You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f3d7feb
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: AGENTS.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -172,6 +172,7 @@ Rule format:
172
172
173
173
## Global Skills
174
174
- Owner direction 2026-10-09 authorizes installing and using [Roslynk](https://github.com/mrpmorris/Roslynk) in this checkout for live semantic navigation, compiler/analyzer diagnostics and reviewed fixes. Pin its published tool version in the repository, configure project-scoped MCP access, and fix confirmed findings without weakening existing diagnostics. Roslynk supplements the canonical formatter, Release solution build, native TUnit/Aspire suites and exact-source Linux qualification; its workspace diagnostics MUST NOT replace those gates. This scoped tool/configuration authorization supersedes historical bootstrap tool-installation restrictions for Roslynk only and does not authorize installing upstream skills or changing global agent configuration.
175
+
- For C# work, open the absolute `KeyLoad.slnx` through Roslynk `open_solution`, wait for `get_solution_status` to report the complete solution Ready, and use its semantic navigation and available reviewed code fixes. After each completed edit stage, run `get_diagnostics` with errors, warnings and analyzers included; resolve confirmed findings and retain load failures as blockers. Preview broad edits with `checkOnly=true`, preserve unrelated source changes, and report unavailable tools or fixes honestly instead of silently treating an incomplete workspace as clean.
175
176
176
177
The owner's 2026-10-06 approval to implement the reviewed native DurableJobs path also authorizes its matching native Journaling API (`ORLEANSEXP005`). Confine that opt-in to the journal provider, native jobs integration and their registration/tests under ADR-110; do not use a global NoWarn or suppress unrelated diagnostics. Journal metadata remains RF3-authoritative and distinct from creator-authorized business effects.
REQ-BACKUP-ROSTER-RESTORE-001 maps to AC-BACKUP-ROSTER-RESTORE-001: restoring an actual replicated materialization into a new incarnation preserves each complete immutable roster entry and admits its first new scoped write, exact original new receipt replay and cold continuation. Historical firstSeen is never reused as current LastApplied, a minimum token or RF3 authority. Old command receipts/tokens remain incarnation-fenced.
63
+
64
+
Freeze before code: a generated native per-partition restore-origin record contains version, complete PartitionRef, actual source/new incarnation, admitted historical applied upper bound and SHA256 of the exact retained native roster bytes. The old four-field entry alias/Ids/bytes remain unchanged. Only a byte-identical historical row can use its bound; a new or changed row without its matching origin must satisfy current applied coordinates. The source restore owner validates existing origin against actual source incarnation/digest before carrying it into another restore; malformed/mismatched origin never falls back. FirstSeen local coordinates stay bounded by the verified source physical position. Replicated source coordinates must fit actual source LastApplied or a valid prior per-row origin.
65
+
66
+
The current staged native restore enumerates one actual roster row at a time and persists one validated historical origin per replicated row using the existing native commit/frame bound, before its original final identity-authority reset/publication. There is no new configured limit or unbounded map. All source/archive bytes stay unchanged; staged failure cannot publish a target. Restored physical position is the original verified cut plus actual historical-origin commits plus the existing reset commit; backups with no replicated roster retain the original single increment. This metadata is historical provenance only, not policy or placement authority. No physical-catalog reconciliation bypass is added.
67
+
68
+
Ownership: shared generated contracts, canonical keys and pure structural/digest match in Abstractions/BackupRestore; original staged restore in Storage.ZoneTree/BackupRestore; Core roster validation/atomic commit; complete native Unit BackupRestore operation flow. Related ADR008/011/046. Root reviews/joins/builds; native normal/scalar and exact-source Linux remain required. Current-format only, no migration or fallback. New public route/SQL/parser/client behavior N/A. Full KL042 catalog manifest/off-node/clean RF3/outbox/graph/RPO/RTO remains OPEN.
69
+
70
+
AC-BACKUP-ROSTER-RESTORE-002 requires actual replicated seed→verified backup→clean restore→first new local and early-new-replication command→full literal state and exact receipt replay→cold reopen→second verified restore; complete immutable roster/archive comparison. Corrupt origin version/scope/source/new identity/bound/digest and changed roster bytes must refuse without effect or physical cut change, then exact original repair yields healthy distinct command. Missing origin cannot admit an old firstSeen above current applied. Supporting native Unit flows do not qualify clean RF3 restoration.
