Skip to content

Commit f8b3ba6

Browse files
committed
Fix native text lease settlement and RF3 acceptance fixtures
1 parent d3c86d8 commit f8b3ba6

38 files changed

Lines changed: 1496 additions & 222 deletions

‎docs/ADR/ADR-019-managed-ann.md‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,3 +74,16 @@ quality, work/deadline limits and all existing tests remain mandatory. A unique
7474
DotProduct candidate copy may remove redundant membership work with actual
7575
charges and identical selection/ties. Root reviews the private Luna patch and
7676
retains full normal/scalar/Linux evidence before any qualification claim.
77+
78+
The 2026-10-05 [prepared-value refinement](../Features/Search/ManagedAnn.md#accepted-prepared-value-refinement-2026-10-05)
79+
accepts REQ/AC-ANN-010 and TASK-ANN-R1-PREPARED-VALUE. Replace per-candidate
80+
prepared-object allocations only in privately owned packed neighbor work with a
81+
finite-checked-carrier readonly value. One shared helper retains the exact current
82+
metric reduction and untrusted validation remains mandatory. Implement numeric
83+
extraction, private value, consumed diversification/overflow joins and independent
84+
exact-score/allocation regressions in that order. Query worker owns its private
85+
Search implementation packet, cluster worker owns its independent real-store test
86+
packet, and root owns complete review, joins, full checks,
87+
Aspire native/scalar corpus gates and original exact-source evidence. No data,
88+
wire, capability or format migration is introduced; rollback reverts the value
89+
joins. This ADR remains unqualified until its original full acceptance is proven.

‎docs/ADR/ADR-082-native-cqrs-streams.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,17 @@ ANN algorithm work owns disjoint Search files and may proceed in parallel. Root
3434

3535
## Migration, delivery and rollback
3636

37+
The 2026-10-05 TASK-CRS-CANCEL-FAILURE-JOIN prerequisite is frozen in
38+
[NativeCqrsRequestV2](../Features/ClusterRouting/NativeCqrsRequestV2.md),
39+
REQ/AC-CRS-JOIN-001. An owning Communication cancellation-callback failure must
40+
not skip the original native producer join. Source repair and independently
41+
controlled native tests precede canonical patch release, full owning checks,
42+
GitHub publication and verified NuGet availability; root then updates KeyLoad
43+
and qualifies actual Aspire consumer behavior. Source/test workers own disjoint
44+
private Communication scopes; root owns package/docs/delivery/consumer joins.
45+
Original failure identities, fatal priority, stream backpressure and public shape
46+
remain unchanged. No data migration, replacement or consumer workaround is allowed.
47+
3748
C0 changes only test infrastructure; canonical data epoch6, signed request envelope, RPCv1, discovery, HTTP/SDK/MCP responses and RF3 topology remain unchanged. No database migration is needed. The new test-only package is pinned to the current native Orleans family and adds no product dependency.
3849

3950
C1 explicitly versions its RPC shape and homogeneous cold rollout independently of data-format upgrades in NativeCqrsRequestV2. Existing source still lacks application-RPC cohort validation until that implementation is qualified. The accepted peer-envelope/MAC upgrade prevents cross-version replica acknowledgements; separate discovery-MACv2 preserves authenticated observation of old versions. No mixed-node rolling compatibility or runtime legacy fallback is approved. Two compatible surviving RF3 voters remain the required failure topology; a reachable authenticated incompatible voter fails public admission/readiness with a bounded cache-detection delay.

