Skip to content

Commit f5fe42f

Browse files
committed
Preserve document content and integrate scoped partition runtime gates
1 parent 788b8fd commit f5fe42f

154 files changed

Lines changed: 5817 additions & 225 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/AGENTS.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,7 @@
6565
- CI website generation MUST NOT wait for unrelated ordinary CI/RF3 execution from another run. Push/manual CI runs use their own run identity; PR keeps its existing ref-based cancellation. Website qualification and deployment use separate bounded job concurrency groups with cancel-in-progress=false, preserving source/latest-evidence freshness and all gates. This implements the owner-authorized independent website action without canceling database or test work.
6666

6767
## Separate database matrices, 2026-10-04
68-
- Owner correction requires one named job matrix per database in Benchmarks. Each target has its own three checks and thirty canonical node/scenario workloads with readable database/node/scenario names. All nine groups depend only on actual plan/image inputs and run independently without a max-parallel cap; steps within each isolated cell remain sequential. Aggregate joins every group and preserves authenticated failed/null results. This supersedes the shared preflight/CRUD/specialized grouping above without changing native topology, cell isolation, required suites or immutable evidence.
68+
- Owner correction requires one named job matrix per database in Benchmarks. Each target has its own three checks and thirty canonical control node/scenario workloads, plus the ADR-103 thirty-six exact profile-qualified scale cells, with readable database/node/scenario/profile names. Preserve all original control identities and authenticated failed/null publication semantics; scale qualification remains a separate complete-profile admission. All nine groups depend only on actual plan/image inputs and run independently without a max-parallel cap; steps within each isolated cell remain sequential. Aggregate joins every group and preserves authenticated failed/null results. This supersedes the shared preflight/CRUD/specialized grouping above without changing native topology, cell isolation, required suites or immutable evidence.
6969

7070
## Feature-local executable artifacts
7171
- This module uses the root-approved fully colocated executable-artifact convention: keep each feature-owned script, website module or workflow with its canonical feature/artifact and its existing entry point. C# Grains/Models folders are N/A here because this module contains executable web, shell or YAML artifacts. Preserve source-bound historical receipts; update live consumers when solution source paths move.

‎.github/workflows/ci.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ jobs:
6262
matrix:
6363
os: [ubuntu-latest]
6464
runs-on: ${{ matrix.os }}
65-
timeout-minutes: 30
65+
timeout-minutes: 120
6666
steps:
6767
- name: Download source code
6868
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

‎README.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -332,6 +332,14 @@ Discovery exposes static operation documentation. Each invocation checks current
332332

333333
> **KeyLoad is a development preview.** Try it, build with it and [tell us what breaks](https://github.com/managedcode/KeyLoad/issues), but don't trust it with production data yet.
334334
335+
The original 104-task plan has **0 fully accepted, 103 in progress and 1 pending**.
336+
The latest local checkpoint passes the Release build, formatter and governance
337+
checks; its full unit suite passes **3,490 of 3,492 tests**, with two failures
338+
and no skips. The [original Linux source788 run](docs/implementation/runtime-qualification-37349838022.json)
339+
passes the official MCP SDK guidance case but fails the complete RF3 and release
340+
gates. [Checkpoint evidence](docs/implementation/partition-runtime-development-2026-10-05.json)
341+
keeps those failures and the remaining scalar, recovery, RF3 and scale gates explicit.
342+
335343
| Ready to try (in source, covered by tests) | Still in progress |
336344
|---|---|
337345
| Documents, typed rows, graphs, queues, events, time series, blobs and search behind one permission model | Full SQL (joins, foreign keys) and a native SQL client protocol |

‎benchmarks/KeyLoad.BenchmarkScenarios/Features/BenchmarkComparisons/Benchmarks/EmbeddedBenchmarks.cs‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,12 @@ internal void Initialize(PartitionRef partition)
129129
[new(Wildcard, Wildcard, Capability.All)], [Wildcard])
130130
{ ClusterAdministrator = true },
131131
DatabaseEngine.Credential(PrincipalId, PrincipalId, BenchmarkCredential));
132+
var shardId = store.Identity.NodeId;
133+
var catalog = new BootstrapPhysicalShardCatalogRequest(1, 0, shardId, store.Identity.Incarnation,
134+
[shardId.ToString(GuidFormat)]);
135+
Database.Apply(Database.CreateNativeOperation(OperationKind.BootstrapPhysicalShardCatalog,
136+
PhysicalShardCatalogIdentity.CreateBootstrapCommandId(shardId), PrincipalId,
137+
TimeProvider.System.GetUtcNow(), NativeSerialization.Serialize(catalog))).Get<bool>();
132138
Submit(OperationKind.ConfigureResource,
133139
new ConfigureResourceRequest(TenantId, DatabaseId,
134140
new(CollectionId, ResourceKind.Collection, CollectionId)));

