Repository navigation
Conversation
…e their body completes Complete the #1091 request-boundary acceptance cases and document the bounded HTTP admission contract.
The request-boundary fix changes bound runtime source, so publish specification coverage 69.0.0 and formal semantic validation 70.0.0. Replayed outcomes and claim limits are unchanged.
Open
11 of 12 tasks
Name the existing size-guard tests in the #1091 module docstring and say why they stay. Drop the 16 parametrized cases whose input repeated another case under a misleading id, require exactly one response start per exchange, and limit the guard's log to the fixed audit-failure message. The guide now says that a route runs once the adapter has read the last body chunk, and that a server can report a disconnect after the client has sent the whole body.
P0 now declares exactly-once-effects and P2 declares multi-owner, so every available profile names the API-404-C4 exclusions that apply to it. The runtime architecture table and the P2 guide state the same limits.
The profile declaration change moves the bound implementation digest, so publish specification coverage 70.0.0 and formal semantic validation 71.0.0 above the #1091 releases. Replayed outcomes and claim limits are unchanged.
doublewhy
force-pushed
the
8-stronger-claim-exclusions
branch
from
October 9, 2026 12:44
01ce1b8 to
a18c821
Compare
doublewhy
marked this pull request as ready for review
October 9, 2026 15:06
9 of 11 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Builds on #1431. The first three commits on this branch are #1431's. They leave the diff once this branch is rebased onto dev after #1431 merges. The evidence is then re-checked against dev and regenerated if #1431 changed before merging or dev gained another evidence release. This PR adds two commits: the declaration change and its evidence republish.
#8 asks that documentation and capability declarations exclude multi-owner operation, high availability, exactly-once external effects, and deployment TLS guarantees. API-404-C4 already says that P0, P1 and P2 must not imply any of them, and the #1185 decision asks for these exclusions to be "explicit where applicable". Two declarations each left one out:
multi-ownerandhigh-availabilitybut notexactly-once-effects, though its deduplication ends with its process.test_p0_process_loss_loses_run_and_claim_even_when_external_effect_survivesresubmits after process loss and records the backend effect twice. Its own comment says P0 "cannot promise exactly-once effects".multi-workerbut notmulti-owner, though it serves exactly one P1 core and P1 namesmulti-owner.This PR adds those two nonclaims and mirrors them in the runtime architecture table. It also adds a paragraph to the P2 deployment guide on what the adapter does not provide. TLS stays a P2-only nonclaim (
tls-proxy-deployment), because P0 and P1 declare no transport. Because this changes source bound by the research evidence, both captures are republished one release above #1431's (specification coverage 70.0.0, formal validation 71.0.0). Retained outcomes, classifications and claim limits are unchanged.Together with #1431 (the request-boundary cases) and #1443 (the clause-to-profile map, the run-binding cases and the traceability), this covers #8's done-when list. #8 has a Requirements section, so it is referenced, not closed, and stays open for post-merge requirement verification.
Requirement UIDs
API-404Related Issues
Refs #8
ADR Impact
docs/decisions/issue-1189-control-plane-profile-declaration-preflight.md, lines 49 and 51) still lists P0's nonclaims without exactly-once effects and P2's without multi-owner or multi-process ownership. That decision makes the runtime catalog the canonical owner of nonclaim identifiers (lines 10-15). The docs(runtime): align API-404 with control-plane profiles #1185 decision's "explicit where applicable" row for excluded stronger claims (docs/decisions/issue-1185-api-404-profile-alignment-preflight.md, line 47) and API-404-C4 authorize the two additions. The dated decision record stays unedited.Changes
raes_runtime/control_plane_profiles.py: the P0 declaration gainsexactly-once-effects("External backend effects are not exactly once.") and the P2 declaration gainsmulti-owner("No concurrent process ownership is promised."). Both reuse the identifiers and descriptions P1 already declares, now held in shared constants. No guarantee, capability, actor boundary or availability changes.tests/test_issue_1189_control_plane_profile_declarations.py: the canonical matrix expects the two added nonclaims.docs/explain/sdl/runtime-architecture.md: the profile table's P0 and P2 nonclaim cells match the declarations.test_explain_profile_identifiers_match_canonical_catalogchecks them.docs/public/guides/control-plane.md: a paragraph at the end of "Deploy the adapter". The adapter is one process that owns one store, with no high availability and no operation by several owners or workers. RAES does not guarantee that a backend effect happens exactly once, and it never replays one (P2'sretained-idempotencyandstartup-reconciliationguarantees). After a crash, an operation whose effect cannot be established becomesINDETERMINATEand keeps that state.POST /operations/{operation_id}/resolutionrecords a separate linked operation and leaves the original unchanged:resolve_indeterminate_operationclaims anINDETERMINATE_RESOLUTIONchild and never rewrites the parent, asdocs/explain/sdl/control-plane-operations.mdalso states. TLS and proxy correctness belong to the deployment.execution-snapshot-v70.json,analysis-v70.json, issue-8 bundle) replays the retained matrix against this branch's source.execution-snapshot-v71.json,analysis-v71.json,retest-v71.json) replays the retained formal cases with baseline 70.0.0 and no deviation.tools/check_specification_coverage.py,tools/formal_semantic_validation/, and the three evidence test modules. Both research indexes record the new releases.Test Plan
The SonarCloud quality gate passed on canonical run 37932071922: new-code coverage 100.0%, 0 new violations and 0.0% duplication.
