Skip to content

Latest commit

 

History

History
288 lines (157 loc) · 64.7 KB

File metadata and controls

288 lines (157 loc) · 64.7 KB

Authorization

Database-persisted API-key verifiers, principals, grants and policy epochs determine every public operation. HTTP/MCP callers cannot supply trusted roles. Existing authorization and field/row projection remain subject to ADR-032's layout debt; the cluster control boundary is defined by ADR-036.

Requirement Acceptance and evidence
REQ-AUTH-001: public identity and grants come from the replicated database after a quorum read AC-REP-005: real SDK/MCP invalid, expired, revoked and unauthorized calls fail before effects, including after failover
REQ-AUTH-002: public credential changes cannot disable or impersonate the cluster's membership authority AC-AUTH-002: a persisted protected internal principal has no public API key; even an administrator cannot edit it or create a credential for it; revoking a public administrator does not revoke internal membership
REQ-AUTH-003: internal authority can perform only its approved membership control operation AC-AUTH-003: ordinary callers cannot submit Membership; the internal principal cannot submit data/security operations; real store outcomes preserve exact denial and unchanged effects

Current unit case-to-acceptance crosswalk

Native case class Existing requirement / acceptance Evidence boundary
ClusterPrincipalPolicyTests, ClusterPrincipalInitializationIntegrityTests, StorageRecovery.PartitionHostRecoveryTests.MissingProtectedPrincipalInVerifiedPendingImageRejectsHostAndSafeRetry, ModifiedProtectedPrincipalInVerifiedPendingImageRejectsHostAndSafeRetry, ValidProtectedPrincipalInVerifiedPendingImageOpensAtRecoveredCut REQ-AUTH-002 / AC-AUTH-002 Protected internal-principal bootstrap/idempotence, public edit/credential denial, snapshot copy, and missing/modified/corrupt row rejection at an existing apply cut. The three StorageRecovery cases exercise a real verified pending-image install: absent/modified principal state rejects both host-open attempts; valid principal state is present after install/reopen. This is local store/snapshot evidence, not quorum or RF3 proof.
ClusterPrincipalAuthorizationTests REQ-AUTH-003 / AC-AUTH-003 Ordinary/public internal-membership denial, internal data/security denial, and internal membership after public-root revocation.
DocumentRowTenantMutationAuthorizationTests REQ-AUTH-005 / AC-AUTH-005, with the owning document boundary REQ-DSTORE-003 / AC-DSTORE-003 Put/Patch/Delete cannot forge row owner or tenant. It does not cover all row-scoped read/query adapters.
DocumentFieldMutationAuthorizationTests, DocumentReplacementFieldAuthorizationTests, DocumentDeleteIndexAuthorizationTests REQ-AUTH-006 / AC-AUTH-006, with the owning document boundary REQ-DSTORE-003 / AC-DSTORE-003 Persisted field-write and index-use grants are independently enforced on the tested mutation paths; this is not the complete adapter/lineage matrix.
ResourcePolicyUpdateTests, ResourcePolicyUpdateRejectionTests, ResourcePolicyUpdateVisibilityTests See the exact REQ-RPOL-001..004 mapping in ResourcePolicyUpdates The unit cases map to RPOL-001/002/003; RPOL-004 remains the real SDK/MCP RF3 criterion. The blob-quota exclusion case is validator-only, not a store-apply flow.

SignedEnvelopeTests is physically under the Authorization test directory but is owned by InternalSerialization: map it only to REQ-IS-007 / AC-IS-007 in InternalSerialization acceptance. It is not evidence for public credential verification or persisted principal authorization.

Slice map: new policy code src/KeyLoad.Core/Features/Authorization/; focused tests mirror tests/KeyLoad.UnitTests/Features/Authorization/. HTTP/MCP adapters remain ClientApi and invoke Orleans request grains. Principals/API keys remain existing shared public contracts. Frontend: N/A, no independent UI is introduced.

flowchart LR
    Caller[HTTP or MCP caller] --> Key[Persisted API key verifier]
    Key --> Principal[Persisted public principal]
    Principal --> Grants[Authorized database effect]
    Membership[Orleans membership provider] --> Internal[Protected persisted internal principal]
    Internal --> CAS[Membership CAS only]
    Principal --> Deny[Internal identity and credentials denied]
Loading

TASK-ROUTE-AUTH owns only new policy and its real ZoneTree regressions; the lead adds the existing DatabaseEngine integration guards and host bootstrap call. No test doubles or local execution. TUnit unit gates and Docker RF3 public-key revocation/membership readiness provide the combined proof. The policy's bootstrap is process-composition authority, not an HTTP/MCP operation: seed an absent internal principal only at apply cut zero; a missing or modified protected row at an existing cut fails closed. Quorum catch-up makes the replicated catalog authoritative before any public authentication. No secrets are added to the protected principal.

Повний public authorization contract

Актори: API-key caller, persisted administrator/resource owner та protected internal membership identity. Current source: principal/key contracts, DatabaseEngine, AuthorizationPolicy, mutation checks, server binding. Persisted public credentials/grants уже існують; новий quorum/bootstrap/internal control ремонт та широка SDK/MCP parity ще потребують qualification.

Вимога Acceptance / flows Test mapping
REQ-AUTH-004: тільки persisted verifier/principal створює public server identity AC-AUTH-004: valid stored credential дає exact principal; unknown/expired/revoked/malformed key та client-supplied trusted roles fail closed без effects; restart/failover зберігають каталог Existing UnsignedPeerRequestsAndClientSuppliedPrincipalAreRejected у ClusterTests; invalid catalog tests у TransactionTests; full credential edge/RF3 parity PLANNED
REQ-AUTH-005: tenant/database/resource/row capability enforcement спільний для read/write AC-AUTH-005: wrong scope/owner/project/row grants не відкривають дані чи effects; forged resource identity не авторизує іншу collection; internal membership authority не перетворюється на public admin Existing RowScopeAndTenantCannotBeForged у SecurityAndQueryTests, AShadowedMutationResourceCannotAuthorizeWritesToAnotherCollection у TransactionTests; REQ-AUTH-001–003 збережені
REQ-AUTH-006: field read/use/write та omit-default projection застосовуються наскрізно AC-AUTH-006: nested/aliased protected fields не витікають у payload/headers/metadata; predicate/sort/index/vector use і replace/patch перевіряють окремі grants; різні query adapters мають однакові omissions Existing NestedSensitiveFieldsAreOmittedAndAliasedPredicateAndSortAreDenied, QueryAdapterTests adapter omission cases, ChangeFeedTests PII cases; full lineage matrix PLANNED
REQ-AUTH-007: current policy epoch перевіряється на request/page/cache boundary AC-AUTH-007: revoke/ACL/policy change invalidates відповідний cursor/result без cached payload leakage; invalid token/history/scope дає typed failure, після відмови healthy authorized call works Existing RevocationInvalidatesCurrentPageAndNeverReturnsCachedPayload у SecurityAndQueryTests, feed revocation/scope tests; ADR-022 RF3 boundary expansion PLANNED
REQ-AUTH-008: worker required inputs та protected effects gate перед unsafe delivery/replay AC-AUTH-008: missing protected-input grants зупиняють claim/replay/checkpoint; changed principal policy блокує стару delivery; inbox replay не обходить current effect authority Existing WorkerRequiredProtectedInputFailsBeforeClaim, SubscriptionTests MissingRequiredWorkerInputStopsDeliveryWithoutAdvancingTheCheckpoint, AnotherWorkerReusesTheInboxOnlyAfterCurrentEffectPermissionsAreChecked
REQ-AUTH-009: diagnostics та derived projections зберігають sensitive classification AC-AUTH-009: PLANNED PII/token canaries не потрапляють у errors/logs/traces/search statistics чи unauthorized derived result; omitted-default lineage зберігається при rebuild/replay/backup Existing safe projector tests — часткове source evidence; PLANNED full cross-interface diagnostics/lineage matrix KL-067/068/096/103