71
+
72
+
This finite native owner regression uses the existing legitimate offline DatabaseEngine composition. Its stored command-outcome incarnation is new, while the archived physical catalog intentionally remains original; it does not prove production RF3 admission or invalidate every old minimum-token placement witness. Physical catalog reconciliation, clean-cluster bootstrap and actual SDK/MCP token fencing remain explicit KL042 gates. Invalid prior origin also rejects a second real restore without target publication or leaked staging; source/archive bytes and cuts stay unchanged, then exact metadata repair and healthy cold operation are required. Generated origin identity/digest metadata is not a MAC, a caller capability, or authority to modify the roster; normal clients cannot write these native families.
73
+
74
+
Each per-row SourceIncarnation must additionally equal the actual source in the native global restore-identity pair persisted by the final authority commit, whose RestoredIncarnation must equal the actual store identity. Prior pairs are checked against the actual recovered source before carry. Missing, mismatched or orphan identities fail closed; a random nonempty source UUID is insufficient. This pair carries no historical upper bound and cannot admit an unbound row. Empty/local-only backups add no origin metadata or extra commits.
75
+
76
+
Ordered stages are verify original artifact/source cut → create unpublished new identity → bounded native roster/prior-origin checks → actual per-row historical metadata commits → one final origin-identity/replica-reset/paused-dispatch commit → publish clean target after owner disposal. Any source/metadata/frame/cleanup failure rejects publication and retains primary plus disposal/staging-cleanup failures. Root alone joins, builds, runs native normal/scalar and source-bound Linux; rollback before publication removes only owned staging. This first-release current-format metadata is not a supported upgrade/downgrade migration or compatibility fallback; older source/runtime artifacts do not qualify it.
77
+
78
+
```mermaid
79
+
flowchart LR
80
+
A[Verified original backup cut] --> B[Unpublished new store identity]
81
+
B --> C[Bounded exact roster and prior origin checks]
82
+
C --> D[Native per-row digest origins]
83
+
D --> E[Atomic new identity pair and paused authority reset]
owns installation, actual MCP interoperability, complete workspace loading,
12
+
located diagnostics, reviewed fixes, rollback and the final verification join.
13
+
Use its native semantic APIs while retaining the selected analyzer catalog,
14
+
EditorConfig and every independent build/format/TUnit/Aspire/Linux gate.
15
+
Upstream advice to replace builds with workspace diagnostics does not apply.
16
+
The tool and disposable loopback workspace own no database execution or storage.
17
+
7
18
Use the owner-selected EditorConfig unchanged, the .NET SDK analyzers at `latest-all`, build-time style checks and warnings-as-errors across every solution project. Keep the eight applicable imported rules, excluding the four whose contracts do not apply to KeyLoad. Own editable Roslyn rules in the central source analyzer project and test them through actual SDK Roslyn compilations with TUnit. Keep compiler SARIF 2.1 reports available for successful and failed builds. Preserve the pinned compiler-host package selection; analyzer tests use SDK Roslyn references rather than a second loader.
8
19
Keep `GenerateDocumentationFile` enabled for the native IDE0005 build diagnostic.
9
20
Missing public documentation remains an error; no imported suppression list is permitted.
Copy file name to clipboardExpand all lines: docs/ADR/ADR-106-partition-owner-movement.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1629,3 +1629,5 @@ This is authored source only. Build, native discovery, Linux normal/scalar RF3 a
1629
1629
R3 source correction for AC-MOVE-PARENT-CLAIMED-DISPOSAL-001: every admitted known NON-retired arm must be present as its exact original bytes in the purpose cleanup snapshot, not only the disposing arm and observed controls. The known-arm set is checked after all actual present records have passed exact byte verification and before any marker publication. Legitimately already-retired absence remains allowed; unfamiliar unclaimed arms remain quota-only and unadmitted. ValidateEntry remains private and is borrowed as the original owner delegate.
