Skip to content

Parity sweep: burn down items_still_open across all AWS services (685 → 161) - #2482

Open
agbishop wants to merge 129 commits into
mainfrom
chore/parity-sweep-2026-10-07
Open

agbishop wants to merge 129 commits into
mainfrom
chore/parity-sweep-2026-10-07

Conversation

@agbishop

@agbishop agbishop commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

Every AWS service's PARITY.md already claimed overall: A. This PR makes those grades honest by working through the 685 items_still_open entries across 152 services. Each item was handled in one of three ways:

  • Fixed: implemented and checked against the pinned aws-sdk-go-v2 shapes, with a table-driven test.
  • Moved to structural_gaps: it can never work in an emulator, for example because it needs a real ML engine, real hardware or billing data.
  • Left open: the SDK and docs don't define the AWS behaviour. Each of these has a one-line reason in its PARITY.md.

685 open items are now 232, across 96 services. The remainder is tracked in a follow-up bd issue.

Highlights

Cross-service wiring (the cli_*_wiring.go files), each covered by a root-level SDK test:

  • Lambda metrics now reach CloudWatch.
  • RDS and DocumentDB managed master passwords are real Secrets Manager secrets.
  • ECS can roll back deployments on ELB health or CloudWatch alarms, and invokes Lambda lifecycle hooks.
  • SWF can schedule Lambda tasks.
  • API Gateway AWS-service integrations call DynamoDB, Step Functions, Kinesis and others directly.
  • CloudControl now creates 18 resource types through the real service backends.
  • CloudFormation fetches templates and policies from S3 and can provision DirectConnect resources.
  • The tagging API covers 7 more services.
  • FIS resolves experiment targets.
  • Object Lambda access points work for GetObject, HeadObject and ListObjects.
  • AppConfig serves configuration stored in SSM, S3 or Secrets Manager.
  • IoT domain certificate status comes from ACM, and rule SQL can decode protobuf.

Real bugs fixed along the way:

  • EventBridge Logs targets never created the log stream.
  • EventBridge CreateEventBus returned a 500 when Tags were given.
  • CodePipeline silently dropped stage conditions sent by a real client.
  • Lambda CreateFunction defaulted to Image instead of Zip.
  • Scheduler accepted the cron tokens L, W and # but never fired on them.
  • DynamoDB GSI updates wiped provisioned throughput.
  • A data race in IoT GetConnection.

Made-up data removed:

  • iotwireless GetPositionEstimate no longer returns [0,0].
  • databrew no longer reports PublishedBy="admin".
  • API Gateway TestInvokeAuthorizer no longer returns a fixed principal.
  • SSM no longer reports a static Custom:Application schema.

Engines added:

  • CloudTrail Lake JOINs, set operations and subqueries.
  • Glacier Select SQL expressions.
  • DynamoDB vector search.
  • S3 MD5/SHA512 and multipart object checksums.
  • KMS rotation of imported key material across versions.
  • STS trust-policy Numeric/IpAddress/Binary condition operators.
  • Cognito device SRP authentication.
  • EC2 regional NAT gateways.

Behaviour changes worth a look

  • elbv2 target group attribute defaults now follow the load balancer family; cross-zone is now use_load_balancer_configuration.
  • elasticache Redis NumCacheNodes > 1 is rejected, and DeleteGlobalReplicationGroup with RetainPrimaryReplicationGroup=false now also deletes the primary replication group.
  • directconnect rejects associating a connection with a LAG at a different location.
  • API Gateway GetExport rejects an unknown stage or export type.
  • WAF tag operations require the resource to exist.
  • shield AutoRenew can only change in the last 30 days of the commitment.
  • CloudFormation AWS::DirectConnect::Lag is created with no connections.

Verification

Run on the final tree:

  • go build ./..., go vet ./... and go vet -tags e2e ./test/e2e/...
  • go test -count=1 . for the root package
  • TestSnapshotVersionGuard and the full persistence package
  • gofmt on all tracked Go files
  • golangci-lint on every touched package
  • go.mod and go.sum unchanged
  • make bd-audit, which found no trailer mismatches

Not run: the terraform and integration suites, which need Docker. Snapshot inventory changes are additive only, with no version bumps.

🤖 Generated with Claude Code

Witness Patrol and others added 30 commits October 7, 2026 22:44
Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ck SyncType on DeleteResourceDataSync

LastModifiedUser/CreatedBy/LastModifiedBy now come from the request's
resolved IAM principal (awsmeta.CallerArn), omitted when unresolved.
items_still_open adjudicated: 14 moved to structural_gaps, 7 left open.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Events Entity keys, filter ListJobs by namespace

items_still_open adjudicated in both PARITY.md files.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… details, SDK-valid VariantStatus

- list pagination uses pkgs/page tokens instead of integer offsets
- CreatedBy/LastModifiedBy IamIdentity on model package groups, packages, projects
- UpdateProject applies provisioning and template-provider updates
- DescribeProject TemplateProviderDetails used the create-side key; SDK decoded empty entries
- VariantStatus used InService, which the SDK enum lacks; now Creating/Updating with StartTime
- DescribeFeatureGroup OnlineStoreTotalSizeBytes from stored records

Snapshot golden also carries the cloudwatchlogs/iot additive rows.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e, state machine TimeoutSeconds

redshift:
- Tags on parameter groups, snapshots, event subscriptions and IdC apps;
  TagKeys/TagValues filters on their describes
- DescribeTags returned the bare cluster id as ResourceName; SDK expects the ARN
- CopyClusterSnapshot kept the source ARN on the copy
- ModifyCluster NewClusterIdentifier re-keys the cluster and its references
- IdC application ServiceIntegrations; GetReservedNodeExchangeConfigurationOptions validation

stepfunctions: top-level TimeoutSeconds was ignored; executions now end
TIMED_OUT with States.Timeout, and RedriveExecution accepts them.

