Skip to content

test(v3): account for cold raw proof and instrument retry source opens - #84

Merged
Ivanbeethoven merged 1 commit into
maint/mst2-native-head-with-projectionfrom
fix/v3-native-cost-oracles
Oct 7, 2026
Merged

Ivanbeethoven merged 1 commit into
maint/mst2-native-head-with-projectionfrom
fix/v3-native-cost-oracles

Conversation

@Ivanbeethoven

Copy link
Copy Markdown
Collaborator

The exact native suite exposed two test accounting errors. Cold raw opens one source to earn its receipt and one for authenticated delivery; its revocation regression now requires both passes while retaining rejected-tail, zero range IO and exact byte accounting. The admission/cancellation source-builder regression now increments its existing loader counter on its real successful retry, preserving the required two source opens, credit refund, producer drop and chunk verification. Production behavior is unchanged.

Validation: independent exact-source review; nightly format, diff and locked offline metadata checks passed. New native execution remains pending. No new performance measurement is claimed. The reviewed change retains production checks and existing integrity assertions. Commit has a valid GitHub signature; no force push. Source and necessary tests only; evidence stays outside the repository.

The exact native suite exposed two test accounting errors. Cold raw opens one source to earn its receipt and one for authenticated delivery; its revocation regression now requires both passes while retaining rejected-tail, zero range IO and exact byte accounting. The admission/cancellation source-builder regression now increments its existing loader counter on its real successful retry, preserving the required two source opens, credit refund, producer drop and chunk verification. Production behavior is unchanged.
@Ivanbeethoven
Ivanbeethoven merged commit e7ddee0 into maint/mst2-native-head-with-projection Oct 7, 2026
1 check failed
genedna pushed a commit that referenced this pull request Oct 8, 2026
…dies (#54)

* Complete native MST2 publication, retention and metadata integration

Rebase the complete PR #54 code and test delta onto current main as one verified signed commit. Preserve the exact previously reviewed source tree, including fixed-content metadata optimizations and controlled native initialization.

* test(mst2): inject and verify actual fixed-content storage faults

Git SinglePut preserves existing immutable objects. In the isolated test fixture, remove the owned object before fault injection or repair, read back the exact bytes, and exclude setup reads from HTTP counters. Preserve all corruption, missing-body, retry and cache assertions.

* feat(mst2): persist native HTTP snapshot sessions and guard delivery (#56)

Use primary PostgreSQL authority for fixed native snapshot sources and per-lease certificates. Atomically hand off installed metadata protection to durable sessions and leases, retain only roots on warm resolve, and retire session pins with the last lease. Recheck current lease, source and captured primary scope before each actual TreeFrame or shared raw block. Add real HTTP/PostgreSQL regressions; native validation and performance remain pending.

* fix(mst2): keep authentication errors typed until middleware response

Resolve native all-target Clippy result_large_err by returning SnapshotError from authentication. Construct the identical HTTP error envelope at the two existing middleware exits inside the same request-ID scope. Preserve bearer and lease checks, codes, messages and every regression assertion; do not suppress the lint.

* feat(mst2): persist fixed metadata generations for native preparation (#57)

Persist complete metadata lifetime bindings and private storage seals before payload installation. Verify exact generations at observed-DAG finalization and recovery; preserve existing v3 HTTP sessions and all original regression assertions. Isolate this repository until generation-aware collection and session adoption are implemented. Native Linux gates and performance remain pending.

* fix(mst2): parse fixed generation records as array chunks

Fix native all-target/all-feature Clippy chunks_exact_to_as_chunks. Keep the prior exact length/count guard, canonical re-encoding, per-entry parsing and every generation regression unchanged; no lint suppression. Native gate run 37610549234 confirmed the single failing lint.

* feat(init): allow a fixed bootstrap commit timestamp (#58)

Add explicit service init --yes --commit-time UNIX_SECONDS to reproduce initial root and materialized path parents for independent backends. Preserve current-time defaults and existing initialization persistence. Under the original advisory lock, reject fixed-input root commit/tree mismatches before object/ref changes. Frozen five-path source independently reviewed; nightly formatting and locked offline metadata passed. Native/PG/network push not run locally.

* feat(mst2): preserve metadata lifetime history and explicit terminal receipts (#59)

Add composite immutable lifetime history, a separate current watermark, persisted domain-bound preparation seals, explicit abort/coverage retirement and same-primary terminal replay. Preserve existing v3 serving, G1 NULL-domain receipts, original guards and bootstrap C1 blobs. No payload deletion, qualified collector, generation replacement or production adoption is enabled. Twelve frozen code/test paths independently source-reviewed; native validation and performance remain unmeasured.

* fix(mst2): timestamp retained roots during native batch acquisition

Fix the two native batch root inserts to supply PostgreSQL now() for the existing required created_at column. Preserve graph locks, identities, ON CONFLICT semantics and all HTTP/generation assertions. Keep the reproducible bootstrap fixture consistent with the validated default import directory. Native run 37615218353 exposed 29 missing-timestamp failures and three invalid-fixture failures; source review, nightly formatting and locked offline metadata passed, native retest pending.

* feat(mst2): collect exact qualified metadata lifetimes atomically (#60)

Add permanent lifetime/domain fences, a generation-qualified graph, bounded discovery and persisted exact GC operations. Physical payload removal, edges/counters, immutable history and APPLIED receipt commit together; fresh preparation requires exact prior removal proof and protects against ABA. Preserve current v3 serving, upstream updates and native timestamp/bootstrap fixes. Nineteen real PostgreSQL regressions added; final frozen source reviewed and formatting/offline metadata passed, native validation and performance pending. Qualified production sessions, collector and generic-to-qualified adoption remain closed.

* fix(mst2): observe renewal locks without exhausting the test pool (#61)

Observe pg_locks through the transaction already holding the retention lock, and clear its statistics snapshot before each poll. Keep all original expiry, root-release and byte-count assertions. Stream repository test diagnostics before a possible CI cancellation. Native regression validation is pending.

* fix(mst2): keep lookup metadata-only and restore native regression coverage (#63)

Use one fixed-path metadata walk and current verified size/digest facts for lookup without whole-content reads. Preserve the original zero-body-read assertions and HEAD behavior. Correct three observed native fixture failures without changing production publication or payload guards. Native execution of this combined source remains pending.

* perf(mst2): validate and seal fixed metadata installation once (#62)

Mint an opaque capability from complete immutable preparation evidence and freeze its durable identity and membership. PREPARING batches use bounded exact-member checks while preserving current primary, scope, state, physical lifetime and payload validation. COMMITTED replay and finalize retain their complete oracle. Native validation and measured performance remain pending.

* test(mst2): repair native capability fixtures without relaxing guards (#64)

Repair exactly diagnosed native capability regressions: mutate verification revision rather than a legal no-op; count the actual canonical radix DAG and batch partitions; inject one handoff corruption with the exact prepare guard restored transactionally; prove both legitimate generic/qualified refusal paths with complete state rollback and retain a real private physical-checker rejection. Production guards and original HTTP integrity/zero-read assertions remain unchanged. Native rerun is separate from source review.

* perf(mst2): share concurrent cold chunk projections (#65)

Deduplicate concurrent same-digest cold projection loads, retain verified results for active participants after cache eviction, and preserve full SHA/map/slice validation. Bound registry keys and clean up exact last-owner gates without dropping large results under the global lock. Add ten failure/cancellation/eviction/capacity regressions. Native and performance evidence remain separate.

* perf(mst2): admit OBJECT batches before bounded body reads (#66)

Admit all fixed paths and current verified facts before body I/O, reject item/batch caps early, and collect actual raw streams with exact EOF/length/full SHA. Share only exact OID/digest/size bodies; verify every different source. Preserve frames/END/current source and lease guards, remove replaced full-body OBJECT helper, and add thirteen HTTP regressions. Native and performance evidence remain separate.