‎docs/Features/ClusterRouting/NativeCqrsRequestV2.md‎

Lines changed: 104 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,110 @@ flowchart LR
2020

2121
## Requirements and acceptance
2222

23+
TASK-CRS-CANCEL-FAILURE-JOIN, accepted 2026-10-05, is an owning-dependency
24+
prerequisite of AC-CRS-004 and the explicit node producer-drain contract. Current
25+
Communication CreateCore awaits CancelAsync before awaiting its real producer;
26+
an actual registered cancellation callback can throw and skip that producer join.
27+
Repair ManagedCode.Communication in its owning repository, never in KeyLoad.
28+
Observe cancellation and then unconditionally await the original producer task,
29+
retaining distinct original cancellation/producer failures without flattening
30+
their identities and preserving the existing fatal-runtime priority. Retain an
31+
iteration cancellation together with a later cleanup failure when both occur;
32+
ordinary cancellation, capacity-one backpressure and native terminal shape stay
33+
unchanged. Cancellation errors cannot become a reason to abandon native work.
34+
35+
REQ-CRS-JOIN-001 / AC-CRS-JOIN-001: a real Create producer with a throwing
36+
registered cancellation callback remains joined by early enumerator disposal;
37+
the disposal cannot complete while that original producer's controlled finally
38+
is still active, and the callback failure is observable afterward. Healthy
39+
subsequent creation, ordinary cancellation and existing fatal-aggregate cases
40+
remain passing. Use real native Create, tokens and controlled tasks; no fake
41+
enumerator or abandoned observation wait. Always release and join original work
42+
in fixture cleanup, preserving observation plus cleanup failures.
43+
44+
Luna lifecycle_wave owns a private source repair to Communication/Cqrs/CqrsStream
45+
and one cohesive cleanup helper; Luna cluster_wave independently owns new owning
46+
CQRS tests. Root owns README, canonical patch10.2.11 over published10.2.10, complete
47+
review, owning build/full TUnit/format checks, scoped commit/push, successful
48+
GitHub release, actual NuGet-feed/package verification and only then KeyLoad's
49+
central package update and Aspire consumer regressions. Both workers read the
50+
owning AGENTS.md and preserve its timestamps, constants, logging and API rules.
51+
No public stream, binary alias/field ID, database format or dependency replacement
52+
is introduced. Rollback retains the previous published package and its explicit
53+
failed-join evidence; no local package or project reference qualifies delivery.
54+
55+
TASK-CRS-C1-PRIOR-CHECKPOINT, accepted 2026-10-05, retains AC-CRS-002 and
56+
ADR-077/091's actual cold native6-to-native7 migration evidence after original
57+
run37242346547. One ten-document command does not produce the required native
58+
replica checkpoint at the default threshold1024. Luna cluster_wave owns a private
59+
patch for RequestCqrsRf3Epoch7Scenario, RequestCqrsRf3Epoch7WaveRunner,
60+
RequestCqrsRf3Wave and a new feature-local RequestCqrsRf3CheckpointSeed helper.
61+
Add an explicitly selected threshold16 only to that scenario's original prior
62+
wave through the existing AppHost KeyLoad:SnapshotThreshold configuration;
63+
ordinary waves and product defaults remain1024. Preserve cancellation-last
64+
signatures and existing native image proof, explicit RF3 membership, readiness,
65+
owned stop/dispose, exclusive lock joins and failure preservation.
66+
After the unchanged ten-document seed and exact SDK/MCP replay, issue at least20
67+
distinct real public SDK commits into a separately configured fixture collection,
68+
with independent stable command IDs and expected revision0. Validate their actual
69+
receipts and records and wait for all three real voters to apply the last receipt
70+
before capturing prior observations and stopping the original wave. Preserve
71+
every original seed document/revision and receipt oracle. Conversion runs only
72+
after owned shutdown and exclusive locks; original non-null snapshot, threshold,
73+
length/hash inventory, topology, byte-identical private profile, mixed-version
74+
rejection, restart, later-write and both-client assertions remain unchanged.
75+
No synthetic hard state, copied snapshot pointer, lowered oracle, shared corpus
76+
expansion, invented prior-image feature or new test authority is allowed. Root
77+