cloudformation: PARITY.md adjudication only.
Snapshot golden rows land with the rds commit.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…uster restore inheritance, receiver configs

docdb:
- CreateDBCluster GlobalClusterIdentifier was ignored; now joins as secondary
- ReadReplicaIdentifiers was never serialized
- CertificateDetails from the CA catalog; orderable options emit Vpc

rds:
- Failover/SwitchoverGlobalCluster move the writer; non-member targets rejected
- CreateDBInstanceReadReplica honors SourceDBClusterIdentifier
- cluster restores inherit engine/KMS/master user/retention from source
- DBClusterSnapshot records MasterUsername, Port, storage and IAM auth

cleanrooms:
- receiverConfigurations on protected query/job summaries
- request-only type key dropped from ProtectedJob responses
- ability-change types derived for existing members

Snapshot golden includes the redshift rows from da52afb.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tIds, OpenZFS volume config, domain-owner checks

fsx:
- ClientRequestToken honored on create/copy/restore/update ops;
  changed params return IncompatibleParameterError
- SubnetIds required with per-deployment-type counts
- OpenZFS volume config stored, updated and enforced on delete/restore/copy
- DRA S3 auto-import/export, file cache DRAs, self-managed AD config
- UpdateFileCache accepted an invented StorageCapacityGiB member; removed
- CopyBackup SourceRegion

codeartifact: failedVersions carry errorMessage; domain-owner validated.
bedrockruntime: PARITY.md adjudication only.
Snapshot golden fsx rows land with the next commit.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…fig, shard metrics, DryRun

s3:
- PutObject x-amz-write-offset-bytes appends on directory buckets
- GetBucketMetadataConfiguration returns a computed result, not the create body
- request-metrics tag filters and FirstByteLatency
- list ops emit RestoreStatus when requested
- PutObject Size populated for notifications; ListObjectVersions no longer hardcodes STANDARD

kinesis:
- shard-level enhanced metrics; stream OutgoingRecords/Bytes were missing
- DryRun returns DryRunOperationException without side effects
- unflushed channel buffers persist across restarts

xray: insight detection honors per-group FilterExpression.
quicksight: asset bundle import overrides echoed; KnowledgeBase PrimaryOwnerUsername.
Snapshot golden also carries the fsx rows from a29457c.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ake aggregates, conformance pack params

codepipeline: Custom-owner actions now create real jobs that block the run
until PutJobSuccess/FailureResult; continuation tokens queue follow-ups.
cloudtrail: StartQuery by QueryAlias resolves the dashboard widget;
dashboard refresh starts per-widget queries; lake SQL SUM/AVG/MIN/MAX/HAVING.
awsconfig: conformance pack input parameters substituted; ListDiscoveredResources
IncludeDeletedResources via tombstones; EvaluationTimeout range-checked.
appsync: internal apiId/tags no longer leak onto the wire.
Snapshot golden rows land with the next commit.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… Splunk failures, replicator Apache Kafka clusters

firehose:
- deliverToSplunk swallowed failures and always reported success
- PutRecord/Batch, backup and per-destination delivery metrics
- Elasticsearch/OpenSearch VpcConfiguration validated against EC2
kafka:
- channels transition CREATING/UPDATING/DELETING
- replicators keep apacheKafkaCluster and ReplicationInfo cluster ids
  (previously dropped, and an empty amazonMskCluster was always emitted)
verifiedpermissions: policy store EncryptionState; Cedar entity Tags converted.
workspaces: IdC ApplicationArn; enum validation on image/application filters.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nt settings, aggregations, remaining filters

ec2:
- Filter.N on peering, route-search, multicast, capacity blocks and more
- DescribeInstanceImageMetadata reported the caller as every image owner
- peering/capacity-block/secondary-interface wire fields
- ModifyReservedInstances mints replacements; CreateFleet ValidUntil enforced
- AssociateVpcCidrBlock applies the VPC user guide restriction matrix
- Docker compute usage metrics
dms: all 18 engine settings blocks round-trip (credentials stripped); CDC window.
elasticbeanstalk: ComposeEnvironments was a stub listing environments; now
reads env.yaml from bundles. RequestId no longer a fixed literal.
inspector2: 12/15 aggregation types, AccountIds, ClientToken replay, CIS sorting,
coverage metadata, ECS GetClustersForImage.
Snapshot golden also carries rows from 49fa96b and 3a5dba6.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nfigs, AppBlockArn checks, finding filters

athena: Identity Center, managed results and S3 access-grant workgroup configs;
UpdateWorkGroup Remove* flags were silently ignored; EngineConfiguration
validated; ImportNotebook reads NotebookS3LocationUri.
appstream: AppBlockArn must exist on Create/UpdateApplication.
accessanalyzer: resourceOwnerAccount/error/resourceControlPolicyRestriction
filters no longer match everything.
vpclattice: required txtMethodConfig members were missing; isManagedAssociation emitted.
workmail: PARITY.md adjudication only.
Snapshot golden athena row lands with the next commit.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…icky task lists, V2 filters, session expiry

swf: decision and activity timeouts enforced; sticky task lists route and
revert; pending task queues persist; empty registrationStatus rejected.
securityhub: GetResourcesV2 ignored its filters; trends/statistics apply
Filters; ListMembers OnlyAssociated defaults true per SDK; BatchUpdateFindings
limits; CreateTicketV2 ClientToken; metadata.uid resolvable.
neptune: SnapshotType public/shared always returned nothing; FailoverState echoed.
redshiftdata: sessions expire after SessionKeepAliveSeconds.
opsworks: ELB VpcId/SubnetIds/AZs derived; errors carry the JSON 1.1 content type.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… token revocation, port ranges, async states

cognitoidp: ClientMetadata reaches every trigger; ConfirmForgotPassword fires
PostConfirmation; RevokeToken invalidates derived access tokens; refresh
RetryGracePeriodSeconds; case-insensitive/alias sign-in; ForceAliasCreation.
ecs: StopServiceDeployment returned a wrapped object, SDK expects the bare ARN;
ROLLBACK stop type; containerPortRange allocation; placement retries on port
collision; resourceManagementType and daemonName filters.
directoryservice: async trust/snapshot/share/setting states; updated settings
stuck in Requested forever; replica Region resolves to the owner directory.
eks: RollbackConfig.TimeoutMinutes validated.
Snapshot golden also carries rows from earlier commits on this branch.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-catalog settings, org feature stats

glue: StartWorkflowRun RunProperties, IncludeGraph, blueprint include flags,
GetPartitions Segment/ExcludeColumnSchema, SearchTables sort, real
TaskRunProperties shape, session tags, ClientToken on glossaries and DQ runs,
UpdateSchema checkpoint, partition CatalogId.
lakeformation: ListPermissions IncludeRelated; Grant/Revoke CatalogId defaults
the resource catalog; data lake settings per catalog.
guardduty: countByFeature and free-trial days from member features.
datasync: ScheduleDetails after a user disables a schedule.
kinesisanalyticsv2: PARITY.md adjudication only.
Snapshot golden rows land with the next commit.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… qualified function URLs, PITR restore

lambda: AWS/Lambda Invocations/Errors/Duration/Throttles emitted; function URLs
scoped by Qualifier; DeleteFunction leaked URL listeners and ports;
qualifier-level event invoke config for async retries; UpdateFunctionCode DryRun;
ESM tuning validation per SDK; TenancyConfig/CapacityProviderConfig stored.
lightsail: point-in-time database restore; ApplyImmediately defers changes to
the maintenance window; RotateMasterUserPassword was ignored; omitted
PubliclyAccessible reset to false; certificate DomainValidationRecords.
medialive: DeleteReservation keeps DELETED with TTL; busy-channel guards on
DeleteCluster/DeleteNode; UsedChannelEngineVersions.
memorydb: DescribeSnapshots ShowDetail; resharding PendingUpdates; multi-region
ShardCount propagates.
mediatailor: ListAlerts requires resourceArn.
Snapshot golden rows land with the next commit; metrics emitter wiring in cli follows.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e jobs, flow validation, WS metrics

batch: array jobs spawn children with SEQUENTIAL/N_TO_N deps and cascade;
multi-node node jobs and nodeOverrides; ListJobs arrayJobId/multiNodeJobId;
eks/ecs property overrides; env/resource overrides merge by key.
NodeRangeProperty used containerProperties where the SDK uses container
(legacy key aliased in UnmarshalJSON).
bedrockagent: ValidateFlowDefinition covers cycles, reachability, connections,
conditions and loops; PrepareFlow fails on findings; ClientToken replay
survives restart and covers KB document ingest/delete.
apigatewayv2: HTTP DataProcessed, WS IntegrationError, route-level detailed
metrics; WS routing uses the stage's deployment snapshot.
account: region enable/disable and primary email update are async.
acm: ACME domain validation settles VALIDATING to VALID.
Snapshot golden rows land with the next commit.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dentials, outpost bucket ARNs, SelectColumn metadata

s3control: GetDataAccess was a stub returning empty credentials for any
target; it now matches access grants and returns 403 when none covers the
target. CreateBucket uses X-Amz-Outpost-Id in the ARN; MfaDelete and
ManifestGenerator stored and echoed.
timestreamquery: PrepareQuery Columns use the SelectColumn shape.
sts, ses, servicediscovery, rolesanywhere: PARITY.md adjudication only.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…etrics and DLQ attributes, per-database SQLite, Ethereum nodes

eventbridge: PutEvents and invocation metrics; DLQ messages carry
ERROR_MESSAGE/EXHAUSTED_RETRY_CONDITION/RETRY_ATTEMPTS and the documented
ERROR_FROM_TARGET code instead of an invented one; DLQ send checks the queue policy.
rdsdata: Database selects a distinct SQLite database; ExecuteSql reaches the
real engine; continueAfterTimeout on docker clusters; 1 MB response cap.
networkmanager: attachment updates transition through UPDATING; route
analysis follows TGW peerings (resolver wiring follows).
managedblockchain: Ethereum mainnet nodes; framework attributes were dropped on clone.
mq, mediastoredata: PARITY.md adjudication only.

Refs: gopherstack-9x62.1

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ective): replication-group topology, domain processing windows, endpoint devices

- elasticache: replication groups own real member clusters per node group;
  Create/Modify cluster, RG, global-datastore and snapshot parameter
  families implemented (placement, scaling, shard changes, failover);
  NoOperationFault/NodeGroupNotFoundFault; StorageEncryptionType and
  EffectiveDurability derived.
- elasticsearch: package association details, domain processing windows
  and per-field OptionStatus, SubnetResolver hook for VPC options.
- directconnect: AwsDevice/AwsDeviceV2/AwsLogicalDeviceId, same-endpoint
  LAG association rule, VirtualGatewayRegion, MACsec secret creator hook.
- comprehend: training status vocabulary fix, VpcConfig/RedactionConfig
  and DocumentReaderConfig validation, flywheel iterations train models.
- codedeploy: legacy String revision type.
- detective: remaining items reclassified as structural.

Snapshot golden rows land with the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s, ECS health and metrics, SWF Lambda tasks

- lambda: handler wired into wireServiceMetrics; S3ObjectVersion code
  fetch through a versioned S3 adapter.
- docdb/rds: ManageMasterUserPassword creates, rotates and deletes a real
  Secrets Manager secret.
- iam: delegation request OwnerId/ApproverId from the caller ARN.
- docdb/neptune/medialive: VpcId, SupportedNetworkTypes and channel ENIs
  resolved from EC2 subnets; NetworkTypeNotSupported on DUAL mismatch.
- ecs: CPU/Memory utilization metrics from container stats, ELB-unhealthy
  task replacement, capacity-provider ASG validation.
- swf: ScheduleLambdaFunction decisions invoke Lambda.
- cleanrooms: association schemas from Glue tables; awsconfig conformance
  pack templates from S3/SSM; appsync wafWebAclArn from wafv2; workmail
  DeleteDirectory removes the Directory Service directory.