Рішення: ADR-014 RBAC, ADR-015 sensitive lineage, ADR-022 policy epoch, ADR-029 event/message privacy. Policies/keys persisted server-side; readers і projections користуються нинішнім principal та scope. Stored raw history може містити protected input, але це не дозволяє unsafe replay до consumer.

Canonical map: Security/Core/Abstractions/Server/tests Features/Authorization/ для policy/behavior; SDK/MCP adapters — ClientApi, business projection — owning slice. UI N/A. Shared identity/epoch/schema/host composition мають одного integration owner. Нові trust boundaries freeze через ADR → реальні adversarial tests → implementation → migration/rollout → GitHub SDK/MCP RF3 failover proof. Source/test names не доказ passing; diagnostics, coverage/complexity та current delivered-source qualification pending.

TASK-AUTH-DENIED-REPLAY-CLOCK-001

REQ-AUTH-008, original ADR002 same-ID outcome contract and TASK-BACKUP-EVENTING-CUT-001 require current authorization to be checked before outcome reuse, while an unreplicated authorization-denied retry of a retained same command must not append another clock-only native commit. A concrete current source path authorizes before outcome selection; denial retains ForNew/persistOutcome=true, skips overwriting an existing outcome, but stages equal ClockBytes. Native ZoneTree staged writes are real journal changes. Thus repeated denied native calls advance the store position despite unchanged immutable receipt.

Freeze before correction: reuse the existing one outcome-key presence read in PersistCommandOutcome. If a previously stored key exists and replicationIndex is nonpositive, the denial has no staged domain effect; preserve current error/current policy checks and immutable outcome and return before clock staging. New rejected IDs still persist failure outcome/clock exactly once. Supplied positive replicated indexes retain original applied watermark and supplied-time clock staging unchanged, including distinct log entries that share an ID. Do not return old success after revoked permissions or weaken authorization, fingerprints/incarnation, compiled validation or token/placement checks. No storage/public/serializer format changes.

Ownership: shared Core AtomicCommandCommit.PersistCommandOutcome only; new UnitTests Authorization real native denial/replay/replicated-apply metadata/healthy flow, plus BackupRestore eventing administrator-resume denial. Before execution, root reviews exact guards, build/analyzers/format and actual full normal/scalar/recovery/RF3 Linux gates. Literal expected native positions/outcomes and full stored bytes—not implementation getters—prove unchanged embedded replay, positive supplied index advancement and healthy effects. Source review is not runtime proof or consensus qualification. Rollback removes this correction and these task contracts/regressions coherently.

AC-AUTH-REPLAY-001 has two native arguments (same evaluatedAt / later trusted evaluatedAt). CommandFingerprint freezes Id/Kind/PrincipalId/PayloadJson, explicitly excluding evaluatedAt; the tests supply actual typed trusted native operation time without substituting a clock provider or waiting. The original ADR002 permission that physical commit position may advance is retained for positive replica indexes and broader historical work; this owner-authorized task tightens only unreplicated, already-retained, no-effect authorization rejection. The native regression independently asserts current exact PermissionDenied, one failure/clock commit, immutable full-store bytes under both same-ID times, then genuine Apply indexes1/2 with exact applied watermark and supplied clock, unchanged original outcome bytes, already-applied-index idempotence and a new authorized document operation. It is not RF3 consensus proof.

The native removed-grant case also first commits a real writer document, removes its persisted grant with the next exact policy epoch, then repeats the original identity and payload with later trusted time: current PermissionDenied, immutable original success receipt, unchanged complete store bytes/position, and a healthy root revision update are required.

TASK-KL015-CROSS-TENANT-RF3-001

REQ-AUTH-KL015-001 / AC-AUTH-KL015-001 supplements REQ/AC-AUTH005/009 and REQ/AC-CLIENT005/006 under existing ADR002/022/039. A persisted non-admin principal belongs to one native tenant, with persisted document read/write/query grants on its resource. Actual SDK and official MCP foreign-tenant GET, bounded full scan, indexed predicate and immutable Batch write must return exact PermissionDenied/safe scope detail and disclose no credential or payload canary. Canonical foreign/owned documents and actual indexed membership remain literal and unchanged after rejection/retry. Same-ID denied replay remains PermissionDenied; authorization precedes fingerprint selection, so different payload under that still-unauthorized ID must likewise remain denied. An authorized healthy command proves exact revision/effect, stable same-ID receipt replay and changed-content Conflict with no second effect.

ADR002 definitive failed writes remain logged: first denied command may advance persisted failure/clock/replica watermark without changing target documents/indexes. Same-ID public retry is stable in result/target effect, not a fabricated global storage position promise. Separate public reads do not guarantee equal cluster-wide cuts while metadata changes; positive cut and complete literal state are checked, and query errors expose no partial page. No pre-submit authorization, product lock, timeout or catalog change is introduced. Telemetry privacy has current R785 local native normal/scalar 12/12 export evidence, including the real signed AcOrl012RealSignedOperationsExportBoundedPrivateNativeTelemetry case; the exact scope and original reports are recorded in ADR-121. Original4e18 artifact paths are unavailable in this session, so that historical checkpoint is not authenticated passing evidence or current Linux qualification. This RF3 scenario separately checks actual public failure envelopes; those envelopes alone do not prove every server exporter. Native exact-source execution and original receipts are mandatory before any KL015 closure.

Canonical ownership: IntegrationTests Features/Authorization Cases/Helpers/Assertions. Existing shared ClusterFixture owns Docker/Aspire RF3 endpoints/lifetime; official session is joined with original primary+cleanup errors preserved. Existing standard catalogs/selectors remain unchanged; no LocalImage expansion.

flowchart LR
  P[Persisted own-tenant principal] --> D[SDK and official MCP foreign operations]
  D --> E[Exact denial and literal target/index invariance]
  E --> R[Original-ID denied replay]
  R --> H[Authorized healthy write and receipt replay]
  H --> C[Changed-content Conflict and no second effect]
Loading

TASK-AUTH-KL015-ORDERED-RECEIPT-001 refines AC-AUTH-KL015-001: compare complete serialized SDK replay, official MCP replay and literal healthy document output by ordered byte content. Byte-array reference identity cannot establish the required receipt contract. Preserve the entire existing persisted authorization, foreign denial, unchanged target/index, changed-content Conflict and healthy continuation flow. The original exact46a4 reference-equality failure stays retained; actual native RF3 execution remains required before closure. Existing ADR-002/022/039 contracts are unchanged.

