Skip to content

feat(occasionally-connected): add first-release durable sync packages - #229

Open
ChrisPulman wants to merge 505 commits into
mainfrom
OccasionallyConnected
Open

ChrisPulman wants to merge 505 commits into
mainfrom
OccasionallyConnected

Conversation

@ChrisPulman

@ChrisPulman ChrisPulman commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

What kind of change does this PR introduce?

feat: the first public release of ReactiveUI.Primitives.OccasionallyConnected across seven NuGet packages. It adds durable local commits, synchronization, SQLite storage, HTTP transport, server coordination, dependency injection, and hosting integration.

What is the new behavior?

Applications can capture owned inputs within a bounded outbox, keep working offline, and reconcile with a remote server after reconnecting. The client and server SQLite stores start at complete V1 schemas and reject unsupported layouts. Encrypted client records authenticate protected values and durable operation state. This does not detect every record deletion or restoration of an older valid database; those threat models require an independently protected checkpoint outside the database. The sample applications cover durable outbox, collaboration, resilience, and a clean packed-package consumer.

What is the current behavior?

main has no OccasionallyConnected packages or end-to-end examples.

Checklist

  • Tests have been added or updated (for bug fixes / features)
  • Docs have been added or updated (for bug fixes / features)
  • Changes target the main branch
  • PR title follows Conventional Commits

Additional information

  • All 12 Release net10.0 TUnit suites passed after integrating the latest main: 4,886 passed, 0 failed, 8 capability-based skips; all 12 builds reported zero warnings and errors.
  • Every package exceeded 98% handwritten line and branch coverage. The lowest branch result was 98.01% for the runtime package; generated JSON code is reported separately without exclusions or suppressions.
  • Package release gate passed deterministic packing, Source Link and symbols, local-feed restore, and all 19 clean-consumer scenarios on net8.0, net9.0, net10.0, net11.0, net462, net472, net48, and net481.
  • Supply-chain gate passed for seven packages with a validated SPDX SBOM; four mutation campaigns were killed by their TUnit tests. NativeAOT, crash, soak, and release workflows run in CI.
  • The branch contains signed feature and merge commits. The feature is unreleased V1; no end-user database migration is needed.

Place exception documentation before remarks to satisfy SST1666 after the final documentation update.
Verified the combined Core and runtime net10.0 build with all analyzers enabled.
Payload contracts:
- Own immutable payload bytes and expose their encoded length without copying.
- Register source-generated JSON schemas and contiguous deterministic upcasters.
- Freeze schema metadata and snapshot registrations for each serializer.

Runtime validation:
- Enforce exact encoded-byte limits with bounded scratch allocation.
- Validate content type, schema, allowlisted type and stored SHA-256 hash.
- Revalidate upcast results and preserve cancellation and stable schema failures.
- Reject reference preservation and polymorphic root metadata.

Verification:
- Root executable regression tests preceded fixes for size boundaries, malformed hashes and cancellation.
- 128 Core and 110 runtime TUnit tests pass on each modern target with 100% line and branch coverage.
- All eight library targets build without warnings or suppressions.
… safety

Admission behavior:
- Enforce count and byte bounds plus a finite blocked-producer budget.
- Preserve FIFO within data and control classes while reserving control capacity.
- Support block, reject, eligible drops and custom blocking decisions.
- Revalidate unlocked custom decisions before admission.
- Preserve cancellation tokens and committed receipts, register callbacks outside locks and release buffers on disposal.
- Avoid overflow and user-defined equality under queue locks.

Configuration:
- Add immutable positive outbox and inbox capacity options with finite defaults.

Verification:
- Worker and root executable regression tests exposed the corrected behavior.
- Disabling capacity validation caused ten failures.
- 142 Core and 161 runtime TUnit tests pass on all four modern frameworks.
- Matching production packages have 100% line and branch coverage; all eight library builds pass.
…iagnostics

Configuration
- Add required nested context options with complete immutable defaults.
- Validate positive retention, payload/message/decompression limits, replay intervals,
  diagnostic sampling and both fault-count and fault-byte queue capacities.
- Keep raw identifiers absent by default and expose explicit hashed-identifier opt-in.

Verification
- Add type-specific TUnit tests for valid defaults, malformed values and copied options.
- Independently verify 182 Core tests on each modern target with 100% line and branch coverage.
- Confirm a high-water boundary mutation causes a real assertion failure, then restore it.
- Build all eight Core target frameworks without warnings, errors or new suppressions.

Documentation
- Record implementation defaults, completed gates and remaining runtime enforcement work.
…ojection contracts

Protocol and persistence
- Add immutable operation, event, batch, recovery, lease and operation-status models.
- Persist effective operation policy in the contract and expose durable retry/status lookup.
- Define lease-owned attempt barriers, optimistic snapshot revisions and atomic result application.
- Validate batch correlation, exact operation membership, stream/sequence order and retry hints.