Includes snapshot golden rows for earlier batches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ices, cost drivers, job summary aggregation, CSR passthrough

- codebuild: build-matrix batch expansion; RetryBuildBatch state rules,
  RETRY_FAILED_BUILDS carry-forward and PriorBuildSummaryList.
- ce: GetCostComparisonDrivers from the cost ledger; DimensionalValueCount
  for TAG and COST_CATEGORY monitors.
- backup: AggregationPeriod bucketing on job summaries; scan result status.
- acmpca: CSRPassthrough templates, issuer path-length enforcement,
  EXPIRED CA status.
- wafv2: Scope/Vendor/Name validation on managed catalog ops.
- transcribe: MedicalScribeContext.
- ssoadmin: primary Region listed and protected from RemoveRegion.

Snapshot golden rows land with the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sis, MQ RAM shares, Logs target authz

- eventbridge: root authz tests attach the events.amazonaws.com
  sqs:SendMessage policy that AWS requires on a DLQ; CloudWatch Logs
  targets authorize logs:PutLogEvents against the log-group resource
  policy and now create the log stream before delivering.
- directconnect: MACsec CAK/CKN keys stored as real Secrets Manager secrets.
- elasticsearch: VPCOptions VPCId and AvailabilityZones from EC2 subnets.
- networkmanager: route analysis walks transit gateway peering attachments
  in both directions.
- mq: DescribeSharedResources reports RAM shares and their resources.
- mediastoredata: ContainerNotFoundException for unknown containers.
- comprehend: training-status test moved to an internal test file.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…,resourcegroupstaggingapi,sqs): live resource queries, delegation endpoints, invoke target validation

- resourcegroups: TAG_FILTERS_1_0 and CLOUDFORMATION_STACK_1_0 queries
  evaluate live with stack QueryErrors.
- resourcegroupstaggingapi: ListRequiredTags reads the Organizations
  effective TAG_POLICY.
- route53resolver: HostVPCId from EC2 subnets; INBOUND_DELEGATION
  endpoints and DELEGATE rules.
- sesv2: EndpointId and identity ARN validation on SendEmail.
- sagemakerruntime: InferenceComponentName and TargetContainerHostname
  validation.
- rekognition: video job NotificationChannel publishes completion to SNS.
- sqs: remaining items reclassified.

Includes snapshot golden rows for earlier batches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sion promote, run options, XKS keys, owning service

- ram: PromoteResourceShareCreatedFromPolicy requires a matching promoted
  permission (UnmatchedPolicyPermissionException); ClientToken replay on
  13 more ops. The Glue RAM wiring test now promotes the permission first,
  as the SDK documents.
- omics: StartRun configurationName/runId, batch filters and failed
  submissions, outputBucketOwnerId, upload ClientToken, workflow owner
  checks, read set creationType.
- kms: XksKeyId on CreateKey; ALL_KEY_MATERIAL rotations for EXTERNAL keys.
- secretsmanager: OwningService from managed names; owning-service and
  primary-region filters.
- iotdataplane: GetConnection after DeleteConnection reports the
  disconnect.
- mwaa: CreateWebLoginToken IamIdentity from the caller.
- outposts, organizations, mgn: items reclassified.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s, target group attribute defaults, foreign registry checks

- dynamodb: vector indexes on CreateTable/UpdateTable/DescribeTable and
  restore overrides; SearchVectors scores COSINE/EUCLIDEAN/DOT_PRODUCT
  with filters and topK; GSI capacity and transaction metrics.
- elbv2: CreateTargetGroup seeds the documented attribute defaults per
  load balancer family and target type.
- ecr: foreign registryId rejected on repository-scoped ops.
- efs: DescribeTags Marker/MaxItems paging; IpAddressInUse.
- forecast: predictor and forecast lineage fields and DatasetGroupArn
  filters.
- iotanalytics, fis, cloudcontrol: items reclassified.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…...): template versions, Select SQL expressions, vault policy enforcement, JWT OpenID tokens

- pinpoint: template versions keep content; ?version= on Get/Update/Delete;
  UpdateTemplateActiveVersion pins a version; version numbers no longer
  reused after the trim.
- glacier: Select SQL parentheses/NOT/BETWEEN/IN/LIKE/arithmetic/CAST/
  COALESCE/NULLIF; vault lock and access policy Deny enforced on data ops
  with principal and condition matching.
- databrew: CreatedBy/LastModifiedBy/PublishedBy/StartedBy from the caller
  instead of a literal; required-member validation.
- cognitoidentity: OpenID tokens are JWTs with expiry and principal tags.
- iotwireless: single import tasks keyed by Id with stored fields;
  WirelessDeviceType validation; ClientRequestToken replay persisted.
- grafana: license removal chaos path; SSO grants across identity stores.
- elb: CreateLoadBalancer checks security groups and subnets in EC2.
- codeconnections: sync blocker contexts. codecommit: file/folder merge
  conflict resolution. cloudwatch: ApplyOnTransformedLogs on insight rules.
- mediaconvert, identitystore: items reclassified.