KL-015 exported telemetry privacy

REQ-AUTH-KL015-002 / AC-AUTH-KL015-002: actual ASP.NET/HTTP-client spans and OpenTelemetry logs must not export caller payload, raw URL/path/query, credentials, scope state or exception messages. Preserve count/duration, status, fixed normalized operation/category, severity, numeric event identity, timestamps and trace correlation. Unapproved arbitrary attributes do not become telemetry authority. The same real Kestrel request executes actual ZoneTree-backed administration, then a denied request preserves canonical state and an authorized healthy request returns a complete literal catalog. Actual exporters capture immutable span/log snapshots; canary absence alone is insufficient: exported server/client spans and failure/healthy log records must exist and preserve exact safe fields. Existing RF3 SDK/official MCP cross-tenant and admission negatives remain mandatory.

ADR-121 freezes this boundary. ServiceDefaults owns validated Authorization privacy options, processors and registration; UnitTests Authorization owns real Kestrel/file-backed operation/exporter lifecycle tests. Root owns integration, architecture/index/status, coherent build/image and delivery. No new package, storage format, trusted role, public endpoint or schema is introduced. Existing native Orleans telemetry policy is unchanged. Startup, primary operation, flush, stop and disposal failures remain original errors and all owned resources settle. Source authoring is not passing execution, numeric coverage, Linux qualification or KL-015 closure.

AC-AUTH-KL015-002 permits only ADR-121's closed native HTTP connection context link shape. Native span IDs and complete safe link fields must match the preprivacy observation; events, tagged/state-bearing/extra links and unsafe ancestry still suppress the original span. Normal and scalar actual HTTP fullflows plus Linux RF3 remain required.

Local REQ/AC-AUTH-KL015-002 export evidence: R785 coherent Release build green, actual native normal and scalar three-class focus each 12/12 PASS with native exit 0 and source/assembly drift zero. ADR-121 records exact scope and original report lineage. Current Linux run 37821315110 attempt 1 on exact source 3458f611 has authenticated original normal/scalar TRX with all 12 telemetry cases passed in each mode, native source/image receipts retained and after-suite identity verification successful; ADR-121 records artifact/TRX hashes. Complete unit suites each retain 19 other failures. Current exact-source Linux RF3 cross-tenant, bounded-input/query and C1 held-write/guard acceptance remain open; neither export gate marks KL-015 done or establishes full-suite/production/endurance qualification.

TASK-AUTH-KL015-COMPLETE-DENIAL-RESULT-001 refines REQ/AC-AUTH-KL015-001 under unchanged ADR-002/022/039: each actual SDK foreign-tenant GET, full scan, indexed predicate, original write/replay and changed-content denied write must have no result payload, exact PermissionDenied/safe scope detail, and a complete serialized native result containing none of the persisted credential or document/conflict/healthy canaries. Checking only Problem cannot prove that a failed result carries no payload or leaked metadata. The existing official MCP complete-result privacy, literal foreign/owned document and real index invariance, healthy exact receipt replay and Conflict/no second effect remain mandatory in the same RF3 wholeflow.

Ownership is the existing Authorization CrossTenantRf3ErrorAssertions helper and Kl015ForeignWritesScansAndIndexesAreDeniedAndAuthorizedReceiptRemainsStable case; no transport, provider, wire, storage, role, admission or timeout change is introduced. Current API payloads are reference-record DocumentResult, QueryPage and CommitReceipt; the helper's nullable reference constraint also accepts the actual Result<DocumentResult?> returned by GetAsync while requiring every denial value to be null. Root joins guarded source and runs the coherent native checks; exact-source Linux RF3 original TRX, source/image receipts and API artifact digest remain required. This stronger oracle is authored evidence until executed and does not mark KL-015 done.

TASK-AUTH-KL015-MODEL-VIEW-DENIAL-001

REQ/AC-AUTH-005/006/009 and REQ/AC-SQLVIEW-002/003/005 require a failed event/queue SQL request to carry no partial page or protected payload/header metadata. Freeze before the test extension under unchanged ADR-014/015/022/072. The existing two real persisted model-authority cases check the SDK error code only at field-use denial and have no actual foreign model partition. Extend those same whole flows using a second genuinely administrator-seeded event/queue partition with its own tenant. The original non-admin persisted own-tenant credential must receive exact PermissionDenied/safe scope detail for both foreign SQL model sources through SDK and official MCP. Every failed SDK result must be IsFailed, Value null and contain no credential or any of the four literal event/queue payload/header canaries in complete native serialization; official MCP must retain its exact error envelope and omit those same canaries from the complete native result. Apply the complete privacy/no-page oracle to the original same-tenant denied sensitive predicate too.

Before and after foreign rejections, actual administrator native stream and message inspection plus SQL rows must equal the literal seeded histories and Ready/unclaimed queue state. Compare ordered logical rows and complete original native records, require positive cuts, and never infer equal cluster-wide cuts across separate calls. The original authorized redacted SDK/MCP read follows the denials, then a real persisted field grant exposes the literal selected value, followed by actual revocation. Original transport, topology, grant epoch, deadlines and cleanup stay unchanged. No product fix or new runtime hook is presumed from this coverage gap.

Ownership: existing QueryExecution Cases/SqlModelViewRf3QueueAuthorityTests.cs and SqlModelViewRf3EventAuthorityTests.cs; new feature-local Helpers/SqlModelViewRf3ForeignTenantFlow.cs and Assertions/SqlModelViewRf3DenialAssertions.cs; requirements here and Authorization/QueryExecution with ADR072. Root alone joins/compiles/formats/delivers. Stages: contract, guarded source-only test repair, coherent native build/discovery, both actual Aspire RF3 flows, exact-source original Linux TRX and source/image/artifact receipts. Native discovery, source review and historical weaker passes cannot qualify these stronger flows. Rollback removes these case extensions and private helpers together; wire, provider, public API, persisted format and UI are N/A. KL015 remains open until current repaired C1 and all required acceptance gates are proven.

KL-096 immutable delivery replay and current classification

REQ/AC-AUTH-006/007/008/009 and REQ/AC-MSG-002 require current persisted field/header policy to protect an original successful queue or subscription receive replay. The original StoredOutcome bytes, original principal-policy fence, group generation/ownership, token and lease fences remain exact. A resource-only policy CAS may change its SchemaVersion without changing principal PolicyEpoch; after successful original lease validation, cached output must therefore be checked against the current projector in the same existing synchronous IKeyValueView. Queue output uses current caller; subscription output uses current persisted data principal followed by current caller, matching genuine acquisition. No nested storage read or await is introduced.

If the common current projector removes an actually retained JSON value, replay refuses PermissionDenied with fixed safe detail and no payload. Complete semantic JSON equality allows formatting changes and hidden paths absent from the retained value; it does not rewrite or redact an original receipt into a different successful receipt. The original outcome, canonical input body, lease and counters stay unchanged. Parsing remains within the existing admitted JSON/receive bounds; no new grant, limit, serializer ID, persisted family, provider, clock, retry or deadline is introduced. Higher-epoch repair never makes an old-epoch result replayable: fresh authorized work produces its own original outcome.

Ordered ownership: specs/ADR first; Core Authorization/Validation owns cached projection validation; CommandOutcomes composes it after real lease validation; native whole Unit plus real SDK/official MCP/both Q1 cases own full body/header, denial/no-effects, persisted revoke/repair, DLQ inheritance and same-root cold continuation. Original native outcome bytes are an independent local authority oracle. Normal/scalar, process and Aspire RF3 Linux source/image/UID/runtime gates remain open until actual qualification. Existing migration/conversion/fallback prohibitions remain exact; this is current-schema authorization, not stored-format compatibility.

TASK-AUTH-KL096-CACHED-DELIVERY-001 source map: existing src/KeyLoad.Core/CommandOutcomes.cs calls new src/KeyLoad.Core/Features/Authorization/Validation/CachedDeliveryPrivacy.cs strictly after native lease validation. EventMessageSensitiveReplayTests.CurrentResourceBodyAndHeaderPolicyRefusesOriginalDeliveryThenRepairedNewWorkAndColdPreserveExactAuthority declares four genuine native operation variants: queue body, queue header, subscription caller body and subscription data-principal header. Each variant includes original complete result/native outcome bytes, resource-only reclassification, no-body/no-effect refusal, required-input refusal, persisted revoke/higher-epoch repair, old-result denial, new-result replay, same-root reopen and final ACK/empty continuation. AbsentProtectedPathPreservesCompleteUnicodeArrayReceiptAfterCurrentPolicyChangeAndColdThenDeniedProducerAndFreshHealthyWork is the complete safe-replay control: Unicode, ordered arrays and null values stay semantically unchanged while an absent protected path causes harmless JSON formatting; original complete outcome replays unchanged through cold, denied producer has no effect, and new authorized work completes.

EventMessageSensitivePublicRf3Tests.CurrentBodyHeaderPoliciesRevokeRepairOriginalRefusalFreshDeliveryDlqAndSameOwnerColdFourRoutes declares the same four current-policy authority variants with real SDK/official MCP/both Q1 routes, persisted inspector omission, required-input refusal, revoke/repair, immutable old-command refusal, new authorized full result/receipt replay and genuine three-node same-owner cold. Queue variants additionally use actual NACK/max-attempt terminal admission, full policy-inherited DLQ inspection and actual state-version/delivery-generation redrive. Each original producer/completion/redrive receipt is compared completely on all four routes; current read generation/applied cut is acquired fresh and can advance on restart. The fixture chooses existing default policy's admitted lease maximum without changing policy ceilings or the original whole-flow deadline. Native test UIDs/counts are not inferred from these source declarations.

Exact role ownership stays under Authorization Cases/Contracts/Models/Helpers/Assertions in Unit and Integration. The existing fixture and caller owners retain credential validation, real official SDK initialization, connection lifetime, RF3 readiness, original operation cancellation and joined cleanup. Specs/ADR, guarded private source, coherent root join, canonical compiler/analyzers/format, actual discovery, normal/scalar Unit, process recovery and Linux Aspire RF3 are sequential gates. This source stage does not qualify process-kill behavior, power loss, performance, complete event/message export/trace lineage or production readiness. No internal compatibility/migration path exists; rollback removes the composed source stage before delivery and preserves immutable original evidence.

KL-065 incoming-row authority continuation, 2026-10-10

REQ/AC-AUTH-005/007: the two original GraphIncomingPrivacyTests retain their initial hidden-source empty and hidden-target NotFound outcomes, then repair actual persisted row owners through revision-fenced root commands. A reduced scoped GraphRead grant and revoked principal refuse with complete native bytes and cut unchanged. A higher persisted epoch repairs exactly the original grants; independently literal full incoming rows, native command outcomes and receipts survive joined same-root cold reopen. No retained principal confers authority; local Unit normal/scalar development does not close all-interface Linux/RF3/cache/Explain gates.

TASK-KL065-INCOMING-PUBLIC-CONTINUATION-002

Test-only extension of SAME GraphIncomingRf3Tests.PersistedSourceGrantHidesCrossRowsAndTargetGraphDenialIsExplicit; original declaration/UID/Args/deadline/native50/exclusiveheavy1 preserved. REQ/AC-AUTH005/007, GRAPH-XPART003/005, GRAPH002 under ADR014/102/125/117. Existing GraphIncomingRf3Scenario explicitly verifies three distinct atomic partitions on ONE physical RF3 owner. Different physical owner remains UnsupportedCapability. No public/persisted/product/options/clock seam.

Ordered flow: preserve original target-only source exclusion and target GraphRead denial. Retain full-reader original grants. Healthy admitted official MCP/SDK owner enters all four direct SDK/official MCP/Q1SDK/Q1MCP incoming routes through existing RequestCqrsRf3Callers and SqlRf3Protocol. Independent three-row literals retain all complete edges, full references, delivered revisions, redacted attributes and page version/projection; each call owns a fresh positive current cut. Persist epoch2 source database grant removal (local row only); epoch3 target DocumentsRead removal (PermissionDenied, no page); epoch4 original scoped repair (complete three rows); epoch5 Revoked (Unauthenticated, no protected page); epoch6 exact original scoped repair (complete three rows). All changes through existing authorized ConfigurePrincipal; full returned principal values compared, not caller role. Original MCP owner is created while healthy before revoke, then original requests reauthorize persisted state.

Each state operation brackets complete current administrator document images for ALL four vertices, all three partition outbox states and complete actual administrator incoming edge rows (cut observed independently, logical rows exact). All four refusal envelopes preserve errors and omit credentials/private marker; no global physical-position equality across replicated system commits or synthesized cut. Existing root administrator acts only as setup/current-state observer, never as substitute for reader admission.

Execute one real root expectedRevision1 PutDocument on original local source with identical literal document, keep exact original command/full receipt. All four stable-ID retries must return full original receipt and identical complete model/outbox images. Capture actual pre-stop NodeStatus per original three voters. Dispose caller sessions first; same fixture Kill ALL, BeginRestart ALL, Restart ALL, original readiness joined under SAME whole-flow token. Fresh callers/status after actual same-volume restart: exact NodeId/incarnation, nondecreasing ReadGeneration/Applied, full reader page/vertices, all four original receipt replays no second revision/outbox effect, then genuine fresh root expectedRevision2 write and complete healthy literal results. No cache/grant/owner/protocol bypass, new limits, retries or timeout changes.

Failure ownership uses existing RequestCqrsRf3Callers.RunOwnedAsync and ServerFailureObserver joined ledgers, fixture owns topology/root cleanup; original failures retained before disposal. New helpers only after native NotSupported creation checks. Private Integration graph build/discovery plus relevant Unit/API controls allowed; Docker heavy1 waits actual handoff. Native discovery must bind original UID, no guessed count/identity. Linux/fullsolution/RF3/coverage/cacheExplain complete KL065 remain OPEN until genuine results.

Native refusal-envelope preflight correction

Actual existing SqlModelViewRf3AuthorizationAssertions.AssertDeniedAsync establishes that a revoked persisted credential reaches MCP HTTP authentication before tool dispatch: official Client CallAsync throws HttpRequestException with HTTP401; no structured dispatched error is fabricated. Preserve both genuine official direct/Q1 denied calls, exact Unauthorized status, and bounded original McpUnauthorizedProbe safe Problem/no operation header under the same credential/node. Capability refusals remain dispatched PermissionDenied structured envelopes. SDK generic result no-body assertions distinguish reference Value null from JsonElement Undefined/Null, preserving the actual ExecuteSqlAsync<Result> type. No fallback or accepted-success branch.

Native target collection privacy fence

GraphIncomingEdgesReader.RequireVisible→TryRequireVisible catches target collection PermissionDenied as hidden visibility and returns exact NotFound. Epoch3 target DocumentsRead reduction requires NotFound/no page, independently from preserved original target GraphRead PermissionDenied. Source GraphRead absence omits remote rows. Original principals/policies and all native public codes stay unchanged.

TASK-KL065-INCOMING-REPLAY-ARGUMENTS-002

TASK-KL065-INCOMING-REPLAY-ARGUMENTS-002 corrects only the new Incoming fixture replay composition. Authentic original R3 normal UID9e4e729a-e869-8544-dd9d-d87073e179d2 failed canonical Q1 SDK Validation at CompositionSqlColdAssertions.ReplayAsync39 after real direct SDK/MCP full receipt replay. Native McpCommandCatalog Batch binds stable ID inside CommandRequest; McpArgumentDecoder.Command calls Request(false), permitting exactly one request key. The reused generic helper supplied an extra outer commandId reserved for HeaderCommand. Replace only GraphIncomingPublicContinuation replay with exact request-only Q1 CALL while retaining original CommandId/full request/full receipt on all SDK/official MCP/Q1 routes, complete no-effects/cold/healthy/privacy models, same original case/UID/deadline/options. No product schema/decoder/auth/transport/retry/quota change and no relaxing Validation; original failed image/TRX/log/cleanup retained. Ordered dependency: immutable READY9 manifestf76213ec + READY7 manifestaaf8a906 + separate original R3 completion7f08c0a8 → this four-path predicted-ancestor successor. Root must compose docs append union; shared Composition helper is unchanged. Local normal/scalar execution is development only, Linux/RF3 task gates remain open. Rollback removes only this correction and appendix, restoring the original retained failed fixture composition, never overriding current public boundaries. ADR014/REQ-AUTH005/007/AC-GRAPH-XPART003 apply. Native preflight proven existing APIs; new/private helper is not yet live-compiled, native get_symbol_body NotFound permits private proposal. Root alone joins source/Git and required full solution checks.

TASK-KL065-ROW-CANDIDATE-SWAP-001

Architecture KL065/29.3 and REQ/AC-AUTH-005/007 + REQ/AC-QUERY-004/005 under ADR014 map to the same four AcAisql008ReversedPointAndIndexPredicatesPreservePersistedRowOwnership arguments. Preserve first point/index ownership refusals, then real acknowledged two-document owner swap with exact original bodies/revision CAS, same-engine normal/reversed current row filtering, independently literal full row/plan/current-cut, whole native no-effect images, exact original receipt/outcome replay, and joined same-root cold/current-policy healthy work. This does not claim a cache hit or add cache/public/store contracts.

Ordered implementation: existing spec/ADR appendix → original case invokes feature-owned continuation → literal query/receipt/no-effect helper → original factory/cold cleanup helper. Native preflight all existing APIs and per-new-path creation refusal precede private code. Original typed limits, clocks, deadlines, four Args/UIDs and native50 remain. Rollback removes only this case extension/helpers and appendix, preserving every original case/assertion. Root joins main and runs required complete solution/Linux gates; local development controls are not RF3 or complete KL065 closure.

Embedded durability clarification: actual ZoneTreeIdentityFile.Open creates ProcessDurable; DatabaseEngine constructor retains that identity profile and ExecuteBatch writes it into the complete original receipt. The four Unit cases independently require literal ProcessDurable, preserving true synchronous native process durability and never manufacturing RF3 acknowledgement proof. Original R4 normal4 failures from an erroneous QuorumProcessDurable fixture oracle are retained; scalar was not executed on that failed oracle. Full original request/receipt/native bytes/read cut/row/plan/replay/cold invariants remain exact. The native discovery child completed before four runtime results, but the runner was launched before waiting its pending process result; preserve that original orchestration ordering mistake separately and use sequential completed discovery before the corrected run. No durability options/product/timeouts/defaults changed.

TASK-KL065-TRAVERSAL-ROW-CONTINUATION-001

REQ/AC-AUTH-005/007 and original KL065 hidden-path acceptance, under ADR014, retain the SAME TraversalStopsAtHiddenIntermediateVerticesAndHandlesCycles case/UID/deadline/defaults. Native GraphTraversalReader.RequireStart/CanVisit runs in the original Store.Read/current principal; the old result and visible cycle use independent complete ordered vertices/EdgeRecords, not a sampled count. Preserve every original assertion.

Ordered stages: original hidden result and root cycle -> independently complete hidden result/native-byte no-effect -> real root revision-CAS b owner Bob to Alice (original JSON unchanged) -> literal complete visible cycle -> reduced graph grant epoch2 PermissionDenied -> revoked original grants epoch3 Unauthenticated -> repaired identical grants epoch4 healthy -> exact original root command receipt/outcome replay/no-effect -> genuine same-root joined Store close/cold open -> exact NodeId/incarnation, nondecreasing ReadGeneration, complete native bytes/cut -> current persisted healthy traversal and same-ID replay -> final healthy traversal and joined cleanup. Existing original embedded ProcessDurable, current policy and atomic mutation ownership remain unchanged. Store cut is observed separately from traversal's DTO; no invented cursor/cache hit/Explain/public authority.

Ownership: existing Cases/GraphTraversalTests.cs and new feature-local Helpers/GraphTraversalRowContinuation.cs, Helpers/GraphTraversalRowCold.cs, Assertions/GraphTraversalRowAssertions.cs. No product/persisted/public format/API/provider/clock/quota changes. Root alone joins/builds/delivers. All initiating, cleanup and fatal failures retained by the existing ServerFailureObserver ledger, disposal remains genuine. Rollback removes extension/helpers/docs together. Native per-new-path NotSupported is recorded before creation; private canonical TUnit50 normal/scalar proof is development only, required full solution/Linux/public RF3 gates stay open. Docs append union with separately sealed Equality/Incoming predecessors; C# disjoint and no dependency on them.

