Repository navigation
feat(v0.6): enforce typed W41 conflict identities - #153
Conversation
Add versioned length-delimited fleet conflict identities, explicit topic/broker parent-child overlap, canonical durable obligation bindings, persistence regression updates, and a W41-specific persistence gate extension without activating provider mutation surfaces. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
a782d07 to
bf325a8
Compare
Fix deterministic C# switch-expression precedence in W41 conflict-key decoding so the backend compiles without changing the admitted conflict identity semantics. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Add the canonical W41 serialization scope that collapses admitted topic and broker conflict families to their exact physical parent identities, preserves exact typed identity elsewhere, and maps only the existing v0.5 topic resource-key shape into the same scope. Add fail-closed regression coverage and include it in v05-persistence. This establishes the database guard-key contract for the next race-safe claim/obligation integration without activating any provider mutation surface. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Add the W41 common fail-closed classifier/guard for existing Connect create, update, resume, restart and task-restart paths. Recognized MirrorMaker 2 connector classes cannot be activated through the v0.5 Connect surface while managed replication activation remains unavailable. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Wire the W41 replication activation bypass guard into existing Connect create, configuration-update, resume, restart and task-restart pre-dispatch validation while leaving pause and non-replication Connect behavior on the admitted v0.5 path. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Exercise the W41 pre-dispatch guard against MM2 create, update, resume, connector restart and task restart while preserving pause and ordinary non-replication Connect behavior. Classification without connector.class fails closed. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Add a server-derived reversible bridge from typed topic-family conflict identities to the existing v0.5 topic resource key. Non-topic fleet effects remain outside the legacy bridge and ambiguous identities fail closed. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Persist a server-derived, read-only legacy topic resource identity alongside typed fleet conflict keys when and only when the conflict is in the admitted topic family. Recompute it on restore so callers cannot widen or substitute the bridge. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Install database-native serialization guards once both legacy resource claims and fleet obligations exist. SQLite writer serialization and PostgreSQL guard-row FOR UPDATE locking make claim-vs-obligation admission race-safe; a blocking fleet topic obligation causes the existing v0.5 claim insert to be skipped and therefore reported as ResourceConflict. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Have each mutation connection factory install the cross-generation guard once both legacy claim and fleet-obligation schemas are present. The guard remains dormant before W41 persistence exists and does not add a parallel executor. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Return a typed fleet-obligation admission conflict when the database-native W41 guard suppresses insertion behind an existing legacy claim, and prove both directions plus concurrent race serialization on SQLite and PostgreSQL. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Introduce the v4-to-v5 mutation persistence compatibility fence and require a drained execution state before migration. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Exercise drained v4-to-v5 mutation schema migration and fail-closed future-version refusal on SQLite and PostgreSQL. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
|
W41 PM safety finding on exact head The new v4→v5 migration fence is not yet sufficient to enforce the admitted mixed-version invariant against an already-running v0.5 executor. Required correction before this mixed-version item can be considered complete: establish a database-enforced effect-admission fence that an old executor cannot satisfy after v5 activation, not only an initialization-time marker check. One viable shape is a version/epoch carried by current claim/slot admission plus DB constraint/trigger enforcement so old SQL fails closed; an equivalent race-safe mechanism is acceptable. Preserve existing outstanding Please add a regression that models an executor initialized under v4, keeps that repository/process alive across another instance's v4→v5 migration, then attempts a new mutation claim/dispatch after the marker is v5. It must fail before any provider effect. Future/unknown schema versions must continue to fail closed. |
Show that expired-worker recovery releases renewable execution state without deleting a blocking fleet obligation, that a conflicting legacy claim remains denied, and that Ready work is not auto-replayed. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Run durable observation-cap/restart accounting tests in the dedicated mutation persistence workflow alongside conflict and recovery evidence. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
|
@codex review Please perform a substantive exact-head review of W41 candidate |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 181104279e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Add provider-native slot/claim execution-version guards so an already-running v0.5 executor cannot acquire new effect-admission state after v5 activation. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Prepare and validate the durable v5 admission fence during migration and require current execution-schema version on every new cluster slot and resource claim. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Model a v0.5 executor initialized under schema v4, activate v5 from another instance, and prove the legacy slot/claim SQL fails at the database before provider-effect admission while v0.6 epoch-bearing SQL succeeds. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Recognize the fully-qualified, simple-class and Connector-suffix-stripped aliases accepted by Kafka Connect for the three standard MirrorMaker 2 connector classes, closing alternate activation paths. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
|
@codex address that feedback Please address both currently unresolved exact-head P1 review threads on
Do not resolve either review thread until the implementation and real regressions are present and passing. Do not weaken the existing execution-version fence, canonical typed conflict identity, current trigger guarantees, or v0.5 compatibility contracts. No new provider mutation surface, generic executor, release/publication, or W42+ work in this correction. |
|
To use Codex here, create an environment for this repo. |
|
@codex address that feedback Please fix the two current exact-head P1 findings on
Add/retain real SQLite and PostgreSQL regressions proving: (a) a legacy partition claim conflicts with a fleet topic/partition/config obligation in both admission directions, including concurrent admission with exactly one winner; (b) a pre-existing obligation snapshot lacking After changes, run the applicable W41/persistence test surface. Do not resolve the review threads merely by comment; leave them for PM reconciliation after the new head and CI are verified. |
|
To use Codex here, create an environment for this repo. |
Normalize recognized legacy partition resource claims to their physical-topic guard scope in SQLite and PostgreSQL triggers while preserving the persisted v0.5 resource key and hash. Version the SQLite guard installation and detect the PostgreSQL helper so existing pre-fix trigger installations are upgraded fail-closed. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
When legacy fleet obligations deserialize without legacyResourceKey, atomically rewrite the normalized snapshot inside the existing serialized initialization transaction before accepting the canonical scope binding. Reject conflicting persisted identities and fail closed if the rewrite is suppressed or races. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Exercise SQLite and PostgreSQL legacy partition claims against fleet topic/partition/config obligations in both directions and concurrent admission, verify old resource keys and hashes remain exact, and prove initialization durably rewrites a legacy obligation snapshot before blocking a subsequent partition claim. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
|
@codex review Please perform a fresh substantive review of current exact head |
Install or upgrade the SQLite/PostgreSQL cross-generation conflict triggers and their scope helper in one database transaction so legacy v0.5 writers cannot pass through a DROP/CREATE visibility window during guard migration. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2e18db487d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Fresh exact-head review requested for |
Add a durable insert/update writer fence for fleet conflict obligations so already-running pre-fence fleet-state processes cannot recreate or mutate obligations without current canonical guard identities after backfill. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Install the fleet conflict writer fence inside the serialized scope/backfill transaction and make every current obligation insert/update explicitly satisfy the database writer version/token contract. Older fleet-state SQL remains unable to write after migration. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Model pre-fence fleet-state INSERT and UPDATE statement shapes after migration and prove the database writer fence rejects both on SQLite and PostgreSQL, preventing live old processes from recreating or mutating obligations without current guard identities. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 225eb37fd2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Pass the current durable writer-fence version into the guarded fleet obligation UPDATE statement so current writers satisfy the database fence while stale writers remain rejected. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Model durable pre-fence fleet state before the current store initializes, then prove initialization backfills the missing legacy guard identity, installs the writer fence, blocks a partition claim immediately, and rejects stale post-migration writer SQL on SQLite and PostgreSQL. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Derive SQLite legacy partition guard scope from the terminal numeric /partition/{n} suffix rather than the first /partition/ token, so admitted cluster IDs containing that token cannot bypass physical-topic serialization.
Refs #150
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Exercise both legacy-claim-first and fleet-obligation-first conflict admission with a cluster ID containing /partition/, proving only the terminal numeric partition suffix is normalized on SQLite while retaining PostgreSQL parity. Refs #150 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
|
@codex review Please perform a fresh substantive review of exact head |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Authority
Continuation of W41 under #150 / tracker #146 from protected
main=31ce6cae5963263e403eda9c65e2d30e541e1be1.Current exact head
2071985bb2f62f19ac2b168748d212a57d4f5646Current source state
The prior partition-scope and durable-backfill P1 findings remain fixed. A subsequent Codex P1 found that a live pre-fence fleet-state process could write another incomplete obligation after backfill. This head adds a database-enforced fleet conflict writer fence and regressions for stale writer INSERT/UPDATE.
Current behavior:
legacyResourceKeyare durably rewritten inside the serialized backfill transaction;Review state
The new writer-fence P1 thread remains unresolved pending exact-head persistence/quality evidence. All prior approvals/reviews are stale after the source push; fresh current-head Codex and
akhiabanchianreview will be required.Fresh exact-head CI
On
2071985bb2f62f19ac2b168748d212a57d4f5646:Admission
MERGE BLOCKED until writer-fence evidence passes, the P1 thread is resolved after validation, all applicable exact-head checks are green, fresh current-head CODEOWNER approval exists, and final live main/head/base/mergeability/rule reconciliation passes.
Refs #150.