Snapshot golden rows land with the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ponse cache, real TestInvokeAuthorizer, translation jobs over S3, AZ ids

- apigateway: embed=methods/apisummary; stage response cache with
  CacheHitCount/CacheMissCount and FlushStageCache; GetExport Accept and
  extensions; GetSdk required parameters; CloneFrom; TestInvokeAuthorizer
  runs the real authorizer instead of returning a fixed principal;
  TestInvokeMethod stage variables, path parameters, client certificates.
- translate: terminology CSV/TSV/TMX parsing with skipped counts;
  parallel data statistics from S3; translation jobs translate S3 input
  documents; EncryptionKey validation.
- autoscaling: LaunchInstances placement, AvailabilityZoneIds,
  IncludeDeletedGroups, InstanceId-derived launch settings.
- applicationautoscaling: ResourceId shape validation per dimension.
- bedrock: automated reasoning test case bodies, client token replay,
  KMS key checks, OfferType validation.
- sns: AuthenticateOnUnsubscribe; SMS and application outcome metrics.
- shield: LockedSubscriptionException outside the renewal window.
- waf: tag ops require an existing resource.
- appconfig, textract: items reclassified.

Snapshot golden rows land with the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…# cron tokens fire, function LIVE stage, deep spec validation

- scheduler: L, LW, L-n, nW, nL and n#m cron tokens now match instead of
  being accepted and never firing; day-of-week L-n rejected.
- cloudfront: Stage on Get/Describe(Connection)Function with a LIVE
  snapshot taken at publish; distribution tenant ManagedCertificateRequest
  stored and reflected in GetManagedCertificateDetails.
- appmesh: virtual node, route, gateway and gateway route specs validated
  (required members, unions, enums, ranges).
- s3tables: CreateTable Iceberg Metadata validated and stored.
- apprunner: CreateVpcIngressConnection requires an existing service.
- amplify, transfer, support, appconfigdata, timestreamwrite: items
  reclassified.

Includes snapshot golden rows for earlier batches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mination, probe VpcId from EC2, import source resolution test

- emr: AutoTerminationPolicy.IdleTimeout terminates idle WAITING clusters.
- networkmonitor: Probe.VpcId resolved from the source subnet via EC2.
- resiliencehub: ImportResourcesToDraftAppVersion source resolution tested.
- polly: ValidationException wire code covered on remaining ops.
- apigatewaymanagementapi: dead constant removed.
- pipes, opensearch, dax, emrserverless, codestarconnections, mediastore,
  kinesisanalytics: items reclassified.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Witness Patrol and others added 2 commits October 10, 2026 14:11
…o S3

Completed async jobs used to leave nothing at their output location, so a
start -> wait -> download flow found no object. Each service now writes
its output through the S3 backend (resolved from the app config like
translate) when the job completes:
- polly: synthesized audio or speech-mark JSON at
  OutputS3BucketName/OutputS3KeyPrefix<TaskId>.<ext>.
- transcribe: transcript JSON for transcription, medical and call
  analytics jobs at the job's output location; TranscriptFileUri appends
  <JobName>.json for an OutputKey ending in "/".
- textract: <S3Prefix>/<JobId>/ output objects when OutputConfig is set.
- comprehend: output.tar.gz under <S3Uri>/<acct>-<CODE>-<jobid>/output/.
A failed write fails the job. Without an S3 backend behaviour is
unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… realism pass; AI-service lifecycle knobs

- iotdataplane: shadow version-conflict bodies carried a numeric "code"
  that the SDK decodes as a string, so every conflict failed to
  deserialize client-side; documented shadow error texts; bodies without
  a message fixed; topic slash limit.
- iotwireless: CreateDestination rejects duplicates (it overwrote) and
  validates fields; multicast session ops on unknown groups are not found
  (they succeeded or 500'd); paging validation; opt-in FUOTA progression.
- iotanalytics: opt-in CREATING->ACTIVE and dataset content
  CREATING->SUCCEEDED; bad nextToken/maxResults rejected.
- mediastore: policy/CORS/lifecycle ops are ContainerInUseException while
  a container is not ACTIVE; modeled InternalServerError code.
- mediastoredata: empty path segments rejected (they created nameless
  folders); clean messages.
- Lifecycle knobs for comprehend, rekognition, textract, translate,
  polly, transcribe, iotanalytics and iotwireless.

Includes snapshot golden rows for earlier batches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
return w.body.Write(b)
}

return w.ResponseWriter.Write(b)
Witness Patrol and others added 19 commits October 10, 2026 15:16
…): realism pass on monitoring and scaling services

- cloudwatch: PutMetricAlarm on an existing alarm no longer resets it to
  INSUFFICIENT_DATA (the SDK says state is unchanged); AWS-style state
  reasons, StateReasonData and history; SetAlarmState on an unknown alarm
  is ResourceNotFound 404; paging, enum, period, time-range, datapoint,
  unit and dimension validation; composite TRUE/FALSE rules.
- applicationautoscaling: scheduled actions now fire (at/rate/cron with
  timezones and start/end), updating capacity, honouring suspension and
  recording activities; schedule and capacity validation; AWS
  not-found wording.
- autoscaling: raising MinSize / lowering MaxSize adjusts desired capacity
  as documented instead of erroring; MaxSize=0 is a real bound; capacity
  changes record scaling activities; unknown launch configuration on
  CreateAutoScalingGroup fails; per-response request ids; ResourceInUse on
  delete; opt-in Pending launch delay.
- eks: version updates go UPDATING with the update InProgress and apply
  the version on completion (it flipped instantly); restore re-arms
  in-flight transitions; nodegroup scaling defaults survive partial
  configs; name/version/role/scaling/upgrade-step validation; UUID update
  ids; opt-in DELETING dwell.
- dynamodbstreams: malformed JSON is SerializationException; Limit bounds.
- Error messages no longer repeat the error code across these services.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…g, eks and more lifecycle knobs

- redshift: NumberOfNodes and ClusterType were dropped so every cluster
  had one node; node count/type/catalog rules; pause/resume/resize state
  checks with InvalidClusterState; deleting status and double-delete guard.
- redshiftdata: statements progress SUBMITTED->STARTED->FINISHED over an
  opt-in delay; cancel aborts sub-statements; sessions report BUSY;
  WaitTimeSeconds enforced (it was dropped); results on unfinished
  statements rejected.
- swf: faults are HTTP 400; unknown domains/executions are
  UnknownResourceFault instead of empty bodies; name validation; paging
  validation; ScheduleActivityTask uses the type's default task list and
  fails for unregistered or deprecated types.
- pinpoint: export/import jobs progress to COMPLETED (they stayed
  CREATED); definitions echo their segment/import members; format, S3,
  schedule and journey state validation; 400s instead of 500s.
- dax: IAM role ARN and maintenance window validation; windows crossing
  midnight roll the end day.
- Lifecycle knobs: autoscaling, eks, redshiftdata, dax, pinpoint.