* feat(mst2): bind generic sessions to immutable storage routes (#67)

Derive permanent semantic SID routes, separate generic physical bindings and immutable original lease routes on actual v3 open/read/renew/release paths. Serialize context/lease insert before row locks via captured core mono, route and namespace retention barriers; backfill complete inventory with fixed-scope proof. Authenticate generic prepare domain at fixed-core registration, preserve original domain immutability and old upgrade reads, and add ten actual PostgreSQL/HTTP regressions. Qualified serving and collector remain closed; native and performance evidence remain separate.

* test(mst2): cover FK and capability truncate barriers separately (#68)

The exact f3e native run passed 2346 tests and failed one expectation: PostgreSQL FK preflight rejects plain prepare-page TRUNCATE before the install-capability trigger. Preserve plain FK rejection, add CASCADE to reach the unchanged capability guard, and prove all prepare mappings and seals survive. Existing identity assertions and actual installation/finalize remain. No production code changes.

* perf(mst2): stream CHUNK maps and read bounded exact ranges (#69)

Build verified chunk maps from raw streams with full digest, exact size and EOF validation. Retain inline data through 512 MiB; larger files retain map metadata and read selected chunks by strict current-source ranges. Keep the existing singleflight, attach projection/response credits to actual owners, and admit complete batches before body I/O. Add seventeen stream, budget, storage and HTTP regressions. Native and performance results remain separate; persistent locators and process RSS are not completed by this slice.

* test(mst2): retain storage while updating chunk fixture facts (#70)

Bind the fixture MonoStorage Arc before borrowing its database connection across async queries. Fix exact E0716 in the new CHUNK test helper. The whole-file delta is this binding only; all test bodies/assertions and production code remain unchanged. Repaired native validation is pending.

* test(mst2): repair OBJECT error and storage-route fixtures (#71)

Repair five observed regressions in exact #67 native run37647717995 (2374 passed/6 failed/2 ignored). Three OBJECT expectations now use the existing formal EXPECTED_DIGEST_MISMATCH wire code. The half-lease fixture reaches actual failed COMMIT with its completeness trigger enabled and deferred, avoiding PostgreSQL pending-event ALTER; failed commit must restore all trigger modes and route/source/root inventories. The temp-shadow fixture uses legal CASE syntax for its exact identity assertion. Production guards, all integrity assertions and the #70 CHUNK lifetime repair remain unchanged. The sixth old FK expectation was repaired by #68. Repaired native validation remains pending.

* perf(mst2): omit existing metadata payloads in native installation (#72)

The actual native session installer classifies each bounded batch using the existing exact-member query, then encodes and submits only missing metadata payloads in the same transaction. Fully reused batches skip both INSERT and byte-comparison statements; mixed batches retain exact comparisons for newly submitted bytes. Primary/schema/state/seal/member, codec/size/current-lifetime/domain/graph/tombstone checks remain. Presence only omits writes: local input hashing/decoding, the complete plan, final stored-byte/canonical/DAG/graph validation and restart recovery remain. COMMITTED replay keeps complete validation and requested-byte comparison and never inserts or repairs. Batch work records encoded/omitted bytes and specified statements; classification_batches is an embedded count, not a SQL trip, and these counters exclude barrier and full-oracle work. Ten PostgreSQL regressions include the real install wrapper, mixed/full reuse INSERT traps, corruption, rollback, replay and retention Lease-root release/GC fences. Fixtures cover installation, not publication/open or the HTTP lease ledger. No new schema/Q serving or wire/profile compatibility. Full proof remains O(total metadata); no measured latency improvement is claimed.

* test(mst2): decode the first streamed CHUNK as a single frame (#73)

The per-frame revocation regression receives one CHUNK DATA before revoking its lease. Parse that DATA with parse_frame, assert exact consumed length and the real map/content IDs, chunk index and bytes. Keep the original successful DELETE, next DATA error and terminal None assertions. Feed only the actual received bytes to the complete stream parser and require its exact missing END/ERROR rejection. No synthetic END, production change or weakened decoder. This repairs the sole failure in the exact #71 full suite (2396 passed, 1 failed, 2 ignored). The original fixture has no isolated credit observer; existing separate ownership regressions remain unchanged. The corrected source has not yet run natively.

