Skip to content

Commit fb08dd3

Browse files
committed
Strengthen refusal recovery flows and Aspire test ownership
Complete the current working-tree checkpoint with original reader/header refusal repair, incoming graph authority continuations, exact native local-profile ownership, current TUnit inventory and the null-service public operation candidate. Verification: full Release solution build and full format passed with 0 errors/warnings; 124 Unit and 10 real process-recovery executions passed in normal/scalar profiles through the canonical Aspire entry; 3299 native identities matched the reviewed source-bound inventory. The genuine null-service RF3 candidate failed on missing persisted scheduler data grants in the new test caller; its original receipt is retained and its scoped-caller successor remains open. Original KL035 Linux normal 48/49 and scalar 49/49 results remain unchanged; no full task, RF3, coverage or production claim.
1 parent b543288 commit fb08dd3

42 files changed

Lines changed: 1582 additions & 54 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ flowchart LR
9090

9191
**Accepted** = original task criteria passed for a recorded source. **In source** = implemented, with qualification open. Later changes require fresh checks.
9292

93-
The latest local checkpoint passed the full Release build, formatting and 80 focused whole-operation test executions in normal/scalar profiles. All 3297 existing native test identities match the reviewed current-source inventory. The current package, source and original test receipts are recorded in the [implementation status](docs/implementation/status.json). Complete Linux/RF3 qualification and product functional coverage remain open.
93+
The latest local checkpoint passed the full Release build, formatting, 124 focused Unit executions and 10 real process-recovery executions in normal/scalar profiles. The focused local RF3 check failed at the new control schedule authority; its scoped persisted caller correction and complete RF3 qualification remain open. All 3299 native test identities match the reviewed current-source inventory. The current package, source and original test receipts are recorded in the [implementation status](docs/implementation/status.json). Complete Linux/RF3 qualification and product functional coverage remain open.
9494

9595
| Workstream | What it does and why | State | Remaining work |
9696
|---|---|---|---|

‎docs/ADR/ADR-010-query-budgets-security.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -102,3 +102,20 @@ REQ/AC-FEED-002/005 and AC-REP-004 preserve every original41-event reference/rev
102102
Correct only the unsupported cross-call cut equality: the complete empty continuation must retain exact known through/tail/first/hasMore/changes and a nonempty actually consumed cursor, and its fresh cut must independently include the original acknowledged tail receipt. Do not infer a cross-node monotone cut beyond that receipt, copy a cursor, synthesize metadata or accept missing events. Strengthen both existing ChangeFeedObservedWorkTests Args without changing their native case identity: after actual observed cancellation/deadline, no-partial/no-effects and complete original literal healthy two-event page, perform a genuine canonical ConfigurePrincipal for an unrelated principal. Compare its complete original result; require the independently captured store position to advance without adding an outbox event or changing root/collection authority. Resume the SAME healthy cursor and compare all seven page fields against literal empty changes/through2/tail2/first1/hasMore=false, its opaque returned cursor and the independent actual new store position. The resumed read must leave the complete canonical image/cut unchanged. An incorrectly frozen old cut fails this control.
103103

