You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 922a9f3
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/ADR/ADR-106-partition-owner-movement.md
+19Lines changed: 19 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -222,3 +222,22 @@ integration, strict checks, original Linux RF3 evidence and commit. No stored-da
222
222
an unmapped route or undisposed owner cannot be reported as delivered membership.
223
223
224
224
Ownership movement and current same-view session tokens retain the contract in [ADR-017](ADR-017-ownership-session-tokens.md). Unknown or unverifiable lineage invalidates explicitly.
225
+
226
+
## Native immutable-image oracle repair
227
+
228
+
TASK-MEMBERSHIP-IMAGE-ORACLE implements the existing AC-MEMBERSHIP-006 pre-start
229
+
identity check using pinned Aspire13.6.0 semantics. The native
- ADR-117 and the root's latest native-entry correction supersede the earlier outer AppHost test commands here. CI invokes native TUnit/Microsoft.Testing.Platform directly after build with Detailed output; C# fixtures own Aspire startup, readiness, discovered endpoints, real client workloads and joined cleanup. `scripts/Features/TestInfrastructure/run-tests.mjs` selects native arguments and environment only. Preserve every required suite, original report, exact-source Linux gate and development/qualification distinction.
28
+
- The canonical current Build and Tests workflow is `.github/workflows/build-and-tests.yml`; historical `ci.yml` references above are not current dispatch instructions.
Copy file name to clipboardExpand all lines: docs/Features/Authorization.md
+18Lines changed: 18 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,6 +11,24 @@ the cluster control boundary is defined by [ADR-036](../ADR/ADR-036-orleans-foun
11
11
| REQ-AUTH-002: public credential changes cannot disable or impersonate the cluster's membership authority | AC-AUTH-002: a persisted protected internal principal has no public API key; even an administrator cannot edit it or create a credential for it; revoking a public administrator does not revoke internal membership |
12
12
| REQ-AUTH-003: internal authority can perform only its approved membership control operation | AC-AUTH-003: ordinary callers cannot submit Membership; the internal principal cannot submit data/security operations; real store outcomes preserve exact denial and unchanged effects |
13
13
14
+
15
+
### Current unit case-to-acceptance crosswalk
16
+
17
+
| Native case class | Existing requirement / acceptance | Evidence boundary |
18
+
|---|---|---|
19
+
|`ClusterPrincipalPolicyTests`, `ClusterPrincipalInitializationIntegrityTests`| REQ-AUTH-002 / AC-AUTH-002 | Protected internal-principal bootstrap/idempotence, public edit/credential denial, snapshot copy, and missing/modified/corrupt row rejection at an existing apply cut. This is local store/snapshot evidence, not quorum or RF3 proof. |
20
+
|`ClusterPrincipalAuthorizationTests`| REQ-AUTH-003 / AC-AUTH-003 | Ordinary/public internal-membership denial, internal data/security denial, and internal membership after public-root revocation. |
21
+
|`DocumentRowTenantMutationAuthorizationTests`| REQ-AUTH-005 / AC-AUTH-005, with the owning document boundary REQ-DSTORE-003 / AC-DSTORE-003 | Put/Patch/Delete cannot forge row owner or tenant. It does not cover all row-scoped read/query adapters. |
22
+
|`DocumentFieldMutationAuthorizationTests`, `DocumentReplacementFieldAuthorizationTests`, `DocumentDeleteIndexAuthorizationTests`| REQ-AUTH-006 / AC-AUTH-006, with the owning document boundary REQ-DSTORE-003 / AC-DSTORE-003 | Persisted field-write and index-use grants are independently enforced on the tested mutation paths; this is not the complete adapter/lineage matrix. |
23
+
|`ResourcePolicyUpdateTests`, `ResourcePolicyUpdateRejectionTests`, `ResourcePolicyUpdateVisibilityTests`| See the exact REQ-RPOL-001..004 mapping in [ResourcePolicyUpdates](Authorization/ResourcePolicyUpdates.md)| The unit cases map to RPOL-001/002/003; RPOL-004 remains the real SDK/MCP RF3 criterion. The blob-quota exclusion case is validator-only, not a store-apply flow. |
24
+
25
+
`SignedEnvelopeTests` is physically under the Authorization test directory but
26
+
is owned by InternalSerialization: map it only to REQ-IS-007 / AC-IS-007 in
Copy file name to clipboardExpand all lines: docs/Features/ClusterRouting/PartitionTransfer.md
+25-6Lines changed: 25 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -52,10 +52,11 @@ above against actual ZoneTree/TestDatabase primitives, without mocks, fake view,
52
52
skips or weakened limits. Preserve callbacks' borrowed lifetime. Root reviews
53
53
the complete private packets, then executes Aspire normal/scalar tests.
54
54
55
-
Complete ownership is a later root-owned stage. Current epoch7 outcome keys have
56
-
no partition locator; their hash cannot recover one. Copying every global outcome
57
-
or dropping outcomes is incorrect. Existing-store migration needs its exact
58
-
accepted upgrade/rollback contract. Current persisted authorization remains
55
+
Complete ownership is a later root-owned stage. Global control outcomes have no
56
+
movable partition locator; their hash cannot recover one. Copying every global
57
+
outcome or dropping outcomes is incorrect. The current product must preserve
58
+
explicit partition-associated outcomes and shared control authority without a
59
+
data conversion or alternate reader. Current persisted authorization remains
59
60
authority and an acknowledged revocation must fence all serving groups. Source
60
61
and destination group indexes are never directly comparable; explicit ownership
61
62
epoch invalidation is the first candidate under KL-072, pending full freeze.
@@ -81,7 +82,7 @@ flowchart LR
81
82
Page --> Later[Later complete ownership and fenced transfer]
82
83
```
83
84
84
-
The accepted native epoch/outcome prerequisite is [TokenOwnershipLineage](TokenOwnershipLineage.md), REQ/AC-PMOVE-005..006 and REQ/AC-MTOKEN-001..004 under ADR-017. Its partition-associated locator is additive; global authority and old unknown-scope outcomes remain explicit complete-image blockers. Family pages or a locator alone do not authorize installation or cutover.
85
+
The accepted native epoch/outcome prerequisite is [TokenOwnershipLineage](TokenOwnershipLineage.md), REQ/AC-PMOVE-005..006 and REQ/AC-MTOKEN-001..004 under ADR-017. Its partition-associated locator is part of the current product; shared global authority remains an explicit complete-image dependency. Family pages or a locator alone do not authorize installation or cutover.
85
86
86
87
87
88
# Accepted Stage 1A: shared Orleans membership; later physical movement contracts
The original plan requires controlled copy/catch-up/barrier/switch/cleanup (KL-036), whole atomic partitions with generation readiness and restartable cleanup (KL-071), and either a supported old-token invalidation or correct lineage translation without comparing independent log positions (KL-072). Current contracts intentionally stop before those operations: AC-PMOVE-004 forbids an installer, `AtomicPartitionPlacementV1` only resolves to the single committed `DefaultShard`, `PhysicalShardCatalog` only boots epoch 1, and AC-MTOKEN-004 explicitly excludes epoch bump/cross-group cutover. This proposal is a new movement contract; it does not reclassify current PMAP, bounded pages, token issuance, outcome association or prior-frame compatibility as movement. Source anchors: `docs/design/architecture-v0.3.uk.md` §§4, 6, 28 and KL-036/071/072; `docs/ADR/ADR-016-atomic-physical-placement.md` §§1–5; `docs/ADR/ADR-017-ownership-session-tokens.md`; current `PhysicalShardCatalog`/`AtomicPartitionPlacement` and `PartitionTransfer` contracts.
96
+
The original plan requires controlled copy/catch-up/barrier/switch/cleanup (KL-036), whole atomic partitions with generation readiness and restartable cleanup (KL-071), and either pre-movement token invalidation or correct lineage translation without comparing independent log positions (KL-072). Current contracts intentionally stop before those operations: AC-PMOVE-004 forbids an installer, `AtomicPartitionPlacementV1` only resolves to the single committed `DefaultShard`, `PhysicalShardCatalog` only boots epoch 1, and AC-MTOKEN-004 explicitly excludes epoch bump/cross-group cutover. This proposal is a new movement contract; it does not reclassify current PMAP, bounded pages, token issuance, outcome association or current-frame recovery as movement. Source anchors: `docs/design/architecture-v0.3.uk.md` §§4, 6, 28 and KL-036/071/072; `docs/ADR/ADR-016-atomic-physical-placement.md` §§1–5; `docs/ADR/ADR-017-ownership-session-tokens.md`; current `PhysicalShardCatalog`/`AtomicPartitionPlacement` and `PartitionTransfer` contracts.
96
97
97
98
Stable identity remains the complete four-field `PartitionRef` / `AtomicPartitionId`. Physical shard identity remains a separate opaque ID for an independently configured RF3 replica group. A node-local `PartitionHost` owns its canonical ZoneTree store, replica log, file locks, materializer and apply gate. Orleans activation migration changes no physical ownership. Replica voters and Orleans silos are not separate logical shards.
98
99
@@ -361,3 +362,21 @@ transport/test ownership, and root owns integration and native evidence.
361
362
There is no data/wire migration. Rollback disables the explicit profile and
362
363
cannot retain an unmapped authority handler or abandoned disposable owner as a
363
364
working six-node implementation.
365
+
366
+
### Native immutable-image oracle repair
367
+
368
+
TASK-MEMBERSHIP-IMAGE-ORACLE repairs the pre-start test oracle for the existing
369
+
AC-MEMBERSHIP-006. `RuntimeContainerImage.Add` supplies the accepted tag and the
370
+
64-character digest separately to native Aspire13.6.0. Its image annotation
371
+
retains the tag and stores the digest without the `sha256:` prefix; the native
372
+
resolved reference uses `repository@sha256:digest`. The current test's null-tag
373
+
and prefixed-annotation assertions reject that valid pinned configuration before
374
+
any of the six resources starts. Require the exact accepted repository, tag and
375
+
digest metadata plus exact native resolved reference on all six resources;
376
+
retain the existing fail-before-start mismatch behavior and actual six-container
377
+
startup, signed membership, closed public calls and joined teardown. The patch
378
+
owns only `TwoRf3MembershipImageAssertions.cs`; no image construction, profile,
379
+
credential, topology, timeout or production behavior changes. Root freezes and
380
+
reviews the contract, the worker prepares the guarded correction, and root joins
381
+
strict build/format plus the existing exact-source Linux RF3 case. Source review
382
+
alone does not qualify membership. Rollback restores only the prior test oracle.
0 commit comments