You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Continuation of Pino de Candia's multi-database implementation in #386, integrated with current main. Pino's original contribution is acknowledged in the commit attribution. This draft does not alter or close#386 and does not claim to solve all lifecycle problems. Maintainer review and release conclusions remain outstanding.
Preserve the shared-control/local-satellite model: one runtime/provider in the configured control database, with origin-local df APIs, metadata, grants, RLS and credentials in satellites. Explicit SQL targets retain name-based semantics and do not require pg_durable.
Keep the shipped 0.2.7 → 0.2.8 migration unchanged; put installation identity/validation DDL in the unreleased 0.2.8 → 0.2.9 upgrade. Preserve legacy control IDs, recorded payloads and old-control-schema compatibility.
Restore SQL autocommit for control, default satellite, explicit same-origin and remote execution, including VACUUM and CREATE INDEX CONCURRENTLY. Exact execution-connection OID/UUID preflights end before business SQL and explicitly roll back validation failures.
Remove activity-long metadata guards and their client-side DDL lock cycles. Graph/status/retention/reconciliation operations validate identity and access metadata in short transactions on the same connection, outside engine calls and arbitrary activity waits.
Refresh trusted source identity after resource waits and before dispatch. Keep endpoint/secret lookup origin-local, preserve credential snapshot consistency, and refresh HTTP execution permission after catalog waits before sending. Preserve current-main HTTP policy, client reuse and secret handling.
Update deterministic regressions and documentation for forced/same-OID replacement, metadata-session loss and colliding replacement IDs, both DDL orders, HTTP authorization/credential waits, and upgrade compatibility. Former negative autocommit/lock-cycle diagnostics are now passing normal regressions.
Removal and admission contract
Normal DROP adds no activity-long drain. Ordinary PostgreSQL locks held by caller transactions or user statements still apply and may delay DDL. Already-admitted remote SQL may finish after source removal; committed SQL and accepted HTTP cannot be retracted. Old metadata operations remain fenced from replacement installations.
Fresh source validation rejects the tested stale queued/pre-dispatch cases, but validation is not atomic with a remote send. A source can disappear after the last successful check and before dispatch. No DDL interception hook or administrative quiesce API is introduced.
Deferred items (4 and 5)
4. Preexisting Duroxide task ownership and shutdown bug
Shared control amplifies the impact of an existing runtime lifetime issue. A deterministic live-Tokio reproduction against pinned Duroxide 0.1.30 holds an activity handler, awaits shutdown(Some(0)) or shutdown(Some(100)), and only then releases the handler. In both cases the handler emits an in-process notification after shutdown returns. This is a runtime task-ownership reproduction, not a SQL/HTTP effects reproduction.
The upstream fix needs ownership of the complete descendant task tree, cancellation and abort-plus-join on every shutdown path, including activity managers, handlers and acknowledgment work. A regression must assert no post-stop handler effect, surviving descendant or late acknowledgment after shutdown returns. Duroxide is neither fixed nor bumped here.
5. Preexisting end-to-end SQL cancellation and quiescence gap
Dropping a Rust task, future, socket or execution permit is not confirmation that the PostgreSQL backend has stopped and drained. This requires pg_durable-owned cleanup and exact-backend cancellation/termination with confirmed drain, plus a persistent admission/quiesce policy coordinated with upstream task ownership. It is not solely a Duroxide fix: joining Rust descendants alone does not prove SQL stopped, while local SQL cleanup alone does not reap orphaned runtime dispatch/ack tasks.
Already-committed SQL and remotely accepted HTTP cannot be undone. The final-check-to-send interval and already-admitted-effects overlap of issue 3 remain explicitly unclaimed and deferred. Full persistent administrative quiesce/resume, restart and queued-work semantics are outside this draft's implemented scope.
Validation
Executed in a disposable PostgreSQL 17.7 / Rust 1.93 / pgrx 0.16.1 environment, with recorded source/build/install provenance retained locally:
425 unit tests passed; 16 ignored. Includes exact-connection OID/UUID validation, error rollback, lock release, preserved timeout/isolation settings and autocommit after preflight.
149 upgrade checks passed: fresh/upgraded schema equivalence, supported control schemas 0.2.2–0.2.8 alongside current satellites, and retained/in-flight work with ABI/OID/grant preservation.
16 focused E2E files passed: 11 multi-database cases 75–85, 14_database, and HTTP feature/policy cases 47, 48, 69 and 70. These include all ten autocommit route/statement cases, both DDL orders, queued A→A/A→B replacement, same-OID UUID replacement with a surviving connection, no writes into replacement metadata, and zero disallowed HTTP sends after catalog waits.
Publication checks confirmed the working tree matches the validated handoff, apart from LF-only normalization of new test files; Python syntax and staged diff checks passed. The documented post-test clarification only explains that native PostgreSQL locks can still delay DROP.
Not claimed/run for this final phase: full repository E2E suite, PG18, production/release-package certification, shipped-package upgrade validation, representative many-origin load, repeated-epoch/task/connection-budget certification, or end-to-end live control-replacement SQL/HTTP quiescence. An earlier test-feature package build is not certification of this phase's production release.
Keep this PR in draft pending maintainer review of the admission/removal contract and disposition of the deferred lifecycle items.
Continue Pino de Candia's implementation from PR #386 on current main. Preserve SQL autocommit, fence origin-local metadata in short transactions, and refresh source identity and HTTP authorization after resource waits. Include migrations, deterministic regressions and documented deferred runtime/SQL quiescence limitations.
Co-authored-by: Pino de Candia <pinod@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep restart-sensitive and TLS-mock cases in the primary CI runner, preserve SQL failure output under errexit, and fail explicitly on startup or copy errors. Add isolated mock runner regressions and dedicated image/container overrides.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
A zero exit status with no TEST FAILED marker is now counted as a pass, so a truncated or otherwise incomplete SQL test can silently succeed. The runner previously required TEST PASSED; keep the failure-marker precedence but retain a separate positive-marker branch and fail when neither marker is present.
For satellite listings this now calls backend_engine_id once per returned row, and that helper performs SPI lookups for the current database and installation identity on each call. A page of the allowed 1,000 instances therefore adds up to 2,000 backend catalog queries before the single batched engine query, which is a substantial regression for a read API. Resolve the origin identity once per listing (or batch it) and derive all engine IDs from that value.
Integrate HTTP body policies and benchmarks from main. Preserve origin-local credentials and final authorization checks, default response sinks to the workflow origin, and fence storage admission without changing explicit remote targets. Extend origin HTTP tests to cover default, same-origin and remote sinks.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Rename the pure schema-name validator test to match its assertions and remove the repeated legacy-schema assertion. Do not imply it exercises installation replacement or schema re-resolution.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Give each route/statement case its own table while retaining parallel execution, terminal-state checks and valid-index assertions. Verified 20 PG17 runs covering 200 successful cases.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Require an explicit success marker and resolve caller origin once per monitoring batch without introducing a lifetime cache.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Retain origin-aware response-sink guidance when integrating main's HTTP security GUC and verify legacy/satellite ID derivation across a full listing-sized batch.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use fallible schema resolution for both listing overloads, instance info and metrics. Warn and return empty rows on lookup failure while keeping execution history and workflow mutations strict. Cover bounded outage fallback and same-session recovery in the multi-database regression.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Continuation of Pino de Candia's multi-database implementation in #386, integrated with current main. Pino's original contribution is acknowledged in the commit attribution. This draft does not alter or close #386 and does not claim to solve all lifecycle problems. Maintainer review and release conclusions remain outstanding.
dfAPIs, metadata, grants, RLS and credentials in satellites. Explicit SQL targets retain name-based semantics and do not require pg_durable.VACUUMandCREATE INDEX CONCURRENTLY. Exact execution-connection OID/UUID preflights end before business SQL and explicitly roll back validation failures.Removal and admission contract
Normal DROP adds no activity-long drain. Ordinary PostgreSQL locks held by caller transactions or user statements still apply and may delay DDL. Already-admitted remote SQL may finish after source removal; committed SQL and accepted HTTP cannot be retracted. Old metadata operations remain fenced from replacement installations.
Fresh source validation rejects the tested stale queued/pre-dispatch cases, but validation is not atomic with a remote send. A source can disappear after the last successful check and before dispatch. No DDL interception hook or administrative quiesce API is introduced.
Deferred items (4 and 5)
4. Preexisting Duroxide task ownership and shutdown bug
Shared control amplifies the impact of an existing runtime lifetime issue. A deterministic live-Tokio reproduction against pinned Duroxide 0.1.30 holds an activity handler, awaits
shutdown(Some(0))orshutdown(Some(100)), and only then releases the handler. In both cases the handler emits an in-process notification after shutdown returns. This is a runtime task-ownership reproduction, not a SQL/HTTP effects reproduction.The upstream fix needs ownership of the complete descendant task tree, cancellation and abort-plus-join on every shutdown path, including activity managers, handlers and acknowledgment work. A regression must assert no post-stop handler effect, surviving descendant or late acknowledgment after shutdown returns. Duroxide is neither fixed nor bumped here.
5. Preexisting end-to-end SQL cancellation and quiescence gap
Dropping a Rust task, future, socket or execution permit is not confirmation that the PostgreSQL backend has stopped and drained. This requires pg_durable-owned cleanup and exact-backend cancellation/termination with confirmed drain, plus a persistent admission/quiesce policy coordinated with upstream task ownership. It is not solely a Duroxide fix: joining Rust descendants alone does not prove SQL stopped, while local SQL cleanup alone does not reap orphaned runtime dispatch/ack tasks.
Already-committed SQL and remotely accepted HTTP cannot be undone. The final-check-to-send interval and already-admitted-effects overlap of issue 3 remain explicitly unclaimed and deferred. Full persistent administrative quiesce/resume, restart and queued-work semantics are outside this draft's implemented scope.
Validation
Executed in a disposable PostgreSQL 17.7 / Rust 1.93 / pgrx 0.16.1 environment, with recorded source/build/install provenance retained locally:
14_database, and HTTP feature/policy cases 47, 48, 69 and 70. These include all ten autocommit route/statement cases, both DDL orders, queued A→A/A→B replacement, same-OID UUID replacement with a surviving connection, no writes into replacement metadata, and zero disallowed HTTP sends after catalog waits.cargo build --features pg17,http-allow-test-domainscargo fmt -p pg_durable -- --checkcargo clippy --features pg17,http-allow-test-domains -- -D warningsNot claimed/run for this final phase: full repository E2E suite, PG18, production/release-package certification, shipped-package upgrade validation, representative many-origin load, repeated-epoch/task/connection-budget certification, or end-to-end live control-replacement SQL/HTTP quiescence. An earlier test-feature package build is not certification of this phase's production release.
Keep this PR in draft pending maintainer review of the admission/removal contract and disposition of the deferred lifecycle items.