Projection and conflict resolution
- Pass decoded TInput to synchronous remote projections alongside the immutable event envelope.
- Add deterministic conflict resolver contracts and defensive copies of all decision collections.
- Provide explicit cancellation-free extension overloads with forwarding verification.

Verification and documentation
- Add type-specific TUnit tests and behavioral regressions for malformed results and collection ownership.
- Verify 257 Core tests per modern framework with 100% line and branch coverage.
- Build all eight Core frameworks without warnings, errors or new suppressions.
- Document completed contract guarantees and pending runtime/storage enforcement.
…chronization

Capability requirements
- Intersect known transport and authenticated peer features and batch limits.
- Reject unsupported durability, cursor, lease, multiprocess and encryption requirements.
- Require idempotency for at-least-once and transactional inbox/effect/acknowledgement support for exactly-once.

Retention and protocol
- Select supported protocol 1.0 and reject incompatible major versions.
- Expose the effective exactly-once window bounded by actual client/server retention.
- Reject unsupported inbox retention promises and clear peer-provided effective guarantee claims.

Validation
- TDD: 35 failing stub cases plus a failing durable-inbox regression before correction.
- 257 Core and 198 runtime TUnit tests per modern target; 100% line and branch coverage via MTP.
- All eight library targets build without warnings, errors or new suppressions.
…ueues

Observer behavior
- Bound each subscription by count and estimated bytes with independently scheduled serial drains.
- Coalesce optional latest-state overflow while always disconnecting overflowing event observers.
- Preserve accepted data before terminal callbacks and clear unclaimed work on disposal.

Failure isolation
- Return scheduler rejection after clearing the subscription without calling consumers or diagnostics inline.
- Contain observer and fault-reporter failures; retain a fixed-size reporter health flag.
- Handle thread-pool queue rejection and avoid nullable suppressions or ineffective exception-observation code.

Validation
- Agent regression RED plus root failing reporter-health regression before fixes.
- 226 runtime TUnit tests per modern framework with 100% lines and branches via MTP.
- All eight library targets build without warnings or errors; tests follow production-type naming.
…faults

Fault contracts
- Add stable component categories and information/warning/error/critical severity.
- Add immutable category, severity and transient-status properties while preserving existing constructor calls.
- Validate nonblank codes, diagnostic messages, defined classifications and optional identifiers.

Validation
- Seven executable negative cases failed before implementing classification and identity checks.
- 268 Core TUnit tests per modern framework with 100% lines and branches via MTP.
- All eight Core library targets build without warnings, errors or new suppressions.
Configuration
- Add required-init typed stream definitions for projection, stream identity and input/state contracts.
- Validate schema and snapshot versions, nested identities, priority bounds and custom policy support.
- Publish matching API baselines for all eight library targets.

Verification
- Add behavioral TUnit tests for defaults, invalid contracts, durable subscription identities and nested policy validation.
- Verify 289 Core tests on each modern runtime with 100% line and branch coverage.
- Build all eight Core library targets without warnings or suppressions.
- Document the verified stage and remaining context identity integration.
…ker (#198)

* feat(occasionally-connected): add validated identities and start positions

Core models:
- Add the new Core package with NFC stream identity validation and bounded opaque subscription start positions.
- Track its public API on all eight supported library target frameworks.

Validation and integration:
- Add 40 TUnit tests with executable failing-stub evidence followed by passing implementations.
- Enforce 100% line and branch coverage without source, method or attribute exclusions.
- Add feature-branch CI and retain per-platform coverage reports.
- Preserve the design specification and document the remaining staged v1 work.

Verification:
- Release builds pass all eight library TFMs with zero warnings or errors.
- TUnit passes on net8.0, net9.0, net10.0 and net11.0; MCP confirms 66/66 lines and 58/58 branches.
- NuGet packing succeeds without new warning suppressions.

* feat(occasionally-connected): validate publishing and subscription options

Core identities and options
- Add stable operation and subscription IDs, delivery/conflict/buffer enums, and immutable option records.
- Validate stream identities, bounded capacities, custom policy registration, configurable priority ranges, and synchronous observer constraints.
- Reject dropping admission for durable work and non-durable exactly-once requests.

Validation
- Expand the suite to 90 TUnit tests on each modern framework; disabling validation causes 29 failures.
- Verify 100% line and branch coverage with Mtpunittestmcp on all four modern frameworks.
- Build all eight library frameworks and refresh API baselines with no warnings or suppressions.

* feat(occasionally-connected): define validated batch limits

Batch configuration
- Add immutable operation count, encoded-byte, dwell-time and per-stream concurrency limits.
- Match the design defaults and reject non-positive limits before runtime initialization.

Validation
- Start with ten tests against a compilable stub; eight fail before implementation.
- Verify 100 passing TUnit tests on each modern framework and 100% line/branch coverage through Mtpunittestmcp.
- Refresh all eight public API baselines without suppressions.