1630
1630
1631
1631
Dedicated removal negative matrix remains OPEN: actual owner removal and OTHER known non-retired arm removal must reject disposal before publication; exact original repair must precede genuine original disposal and whole no-effect/healthy/cold continuation. Existing two active malformed-adjunct cases do not cover this matrix. No source/runtime acceptance credit is assigned until the genuine producer/cleanup refusal boundary and complete automated flow are implemented and qualified.
1632
+
1633
+
TASK-KL036-CLAIMED-CLEANUP-STYLE-005 is a source-only style repair to the same owner-bound cleanup aggregate counter from its typed long constant. Preserve all locked inventory, publication, owner and negative/healthy flow semantics, limits and failed original39c02ec6 Linux evidence. Root owns fresh canonical build/format and whole native RF3 qualification; rollback changes only the local declaration.
Copy file name to clipboardExpand all lines: docs/Features/BackupRestore.md
+27Lines changed: 27 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -371,3 +371,30 @@ Independent R2 review tightens the literal healthy continuation oracle: all new
371
371
## TASK-KL098-TOPIC-RETENTION-001 contract join
372
372
373
373
[REQ/AC-EVENT-RETENTION-001–003](EventStreams.md) and [ADR-030](../ADR/ADR-030-retention-paused-restore.md) govern PurgeTopic through existing Batch. SDK CommitAsync, official MCP keyload_documents_commit and SQL CALL keyload_documents_commit use the same typed mutation decoder and fresh authorized request grain; no operation catalog/route/SQL dialect expansion. Canonical mutation schema now includes the explicitly frozen purgeTopic discriminator (26 total) with topic, throughPosition and generation. Current raw backup/snapshot includes bounded native identity tombstones inside existing topic-event-id family without a format migration. Read-cut/restore authority, receipts, paused groups and other models remain unchanged. Existing AcMcp001EveryCanonicalMutationIsRepresentedAndRoundTripsThroughTypedDecoder plus real TopicRetentionRf3Tests and native TopicRetentionOperationTests bind this join; build/runtime/exact-SHA Linux recovery/RF3 qualification remains pending.
REQ-BACKUP-ROSTER-RESTORE-001 maps to AC-BACKUP-ROSTER-RESTORE-001: restoring an actual replicated materialization into a new incarnation preserves each complete immutable roster entry and admits its first new scoped write, exact original new receipt replay and cold continuation. Historical firstSeen is never reused as current LastApplied, a minimum token or RF3 authority. Old command receipts/tokens remain incarnation-fenced.
378
+
379
+
Freeze before code: a generated native per-partition restore-origin record contains version, complete PartitionRef, actual source/new incarnation, admitted historical applied upper bound and SHA256 of the exact retained native roster bytes. The old four-field entry alias/Ids/bytes remain unchanged. Only a byte-identical historical row can use its bound; a new or changed row without its matching origin must satisfy current applied coordinates. The source restore owner validates existing origin against actual source incarnation/digest before carrying it into another restore; malformed/mismatched origin never falls back. FirstSeen local coordinates stay bounded by the verified source physical position. Replicated source coordinates must fit actual source LastApplied or a valid prior per-row origin.
380
+
381
+
The current staged native restore enumerates one actual roster row at a time and persists one validated historical origin per replicated row using the existing native commit/frame bound, before its original final identity-authority reset/publication. There is no new configured limit or unbounded map. All source/archive bytes stay unchanged; staged failure cannot publish a target. Restored physical position is the original verified cut plus actual historical-origin commits plus the existing reset commit; backups with no replicated roster retain the original single increment. This metadata is historical provenance only, not policy or placement authority. No physical-catalog reconciliation bypass is added.
382
+
383
+
Ownership: shared generated contracts, canonical keys and pure structural/digest match in Abstractions/BackupRestore; original staged restore in Storage.ZoneTree/BackupRestore; Core roster validation/atomic commit; complete native Unit BackupRestore operation flow. Related ADR008/011/046. Root reviews/joins/builds; native normal/scalar and exact-source Linux remain required. Current-format only, no migration or fallback. New public route/SQL/parser/client behavior N/A. Full KL042 catalog manifest/off-node/clean RF3/outbox/graph/RPO/RTO remains OPEN.
384
+
385
+
AC-BACKUP-ROSTER-RESTORE-002 requires actual replicated seed→verified backup→clean restore→first new local and early-new-replication command→full literal state and exact receipt replay→cold reopen→second verified restore; complete immutable roster/archive comparison. Corrupt origin version/scope/source/new identity/bound/digest and changed roster bytes must refuse without effect or physical cut change, then exact original repair yields healthy distinct command. Missing origin cannot admit an old firstSeen above current applied. Supporting native Unit flows do not qualify clean RF3 restoration.
386
+
387
+
This finite native owner regression uses the existing legitimate offline DatabaseEngine composition. Its stored command-outcome incarnation is new, while the archived physical catalog intentionally remains original; it does not prove production RF3 admission or invalidate every old minimum-token placement witness. Physical catalog reconciliation, clean-cluster bootstrap and actual SDK/MCP token fencing remain explicit KL042 gates. Invalid prior origin also rejects a second real restore without target publication or leaked staging; source/archive bytes and cuts stay unchanged, then exact metadata repair and healthy cold operation are required. Generated origin identity/digest metadata is not a MAC, a caller capability, or authority to modify the roster; normal clients cannot write these native families.
388
+
389
+
Each per-row SourceIncarnation must additionally equal the actual source in the native global restore-identity pair persisted by the final authority commit, whose RestoredIncarnation must equal the actual store identity. Prior pairs are checked against the actual recovered source before carry. Missing, mismatched or orphan identities fail closed; a random nonempty source UUID is insufficient. This pair carries no historical upper bound and cannot admit an unbound row. Empty/local-only backups add no origin metadata or extra commits.
390
+
391
+
Ordered stages are verify original artifact/source cut → create unpublished new identity → bounded native roster/prior-origin checks → actual per-row historical metadata commits → one final origin-identity/replica-reset/paused-dispatch commit → publish clean target after owner disposal. Any source/metadata/frame/cleanup failure rejects publication and retains primary plus disposal/staging-cleanup failures. Root alone joins, builds, runs native normal/scalar and source-bound Linux; rollback before publication removes only owned staging. This first-release current-format metadata is not a supported upgrade/downgrade migration or compatibility fallback; older source/runtime artifacts do not qualify it.
392
+
393
+
```mermaid
394
+
flowchart LR
395
+
A[Verified original backup cut] --> B[Unpublished new store identity]
396
+
B --> C[Bounded exact roster and prior origin checks]
397
+
C --> D[Native per-row digest origins]
398
+
D --> E[Atomic new identity pair and paused authority reset]
Copy file name to clipboardExpand all lines: docs/Features/ClusterRouting/PartitionTransfer.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1828,3 +1828,5 @@ This is authored source only. Build, native discovery, Linux normal/scalar RF3 a
1828
1828
R3 source correction for AC-MOVE-PARENT-CLAIMED-DISPOSAL-001: every admitted known NON-retired arm must be present as its exact original bytes in the purpose cleanup snapshot, not only the disposing arm and observed controls. The known-arm set is checked after all actual present records have passed exact byte verification and before any marker publication. Legitimately already-retired absence remains allowed; unfamiliar unclaimed arms remain quota-only and unadmitted. ValidateEntry remains private and is borrowed as the original owner delegate.
1829
1829
1830
1830
Dedicated removal negative matrix remains OPEN: actual owner removal and OTHER known non-retired arm removal must reject disposal before publication; exact original repair must precede genuine original disposal and whole no-effect/healthy/cold continuation. Existing two active malformed-adjunct cases do not cover this matrix. No source/runtime acceptance credit is assigned until the genuine producer/cleanup refusal boundary and complete automated flow are implemented and qualified.
1831
+
1832
+
TASK-KL036-CLAIMED-CLEANUP-STYLE-005 preserves the exact claimed cleanup owner, quota, inventory and publication flow under REQ-MOVE-ACTIVE-ADJUNCT-CLEANUP-001 and AC-MOVE-PARENT-CLAIMED-DISPOSAL-001. Original source39c02ec6/run37945550147 failed the unchanged IDE0007 rule at the aggregate-byte local declaration. Use inferred var from the same typed long InitialAggregateBytes constant, without a limit or runtime change. Existing genuine active-invalid adjunct refusal, producer disposal, healthy continuation and RF3 cleanup remain the focused regressions; root owns the repair and fresh original Linux checks. Source repair is not acceptance.
0 commit comments