‎docs/ADR/ADR-017-migration-tokens.md‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,3 +83,24 @@ Removal or rollback of the test must retain qualification artifacts; product
8383
outcomes/locators retain the compatible forward-reader rollout contract above.
8484
The ADR remains accepted with implementation and all required gates open until
8585
the genuine prior-frame case and complete related source qualification pass.
86+
87+
## Accepted transaction-local witness reuse, 2026-10-05
88+
89+
REQ/AC-MTOKEN-007 fixes the source-review gap where Batch authorization still
90+
compared a literal epoch while receipt and per-effect outbox token creation
91+
repeated placement reads. Root first freezes the feature contract, then joins
92+
CommandAuthorization, AtomicCommandCommit, OperationDispatcher and
93+
AtomicMutationApplication in the existing apply path. Authorization returns only
94+
its validated same-transaction Batch witness; receipt and all outbox effects
95+
reuse one typed token. Other mutation groups resolve one token per group. No
96+
request/transaction cache or public/native format change is introduced.
97+
98+
The genuine document paired-size read counters account for exactly three new
99+
placement point reads, with unchanged single before-image decode and no final
100+
staged image read. Native epoch, same-ID replay, domain-failure, composition,
101+
messaging, recovery and RF3 tests remain required through Aspire. Root retains
102+
original failures, source-bound receipts and actual gate outcomes before stage
103+
delivery. Rollback joins authorization/issuance/outbox callers coherently and
104+
cannot restore an invented epoch or discard scoped outcomes; recover forward if
105+
acknowledged metadata already exists. No movement-created epoch or acceleration
106+
claim follows from source/counter changes alone.

‎docs/ADR/ADR-019-managed-ann.md‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -184,3 +184,21 @@ The source owner is restricted to `PackedAnnCandidateHeaps.cs` and
184184
patches, review, normal/scalar unchanged-corpus observations, strict gates and
185185
qualification. This is an unmeasured repeated-check optimization candidate,
186186
not a deadline diagnosis or speed claim. Rollback restores the five checks.
187+
188+
## Accepted reciprocal insertion invariant, 2026-10-05
189+
190+
REQ/AC-ANN-018 and TASK-ANN-RECIPROCAL-INSERTION in ManagedAnn freeze a narrow
191+
source-proven correction. Ascending private construction inserts a source once
192+
per layer; distinct prior reciprocal targets cannot already contain that new
193+
source at that layer. Remove only the target membership scan and unused helper,
194+
preserving the graph, candidate deduplication, scores, actual distance/edge work,
195+
cancellation, original deadlines and admission. Work counters must report the
196+
comparisons actually performed, without fabricated replacement charges.
197+
198+
The Luna owner supplies the guarded source packet and independent native
199+
adjacency regressions. Root compares complete successful controls, retains
200+
original incomplete Linux normal/scalar observations, and owns the join and
201+
all strict/Aspire gates. A partial failed build cannot prove graph equivalence
202+
or speed. Migration is N/A: R1 remains an internal immutable candidate with no
203+
serialized/public contract; R2/R3 require separate accepted contracts. Rollback
204+
restores only the removed scan and helper.

‎docs/ADR/ADR-039-official-mcp-agent-api.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ then the existing capability/partition grain with a reloaded persisted principal
9191
## Frozen catalog and wire contract
9292

9393
ADR-098 adds its direct and SQL graph-path tools as additive version-one reads;
94-
AC-MCP-001 independently verifies the complete 66-name catalog, typed schemas
94+
AC-MCP-001 independently verifies the current complete 68-name catalog, typed schemas
9595
and effect hints. The two PMAP tools use strict generated request/result schemas:
9696
bind is `{ commandId, request }` with version, expectedRevision, complete
9797
partition and physicalShardId, while read is `{ request }` and returns the full

‎docs/ADR/ADR-047-embedded-benchmark-host.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,15 @@
11
# ADR-047: public embedded benchmark scenarios and typed executable
22

3+
The 2026-10-05 native placement prerequisite preserves REQ-BC-022 / AC-EM-002/003's
4+
real embedded microbenchmark contract: its setup must bootstrap a native physical
5+
catalog using that actual local store's NodeId/Incarnation and one explicit local
6+
voter before the existing ConfigureResource/Batch seed. Use the existing Core
7+
native operation factory and persisted bootstrap command, outside measured
8+
methods, with the same TimeProvider.System clock and owned cleanup. Root owns
9+
the BenchmarkScenarios setup join and real fixture/generated-consumer regressions
10+
through Aspire. This is the existing embedded control, not RF3 or comparison
11+
topology qualification; its three measured methods and inputs remain unchanged.
12+
313
Status: Accepted; implementation and qualification pending.
414
Related: REQ-BC-022, AC-EM-001..004, AC-CQ-007/008, ADR032/033/035.
515

