Skip to content

Commit 259a3fa

Browse files
committed
Cover malformed persisted keys and correct native MCP schema oracles
1 parent 922a9f3 commit 259a3fa

13 files changed

Lines changed: 396 additions & 40 deletions

File tree

‎docs/ADR/ADR-005-canonical-keyspace-codec.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -125,3 +125,20 @@ failures remain visible and RF3/endurance/power-loss gates remain separate.
125125
Verification comprises the existing native source-ownership regressions,
126126
workflow static checks, and the original Linux artifacts. Rollback removes only
127127
the additive workflow receipt steps; no storage or runtime rollback is needed.
128+
129+
TASK-KEYCODEC-COVERAGE-GAPS implements the existing REQ/AC-KEYCODEC-002/003 in
130+
StorageRecovery. Root freezes the source-bound199/203 local line baseline and
131+
reviews the final join; cli_static_collection Luna owns only
132+
`UnitTests/Features/StorageRecovery/Cases/KeyCodecMalformedContractTests.cs`.
133+
First add independent persisted NaN/infinity, unterminated text/binary, invalid
134+
decimal digit and30-digit vectors to one whole rejection/unchanged-bytes/healthy
135+
roundtrip operation. Then build and execute the original native codec cases in
136+
normal/scalar mode and collect actual scoped coverage with unchanged source and
137+
test/product DLL/PDB identity. Root updates the real native case roster and
138+
retains current-source Linux normal/scalar and full recovery originals before
139+
KL-007 closure. Constant-only token files are executable-coverage N/A; a native
140+
report without branch outcomes cannot establish branch coverage. Keep the final
141+
decimal representability guard even if the preceding canonical-domain checks
142+
make it unreachable; coverage does not authorize altering the implementation or
143+
adding artificial private calls. Production storage/format/trust/topology and
144+
dependency changes are N/A. Rollback removes only the added regression flow.

‎docs/ADR/ADR-039-official-mcp-agent-api.md‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -319,3 +319,33 @@ response is introduced. Public API, persistence and dependencies are unchanged.
319319
Original failed assertions remain failures. Fix their owning schema/oracle only
320320
after actual payload evidence establishes the defect; no compatibility reader
321321
or permissive integer/nullability fallback is authorized.
322+
323+
TASK-MCP-NATIVE-SCHEMA-ORACLE implements REQ/AC-CLIENT-006, AC-MCP-001 and
324+
REQ-GRAPH-010 / AC-GRAPH-009 using original876c run37546085722 input captures and
325+
the unchanged JsonDefaults.Web decoder/exporter. Root freezes and joins the
326+
ClientApi contract; ci_failure_evidence Luna owns only the existing
327+
IntegrationTests GraphIncomingMcpSchemaAssertions,
328+
PartitionQueryMcpSchemaAssertions and McpGraphPathInputSchemaAssertions.
329+
First review exact integer string/integer, Labels array/null and optional
330+
computed AtomicPartitionId string/null projections against native metadata.
331+
Then correct exact-set oracles, rejecting duplicates/extra types while retaining
332+
all required fields, item schemas, hints, bounded references and actual official
333+
SDK discovery/invocation flows. The four required PartitionRef constructor
334+
identity fields and recomputed authority are unchanged. Input/output use the
335+
same native exporter options; source review cannot qualify an uncaptured output
336+
execution. Root joins full build/quality review and actual Aspire RF3/Linux
337+
originals. No public API, persistence, topology, dependency or trust change,
338+
compatibility reader or permissive type fallback is introduced. Rollback restores
339+
only prior test oracles; original failed outcomes remain historical failures.
340+
341+
TASK-MCP-NATIVE-FAILURE-CODE maps REQ/AC-CLIENT-006 and AC-MCP-003/005/007 to
342+
the existing official-client success/error flows. Root owns the ClientApi
343+
contract and join; ci_failure_evidence Luna changes only McpCallerAssertions.cs.
344+
Reuse the existing closed enum validation to append actual safe errorCode and
345+
its mapped HTTP status to the unchanged failed-success assertion, bounded below
346+
128 UTF-8 bytes. Unknown/malformed envelopes use fixed Unclassified text; no
347+
detail, result, request ID, credentials, new signature or alternate decoder.
348+
First review the native envelope, then build and execute real Aspire RF3 flows,
349+
retaining exact-source Linux originals. The known timeout failure remains
350+
unqualified until its actual cause and full saga outcomes are verified. No
351+
production/trust/persistence/dependency change. Rollback removes only the reason.

‎docs/Features/Authorization.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ the cluster control boundary is defined by [ADR-036](../ADR/ADR-036-orleans-foun
1616

1717
| Native case class | Existing requirement / acceptance | Evidence boundary |
1818
|---|---|---|
19-
| `ClusterPrincipalPolicyTests`, `ClusterPrincipalInitializationIntegrityTests` | REQ-AUTH-002 / AC-AUTH-002 | Protected internal-principal bootstrap/idempotence, public edit/credential denial, snapshot copy, and missing/modified/corrupt row rejection at an existing apply cut. This is local store/snapshot evidence, not quorum or RF3 proof. |
19+
| `ClusterPrincipalPolicyTests`, `ClusterPrincipalInitializationIntegrityTests`, `StorageRecovery.PartitionHostRecoveryTests.MissingProtectedPrincipalInVerifiedPendingImageRejectsHostAndSafeRetry`, `ModifiedProtectedPrincipalInVerifiedPendingImageRejectsHostAndSafeRetry`, `ValidProtectedPrincipalInVerifiedPendingImageOpensAtRecoveredCut` | REQ-AUTH-002 / AC-AUTH-002 | Protected internal-principal bootstrap/idempotence, public edit/credential denial, snapshot copy, and missing/modified/corrupt row rejection at an existing apply cut. The three StorageRecovery cases exercise a real verified pending-image install: absent/modified principal state rejects both host-open attempts; valid principal state is present after install/reopen. This is local store/snapshot evidence, not quorum or RF3 proof. |
2020
| `ClusterPrincipalAuthorizationTests` | REQ-AUTH-003 / AC-AUTH-003 | Ordinary/public internal-membership denial, internal data/security denial, and internal membership after public-root revocation. |
2121
| `DocumentRowTenantMutationAuthorizationTests` | REQ-AUTH-005 / AC-AUTH-005, with the owning document boundary REQ-DSTORE-003 / AC-DSTORE-003 | Put/Patch/Delete cannot forge row owner or tenant. It does not cover all row-scoped read/query adapters. |
2222
| `DocumentFieldMutationAuthorizationTests`, `DocumentReplacementFieldAuthorizationTests`, `DocumentDeleteIndexAuthorizationTests` | REQ-AUTH-006 / AC-AUTH-006, with the owning document boundary REQ-DSTORE-003 / AC-DSTORE-003 | Persisted field-write and index-use grants are independently enforced on the tested mutation paths; this is not the complete adapter/lineage matrix. |

‎docs/Features/BackupRestore.md‎

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
11
# BackupRestore
22

3-
TASK-SQLC-NATIVE-JOIN / AC-SQLC-011 under
4-
[ADR-065](../ADR/ADR-065-full-sql-client-compatibility.md) closes the omitted restore
5-
caller for ADR-060's two-argument native backup verifier. This remains the
6-
BackupRestore slice under REQ-BACKUP-002 / AC-BACKUP-002 and AC-IS-004. Root joins
7-
the existing private staged restore; BackupRestoreStagingJoinTests adds genuine
8-
absent/empty-target positive byte/source/readability/identity/pause/cleanup proof,
9-
with all delivered NativeBackupCut negatives and recovery checks retained.
10-
No new format or migration is defined; exact-source GitHub execution is pending.
3+
The native staged-restore caller remains in the BackupRestore slice under
4+
REQ-BACKUP-002 / AC-BACKUP-002. `BackupRestoreStagingJoinTests` directly invokes
5+
the native ZoneTree restore; despite its historical `AcSqlc011` method label, it
6+
does not execute a SQL client operation and is not evidence for AC-SQLC-011.
7+
Its absent/empty-target flows support AC-BACKUP-002 clean-target publication and
8+
the identity/paused-dispatch portion of AC-BACKUP-003, with byte/readability and
9+
cleanup assertions. They do not establish every old cursor/lease invalidation or
10+
operator-reconciliation requirement. Delivered NativeBackupCut negatives and
11+
recovery checks remain distinct. No new format or migration is defined;
12+
exact-source GitHub execution is pending.
1113

1214
AC-CQ-018 preserves the complete original ManagedCode file-storage transfer byte
1315
oracle in ArtifactTests through ordered content equivalence under pinned TUnit.
@@ -70,14 +72,16 @@ cluster-cut, power-loss, bounded-manifest-memory or performance claim.
7072
| Requirement | Measurable acceptance | Existing or planned evidence |
7173
|---|---|---|
7274
| REQ-BACKUP-001: produce and package a verifiable offline backup | AC-BACKUP-001 passes when a backup includes its manifest/checksums, archives in bounded pieces, and round-trips canonical files. Separate planned resource verification must measure bounded streaming/peak-memory behavior before making a memory-bound claim. | Existing test source: `ArtifactTests.ChunkedCartographBackupRoundTripsAndManagedCodeStorageTransfersIt` checks multi-piece round trip and copy. Planned real-file resource-bound verification; current GitHub TUnit qualification pending. |
73-
| REQ-BACKUP-002: restore only verified data to a clean target | AC-BACKUP-002 passes when a valid backup restores canonical data to a clean location; missing/tampered files and nonempty or unsafe destinations fail without publishing a usable partial database. | Authored real-operation source includes `CliBackupRestoreInvalidCatalogTests`, `CliBackupRestoreLengthMismatchTests`, `CliBackupRestoreMissingInputTests`, `CliBackupRestoreFlowTests`, `ArtifactTests`, and `RecoveryTests.VerifiedBackupRestoresDataWithNewIdentityAndPausedDispatch`. These cover noncanonical catalog rejection, actual rejected output restore, missing required inputs, nonempty destination, original-byte/state preservation, and healthy restore/reopen controls. Exact-source Linux execution remains pending; path-traversal/reparse-specific and resource-bound evidence remains distinct and open. |
75+
| REQ-BACKUP-002: restore only verified data to a clean target | AC-BACKUP-002 passes when a valid backup restores canonical data to a clean location; missing/tampered files and nonempty or unsafe destinations fail without publishing a usable partial database. | Authored real-operation source includes `CliBackupRestoreInvalidCatalogTests`, `CliBackupRestoreLengthMismatchTests`, `CliBackupRestoreMissingInputTests`, `CliBackupRestoreFlowTests`, `BackupRestoreStagingJoinTests`, `ArtifactTests`, and `RecoveryTests.VerifiedBackupRestoresDataWithNewIdentityAndPausedDispatch`. StagingJoin directly tests native ZoneTree restore into absent/empty targets and supports this AC's clean-target behavior; its `AcSqlc011` name does not make it an SQL-client test. These cases cover noncanonical catalog rejection, actual rejected output restore, missing required inputs, nonempty destination, original-byte/state preservation, and healthy restore/reopen controls. Exact-source Linux execution remains pending; path-traversal/reparse-specific and resource-bound evidence remains distinct and open. |
7476
| REQ-BACKUP-003: fence old identity and pause delivery after restore | AC-BACKUP-003 passes when restore produces a different incarnation, sets dispatch paused, and invalidates old cursor/lease identities until explicit operator reconciliation. | Existing `VerifiedBackupRestoresDataWithNewIdentityAndPausedDispatch`; planned auth/feed/lease token invalidation and explicit resume integration cases. |
7577
| REQ-BACKUP-004: restore a declared cluster cut with capability invariants | AC-BACKUP-004 passes when a captured per-partition cut restores document/event/outbox/inbox/queue/group state consistently, reports unavailable history explicitly, and performs no automatic external redelivery before resume. | Planned Docker/Aspire RF3 backup/restore and process-recovery scenarios under KL-042/KL-098; no current test or GitHub artifact establishes this acceptance. |
7678
| REQ-BACKUP-005: bound local metadata and parse the verified identity region once | AC-BSM-001..005: inclusive16KiB manifest/4KiB identity limits, same-owned-region outer/inner checksum, preserved error/destination/lock ordering and real allocation/restore proof | [ADR-048](../ADR/ADR-048-bounded-storage-metadata.md), [acceptance](../ADR/ADR-048-bounded-storage-metadata.md) and [task graph](../ADR/ADR-048-bounded-storage-metadata.md); Metadata* real-file test source and exact-SHA GitHub qualification pending |
7779
| REQ-BACKUP-006: publish an unpacked archive only after complete native validation | AC-BACKUP-006 passes when first/last entry length failures leave an initially absent destination absent or an initially empty destination empty, the real CLI cannot restore either failed output, and the unchanged original archive still restores canonical data with a new incarnation and paused dispatch. All handles and owned cleanup settle; primary and cleanup failures are preserved. | Authored complete real CLI flow: `CliBackupRestoreLengthMismatchTests.AcBackup006CliLengthMismatchCannotPublishRestorablePartialBackup`, plus `CliBackupRestoreMissingInputTests.AcBackup002CliMissingRequiredBackupFilesRejectWithoutPublicationAndRestoreAfterRepair`; see TASK-BACKUP-UNPACK-PUBLICATION-001, TASK-BACKUP-CLI-MISSING-INPUT-002 and [ADR-114](../ADR/ADR-114-verified-artifact-publication.md). Source and tests exist; actual execution and all required Linux qualification remain pending. |
7880

7981
### Functional CLI operation coverage
8082

83+
`BackupRestoreStagingJoinTests.AcSqlc011AbsentTargetPublishesNativeCutAndPreservesEveryBackupByte` and `AcSqlc011ExistingEmptyTargetPublishesNativeCheckpointAndPreservesEveryBackupByte` each have two trailing-separator cases. Their bodies directly call the native restore API, reopen the target, verify new identity/incarnation, paused dispatch, restored data and exact archive bytes. Map them to REQ-BACKUP-002 / AC-BACKUP-002 and the identity/pause portion of REQ-BACKUP-003 / AC-BACKUP-003 only. They do not exercise SQL, so the source's AC-SQLC-011 label is not an acceptance mapping. The cases do not close the complete cursor/lease fencing and operator reconciliation parts of AC-BACKUP-003. Their original native report rows remain failed-cohort historical evidence until current-source normal/scalar qualification.
84+
8185
TASK-GENERAL-OPTIONS-RESTORE-INPUT-001 maps REQ-BACKUP-002 / AC-BACKUP-002 to
8286
`MissingBackupManifestTests`: the real embedded restore normalizes only a missing
8387
manifest or its directory to the existing `FormatUnsupported` Problem and fixed

‎docs/Features/ClientApi.md‎

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -242,3 +242,42 @@ and uploaded `artifacts/qualification/mcp-schema-evidence/` ownership. Root owns
242242
contract, review, native RF3 evidence and delivery; a Luna worker prepares the
243243
guarded helper/calls. Schema capture alone is diagnostic evidence, not a passing
244244
operation or an authorization to relax assertions or alter production schemas.
245+
246+
TASK-MCP-NATIVE-SCHEMA-ORACLE repairs the three test observations established by
247+
the original876c official-client captures in run37546085722. It retains
248+
REQ/AC-CLIENT-006, AC-MCP-001 and REQ-GRAPH-010 / AC-GRAPH-009. JsonDefaults.Web
249+
accepts quoted integers and the native schema projection copies those options;
250+
integer schemas therefore have the exact string/integer type set. Nullable
251+
Labels has the exact array/null set with string items. PartitionRef's optional
252+
computed AtomicPartitionId is getter-only: its captured string/null input
253+
projection cannot supply authority or replace the four required constructor
254+
identity fields. Their required set and the computed output value remain fixed.
255+
256+
Root owns the contract and joins. ci_failure_evidence Luna owns only
257+
GraphIncomingMcpSchemaAssertions, PartitionQueryMcpSchemaAssertions and
258+
McpGraphPathInputSchemaAssertions in their current IntegrationTests slices.
259+
Compare exact allowed sets, rejecting duplicates and extra types; distinguish
260+
the optional computed metadata field from required identity strings. Preserve
261+
all property/required-member/item/effect-hint/catalog checks and native official
262+
client flows. Native output uses the same unchanged exporter options; review its
263+
current source shape and retain output execution as unqualified until the actual
264+
RF3 flow passes. No production schema, decoder, public contract, dependency or
265+
trust change is authorized by this test repair. Root builds, reviews, executes
266+
the real Aspire RF3 SDK flows and retains exact-source Linux original reports.
267+
Rollback removes only the oracle corrections, preserving captured failure
268+
evidence and every mandatory suite. UI/storage changes are N/A.
269+
270+
TASK-MCP-NATIVE-FAILURE-CODE supports REQ/AC-CLIENT-006 and AC-MCP-003/005/007
271+
after the original876c saga-timeout RF3 invocation returned IsError without its
272+
safe classification in the failed assertion. Root freezes and joins; a Luna
273+
worker owns only IntegrationTests/Features/ClientApi/Assertions/McpCallerAssertions.cs.
274+
The existing SuccessAsync assertion may read only the actual StructuredContent
275+
errorCode, reuse its closed canonical enum validation and append that code with
276+
the mapped HTTP status. Malformed/unknown envelopes produce fixed Unclassified
277+
text. Keep the reason below128 UTF-8 bytes; never print detail, result, request ID,
278+
tool arguments or credentials. No parallel Problem decoder, changed signatures,
279+
guessed expected code or relaxed success/error assertions. The original test
280+
identity/call-site supplies operation context; CallToolResult contains no tool
281+
name. Root builds and retains actual official-client Aspire RF3/Linux outcomes;
282+
this observation cannot qualify the saga or repair its unknown initiating cause.
283+
Production/format/dependency changes are N/A. Rollback removes only this reason.

0 commit comments

Comments
 (0)