reviews the complete patch and qualifies it through the real Aspire RF3 caller.
78+
79+
TASK-CRS-C1-MCP-REJECTION-EVIDENCE, accepted 2026-10-05, refines
80+
AC-CRS-002/004 after the original follower-restart initialize HTTP400. The
81+
original capped shared-fixture logs did not retain a transport stage for the
82+
separately owned C1 wave. Luna cluster_wave owns a private patch for feature-local
83+
RequestCqrsRf3Diagnostics helpers/pure records, RequestCqrsRf3Wave and
84+
RequestCqrsRf3Epoch7WaveRunner; root joins other C1 wave callers if required.
85+
Subscribe to the actual Aspire wave's ResourceLoggerService before starting its
86+
resources and join every owned subscription before deleting or disposing its
87+
owner. Parse only the existing fixed MCP rejection message into defined
88+
McpTransportStage and McpTransportMethodCategory values; retain at most32 closed
89+
records per actual node, a server-test-derived wave GUID and closed node identity.
90+
Never retain raw log lines, exception text, HTTP headers/body/target, credentials,
91+
private profile or user data in this artifact. Preserve ordinary public MCP
92+
behavior and the official SDK; no branch guess, client fallback or hidden retry.
93+
The diagnostics ownership correction may extract a cohesive WaveStartup helper
94+
inside the same ClusterRouting/Helpers scope to keep existing numeric limits.
95+
Luna query_wave owns that private correction after the source packet is frozen;
96+
root reviews it and runs the integrated warnings-as-errors build. Disposable
97+
ownership must transfer explicitly or settle in unconditional finally, and the
98+
CTS must dispose directly after its original subscriptions join. Preserve every
99+
original failure and stop-before-subscription-before-app-disposal ordering; no
100+
analyzer suppression, relaxed numeric policy or interface-removal bypass.
101+
102+
On an actual C1 failure, retain a uniquely named bounded JSON under the existing
103+
qualification artifact directory, associate its path with the original test
104+
failure, and preserve both original and diagnostic/stop/disposal failures through
105+
ServerFailureObserver. Do not overwrite another wave's receipt. Source/image/run
106+
provenance remains the original verified image proof and TUnit artifacts.
107+
Captured node/wave/stage/category evidence may identify a rejecting check; if
108+
multiple events prevent unique correlation, report that limit rather than
109+
inventing a request correlation or declaring the MCP cause fixed. Verify the
110+
actual follower-restart case through the same Aspire RF3 caller before making a
111+
runtime claim. No public contract, authorization, data or topology change occurs.
112+
113+
REQ-CRS-DIAG-001 / AC-CRS-DIAG-001: feature-local TUnit tests use the actual
114+
Aspire ResourceLoggerService and three ContainerResource identities to publish
115+
the existing fixed transport message and inspect the resulting bounded artifact.
116+
They verify defined stage/category values, distinct wave identity, the32-record
117+
limit per node, and exclusion of oversized, repeated-marker, numeric-enum,
118+
unknown-value and trailing-content lines. Retained JSON contains only the
119+
version, wave, node and closed stage/category fields. Tests join the actual
120+
subscription owner before reading/removing its uniquely owned artifact and
121+
verify repeated disposal observes the same completion. No parser copy, fake
122+
logger stream or weaker test-only parser entry is permitted. Luna lifecycle_wave
123+
owns only a private patch for new ClusterRouting/Cases diagnostics tests and a
124+
cohesive Helpers support file in IntegrationTests; root owns source integration,
125+
the warnings-as-errors build and the real Aspire test caller.
126+
23127
| Requirement | Measurable acceptance | Automated evidence |
24128
|---|---|---|
25129
| REQ-CRS-001: one versioned native stream replaces the request Task RPC | AC-CRS-001: genuine native Orleans calls execute the signed read and command through exactly one independently keyed request grain and the existing capability grains. The new interface/method aliases and generated progress record round-trip with the native Communication converter. The retired request Task method and unused envelope-alias constant are absent; there is no runtime fallback or second dispatcher. | RequestCqrsRoutingTests; real Aspire SDK/MCP RF3 operations |

‎docs/Features/Search/GraphRetrieval.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ SQL, distributed ranking, performance and RF3 qualification requirements.
77

88
TASK-GSEARCH-RF3-RANK-FAILOVER preserves REQ/AC-GSEARCH-003/006 and ADR-090
99
after original run37242346547. Luna cluster_wave owns only a private overlay of
10-
GraphSearchRf3Tests, SqlGraphSearchRf3Tests, GraphSearchRf3LeaderLossTests and
10+
GraphSearchRf3Tests, SqlGraphSearchRf3Assertions, GraphSearchRf3LeaderLossTests and
1111
a feature-local bounded survivor-status helper if needed. Preserve exact corpus,
1212
policy, projected results, expansion, public SDK/official MCP parity and faults.
1313
The independent graph branch sorts shortest hops then full EntityRef and feeds

‎docs/Features/Search/ManagedAnn.md‎

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -196,3 +196,49 @@ current-source patch. Preserve numeric limits and existing tests. Review owned
196196
carrier/uniqueness invariants, run full Release/format/governance and unchanged
197197
Aspire normal/scalar/related recovery/RF3; retain original failures and exact-source
198198
Linux results. No acceleration or qualification claim precedes those results.
199+
200+
## Accepted prepared-value refinement, 2026-10-05
201+
202+
TASK-ANN-R1-PREPARED-VALUE refines the existing owned-score path without changing
203+
its score formulas, work accounting or admission. The current diversification and
204+
reciprocal-overflow loops allocate one PreparedSimilarity object for each examined
205+
candidate. Use a private-constructor readonly PreparedPackedSimilarity value,
206+
created only from an actual finite-checked PackedAnnVectors carrier and ordinal.
207+
Its internal API is Create(PackedAnnVectors, int ordinal, DistanceMetric) and
208+
Score(PackedAnnVectors, int ordinal), returning the exact double similarity.
209+
It retains only that owned query slice, metric and one query norm; no norm array,
210+
new retained vector copy, normalization, approximate formula or public bypass.
211+
212+
REQ-ANN-010 / AC-ANN-010: its scores equal SearchEngine.Similarity exactly in the
213+
same native/scalar invocation mode for all three metrics, zero, subnormal, large
214+
finite values and dimensions1/4096. Invalid ordinal, metric, dimension and
215+
untrusted nonfinite input still fail through the original typed validation.
216+
Mutating input buffers after Copy cannot affect the value. A warmed synchronous
217+
loop of actual packed-value construction and scoring must allocate zero bytes
218+
as measured on that same thread; setup, persisted corpus and assertions remain
219+
outside that interval. This is an allocation oracle, not a latency claim.
220+
221+
Keep one canonical implementation of the existing ordered metric reductions in
222+
a feature-local execution helper consumed by both PreparedSimilarity and the
223+
new packed value. Preserve the exact widen, reduction, tail, zero and square-root
224+
order. PackedAnnNeighborSelection uses the value in diversification and overflow;
225+
the existing budgeted PackedAnnLayerSearch score join charges the identical work
226+
before scoring. Ordinary untrusted search and other prepared-query ownership stay
227+
unchanged. No public DTO, native alias/field ID, canonical record or persisted
228+
index format changes are permitted.
229+
230+
Root freezes this contract and ADR-019, and owns integration and gates. Luna
231+
query_wave owns a private exact-base patch for PreparedSimilarity,
232+
PackedAnnNeighborSelection, PackedAnnLayerSearch and new cohesive Search/Execution
233+
numeric/value helpers only. Luna cluster_wave independently owns new
234+
PackedAnnPreparedValueOracleTests and cohesive feature-local test helpers for the
235+
exact-score, invalid-input, ownership and allocation criteria. Implement
236+
the shared numeric helper, finite-owned value, consumed loop joins, then independent
237+
public-oracle/allocation tests. Preserve every existing test, corpus, deadline,
238+
option, graph order, budget charge and error. Root reviews the complete diff,
239+
builds/formats/governs the full solution and runs Aspire native/scalar metric and
240+
the unchanged ANN corpus/recall/filter/deadline gates before qualification.
241+
Rollback reverts the computational joins; there is no data migration. Public
242+
SDK/MCP/frontend additions are N/A because this internal optimization preserves
243+
their existing exact operation contracts. Comparable GitHub measurements and
244+
remaining ANN projection/public/RF3 acceptance are still mandatory.

‎docs/Features/Search/OnlineGenerationLifetime.md‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -80,6 +80,53 @@ invalidation, unknown-path denial and closed/restart corruption controls through
8080
the actual Aspire caller. This source repair does not qualify L1, L2 or RF3;
8181
full suites and exact-source Linux evidence remain required.
8282

83+
TASK-LEASE-LIVE-SIZE, accepted 2026-10-05, corrects the actual native-text71
84+
failure while preserving REQ/AC-LEASE-001/002/003. The retained manifest describes
85+
the fully closed publication inventory; a manager-owned reopened native WAL may
86+
have a different current length. Live preflight must inspect every tracked native
87+
file without reopening it, reject nonregular/linked files and any current file
88+
over MaximumDiskBytes, and retain the existing per-generation and aggregate
89+
actual-byte census. It must not compare a live file length with its closed
90+
manifest length. Retained manifest scope, records and file metadata must still
91+
match the manager's verified publication. All cold generations, publication,
92+
reopen, retirement, deletion and restart keep exact lengths and checksums.
93+
Luna query_wave owns only a private NativeTextLiveGenerationMetadata correction;
94+
root reviews and joins it before the same original native tests run through
95+
Aspire. No provider, sharing mode, ceiling, deadline or persisted format changes.
96+
97+
TASK-LEASE-COLD-FIXTURE, accepted 2026-10-05, preserves the original native
98+
capacity and retirement oracles. Luna lifecycle_wave owns only a private patch
99+
for NativeTextGenerationCapacityTests and NativeTextGenerationLifetimeTests,
100+
with a feature-local cleanup helper if the numeric policy requires extraction.
101+
Sort the independently created expected generation leaves ordinally before the
102+
existing exact ordered comparison. Every borrowed lease must settle before its
103+
owning projection's shutdown even when an earlier operation fails; retain every
104+
primary and cleanup failure through ServerFailureObserver. The restart fixture
105+
must first preserve its real borrowed retired generation by the existing owned
106+
foreign-file failure, settle that lease, then run and observe failed projection
107+
shutdown so both native indexes are actually closed. Only after closure may it
108+
remove the fixture-owned foreign file, create the third leaf through the
109+
unchanged cold WriteOwner call, and restore that same owned foreign entry.
110+
Restart must still reject the entry before deleting any of the three generations,
111+
preserve every original generation, and succeed after removing only that entry.
112+
Keep the original old-reader, revisions, three-leaf bound, denial, healthy retry
113+
and real provider assertions. Do not pass fabricated live slots into cold calls
114+
or weaken full cold inventory validation. Root runs the unchanged acceptance
115+
suite and captures actual source/runtime and terminal results.
116+
117+
TASK-LEASE-CANCEL-SETTLEMENT, accepted 2026-10-05, addresses the actual Aspire
118+
native-text72b failure in SaturationAndCancellationReleaseNativeLeaseForHealthySearch.
119+
The final aggregate physical census in NativeTextProjection.Release must use the
120+
same completed-operation rule as NativeTextSettlement.Refresh: an incomplete
121+
or cancelled operation settles without consulting its exhausted caller budget,
122+
while retaining all real file, byte and generation ceilings and distinct cleanup
123+
errors. A successfully completed operation retains its existing budget checks.
124+
Luna query_wave owns a private patch to NativeTextProjection.Release only,
125+
unless the unchanged original regression identifies a further owning defect.
126+
Do not suppress cancellation globally, hide physical failures, change deadlines,
127+
or weaken tests. Root reviews the joined change and reruns the original 36-case
128+
native-text selection through the Aspire AppHost; full qualification stays open.
129+
83130
Frontend/new SDK/MCP syntax N/A: unchanged public search surfaces consume this
84131
manager. Migration N/A: no canonical record or persisted index format changes.
85132
Rollback stops the capable node and rebuilds disposable indexes; no canonical

0 commit comments

Comments
 (0)