‎docs/ADR/ADR-060-native-internal-serialization.md‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,17 @@
22

33
Status: Accepted. Date:2026-10-03. Owner: serialization integration lead.
44

5+
Accepted2026-10-05 TASK-DSTORE-EXACT-TEXT repairs the existing exact caller-owned
6+
document-string requirement under REQ/AC-DSTORE-008. Root separates validation
7+
from PutDocument text rewriting: the same native canonical writer validates into
8+
a discard sink and the record retains the original validated string. Public
9+
JsonData.Validate output, canonical fingerprint digests, record aliases/field IDs,
10+
and native data epochs remain unchanged. No automatic existing-record rewrite;
11+
patch/redaction retain their derived-text contracts. Run real-store exact-text,
12+
replacement/replay and invalid atomicity regressions, unchanged canonical golden
13+
tests, and actual Aspire RF3 SDK/official MCP Unicode/restart cases before
14+
qualification. This is a repair of the frozen contract, not a new data format.
15+
516
## Decision and contracts
617

718
Implement REQ-IS-001..009 / AC-IS-001..009 using Orleans10.3.1 generated codecs, stable aliases and explicit immutable field IDs across all owned internal concrete DTOs. Use pooled native sessions and raw ReadOnlyMemory<byte> codecs; reject incomplete/trailing/malformed input and validate required semantic fields before effects. Do not use Orleans' optional JSON codec or a runtime JSON fallback. JSON DOM adapters represent structural ordered fields and original numeric lexemes; native DOM materialization is a concrete boundary, not a persisted JSON subtree.
@@ -506,3 +517,10 @@ recovery228/228 passes with unchanged complete source/runtime inventories.
506517
No tolerance, product cache, runtime switch or allocation bound was changed.
507518
This is local development evidence; exact delivered-source Linux and RF3
508519
qualification and comparative performance remain required.
520+
521+
TASK-DSTORE-EXACT-TEXT retains the original literal JSON in the existing native
522+
operation-ownership, restored-record, canonical-retry and embedded-fixture
523+
oracles. Only their obsolete normalized-document expectation changes; all
524+
native authority, corruption, revision, canonical digest and no-second-effect
525+
checks remain. This is the REQ/AC-DSTORE-008 contract already frozen above,
526+
not a change to canonical fingerprint bytes or stored aliases/field IDs.

‎docs/ADR/ADR-068-native-benchmark-gate-repair.md‎

Lines changed: 69 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,8 @@ matches provider/upload proof. Accepting queued as running is forbidden.
8080
Keep bounded attempt-page discovery and all existing source/job/attempt/main/
8181
workflow and existing canonical-or-legacy URL checks. Corroborate only the discovered ID through the
8282
authenticated exact jobs/{id} endpoint. A still-queued same-identity/null-result
83-
record permits at most3 captures separated by1000ms. Any mismatch, terminal/
83+
record originally permitted at most3 captures separated by1000ms; the accepted
84+
G2 cache-window contract below replaces that insufficient refresh bound. Any mismatch, terminal/
8485
unknown state or network/parse failure rejects immediately; final queued state
8586
rejects. Only exact in_progress/null-result authority permits native allocation.
8687
No reselection, workload retry, invented runtime evidence or queued success.
@@ -142,7 +143,8 @@ data migration. This ADR remains Accepted.
142143
isolated-current-job.mjs and the necessary existing isolated-github-api.mjs /
143144
isolated-github-job.mjs joins. Use existing captureApi/requestNative byte,
144145
network, rate and original-child lifetime bounds. NEW private constants fix
145-
captures3/delay1000; no shared GH/transport/workflow changes. Preserve original
146+
captures3/delay1000 was the original G1 contract; G2 below owns the narrow
147+
current-job transport extension. No unrelated GH/workflow changes. Preserve original
146148
pages and every exact request/response under current-job-refresh-NN files;
147149
final job.json and environment ID appear only after strict fresh validation.
148150
Existing validateJobIdentity remains authoritative, including optional attempt
@@ -174,14 +176,78 @@ Kurrent rollout/rollback must be frozen before that stage's implementation.
174176

175177
Source review covers actual transport joining and absence of doubles. First-author
176178
pure policy tests cover stale/valid/wrong-ID/source/attempt/terminal/error records;
177-
Actual source review verifies the fixed three captures, two bounded waits, immediate
179+
Actual source review verifies the accepted G2 capture/deadline bounds, immediate
178180
transport failure and absence of writes before final validation. Pure classifier
179181
tests do not execute refresh exhaustion or authenticate HTTP. Actual GitHub
180182
current-job startup must cover authenticated transport/exhaustion and original
181183
same-ID running proof. Neither source/static checks nor supplied JSON authenticate
182184
the provider. Every worker escalates contract/scope/lifecycle drift. This ADR stays
183185
Accepted until all required implementation and genuine verification exist.
184186

187+
## Accepted G2: native current-job cache revalidation
188+
189+
REQ-NGR-001 / AC-NGR-001 / TASK-NGR-G2 addresses the retained genuine Benchmarks
190+
run37320853130 attempt1 failure before workload setup. Two executing cells received
191+
three exact queued responses with the same ETag and advertised
192+
`Cache-Control: private, max-age=60, s-maxage=60`. These originals support a stale
193+
provider-cache hypothesis; they do not authenticate running state or permit a
194+
failed/null workload substitute. The site correctly rejected the incomplete
195+
producer. Preserve that historical failure and every original capture.
196+
197+
Before code, freeze this ordered contract: first author captured-record/header
198+
policy and actual-caller regressions; then extend only the existing current-job
199+
helper, API/transport joins and native HTTP stream cancellation seam. Send
200+
`Cache-Control: no-cache, max-age=0` only to the authenticated same discovered
201+
`jobs/{id}` route. General metadata/download requests keep their existing header
202+
and rate behavior. Do not add a query cache-buster, choose another job/run/route,
203+
accept queued, drop a required cell or fall back to an older producer.
204+
205+
The initial current-job request retains the existing120,000ms metadata deadline.
206+
After the first exact queued/null-result response, one monotonic60,000ms window
207+
owns all further1,000ms cadence waits, native requests and permitted rate waits;
208+
at most61 captures include the initial request. Each next native timeout is the
209+
minimum of the existing bound and the positive remaining window. Do not start a
210+
request/wait after exhaustion. Rate delays must fit both the existing accumulated
211+
rate budget and the remaining window; otherwise reject. Network, parse, auth,
212+
identity, terminal and unknown-state failures reject immediately at their existing
213+
boundary. Only the unchanged exact in_progress/null-result proof authorizes
214+
job.json/environment-ID finalization and database/timing allocation.
215+
216+
The current-job scope owns one cancellation signal, observes SIGTERM/SIGINT
217+
during polling as well as HTTP, cancels the same original native child, and joins
218+
its exit/readers before releasing files or returning. Preserve the existing
219+
one-second TERM-to-KILL grace and original byte/file/privacy bounds. Abort is not
220+
a successful capture or a replacement request. Timers/listeners are disposed and
221+
original failures remain observable. The60s window bounds admitted work; actual
222+
owned-child termination/join is retained after deadline, never WaitAsync-style
223+
abandonment or timeout-as-settlement. No credential/raw response diagnostic text.
224+
225+
Ownership: root freezes these docs, reviews/joins source, owns Aspire gates,
226+
receipts, commits/pushes and exact-source GitHub evidence. One gpt-6-luna/high
227+
worker owns scripts/Features/BenchmarkComparisons/isolated-current-job.mjs,
228+
isolated-github-api.mjs, isolated-github-transport.mjs and only the necessary
229+
optional-signal join in isolated-github-stream.mjs, plus focused UnitTests
230+
Features/BenchmarkComparisons IsolatedCurrentJob-prefixed cases/helpers. Keep
231+
default callers byte/behavior compatible, fixed closed headers, original
232+
authenticated transport and canonical-or-legacy URL/source/attempt/name checks.
233+
Any required additional boundary is returned for freeze before implementation.
234+
235+
Tests retain captured identical-ETag queued/header sequences and the separate
236+
authentic running record unchanged. No retained artifact currently shows that
237+
same-ID transition. An explicitly constructed pure policy transition fixture
238+
may test queued-to-running control flow, but is not provider/runtime evidence.
239+
Actual same-ID queued-to-running proof remains pending real GitHub startup.
240+
Tests map persistent queued to exact cutoff;
241+
wrong ID/name/SHA/run/attempt/workflow/URL,
242+
terminal/auth/parse states to rejection; cancellation while waiting and in the
243+
real native child to joined cleanup; rate delays to both budgets; and the actual
244+
captureCurrentJob caller to finalization only after strict running proof. Pure
245+
records do not authenticate GitHub or qualify workload success. Local tests run
246+
through the Aspire-owned entry under the root's later local-development
247+
authorization; actual Linux GitHub startup must retain fresh source/job/provider
248+
originals before G2 is qualified. Roll back the helper/optional transport joins and
249+
tests together; no public schema, data, engine, image or website policy migration.
250+
185251
## Accepted Kurrent metadata stage A
186252

187253
The exact pinned1.4.0 DLL (SHA2560f19cb40551bd5b7548ea1ef3afb2e4326d9b2dc05ac4b0eef7baf3ffde816c2)

0 commit comments

Comments
 (0)