TASK-KL065-PROJECT-ROW-CONTINUATION-001

REQ/AC-AUTH-005/007 and original KL065 owner/project predicate acceptance under ADR014. Existing SecurityAndQueryTests.RowScopeAndTenantCannotBeForged is owner-only, ending in own-row id/hidden Get null/foreign Tenant PermissionDenied. Preserve SAME case/UID and ALL original assertions. Native RowAccess OwnerId/ProjectId are exact immutable fields0/1; current CanReadRow authorizes the OR of actual owner equality and ordinal membership in freshly persisted PrincipalRecord.Projects. No caller-trusted roles, cached membership authority, added team/public/persistence fields or ID-set claims.

Finite test-only phases: original owner/scoped denials -> literal full original SQL rows/EXPLAIN/current native cut and noeffects -> root CAS revision1 of existing hidden row keeps ownerBob/JSON{} while adding the actual projectAlpha -> current principal epoch2 OwnerAlice/RestrictRows/ProjectsAlpha and identical original scoped DocumentsRead+Query grants -> independent complete ordered hidden+mine row model through same QueryEngine -> epoch3 removesProjects, complete mine-only row/EXPLAIN/nativebytes noeffect -> epoch4 revoke original grants/project -> exact Unauthenticated/no protected page/noeffects -> epoch5 exact original project+grants repair -> complete healthy rows -> original root command sameID full receipt/outcome/native-byte noeffect -> genuine Store joined close and same-root native reopen -> exact NodeId/incarnation/nondecreasingReadGeneration/complete original bytes/cut -> fresh current principal SQL rows/EXPLAIN/replay/healthy. No request cursor is copied; each result compares actual call cut against current store.

Use exact existing ConfigurePrincipal/Batch/PutDocument/RowAccess/QueryEngine/ZoneTreeStore and TestDatabaseEngineFactory original embedded composition. Mutation receipt independently ProcessDurable/current original root epoch, no quota/default/deadline/timeprovider changes. Errors+cleanup/fatal ledgers preserved. Helpers/Assertions remain feature-local with method64/class200 bounds. Native newpath NotSupported before creation; existing intent-preserving previews before root join. Docs append union with owner/traversal/incoming predecessor docs only; C# independently guarded against actual main.

Bounded independent complete native key/value/outcome image is test-only authority oracle, not a provider/compatibility path. This contract is private source design, not implementation/PASS. Canonical native TUnit50 normal/scalar original case required; actual full solution/Linux/public RF3/caches/generation-scoped ID set and team-specific design remain honest separate gates. Root sole main writer/build/integration/Git; no Docker concurrent launch while IncomingR4 heavy1 owns resources.

TASK-KL065-NATIVE-TASK-QUALIFICATION-001

Related original architecture29.3/KL065, REQ/AC-AUTH005/007, REQ/AC-GRAPH002, ADR014/117. Freeze before source: append ONLY KL065 to actual thirteen current strict task objects. Preserve every existing strict case union, selectors, counts, native image/source/process/TRX/cleanup/coverage predicates and separate Benchmarks/Website. Current root is sole live writer. Project membership READY6 is an explicit operation-source predecessor, not an invented new native case.

Existing-operation source map includes the complete current SecurityAndQuery, document row/tenant mutation, equality access path, SQL join row authorization, bounded partition query/public authorization, incoming/traversal/shortest-path/search authorization, node-local raw point-cache authorization and original replica security classes; the original PeerDiscoverySecurity recovery class; and genuine GraphIncoming, GraphPath authorization, cross-tenant, relational join authorization and partition-query public RF3 classes. All original Test/Arguments declarations remain, each class uses its full exact native filter. Native semantic bodies provide source candidate method/parameter/Arguments cardinality only. Do not invent instance displays, UIDs or compiled counts from these declarations.

Ordered stages: this contract/spec/ADR before candidate descriptors and closed task selectors; complete source-bound Release build and current native prepared DLL/PDB/source/image receipts; normal/scalar native census using existing bounded discovery/process/image/source owners, with unchanged source verification and artifact upload/registry cleanup. The census stage intentionally fails acceptance after retaining originals; it never executes or creates a passing receipt. Authenticate actual GitHub source/run/attempt/job/artifact/ZIP digests separately; then use the feature-local create-only proposal binder with both original profiles, current-source/full-image equality and exact unique native cases to produce only a strict task proposal and observation/review files. Root reviewed guarded graduation replaces ONLY new KL065 census object; actual complete Unit/recovery/RF3 execution and final independent verifier follow. No script authenticates supplied files as GitHub.

Original50 ordinary slots/existing exclusiveheavy1, native discovery1800s, Unit/Recovery1800s, RF3 child3600s, settlement30s and job180min remain exact. Caller scalar is distinct from server intrinsic profile. Fixture-owned Aspire realRF3, SDK/officialMCP/Q1, fresh persisted authority, no partial/noeffects and full receipt/body/cold oracles remain original. Full-suite/functional coverage and inventory/contributors are mandatory independent gates; the binder does not generate covered outcomes or relax them.

Important completeness fence: current RowAccess contains OwnerId0/ProjectId1; PrincipalRecord Projects6 and current epoch10; native CanReadRow uses owner OR ordinal project membership in current persisted principal. There is NO current native team contract, and this lane does not manufacture one. Generation-scoped ID-set design and exact cross-tenant cache-key isolation are not established by these row/query results. PeerDiscovery recovery/support declarations are not relabeled as process-kill row-policy qualification. These original whole-task implementation/qualification gaps remain explicitly OPEN even if every mapped existing operation later passes. No team/cache/fullQL/performance/endurance/power-loss/production claim, no narrowed task acceptance assertion. This is a complete current-existing-operation lane, not proof that missing product criteria exist.

Exact affected owners: docs Features Authorization/TestInfrastructure +ADR117 append; CodeQuality task contract/producer/verifier/feature-local binder; single canonical build-and-tests workflow selection. No product/public/persisted aliases/IDs/options/defaults/topology/provider/dependency changes. Rollback removes only additive KL065 candidate/binder/selector/appends before delivery; preserve thirteen originals and all authentic failure/intake evidence. Existing strict execution implementation and final verifier remain unchanged apart from closed KL065 admission; no migration/legacy fallback. Root must retain authenticated original Linux census before graduation and keep missing/duplicate/extra/changed bindings fail-closed.

TASK-KL065-TEAM-ROW-POLICY-001

Frozen before private implementation. Architecture29.3/KL065 and REQ/AC-AUTH-005/007 require real declared team membership, distinct from existing owner/project coverage. Existing CanReadRow supports only owner/project. This tranche adds actual persisted team row policy and whole native operation controls; generation-scoped ID sets and exact cross-tenant acceleration cache implementation/qualification remain separate OPEN criteria.

Append PrincipalRecord.Teams at native Id11, initialized to the valid empty ImmutableArray; append RowAccess.TeamId at native Id2 with optional null. Existing aliases, IDs, constructor arguments and owner/project OR semantics stay exact. Both fields are ordinary public JSON through current native schema/SDK/MCP/Q1 codecs; neither is a trusted caller role. Only the existing persisted administrator ConfigurePrincipal operation publishes membership, with strict increasing PolicyEpoch. Tenant/capability checks remain before row visibility. Protected cluster and runtime-journal principals require empty teams as well as their unchanged exact original fields.

Use the existing 256 project-membership admission as a combined Projects+Teams ceiling: teams may consume remaining membership slots, never increase that ceiling. Default arrays/invalid identifiers fail Validation before catalog write. Blob current metadata validates optional TeamId exactly as owner/project, mapping malformed persisted metadata to existing Corruption. Document Put validates TeamId before row authorization/publication; Patch preserves access and cannot forge membership. No new quota, schema fallback, internal format conversion, migration, provider, policy clock or trusted-state cache.

Ordered stages: this feature/ADR appendix -> additive existing native contracts -> current policy and bounded validation/protected identity checks -> original native ConfigurePrincipal/Batch/SQL/Get operation sequence -> joined same-root cold replay/healthy literal -> current native build/discovery/normal+scalar -> delivered Linux full-suite/process/public RF3. All original cases/UIDs/Args remain untouched; new meaningful team case has no invented UID. New controls prove configured team-only row read/write, independent full literal ordered query/EXPLAIN/current cut, actual denied forged membership and other-team write, removal/revoke/higher-epoch repair, old command current-epoch refusal, original immutable outcome bytes, new current receipt and same-ID replay, actual cold NodeId/incarnation/nondecreasing generation/full native image and healthy work. Combined membership invalid-scope rejection must preserve principal state then genuine valid grant repair/work, not a property-only test.

Ownership: Abstractions AuthorizationContracts/DocumentStorageContracts; Security AuthorizationPolicy; Core ProtocolValidation, DocumentMutationCommands, BlobMetadataRules, ClusterPrincipalPolicy and RuntimeJournalIdentity; new Authorization Cases/Helpers/Assertions; append Authorization.md and ADR014. No Orleans routing/storage owner change. Native API reads and per-new-path NotSupported precede new C#. Root joins live/source/Git; isolated Unit build/testing are development only. Existing source/image/UID/coverage and RF3/recovery gates remain mandatory. Rollback removes additive team code/tests/docs together from a first-release source image; no legacy reader or conversion is supplied and no runtime compatibility rollout is claimed.

Team graph source map: same new whole team case also seeds an actual collection of owner-a/team-b/owner-c vertices and actual ab/bc graph edges via original authorized Batch. Team membership yields complete ordered a,b,c and ab,bc; removal yields onlya/noedges, revoke rejects without page, higher-epoch repair and same-root cold yield complete original graph again. Existing GraphVertexVisibility actual source owns synchronous current-principal lookup; no cache hit or reusable ID-set claim. New Assertions/TeamGraphVisibilityAssertions.cs owns independent literal vertices/edge records and full native byte/cut invariance.

TASK-KL065-TEAM-CONTRIBUTOR-022

REQ/AC-AUTH-005/007: the new TeamRowPolicyTests.PersistedTeamMembershipRemovalRevocationRepairReplayAndSameRootColdAreComplete is a whole database operation, not a field/metadata test. It qualifies configured membership, literal SQL/Get/graph visibility, persisted forgery/foreign-tenant refusal, removal/revoke/higher-epoch repair, original outcome replay and genuine same-root cold/healthy continuation. Before contributor enrollment, obtain fresh complete current-main normal/scalar native discovery and independent PE/PDB/source observation. Enroll ONLY the actual new native instance in one existing functional group; preserve every original functional/noncontributor case and all five groups. Refresh only observed current source hashes, canonical selectors and actual native source spans, then run the unchanged strict census validator. No private UID/count/PASS transfer, changed case classification, wildcard, load contributor or inferred numerical coverage. Root owns guarded enrollment and original source/image validation; actual Linux full suites, generation-cache implementation/qualification and whole KL065 acceptance remain open. This test-only enrollment adds no dependency, runtime boundary or public contract; ADR117 supplies the existing execution contract.

KL-065 generation-scoped native visibility ownership

Architecture 29.3 / KL065 and REQ/AC-AUTH-005/007 require a genuine generation-scoped document-ID visibility acceleration set. Team tranche READY15 is a required source predecessor for team semantics; original owner/project checks remain. This is disposable current-source state, with no persisted/public fields, aliases, protocol changes or replacement storage provider.

Exact existing APIs: KeyLoad.ICacheMemoryBudget.TryReserve(bytes, entries, out ICacheMemoryReservation) and CacheMemoryBudget, DatabaseEngine.WithQueryView, DocumentEpoch, ReadExecutionBudget.VisitRange, QueryCandidateReader.Candidate/Visit and GraphVertexVisibility.CanVisit/ReadVisibility. Core already grants Query and Server friend access. Native receipts retained beside this contract. PartitionHost creates CacheMemory before OpenCanonicalDatabase; existing shutdown joins maintenance/coordinator/materializer before CacheMemory and canonical stores. No IAtomicStore or IKeyValueView expansion.

Minimum actual scope: Core/Authorization owns an internal RowVisibilityCache, scope identity and disposable build/lookup leases; one DatabaseEngine owns it for one actual store, explicitly borrowing the SAME PartitionHost CacheMemory. Composition closes the cache after operations/apply join and before CacheMemory; embedded test fixture owns its same validated shared budget and cache lifecycle. No separately sized cache ceiling or per-query substitute. Default embedded owners without this collaborator preserve the existing canonical path and cannot be credited as cache tests.

Identity is an exact structured tuple: actual Store.Identity NodeId/incarnation/read generation, current Store.Position observed INSIDE original read view, full PartitionRef (including tenant), collection, resource schema version, source DocumentEpoch, current persisted principal ID/tenant/policy epoch. Existing strict principal epoch CAS is membership version, including owner/project/team changes. No signing key, credential, document JSON, retained PrincipalRecord, live IKeyValueView or caller role is cached.

Fill reuses ONLY the original authorized full collection scan already performed by QueryCandidateReader. It accumulates actual visible document IDs after existing current row policy checks; it does not issue a second scan, affect point/index paths, change their access-path labels, skip original scan/result limits or accept a partial prefix. Publish only after original native scan reports HasMore=false, original cancellation/budget remains valid, and owning scan has completed successfully. Partial/failed/cancelled scans dispose the unpublished draft and all accepted reservations, retaining initiating/cleanup failures. Schema/filter/SQL projection does not define visibility: every candidate in the actual complete collection scan contributes independently of residual predicate, paging or result limit.

A later matching full scan may exclude IDs absent from this COMPLETE set before current row policy; all positive IDs STILL deserialize current records, check Deleted and current CanReadRow before materialization. Native scan/byte/cancellation accounting stays exactly the original scan. Graph may borrow the same matching complete set after its current collection authorization/resource check: known-negative IDs avoid canonical vertex decode; positive IDs STILL perform current canonical read/current CanReadRow, and misses/unsupported/incomplete sets use existing actual canonical path. Never infer completeness from count, requested result limit or a graph traversal's visited IDs. No cache-hit performance claim from result equality.