pytestontest_issue_1189_control_plane_profile_declarations.py,test_issue_1185_api_404_profile_alignment.py,test_issue_1151_runtime_control_plane_design.pyandtest_issue_1187_control_plane_profiles.pypassed (37 passed). Under-m integrationthe four modules select nothing (37 deselected). With onlycontrol_plane_profiles.pyrestored to the base branch, two 1189 cases fail: the canonical matrix and the runtime architecture table check.The guide's sentences on recovery and resolution rest on existing cases in
test_issue_1179_startup_reconciliation.py, which passes (22 passed; nothing selected under-m integration).test_running_claim_without_observer_is_indeterminate_and_retry_never_replaysshows that an interrupted claim with no observer becomesINDETERMINATEand that a same-key retry applies nothing.test_resolution_creates_fresh_linked_operation_and_unblocks_mutation_without_rewriting_parentshows that the parent record is unchanged after resolution and that the child is a linkedINDETERMINATE_RESOLUTIONoperation.test_http_resolution_is_operator_only_and_returns_stable_errorsshows that the HTTP route refuses a backend identity with403and returns the linked child's receipt to an operator.Evidence: the republish ran against
origin/1091-request-limit-boundaryat11854670, so this branch's releases sit one above #1431's. It was regenerated after the guide fix and the rebase onto that tip, because the captures bind the last code commit (e16330e9). The declaration change moves the implementation digest from #1431's93a03ceetod4356954. The later guide fix did not change it, because docs are outside the digest. Both evidence checker CLIs pass (integrity and replay). The three evidence modules pass with default markers (209 passed, 19 deselected) and with-m integration(19 passed, 209 deselected). The formal retest records no deviation and no spec artifact pin changed. The helper's--checkreports "evidence is current".nox -s verify-fast-feedback -- --base-rev origin/devpassed. Its changed-module stage ran 377 passed and 19 deselected, including #1431's modules.nox -s lintpassed.make policypassed; requirement governance is skipped there because the branch selects no UID.tools/check_requirement_governance.py --base-rev origin/dev --requirement-uid API-404also exits 0.nox -s contracts -- --base-rev origin/dev, the command of CI's "Run governed contract graph" step, passed all 14 steps, including both evidence steps.nox -s docs-localpassed: Vale reported 0 errors in 22 files, and the Sphinx-WHTML build and the public output inventory passed.Ground Control Checks
01ce1b82returned one blocking finding and two minor ones, and this revision addresses all three. The blocking finding was the guide's wording, which implied that resolution changes anINDETERMINATEoperation's state and could be read as allowing a backend effect to be applied twice. The minor ones were the Summary's stack sentence and the feat(runtime): declare control-plane profiles and capabilities #1189 preflight matrix, now covered under ADR Impact.Traceability
Checklist
fix(runtime)becauseprofile_declaration()returns the added nonclaimsDocumentation
Updated:
docs/explain/sdl/runtime-architecture.md(profile table) anddocs/public/guides/control-plane.md("Deploy the adapter").