-REC-FUP-001 requires the existing
89+
physical-temp helper and unchanged fail-closed guard; AC-REC-FUP-002 requires the
90+
same genuine source/target stores, incarnation, holders, assertions and cleanup.
91+
Either criterion fails on setup rejection, changed ownership or leaked work;
92+
all11 native cases and original snapshot/tail cases must pass. ADR035/036/033 cover this preserving private
93+
fixture reuse; rollback reverts only the allocator call. Environmental path or
94+
cleanup failures require source lifetime review rather than a synthetic injector.
95+
7296
## Actors, entry points and failure boundaries
7397

7498
Actors are authenticated SDK/MCP callers, the node-local replica host, fixed voters, the membership provider and the recovery operator. Current source is composed by [ServerApplication](../../src/KeyLoad.Server/Features/ClientApi/ServerApplication.cs): it starts the node-local [PartitionHost](../../src/KeyLoad.Server/Features/StorageRecovery/PartitionHost.cs) and Orleans silo, whose [replica service](../../src/KeyLoad.Orleans/Features/ClusterReplication/PartitionReplicaGrainService.cs) routes peer operations. Aspire declares three Docker nodes with separate data mounts. This source is not yet qualified as a delivered RF3 deployment: current tests do not force request-activation migration and then verify storage ownership and a durable caller-visible outcome. Public HTTP/.NET transport belongs to ClientApi; required official MCP parity is pending. Frontend is N/A because replica consensus has no independent UI. Shared contracts stay in Abstractions and the exact ClusterReplication/StorageRecovery slice owners above.

‎docs/Features/StorageRecovery.md‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,24 @@ either path, then restore the actual store files and prove subsequent reopen
2323
and commit. Missing required ownership/journal files must still fail, and the
2424
existing held-file/cancel/pre-cancel/permanent-lock tests remain intact.
2525

26+
TASK-RUNTIME-WIN-ELAPSED-W6 refines AC-STORAGE-012 using exact323d60499 /
27+
CI37044499074. Both missing-required-file arguments catch the expected exact
28+
FileNotFoundException, then exceed the unchanged six-second observation cap.
29+
They overlap the concurrent native suite; the report does not identify the
30+
precise scheduler delay. Apply method-level keyless TUnit NotInParallel only to
31+
AcStorage012_MissingRequiredOwnershipFileStillFails, preserving both arguments,
32+
five-second lower/six-second upper assertions,25ms polling and no-file-creation
33+
checks. Existing permanent-holder timing isolation and every other case remain.
34+
No helper, timeout, retry or product change is authorized. Root owns accepted
35+
criteria/evidence; the disjoint worker owns only KilledProcessFileReadinessTests.
36+
Both formerly red native cases and full three-OS recovery must pass at the
37+
delivered SHA; source isolation is not proof against external VM preemption.
38+
AC-REC-FUP-003 maps to these two argument cases and requires their unchanged
39+
exact exception/no-create/5s lower/6s upper assertions. A timing failure, broader
40+
serialization or weakened assertion fails this criterion.
41+
ADR035/036/033 lifetime/test contracts suffice; rollback removes only this
42+
attribute, retaining all failure evidence.
43+
2644
The common synchronous probe is internal test infrastructure shared with
2745
ClusterReplication's existing store barrier. That caller retains one
2846
five-second deadline across target stores and, only at typed snapshot/transfer

‎docs/Features/TestInfrastructure.md‎

Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -162,6 +162,63 @@ not claim its unexecuted failure path qualified. ADR-035/036/039 existing
162162
privacy/lifetime contracts suffice; no product/public/dependency boundary changes.
163163
Rollback reverts only this additive diagnostic join and its helpers/tests.
164164

165+
## Accepted comparison-host startup diagnostics
166+
167+
AC-REC-FUP-004 records the preserving W6 fixture follow-up: the exact delivered
168+
SHA, complete GitHub job/report artifacts, native failure identities and report
169+
hashes remain in the runtime ledger. Unit/Recovery/RF3/Comparison must all execute;
170+
failed or unexecuted cases cannot count as green. Local development build,
171+
formatter and governance are source validation only. Full native artifact review
172+
and source lifetime/predicate audit cover environmental branches which cannot be
173+
injected without prohibited service doubles. StorageRecovery owns AC-REC-FUP-003;
174+
ClusterReplication owns AC-REC-FUP-001/002. Existing ADR035/036/033 apply.
175+
176+
REQ-TEST-009 / AC-TEST-009 (TASK-RUNTIME-HOST-DIAGNOSTICS-W5) refines the
177+
private real-process AC-HOST-003/007 fixture after exact8b475d4 /
178+
CI37042082081 repeats four Windows20-second failures. One existing deadline
179+
covers both native exit and redirected-output drain; current failure evidence
180+
does not distinguish them. Source configuration order is not a diagnosis.
181+
182+
Before the existing timeout cleanup, retain only a closed ProcessExit/OutputDrain
183+
stage, actual available exit state/code, closed capture-task states, capped
184+
capture lengths and boolean matches for existing static validation markers.
185+
The receipt is at most8KiB and keeps the original TimeoutException message
186+
prefix. No raw child output, exception text, arguments, environment, paths,
187+
endpoints, credentials or unknown values are logged. Diagnostic observation
188+
failure becomes a fixed unavailable marker and cannot replace the original
189+
startup timeout or caller cancellation.
190+
191+
Each actual StreamReader still uses4096-character reads, retains32768 characters
192+
maximum and drains the remainder. Synchronize partial-buffer observation; retain
193+
the same20-second shared startup deadline and five-second cleanup behavior.
194+
Do not add retries, serialization, sleeps, client/config reorder, product changes
195+
or new detached work. Preserve all four configuration/ordering assertions and
196+
the real cleanup test. Environmental failure/cancellation additionally needs
197+
source lifetime review and the actual GitHub failure receipt; a successful run
198+
does not qualify its unexecuted failure branch.
199+
200+
```mermaid
201+
flowchart LR
202+
Host[Actual CLI child] --> Exit[Native exit wait]
203+
Host --> Capture[Bounded readers drain to EOF]
204+
Exit --> Drain[Capture completion wait]
205+
Exit --> Failure[Existing startup timeout]
206+
Drain --> Failure
207+
Failure --> Receipt[Closed stage and pre-cleanup facts]
208+
Receipt --> Cleanup[Existing owned cleanup]
209+
```
210+
211+
Slice ownership: one worker owns only UnitTests/Features/BenchmarkComparisons/
212+
ComparisonHostProcess.cs and new cohesive capture/diagnostic/test helpers;
213+
root owns shared documentation and integration. New genuine native-shaped
214+
projection/privacy and real-stream prefix/EOF cases map AC-TEST-009.1–003;
215+
the existing real host cases map009.4. Exact delivered-SHA full GitHub
216+
unit/recovery/RF3/comparison plus native receipt review map009.5. All tests
217+
remain TUnit/MTP and CI-only. Existing ADR035/043 private fixture ownership,
218+
privacy and lifetime contracts suffice; no public/data/dependency/deployment
219+
migration is authorized. Rollback reverts only this additive private diagnostic
220+
packet and its source docs; coverage and full goal remain unqualified.
221+
165222
## Platform, dependency та release qualification
166223

167224
B3 keeps the exact task lifetime above while satisfying enabled CA1031: a private

‎docs/implementation/runtime-qualification-20261002.md‎

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,18 @@
11
# Runtime qualification, 2026-10-02
22

3-
## Main runtime baseline: 8b475d4
3+
## Main runtime baseline: 323d60499
4+
5+
[Run37044499074](https://github.com/managedcode/KeyLoad/actions/runs/37044499074) retains all12 source-checked native reports. Full build, formatter, governance and118 analyzer cases pass on all three OSes; units are **805/805 on each OS**. **Native Docker/Aspire RF3 passes41/41**, including real .NET/MCP clients, Chrome and five new safe-diagnostic regressions. Recovery is **136/136 Linux**,125/136 macOS and134/136 Windows. [Exact native hashes, failures, previous-case transitions, job URLs and artifact metadata](runtime-qualification-37044499074.json) retain the complete scope.
6+
7+
Prior checkpoint stages7/8 and Windows target-WAL reopening now pass. All11 new macOS replica-readiness cases fail during fixture construction at ReplicaSnapshotFiles.RejectLinks; two Windows missing-required-file cases exceed the preserved6s observation cap. These remain real failed gates, with fixture path and scheduling review required before a preserving repair. The four prior Windows startup timeouts pass without a demonstrated source-cause repair; the additive startup diagnostic still requires its own delivered-SHA CI.
8+
9+
Both comparison completion predicates still fail with the runner in Waiting; retained smoke/TimeSeries reports are unqualified and measured profiles skipped. Native RF3 success leaves the environmental restart failure branch unexecuted. Numeric coverage, actual activation movement, server-resource costs, endurance and power-loss gates remain open. No local runtime qualification ran.
10+
11+
## W5/W6 source follow-up
12+
13+
[Source join](runtime-source-w5-w6.json) retains all six source hashes, accepted feature/task ownership, native red baseline and authored source chronology. It reuses the existing physical-temp resolver for the macOS readiness fixture, isolates only two Windows intrinsic missing-file timing cases, and adds closed bounded startup exit/drain diagnostics. All25 projects pass an enabled Release development build with0warnings/0errors; canonical formatter and static governance pass. No local runtime tests ran. Four new startup projection/real-stream methods and preserved recovery cases require the next delivered-SHA GitHub run; the full goal remains in progress.
14+
15+
## Previous main runtime baseline: 8b475d4
416

517
[Run37042082081](https://github.com/managedcode/KeyLoad/actions/runs/37042082081) retains all12 source-checked native reports. Full build, formatter, governance and118 analyzer cases pass on each OS. Units are805/805 on Linux/macOS and801/805 on Windows: four real comparison-host startup cases reach their unchanged20-second deadline. Recovery remains119/121 Linux/macOS and118/121 Windows. **Native Docker/Aspire RF3 passes36/36**, including real .NET/MCP SDK calls and Chrome administration. Comparison remains2/4 with measured profiles skipped. [Exact reports, failure identities, job URLs and artifact hashes](runtime-qualification-37042082081.json) are retained.
618

0 commit comments

Comments
 (0)