Bounds/lifetime: modeled retained charge includes scope strings and tuple/index/node/list capacity, each actual copied document ID string, reference/ordinal index state and every cache/build/lookup lease; reserve the original shared byte+entry grant BEFORE owned allocation/copy. Fixed implementation representation-size terms are accounting constants, not new operational limits or measured CLR heap. Refusal to retain accelerator state leaves original canonical execution intact; it cannot authorize/deny a row or change operation outcomes. No unlimited dictionaries or uncharged growth. Retire stale same-scope entries on new current scope/epoch/cut; bounded admission may retire unpinned entries. Retired pinned entries retain the same original charges until actual final lease Dispose. No lease evicted from under caller; no advisory invalidation needed for correctness. On cache Dispose close admission and retire entries; retain uncertain/pinned ownership until actual closure. Restart reconstructs an empty disposable cache using fresh identity; old cursors/sets never bind the new generation.

Required complete operation controls: real team/owner/project corpus with same-ID cross-tenant documents; original SQL complete scan warms a real set, graph/page positive+negative paths retain complete independent literals and fresh final policy. Root revision-fenced row-owner/team changes, delete and real policy membership reduction/revoke ACK yield exact hidden/denied no-effect results despite old pinned set; higher epoch repair fresh healthy set/results. Actual shared budget contention refuses only accelerator retention, original native bounded healthy operation remains exact; cancelled original scan publishes no partial set, then fresh healthy scan. Same-root joined cold retains canonical full bytes/receipts and returns current literal pages/graph with empty new cache. Observation of cache reuse/reservations is test-only internal actual owner evidence alongside full operations, not a getter-only test. No fake clock, synthetic trusted state, quotas, deadline changes or performance claims.

Ordered owners: docs/ADR014 first; Core internal cache/scope/retention; actual DatabaseEngine composition; Query full-scan draft/terminal publication and final row checks; Graph matching lookup/current checks; PartitionHost/TestDatabase lifecycle; whole Unit normal/scalar and real existing SDK/MCP/Q1/cold acceptance. Root joins main/Git. Source/DLL/PDB/native UID/cleanup and mandatory full solution/Linux/RF3/coverage remain OPEN. This finite contract freezes integration before new native seams; implementation and passes are not claimed.

Current-cut graph bridge before source: retain only the actual SchemaVersion scalar with the ORIGINAL bounded collection-decision entry (no second map/resource object). After its original persisted collection capability/resource check, match actual store NodeId/incarnation/read generation/Position, full partition/collection, actual schema version and fresh principal tenant/id/epoch. Under SAME unchanged live native read gate, exact current physical position proves the full-scan entry's actually observed DocumentEpoch unchanged; snapshot replacement requires a new read generation and cannot match. No second scan or metadata-read budget is introduced. The full entry still records original actual DocumentEpoch; query acquisition compares it exactly with already observed ResolveCursor.SourceEpoch. Graph positive IDs still canonical-read/current CanReadRow; negative closure is valid only for this exact current cut. Existing graph collection-decision metadata reserve includes this scalar; no new collection index/map, new quota or authority.

TASK-KL065-GENERATION-VISIBILITY-001 whole-operation regression closure

GenerationVisibilityTests owns two real-store operations: complete SQL/graph visible images, a foreign tenant with the same row ID and independent JSON, a held original cache pin across persisted removal/revocation/repair, original-command epoch refusal and current-command exact replay, then joined cache/store closure and same-root cold reconstruction with an empty disposable cache. The second operation exhausts the SAME original shared memory admission before a complete canonical scan, releases the genuine competing reservation, exercises actual cancelled caller refusal with complete no-effects, and ends in repaired healthy SQL/graph and same-root cold continuation. Cancellation is a real already-cancelled caller control, not a claim of a mid-scan barrier. All copied IDs and collection/index metadata remain charged through actual pin release; cache observations support the whole operation and do not replace complete literal public rows/native bytes/receipts. These are Unit normal/scalar development gates; process, RF3, authentic census/coverage and Linux task graduation remain open. No persisted/public ID, quota, clock or transport contract changes.

The retained-byte model includes pointer-aligned object/string footprints, the retained PartitionRef object, cache/lease/entry/ID/reservation and sorted-set metadata, plus conservative native Lock/wait-event/safe-handle managed metadata reserved before owner creation. The .NET10 Lock fields are source-linked to the official runtime v10.0.12 Lock implementation; ulong thread identity covers the larger macOS layout and conservatively overcharges the Linux uint layout. This is modeled shared admission, not measured CLR heap/RSS or kernel-memory qualification. An uncertain reservation-release failure is latched by the original owner; a later idempotent native Dispose cannot be treated as a new successful release. Retired failed entries/leases keep their original identity and charges.

The Query closure owns either its exact completed-set lease or its unpublished draft, never both: Begin is called only when Acquire returns null. Both direct nullable Dispose calls remain visible in the lexical finally; the initiating scan error is retained before cleanup and any cleanup refusal is aggregated outside finally. No second cleanup resource can be skipped because of the exclusive original acquisition path.

Final responsibility ownership: pure RowVisibilityScope/CurrentScope stay in Models; the retained mutable entry and its actual reservation closure belong to Lifecycle/RowVisibilityEntry.cs, and the modeled native layout/byte admission calculator belongs to Admission/RowVisibilityMemoryModel.cs. Execution owns the current node cache/database composition, Admission owns draft/transfer construction, QueryExecution/Queries owns the original full-scan closure. No public namespace, alias, field ID, effect or authority changes accompany this private source-role correction.

Node composition remains in the original PartitionHost: the existing canonical DatabaseEngine construction/runtime-journal preparation is factored into StorageRecovery/Hosting/PartitionDatabaseComposition, with the same store/configuration/clock/physical-owner arguments and the original shared CacheMemory. This helper owns no store or extra service. The host receives the original engine/cache pair before its unchanged transfer/log/snapshot/bootstrap stages. Direct typed field disposal after text closure and before CacheMemory closure preserves every failure in the host's original ledger, including construction refusal; failed cache ownership is never cleared or replaced.

TASK-KL065-GENERATION-ADMISSION-EXTRACTION-003

The cache retains its original lock, closed check, scope lookup, invalidation and retirement ownership. Native lease reservation and successful constructor-to-pin transfer are owned by the existing Admission/RowVisibilityTransfers.CreateLease; the call occurs under the same cache gate. Direct nullable-reservation disposal and initiating/cleanup error preservation remain unchanged. No new owner, callback, quota, public/persisted contract or policy is introduced. Both original GenerationVisibilityTests whole operations verify cross-tenant/revoke/repair/replay, pinned retirement/admission/cancellation and same-root cold continuation in normal/scalar profiles. Canonical formatting, build and authentic runtime gates remain required.

Current native generation visibility contributor enrollment

Under ADR117 and existing REQ/AC-AUTH-005/007, enroll only the two actual GenerationVisibilityTests native whole-operation instances after complete current-main normal/scalar discovery and independent native PE/PDB/compiled-source observation. Preserve all3301 original native cases, their classifications, all424 required noncontributors, zero exclusions and all five functional groups. Source hashes and spans must match actual native observations; selectors come from the unchanged canonical selector function. Whole SQL/graph/tenant/policy/pin/admission/cancellation/replay/cold flows are supporting operation evidence. Discovery and contributor enrollment are not numerical coverage, Linux RF3 qualification or complete KL065 acceptance.