104104
Ordered ownership: append this feature/ADR010 contract; native-preview/apply only existing SnapshotInstallFeedAssertions and ChangeFeedObservedWorkTests, with bounded feature-local ChangeFeedReadCutAssertions. No product/public contract, format/alias/Id, deadline, quota, topology, signed operation or fixture readiness change. Root joins once after the prior immutable image tests settle, builds affected images, retains native discovery/source/PE/PDB and executes full36 Unit normal/scalar plus all original7 process and5 RF3/Linux scopes. Strict48 task qualification, complete product coverage and all other acceptance gates remain mandatory and OPEN. Rollback removes only this coherent oracle/control extension; the original Linux failure remains immutable.
105+
106+
107+
## TASK-KL079-FEED-COORDINATE-DOMAINS-010
108+
109+
REQ/AC-FEED-002/005 and AC-REP-004 keep the original erased-follower snapshot installation, all 41 original document changes, exact original receipt authorities, native snapshot checksum and strictly later ordered tail, current persisted authorization, SDK/official MCP/both Q1 routes, same installed-owner cold reopen and complete seven-field continuation.
110+
111+
Authenticated Linux run 38079749196, attempt 1, source 98c5949b7a11d51d045700eaa761d9d0593b670c, normal job 114294033580 retained 48 passing cases and one actual failed erased-follower case: SnapshotInstallFeedAssertions compared the first replica Commit.Position to original ChangeFeedPage.CutPosition and observed 30 versus 31. Scalar job 114294033468 completed all 49 cases successfully; scalar success does not remove the normal failure. Preserve both original ZIP artifacts, source/image receipts, TRX and cleanup.
112+
113+
Native NodeAdministration.StatusAsync reports consensus MaterializedPosition as NodeStatus.Applied; DocumentChange.Commit and the original CommitReceipt.Token use that replica position domain. Native ProjectChangePage reports the invocation's local Store.Position. QueryEngine.ResolveCursor also captures local Store.Position for a new query. These are separate coordinates and must never be numerically compared or translated without a defined mapping.
114+
115+
AC-FEED-COORDINATE-DOMAINS-001 passes when the same original fixture captures a real follower NodeStatus after its original caught-up feed cursor and before erase/producer commands. Check the actual original follower identity/incarnation, readiness, voters/durability and nondecreasing applied position against its real previous status; retain the complete observed status. Every returned change's replica position must be strictly ordered after that real applied witness, bounded by the original tail receipt and in the same incarnation/atomic partition/ownership epoch; original final document and tail commits still byte-match their original receipts.
116+
117+
AC-FEED-COORDINATE-DOMAINS-002 passes when every complete feed page and its own empty continuation are bracketed by independently executed, complete literal point-query pages through the same installed follower SDK endpoint. Before each point query, the ordinary minimum-token Get operation must return the exact acknowledged ordered-tail document/revision/body under the original tail token. Query pages must contain exactly that known row, null cursor and native point access path. Compare each feed cut only with these before/after local Store.Position cuts. Current cuts may advance between calls; do not demand cross-call equality, use a replica token as a storage cut, synthesize metadata or weaken any event/cursor/receipt assertion. The original physical owner is checked around the bracket against the actually reopened status.
118+
119+
Implementation order: freeze this contract in ChangeFeeds and ADR010 before source; add only a bounded feature-local ChangeFeeds assertion helper, adjust existing SnapshotInstallFeedAssertions and additive real status capture/pass-through in EmptyReplicaSnapshotScenario. Preserve original test declaration/native identity, deadlines, thresholds, grants, topology, failure ledger and every existing fault/cold/healthy operation. Root owns this independent fix while three other owners continue their own tasks. No product, protocol, serialized alias/Id, stored format, quota, fixture readiness or clock change; migration/rollout/rollback are N/A for persisted data, and rollback removes only these coherent test-oracle changes while retaining the original failures.
120+
121+
Verify canonical solution/analyzers/formatter, same original native discovery, real local fixture-owned Aspire RF3 operation and authenticated exact-source Linux normal/scalar KL03549 and KL07948 scopes. Existing observed cancellation/deadline -> no effects -> actual unrelated principal commit -> original-cursor fresh local-cut continuation controls remain required. Full functional coverage and other task/fault/endurance gates remain open; a source packet, prior scalar success or local build is not task completion.

‎docs/ADR/ADR-014-principals-rbac-row-policy.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,3 +32,11 @@ flowchart LR
3232
Row --> Operation[Authorized read mutation delivery or query]
3333
Operation --> Audit[Safe outcome without protected payload]
3434
```
35+
36+
## KL-065 test-only implementation tranche, 2026-10-10
37+
38+
Ordered stages: preserve the two original incoming privacy refusals; revision-fenced persisted row-owner repair; independent complete healthy page; persisted reduced scoped grant refusal/no effects; persisted revocation refusal/no effects; higher-epoch exact grant repair; original store join and same-root reopen; current-authority full page; exact original root repair receipts/outcome bytes and unchanged document revisions on replay; joined cold disposal. Ownership: existing GraphIncomingPrivacyTests plus GraphIncomingRowAuthorityContinuation, GraphIncomingRowAuthorityAssertions and GraphIncomingRowAuthorityCold under Unit GraphTraversal. Dependencies reuse GraphCrossPartitionTestSupport, GraphShortestPathFullStoreImage, the original embedded TestDatabaseEngineFactory.Capture composition and native ZoneTree. No public, persisted, resource, clock or topology change and no migration; rollback removes only the additive test extension. Root integrates guarded docs before source and runs complete solution/native Linux gates. Local normal/scalar original-case results are development evidence, not all-interface qualification.
39+
40+
The source-proven embedded same-ID repair replay also retains the complete bounded native key/value image and physical cut: the cached path reauthorizes and returns before clock/effects, with no positive replicated apply index. Lexical cold-store ownership retains both the initiating operation failure and any distinct real disposal failure, emitted after cleanup.
41+
42+
The two original graph cases use the embedded null physical-owner composition, distinct from the native configured-owner fixture. Cold reopen reuses exactly that existing centrally validated engine factory/default profiles and original clock; it does not call the configured-owner constructor with the graph catalog fixture incarnation, change that constructor guard, bootstrap or rewrite owner/store identity.

‎docs/ADR/ADR-025-event-revision-feed-positions.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -121,3 +121,10 @@ The same registered serializer measures and admits the complete native row befor
121121
### TASK-EVENT-VECTOR-CODEC-RESPONSIBILITY-033
122122

123123
The bounded event-vector phase additions retain the original GrainRequestCodec API. Its exact native payload verification responsibility moves to feature-local `ClusterRouting/Serialization/GrainRequestPayloadVerification`; the façade borrows the same codec, engine and captured maximum token length. Evaluation remains token-length → native signature verification → original scope validation → configured MaxBatchBytes → native payload validation → DecodedGrainRequest. No new authority, configuration capture, allocation, alias, field ID, fallback or exception order is introduced. Existing signed-request negative/healthy operation tests remain the verification gate; source extraction and private compilation are not Linux/RF3 qualification.
124+
125+
126+
## TASK-KL084-RESERVED-LOCAL-PROFILE-001
127+
128+
Traceability: existing REQ-EVENTS-FIRST-OPEN-ORDERED-001 / AC-EVENTS-FIRST-OPEN-ORDERED-001 and TASK-EVENTFEED-FIRST-RESERVED-OWNER-001, plus the R22 immutable failed-replay/abandonment/cleanup chain.
129+
130+
The fixture-only EventVector reserved-phase enrollment explicitly selects the genuine two-RF3 protected query profile under a validated local image. It preserves the independent NativeDiscoveryOmission branch and ordinary local-profile refusal. The existing signed first-dispatch reserved barrier, original expiry, all six source/image/StartedAt identities and joined all18 locks remain required. R104 was a pre-operation profile rejection; profile admission, compilation and native provider Unit controls do not qualify FirstOpen or Linux RF3 acceptance. See the finite EventVectorReservedProbeProfile owner and original EventFeedFirstOpenRf3Tests whole-operation gate.

‎docs/ADR/ADR-094-orleans-due-coordination.md‎

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -171,3 +171,55 @@ REQ-MSG-004, AC-MSG-004 and AC-MSG-092-DEADLINE retain the original cancellation
171171
The same complete native Unit flows keep their revoked/stale/not-due refusals, canonical message/index/counters and two cold receipt replays. Their healthy Receive explicitly admits the existing maximum of two known ready messages, so the original promoted head and newly enqueued healthy message are both actually claimed and acknowledged. It must retain the exact final ready sequence, attempts, lease/state revisions and empty counters. Compare the complete generated native MutationReceipt bytes, including composition references, rather than ImmutableArray backing identity; all original Kind/Resource/Id/Revision values and all five real process-cut arguments remain exact.
172172

173173
Owned files: Core Messaging Queries/QueueDeadlineDiscovery; Unit Messaging Helpers/QueueDeadlineNativeHealthy and QueueDeadlineNativeContinuation; Recovery Messaging Assertions/QueueDeadlineRecoveryAssertions. Existing original named full-operation tests are the regression oracles; no accessor/helper-only tests or deadline increases. Root integrates this finite repair and verifies native diagnostics, canonical format, coherent Release build, mapped normal/scalar Unit and genuine process recovery, then commits/pushes the complete authorized scope. Current Linux RF3, full-suite, coverage and whole KL092 acceptance stay open until their original delivered-source evidence exists.
174+
### TASK-KL092-NULL-SERVICE-PUBLIC-OPERATION-001
175+
176+
REQ-MSG-004 / AC-MSG-004 and AC-MSG-092-DEADLINE require an actual null-selected
177+
disabled queue branch with no queue effects. Preserve the existing selected-principal
178+
case and all original assertions. The additive
179+
QueueDeadlineAutonomousRf3Tests.NullSelectedServicePreservesScheduledStateReceiptsAcrossColdThenPublicClaimAndHealthyAck
180+
owns a fresh standard ClusterFixture, whose QueueDeadlinePrincipalId remains
181+
null, three actual Aspire Docker nodes, discovered SDK/official MCP endpoints
182+
and original caller/cleanup deadlines. Configure an ordinary scoped persisted
183+
worker through the administrator SDK; its existence never selects it as the
184+
service principal.
185+
186+
Seed independently authored due/future messages and their complete inspection
187+
models. Retain the actual original commit receipt and public queue counters/items.
188+
The native null option disables queue turns; do not wait for an UnsupportedCapability
189+
dispatch log from a branch which never runs. In the same real RF3 fixture, configure
190+
a distinct control queue and one ordinary recurring schedule in the original
191+
atomic seed command. Its due instant equals the scheduled message's due instant;
192+
its original one-day interval keeps the next occurrence outside this flow.
193+
Require the complete independently literal autonomous first occurrence and schedule
194+
inspection through SDK, official MCP and both Q1 routes. No manual Emit or Receive
195+
may produce this witness. Then cancel the control through the real original
196+
revision-fenced command and replay its complete receipt. BEFORE any Receive of the
197+
subject queue, require both original message models, exact counters/items and
198+
the original seed receipt on all four routes. The recurring effect proves a real
199+
scheduler operation; it does not grant success to the disabled queue branch.
200+
201+
Reopen the same owned volumes and repeat the full no-effects/receipt oracle.
202+
Then exercise the ordinary authorized official Receive and SDK ACK with all four
203+
replay routes, a second cold terminal/receipt check and fresh healthy enqueue,
204+
claim and ACK. Receive may itself promote due work; this proves ordinary caller
205+
health, never autonomous null-service success. No product logger, principal,
206+
clock, role, diagnostic endpoint, dispatcher, storage format or timeout changes.
207+
208+
Ownership: Messaging Cases keeps the original case and adds this operation;
209+
Messaging Helpers owns the trial, public operations and genuine recurring control;
210+
Messaging Models owns only immutable operation observations. Existing fixture,
211+
native due service, SDK/MCP/Q1 and cold helpers are reused unchanged. Root joins
212+
these finite sources, exact local-filter enrollment and required native inventory,
213+
then builds/formats and runs the actual normal/scalar operation after heavy-owner
214+
settlement. Root commits/pushes the completed stage and retains exact delivered
215+
Linux evidence. Rollback removes only this added test/enrollment. Null service,
216+
leadership/migration, physical drift/lateness and whole KL092 remain OPEN until
217+
their separate genuine gates pass; no new UID or PASS is inferred from source.
218+
219+
TASK-KL092-NULL-SERVICE-CONTROL-AUTHORITY-003 in
220+
Features/Messaging/DueCoordination.md freezes the scoped persisted recurring
221+
control creator, its separate full configure/cancel receipts and original four
222+
public replay routes. The original normal R3 PermissionDenied is retained; native
223+
schedule data grants remain mandatory even for a cluster administrator. This is
224+
a test-caller correction with unchanged product authority and subject worker
225+
scope. Actual normal/scalar RF3 and complete KL092 qualification remain open.

0 commit comments

Comments
 (0)