Skip to content

Bump WolverineFx from 6.31.0 to 6.35.0 - #2387

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/WolverineFx-6.35.0
Closed

Bump WolverineFx from 6.31.0 to 6.35.0#2387
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/WolverineFx-6.35.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Updated WolverineFx from 6.31.0 to 6.35.0.

Release notes

Sourced from WolverineFx's releases.

6.35.0

Store operation side effects, everywhere

MartenOps covered store / insert / update / delete plus StartStream; anything else meant taking an
IDocumentSession and giving up on the handler being a pure function. All three stores now cover
what their own session API supports.

Op Marten Polecat Fisher
HardDelete, HardDeleteWhere, UndoDeleteWhere
UpdateExpectedVersion
UpdateRevision
TryUpdateRevision
Patch, PatchWhere
QueueSqlCommand
InsertObjects, DeleteObjects
Append, ArchiveStream
UnArchiveStream, TombstoneStream

The gaps are deliberate: each set was checked against that store's own session API rather than copied
across, and an op whose Execute could only throw is worse than the absence of one. Polecat's last
row is the reverse case — two operations Marten has no counterpart for.

Every op also implements ITenantedMartenOp / ITenantedPolecatOp / ITenantedFisherOp, so one
extension scopes any of them while preserving the concrete return type:

MartenOps.ArchiveStream(command.OrderId).ForTenant(command.TenantId);
PolecatOps.StoreMany(items).ForTenant(tenantId).With(oneMore);

Thanks to @​erdtsieck for the Marten half, which is where this started.

Event Modeling: a declared model and the code now meet

Three findings from one comparison of a curated Event Model against the application built from it
(#​4385, #​4386, #​4387):

  • Slices join on handler type. Slice names are the merge key, and a board names a slice for the
    behaviour (ConfirmAppointment) while a derived source names it for the message type or the route.
    An eleven-slice application assembled as twenty-two with no disagreements — not because the sources
    agreed, but because they never met.
  • [Emits(typeof(...))] lets a handler name the events its signature cannot carry. EventsToAppend
    and StartStream erase the element types, so the more idiomatically event-modelled an application
    was, the emptier its derived model got.
  • Pattern is left unclaimed for a message handler. A handler cannot tell a Command from an
    Automation, so a declaration wins the role instead of losing to a guess.

⚠️ Behaviour change: a plain message-handler slice no longer reports pattern: "Command" in
event-model output or the ServiceCapabilities snapshot. Pattern is still derived wherever the
code answers the question — HTTP routes, gRPC RPCs, schedules, external systems, and any slice whose
... (truncated)

6.34.0

Seventy commits since 6.33.0. The bulk of it is a sustained performance wave on the durability
and message-execution paths, alongside a new recurring-schedule feature, Native AOT support that
now boots end to end, and a long run of clustering and transport fixes.

New

  • Recurring cron-scheduled messages. opts.Schedules registers messages to be published on a
    cron expression, coordinated across the cluster so exactly one node fires each occurrence. (#​4307)
  • Azure Service Bus takes a configurable prefix for the system queues it names for itself, plus
    a transport-wide default dead letter queue name. Note the migration hazard called out in the docs
    if you adopt the prefix on an existing deployment. (#​4263, #​4281)
  • Amazon SQS takes the same kind of configurable prefix for the queues it names for itself. (#​4292)
  • The HTTP transport now answers to plain http:// destinations, not just https://.
    ITransport.AdditionalProtocols is the general mechanism, so any transport with legitimately
    multi-scheme addresses can opt in. (#​4200 / #​4379)
  • Broker resource setup honors ResourceMigrationFailureMode. FailFast stays the default and
    keeps resources setup strict; ContinueOnFailures lets a host whose broker topology is
    externally owned log the failures and start. (#​4119 / #​4380)

Performance

The GH-4316 wave, measured on the multi-transport perf rig rather than by inspection. Highlights:

  • Recovery poll and handled-cleanup get indexes they can actually use — three partial indexes on
    PostgreSQL and SQL Server, 37ms down to 0.04ms on the measured query. (#​4336)
  • Batched outbox stores for Oracle, RavenDB and Cosmos DB — 13.1x on Oracle, 61.4x on
    RavenDB. (#​4369 / #​4370)
  • Insert-side coalescing of the last un-batched per-message durability round trips: +24.5%
    throughput and 26% lower publish latency where the application publishes concurrently. (#​4319 / #​4368)
  • Fixed-arity batched inserts on PostgreSQL (1.35x) and pooled Envelope bodies above the LOH
    threshold
    (13.5x at 100KB, with Gen1/Gen2 collections gone). (#​4320, #​4333)
  • Batched durability commands are chunked under each provider's parameter ceiling, so a large
    transaction no longer trips SQL Server's 2100-parameter limit. (#​4375 / #​4376)
  • Per-message allocation and lookup trims across routing, the send path, the execution pipeline,
    header handling, and metric accumulation. DateTimeOffset.Now is gone from the per-message paths.
    (#​4322, #​4323, #​4324, #​4325, #​4326, #​4328, #​4335)
  • Idle polling stops hammering (#​4321); the database queue transports drop their per-poll temp
    tables (#​4334); SQL Server metrics counts come from index metadata instead of three full scans
    (#​4318); Redis Streams gains batched durable arrival, measured at +159% (#​4329).

Two changes measured negative on the rig and were reverted rather than shipped — the Azure Service
Bus prefetch default and the coalescer's Queue shape. Both are recorded so they are not revisited.

Native AOT

A Wolverine application now completes a Native AOT publish and boots through its own bootstrap.
(#​4287, #​4298, #​4301, #​4305). A Native AOT app with any external transport used to die building its
first route — fixed in #​4232 / #​4378. The AOT publish smoke test hard-asserts a full boot.

Clustering, agents and durability

... (truncated)

6.33.0

The headline is a new package. WolverineFx.AI makes a one shot LLM call an ordinary Wolverine message: durable, outbox enrolled, retried by the same rules as everything else, and testable without a model anywhere in sight.

WolverineFx.AI (new package)

An LlmCallout is a message. Return one from a handler next to your storage action and it is enrolled in that handler's outbox, so a callout cannot fire for a transaction that did not commit and cannot be lost to a restart in between. The model's answer comes back as an ordinary cascading message, with an ordinary handler, an ordinary retry policy, and its own place in the correlation chain. (closes #​4227)

  • Spend guardrails as middleware on the callout queue. LlmBudget.MaximumPromptCharacters refuses a runaway prompt before your provider is ever called; MaximumTokensPerWindow refuses callouts once the node has burned its allowance. Both dead letter rather than retry, and so does an answer that cannot be parsed into the response type you asked for -- retrying either is the runaway spend the budget exists to stop.
  • A scripted IChatClient for testing. StubChatClient exercises a callout's whole round trip with no key, no network and no model.
  • Trim and AOT clean, guarded by a Wolverine.AI.AotSmoke project under TrimMode=full that CI runs. (closes #​4230)
  • Documentation for tuning it, new in this release: how to control parallelism against your provider, why the answer has its own queue with its own settings, and how to bring your own error handling on both sides.

The package references only the Microsoft.Extensions.AI abstractions, never a vendor SDK. The provider -- Anthropic, OpenAI, Azure, Ollama -- and any middleware over it stay your choice.

Fixes

  • A node no longer sweeps up its own in-flight stop as a wedged shard. An event-subscription agent could end up running on two nodes at once while wolverine_nodes credited only one, so nothing in the system could ever stop the extra copy. (closes #​4240)
  • Node record descriptions no longer overflow the column and fail the insert. An AssignmentChanged description carries an agent URI, a schema name and a destination node, which on a real cluster overran the description column and failed the whole AgentCommand batch behind it. MySQL was worst hit at VARCHAR(255). (closes #​4246)
  • DataAnnotations validation works with ServiceLocationPolicy.NotAllowed -- on HTTP endpoints and, now, on message handlers. Under the Wolverine 6 default this made the validation middleware unusable and threw at bootstrap. (closes #​4238)
  • A failed EF Core rollback no longer displaces the exception that caused it. (closes #​4239)
  • Wolverine parameter attributes work on gRPC before/after hooks -- [Entity], [All], [Queryable], [WriteAggregate] and the rest. (closes #​3935)
  • An application-wide default duplicate status code via opts.DefaultDuplicateStatusCode, and deduplication refusals now advertise their problem document in OpenAPI.
  • Concurrent IHost.StopAsync no longer tears the agents down twice.

Upgrade note

6.33.0 requires Weasel 9.30.0, and that raises the GH-4246 fix from "new databases only" to "existing ones too": the schema differ now compares character lengths, so a widened varchar is no longer invisible to it and an existing table is corrected in place by an ALTER TABLE ... MODIFY that keeps its rows.

Worth knowing before you upgrade: that comparison runs in both directions. Width drift that was previously invisible now generates ALTERs, and a model narrower than an existing column will emit a narrowing ALTER that can fail on real data. Sizes that are not character lengths -- a MySQL int(11) display width, a decimal precision, a datetime fsp -- are still ignored.

Dependencies

JasperFx 2.60.0, Marten 9.30.0, Polecat 5.21.1, Fisher 1.0.6, Weasel 9.30.0.

6.32.0

See CHANGELOG.md for the full entries.

New packages

WolverineFx.AmazonS3 and WolverineFx.AzureBlobStorage carry document and saga persistence plus the claim check store that used to ship separately. Registration is explicit per type — Store<T>() and Saga<T>() are separate calls and each refuses the other's type — and saga writes are guarded by conditional requests, surfacing as SagaConcurrencyException so one OnException<ConcurrencyException> policy still covers every store. (#​4160, originally #​4165 by Anne Erdtsieck.)

WolverineFx.ClaimCheck.AmazonS3 is deprecated. The namespace is unchanged, so migration is a package reference swap — but keeping both referenced produces ambiguous-type errors.

Redis document and saga persistence folds into the existing WolverineFx.Redis rather than a new package, with saga concurrency implemented as a Lua compare-and-swap.

Fixes

  • A shutting-down node no longer dead-letters work whose handler never ran (#​4213). Core, so every transport.
  • Scheduled promotion matches the whole message identity on SQLite, SQL Server, MySQL and Oracle rather than PostgreSQL alone (#​4216) — including a not-yet-due scheduled message being promoted and executed early.
  • A redelivered inbox row can be retired when its identity is already handled under EnableInboxPartitioning (#​4216); previously it could not be retired at all.
  • A listener whose broker entity was deleted underneath it now heals instead of retrying once a second forever (#​4215).
  • Terminal settle failures are classified on the retry block, closing a gap where two of four Azure Service Bus listeners had no classification at all (#​4012).
  • Scope priming no longer manufactures a Marten session for every handler that service-locates anything (#​4198). Requires JasperFx 2.58.0 or later.
  • A duplicated scheduled identity no longer wedges promotion on a partitioned PostgreSQL inbox (#​4202).
  • AddStopConditionIfNull accepts the null identity its signature declares (#​4161).

Diagnostics

  • NativeAck and partitioned listeners report ceilings, per-lane depth and duplicate-suppression counts (#​4199). BufferLimit is now null on the modes that never enforced it, with the broker's prefetch window reported as InFlightLimit.
  • MaximumBrokerRedeliveries is documented as the delivery count it actually is (#​4216). Behaviour unchanged.

Event model

  • A stream-appending handler's return value is reported as a reply rather than an emitted event (#​4204).
  • A generic message type's slice reads the way source spells it, which also stops two relays with different payloads colliding on one slice (#​4205).

Also

  • Explicit per-provider entity attributes, starting with [FromMarten] and [FromEfCore] (#​4214).
  • RabbitMQ documentation for AddResourceSetupOnStartup and AutoProvision (#​4223).

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: WolverineFx
  dependency-version: 6.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #2388.

@dependabot dependabot Bot closed this Sep 8, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/WolverineFx-6.35.0 branch September 8, 2026 02:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment