Skip to content

Latest commit

 

History

History
666 lines (583 loc) · 60 KB

File metadata and controls

666 lines (583 loc) · 60 KB

ResourceExecution

Actual database phase diagnostics are specified in DatabasePhaseProfiling under ADR-063, REQ-RESOURCE-003..006 and AC-DBPROF-001..008. The fixed BCL-only Diagnostics schema is joined first; bank, preserving producer instrumentation, private node capture and genuine source-bound measurements remain open. This optional workstream changes no authorized cut, database state, WAL or acknowledgement.

The additive TimeSeries readers under ADR-052 map REQ-MP-002/005 and AC-MP-002/005/011/012 to AC-SERIES-011 and AC-RANGE-REV-003. One original read gate and one budgeted view charge metadata/data/lookahead exactly once, enforce deadline/cancellation and exact full JSON results, and preserve healthy following operations after failure. Root owns BudgetedReadView reverse forwarding; TimeSeries and StorageRecovery workers own their disjoint operation/provider acceptance tests. Source and exact-SHA evidence are pending; architecture choices do not establish maximum throughput, physical I/O, process RSS or numeric coverage.

TASK-RUNTIME-CANCEL-W2 is an accepted AC-MP-009/010/012 fixture refinement under ADR035: arm a dedicated real-file growth observer before native async report writing; retain the corpus,10second deadline, quarter-output cutoff, OCE and no-later-file assertions. The same scoped worker coordinates one bounded second real Kestrel partial-body write after the cancelled client result while preserving actual RequestAborted, incomplete response, five-second waits and same-client reuse. Only the four named fixture files and a necessary same-slice observer helper belong to this worker; product serializers, client/SDK transports, public contracts and all budgets remain unchanged. Existing run37015193756/ad594642 is the failing baseline; enabled source quality and the full new exact-SHA GitHub suite qualify the final result.

Status: Accepted contract; implementation and qualification in progress. ADR-035 owns scoped read/resource/lifetime decisions. Full requirements and test strategy: acceptance.

The staged disposable-cache contract and ordered task graph are accepted in ADR-058. The common pool and explicit embedded positive-point stage are approved source scopes; authenticated Orleans control still needs its exact lead-reviewed contract before coding. Local brainstorm/acceptance/plan scaffolds remain ignored by owner policy; these durable requirements and the ADR are the reviewable source of truth. No cache or performance capability is qualified yet. UI/HTTP/SDK/MCP cache administration is N/A in this stage; existing public database operations remain the visible boundary.

Cache requirement Acceptance Task and automated proof
REQ-CACHE-001: shared validated retained-byte/entry reservations and lifetime AC-CACHE-001/002 TASK-CACHE-MEMORY-R26; real CacheMemoryBudget capacity/overflow/index/concurrent/disposal TUnit
REQ-CACHE-002: exact-key coherence and store-generation/recovery fencing AC-CACHE-003/004/015 TASK-CACHE-PROVIDER/PROVIDER-TESTS/INTEGRATION-R28; actual ZoneTree transactions/snapshots/reopen; R83 genuine fixture identity regressions
REQ-CACHE-003: owned/scoped buffers and bounded local work AC-CACHE-005/006/015 TASK-CACHE-PROVIDER/PROVIDER-TESTS/INTEGRATION-R28; real pins/callbacks/eviction/logical-charge tests; R83 typed owned-copy oracle
REQ-CACHE-004: bounded authenticated Orleans physical-node policy coordination AC-CACHE-007/011/012/013/014 TASK-CACHE-CONTROL-R26; native RF3 grain/service restart/migration/forged-message tests; R69/R81 genuine local prerequisites and R82 bounded wire/crypto remain separately qualified
REQ-CACHE-005: current grants, barriers and field/tenant decisions AC-CACHE-008 TASK-CACHE-CONTROL-R26; current public SDK/MCP authorization flows
REQ-CACHE-006: honest closed resource metrics and comparable benefit AC-CACHE-009 TASK-CACHE-NATIVE-R26; repeated GitHub cache-on/off resource JSON
REQ-CACHE-007: complete delivered-source/native qualification AC-CACHE-010/014/015 TASK-CACHE-NATIVE-R26; build/format/analyzers/complexity/governance + unit/scalar/recovery/RF3 and real coverage

Cache acceptance and testing methodology

AC-CACHE-011 adds the exact local provider binding under ADR-058 R69. An actual opened store creates one configured-cold control with no index charge. Embedded or existing owners reject another configuration; held/same-thread storage gates return Busy, and permanent close cannot reopen. Exact ready receipt application is idempotent; genuine continuous predecessor renewal retains entries/counters, while skipped predecessor, withdrawal or expiry makes a fresh cold helper. Dispose the old helper under the real writer before reserving a new index. Real one-index-budget and pressure-release cases must progress without lost native data. Delayed old retirement cannot disable a newer binding. Withdraw in an actual native observer must perform one lookup/charge/callback and publish no candidate; already admitted pinned readers retain charges until completion or exception. Actual Dispose publishes admission-close before draining its held reader; all owned charges release after the real drain. R75 rejects Dispose inside the same thread's actual Read/Commit callback with LockRecursionException before closing publication. Rejection leaves current eligibility, data and charges intact; external close and same-directory reopen must then succeed. The exact preserving repair, ownership and regression sequence are in ADR-058 R75. Tests use genuine ZoneTree/files, CacheMemoryBudget and System-clock CacheReadPermit in new ZoneTreeCoordinatedPointCache*Tests.cs and real fixture/support files under UnitTests/ResourceExecution, executed only by GitHub unit normal/scalar.

The2026-10-04 full Aspire development run retained an unchanged real-clock expiry observation failure in AcceptedReceiptExpiresFromItsRealPrepareTimestamp: the observation arrived after its original upper bound while concurrent local solution verification was active. TASK-CACHE-REALCLOCK-ISOLATION applies only a method-level keyless TUnit NotInParallel to that case. Preserve TimeProvider.System, the2second preparation delay,10second preparation limit,15second lease, 30second test deadline, original lower/upper age assertions and renewal/revision checks. No production clock, lease, retry, tolerance, skip or other test changes. Root owns full normal/scalar qualification; source isolation does not prove against external process interference or VM preemption.

AC-CACHE-012 requires IsCurrentAcceptance to validate the complete immutable accepted receipt and existing prepare-origin15second lease from one state read. Default, stale, altered PreviousRevision/Continuous, withdrawn, expired or closed receipts reject. The10second ceiling is acceptance-only. Real CacheReadPermitAcceptanceTests.cs and the provider expiry cases cover this local prerequisite; freely constructed equal values do not certify wire origin.

AC-CACHE-013 adds the accepted R81 actual physical-owner observation in ADR-058. Control.TryReadOwnerIdentity returns Healthy/Busy/Closed and only actual NodeId/incarnation/control RuntimeId. It attempts the actual reader with timeout zero; same-thread operations/foreign writer are Busy, foreign reader may coexist, closing is Closed, and acquired-gate runtime.Check preserves RecoveryRequired. No index/lookup/lease, complete identity, secret, cache/pool lock or I/O is involved. Real ZoneTreePointCacheOwner*Tests cover cold/warm counters, callback/held gates, pre-drain/permanent closure, faulted apply and same-directory recovery. Root owns the local seam/shared fixture; Luna owns only new tests. GitHub normal/scalar and required recovery/RF3 qualify the source; tiny closure interleavings require independent review. Observation is not full silo readiness or a remote grant.

AC-CACHE-014 implements only the accepted exact internal v1 wire/primitive contract and ADR-058 R82 stages. Thirteen immutable generated metadata types, closed byte enums, dedicated bounded canonical bytes/HMAC, nested-proof validation and exact original-request correlation have no production caller or eligibility side effect in this stage. Actual pinned Orleans serialization and independent literal golden C/S/MAC/digest vectors, per-field/null/enum/address/range mutations, signed policy mismatch, flat rejection, valid-outer/invalid-nested MAC, accepted binding/sequence and real concurrent signer disposal map to new CacheControlWire* TUnit files. Complete size preflight and constant-time/private-key/disposal/alias/Id contracts receive independent review; the unreachable64KiB edge has the explicit size-arithmetic exception recorded in the exact contract. Root owns generated contracts and primitives; Luna owns only new acceptance-led tests after freeze. Full enabled source gates and a new exact-SHA GitHub run qualify them. Receiver, replay, coordinator, timers, DI, native probes and RF3 enablement remain later stages.

AC-CACHE-015 repairs only the native test-fixture and assertion failures from exact source2ecbeee4d/run37093992229:1539 normal cases,1522 pass,17 errors; scalar skipped. A null byte[] signing key must remain absent nullable ReadOnlyMemory, explicit valid32byte keys retain their genuine configured incarnation, and explicit empty remains present and rejects TokenInvalidated. ZoneTreePointCacheFixtureIdentityTests proves default real-store open/reopen, configured valid-key peers and empty-key rejection without emitting secrets. ZoneTreeCoordinatedPointCacheReadTests uses one named byte77 for assignment and comparison, retaining independent warm copied bytes and all cache counters. The existing fixture collects body and every store/directory/pool cleanup independently and starts Dispose once before cleanup. Root owns traceability, enabled source gates, independent review and exact-SHA normal/scalar/recovery/ RF3 qualification; Luna owns only these three test files. All17 failing IDs must pass on the next delivered source. No product identity validation, key generation, provider error, cache data or dependency behavior changes. ADR-058/035/041 already govern these unchanged boundaries; no new migration.

R86 exact source397a89c46df8caaf0cc89a51e2e1c7b9208adcc6/ run37097831105 passes63 RF3,164 recovery/1000 seeded process-cut rows and118 analyzer cases. Normal1583 has1566 pass/17 identity errors; scalar/comparisons are skipped. The historical byte77 case passes,16 prior identity errors persist and the new genuine default-key/reopen case fails. R88 explicitly casts the absent conditional branch to ReadOnlyMemory?; a bare null branch still permits natural present-empty memory conversion. The already shared one-line source correction preserves all genuine original/empty-key assertions and product validation. Every current identity failure and the historical byte case must pass on the next exact source. Seven R81 owner-observation cases pass in normal mode, with no full-ready, signer/controller, scalar or coverage qualification. The original native receipt (report removed from repository) is the canonical result and artifact join.

R93 delivered sourced45d7f253d309610d7cce66684f155170277252a/run37098964980 closes AC-CACHE-015: all1583 native unit cases pass in normal and scalar modes, with identical complete ID/status sets and no skips. All17 R86 identity failures and the historical byte77 oracle pass in both modes. Recovery164/164 plus1000 seeded rows, analyzer118/118 and actual SDK/MCP RF363/63 pass. Root joined the original API/run/SHA/ZIP digests, every native ID,20 seed files and four genuine container restart receipts in the R93 source-gates receipt (report removed from repository). The comparison workflow concluded failure:24/27 preflight jobs succeeded,3 failed (MongoDB n2 image import, MongoDB n3 NotPrimary reads, KurrentDB n2 cleanup). Two successful Neo4j Community jobs report unsupported topology; the270-cell matrix and aggregate did not execute. The R100 wire source receipt (report removed from repository) binds the independent34-product/26-test review and root's complete hash comparison. This source is absent from d45 and requires fresh integrated gates and its own delivered native codec/crypto/lifetime qualification. Full-ready control, coverage, matched cache profiles, endurance and power-loss gates remain open; RF3 caches stay off.

The later ALL186-file5bb checkpoint/run37104211481 passes actual RF363/63 and analyzer118/118, with exact native reports, six original ZIP digests and four new-container restart receipts in the R104 terminal receipt. Full solution verify fails20 Node test-helper diagnostics; normal/scalar units, recovery and comparison lanes are skipped. AC-CACHE-014 wire tests were not executed. Current preserving helper corrections, complete development gates and a new delivered-SHA native run remain required; this checkpoint is not full AC-CACHE-010 qualification.

TASK-CACHE-BINDING-INTEGRATION-R69 is root-only: shared contracts, permit join, public control/facade/runtime/lifecycle/read admission and durable docs. TASK-CACHE-BINDING-STATE-R69 owns only new private ResourceExecution binding/state helpers; TASK-CACHE-BINDING-TESTS-R69 owns only the new acceptance-led real tests. The full ordered implementation, exact APIs/result subsets, disjoint file owners, dependencies, rollback and join gates are in ADR-058 R69. Shared lifecycle and transition order and tiny post-pin/create-close interleavings receive explicit independent source review because deterministic forcing would require forbidden production hooks. Real callback, pressure, revoke, close and concurrent lifecycle tests remain mandatory; that exception does not substitute for signed RF3 proof.

Coordinated snapshots report effective eligibility and configured-cold state. Closed means permanent admission closure; retained pinned/index bytes remain visible until actual release. Current-helper counters reset on cold replacement and have no-helper gaps; Hits counts successful pins, including rejected pins. Store diagnostics remain cumulative logical read work across both cache hits and native reads. A fresh local RuntimeId is not actual RF3 readiness, membership or physical permit certification. Production composition remains cold.

  • AC-CACHE-001 passes only when one shared node pool atomically reserves validated positive modeled bytes/nonnegative entries before optional owned allocations; exact byte/entry caps succeed, one-over and overflow fail without mutation, and real concurrent consumers cannot exceed either ceiling. Positive index charges may reserve zero entries. Invalid limits/requests must reject explicitly.
  • AC-CACHE-002 requires idempotent/concurrent reservation release and coherent snapshots after closure. Closing admission or retiring an entry cannot release any charge while a reader/candidate still owns its bytes. Real public pool tests and genuine pinned-store callbacks prove cleanup on success and exceptions.
  • AC-CACHE-003 requires privately owned positive bytes keyed by complete encoded content, physical runtime and ReadGeneration. Every Apply invalidates before native mutation; unrelated commits retain coherent entries. Real staged put/delete/reset/rejection, multi-key commits, tombstones/reinsert and replay tests fail if staged or old data appears as a committed hit.
  • AC-CACHE-004 requires independent Clear before authority/tree replacement, including warm keys absent from a snapshot and interrupted install. Corrupt or stale snapshots preserve existing typed failure/authority behavior; known poison cannot be bypassed. Same-cut compaction/export may retain entries. Real files, recovery observers and cold reopen/disposal prove unchanged durable results.
  • AC-CACHE-005 requires caller-owned output copies, the existing scoped readonly borrowing boundary and no allocated hit lease. Index/live/retired-pinned/fill ownership stays charged; immutable key binding precedes callbacks. Observer and consumer execute outside cache/budget locks, with finally release on throw, cancellation and eviction. Real synchronized readers prove pin/duplicate-fill lifetime rather than inferring it from final occupancy.
  • AC-CACHE-006 requires the sole StoreGate -> CacheGate -> budget order and no cross-store callbacks/eviction. Admission checks current revision/generation, makes at most16 local victim attempts and preserves native results when full, oversized, disabled, pin-limited or unavailable. Logical charges/observer order and typed errors remain exact; unexpected invalidation failures fail closed. Real native diagnostics and shared-store pressure cases prove these conditions.
  • AC-CACHE-007 requires authenticated bounded Orleans exchange binding actual fixed-voter readiness, silo generation, physical store/incarnation, exact local policy and receiver-owned finite lease. Server starts cold. Forged/replayed, stale/expired/wrong-node, unavailable control, restart and migration cannot enable a node without its own valid acceptance. No grant precedes complete RF3 readiness and cohort preparation. Partial final acceptance stops renewals and attempts bounded revocation; nodes without acceptance stay cold, while an already accepted node may remain locally accelerated only until its receiver lease expires within15seconds. Instant atomic RF3 cache activation/revocation is not promised. Every request still uses the original fresh quorum and current authorization path. No control message moves data/files or grants access. Actual RF3 grain/service SDK/MCP tests are mandatory; embedded opt-in is separate.
  • AC-CACHE-008 requires fresh current authentication, credential time/revocation, quorum, row/field policy and command replay fingerprint/incarnation checks on every public operation. Coherent raw principal/StoredOutcome bytes may be retained; grants, final authorized objects and negative lookups may not. Real authority changes and cross-tenant/hidden-field/error flows must keep exact results.
  • AC-CACHE-009 requires closed data-free counters and repeated matched exact-SHA on/off cold/warm/mixed/pressure GitHub profiles with the same topology/ACK/read contracts. Retained modeled bytes, allocations/GC, per-node RSS, native lookups, latency, throughput, contention and backlog remain distinct. Missing or mixed measurements fail any speed/RSS claim; a build is never measurement evidence.
  • AC-CACHE-010 requires the delivered-SHA full build/format/governance/analyzer, normal/scalar TUnit, real process recovery and Docker/Aspire RF3 SDK/MCP gates, plus actual compatible coverage before claiming numeric thresholds. Skipped suites, fake providers, local load or unpublished packages cannot count as pass.

Automated sources live in matching ResourceExecution tests; storage/domain tests retain their original owners. Unit execution is through ci.yml normal/scalar; recovery and RF3 execute their real process/container projects in that workflow. The accepted R28 task graph supplies exact disjoint files and joins in ADR-058. Lock order, secret-free metadata and physical ownership have a source-review exception requiring independent inspection; it does not replace native cases. Rollback disables ephemeral admission, drains readers and removes optional joins together. No persisted format, authorization, ACK or production RF3 migration.

Baseline63ac27c run37082449440 failed the solution build with IDE0032/IDE0290 in the website receipt source; normal/scalar/recovery/comparisons were skipped. Separate native analyzer118/118 and RF3 63/63 passed, including new dependency consumption on that source. Current cache source awaits a later exact-SHA run.

Requirement Acceptance Task / test ownership
REQ-MP-001: all current operation/resource paths reviewed and evidenced defects closed AC-MP-001 TASK-MP-001/002/003/004; located inventory and independent final review
REQ-MP-002: bounded consistent read/mutation work without redundant materialization AC-MP-002..006 TASK-MP-005/006/007; real StoreRecovery, QueryExecution, Search, core feature tests
REQ-MP-003: bounded cluster lifetime/transfer and crash-safe retention AC-MP-007/008 TASK-MP-009; real ClusterReplication persistence, recovery and RF3
REQ-MP-004: bounded streaming caller/report transport AC-MP-009/010 TASK-MP-008; ClientApi and BenchmarkComparisons real contracts
REQ-MP-005: honest integrated qualification and resource measurement AC-MP-011/012 TASK-MP-010/011; exact-SHA GitHub full suites and resource JSON
REQ-MP-006: remove avoidable JSON text byte copies and cached-receive request parses AC-MP-006/009/011/012 TASK-MP-007J under ADR-035; public strict text/byte, Unicode/error, owned lifetime, allocation and real-store replay cases

Existing ResourceExecution test traceability proposal

These links describe the tested subflow only. They do not close a complete AC or qualify the current delivered source. Exact parameterized case IDs, source hashes, line spans, candidate REQ/AC references and per-case limitations are captured in the private R1 review artifact; the R111 census itself was failed/non-final.

Existing requirement / AC Exact source families or method identities Observed contribution and boundary
REQ-RESOURCE-001 / AC-RESOURCE-001; REQ-ADM-001 / AC-ADM-001 CommandAdmissionGovernorTests.CancellationBeforeAdmissionDoesNotConsumeCapacity; HttpAdmissionGovernorTests; AdmissionOwnershipTests.HttpAdmissionRejectsInvalidPathFramingAndPrincipalBeforeReservation; current command-governor cases named in the requirement table above Real governor reservations check bounded node/data/control lanes, verified scope binding, rejection/cancellation accounting and release. Unit admission is not the planned mixed-load RF3 profile.
REQ-ADM-001 / AC-ADM-001 AdmissionOwnershipTests.InvalidCommandReservationArgumentsLeaveEveryCounterUnchanged; DisposingUnresolvedDispatchedCommandReportsUnknownOutcomeAndReleasesOnce Actual invalid reservations leave counters unchanged; unresolved admitted command publishes UnknownWriteOutcome and releases its reservation once. This does not establish current caller integration or AC-ADM-003.
REQ-ADM-002 / AC-ADM-002 AdmissionOwnershipTests.InboxRejectsConcurrentReaderWithoutConsumingTheQueuedSignal; AsyncDisposalStopsAndDrainsRegisteredReaderBeforeRejectingFutureWork; PreCancelledReadIsRejectedBeforeReaderOwnershipEvenAfterStop; AdmittedCommandInboxTests Real inbox single-reader, cancellation, FIFO, control-burst fairness, stop/drain, response cancellation, queue release and bounded reader behavior. AdmittedCommandReadAllocationTests.WarmedPrefilledInboxReadsWithinSmallAllocationWindow is an allocation control, not an AC-ADM-002 numeric criterion.
REQ-MP-002 / AC-MP-004, AC-MP-005 AnalyticalAdmissionTests; BudgetedReadViewTests; ReadBudgetAllocationTests; ReadExecutionBudgetGrant*Tests; ReadExecutionTests Real engine/store reservation, shared read-byte/record debit, limits before reader/callback/materialization, read cancellation and healthy-follow-up subflows. Allocation assertions are scoped observations, not RSS/physical-I/O or performance qualification.
REQ-MP-006 / AC-MP-006; REQ-MP-002 / AC-MP-003 CanonicalJsonTests; CanonicalJsonAllocationTests; JsonPathTests; JsonTextProtocolTests; JsonTextAllocationTests; PreparedScalarTests Exact canonical bytes/fingerprints, pointer/scalar behavior, strict text/byte decoding, malformed-input cleanup, persisted retry and bounded allocation cases. These cover named serializer paths, not all public API transports.
REQ-MP-006 / AC-MP-006; REQ-MSG-001 / AC-MSG-001; REQ-MSG-003 / AC-MSG-003 JsonTextQueueReplayTests and JsonTextSubscriptionReplayTests Actual receive/replay preserves delivery identity, rejects changed raw request/result data, rechecks current principal or subscription generation, and rejects stale lease/token use. This is a replay/lease subset, not the full messaging API or official-client proof.
REQ-ROC-001..004 / AC-ROC-001..004 ReadOnlyCollectionContractTests; ReadOnlyCollectionValidationTests; ReadOnlyCollectionWireTests; CanonicalKeyContractTests; relevant ReadBudgetAllocationTests typed owned-read case Reflection/API shape, exact wire/fingerprint bytes, required collection validation and real independent owned buffers/read results. AC-ROC-005/006 caller-wide build/delivery gates remain separate.
REQ-CACHE-001..004 / AC-CACHE-001..008, AC-CACHE-011..015 (only per-method subset) CacheMemoryBudget*Tests; CacheReadPermit*Tests; ZoneTreeCoordinatedPointCache*Tests; ZoneTreePointCache*Tests Actual budget, permit, ZoneTree cache, owner-gate, coherence, authorization, pin/retirement and wire-primitive subflows as enumerated per case. CacheControlWire*Tests map only to the internal wire primitive AC-CACHE-014. No unit case here proves remote coordinator/RF3 activation, AC-CACHE-009 measured benefit or AC-CACHE-010 full qualification.
REQ-RESOURCE-003/004 / AC-DBPROF-001..004 DatabasePhaseSchemaTests; DatabasePhaseBankTests; DatabasePhaseBankConcurrencyTests; DatabasePhaseArithmeticTests; DatabasePhaseAllocationTests Fixed bank shape, independent lanes, bounded arithmetic/contention/saturation, detached snapshots and configured primitive allocation. These do not prove all 32 production phase boundaries, private capture or overhead/benefit (AC-DBPROF-005..008).
REQ-RESOURCE-003 / REQ-CQ-013; AC-DBPROF-002 / AC-CQ-034/035 DatabasePhaseExecutionOptionsTests Actual central options binding/validation and bank-construction ordering, including malformed/unknown/scalar settings and allowed bounds. This does not qualify enabled production startup or profiling output.
REQ-CQ-013 / AC-CQ-034/035 CurrentPeerOptionsOwnerTests.AcNativePeerDiscoveryConfigurationReachesSocketBeforePhysicalOwnership; AcNativeDiscoveryDeadlineAtRpcBoundaryRejectsBeforePhysicalOwnership Actual IOptions values reach the socket handler and invalid settings reject before creating a physical data directory. Their source comment IDs AC-NATIVE-004..006 do not match the current-format meanings; keep those IDs unmapped until their owner corrects the source traceability.
REQ-AISQL-003 / AC-AISQL-007 SqlAdmissionTests Actual HTTP governor treats SQL as heavy data work, reserves before verified-scope binding, preserves direct-control progress during data saturation and exposes nonrecursive dynamic-effect discovery. Unit evidence does not replace the official .NET/MCP RF3 flow.
REQ-DSTORE-001/002/004; REQ-EVENT-004; REQ-MSG-005; REQ-ROUTE-004; REQ-AUTH-004/005 TransactionTests.DocumentEventAndQueueCommitTogetherAndCommandRetryDoesNotRepeatEffects; UniqueConflictRollsBackDocumentIndexEventAndEnqueue; ConcurrentCompareAndSwapHasOneWinner; SameLiteralPartitionKeyCannotCrossTransactionDomains; TransactionAuthorizationTests Preserve the existing many-to-many associations in DocumentStorage, EventStreams, Messaging, ClusterRouting and Authorization. These are actual single-partition DatabaseEngine operations with narrow effects/denial assertions; they do not prove cross-partition atomicity or RF3. TransactionProtocolTests.MalformedMutationElementsBecomePersistedRejectionsRatherThanApplyExceptions has per-argument candidate rows for document patch, event revision, topic, and sample negatives in the JSON sidecar; each is a narrow malformed-input persisted-rejection subflow, not its owning feature’s complete AC. The null generic mutation and oversized-frame scenario retain their separate proposals/unmapped reason.

The following cases remain deliberately unmapped: core null-argument guards without a current feature AC; the inbox allocation-window control without a declared numeric AC; ReadGateLifetimeTests.AcCq016_DisposalObservesRealGateBeforeLaterStoreUse (the referenced AC-CQ-016 is not currently defined); and ResourceProtocolFailureTests.AcRoc003* (the body tests persisted invalid-resource outcome/replay, while AC-ROC-003 governs owned results/dense-vector efficiency). Do not resolve these by prefix or filename inference. The AC-RESOURCE-002 measured operation/resource requirement, cache-on benefit, full RF3 admission, DB phase capture and all full delivered-source qualification remain open even when their unit subflows pass.

Common storage/resource primitives are shared building blocks. Feature behavior stays in its canonical slice: StorageRecovery, QueryExecution, Search, DocumentStorage, EventStreams, TimeSeries, GraphTraversal, Messaging, ChangeFeeds, ClusterReplication, ClusterRouting, ClientApi and BenchmarkComparisons. New helper and test files use matching Features paths; flat existing paths remain ADR-032 migration debt and may be repaired without expanding that debt. Shared contracts and API/composition/CI/docs have exactly one integration owner.

Strict public-collection prerequisites are governed by ADR-041. REQ-ROC-001..006 / AC-ROC-001..006 map to AC-MP-002/003/004/006/012. The explicit CLR API migration preserves JSON arrays/base64, exact fingerprints and owned buffers; all consumer signatures and dense-vector spans must join before build/CI. New tests use this slice; original business Feature owners retain DTO/operation ownership. The lead-owned strict converter stage delegates the array protocol to the official serializer and attaches only its fresh private arrays without another full copy. Required null/default values reject explicitly; nullable arrays and byte tombstones keep their meaning. See ADR-041 for exact ownership and tests-first join conditions.

flowchart LR
    Caller[SDK or MCP caller] --> Admission[Node resource admission]
    Admission --> ReadCut[Node local consistent read cut]
    ReadCut --> Work[Budgeted scan and point reads]
    Work --> Selection[Bounded feature selection]
    Selection --> Response[Bounded typed streaming response]
    Work --> Counters[Scoped logical resource counters]
    Counters --> CI[GitHub correctness and resource evidence]
Loading

Admission/inbox ownership and the related CLR type migration are governed by ADR-042: REQ-ADM-001..003 and AC-ADM-001..003 extend REQ-RESOURCE-001 / AC-RESOURCE-001 and AC-MP-006/012. TASK-MP-010J owns disjoint admission source/tests; the lead joins actual callers and exact GitHub evidence. Semaphore disposal must follow registered-reader drain.

TASK-ADM-CATALOG-BOOTSTRAP refines REQ-RESOURCE-001 / AC-RESOURCE-001 and REQ-ADM-001 / AC-ADM-001 before integration. Original Linux RF3 startup with a 4,096-byte data ceiling rejects the administrator-authenticated BootstrapPhysicalShardCatalog through the ordinary data lane before the test can exercise its public operations. Classify only that existing system startup command into the existing reserved control lane. Keep its control payload/byte, node/tenant/principal count ceilings, native queue ordering, authentication, authorization, one request grain and RF3 acknowledgement unchanged. The native governor regression must hold a full data reservation, reject another data command without counters changing, admit bootstrap through the bounded control reserve, reject exhausted control capacity, release both leases exactly once and admit a healthy following operation. The existing actual Aspire RF3 AdmissionClusterTests.FullDataBudgetRejectsBeforeCommitWhileControlCommandsAndRf3RoutingStayAvailable must still start all three voters, reject ConfigureResource without claiming its command ID, reuse that ID for the authorized control operation, and report zero settled usage plus ready three-voter routing. No budget increase, bypass, bootstrap retry or alternate dispatcher is permitted. ADR-042 owns the ordered two-file implementation and original Linux qualification; local proof remains development evidence.

No cache may outlive its authority/read cut without explicit invalidation. Mutable storage arrays cannot escape through a borrowing optimization. Cancellation and budgets must stop work before a complete excess page is allocated. Logical work, managed allocation and process working set are different measurements; physical I/O needs real provider/OS evidence. UI/persisted domain-data changes are N/A for the common resource contract; any required retention/transport mutation receives an explicit ADR implementation stage before coding.

Accepted TASK-MP-007E canonical-JSON work

REQ-MP-002 maps AC-MP-006/012 to exact canonical validation and fingerprints used by mutations, signed cursors and replay. Validation retains ordinal property order, duplicate-name rejection, decimal G29 normalization, escaping, object/depth/input byte rules and the existing owned UTF-8-decoded string. Fingerprinting retains raw number spelling and exact lowercase SHA-256 under the same JsonDefaults options. Null fingerprints remain valid; invalid arguments fail before work.

Serialize fingerprints directly to a JsonDocument sharing its pooled serializer buffer, then stream canonical bytes to IncrementalHash. Flush Utf8JsonWriter after each complete value when pending bytes reach a named 64 KiB threshold; a single large token and object-sort metadata remain separately allocated. Validation decodes the used MemoryStream buffer without ToArray. No hard RSS limit, input limit change, storage migration, signature or public API change is implied.

Lead owns JsonData.cs and shared docs; worker owns only new Core/UnitTests Features/ResourceExecution canonical writer/hash adapter and tests. Tests precede code: handcrafted canonical/hash fixtures cover property order, nested arrays, Unicode, null, duplicate names and numeric spelling; real database retries preserve outcomes; warmed allocation growth over many modest tokens detects full-output buffer duplication. Execution is GitHub-only; runtime/resource evidence is pending. Lead moves the existing JSON-pointer parse/escape algorithm into a matching shared helper solely to keep JsonData within the mandatory type limit while repairing its documentation, braces and null guards. Public wrappers, 1,024-character bound, RFC 6901 decoding, missing/scalar distinction and field-patch behavior stay exact; direct pointer/patch acceptance cases join existing real-document regressions.

Accepted progressive report output repair

TASK-MP-008C implements REQ-MP-004, REQ-BC-010 and AC-MP-010/012 under ADR-035/044. The current owned synchronous Cases/Samples converters retain full serialized payloads before SerializeAsync can flush. Private write-only views adapt both collections to native async enumeration over existing immutable arrays. Public ComparisonReport/ComparisonCase, strict read converters, targets, exact JSON schema/property order, every attempt and CSV/Markdown content stay unchanged. Default arrays still reject with the existing JsonException and safe detail.

Tests-first source retains the real-file byte/schema/roundtrip oracle, populates optional provenance/image metadata, and cancels directly in the early-growth observer. The fixed 20,000-by-4,096 sample input stays bounded; partial output must remain below one quarter of its complete raw error-byte lower bound, with no Markdown/CSV. Source audit verifies no sample-array/list/string duplication. The worker owns new BenchmarkComparisons write views/helpers and ReportFileTests.cs; lead alone joins ReportWriter and shared docs. Enabled build/format/governance and complete exact-SHA GitHub tests qualify correctness; matched memory/speed evidence remains open. No public/data/report-version or package migration.

Accepted exact-CI fixture corrections

TASK-RUNTIME-ADMISSION-W preserves REQ-MP-002/005 and AC-MP-004/011/012 under ADR-035. Run37005805424 proves that a held shared read callback does not block another reader. Only the two analytical-admission cases use a new real exclusive ZoneTree Commit callback holder with no staged changes; existing read-lifetime tests retain their original helper. Keep all saturation, independent-engine, in-flight cancellation, cleanup, ten-second bounds and healthy-followup assertions. The worker owns those two test references and the new helper; the lead reviews complete task/holder release before store disposal and qualifies on GitHub.

TASK-RUNTIME-JSON-ORACLES-W keeps REQ-MP-006 / AC-MP-006/012 and ADR-035/041 serializer contracts. Existing direct System.Text.Json byte/text/OperationResult lone-escaped-surrogate cases expect the actual JsonException on all three paths; raw UTF-8 replacement and all strict collection/base64 cases remain unchanged. The embedded benchmark keeps unsorted producer input and expects ordinal canonical stored JSON under ADR-047 / AC-EM-002. Topic quota comparisons use the correct Int64 operands without changing exact-byte, one-byte-short or rollback checks. These are test-oracle repairs, with no new product or persistence decision.

Admission, operations та observability

Accepted TASK-MP-006C analytical-read admission

REQ-MP-002/005 and AC-MP-003/004/011/012 require one fail-fast analytical-read allowance per DatabaseEngine for SQL, AST, both live-query calls and text/vector/ hybrid search. The configured MaxConcurrentQueries must be positive. A new shared Core/Features/ResourceExecution gate uses one bounded atomic count, no wait queue or per-caller dictionary. DatabaseEngine exposes an owned IDisposable reservation and an observational current reservation count through a new partial source file; existing DatabaseEngine.cs remains with its concurrent integration owner.

Acquire checks cancellation before reserving, rejects saturation with the existing ResourceExhausted query-concurrency detail, and compensates if cancellation or allocation fails immediately after the atomic reservation. Dispose releases exactly once. Each operation keeps the reservation across adaptation, authorization, store gate wait, scanning/ranking and final result validation. Existing public result, fingerprint, storage and cancellation contracts stay unchanged; no host clock change.

TASK-MP-006C owns QueryEngine.cs, LiveQueries.cs and SearchEngine.cs admission joins, new Core/Features/ResourceExecution gate/partial files and new UnitTests Features/ResourceExecution admission cases. Lead owns shared docs and final review. Tests first use real ZoneTree read-gate coordination to hold an actual admitted search while SQL/AST/live/search requests and a second engine instance are rejected before storage work. Independent databases remain independent. Direct reservation disposal, invalid limits, pre-/in-flight cancellation, validation/budget errors and a successful following call prove release. Coordination timeouts detect hangs and are not throughput measurements. Tests run in GitHub only; source rollback changes no persisted format or wire and removes the new method/joins together.

Accepted TASK-MP-011A provider diagnostics

TASK-MP-007H additionally owns an internal BudgetedReadView in this slice. It wraps an existing IKeyValueView only inside a committed read action, forwards borrowed callbacks with one cumulative ReadExecutionBudget charge before copy/ decode, and implements the same owned Get/Scan contracts through borrowed work. VisitRange composes a caller observer without double charging and honors both the operation and any method-specific cancellation token. Existing provider budgets, ordering, lookahead, stop flags and callback non-mutation remain unchanged. This adapter reuses persisted authorization helpers; it does not reimplement principal or policy decisions. The shared budget's CreateView(IKeyValueView) exposes that read-only capability under an explicit same-store-action lifetime contract; the concrete adapter remains internal. Direct real-store adapter cases cover every method, observer order/failure, cancellation and healthy follow-up in addition to source-read flows.

REQ-MP-005 / AC-MP-011/012 adds an immutable per-ZoneTreeStore read snapshot with a fresh nonpersisted session ID and cumulative Int64 owned/borrowed point counts, point examined bytes, range attempts, baseline/staged/tombstone entries, logical limit lookaheads and range examined bytes. Counters use constant memory and atomic, saturating increments; a saturated field stops growing and cannot prove later deltas. Snapshots are observational and non-atomic across fields under concurrency; only quiescent isolated real-store test windows provide exact operation deltas.

Point hits count key plus logical value bytes, misses/tombstones key bytes, before copy/observer/decode. A transaction fallback is counted once by the owner; a staged hit is counted once by the transaction. Scan delegates the one range attempt. Range attempts include invalid/pre-cancel calls with zero examined work. Each matching fetched baseline or selected staged entry is counted before cancellation, provider cap or observer rejection, including prefetch, overwrite, tombstone and true live result-limit lookahead. Never-fetched staged peeks and iterator keys outside the range are not examined payloads. Existing StorageScanResult.ReadBytes remains accepted budget work and is distinct from these total attempted counters.

This observes logical provider operations only; native iterator/cache/seek and OS physical I/O remain unmeasured. No keys, paths, identities, payloads or credentials are recorded. Reopen starts a new session; diagnostics do not alter durable data, authorization, gates or wire. Public node/report telemetry is a later lead-owned contract, with canonical and replica store scopes separate.

Lead owns existing provider instrumentation joins and public composition; worker owns new StorageRecovery counter/snapshot helpers and matching real-store tests. Tests precede integration: found/missing/staged/tombstone/failing-observer points, range overwrite/tombstone/prefetch/lookahead/bounds, pre- and mid-cancellation, provider budget failure and healthy subsequent reads. GitHub executes them; no measurement claim follows from authored counters or local static validation.

Актори: data caller, trusted control caller, operator та CI observer. Actual entry points: CommandAdmissionGovernor, HTTP admission, ServiceDefaults telemetry, Aspire composition; shared resource contracts у Admission і HttpAdmission. Public UI N/A; benchmark views належать BenchmarkComparisons.

Вимога Acceptance / flows Test mapping
REQ-RESOURCE-001: node/tenant/principal admission має bounded data lanes та незалежний control reserve AC-RESOURCE-001: concurrent admissions не перевищують ceilings; quota/cancel/auth rejection звільняє reservation exactly once; кілька API keys не обходять principal cap; full data traffic не вичерпує bounded control capacity Existing BytesAndScopesAreReservedAtomicallyAndReleasedExactlyOnce, TenantAndPrincipalCapsCannotBeEvadedWithMoreApiKeys, FullDataAdmissionPreservesBoundedControlCapacity, ConcurrentLoadCannotExceedTheNodeCeilingAndReleasedScopesDoNotAccumulate у CommandAdmissionTests; HttpAdmissionTests; real RF3 mixed-load expansion PLANNED
REQ-RESOURCE-002: operations/telemetry показують фактичні guarantees і bounded work без secrets AC-RESOURCE-002: кожна advertised operation family має exact workload, topology, read/acknowledgement semantics, explicit numeric resource/latency/throughput budget і measured result; bounded low-cardinality counters/timings покривають admission, Orleans hops, quorum/apply wait та logical reads/bytes/scans where applicable; PII/keys/tokens/request IDs відсутні; logical bytes, managed allocations/GC, client working set і per-node CPU/RAM мають окремі names/provenance; unknown measurements are reported unavailable, not zero Source counters alone do not pass. TUnit proves metric names/labels/privacy and configured thresholds; real Docker/Aspire RF3 profiles exercise successful, saturated, rejected, cancelled and slow-consumer/backpressure cases through the .NET SDK and official MCP client. Repeated exact-SHA baseline/candidate JSON must use identical workload, topology and acknowledgement/read guarantees; thresholds are derived from that evidence under AC-MP-011.

Рішення: ADR-010, ADR-028 scheduling time, ADR-031 modular resource isolation, ADR-035. TimeProvider.System залишається host/Orleans clock; operation clock не заморожує cluster runtime. Mixed query/search/graph/event/queue workloads потребують real correctness+liveness tests, а не окремих synthetic doubles.

Shared primitive/config/telemetry composition мають одного integration owner; бізнес-work і matching tests залишаються в owning Features/<SliceName>/. Configuration validation, invalid bounds, zero/empty work, overflow, cancellation/deadline і healthy follow-up входять до AC. Freeze shared limits → real regression source → feature fixes → integrated GitHub gates → actual measurements. Local doc review не доводить numeric coverage, memory ceilings чи performance gain; metrics публікуються тільки з successful GitHub JSON.

TASK-CACHE-EXPIRY-ORACLE: real prepare-origin expiry measurement

REQ-CACHE-EXPIRY-ORACLE-001 preserves REQ-CACHE-004/005 and the existing 15-second prepare-origin lease and 10-second acceptance ceiling. A real-clock test must distinguish prepare age from receipt age while observing the actual permit and native ZoneTree cache. Source clocks, production bounds and persisted authority are unchanged. ADR-058 already specifies this contract; no new boundary or timing semantics are introduced.

AC-CACHE-EXPIRY-ORACLE-001 maps to CacheReadPermitExpiryTests.LeaseExpiresAtFifteenSecondsFromItsPrepareTimestamp and ZoneTreeCoordinatedPointCacheReadTests.ExpiredWarmReceiptFallsBackToOneNativeReadWithIdenticalBytes. Only these two methods are isolated with TUnit NotInParallel. Accept at a measured prepare age of at least six seconds and below the unchanged ten-second ceiling; use monotonic elapsed-time polling with a one-millisecond minimum delay. Observe after prepare age reaches fifteen seconds plus the existing fifty- millisecond boundary margin, and still require receipt age below fifteen seconds. Keep the original thirty-second caller bound, stale capture/revision rejection, renewal proof, identical bytes and exactly one native fallback lookup. Open, seed and compose the real ZoneTree store before starting its lease measurement. Neither a fake clock nor an increased lease/deadline or removed assertion is an acceptable correction. Preserve the two failed original Linux reports from run 37249197752 before recording any new local or exact-source Linux result.

The lead freezes and reviews this scope, joins the source and owns Aspire tests, receipts and commits. The query worker owns a private patch for only the two existing Cases files and, if required, one cohesive real-clock Helpers file. Other test methods, cache admission and production code are outside this stage.

TASK-ADM-RUNTIME-JOURNAL-BOOTSTRAP (2026-10-07)

This narrow refinement of REQ-RESOURCE-001 / AC-RESOURCE-001 and REQ-ADM-001 / AC-ADM-001 follows the actual R199 admission regression. The existing4096-byte user-data ceiling rejects the separately authenticated native RuntimeJournalMutation(BootstrapIdentity) at startup after catalog bootstrap. The fixture never reaches its unchanged user admission assertions. This private startup identity mutation must use the existing bounded control reservation.

Classify only the native OperationKind.RuntimeJournal, typed action BootstrapIdentity and exact current empty bootstrap shape: empty journal name, Guid.Empty instance, zero owner/content revisions, null metadata ETag, empty data, initialized empty set/remove collections. Preserve current native HMAC authority validation, signed RuntimeJournalPurpose, verified principal binding, persisted administrator validation, protected-identity rejection and execution reauthorization. The lane is not authority; no caller-supplied purpose, role or lane flag may grant it. Kind-only RuntimeJournal remains data, as do Create, UpdateMetadata, Append, Replace and Delete. Malformed, unsupported, unauthenticated or oversized candidates must not gain control admission or state effects.

Reuse native generated serialization/inspection and existing shape validation. Bound candidate inspection with the existing control payload ceiling, rejecting large candidates from control eligibility before materializing their body; do not decode large ordinary journal content solely for lane classification, copy a codec or let borrowed proxy strings escape as executable operations. Replica classification remains after native authority and exact payload validation. Record the admitted lane immutably once in the lease/command and route the inbox from that owned reservation, retaining native FIFO and bounded control-burst fairness. Preserve all data/control payload, bytes, count, tenant and principal limits, original cancellation, exactly-once reservation release, unique request grain, ordered node-local ownership and RF3 acknowledgement barriers.

Root freezes ADR-042 and this contract. The Luna worker owns a private guarded packet in Core ResourceExecution/Commands (governor, inbox, lanes, admitted command and a cohesive classifier helper if needed), Replication/ClusterReplication/Admission/ReplicaNativeOperationAdmission.cs, and whole-operation UnitTests/Features/ResourceExecution cases/helpers. A new helper must preserve400-file/200-type/64-method syntax-token limits; do not expand a type or duplicate code to bypass them. Existing signed native APIs, wire fields, aliases, persisted format, dependency and public routes stay exact. Root reviews/joins and owns all native gates.

Required positive/negative/edge flows fill the data reserve, reject a second ordinary mutation without quota/state effects, admit and execute the genuine identity bootstrap through bounded control, reject exhausted control capacity, and complete/fail/dispose/cancel with exact settled counters and a healthy following command. Ordinary journal actions, nonempty bootstrap shape, wrong principal/purpose/native authority and oversized candidates cannot use the startup reserve. Assert actual operation/state and owned queue settlement, not just classifier booleans or getters. Existing journal authority regressions remain mandatory. The unchanged actual native Aspire Docker RF3 AdmissionClusterTests.FullDataBudgetRejectsBeforeCommitWhileControlCommandsAndRf3RoutingStayAvailable must start all three voters, reject data before claiming its command ID, reuse that ID for authorized control, keep3-voter readiness and report settled usage. Run normal/scalar focused operations, full Release/formatter/governance and actual SDK/official MCP RF3, then retain exact-source Linux evidence. All gates remain required; no increased cap, retry, alternate dispatcher or fixture-only authorization bypass repairs this product defect.

The unit saturation cohort must retain valid signed evaluation times when the reserved bootstrap is dequeued before an already-admitted data command. R214 passed98/99 owning cases; the new flow admitted/applied bootstrap successfully, then its earlier-timestamp data command correctly failed the existing ClockUncertain guard. Create the data operation first, sign its bootstrap control peer at that same captured evaluation instant, and create the later malformed/oversized candidates in their eventual apply order. Preserve the production committed-clock check, all authority and capacity assertions, exact state/error expectations and healthy following operations. This is fixture ordering under the existing contract, not a product clock exception.

Local Stage V evidence now passes the actual owning operation cohort99/99 in normal R216 and scalar R217, without skips or source/assembly drift. R219 actual Aspire-owned Docker RF3 admission cases2/2 pass the unchanged data/control assertions through real SDK/MCP callers after native bootstrap admission. R222 full Release remains clean with zero warnings/errors. The original Stage III Linux RF3 node1 admission-exhaustion failure is retained separately; these local results do not qualify full Linux, mixed-load performance or every ResourceExecution acceptance gate. Those remain open.

Independent query output ceiling, TASK-QUERY-RESULT-CAP-001

REQ-QUERY-007 / AC-QUERY-007-JOIN-001 and AC-REL-004-JOIN-004/006 require the literal4096 complete joined-result rejection without disabling native RF3 startup. Authentic run37612238705 attempt1 SHA24c0ac47 job112762012221 retains node1/node2/node3 native startup failures: RuntimeJournalClient.ValidateOptions rejects default MaximumJournalBytes2097152 against MaxBatchBytes4096 minus required EnvelopeMetadataBytes65536. Even a minimum journal cannot fit a negative capacity. These are actual original log diagnostics; no bind or image mismatch is established. Raising4096 or reducing invalid journal quotas is inadmissible.

Freeze before implementation: add nullable positive QueryExecutionOptions.MaximumResultBytes; null applies the existing MaxBatchBytes ceiling, explicit values add a ceiling min(configured, native MaxBatchBytes), never expand it. This is server-owned typed query/read output configuration, not a caller request field, native command budget or persisted format. Existing Core ReadExecutionBudget adds a monotonic result-byte constraint over its original captured limits, cancellation and deadline. It changes only bounded exact UTF8 output counting; it does not restart a clock, native read/work grant, admission lease, authorization or read cut. Default null preserves original calls and clock checks. Callback/page state and complete response accounting remain shared across SQL/AST/SDK/official MCP execution.

Map every existing output owner before implementation: QueryEngine scalar/Q2/model/explain and GraphPath SQL, live-query snapshot/delta, partition query plan/leaf retained grants/merge/public mapping, SearchEngine text/vector/hybrid/graph results and SQL graph search consume the same bound. Existing cumulative selected-result/retained byte checks use the constrained budget; native store scanned-byte/record limits remain unchanged. Exact final serializer accounting includes response metadata and must throw existing BudgetExceeded without a successful partial result. No serialization alias/field IDs, policy/authority, cursors, native journal limits, HTTP input admission or database MaxBatchBytes changes. Existing server native QueryExecutionOptions binding/Validate remains configuration authority.

Ownership: Core ReadExecutionBudget owns monotonic counter constraint; Query QueryExecution/Validation/QueryResultBudgetPolicy.cs resolves/composes the typed ceiling; existing feature execution owners consume it. Integration ClusterFixture gets an explicitly validated query-options overload and feature-local ClusterReplication helper applies only the explicit MaximumResultBytes environment setting to every owned Aspire node before Build. Existing twenty DatabaseLimits properties are unchanged. Result-budget RF3 case keeps4096 and all original source/payload/no-effect/error/healthy SDK/official MCP assertions, configuring only the independent query cap with default valid native batch/journal limits. Existing work/read-byte cases remain unchanged.

Native QueryExecution QueryResultByteLimitTests must execute real scalar and Q2 SQL/AST large-page rejection at4096, default successful baseline, complete persisted-source equivalence and a complete healthy smaller projection with unchanged position; null/default and explicit larger cap cannot expand native MaxBatchBytes. Shared constraint uses original token/deadline and no reset. Root owns guarded join/fresh strict build/native normal/scalar/current RF3 and original Linux gates; this private source stage is unexecuted. Original151/165 report and all node diagnostics remain immutable. No performance/SIMD/durability/readiness claim. Rollback removes this query configuration and its consumer composition, never changes stored bytes, native admission or old outcomes.

TASK-QUERY-RESULT-CAP-002 composition amendment (source-stage; unqualified): REQ-QUERY-007 and AC-QUERY-007-GRAPH-002 require SQL graph parsing, graph owner admission, native graph reachability, selected document/context projection and final protocol serialization to share the original ReadExecutionBudget. QueryEngine may receive a SearchEngine with different frozen options: effective output/retained cap is the monotonic minimum of the original native ceiling, SQL owner configured cap and SearchEngine configured cap. No new clock/start, token, examined-record/read-byte grants or task boundary may replace that parser budget. The public SearchEngine GraphSearchAsync entry still creates its original budget, then delegates to one feature-local internal owned-budget overload; that overload constrains its own frozen output policy, admits with the original initiating token, awaits the original worker, and disposes its actual admission. SQL delegates to that same overload and retains existing final checks. No duplicated dispatcher or worker exists.

AC-QUERY-007-GRAPH-002 maps to SqlGraphSearchResultCompositionTests: actual persisted ZoneTree documents and graph, mismatched caps in both directions, exact projected-search cumulative BudgetExceeded diagnostic before final graph serialization, no returned partial result, complete ordered raw native record bytes and commit position unchanged, then literal healthy graph hit/entity/revision/JSON/rank/empty-expansion oracle under the same owners. This specifically distinguishes early retained projection enforcement from post-allocation wrapper rejection. Root must run native full normal/scalar, focused graph cases and RF3 gates; this amendment does not claim runtime qualification. Rollback removes the shared-budget composition and regression coherently with its accepted query-cap contract; native journal/auth/storage/SQL dialect contracts remain unchanged.

Live delta retained output composition, TASK-QUERY-RESULT-CAP-LIVE-002

REQ-QUERY-001/003, AC-MP-003/012 and REQ/AC-FEED-002/003 under ADR-004/010/013/022/118 require the existing constrained result budget to admit each retained selected live delta before retention. Core keeps its existing public ReadChangeFeedView signature and adds an internal synchronous before-retain overload, invoked only after original request.MaxBytes admits the change and before changes.Add/checkpoint advancement. LiveQueryResultByteAdmission uses exact original budget.MeasureResult and cumulative MaximumResultBytes; overflow is existing QueryEngine.ResultLimitExceeded BudgetExceeded, not partial success. Full wrapper serializer check remains. No operation clock/token/read grants/admission/read cut reset or new request/serialization/persistence field. Install this additional callback only for an explicit configured result cap; null/default preserves old feed behavior.

LiveQueryResultCompositionTests use actual ZoneTree Start->multirow mutation->Read, individually fitting changes whose combined output exceeds4096, exact terminal error/noPartial/fullnative store bytes and position invariance, healthy smaller literal projection and complete checkpoint/cut/receipt/row metadata. A separate original request.MaxBytes page/resume flow proves candidates excluded by original pagination are not charged against retained query cap. Root owns discovery/native normal/scalar/full RF3 proof; source-only packet is unexecuted. Rollback removes internal callback, live admission helper and matching cases together; R2 default cap/native journal/auth contracts remain unchanged.