* perf(mst2): serve native META from protected persisted pages (#74)

Native HTTP META now walks durable MTP2 pages from the fixed descriptor root instead of loading Git trees and rebuilding directory/radix projections. One captured G READ COMMITTED transaction proves primary and exact original lease routes before and after bounded retention-barrier acquisition, rechecks the complete immutable session, then owns all response bytes before committing. Every touched page retains prepare membership, exact current lifetime/generation/domain, LIVE graph/codec/size/tombstone, outgoing-reference equality and formal page-ID/codec checks. Path/radix partition counts and scope bounds, first-seen deduplication, expected digest, META frame caps and END exact request-body hash remain; cold complete restore and per-frame auth/lease validation are unchanged. Eight real PostgreSQL/HTTP regressions cover canonical identity/zstd/END, old SID after advance/restart with real Git-table lock traps, absence/digest/limits, corruption/missing pages, exact nullable/bound generic lifetimes, graph damage, lock-wait deadline/release rechecks and deterministic reader versus release/GC protection. Page work counters exclude setup/session/lock wait, cold full restore, response encoding and per-frame checks. This removes warm source projection work; it does not claim cold O(route), O(delta), measured latency, commit-update speedup or a Git win. No migration, dependency or Q compatibility path.

* fix(mst2): exercise missing payload installs and await history rejection rollback (#75)

The durable HTTP interruption fixture now resolves the deployment root, proves that only its root page is missing, and preserves the real INSERT failure, rollback, old SID readability, and successful retry. The wide-DAG fixture computes expected INSERT statements from the original 64-page batch boundaries and existing immutable IDs, counts actual new rows, and preserves the real page/edge lock trap and cold old-SID read. Native maintenance explicitly awaits rollback when publication history prevents initialization, so its exclusion lock is released before returning; the existing history-loss regression retains all exact history/root/paused-state assertions and adds immediate independent transaction lock reacquisition plus useful failure diagnostics. The old native log did not print the rejected error, so that failure cause is not conclusively established until the new native regression runs. Production missing-only deduplication and history rejection remain unchanged. Local nightly formatting, diff and locked offline no-dependency metadata checks passed; native tests remain unverified for this candidate, and no performance or large Git comparison was run.

* test(mst2): observe actual retention waits and drain deferred fixture events (#76)

The persisted META concurrency oracle now observes the actual advisory lock tuple in its current PostgreSQL database and schema, without relying on application_name from a statistics snapshot. It still requires a real waiting competitor, unfinished reader and competitor, both exact route bytes, root/directory counts, release or GC behavior, successful post-read collection and rejection of the old context. A competitor that returns early reports its actual result and release/GC case instead of being hidden by a wait timeout. The source of the earlier timeout has not yet been established by a new native run. The bound-current corruption fixture keeps its active, deferrable, initially deferred protection trigger, executes its queued check explicitly before ALTER TABLE, restores deferred mode, and reenables the original mutation guard before commit. All six original damage/repair cases, exact HTTP errors, recovered canonical bytes and complete trigger-mode checks remain. This addresses the observed PostgreSQL pending-trigger-events error without disabling completeness protection. Production code and guards are unchanged. Local nightly formatting, diff and locked offline no-dependency metadata pass; new native results and all performance measurements remain pending.

* perf(mst2): persist source-bound chunk maps and authenticate selected pages (#77)

Actual chunk-map, page and CHUNK routes replace the digest-only process cache with immutable source-bound PostgreSQL indexes and independent object-store receipts minted only after one complete current-OID size/SHA256/chunk/EOF pass. Exact-source cold callers share an installation gate, then each request reads its own backend receipt. Reconstructed warm readers consume no full source body and fetch only selected MCL2 pages and exact Merkle sibling intervals; CHUNK still reads and authenticates the current request OID range. Captured physical primary scope, bounded qualified SQL, full fact tuple, opaque verifier publication, deferred complete atomic installation, mutation-resistant receipts, owned descriptor/page/JSON credits, cancellation and per-transport lease checks retain fail-closed behavior. Old cache/runtime and page alias are removed; MCM2/MCL2 schema_version=2 remains the formal wire codec within v3. PostgreSQL and actual HTTP regression fixtures cover forged ordinary-DML indexes, receipt size/bytes/EOF, corrupted selected proofs, source and primary changes, temp shadows, SQL rollback, concurrency, cancellation and owned-reader release. Source formatting/diff/offline metadata pass. Native compile, Clippy, PG/HTTP tests and measured latency/RSS/Git comparison remain pending.

* fix(mst2): finish chunk-map admission and isolate native observers (#78)

Fix the missing native_chunk_maps field in the shared test Storage constructor and replace the redundant install-flight initializer closure without changing its behavior. The persisted-META reader/GC race now observes the actual lock wait through a separate one-connection pool, preserving the original two-connection service pool and every protection, release/GC, owned-byte and damage assertion; the prior observer itself consumed the connection needed by its competitor. Certificate lifetime checks bind the requested ten-day expiry to the actual issuance request interval rather than time spent later parsing/verifying the certificate, preserving the X509/response expiry equality, key and SAN checks. Exact earlier #76 native result was 2413 passed/2 failed/2 ignored (reader observer and certificate timing); #77 failed all-target Clippy for the missing constructor field and redundant closure. Production trust/lease/retention guards remain. Format/diff/locked offline metadata pass; corrected native tests remain pending.

* perf(mst2): stream authenticated raw blobs with owned chunk credit (#79)

Raw GET replaces the materializing whole-blob handler with one sequential current-OID stream, authenticated against an independently earned immutable source receipt and one selected canonical chunk page at a time. Consumer scratch and first response credit are admitted before cold source IO; each at-most-1-MiB transport chunk owns its memory credit and map reader through its last Bytes clone. Physical metadata, exact lengths, authenticated per-chunk hashes, final full SHA256 and real final EOF reject corruption, truncation, growth and late IO errors. First-poll, post-await and per-delivery access validation preserves lease revocation, cancellation drops producer ownership, and empty files require a verified empty digest and actual zero-byte EOF. The formal unsupported Range-header HTTP 400 behavior is retained. Thirteen actual HTTP regression tests cover cold two-pass and warm one-stream read counts, fragmentation, owned clone credit, admission, producer item limits, no proof fallback, physical facts, real stored corruption, lease cancellation and immediate post-await rejection of short/empty fragments and real EOF without a later backend poll. Formatting/diff/offline metadata pass; native build/Clippy/PG tests and measured throughput/latency/RSS remain pending.

* fix(mst2): place chunk-map SQL tests after production items (#80)

Move the unchanged cfg(test) SQL qualification regression module to the end of native_chunk_map.rs. This fixes the exact #78 all-target/all-feature Clippy items_after_test_module failure without a lint allow or any production or test assertion change. The raw streaming implementation merged in #79 is retained. Nightly formatting, diff and locked offline metadata checks pass; corrected native build/tests remain pending.

* fix(mst2): validate raw streams through their exclusive owner (#81)

Change RawBlobReader access validation to borrow its exclusive owner. The byte producer is Send and deliberately need not be Sync; retaining a shared reference to the whole reader across an await made the actual Axum body future non-Send. This fixes exact #80 native compilation at snapshot_raw_blob.rs189/235 without adding a lock or weakening any first-poll, post-await, EOF or per-delivery access check. All13HTTP regression assertions remain. Formatting, diff and locked offline metadata pass; corrected native execution remains pending.

* perf(v3): serve fixed snapshots from rooted delta metadata (#83)

Commit publication builds canonical local directory proofs and reuses unchanged fixed-root metadata. Default qualified-family serving reads bounded DIR windows and selected LOOKUP routes with current source revision facts; warm body callers avoid Git-tree projection. Permanent snapshot routes, exact publication and lease identities, source mutation invalidation, root ownership and bounded background recovery/GC remain enforced. The authority catalog validates exact registered physical families, full qualified shape and source revision triggers, including precise treatment of legitimate qualified foreign-key RI triggers. Direct lease lock contention maps to retryable HTTP 503. Publication-disabled formal MST/2 sessions retain fixed-root HEAD/body/OBJECT/CHUNK service. Migration 000200 and actual PostgreSQL/HTTP regression sources are integrated without raising existing projection limits. Independent review covers all 46 paths, all four corrected findings and every changed assertion site. Format, diff and locked offline metadata pass; native PostgreSQL execution and performance measurement remain separate.