* feat(occasionally-connected): add deterministic endpoint circuit breaker

Runtime policy
- Add the lean runtime project and thread-safe closed/open/half-open admission with TimeProvider injection.
- Apply configurable five-failure and thirty-second defaults, one recovery probe, successful reset and explicit abandoned-probe recovery.
- Preserve deadlines on late failures and bound failure counts and UTC deadline arithmetic.

Verification
- Root review completes the worker handoff and removes unreachable state branches without suppression.
- Pass 106 Core and 15 runtime TUnit tests per modern framework with 100% line and branch coverage inspected via Mtpunittestmcp.
- Verify threshold mutation causes seven failures and refresh all eight public API baselines.
Coverage tooling
- Upgrade Microsoft.Testing.Extensions.CodeCoverage from 18.11.0 to 18.11.2, the upstream fix for SharedBufferReconciler AbandonedMutexException (microsoft/codecoverage#245).
- Cancel superseded feature coverage runs while retaining the complete OS/framework matrix and strict coverage gate.

Deterministic verification
- Add a fixed-clock resumed-operation test proving elapsed age reduces the remaining retry budget; replacing elapsed-age handling produced an executable failure.
- Give the existing async-enumeration completion guard 30 seconds on instrumented CI runners and dispose its subscription; preserve all value/completion assertions.

Validation
- Strict builds pass for Core, runtime and existing test projects on net8/net9/net10/net11 without warnings.
- All 289 Core and 227 runtime tests pass on every modern TFM with collector18.11.2; MTP confirms 100% matching-package line and branch coverage.
- The affected existing SignalOperatorMixins test passes on all four modern TFMs.
- No suppressions, test skips, coverage exclusions or relaxed coverage thresholds added.
Transaction kernel
- Require validated durable recovery before local publishing and reject overlapping operations without an unbounded waiter queue.
- Serialize and decode persisted input before pure optimistic projection, then atomically store operation and snapshot with expected revision.
- Advance visible state only after validated commit receipts; retain successful receipts after late cancellation and poison malformed store results.
- Recover stable identity, snapshot, cursor and sequence without replaying already-projected pending operations.

Validation
- Exercise cancellation, failed storage, corrupt recovery, malformed receipts, overflow and policy validation using TUnit.
- Add restart and stale-writer tests with atomic revision/sequence checks and explicitly complete concurrency test operations.
- Verify 263 runtime tests on each modern framework with 100% matching-package line and branch coverage using collector18.11.2.
- Build all eight runtime library targets with zero warnings/errors and no suppressions.

Scope
- Keep queue/lifecycle/remote synchronization integration and concrete durable adapters as subsequent stages.
… resolution

Contract
- Resolve one durable subscription identifier per initialized store and stream.
- Specify first committed mapping wins, explicit preference mismatch rejection, and cancellation without deleting other committed mappings.
- Add the explicit no-cancellation overload and all eight public API baselines.

Validation
- Verify exact forwarding and failure propagation with TUnit; mutation of the preferred identifier produced an executable regression failure.
- Pass 291 Core and 263 runtime tests on each modern framework with 100% matching-package line and branch coverage.
- Build all eight Core library targets without warnings or errors.
- Document that concrete durable-store identity conformance remains separate implementation work.
Behavior
- Add QueueCapacityExceededException with an immutable hint indicating whether an operation may fit after draining.
- Keep standard exception constructors conservative: failures without a hint never automatically wait for capacity.
- Preserve messages and wrapped causes and reject null messages before use.

Validation
- Add TUnit cases for full queues, permanently oversized items, standard constructors, wrapped failures and null messages.
- Verify an inverted hint fails three executable tests before restoring the implementation.
- Pass all 296 Core tests on each modern framework with 100% line and branch coverage.
- Build all eight Core targets without warnings or errors and update their public API baselines.

Scope
- Define the failure contract; store capacity enforcement and producer waiting remain subsequent integration stages.
API: Forward operation application and remote subscriptions with explicit CancellationToken.None while preserving argument and result identity.

Validation: Add four TUnit forwarding, ordered enumeration and exception propagation tests. Root mutation fails before restoration. All 300 Core tests pass on each modern target at 100 percent line and branch coverage; all eight library targets build cleanly.
Transactions: Share exclusive ownership with local commits and recovery. Filter durable inbox duplicates before decoding and projection, then persist cursor and snapshot under the expected revision. Validate receipts before state publication and fail closed on adapter contract violations.

Recovery: Preserve cursor monotonicity for duplicate replays, commit duplicate cursor advances, reject stale revisions and retain successful receipts after cancellation.

Validation: Add remote protocol, retry and restart, malformed receipt, cancellation and overlap TUnit cases. Root dedup mutation caused eleven failures before restoration. All 298 runtime tests pass on four modern targets with 100 percent matching line and branch coverage; all eight library targets build cleanly.
Storage: Add a file-backed identity component with atomic first-write-wins mappings per store partition and stream. Validate schema ownership and definitions, verify WAL and FULL synchronous durability, reject malformed records and incompatible initialization, and preserve committed mappings through cancellation and reopen.

Packaging: Add SQLite library and TUnit projects to the solution. Use Microsoft.Data.Sqlite 10.0.12 and the corrected SQLitePCLRaw bundle 2.1.13 with normal runtime assets and public API tracking enabled.

Validation: Add 37 real-file TUnit tests per modern target for reopen, competing writers, schema corruption and lifecycle/cancellation failures. Root mutation failed the cross-stream mapping regression before restoration. Matching package coverage is 100 percent lines and branches across four targets; all eight library targets and package creation pass.
Behavior: add decoded remote messages, subscription and publish interfaces, and explicit cancellation/default-input convenience overloads.

Validation: root-reviewed 308 TUnit tests per modern target, 100% matching line and branch coverage, all eight library builds, and an executable input-forwarding mutation regression. Concrete facade implementation remains pending.
… APIs

Replace the oversized positional operation example with the approved required-init shape and persisted policy. Show decoded TInput in ApplyRemote and document owned metadata semantics to match the verified Core API.
API
- Add typed stream interfaces and explicit publish/start/stop overloads.
- Document local replay, committed remote delivery and producer-local input semantics.
- Record the API across all eight supported library frameworks.

Validation
- Add TUnit forwarding, type-surface, reference-identity and failure propagation tests.
- Root cancellation mutation fails as expected before restoration.
- All 315 Core tests pass on each modern TFM with 100% matching line and branch coverage.
- All eight Core library targets build without warnings or errors.

Scope
- Contracts only; concrete stream runtime and durability integration remain pending.
Context API
- Add the context-owned sync engine, lifecycle observable and typed stream factory interface.
- Provide explicit no-cancellation start and stop convenience overloads and all eight API baselines.

Verification
- Verify incomplete lifecycle forwarding, exact calls and unwrapped failures with TUnit.
- Root mutation redirecting start to stop compiled and failed three tests before restoration.
- All 319 Core tests pass per net8-net11 with 100% matching line and branch coverage; all eight library targets build cleanly.

Documentation
- Align context cancellation signatures with the approved API shape and record component-only scope.
Storage transactions
- Share exact schema validation and migrate identity schema v1 to local commit schema v2 atomically.
- Commit partition-scoped outbox records, snapshots and monotonic sequence updates in one transaction.
- Preserve exact replay receipts with canonical intent fingerprints independent of later snapshots.
- Reject sequence and revision overflow plus inconsistent recovered cursors, pending sequences and subscription identities.

Durability and concurrency
- Validate ownership before persistent journal changes; apply foreign keys and FULL synchronous settings per connection.
- Bound writer lock waits and observe cancellation between attempts while preserving committed receipts.
- Keep clock callbacks outside the storage gate and reject required encryption before plaintext writes.

Verification
- Add real SQLite reopen, competing-writer, migration, corruption and rollback tests using TUnit assertions.
- Fix six executable RED recovery and overflow cases; independently verify actual connection settings through SQL probes.
- All 82 tests pass per net8-net11 with 100% matching line and branch coverage; all eight library targets build cleanly.
- Keep this component internal; full adapter, remote inbox, leases, encryption and process-crash conformance remain later stages.
Preserve preallocated capacities for remote event identifiers, filtered events, decoded inputs and validated lookup snapshots while satisfying the merged SST2106 analyzer.

Validation: Core319, runtime298 and SQLite82 TUnit tests pass on each of net8, net9, net10 and net11. Matching package coverage is 100 percent for lines and branches on all twelve reports. The broader consolidated solution build is still running.
…Lite

Storage: migrate identity and local-commit schemas transactionally to version three; atomically commit inbox identifiers, projected snapshots and batch cursors with revision and cursor checks. Scope lookups to requested identifiers and record local application time for retention.

Validation: cover reopen, filtered cursors, duplicate races, rollback, partition isolation, corruption, cancellation and historical migration. Root verified 97 TUnit tests on each net8-net11 target with 100% line and branch coverage plus all eight library target builds without warnings or suppressions.
…te storage stage

Record completed local branch cleanup and the zero-warning full solution build, along with root-reviewed remote inbox transaction behavior and all-target TUnit coverage. Keep incomplete adapter and runtime stages explicit.
API: add cancellable durable status lookup and explicit no-token convenience overload so synchronization waits can recover terminal outcomes after restart.

Verification: preserve incomplete status operations and exact returned records; root mutation of operation identity fails two tests. All 321 Core TUnit tests pass per net8-net11 with 100% line and branch coverage; all eight library targets build cleanly.
Worker: serialize commands on one dedicated processing task with FIFO ordering, active-inclusive count and retained-byte limits, immediate capacity rejection, queued cancellation removal and shared asynchronous disposal.

Safety: release cancellation registrations across completion races without a test-only callback, preserve committed results after cancellation, and complete all queued work before disposal finishes.

Validation: root capacity mutation produced a behavioral failure; restored implementation passes 105 SQLite TUnit tests on each modern target with 100% package line and branch coverage and all eight library builds without warnings or suppressions.
Subscribe before persisted status lookup to avoid missed completion races. Add explicit cancellation and injected clock overloads, terminal failure handling, and subscription cleanup without waiting on adapter cancellation callbacks.

Validation: 321 TUnit tests pass on net8 through net11 with 100% runtime line and branch coverage. All eight library targets build without warnings or errors. Executable regressions cover premature completion and blocked cancellation callbacks.
ChrisPulman and others added 29 commits October 1, 2026 08:25
Keep the manual clock advancing while the lost-ACK observer waits for remote and local convergence. A parked HTTP subscription can time out before the writer releases the host gate; its receive retry may be registered after the one-time writer retry advance. Freezing manual time then prevents observer convergence indefinitely.

Preserve the existing whole-scenario deadline, HTTP timeout, retry policy, durable proofs and cleanup error aggregation. Add deterministic regressions for a late receive timer and cancellation. Complete net10 resilience suite: 113 tests passed with normal analyzers and fresh coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the cross-stream SQLite acknowledgement/admission test apart from unrelated database fixtures during profiled runs. Preserve its two streams, blocked publisher, real durable acknowledgement and five-second guards. Full Release net10 runtime validation passes: 1692 tests and four existing capability skips with fresh coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ble lanes

Wait until the virtual retry timer is registered before advancing manual time in the disposed-session retry test. Persisting retry state does not prove that the scheduler has installed its timer.

Run the strict real SQLite capacity-release and disposal-drain fixtures apart from unrelated database work. Keep their blocked producers, durable receipts and original guard deadlines unchanged.

Full Release net8 runtime validation with two CPUs and fresh TUnit coverage: 1692 passed, four existing capability skips, no warnings.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run the real Node event bridge fixture apart from competing lifecycle fixtures during profiled execution. Keep its 15-second process guard, shipped JavaScript assertions, both target frameworks and complete listener/disposal checks unchanged. Both Web suites pass: 38 tests, normal analyzers and fresh coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…elease blockers

Restore complete release-filter membership and distinguish stable package assets from experimental net11 assets without suppressing package warnings. Verify actual stable and prerelease release-filter packing and complete consumer dependency closure.

Make equal-stamp CRDT merges deterministic, align collection bounds, and add explicit causal OR-set checkpoints that retain permanent caller-proven retired frontiers. Preserve legacy payload bytes for states without checkpoints.

Retain server operation replay results for thirty days by default and let subscriber history expire independently without deleting idempotency proofs. Persisted exactly-once first-attempt anchors stop lost-ACK operations before resending after their window expires, including restart after days offline.

Build and stage all supported Mobile native heads before final release signing. Bind database ownership to canonical paths and secure installation identities; fail closed for missing keys or installation markers. Preserve .NET Framework path safety and compatibility.

Scope authenticated record encryption claims accurately: malicious whole-file rollback or arbitrary deletion requires an independent checkpoint outside the database. Add regression evidence for that boundary instead of promising unsupported freshness protection.

Keep WebSocket event lanes bounded while allowing concurrent ACK progress, and propagate sticky receive failures to current and future requests.

Independent reviews found and verified corrections for existing-subscription receive expiry and missing installation marker recovery. Complete feature coverage gate, normal referenced suites, stable and prerelease twenty-package gates, determinism, Source Link, and all eight clean-consumer targets pass locally. Apple-inclusive native package verification remains a required CI gate.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…very

Native workload jobs use the supported .NET 10 SDK with explicit preview language syntax required by the repository's existing collection-expression arguments. Replace inline PowerShell orchestration with Bash dotnet commands and a tested dotnet-run SDK selector.

Serialize mount enumeration across SQLite owners. The .NET 8 macOS native implementation uses getmntinfo's shared buffer; concurrent calls caused an AccessViolation in the required conformance run. Preserve longest-mount network checks and add a concurrent independent-owner regression.

Use structured net11 process exit status in new junction fixtures, including cancellation and signal assertions, while retaining older target APIs.

Model the existing late-ACK registration test as an irreversible send whose response arrives after cancellation, rather than a cancellable before-send pause. Drive observed virtual upload wakes after the recovered retry due time so asynchronous merge callbacks cannot leave the test clock frozen. Preserve guard deadlines and all ordering/retention assertions.

Verified Windows/Android native packing with SDK 10.0.301, all 64 Mobile tests against the exact native package/version/commit, net11 ownership helpers, and the complete net8 runtime suite (1704 passed, four capability skips). SDK selector fixture and workflow Bash syntax checks pass.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Build Windows resources on Windows rather than executing MakePri.exe on macOS. The Apple job builds Android, iOS and Mac Catalyst assets; a dependent composition job imports the matching Windows native assets and symbols into one unsigned complete package before the existing final signing/publication gate.

