Skip to content

Commit fdc3128

Browse files
committed
Complete RF3 replay and authorization flows and expose original failure diagnostics
1 parent e47803e commit fdc3128

14 files changed

Lines changed: 335 additions & 14 deletions

File tree

‎.github/workflows/build-and-tests.yml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -255,7 +255,21 @@ jobs:
255255
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
256256
"KEYLOAD_PRODUCT_COVERAGE_SOURCE_MANIFEST=$evidence/functional-coverage.production-source-manifest.json" | Add-Content $env:GITHUB_ENV
257257
- name: Test three-node database with .NET and MCP clients
258+
id: rf3-required
258259
run: node scripts/Features/TestInfrastructure/run-tests.mjs --KeyLoadTests:Suite=rf3 --KeyLoadTests:ResultsDirectory=TestResults/rf3-required --KeyLoadTests:ReportTrx=true
260+
- name: Check original three-node reports for diagnostic upload
261+
id: rf3-original-reports
262+
if: ${{ !cancelled() && (steps.rf3-required.outcome == 'success' || steps.rf3-required.outcome == 'failure') }}
263+
run: rg --files --no-ignore TestResults/rf3-required -g '*.trx'
264+
- name: Save original three-node diagnostics before covered suites
265+
if: ${{ !cancelled() && steps.rf3-original-reports.outcome == 'success' }}
266+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
267+
with:
268+
name: docker-rf3-original-diagnostics
269+
path: |
270+
TestResults/rf3-required/**
271+
TestResults/functional-coverage/rf3/**
272+
if-no-files-found: error
259273
- name: Reconcile original native full and five-group discovery in both modes
260274
id: native-census
261275
if: ${{ !cancelled() && steps.coverage-source.outcome == 'success' }}

‎docs/ADR/ADR-017-ownership-session-tokens.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -248,3 +248,10 @@ REQ/AC-MTOKEN-ISOLATION-003/004/005 retain strict native namespace admission and
248248
Ordered contract: require actual owned AppHost stop success; invoke existing VerifyNodesStoppedAsync for every exact admitted model name, using recorded full IDs where available and its existing exact-name/unique-full-ID/stopped-state checks for unobserved nodes. Any running, ambiguous, substituted observed ID or native Docker failure retains primary/cleanup/root/image ownership and fails. Only after all namespaces settle, acquire all9 actual native locks (3node owners plus3canonical/3replica owner.lock files); only then run unchanged actual derived-image/base/layer/source proof, no-referencing-container check, tag removal and remaining-tag verification. Capture original retirement/mutation evidence and original cleanup failures. Incomplete admission alone does not establish unsettled resources; actual native stopped and lock proofs do. No weakened namespace, lock, image, deadline, resource, exception or assertion contract is introduced.
249249

250250
IntegrationTests ClusterReplication Lifecycle/ReplicaIsolationOwner.cs owns partial-start shutdown admission; Lifecycle/ReplicaIsolationRetirement.cs owns exact physical locks. Cases/ReplicaIsolationNativeRetirementTests.cs and Fixtures/ReplicaIsolationNativeRetirementFixture.cs exercise real native3node lock files and6ZoneTree stores: committed literal rows, all9-held-lock retirement rejection without FileNotFound, actual owner disposal, all9exclusive canonical lock proofs, unchanged literal rows/positions after native reopen and joined private-root cleanup. This is supporting native storage/lifecycle regression, without claiming Docker RF3 or functional product-contributor coverage. The existing full genuine Kl021 SDK/officialMCP isolation/restoration/retirement flow remains mandatory exact-source Linux proof; source and original failure are not passing runtime evidence. Root owns docs-first guarded join, build/format, native TUnit and required Linux RF3 qualification. Rollback restores both cleanup corrections together; original primary errors remain visible.
251+
252+
253+
### KL021 persisted grant denial across session-read adapters
254+
255+
Related REQ/AC-SESSIONREAD-001..004. The existing IntegrationTests ClusterReplication DocumentSessionReadRf3Authorization owns a complete grant revoke→valid-minimum rejection→administrator unchanged document→grant restore→healthy continuation through direct SDK, official MCP and Q1 CALL. Denied SDK typed reads carry no value; denied SQL SDK reads carry no JSON value; actual official errors retain dispatched request identity, safe envelope and private-data omission. Full administrator document equals the independent literal reference/revision/JSON/unredacted/empty-redactions model.
256+
257+
Stages: canonical ClusterReplication contract and this amendment; private guarded assertion-only delta; root source join and native build; unchanged fixture-owned failover case and delivered-source Linux RF3 original evidence. Dependencies, routing, authorization, token validation, storage format, admission and lifecycle unchanged. Root owns shared integration/compiler/Git, author owns complete adapter oracle. No data migration; rollback this coherent assertion-only delta. Original failures remain preserved and acceptance remains open until required runtime reports.

‎docs/ADR/ADR-035-memory-performance.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -107,3 +107,13 @@ Ordered stages: freeze ClientApi requirement/test map and this amendment; update
107107
REQ-CLIENT-002/005 and AC-MP-009/AC-CLIENT-005: retain original R792 eight native failures. Complete independently literal HTTP request/Status values must compare using existing strict public JSON bytes, not internal Orleans reference-graph bytes. Exact pinned native StringCodec records/tracks reference identity; authored repeated strings and JSON-decoded equal strings can therefore have different native encodings without a wire-value change. Change only those two complete comparisons in UnitTests Features/ClientApi KeyLoadClientNullReadTests/NullWriteTests, preserving native fullreceipt/document comparisons, all null/unknown/ID/body/header/healthy/cleanup assertions and required supporting-control classification. No graph-shaping fixtures, product serializer, dependency, schema, public API or migration changes.
108108

109109
Stages: source/exactoriginal failure review → docs/this amendment → private guarded minimal two-case repair → root joins/focused native Unit rebuild → actual normal/scalar fourcase runs with originals and immutable source/assembly binding → final complete solution build, census/PE/PDB source binding and current Linux whole-task gates. Root sole source/compiler/formatter/Git owner; author owns source/failure review and native runs on explicit grant. Rollback coherent source only; original failures immutable. No acceptance/coverage/production claim from this repair.
110+
111+
112+
### KL014 interrupted RF3 stable replay continuation
113+
114+
REQ-CLIENT-005 / AC-CLIENT-005 retains the four existing ClusterRouting RequestCqrsPhaseFaultTests and their actual SDK/official MCP fault observations. Ordered stage: freeze the ClientApi complete retry/conflict/healthy continuation contract; extend Assertions/RequestCqrsFaultReceiptOracle and add Assertions/RequestCqrsFaultReplayContinuation; guarded root join and native compilation; execute the same four bounded Aspire-owned RF3 cases; retain current Linux original reports and source/image binding. Both client paths compare full literal public DocumentResult JSON and full original receipt JSON, reject changed-content original IDs, and prove that replay after a fresh-ID healthy write cannot revert the document. Persisted principal, deadline, original fault markers, retirement, resource admission and joined cleanup remain owned by the unchanged scenario.
115+
116+
Dependencies, public API, storage format and deployment unchanged; no migration. Root exclusively owns source/compiler/Git joins and author owns guarded assertions and exact originals. Rollback removes this coherent assertion-only delta without modifying data. Original failures remain immutable; implementation and qualification status remain separate.
117+
118+
119+
KL014 receipt-owner follow-on freezes native administrator placement/status witnesses around the healthy fresh-ID command, complete independent expected receipt and bounded monotone same-owner position under REQ-CLIENT-005 / AC-CLIENT-005. Existing scenario passes its already owned administrator into the receipt oracle; no new credentials, resources, requests bypassing native clients or lifecycle owners. DocumentSession SDK Get and official GetDocumentRequest validate the actual healthy token against complete literal document after commit. Ordered guards apply only after the sealed R1 fullflow packet, then root build and actual current Linux fourcase execution; source-only, rollback assertion delta only.

‎docs/ADR/ADR-117-native-tunit-ci-entry.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,3 +24,7 @@ passes arguments only; the TUnit case removes the recursive runner, executes the
2424
existing Aspire image prerequisite, passes typed identity without environment
2525
mutation, and joins final exact-tag cleanup after the actual six-silo wave. Root
2626
freezes/joins; Luna prepares guarded source. Implementation and runtime pending.
27+
28+
TASK-TUNIT-EARLY-RF3-DIAGNOSTICS-008 implements REQ/AC-TUNIT-ENTRY-008 from NativeTUnitEntry. The original ordinary RF3 test step has a stable `rf3-required` identity. After its native process and fixture cleanup return with success or failure, a native `rg --files --no-ignore` report-presence check requires the original TRX; missing reports fail that check before upload. The existing pinned artifact action uploads unchanged `TestResults/rf3-required/**` plus the original prepared source/image receipts to a separately named `docker-rf3-original-diagnostics` artifact before covered discovery/execution starts. Root owns docs-first workflow integration and actual GitHub provenance verification; agents may diagnose their real failed cases from that authenticated original archive.
29+
30+
The diagnostic archive does not replace or admit the final `docker-rf3-qualification` artifact. Existing full suites, collector ownership, final source/image verification, descriptor/product admission, thresholds, deadlines, outcome/cleanup behavior and permissions remain unchanged. No report transformation, extra test runner or synthesized status is introduced. Rollout is the next normal workflow source revision; rollback removes only the diagnostic upload. Native workflow/source syntax review and original successful upload with exact API/archive digest verification are required evidence. Status remains Accepted with current Linux verification pending.

‎docs/Features/Authorization.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,3 +113,8 @@ REQ-AUTH-KL015-002 / AC-AUTH-KL015-002: actual ASP.NET/HTTP-client spans and Ope
113113
AC-AUTH-KL015-002 permits only ADR-121's closed native HTTP connection context link shape. Native span IDs and complete safe link fields must match the preprivacy observation; events, tagged/state-bearing/extra links and unsafe ancestry still suppress the original span. Normal and scalar actual HTTP fullflows plus Linux RF3 remain required.
114114

115115
Local REQ/AC-AUTH-KL015-002 export evidence: R785 coherent Release build green, actual native normal and scalar three-class focus each 12/12 PASS with native exit 0 and source/assembly drift zero. [ADR-121](../ADR/ADR-121-exported-telemetry-privacy.md#local-development-verification-2026-10-08) records exact scope and original report lineage. Current Linux run 37821315110 attempt 1 on exact source 3458f611 has authenticated original normal/scalar TRX with all 12 telemetry cases passed in each mode, native source/image receipts retained and after-suite identity verification successful; ADR-121 records artifact/TRX hashes. Complete unit suites each retain 19 other failures. Current exact-source Linux RF3 cross-tenant, bounded-input/query and C1 held-write/guard acceptance remain open; neither export gate marks KL-015 done or establishes full-suite/production/endurance qualification.
116+
117+
118+
TASK-AUTH-KL015-COMPLETE-DENIAL-RESULT-001 refines REQ/AC-AUTH-KL015-001 under unchanged ADR-002/022/039: each actual SDK foreign-tenant GET, full scan, indexed predicate, original write/replay and changed-content denied write must have no result payload, exact PermissionDenied/safe scope detail, and a complete serialized native result containing none of the persisted credential or document/conflict/healthy canaries. Checking only Problem cannot prove that a failed result carries no payload or leaked metadata. The existing official MCP complete-result privacy, literal foreign/owned document and real index invariance, healthy exact receipt replay and Conflict/no second effect remain mandatory in the same RF3 wholeflow.
119+
120+
Ownership is the existing Authorization CrossTenantRf3ErrorAssertions helper and Kl015ForeignWritesScansAndIndexesAreDeniedAndAuthorizedReceiptRemainsStable case; no transport, provider, wire, storage, role, admission or timeout change is introduced. Current API payloads are reference-record DocumentResult, QueryPage and CommitReceipt; the helper's nullable reference constraint also accepts the actual Result<DocumentResult?> returned by GetAsync while requiring every denial value to be null. Root joins guarded source and runs the coherent native checks; exact-source Linux RF3 original TRX, source/image receipts and API artifact digest remain required. This stronger oracle is authored evidence until executed and does not mark KL-015 done.

‎docs/Features/ClientApi.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -722,3 +722,13 @@ KeyLoadClientNullReadTests executes every one of the nine actual SDK nullable ca
722722
REQ-CLIENT-002/005 / AC-MP-009 / AC-CLIENT-005 retains original R792 four normal and four scalar failures. Every null/malformed classification and nine nullable-site assertion reached its expected relation; two read cases failed only complete native Status comparison, and two write cases failed only complete captured-request comparison after successful full native receipt equality. They remain failed cases. Independently authored NodeStatus shares the same literal Node string in NodeId/Leader; PutDocument(Collection) inherits Mutation(Collection), sharing Collection/Resource. Exact pinned Orleans10.4.0 StringCodec/ReferenceCodec tracks CLR object references, whereas HTTP JSON carries value fields without that graph identity. No assertion of canonical semantic native bytes is made.
723723

724724
Repair only those two complete transport comparisons to strict typed public JSON bytes against the original independently literal fixtures, retaining all fields and every other assertion: exact unknown/read failures, full original stable body/header/ID retry, native fullreceipt parity, legal absent reads, native fulldocument continuation and joined cleanup. Do not manufacture distinct expected strings or alter product/native serializers. These four cases are required supporting real Kestrel transport controls, not functional database coverage contributors. Actual native normal/scalar reproduction and fresh complete build/census/source+PE/PDB binding remain required. Current committed3458 Linux RF3 bootstrap/SDKofficialMCP stable replay remains separate from the new dirty SDK image.
725+
726+
727+
### KL014 interrupted RF3 retry complete continuation
728+
729+
REQ-CLIENT-005 / AC-CLIENT-005: the existing four RequestCqrsPhaseFaultTests must continue from their actual BeforeSubmit/SubmitReturned SDK or official MCP interruption into identical-command retry, complete SDK/MCP receipt parity and a complete independently literal DocumentResult. The same persisted nonadministrator then submits changed content with the original ID through both real clients: exact Conflict, safe fixed detail, no SDK value and unchanged full document. Both clients replay the original full receipt after rejection. A fresh ID commits the changed content once, both callers observe the complete document at the next revision, and another original-ID replay must return the original receipt without reverting the later document. This is one bounded native fixture-owned RF3 flow, preserving actual cancellation, settled producer authority, original diagnostics, retirement and joined cleanup.
730+
731+
Ownership: IntegrationTests ClusterRouting Assertions existing receipt oracle plus feature-local replay continuation; product/server/schema/storage/transport changes N/A. ADR-035 extends only acceptance oracles under existing contracts. Private guarded docs-first source review precedes root join/build; the four actual native cases and authentic current Linux RF3 originals are mandatory. No code-present, local build, old-source or running-job acceptance claim.
732+
733+
734+
KL014 interrupted replay owner-oracle follow-on: the healthy complete receipt is independently constructed from the caller-issued fresh command ID, real administrator placement witness (incarnation, exact atomic partition, current ownership epoch), literal putDocument mutation and QuorumProcessDurable. Its observed position must strictly exceed both original receipt and precommand same-owner Applied, and not exceed postcommand same-owner Applied; no exact position reservation is claimed. SDK/official MCP minimum-token reads with that actual healthy token must each equal the complete literal healthy document. Existing complete receipt parity, post-conflict original replay and post-healthy original replay/no-revert assertions remain unchanged. The existing administrator is passed only for authenticated native placement/status observations; the database effects retain the original persisted nonadministrator.

0 commit comments

Comments
 (0)