* test(v3): account for cold raw proof and instrument retry source opens (#84)

The exact native suite exposed two test accounting errors. Cold raw opens one source to earn its receipt and one for authenticated delivery; its revocation regression now requires both passes while retaining rejected-tail, zero range IO and exact byte accounting. The admission/cancellation source-builder regression now increments its existing loader counter on its real successful retry, preserving the required two source opens, credit refund, producer drop and chunk verification. Production behavior is unchanged.

* fix(v3): read metadata primary scope from its captured permanent schema (#85)

A TEMP table with the same name could poison native metadata repository initialization. Capture the actual permanent schema through pg_catalog, qualify the storage identity read during initialization and mutation/recovery barriers, and continue observing and comparing the actual current database/schema/OIDs/server/replica identity. A matching fake TEMP UUID cannot authorize another primary schema. Add a single-connection regression with TEMP present before construction, primary schema switching and restoration. Runtime verification query counts and existing integrity assertions are preserved.

* fix(v3): repair rooted metadata native type and lint gates (#86)

The exact rooted metadata native check exposed unused private type reexports, a u64/u32 END assertion and two strict Clippy findings. Remove unused exports, compare the same exact count after lossless conversion, return existing typed SnapshotError from JSON/cursor helpers and name the unchanged proof page type. Response conversion keeps the same MST/2 HTTP error mapper at the caller boundary; proof bounds and validation are unchanged.

* fix(v3): remove unused rooted reader type reexports (#88)

The exact native check exposed the remaining unused directory-window and lookup-batch reexports in the intermediate rooted module after the outer family reexports were removed. Remove those two unused names and retain the used lookup status reexport. Reader type definitions, methods, proof bounds, HTTP behavior and every test assertion are unchanged.

* test(v3): borrow the canonical donor payload without cloning (#89)

Strict native Clippy identified an unnecessary cloned single-item slice in the rooted metadata donor fixture. Pass the same immutable payload with std::slice::from_ref. Preserve every donor certificate, source verification, delta reuse and fixed-root integrity assertion; production code is unchanged.

* Bound v3 chunk-map ownership and cancel stalled backend waits at the actual deadline (#91)

Bound persisted v3 chunk maps and exact receipt generations with primary database owners, capacity admission, resumable collection and final transport-clone retention. Pending cold and warm backend opens, input polls and receipt creates now terminate under the actual remaining owner deadline; empty fragments grant no renewal. Add actual HTTP/storage/database test sources for expiry, withheld final bytes, refund and safe replay. Owned nightly format, canonical candidate whitespace and SQL lexical checks pass; native build/tests, database execution and commit-update performance measurements remain unrun. Truthful backend capabilities are a separately reviewed source-only follow-up dependency.

* Stream v3 rooted facts and report actual backend hydration capabilities (#92)

Missing rooted blob facts now hash a complete source stream under fixed consumer credit, removing full-file materialization while preserving exact size, digest and EOF checks before persistence. Local and memory backend streams split visible items lazily without copying; capability discovery reports raw, chunk and full hydration support from the actual backend without IO. Eleven added test sources retain previous assertions and the actual merged chunk-owner deadline work. Seven owned Rust format/parse and canonical whitespace checks pass; native/database/performance execution remains unrun.

* Fix rooted plan SQL column bindings and exact large-integer byte encoding (#93)

Rooted cold and zero-delta preparation referenced value from unnamed unnest outputs in both graph-member checks, causing the exact native column-value failures. Explicitly bind the four array output columns. MTP2 integer serialization also divided numeric values before truncation, rounding u64MAX into wrong bytes; use the exact integer quotient instead. Enhance existing real database test sources for persisted rooted plan/payload reuse and independent Rust byte encoding at integer boundaries, retaining all prior full-byte/page-id and rejection assertions. Owned nightly format/parse, canonical whitespace and exact SQL lexical preservation checks pass; PostgreSQL/native/performance execution remains pending. Other CI failure groups are separate.

* Bootstrap rooted metadata fixtures through their actual database configuration (#95)

Use production rooted metadata provisioning for ordinary snapshot, view operations, and native push fixtures. Retain schema ownership, generic history behavior, native queue timing, and all existing test assertions. Validation is source-only: owned nightly format checks and Git whitespace checks; native builds, database tests, and performance runs are deferred.

* Align native fixtures with captured database scope and exact guards (#96)

The UN30 facade fixture now supplies its actual per-test database config to full storage assembly, so the rooted Q pool shares the correct database. The forged namespace insertion must match its exact BEFORE INSERT registration guard and roll back, preserving every route/source state assertion. The durable scope-drift test now expects the shared family-selection contract: 502 INTEGRITY_ERROR with retryable=false for both descriptor and renew, before a G/Q repository is selected. It retains stream error/no-END, scope restoration and no-IO assertions. Three owned nightly format/parse and whitespace source checks pass; native execution remains unrun.

* Fix chunk retention error conversion and test owner lifetimes (#97)

The exact PR91 repository gate stopped at compilation: common IoOrbitError conversion missed the two retention variants, fourteen test connection borrows outlived temporary MonoStorage owners, and one spawned install borrowed fixture storage. Explicitly convert both concrete retention errors through existing MegaError::ObjStorage without changing their specialized Snapshot classifications, bind each connection owner, and move an owned Storage clone sharing the original Arc<OnceCell> repository cache into the install task before borrowing that same cached repository. All original assertions, deadlines, cancellation and final Bytes retention checks remain byte-for-byte preserved outside these lifetime edits. Owned nightly format and exact source/tree checks pass; native build, Clippy and repository tests remain pending.

* Use equivalent let chains for raw progress and cancelled installs (#98)

The exact PR97 and integrated c1ff repository gates both stop at two Clippy collapsible_if errors. Collapse only those nested conditions: nonempty raw bytes followed by an existing chunk map, and a successful cancelled-install mutex lock followed by its strict 64-entry cap. Preserve short-circuit order, lock scope, ownership, progress error propagation and every cancellation/stream assertion. Two owned nightly format/parse checks, exact whole-file forward/inverse reconstruction and the complete unchanged-outside-paths tree proof pass. Native Clippy, build and repository tests remain unrun for this candidate.

* Parenthesize chunk retention CASE expressions in PL/pgSQL IF guards (#99)

Database bootstrap currently fails with PostgreSQL 42601 at Original(10355): the first unparenthesized CASE in a PL/pgSQL IF exposes its internal THEN as the end of the IF condition. Parenthesize that CASE and the identical later map guard expression. Preserve both 512 MiB capacity checks, state-dependent 256 KiB/1 MiB reserves, error messages and every other migration byte. Exact original source-offset and whole-file inverse proofs plus whitespace and unchanged-tree checks pass. The cancelled native run has no completed test summary; this candidate has not executed SQL or native tests.

* fix(v3): bound qualified reader history with complete owner identity (#100)

Qualified metadata requests previously retained every completed reader, so the 65,536-owner history cap eventually blocked new requests. Reclaim at most 64 previously committed terminal owners without roots before admission, and fence every page/source/finish operation with UUID plus a monotonically issued generation stored in one high-water row per Q. Same-transaction terminal owners remain until their deferred completion commits. Add a trusted transactional forward migration, remove UUID-only function overloads, and preserve permanent SID, source, certificate and lease history. Nine default database regression test sources cover fresh/old-Q/Q-less/tampered upgrades, real HTTP requests, stale actual-reader replay, rollback issuance, maximum issuance and the 64-owner deletion budget; a new ignored capacity soak issues 65,537 real HTTP requests. Owned nightly formatting, complete candidate whitespace, patch checks and offline source proofs pass. Native build/tests/Clippy, PostgreSQL execution and performance measurements remain pending; this package claims source validation only.

* fix(v3): repair native decoder and authenticate existing family upgrades (#101)

Native rooted plan admission failed because PL/pgSQL parent and child locals conflicted with unqualified graph-query columns. Qualify both columns and repair the migration shape sampler to deparse under pg_catalog,pg_temp with parameterized caller-path restoration. Share trusted forward migration logic between 400 and new 500: authenticate exact 6d/900e/current implementation, captured historical templates, authority/full physical catalogs, scope and canonical namespace identity; replace the decoder on old 6d and the three changed functions on 900e while preserving its relations, function OIDs, reader high-water and retained ownership/history. Admit the exact known Q-visible legacy deparse shape only for the authenticated 900e policy with no actual Q. Handle the legitimate 900e state with a missing 400 ledger without replaying reader DDL. Move the old reader capture into migration verification and reuse the forward-only template renderer in owned fixtures. Add six PostgreSQL regression sources for active/terminal readers, nonzero issuance, all anchors/OIDs, old SID lookup, Q-less canonical/known legacy policies, missing ledger, tampering and idempotence. Add test-only underlying install error output; the production 503 remains unchanged. Owned nightly formatting, candidate whitespace, historical-source equivalence and patch checks pass. Native build/tests/Clippy, PostgreSQL execution and performance measurements remain pending; this is a source-only submission.

* perf(v3): cache compiled qualified implementation fingerprint (#102)

Cache the immutable compiled qualified-family implementation fingerprint in a process-local OnceLock<[u8; 32]>, preserving the existing Vec return API. Keep all 15 source components, domain separator, length prefixes and digest bytes unchanged; every database catalog, shape, policy, identity and physical-stamp check still runs. Owned nightly formatting, offline source equivalence and candidate/patch checks pass. Native typecheck, Clippy, PostgreSQL tests and performance measurements remain pending.

* fix(v3): encode canonical descriptors with the codec wire order (#103)

Rooted PostgreSQL resolve failed its exact descriptor handoff because SQL encoded descriptor u16 fields in big endian while mst2-codec 0.3.1 writes little endian. Encode version, flags and UTF-8 byte length with the locked codec order. Add independent transactional migration600; freeze400/500 at authenticated87b so ledger replay cannot downgrade the repaired family. Authenticate unchanged core/Q catalogs, complete physical shape, scope and exact identities before every no-op or forward repair. Preserve existing OIDs, issuance, anchors, readers, source roots and canonical sessions. Add four real PostgreSQL regression sources for bytewise root/ASCII/256-byte/UTF-8 descriptors, authenticated87b upgrades and missing ledgers, Q-less provisioning, idempotence and descriptor tampering; verify compiled-family400/500 replay without a downgrade in the same strong fixture. Correct the complete20-name migration-order assertion while preserving alias DB behavior; historical900e replay includes600. Add a focused24-test native gate with exact inventory presence checks before the retained full repository suite. Formatting, historical-source equivalence, exact function replacement sets, candidate whitespace and bidirectional patch checks pass. Native compile, PostgreSQL regression execution and performance measurements for this candidate remain pending.

* test(v3): complete reader owners before committing a prune backlog (#104)

The native 64-owner backlog regression failed at its first bulk ACTIVE-owner commit, before any explicit prune assertion, because the shared deferred ownership guard rejected the final state. Source inspection supports the 60-second reader deadline as the most likely explanation; the runtime log does not identify which guard predicate failed. Complete each of the 65 admitted readers immediately in the same transaction, preserving the terminal transaction fence and deferred validation. After its first successful commit, assert 65 FINISHED owners, no ACTIVE owners or REQUEST/READER anchors, and an issuance high-water advance of 65. Preserve the same-transaction prune=0 and later prune=64 then1, with retained-row counts1 then0 and all existing tests. Production SQL, deadlines, ownership guards, implementation fingerprints and the focused24-test workflow remain unchanged. Nightly formatting, scoped source checks, candidate whitespace and bidirectional patch checks pass; native execution of this new fixture remains pending.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant