Skip to content

Commit 24c0ac4

Browse files
committed
feat(query): add bounded Q2 joins and committed scan verification
Execute authorized same-partition typed-row INNER JOIN with explicit Q2/AST2, exact source identities and existing cumulative read/work/result bounds. Verify real concurrent document/index cuts and preserve native MCP schema, persisted field-use/redaction and whole-operation contributor selection. Full local Release and formatter pass. Owning native normal/scalar each606/606 and indexed/idempotency real process recovery2/2 pass with zero skips or source/DLL/PDB drift. Retain original failed observations and honest status: new Q2 public RF3/Linux, full SQL/protocol and complete product coverage remain open; latest original StageVI Linux RF3 has7failed operations.
1 parent 4c48909 commit 24c0ac4

71 files changed

Lines changed: 5706 additions & 345 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/build-and-tests.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -264,12 +264,12 @@ jobs:
264264
'--KeyLoadTests:ReportTrx=true',
265265
'--KeyLoadTests:CoverageSettings=scripts/Features/CodeQuality/functional-coverage.production.settings.xml',
266266
'--KeyLoadTests:CoverageFormat=coverage')
267-
& node @common '--KeyLoadTests:Suite=unit' '--KeyLoadTests:Filter=/*/*/PartitionQuery*/*' `
267+
& node @common '--KeyLoadTests:Suite=unit' '--KeyLoadTests:Filter=/*/*/(PartitionQueryAuthorizationTests|PartitionQueryCancellationTests|PartitionQueryContractTests|PartitionQueryGrantTests|PartitionQueryMcpContractTests|PartitionQueryMergeTests|PartitionQueryPublicAuthorizationTests|PartitionQueryPublicBudgetTests|PartitionQueryPublicContractTests|PartitionQueryPublicMergeTests|SqlInnerJoinBudgetTests|SqlInnerJoinCancellationTests|SqlInnerJoinDeclaredProjectionTests|SqlInnerJoinExecutionTests|SqlInnerJoinLifecycleTests|SqlInnerJoinOrdinalOrderTests|SqlInnerJoinRowAuthorizationTests|DocumentIndexCommittedScanTests)/*' `
268268
'--KeyLoadTests:ResultsDirectory=TestResults/functional-coverage/rf3/unit' `
269269
'--KeyLoadTests:CoverageOutput=TestResults/functional-coverage/rf3/unit/coverage.coverage'
270270
$unitExitCode = $LASTEXITCODE
271271
"unit_exit_code=$unitExitCode" | Add-Content $env:GITHUB_OUTPUT
272-
& node @common '--KeyLoadTests:Suite=unit-scalar' '--KeyLoadTests:Filter=/*/*/PartitionQuery*/*' `
272+
& node @common '--KeyLoadTests:Suite=unit-scalar' '--KeyLoadTests:Filter=/*/*/(PartitionQueryAuthorizationTests|PartitionQueryCancellationTests|PartitionQueryContractTests|PartitionQueryGrantTests|PartitionQueryMcpContractTests|PartitionQueryMergeTests|PartitionQueryPublicAuthorizationTests|PartitionQueryPublicBudgetTests|PartitionQueryPublicContractTests|PartitionQueryPublicMergeTests|SqlInnerJoinBudgetTests|SqlInnerJoinCancellationTests|SqlInnerJoinDeclaredProjectionTests|SqlInnerJoinExecutionTests|SqlInnerJoinLifecycleTests|SqlInnerJoinOrdinalOrderTests|SqlInnerJoinRowAuthorizationTests|DocumentIndexCommittedScanTests)/*' `
273273
'--KeyLoadTests:ResultsDirectory=TestResults/functional-coverage/rf3/unit-scalar' `
274274
'--KeyLoadTests:CoverageOutput=TestResults/functional-coverage/rf3/unit-scalar/coverage.coverage'
275275
$scalarExitCode = $LASTEXITCODE
@@ -281,7 +281,7 @@ jobs:
281281
$recoveryExitCode = $LASTEXITCODE
282282
"recovery_exit_code=$recoveryExitCode" | Add-Content $env:GITHUB_OUTPUT
283283
& node @common '--KeyLoadTests:Suite=rf3' `
284-
'--KeyLoadTests:Filter=/*/*/(PartitionQueryPublicRf3Tests)|(McpDocumentCrudParityTests)/*' `
284+
'--KeyLoadTests:Filter=/*/*/(PartitionQueryPublicRf3Tests|McpDocumentCrudParityTests|RelationalSqlRf3JoinTests|RelationalSqlRf3JoinAuthorizationTests|RelationalSqlRf3JoinBudgetTests|RelationalSqlRf3JoinCancellationTests|RelationalSqlRf3JoinReadCutTests)/*' `
285285
'--KeyLoadTests:ResultsDirectory=TestResults/functional-coverage/rf3' `
286286
'--KeyLoadTests:CoverageOutput=TestResults/functional-coverage/rf3/coverage.coverage' `
287287
'--KeyLoadTests:NativeCoverage:ServerMode=rf3-original-node-v1' `

‎AGENTS.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -450,6 +450,7 @@ For changes outside existing owner authorization, obtain direction before changi
450450
- Owner correction 2026-10-04 separates database measurements from website testing: Benchmarks owns native database preparation, independent workloads, result validation and authenticated JSON aggregation. Chrome, browser/site tests and website qualification MUST NOT be benchmark dependencies. A separate website-build action may run after the JSON is ready or be triggered through CI; the owner explicitly permits static site building at the end of Benchmarks. The selected implementation uses independent CI website jobs on own-main push/manual and completed Benchmarks events. Every website build MUST use the newest completed own-main Benchmarks run and its successful authenticated aggregate, across push/manual producers, rather than blindly using the triggering run or falling back after invalid latest evidence. Preserve exactly three workflows, failed/null cells, original provenance, website gates and predeploy freshness. Website failure cannot block database metrics production. This supersedes earlier integrated qualification placement and the interim static-build prohibition. KeyLoad engine implementation remains owned by the other agent.
451451
- Complete the coherent task's implementation before executing its runtime tests or benchmarks. Author the mapped tests with the code, then run the required validation after the implementation and self-review; do not let repeated intermediate verification replace implementation progress. This owner correction2026-10-03 supersedes test-first execution for the current work while preserving every final correctness, CI, fault and performance gate.
452452
- Owner reiteration 2026-10-04 requires concurrent feature implementation with three to five capable Luna coding agents when slots permit. Keep independent pending product tasks moving while the lead integrates and verifies completed stages; a long test run or unfinished qualification of one feature MUST NOT block implementation of unrelated features. Use disjoint write scopes and stable compiled test snapshots, retain every acceptance gate, and close each task as soon as its own complete acceptance evidence exists rather than waiting for the entire plan.
453+
- Owner correction 2026-10-07 requires parallel batches of complete-operation test creation, execution and fixes across independent acceptance scopes. For this work the owner explicitly authorizes GPT-6.1 Sol workers with low effort in place of the earlier Luna selection. Keep available worker slots occupied with concrete disjoint scopes while the lead reviews, integrates and delivers batches. Read-only execution of already compiled native TUnit suites may run concurrently only with distinct result/temporary paths, independent owned resources and unchanged source/DLL/PDB identities; serialize builds, shared source joins and any conflicting Aspire/image lifecycle. Preserve whole-flow assertions and every existing acceptance, provenance, cleanup and delivery gate.
453454
- Each agent MUST follow the execution plan for its own user-assigned task and complete only that task; change its scope only when the owner explicitly redirects it (owner correction 2026-10-03).
454455
- Other chats' plans, progress, requests and concurrent changes MUST NOT expand an agent's task or redirect its implementation. Preserve their work and leave their tasks to their owners (owner correction 2026-10-03).
455456
- Repairs and verification MUST stay within the assigned task. Report an unrelated failure to the owner without taking over its implementation; direct user instructions remain authoritative (owner correction 2026-10-03).

‎README.md‎

Lines changed: 34 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -338,40 +338,38 @@ The accepted tasks are **KL-007** storage codecs, **KL-010** document CRUD/CAS a
338338
source, including real process retries and task-specific SDK/MCP RF3 operations.
339339
Their acceptance does not qualify the remaining features or the complete cluster.
340340

341-
The [latest completed Linux RF3 cohort](https://github.com/managedcode/KeyLoad/actions/runs/37578573276/job/112652868979)
342-
recorded **122/132**, with ten failed operations. Coverage collection and merge
343-
were skipped after that failure. The [same run's Linux verify job](https://github.com/managedcode/KeyLoad/actions/runs/37578573276/job/112652908001)
344-
passed normal and scalar **2,767/2,768** and recovery **235/235**, without skips.
345-
Its sole unit failure is an incorrect expected rejection in the C1 fixture; the
346-
correction passes locally and awaits fresh complete Linux verification.
347-
Local Stage V passed **99/99** owning unit
348-
operations in each mode and actual Aspire RF3 SDK/MCP admission, backup/restore
349-
and queue dispatch flows, in separately retained source/image cohorts.
350-
351-
Stage VI has joined whole-operation query-factory, indexed-document backup/dedup,
352-
scalar-index process-recovery and six-resource membership configuration work.
353-
A fresh isolated restore now selects all **264** package/version archives from
354-
NuGet.org with zero unresolved package/license inventory rows. The corrected
355-
compile-identity target passes actual native builds with both package-root forms
356-
and rejects a counterfeit defining import. The complete Release build and native
357-
formatter pass; owning native normal/scalar flows each pass **10/10**, and real
358-
indexed/idempotency process recovery passes **2/2**, without source/assembly drift
359-
or skips. These are focused local results; a new complete Linux run is required.
360-
Bounded Q2 relational INNER JOIN and a
361-
TUnit-owned fresh-image six-silo flow have frozen contracts and private source
362-
stages; neither is runtime-qualified yet. KL-075 scaling, full SQL/client protocol,
363-
complete Linux RF3, functional coverage, endurance and release gates remain open.
364-
The [implementation status](docs/implementation/status.json) retains original
365-
failures, source hashes and each qualification boundary.
341+
The [latest completed Linux RF3 cohort](https://github.com/managedcode/KeyLoad/actions/runs/37590715245/job/112691267500)
342+
recorded **151/158**, with seven failed operations. Coverage collection and merge
343+
were skipped after that failure. The [same run's Linux verify job](https://github.com/managedcode/KeyLoad/actions/runs/37590715245/job/112691308536)
344+
passed normal and scalar **2,771/2,771** and recovery **236/236**, without skips.
345+
These results bind to Stage VI commit `4c48909`; they do not qualify later edits.
346+
Stage VII has joined bounded Q2/AST2 relational INNER JOIN, real concurrent
347+
committed document/index scanning, strict native MCP schema oracles and exact
348+
functional contributor selection. The final full Release build and formatter
349+
pass with zero warnings, errors or source drift. Owning normal/scalar operations
350+
each pass **606/606**, and real indexed/idempotency process recovery passes
351+
**2/2**, with unchanged source/DLL/PDB identities and no skips. These are local
352+
owning subsets. New public Q2 RF3 and complete current-source Linux qualification
353+
remain open; the Stage VI results above predate these additions.
354+
355+
Three GPT-6.1 Sol workers prepare disjoint implementation and whole-operation
356+
verification batches while the integration owner runs stable compiled cohorts.
357+
The next reviewed source packets contain **52 JOIN rejection scenarios** and
358+
TUnit-owned fresh-image preparation/shutdown for standard RF3 and six silos;
359+
these packets have not been integrated or executed yet. Full SQL/client protocol,
360+
FK, KL-075 scaling, complete RF3, functional coverage, endurance and release gates
361+
remain open. The [implementation status](docs/implementation/status.json) retains
362+
original failures, source/report hashes and each qualification boundary.
366363

367364
Functional coverage excludes load/comparison runs and admits complete operation
368-
flows only. The current Query profile binds exactly 25 named cases and 103 source
369-
files; fresh current-source coverage is pending. Scoped local KeyCodec coverage
370-
records **202/203 executable lines** across three files, with all19 native cases
371-
passing normal and scalar. Its branch coverage is unmeasured. The complete
372-
sixteen-module/RF3-server cohort remains unmeasured. See the
373-
[coverage contract](docs/Features/CodeQuality.md) for source/contributor binding,
374-
native report preservation and complete-operation test requirements.
365+
flows only. The current registry selects **94 contributors**: 41 normal, 41
366+
scalar, one recovery and eleven RF3 cases. Selection is not measured coverage.
367+
The first historical Query profile bound 25 cases and 103 source files. Scoped
368+
local KeyCodec coverage records **202/203 executable lines** across three files,
369+
with all 19 native cases passing normal and scalar; branch coverage is unmeasured.
370+
The complete sixteen-module/RF3-server product cohort remains **unmeasured**.
371+
See the [coverage contract](docs/Features/CodeQuality.md) for source/contributor
372+
binding, native report preservation and the required product-admission flow.
375373

376374
| Ready to try (in source, covered by tests) | Still in progress |
377375
|---|---|
@@ -387,13 +385,13 @@ Full-text search comes from [ZoneTree.FullTextSearch](https://github.com/ZoneTre
387385
Native Orleans [runtime adoption](docs/Features/ClusterRouting/RuntimeAdoption.md)
388386
and [journal-backed Durable Jobs](docs/Features/ClusterRouting/RuntimeJournal.md)
389387
are being integrated. The source includes due-work wakeups, bounded telemetry,
390-
local lifecycle ownership and saga timeout jobs; current-source build and runtime
391-
qualification remain in progress. Native
388+
local lifecycle ownership and saga timeout jobs. The current solution build
389+
passes; complete native runtime qualification remains in progress. Native
392390
job restart/adoption and real SDK/MCP RF3 fault qualification remain open.
393391

394392
Runtime timeouts, retries and resource limits use centrally validated typed options. The [configuration contract](docs/ADR/ADR-113-centralized-runtime-options.md)
395-
also covers the SDK, CLI and Aspire host; complete build and runtime verification
396-
of the current source remain pending.
393+
also covers the SDK, CLI and Aspire host. The full current solution builds;
394+
complete runtime and original Linux qualification remain pending.
397395

398396
For detailed status, see the [implementation tracker](docs/implementation/status.json) and the [qualification records](docs/implementation/). We publish performance numbers only from real GitHub Actions runs, on the [website](https://www.keyload.cloud/).
399397

‎docs/ADR/ADR-033-code-quality.md‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -173,3 +173,39 @@ TASK-CQ-FUNCTIONAL-UNIT-INVENTORY-043 joins temporary-directory creation to the
173173
TASK-CQ-FUNCTIONAL-UNIT-INVENTORY-043 inventory validation preserves native multi-case declaring classes and byte-preserving benchmark transfer namespaces. Distinct declaring classes still obey the frozen positive selector identity contract. The exact physical ComparisonTests source path/hash establishes moved-case ownership; preserved UnitTests namespaces are not functional coverage authority. Case identities remain unique and all functional census/positive-group parity and exclusion checks remain mandatory.
174174

175175
The 2026-10-07 report-display amendment to TASK-CQ-FUNCTIONAL-UNIT-INVENTORY-043 records the declared CLR `className` from original TRX separately from exact original MTP `nativeReportClassName` on each functional inventory row. Native TUnit tree selectors use the former; fixture display suffixes remain untouched in the latter. The linked CodeQuality contract freezes the extra field's bounds, one-to-one report/TRX/source joins, unchanged moved-case shape and mandatory successful census/group parity. Ordered stages are contract freeze, private two-script producer repair and native draft reconciliation, one coherent inventory/producer/workflow join, strict build/format/parser checks, and original complete Linux coverage plus ProductAdmission qualification. Root owns integration; the Luna worker owns only `functional-coverage.native-merge.contributors.ps1` and `functional-coverage.native-merge.functional-report.ps1` within the existing stage. Rollback removes the coherent amendment without introducing a fallback alias reader. Public APIs, persisted formats, dependencies and all existing thresholds are unchanged; failed draft evidence remains unqualified.
176+
177+
178+
## Q2 whole-operation contributor integration
179+
180+
TASK-CQ-Q2-CONTRIBUTOR-044 and AC-CQ-Q2-CONTRIBUTOR-001 continue REQ-CQ-009 /
181+
AC-CQ-044/046/047 under the matching CodeQuality contract frozen 2026-10-07.
182+
Root joins the 37 additional exact operation rows in the existing product
183+
contributor registry and the native report reader as one coherent stage. The
184+
Luna reader owner extends only the exact RF3 display/CLR/fixture/native-ID join
185+
for the four constructor-data Q2 classes and the one parameterless budget
186+
class; preserve the two existing exact mappings, original TRX/source checks,
187+
rejection behaviour, schemas and bounds. It is current pinned-TUnit identity,
188+
not a stored database format or compatibility path.
189+
190+
Ordered stages: freeze this feature/ADR contract; review disjoint guarded JSON
191+
and one-script proposals; run strict build/format and native whole-flow tests;
192+
require original complete Linux normal/scalar/recovery/RF3 and the required
193+
ProductAdmission original-admit/controlled-denial/immutability/re-admit/cleanup
194+
operation before qualification. Source review is the explicit exception for
195+
unchanged strict native-ID denial branches, with genuine matching RF3/report
196+
results mandatory. Root owns final source/report/compiled-image verification,
197+
status and delivery. Rollout and source rollback keep registry and reader
198+
coherent; all numeric coverage, no-decrease, provenance and original-report
199+
gates remain mandatory. No source-only inventory check qualifies execution.
200+
201+
The Stage VII audit confirms ProductAdmission is specified but absent from the
202+
current Product/ToolingProof entry and CI. NativeCoverageMergeTests proves CLI
203+
tooling collection/merge, not product admission. Implementation and the required
204+
whole native-evidence flow remain mandatory open work, alongside the complete
205+
inventory/census descriptor amendment. Root repairs the three existing CI
206+
functional collection selectors to consume the 92-row Q2 registry coherently;
207+
all ordinary suites, server collectors, source/image/report identity, module
208+
completeness and numeric gates stay intact. The separate AC-CQ-018 first-profile
209+
contract is preserved. Luna owns a private one-workflow selector patch, root
210+
reviews and joins it before delivery; no fabricated native evidence or coverage
211+
claim is permitted. A rollback removes registry, reader and selectors together.

0 commit comments

Comments
 (0)