Skip to content

Commit fa80c70

Browse files
committed
Stop queue overread and retain exact runtime failure evidence
Stop ready traversal at requested delivery count or the 256-record ceiling without visitor mutation. Preserve actual corruption/FIFO/quota/lease semantics. Arm real file cancellation observation and retain client abort/reuse assertions. Add closed MCP rejection stages, bounded per-failure RF3 receipts and independent process recovery CI execution. Merge the delivered website main history without changing its files or the shared checkout/index. Full enabled development build and static checks pass; runtime qualification still requires the next exact-SHA canonical GitHub run.
2 parents ad59464 + 0eb772c commit fa80c70

122 files changed

Lines changed: 12810 additions & 847 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/AGENTS.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,3 +26,14 @@
2626
## ADR-040 site qualification migration
2727
- Existing Node command listings above are the preserved historical baseline. Root TUnit policy controls their replacement with the full independently buildable `tests/KeyLoad.SiteTests` suite in `pages.yml`. Its explicit validation-only mode qualifies candidate website source against downloaded successful-main-CI historical reports and uploads review artifacts without deploying.
2828
- Validation and publication jobs retain least privileges and separate website-source and measured-source revisions. Publication must continue to use qualified measured-source checkout and cannot infer current database qualification from a historical site test. A validation result never authorizes DNS or public deployment.
29+
30+
## Fresh-evidence publication extension
31+
- The owner's subsequent separate post-test deployment request is REQ/AC-BC-028 under ADR-040 and `site-publication.acceptance.md`/`.plan.md`. Preserve every prior policy and measured-source checkout; this new task authorizes the publication workflow after its complete gates. DNS remains excluded.
32+
- `pages.yml` MUST use trusted selection, one complete qualification/build path and a needs-gated deploy-only job. Only deployment receives Pages/OIDC writes. Qualification MUST retain all existing tests, native thresholds, real Chrome, format and governance without skips or fake transport.
33+
- Publish MUST require the highest authenticated own-main-push CI run/current attempt itself successful, exact successful comparison job/steps, one immutable unexpired artifact and verified same-archive bytes; newer unsuccessful work blocks refresh. Recheck the complete tuple immediately before deployment. Historical pinning is validation-only.
34+
- Record actual checkout source separately from triggering/control workflow SHA. Published measurements and report hashes MUST match the downloaded qualified JSON; successful workflow/provider/live evidence is required before claiming publication.
35+
36+
## Owner-directed site-only boundary, 2026-10-02
37+
- The owner's explicit subsequent instruction to finish only the website supersedes the earlier BC028 conservative-B/equal-website-and-measured-SHA task restrictions above. Preserve those records; the current implementation contract is site-publication.acceptance.md and ADR-040. Inspect measured source in a separate sibling checkout; qualify current trusted-main website source independently and record every revision accurately.
38+
- Select the highest successful actual comparison job by main-push run number and descending attempt history, independent of unrelated job or overall workflow conclusion. After selecting success, missing/expired/ambiguous artifacts and invalid reports MUST fail without fallback. Recheck both current website source and the exact evidence tuple before deployment.
39+
- The separate pages.yml MUST trigger on main site/** changes, producer workflow completion and manual dispatch. workflow_run arrives after the enclosing workflow; do not claim an individual-job webhook. Full website qualification and least privileges remain mandatory; database implementation and DNS remain outside this task.

‎.github/workflows/ci.yml‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,15 +44,18 @@ jobs:
4444
with:
4545
global-json-file: global.json
4646
- run: dotnet restore KeyLoad.slnx
47-
- run: dotnet build KeyLoad.slnx --no-restore --configuration Release
47+
- id: build
48+
run: dotnet build KeyLoad.slnx --no-restore --configuration Release
4849
- name: Verify EditorConfig and analyzer fixes
4950
run: dotnet format KeyLoad.slnx --verify-no-changes --no-restore
5051
- name: Verify repository governance
5152
run: node scripts/Features/RepositoryGovernance/verify.mjs
5253
- name: Verify source-owned Roslyn rules
5354
run: dotnet test --project tests/KeyLoad.Analyzers.Tests --no-build --no-restore --configuration Release
5455
- run: dotnet test --project tests/KeyLoad.UnitTests --no-build --no-restore --configuration Release
55-
- run: dotnet test --project tests/KeyLoad.RecoveryTests --no-build --no-restore --configuration Release
56+
- name: Qualify real process recovery after a successful build
57+
if: ${{ !cancelled() && steps.build.outcome == 'success' }}
58+
run: dotnet test --project tests/KeyLoad.RecoveryTests --no-build --no-restore --configuration Release
5659
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
5760
if: always()
5861
with:

‎.github/workflows/pages.yml‎

Lines changed: 217 additions & 115 deletions
Large diffs are not rendered by default.

‎README.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -233,17 +233,17 @@ Tests use TUnit and Microsoft.Testing.Platform and execute in GitHub Actions. De
233233

234234
The root `.editorconfig` is copied directly from Prostir. Every project enables SDK/static/style analysis with warnings as errors. Edit custom rules under `src/KeyLoad.Analyzers/Features/CodeQuality/` and add real-compilation cases under `tests/KeyLoad.Analyzers.Tests/Features/CodeQuality/`. They attach centrally to consumer projects and report in the IDE and build. Compiler SARIF 2.1 reports live under `artifacts/code-quality/<project>/<configuration>/<framework>/diagnostics.sarif`; CI retains them even when the build fails. See [CodeQuality](docs/Features/CodeQuality.md) for the rule catalog, authoring and applicability, and [current evidence](docs/implementation/code-quality.md) for actual gates.
235235

236-
Commit [`3559225a5f918160e46e32c9a812c3f71790e382`](https://github.com/managedcode/KeyLoad/commit/3559225a5f918160e46e32c9a812c3f71790e382) is the shared `main` baseline. Repair checkpoint [`6949fa0c3099443c6f34f91245ab8064ef22c63c`](https://github.com/managedcode/KeyLoad/commit/6949fa0c3099443c6f34f91245ab8064ef22c63c) is on `codex/runtime-qualification-20261002`. Its exact-SHA GitHub run [37005805424](https://github.com/managedcode/KeyLoad/actions/runs/37005805424) passed the full solution build, formatter, governance and 88/88 analyzer regressions on all three OSes. Runtime qualification failed: unit tests passed 719/770 on Ubuntu, 717/770 on macOS and 720/770 on Windows; RF3 passed 6/26 and comparisons 2/4. Recovery and measured comparison profiles did not execute after those failures. Subsequent scoped repairs await another exact-SHA run. The [runtime ledger](docs/implementation/runtime-qualification-20261002.md) retains each failure, job and artifact receipt. Numeric coverage collection and its baseline are still not configured.
236+
The latest completed runtime checkpoint [ad594642b4f1a05ac5df0fff0a33b562f4aebf87](https://github.com/managedcode/KeyLoad/commit/ad594642b4f1a05ac5df0fff0a33b562f4aebf87) is on codex/runtime-qualification-20261002. Its exact GitHub [run37015193756](https://github.com/managedcode/KeyLoad/actions/runs/37015193756) passed full solution build, formatter, governance and88/88 analyzer regressions on all three OSes. Unit results are778/781 Ubuntu,777/781 macOS and779/781 Windows; RF3 is8/26 and comparison2/4. Four distinct unit failures remain. Recovery and later measured comparison profiles did not execute. Subsequent bounded queue, cancellation and safe MCP diagnostic repairs await another exact-SHA run. The [runtime ledger](docs/implementation/runtime-qualification-20261002.md) retains exact jobs, report hashes and artifact receipts. Numeric coverage and server-resource qualification remain unconfigured.
237237

238-
The comparison library/sole CLI host split under [ADR-043](docs/ADR/ADR-043-comparison-library-host.md), immutable harness under [ADR-044](docs/ADR/ADR-044-benchmark-immutable-contracts.md), owned PostgreSQL schema repair under [ADR-045](docs/ADR/ADR-045-postgres-schema-ownership.md), private storage owners under [ADR-046](docs/ADR/ADR-046-storage-private-owners.md) and genuine BenchmarkDotNet library under [ADR-047](docs/ADR/ADR-047-embedded-benchmark-host.md) are source joins awaiting full runtime qualification. The read-only product contract migration preserves JSON/base64 and fingerprints under [ADR-041](docs/ADR/ADR-041-read-only-public-collections.md). Exact-SHA run [37005805424](https://github.com/managedcode/KeyLoad/actions/runs/37005805424) passed all 88 analyzer cases and the enabled solution builds; subsequent repairs require renewed verification. Compatible coverage collection, container export and its numeric baseline remain pending. Historical source stages are retained in the [code-quality record](docs/implementation/code-quality.md); the [runtime ledger](docs/implementation/runtime-qualification-20261002.md) records the latest completed candidate run.
238+
The comparison library/sole CLI host split under [ADR-043](docs/ADR/ADR-043-comparison-library-host.md), immutable harness under [ADR-044](docs/ADR/ADR-044-benchmark-immutable-contracts.md), owned PostgreSQL schema repair under [ADR-045](docs/ADR/ADR-045-postgres-schema-ownership.md), private storage owners under [ADR-046](docs/ADR/ADR-046-storage-private-owners.md) and genuine BenchmarkDotNet library under [ADR-047](docs/ADR/ADR-047-embedded-benchmark-host.md) are source joins awaiting full runtime qualification. The read-only product contract migration preserves JSON/base64 and fingerprints under [ADR-041](docs/ADR/ADR-041-read-only-public-collections.md). Exact-SHA run [37015193756](https://github.com/managedcode/KeyLoad/actions/runs/37015193756) passed all88 analyzer cases and the enabled solution builds; subsequent repairs require renewed verification. Compatible coverage collection, container export and its numeric baseline remain pending. Historical source stages are retained in the [code-quality record](docs/implementation/code-quality.md); the [runtime ledger](docs/implementation/runtime-qualification-20261002.md) records the latest completed candidate run.
239239

240-
Memory and read-work repairs are in progress across storage, SQL/search, events, time series, graph, messaging, replication and transport. The [located repair inventory](docs/implementation/memory-performance.md) records authored changes and remaining proof separately. Earlier baseline CI [36936319423](https://github.com/managedcode/KeyLoad/actions/runs/36936319423) passed on its earlier SHA; candidate CI [37005805424](https://github.com/managedcode/KeyLoad/actions/runs/37005805424) failed and does not qualify system correctness or performance. Portable vector scoring is present; further SIMD validation, software-fallback checks and matched RF3 resource/latency measurements remain open.
240+
Memory and read-work repairs remain in progress across storage, SQL/search, events, time series, graph, messaging, replication and transport. The [repair inventory](docs/implementation/memory-performance.md) distinguishes source changes from proof. [Candidate CI37015193756](https://github.com/managedcode/KeyLoad/actions/runs/37015193756) remains failed and qualifies no system-wide performance gain. Portable vector scoring is present; its five finite/golden/real-store edge cases pass on three OSes. Validation optimization, software-fallback execution and matched RF3 server-resource/latency measurements remain open.
241241

242242
All test qualification and load measurements run in GitHub Actions. The comparison harness uses deterministic JSON, float32 vectors and cyclic graphs, verifies the complete returned payload, and retains every measured attempt, including failures. Reports include useful throughput, p50/p95/p99, separate enqueue/receive/ACK timings and load-generator CPU/allocation/RSS. These resource metrics describe the client process. See the [comparison methodology](docs/implementation/comparative-benchmarks.md).
243243

244244
The [public benchmark lab](https://www.keyload.cloud/) displays verified CI reports with workload, scenario, measure and repetition controls. CI runs a correctness smoke and two measured profiles with 1 KiB/16 KiB documents, eight/four clients and three/five graph hops. GitHub Pages publishes their reports only after the complete CI workflow succeeds; [website operations](docs/implementation/website.md) describes provenance and the custom domain. Current external baselines are single-node and contracts differ; matched-durability, database resource budgets, Marten/Wolverine and scaling qualification remain planned. These development observations do not establish an equal-durability winner or production readiness.
245245

246-
The separate TimeSeries comparison profile is authored under [ADR-050](docs/ADR/ADR-050-timeseries-timescale-comparison.md). Its test is designed to start a digest-pinned, ephemeral TimescaleDB container, send identical UTC samples through KeyLoad's RF3 .NET SDK and TimescaleDB's hypertable, and verify bucket results against the published `ManagedCode.TimeSeries` in-memory aggregation library. The library is not a persistence provider, and the Timescale container has no cross-run data volume; reports label each guarantee separately. Candidate run 37005805424 failed the native image assertion before Timescale startup. The source assertion now preserves Aspire's native repository/digest representation; actual database startup, workload, schema isolation and cleanup still need exact-SHA GitHub qualification.
246+
The separate [TimeSeries profile](docs/ADR/ADR-050-timeseries-timescale-comparison.md) ran a digest-pinned ephemeral TimescaleDB2.30.2-pg18 container, RF3 KeyLoad and published ManagedCode.TimeSeries10.0.0 in-memory aggregation. Its retained report atad594642 records20 successful attempts and20 matching correctness checks across48 identical samples, including range/boundary/offset/empty/invalid handling, buckets and cleanup. The complete Aspire test failed its native runner-completion gate and did not reach the foreign-schema assertion; it remains unqualified. The library has no persistence guarantee and the Timescale container has no cross-run data volume. [Exact receipts](docs/implementation/runtime-qualification-20261002.md) keep those guarantees and partial evidence explicit.
247247

248248
The product website redesign is in progress under [ADR-040](docs/ADR/ADR-040-static-site-threejs-evidence.md): a product introduction, a conceptual Three.js RF3 illustration and the complete evidence workspace. Its independent TUnit site suite runs in GitHub Actions against authentic historical reports. Website source, measured source and raw hashes stay distinct; the preview does not qualify current database changes or publish the pending nine-engine comparison profiles.
249249

0 commit comments

Comments
 (0)