Validate exact package identity, version and repository commit, reject signed or missing inputs, bound archive counts/bytes, retain normalized NuGet framework folders and Windows PRI content-type metadata, and produce deterministic archives. No partial or fallback artifact is published.

Add six TUnit regression cases for four-head asset/symbol preservation, Windows dependencies/resources, mismatched version/commit, missing symbols, signed inputs and deterministic output. All pass with normal analyzers. Workflow Bash syntax and supported-host dependency checks pass. Native CI still proves the actual Apple-inclusive complete artifact.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Move file-app local functions into explicit static PackageInspector methods so the compiler-generated entry point no longer aggregates the full inspector into a zero-maintainability method. Preserve every inspection, output and nonzero failure result; do not suppress CA1505.

Verified the exact CI composition and verify-native commands against real Windows and macOS artifacts from run36913014819. The complete package contains neutral net10 plus Android, iOS, Mac Catalyst and Windows assets, matching symbols, exact source/version, deterministic debug identity and resolvable Source Link. All checks passed with normal analyzers.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run the three custom overflow fixtures with TUnit NotInParallel, matching the existing durable overflow fixture. Windows net8 coverage exposed simultaneous five-second publication guards while unrelated synchronous SQLite fixtures occupied the worker pool. Keep every assertion and guard unchanged and document the resource isolation.

The complete net8 runtime suite passes with coverage and two logical processors: 1710 passed, four capability skips, zero failures. Runtime coverage remains 98.95% lines and 97.87% branches.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…olls

Release the completed publish's active-call slot before signaling subscription polls. Signal under the lifecycle gate before completing the disposal drain so the semaphore cannot be closed between release and wakeup. Failed publishes still do not signal.

Linux net11 CI exposed the previous race: an idle poll woke while the successful publish still held the sole slot and terminated with QueueCapacityExceededException. Keep the original regression and capacity limits unchanged.

Full net11 Server coverage suite passes: 567 tests, zero skips or failures. ReleaseActiveCall has 100% line and branch coverage across publish, failure and disposal paths.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep all four independent owners concurrent but isolate the mount-discovery regression from unrelated synchronous database fixtures using TUnit NotInParallel. Cancel and drain its workers before removing the temporary directory, including when the unchanged guard fails, so Windows cleanup cannot mask the original timeout with a sharing violation.

The exact native SDK10 full SQLite coverage suite passes with two logical processors: 576 tests, three unavailable symlink-privilege skips, zero failures. Native CI uses the same supported ownership checks without retries or increased guards.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Isolate the virtual-clock deferred-recovery fixture from unrelated synchronous SQLite work, as for the existing recovered retry/merge fixture. Sonar's instrumented Windows run timed out only after the recovered batch had been sent, while waiting for its durable acknowledgement commit. Keep pre-start deferral, operation ordering, synchronized-state assertion and the original guard unchanged.

Full runtime net10 coverage passes with two logical processors: 1710 tests, four capability skips, zero failures.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Replace the builder fixture's CPU-count limiter with TUnit NotInParallel. Limiting thread-pool concurrency does not bound competition between the dedicated synchronous SQLite workers used by these cold initialization and durable commit fixtures. Windows coverage demonstrated simultaneous first-publication and startup timeouts with no pending thread-pool work, so per-method isolation was insufficient.

Preserve every guard, assertion and internally concurrent producer, cancellation, reconnect and recovery scenario. Isolate the fixture at its actual resource boundary rather than continuing to special-case individual failing tests.

The full net8 runtime coverage suite passes with two logical processors: 1710 tests, four capability skips, zero failures, under38 seconds.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove the reserve-and-release TCP port race exposed by macOS net10 coverage. Both the in-process runner and real executable now request loopback port0 and observe the actual bound endpoint instead of reopening a supposedly free port.

Share application creation/ownership in the existing runner without changing public signatures or asynchronous exception behavior. Observe in-process ApplicationStarted and child host lifetime output, retain the health, database, cancellation and disposal assertions, and keep one original ten-second readiness deadline across endpoint discovery and health probing. Refresh all four example API baselines for the required inlining attribute.

Complete net10 Collaboration.Server TUnit coverage: 138 tests passed, zero skips or failures. No retries, suppressions or increased deadlines.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove unrelated automatically timed cancellation from four replay completion fixtures. Windows net8 instrumentation delayed their continuations until the one-second caller token expired, so the duplicate completed from cancellation before the session-registration or owner-disposal action being tested.

Use uncancelled duplicate admission, matching the adjacent lifecycle fixtures, while retaining the exact50ms pending observation and1000ms completion guards. The owned coordinator still drains waiters on failure; explicit caller-cancellation tests are unchanged. This makes the assertion prove owner/session behavior instead of racing an unrelated token timer.

Full net8 HTTP coverage:970 tests passed. HttpReplayCoordinator remains100% line and branch coverage, including CancelWaiter and atomic-owner-close failure paths. No increased guard, suppression or retry.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the browser bridge test's original15-second exit deadline. Do not cancel its output drains at the same moment as the process wait: kill the owned process if necessary and drain both streams before disposing its handle. Report a timeout with process-exit and stream-task states instead of losing evidence in a generic TaskCanceledException.

Windows net10 CI exposed a Node process wait exceeding the deadline; the JavaScript assertions and shipped bridge remain unchanged. This improves cleanup and diagnosis without hiding the timeout, retrying Node or increasing its test deadline.

Full Web net10 TUnit coverage:19 tests passed. BrowserLifecycleAdapter remains100% line and branch coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Run the durability cancellation signal on a joined dedicated thread, matching the adjacent real writer-lock fixture. Signal entry, retain the original100ms cancellation delay, and cancel without depending on a thread-pool timer while the test synchronously waits for SQLite.

Windows net8 instrumentation delayed the old timer until the unchanged five-second writer deadline expired, producing TimeoutException instead of the expected OperationCanceledException. Preserve that exact cancellation assertion and every production deadline; join the signal worker even when the assertion fails.

Freshly rebuilt full net8 SQLite TUnit coverage passes:576 tests, three unavailable symlink-privilege skips, zero failures or build warnings. No retries, suppressions or deadline increases.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ates

Run the durable SQLite performance measurement in runner.temp rather than the operating-system profile's default temp directory. Set TMP, TEMP and TMPDIR only for the performance step, and include the actual database path in the result so hosted storage differences are visible.

Keep FULL synchronous writes, all512 offline operations, the10 commits/second floor, allocation limits and15-second recovery/compaction budgets unchanged. Document the measurement location. Do not introduce the separately deferred connection-pooling work.

Windows hosted performance reported5.0 commits/second in the default location. The explicit measurement passes locally in temporary work storage with the unchanged budgets. All other completed current-head gates, including Sonar analysis/quality gate, passed; new CI must verify the hosted work-volume result.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reuse the existing manual receive-clock driver while waiting for the reopened writer's durable synchronization proof, not only while waiting for the independent observer. An upload ACK can synchronize its operation before a parked receive poll or retry stores the cursor; freezing shared time at that point strands receive progress until the scenario deadline.

Keep all persisted cursor, snapshot, pending-count, idempotency and recovery predicates and the original scenario deadline. Preserve proof exceptions through the clock driver and document both clock-driven convergence phases.

Complete net9 ResilienceLab TUnit coverage:114 tests passed, including both real lost-ACK recovery and cleanup-error propagation. Added a failed durable-proof propagation regression. IsDurablySynchronized remains100% line and branch coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Storage conformance and durability
- Ship a reusable local-store conformance source kit and TUnit coverage for rollback, cancellation, corruption, restart, ownership, native process termination, and browser IndexedDB persistence.
- Use incremental filesystem journal deltas with bounded growth and strict recovery of incomplete trailing frames.

SQLite and server efficiency
- Reuse initialized connections and bounded prepared statements with serialized transaction lifetimes and safe cancellation/disposal.
- Add transactional outbox capacity counters, authenticated charge integrity, and selected-key metadata batching.
- Batch server processing and event selection, index receive queries, avoid write reservations for empty offers, bound worker admission, and broadcast receive wakeups.

Packaging and samples
- Disable MSBuild node reuse in deterministic package builds to prevent retained PDB locks.
- Compose atomic sample counter snapshots and add concurrent snapshot regressions.
- Preserve provider capability boundaries and existing startup compatibility.

Documentation and verification
- Track Glenn review items 1-15, supporting evidence, capability limits, and remaining items 16-33 in docs/GlennReviewTracking.md.
- Include the previously verified .NET 8-11 TUnit conformance suites, SQLite/server regressions, and stable/prerelease package-consumer gates.
- Remote CI must independently validate this new head; this commit does not assert all checks are green.
Ownership fix
- Acquire a persistent exclusive sidecar before opening LiteDB and retain it for the adapter lifetime.
- Prevent competing Unix writers from mutating a database behind cached adapter state.
- Release ownership after database disposal and on failed initialization, including exceptional cleanup.

Regression tests
- Add TUnit checks for competing-owner rejection, retry after disposal, and identity-validation failure cleanup.
- Retain the existing live competing-writer and process-kill durability assertions unchanged.

Verification
- Release .NET 8 and .NET 10 LiteDB builds: zero warnings/errors; each suite passed 13 tests.
- Rebuilt .NET 8 conformance: 135 passed, 4 legitimate transport-capability skips; MTP coverage inspected.
- Full local coverage reached filesystem tests but found an independent Windows File.Replace failure under investigation; all four existing remote Windows coverage jobs passed.
- Remote CI must verify the new head on Linux, macOS, and Windows. No gates, thresholds, or CodeQL settings changed.
…eanup

Deterministic retry regression
- Wait for the exact upload retry timer before advancing virtual time.
- Add a controlled retry-save completion gate after state publication to prove persisted state is not timer readiness.
- Preserve two sends, two lease releases, the configured single retry, and the terminal fault assertions.
- Release the controlled gate in an outer finally before engine disposal.

Owned process cleanup
- Join the example server and require exclusive access to its fixture files before directory cleanup.
- Share the original five-second shutdown deadline, starting before termination, across exit and file-release waits.
- Propagate join cancellation and unrelated I/O failures; wait only for Windows sharing/lock violations.
- Add three TUnit tests for release, cancellation, and non-sharing failure propagation.

Verification
- Runtime analyzer-enabled Release .NET 8/9 builds: zero warnings/errors.
- Runtime TUnit suites: 1711 passed and four legitimate skips on each framework; MTP coverage above existing thresholds.
- Collaboration.Server analyzer-enabled Release .NET 8/10 builds: zero warnings/errors; 141 TUnit tests passed per framework.
- Independent review preserved production behavior, timeouts, assertions, and quality gates. CodeQL settings remain unchanged.
…indows

Browser startup
- Share one bounded DevToolsActivePort wait across initial startup and process restart.
- Wait for Windows EBUSY while Chromium publishes the port file; retain the original 45-second deadline and 25-ms polling interval.
- Continue propagating permission errors, non-Windows busy errors, process exits, and deadline cancellation.

Regression tests
- Add six deterministic TUnit cases for startup readiness, strict errors, process exit, and deadline handling.
- Keep all existing real-browser IndexedDB transaction and process-restart assertions intact.

Verification
- Fresh analyzer-enabled Release net10 build: zero warnings and errors.
- Full net10 conformance with installed Chromium: 153 passed, four legitimate transport skips, zero failures.
- MTP coverage inspected; no thresholds or gates changed.
Completion synchronization
- Observe the Task-owned completion event directly in the background-thread test helper.
- Avoid racing queued Task.WhenAny completion notifications against a timer after the worker has already completed.
- Retain the original five-second bound and completion-only fault/cancellation semantics.
- Leave production DeliveryGate code and all deadlock-regression assertions unchanged.

Regression tests
- Cover successful, faulted, and canceled operations.
- Verify a blocked worker still fails its deadline even when it later completes.
- Keep task-owned wait-handle lifetime with its Task.

Verification
- Fresh analyzer-enabled Release builds for net8, net9, net10, and net11: zero warnings and errors.
- Full suites run concurrently under coverage: 1661, 1663, 1663, and 1663 passed respectively, with zero failures or skips.
- MTP coverage inspected and independent source review completed; no suppressions, retry policies, or gate changes.
Regression verification
- Await the original faulted and canceled tasks and assert their exact exceptions with TUnit.
- Avoid leaving the deliberately injected fault unobserved.
- Keep the five-second completion guard and production code unchanged.

Validation
- Fresh analyzer-enabled Release builds for net8/net9/net10/net11: zero warnings and errors.
- All four helper regression cases pass concurrently on each of the four frameworks.
SQLite ownership
- Replace server connection leases with lexical Monitor lock scopes and disposal rechecks.
- Keep local store connection acquisition and release in one callback scope, preserving reentrancy and 10 ms cancellation polling.
- Finish native transaction/cancellation cleanup before releasing ownership, including failed preparation and retirement.
- Split local commit implementation into a focused partial file to retain analyzer limits.

Browser lifecycle
- Invoke synchronous notification callbacks directly without redundant void expressions.
- Preserve bounded asynchronous delivery, disconnect recovery, and departed/frozen state transitions.

Regression verification
- Add cross-thread ownership release, reentrant failure, competing-owner cancellation, and lifecycle resume/pageshow tests using TUnit.
- Fresh server and SQLite analyzer builds and full suites pass on net8/net10; Web net10 suite passes.
- Full OccasionallyConnected net8 coverage gate passes unchanged 95% line/90% branch core thresholds.
- No suppressions, quality gate changes, CodeQL settings, or public API changes.
Retry telemetry regression
- Wait for the replacement retry timer registered after a second explicit sync request before advancing virtual time.
- Track timer registration generations under the manual clock lock and expose a test-only creation barrier for the exact retry delay.
- Exercise both immediate and deliberately held replacement registration; assert pending requests and no early retry before releasing the barrier.
- Release synchronization hooks in finally and keep their event alive through engine disposal.

Verification
- Retain the original retry delay, single virtual-time advance, two sends, durable operation identity, synchronized state, empty outbox, and guard deadline.
- Fresh Release analyzer builds on net8/net10 report zero warnings/errors.
- Full TUnit runtime suites pass 1712 tests with four existing capability skips on each framework; MTP coverage remains approximately 98.95% lines and 97.87% branches.
- No production retry behavior, quality gates, suppressions, or CodeQL settings changed.
@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants