Skip to content

Commit fe8e813

Browse files
committed
Add bounded follower reads and parallel task acceptance
Integrate explicit follower document reads, RF3 lifecycle and authority regressions, genuine issued-grant expiry coverage, native TUnit default20 and six isolated task/profile CI cells. Retain original source/report admission and all full qualification gates. Validation: complete Release build and native formatter passed; related88 whole-operation cases passed at20 and50, with actual20 original TRX overlap. Exact3114 native census and60 task expectations bind. Current-source Linux RF3 and product coverage remain unqualified.
1 parent fdc3128 commit fe8e813

104 files changed

Lines changed: 4384 additions & 290 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/build-and-tests.yml‎

Lines changed: 90 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,12 @@ on:
44
branches: [main]
55
pull_request:
66
workflow_dispatch:
7+
inputs:
8+
task:
9+
description: 'Acceptance task; all runs complete qualification and all task lanes'
10+
type: choice
11+
default: all
12+
options: [all, KL-011, KL-014, KL-015]
713
permissions:
814
contents: read
915
concurrency:
@@ -21,6 +27,7 @@ jobs:
2127
run: node scripts/Features/RepositoryGovernance/verify.mjs
2228
analyzer-rules:
2329
name: Test code analyzers
30+
if: ${{ github.event_name != 'workflow_dispatch' || inputs.task == 'all' }}
2431
runs-on: ubuntu-latest
2532
timeout-minutes: 10
2633
steps:
@@ -95,6 +102,7 @@ jobs:
95102
if-no-files-found: error
96103
verify:
97104
name: Build and test KeyLoad
105+
if: ${{ github.event_name != 'workflow_dispatch' || inputs.task == 'all' }}
98106
needs: repository-checks
99107
strategy:
100108
fail-fast: false
@@ -210,8 +218,84 @@ jobs:
210218
name: code-quality-${{ matrix.os }}
211219
path: artifacts/code-quality/**
212220
if-no-files-found: error
221+
task-acceptance:
222+
name: Qualify ${{ matrix.task }} (${{ matrix.profile }} caller)
223+
runs-on: ubuntu-latest
224+
timeout-minutes: 180
225+
strategy:
226+
fail-fast: false
227+
matrix:
228+
task: ${{ fromJSON(inputs.task == 'KL-011' && '["KL-011"]' || inputs.task == 'KL-014' && '["KL-014"]' || inputs.task == 'KL-015' && '["KL-015"]' || '["KL-011","KL-014","KL-015"]') }}
229+
profile: [normal, scalar]
230+
steps:
231+
- name: Download source code
232+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
233+
- name: Set up .NET
234+
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
235+
with:
236+
global-json-file: global.json
237+
- name: Check Docker
238+
run: docker version
239+
- name: Build this task's KeyLoad server image
240+
id: images
241+
run: node scripts/Features/BenchmarkComparisons/prepare-images.mjs --server-only
242+
- name: Configure this task's Docker image
243+
shell: bash
244+
env:
245+
KEYLOAD_SERVER_IMAGE: ${{ steps.images.outputs.server-image }}
246+
run: |
247+
test -n "$KEYLOAD_SERVER_IMAGE"
248+
printf 'KeyLoad__ContainerImages__Server=%s\nKEYLOAD_IMAGE_RECEIPT=%s\n' "$KEYLOAD_SERVER_IMAGE" "$RUNNER_TEMP/keyload-images/image-receipt.json" >> "$GITHUB_ENV"
249+
- name: Restore .NET packages
250+
run: dotnet restore KeyLoad.slnx
251+
- name: Build the complete current solution
252+
id: build
253+
run: dotnet build KeyLoad.slnx --no-restore --configuration Release
254+
- name: Prepare original task source and test-image receipts
255+
id: source-identity
256+
shell: pwsh
257+
run: |
258+
& pwsh -NoLogo -NoProfile -File scripts/Features/CodeQuality/functional-coverage.production-source-manifest.ps1 `
259+
-Mode prepare -Root $env:GITHUB_WORKSPACE `
260+
-EvidenceRoot (Join-Path $env:GITHUB_WORKSPACE 'TestResults/task-acceptance')
261+
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
262+
- name: Discover and execute this task's complete acceptance flows
263+
id: acceptance
264+
if: ${{ !cancelled() && steps.build.outcome == 'success' && steps.source-identity.outcome == 'success' }}
265+
shell: pwsh
266+
env:
267+
KEYLOAD_ACCEPTANCE_TASK: ${{ matrix.task }}
268+
KEYLOAD_ACCEPTANCE_PROFILE: ${{ matrix.profile }}
269+
run: |
270+
& pwsh -NoLogo -NoProfile -File scripts/Features/CodeQuality/task-acceptance.ps1 `
271+
-Repository $env:GITHUB_WORKSPACE `
272+
-EvidenceRoot (Join-Path $env:GITHUB_WORKSPACE 'TestResults/task-acceptance') `
273+
-Task $env:KEYLOAD_ACCEPTANCE_TASK -Profile $env:KEYLOAD_ACCEPTANCE_PROFILE
274+
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
275+
- name: Verify unchanged task source and test images
276+
if: ${{ !cancelled() && steps.source-identity.outcome == 'success' }}
277+
shell: pwsh
278+
run: |
279+
& pwsh -NoLogo -NoProfile -File scripts/Features/CodeQuality/functional-coverage.production-source-manifest.ps1 `
280+
-Mode verify -Root $env:GITHUB_WORKSPACE `
281+
-EvidenceRoot (Join-Path $env:GITHUB_WORKSPACE 'TestResults/task-acceptance')
282+
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
283+
- name: Clean up this task's Docker registry
284+
if: ${{ always() && (steps.images.outcome == 'success' || steps.images.outcome == 'failure') }}
285+
run: node scripts/Features/BenchmarkComparisons/cleanup-images.mjs
286+
- name: Save this task's original acceptance results
287+
if: always()
288+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
289+
with:
290+
name: task-acceptance-${{ matrix.task }}-${{ matrix.profile }}
291+
path: |
292+
TestResults/task-acceptance/**
293+
artifacts/code-quality/**
294+
${{ runner.temp }}/keyload-images/**
295+
if-no-files-found: error
213296
docker-rf3:
214297
name: Test three-node database
298+
if: ${{ github.event_name != 'workflow_dispatch' || inputs.task == 'all' }}
215299
runs-on: ubuntu-latest
216300
timeout-minutes: 180
217301
steps:
@@ -260,7 +344,12 @@ jobs:
260344
- name: Check original three-node reports for diagnostic upload
261345
id: rf3-original-reports
262346
if: ${{ !cancelled() && (steps.rf3-required.outcome == 'success' || steps.rf3-required.outcome == 'failure') }}
263-
run: rg --files --no-ignore TestResults/rf3-required -g '*.trx'
347+
shell: bash
348+
run: |
349+
test -d TestResults/rf3-required
350+
original_trx=$(find TestResults/rf3-required -type f -name '*.trx' -size +0c -print -quit)
351+
test -n "$original_trx"
352+
printf '%s\n' "$original_trx"
264353
- name: Save original three-node diagnostics before covered suites
265354
if: ${{ !cancelled() && steps.rf3-original-reports.outcome == 'success' }}
266355
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1

‎AGENTS.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -566,3 +566,11 @@ A bounded website qualification candidate contains the20-project historical runt
566566
- After the wave's changes are integrated, stop source and compiled-image mutations across every owner at one explicit verification barrier. Build the coherent solution once, run independent required test lanes together when their native resources do not conflict, and assign every failure back to its task owner. Preserve original failures and resource cleanup; no shared compiler races, concurrent writes to the same files, or weakened tests are allowed.
567567
- Record actual acceptance outcomes in the canonical plan, commit and push the complete authorized wave, then immediately assign the next independent tasks. Count a task as done only when its complete required acceptance evidence exists; report the real executor limit when the environment cannot run the requested number of agents.
568568
- Owner selection 2026-10-08 requires GPT-6.1 Sol with medium reasoning for the parallel implementation agents completing this plan, unless the owner explicitly changes that selection. Preserve each task's code, acceptance ownership and handoff when changing its executor.
569+
570+
## Parallel GitHub acceptance, owner direction 2026-10-09
571+
572+
- Run independent complete module acceptance scopes concurrently in isolated Linux GitHub Actions jobs so one long RF3 suite does not hold every task's qualification. Keep all mandatory full build, unit/scalar, recovery, RF3 and coverage jobs; a scoped job supplements those gates and proves only its explicitly mapped task criteria.
573+
- Every scoped job MUST discover its actual native TUnit cases, retain source/DLL/PDB identities and original reports, execute the complete mapped operation flows without retries or skips, and join cleanup of its own Aspire resources. Preserve real .NET and official MCP clients, genuine RF3 membership, bounded execution and truthful caller-versus-server scalar evidence; partial suites MUST NOT become full-suite or coverage qualification.
574+
- Owner clarification 2026-10-09 permits task iterations and checkpoints to execute only the tests mapped to that task's acceptance scope, locally or through an explicitly selected GitHub task run. Preserve the full mandatory final qualification; a focused run's green result proves its selected task flows only and MUST NOT be reported as the complete solution or coverage gate.
575+
- Owner correction 2026-10-09 requires at least 20 native TUnit execution slots for independent functional tests, rather than substituting parallel CI jobs for test concurrency. Default the native selector and typed test execution options to 20 and remove forced one-test execution from task lanes. Preserve genuine shared-resource invariants with narrowly justified native scheduling; audit blanket serial attributes and prove actual concurrency from original native execution records rather than fabricated counters.
576+
- Owner authorization 2026-10-09 permits increasing native TUnit concurrency up to 50 during implementation when actual CPU/resource use and complete-flow outcomes support it. Start at 20, compare real execution duration and resource pressure, retain original failures, and choose the measured useful concurrency without changing acceptance, timeouts, shared-resource ownership or cleanup.

‎README.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -355,6 +355,17 @@ local seed/replay/cold-reopen flow; public transfer and fresh full Linux RF3,
355355
model, recovery and performance qualification remain open. Original source
356356
identities and results belong in the [qualification records](docs/implementation/status.json).
357357

358+
Current source also includes an explicit bounded follower document read through
359+
the .NET SDK and MCP, with a selected replica, lag limit and fresh authorization.
360+
Its [document contract](docs/Features/DocumentStorage.md) keeps the captured data
361+
cut distinct from the current authorization cut. Complete current-source RF3
362+
qualification remains open.
363+
364+
Native TUnit now defaults to 20 parallel tests. GitHub also runs separate
365+
normal/scalar-caller acceptance lanes for strict indexes, the server/SDK and
366+
security/telemetry. Focused task runs retain their complete declared operation
367+
scope; full build, unit, recovery, RF3 and coverage gates remain mandatory.
368+
358369
Complete product functional coverage remains **unmeasured**. The
359370
[coverage contract](docs/Features/CodeQuality.md) admits whole operation flows,
360371
excludes load and comparison runs, and requires matching source and build reports.

‎docs/ADR/ADR-017-ownership-session-tokens.md‎

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -152,6 +152,8 @@ Frozen bounded native authority observation (owner approved2026-10-08): under th
152152

153153
Service-user invariant clarification: the fault Dockerfile inherits and restores the base APP_UID USER. The selected resources preserve the already existing ClusterResourceSettings --user uid:gid override exactly, captured through pinned public ContainerRuntimeArgsCallbackAnnotation before adding NET_ADMIN. They do not change default host/container identity or start service as root. Native tool/read commands alone use --user0 inside each verified owned namespace.
154154

155+
TASK-KL021-NATIVE-NETWORK-IDENTITY-003 refines the existing REQ-MTOKEN-ISOLATION-003 / AC-MTOKEN-ISOLATION-003/005 native inspection contract without changing topology or namespace ownership. Docker's original NetworkMode must exactly equal either the nonempty name or nonempty native ID of its sole actual attached network; the same entry supplies both identities. An unrelated mode, absent/malformed ID or multiple networks fails closed, with no alias/prefix lookup or raw identity export. The original schema2 Linux3458/run37821315110/attempt1 admission receipt proves modeMatchesAttachedId=true and modeMatchesAttachedName=false. Root freezes this predicate correction in TestInfrastructure, changes only IntegrationTests Features/ClusterReplication/Validation/ReplicaIsolationContainerAdmission, builds/reviews it and executes the existing full former-leader SDK/official-MCP minimum-token/isolation/restoration flow through the Linux-owned fault image. All original privilege, service-user, PID, source/image/incarnation and actual majority-ACK/cleanup gates remain unchanged. Rollout is the next native source/image cohort; rollback removes the predicate refinement without any database migration. Accepted; genuine current-source runtime qualification is pending.
156+
155157
Persisted NodeStatus.NodeId is a physical GUID independent of Aspire node1/node2/node3 resource names. The real flow captures each original authenticated endpoint identity and requires it unchanged after restoration; public SDK/official MCP status comparisons bind that actual GUID rather than an invented resource-name identity.
156158

157159

@@ -255,3 +257,46 @@ IntegrationTests ClusterReplication Lifecycle/ReplicaIsolationOwner.cs owns part
255257
Related REQ/AC-SESSIONREAD-001..004. The existing IntegrationTests ClusterReplication DocumentSessionReadRf3Authorization owns a complete grant revoke→valid-minimum rejection→administrator unchanged document→grant restore→healthy continuation through direct SDK, official MCP and Q1 CALL. Denied SDK typed reads carry no value; denied SQL SDK reads carry no JSON value; actual official errors retain dispatched request identity, safe envelope and private-data omission. Full administrator document equals the independent literal reference/revision/JSON/unredacted/empty-redactions model.
256258

257259
Stages: canonical ClusterReplication contract and this amendment; private guarded assertion-only delta; root source join and native build; unchanged fixture-owned failover case and delivered-source Linux RF3 original evidence. Dependencies, routing, authorization, token validation, storage format, admission and lifecycle unchanged. Root owns shared integration/compiler/Git, author owns complete adapter oracle. No data migration; rollback this coherent assertion-only delta. Original failures remain preserved and acceptance remains open until required runtime reports.
260+
261+
262+
## TASK-KL021-FOLLOWER-SNAPSHOT-001 implementation contract
263+
264+
Decision and related REQ/AC-FOLLOWERREAD-001..005 are canonical in
265+
[DocumentStorage](../Features/DocumentStorage.md#task-kl021-follower-snapshot-001-explicit-bounded-follower-document-reads).
266+
The architecture's required follower mode is a separate explicit version1 point
267+
read, preserving the initial strong/minimum stage boundary. Signed server-only
268+
DatabaseCredentialWitness, FollowerDocumentReadCapability and local snapshot use
269+
stable generated Orleans aliases/Ids. Existing owning DatabaseEngine credential
270+
issuer/verifier serves both Authenticate and final same-cut key/principal/policy/
271+
current+captured row validation. Public callers cannot create proof or trusted roles.
272+
273+
Ordered integration: frozen contract and broader unsupported inventory; guarded
274+
Abstractions DTO/alias + Core Authorization/DocumentStorage + Orleans
275+
ClusterRouting capture/barrier/final-admission + Server canonical routes/catalog/
276+
safe-output + shared SDK transport; authored native Unit17 ZoneTree functional and
277+
Schema2 supporting cases;28 actual independently owned Aspire RF3 SDK/official
278+
MCP/Q1 held/refusal/cancel/no-quorum/restoration cases; root full solution/native
279+
census/source/PE/PDB checks and exact-current committed Linux qualification.
280+
Root alone owns shared source joins/compiler/formatter/Git; author retains whole
281+
acceptance ownership. Existing dependencies, unique request grain, node-local
282+
store/apply ownership, admission/deadline/cancel/drain, readiness and cleanup are
283+
unchanged. No data/storage/legacy migration, private transport, history allocation
284+
or stronger durability promise is introduced. Homogeneous current first-release
285+
sources/images include the new explicit operation. Rollback removes the new
286+
capability and its catalog/SDK/tests coherently, retaining original strong routes.
287+
New source/tests remain unexecuted and ADR completion cannot be inferred. Broader
288+
KL021 model stale modes and remote forwarding stay open until their contracts
289+
and actual acceptance are complete.
290+
291+
```mermaid
292+
sequenceDiagram
293+
participant Client
294+
participant Gateway
295+
participant RequestGrain
296+
participant LocalOwner
297+
Gateway->>RequestGrain: Signed server-created native witness
298+
RequestGrain->>LocalOwner: Capture one bounded committed document cut
299+
RequestGrain->>LocalOwner: Fresh quorum and apply barrier
300+
RequestGrain->>LocalOwner: Revalidate key principal policy and both rows
301+
LocalOwner-->>Client: Explicit data cut and current authority cut or safe refusal
302+
```

‎docs/ADR/ADR-072-authorized-sql-model-views.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -108,3 +108,12 @@ flowchart LR
108108
Models --> Policy[Rebased field-use checks and safe projection]
109109
Policy --> Result[Bounded ordered rows without lease authority]
110110
```
111+
112+
113+
### TASK-AUTH-KL015-MODEL-VIEW-DENIAL-001
114+
115+
REQ/AC-AUTH-005/006/009 and REQ/AC-SQLVIEW-002/003/005 require a failed event/queue SQL request to carry no partial page or protected payload/header metadata. Freeze before the test extension under unchanged ADR-014/015/022/072. The existing two real persisted model-authority cases check the SDK error code only at field-use denial and have no actual foreign model partition. Extend those same whole flows using a second genuinely administrator-seeded event/queue partition with its own tenant. The original non-admin persisted own-tenant credential must receive exact PermissionDenied/safe scope detail for both foreign SQL model sources through SDK and official MCP. Every failed SDK result must be IsFailed, Value null and contain no credential or any of the four literal event/queue payload/header canaries in complete native serialization; official MCP must retain its exact error envelope and omit those same canaries from the complete native result. Apply the complete privacy/no-page oracle to the original same-tenant denied sensitive predicate too.
116+
117+
Before and after foreign rejections, actual administrator native stream and message inspection plus SQL rows must equal the literal seeded histories and Ready/unclaimed queue state. Compare ordered logical rows and complete original native records, require positive cuts, and never infer equal cluster-wide cuts across separate calls. The original authorized redacted SDK/MCP read follows the denials, then a real persisted field grant exposes the literal selected value, followed by actual revocation. Original transport, topology, grant epoch, deadlines and cleanup stay unchanged. No product fix or new runtime hook is presumed from this coverage gap.
118+
119+
Ownership: existing QueryExecution Cases/SqlModelViewRf3QueueAuthorityTests.cs and SqlModelViewRf3EventAuthorityTests.cs; new feature-local Helpers/SqlModelViewRf3ForeignTenantFlow.cs and Assertions/SqlModelViewRf3DenialAssertions.cs; requirements here and Authorization/QueryExecution with ADR072. Root alone joins/compiles/formats/delivers. Stages: contract, guarded source-only test repair, coherent native build/discovery, both actual Aspire RF3 flows, exact-source original Linux TRX and source/image/artifact receipts. Native discovery, source review and historical weaker passes cannot qualify these stronger flows. Rollback removes these case extensions and private helpers together; wire, provider, public API, persisted format and UI are N/A. KL015 remains open until current repaired C1 and all required acceptance gates are proven.

0 commit comments

Comments
 (0)