Includes snapshot golden rows for earlier batches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…isabled streams stay readable; realism pass

- dynamodb/dynamodbstreams: disabling a stream used to drop it
  immediately; it now stays listed and describable as DISABLING then
  DISABLED with closed shards, readable via GetShardIterator/GetRecords,
  for 24 hours; re-enabling creates a new stream ARN and label;
  iterators carry their stream ARN; disable resets the table's stream
  records and sequence.
- lightsail: StopInstance/StartInstance pass through stopping/pending
  (they were instant) with state guards; multi-name creates no longer
  leak earlier names when a later one is a duplicate; AZ and name rules;
  CreateBucket returns the bucket.
- elb: identical CreateLoadBalancer is idempotent; duplicate listener
  ports, foreign AZs and bad tags rejected without leaving a partial
  load balancer; PageSize/Marker validation; PolicyNotFound; AWS wording.
- kinesisvideo: media type, device, storage tier, KMS, tag, channel,
  TTL, retention and APIName validation; paging validation.
- ecrpublic: ECR wording, policy JSON, catalog data, tag and batch limits.
- Error messages no longer repeat the error code across these services.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…): realism pass; lifecycle knobs

- verifiedpermissions: STRICT validation mode is enforced on
  CreatePolicy/UpdatePolicy (no schema rejects static policies; principal,
  resource and action types must be declared); paging validation.
- vpclattice: documented name rules and id-prefix exclusions; port and
  rule priority ranges with unique priorities; forward actions to unknown
  target groups are ResourceNotFound; opt-in CREATE/DELETE_IN_PROGRESS and
  target INITIAL->HEALTHY / DRAINING; not-found names the resource.
- kafkaconnect: MCU, worker, autoscaling, role and name validation on
  create and update; base64 worker config; paging validation.
- elasticsearch: instance type/count, dedicated master and EBS validation;
  upgrades require a known newer version.
- grafana: workspace name and enum validation; paging validation.
- Lifecycle knobs: --lifecycle-vpclattice, -kafkaconnect, -grafana.

Includes snapshot golden rows for earlier batches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…essanalyzer, appstream, dlm, fis

- Janitors started their worker group inside `go janitor.Run(ctx)`, so the
  ticker goroutine could appear after a goleak baseline and be reported as
  a leak (TestSiblingJanitorStopsWithSibling/restore flaked in CI). Start
  now builds the group and starts tickers before returning; callers wait
  in a goroutine. Applied to apigatewaymanagementapi, lambda, cloudwatch,
  appsync, bedrock and bedrockruntime.
- acmpca: key and signing algorithm enum and family checks (mismatches
  like RSA keys with ECDSA signing were accepted); NextToken validation;
  opt-in audit report CREATING dwell.
- appstream: ComputeCapacityStatus reflects RUNNING fleets and in-use
  sessions (it was hard-coded); opt-in STARTING/STOPPING and image
  builder PENDING; fleet range validation.
- dlm: policy state, resource type, schedule, interval, cron and retain
  rule validation (bogus states were stored); 17-hex policy ids.
- accessanalyzer: analyzer name/type/configuration validation; unknown
  list tokens rejected; opt-in CREATING dwell.
- fis: list paging validation; natural not-found messages; configurable
  lifecycle pause.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…productivity and ML-ops services

- workmail: organization ids were m- plus 20 hex, below the 34-char
  minimum the AWS CLI enforces, so every CLI call on a created org
  failed; now m- plus 32 hex. Missing orgs return
  OrganizationNotFoundException (about 40 sites returned
  EntityNotFoundException); alias/name rules; opaque tokens; export job
  requirements; opt-in REQUESTED/CREATING lifecycle and export progress.
- personalize: list pagination dropped one item at every page boundary;
  tokens now resume after the last returned item. Name, schema, filter
  expression and role validation; data deletion jobs end COMPLETED;
  minProvisionedTPS defaults to 1; opt-in CREATE PENDING/IN_PROGRESS.
- opsworks: ResourceNotFound is 400 (was 404); CustomCookbooksSource and
  UseCustomCookbooks were dropped and now round-trip with secrets masked;
  stack/layer/hostname validation; opt-in instance boot progression.
- outposts: name/description/notes bounds; rack property enums;
  configurable transition delay.
- support: natural not-found messages; cc address validation; opt-in
  opened -> work-in-progress.

Includes snapshot golden rows for earlier batches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ealism pass

- elb: DescribeInstanceHealth reported every registered instance as
  InService; it now reads the EC2 instance state (running InService,
  pending/stopped/terminated OutOfService with the documented reason,
  missing Unknown) through a new EC2Resolver.InstanceStateName.
- macie2: ONE_TIME classification jobs stayed RUNNING forever and now
  complete after a window; clientToken replay (it was ignored); job,
  allow list and filter validation (bad regexes and BOGUS actions were
  accepted); bad list tokens rejected; member ARNs include member/<id>;
  sentinel messages carry documented wording.
- dsql: 26-char identifier validation; paging, tag and policy validation;
  not-found carries the resource; configurable lifecycle windows.
- detective: graph ARN validation; MaxResults ceilings; new graphs start
  with DETECTIVE_CORE ingest; opt-in investigation RUNNING window.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s, dsql, macie2, detective, workmail, personalize, opsworks, outposts, support

Each --lifecycle-<service> flag (with its env var) falls back to the
global --lifecycle-delay and defaults to 0; services with non-zero
built-in windows (fis, dsql, macie2, outposts) are only overridden when
set. The wiring harness covers the knobs whose default settles
instantly.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…: realism pass on data planes; resolve cross-service lookups lazily

- sagemakerruntime: the endpoint existence/InService check never ran in a
  real server because Provider.Init read GetSageMakerHandler() before the
  CLI stores handlers, so unknown endpoints returned 200; lookups now
  resolve per call. Unknown TargetVariant rejected; header constraints
  (CustomAttributes, InferenceId, InputLocation, TTL, timeout, session).
- bedrockruntime: Converse role order/alternation, content, inference
  config and toolConfig validation; guardrail references resolved against
  the bedrock registry (lazily, same Init-ordering fix); model id format;
  ListAsyncInvokes paging validation.
- s3tables: list limits, bucket type, policy JSON, encryption and
  maintenance status validation; clean messages.
- cloudfrontkeyvaluestore: required Key/Value enforced (empty values were
  stored); malformed NextToken rejected; backend codes no longer leak
  into messages.
- appconfigdata: probed session token rotation and polling; no deviations.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rn-conformant guardrail ids

- cloudwatchlogs: Provider.Init captured GetS3Handler() before the CLI
  stores sibling handlers, so in a real server the export sink was never
  set and CreateExportTask stayed PENDING without writing to S3. The sink
  now resolves the S3 backend per PutObject.
- bedrock: guardrail ids were bedrock-guardrail-0000001; they are now
  10-char [a-z0-9] ids (deterministic per counter) as real guardrails use.
- TestSiblingLookupsAreLiveInRealServer drives sagemakerruntime,
  bedrockruntime and cloudwatchlogs cross-service lookups through the full
  server stack.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nobs

- omics: import/export/activation jobs completed instantly and now go
  SUBMITTED->IN_PROGRESS->COMPLETED; runs and stores progress on an
  opt-in timer so Get and List agree; opaque tokens and bounds; workflow
  and run enum validation.
- resiliencehub: appVersion "release" resolves to the latest published
  version (it was always not found); list token, bound and filter
  validation.
- databrew: stopping a run no longer gets overwritten to SUCCEEDED by
  the completion timer; runs pass through RUNNING; format, sample and
  recipe version validation; opaque tokens; messages name the resource.
- mwaa: SourceBucketArn/ExecutionRoleArn validated (notanarn was
  accepted); tag rules; opaque tokens; opt-in CREATING/UPDATING/DELETING.
- mgn: replication and launch configuration enum validation; bad tokens.
- Lifecycle knobs: mwaa, omics, resiliencehub, databrew, mgn.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n): realism pass

- cleanrooms: StartProtectedQuery dropped sqlParameters
  analysisTemplateArn/parameters; they are stored and echoed. SQL, result
  configuration and target status validation; opt-in SUBMITTED->STARTED->
  SUCCESS progression for protected queries and jobs.
- forecast: resource names accepted hyphens and leading digits (real rule
  ^[a-zA-Z][a-zA-Z0-9_]*$, max 63); S3 path, format, schema, frequency,
  backtest window and MaxResults validation; opt-in CREATE_PENDING->
  CREATE_IN_PROGRESS->ACTIVE with ResourceInUse on early delete.
- managedblockchain: ids were UUIDs and now use the real prefix plus 26
  base32 chars; admin password complexity, voting policy and name
  validation; opt-in CREATING with ResourceNotReadyException.
- networkmonitor: probe destinations must be IP addresses; opt-in PENDING.
- rolesanywhere: name, duration, role ARN, policy ARN, CRL size and
  notification validation from the botocore model.
- All five: error messages no longer repeat the exception code.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Several REST matchers claimed paths that other services share, so
correctly signed requests reached the wrong backend:
- databrew /schedules* went to Scheduler (CreateSchedule/ListSchedules
  returned ResourceNotFound from the CLI)
- detective, macie2 and securityhub /invitation* went to GuardDuty
- macie2 /usage/statistics went to Inspector2
- securityhub /administrator* and /master* went to Macie2
- networkmanager /resource-policy went to Bedrock and
  /organizations/service-access to SecurityHub
- resourcegroups /resources/{arn}/tags could reach Backup
- signin /v1/token went to Batch

Each matcher now declines when httputils.SignedForOtherService reports
a SigV4 scope (header or presigned) for a different service; unsigned
requests behave as before and no MatchPriority changed.
routing_signing_scope_test.go drives each pair through the production
registry with the real SDK; the routing corpus golden is regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…,apigatewaymanagementapi): realism pass

- resourcegroups: ListGroups maxResults/nextToken travel in the query
  string and were dropped, so paginators never paged; opaque tokens and
  bounds; resource query shape validation; opt-in UPDATING configuration.
- serverlessrepo: versions sorted as strings (1.10.0 before 1.2.0) and
  accepted non-semver; templates and change sets for unknown versions are
  rejected; stack/change set names and policy principals validated;
  opt-in PREPARING templates.
- codeconnections: 40-char connection names were accepted (limit 32);
  CreateConnection with only HostArn failed instead of inheriting the
  host's provider; tag limits; opt-in PENDING connections and hosts.
- codestarconnections: list paging validation; opt-in handshake delay.
- apigatewaymanagementapi: modeled error wording; no extra members.
- All: error messages no longer repeat the exception code.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- cognitoidp: PasswordPolicy.PasswordHistorySize is stored and enforced
  on ChangePassword, ConfirmForgotPassword and NEW_PASSWORD_REQUIRED
  (PasswordHistoryPolicyViolationException).
- ec2: CreateVolume without Size or SnapshotId is MissingParameter;
  RunInstances mints one reservation id per call, DescribeInstances
  groups by it and supports the reservation-id filter.
- sagemaker: DeleteEndpoint passes through Deleting so the
  endpoint-deleted waiter works.
- rdsdata: Postgres column origin metadata moved to structural gaps.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…kchain, cleanrooms, resourcegroups, serverlessrepo, codeconnections, codestarconnections

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- s3: the per-bucket key index was a flat sorted []string, so every new
  or deleted key shifted the whole slice (O(n) per write). It is now
  chunks of at most 512 keys with the same ordering and seek semantics.
  PutObject on a 100k-key bucket drops from ~55us to ~7us, DeleteObject
  from ~40us to ~7us, CopyObject from ~133us to ~24us.
- dynamodb: BETWEEN unwraps and parses its operands once and comparisons
  stop unwrapping twice; a filtered Scan of 2000 items is ~17% faster.
- Fix the complex Scan benchmark, which used the reserved word Source.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…; hand-written list XML

- cosmosdb: queries evaluate stored documents with lazily added system
  properties, a parse cache, cached sorted docs and precomputed ORDER BY
  keys. A WHERE query over 10k docs drops from ~82ms/641k allocs to
  ~2ms/786 allocs; ListDocuments breaks equal ids by partition key.
- azuretable (pkgs/odatatable): cached sorted entities and filter before
  clone; a $filter query over 10k entities drops from ~10.8ms to ~1.2ms.
- azurequeue, azureservicebus: id index plus an in-flight scan hint, so
  get/peek/delete no longer scan thousands of locked messages
  (~117us to ~1.5us). Put/Send pay ~25% more for the index map.
- azureblob, azurequeue: hand-written list XML (byte-identical to
  xml.Marshal, tested) via the new pkgs/xmlappend; GetBlob avoids a copy.
  Listing 10k blobs drops from ~31ms/10k allocs to ~7ms/50 allocs.
- azurearm: per-type resource index and cheaper ARM ids.
- azurestoragevhost: host parse without SplitN.
Snapshot inventory rows updated for unexported, non-persisted index
fields; no format change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Comment thread pkgs/odatatable/store.go Outdated
Witness Patrol and others added 7 commits October 11, 2026 00:56
- EventBridge rules deliver to SSM Run Command (document ARN plus
  RunCommandParameters targets), SSM Automation (automation-definition
  ARN; payload as parameters, documented as an assumption) and AppSync
  (AppSyncParameters.GraphQLOperation executed with the event as
  variables, authorised as an IAM service invocation). Failed deliveries
  take the existing retry/DLQ path.
- Pipes deliver to Timestream: single- and multi-measure mappings,
  dimension/time/version paths into JSON-string and base64 Kinesis
  bodies, epoch units and TIMESTAMP_FORMAT; any bad mapping fails the
  invocation without a partial write.
- Inspector is not a rule or pipe target in the current APIs; recorded
  as structural.
- Adapters resolve sibling backends per call; full-stack tests drive
  each target and its failure path through the SDK.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mented ranges

- CreateDBCluster returned an instantly available cluster; it now reports
  creating and the lifecycle reconciler flips it to available, as the
  Docker-engine path already did (the SDK cluster-available waiter now
  has something to wait for).
- Describe* validate MaxRecords against each op's documented range
  (20..100 by default, 20..1000 orderable options, 1..200 serverless v2);
  in-repo tests that paged with 1 or 2 now page realistically.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…cloudformation): realism pass; wait for SageMaker endpoint deletion

- cloudformation: stack delete waits (bounded) for the SageMaker endpoint
  to disappear now that DeleteEndpoint passes through Deleting, as real
  CloudFormation reports DELETE_COMPLETE only once the resource is gone.
- cloudcontrol: clean not-found wording; bad NextToken rejected; opt-in
  IN_PROGRESS progress events with RetryAfter and CancelResourceRequest.
- directconnect: bandwidth, gateway ASN and VLAN validation; unknown
  connection/LAG ids error instead of an empty list; LAG child
  connections progressed past requested (they never did).
- kinesisanalytics: ResourceNotFoundException is 400 (was 404);
  ExclusiveStartApplicationName for an unknown name returned the full
  list and now continues after it.
- mediapackage: harvest jobs stayed IN_PROGRESS forever and now succeed;
  ManifestName defaults to index; lowercase message key.
- rdsdata: TransactionNotFoundException is 404; no code prefix.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… and mediapackage lifecycle knobs

Cloud Control (in-process SDK client) and CloudFormation AWS::SQS::Queue
created queues from requests with no Host, so the returned QueueUrl was
http:///000000000000/q1 and unusable. The SQS backend now falls back to
the server endpoint when a request supplies none; real requests still
use their Host. Full-stack tests check the Cloud Control identifier and
the CloudFormation Ref match GetQueueUrl and accept SendMessage.

Adds --lifecycle-cloudcontrol and --lifecycle-mediapackage.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- s3: object lock headers and bucket default retention were ignored on
  PutObject/CopyObject/multipart, so locked buckets never locked; they
  apply now, with validation. Lock-enabled buckets turn on versioning and
  refuse suspension. Ranged GETs no longer return full-object checksums
  (the CLI/SDK validation failed). If-Match on a missing key is 404;
  CompleteMultipartUpload honours conditional headers. CORS header
  wildcards and Vary. A Date expiration now expires every matching
  object once the date passes (it only expired objects modified before
  the date). Lifecycle rules need an action.
- dynamodb: PartiQL accepts the real dialect (bare names, IN lists,
  numeric/boolean/null literals, set/list/map literals, set_add,
  RETURNING, extra WHERE conditions as conditions, reserved names);
  BatchExecuteStatement uses the real error code enum.
- sns: MessageBody filter policies with nested objects are accepted and
  matched.
- kinesis: shard SequenceNumberRange derives from shard open/close time
  instead of "0" or the ring buffer position.
- CI: the compression byte-identity test ignores the per-process memory
  stats header; the S3 lifecycle integration test uses a valid Date rule
  (Days=0 is rejected by AWS).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… pass; integration fixes

- ecs: UpdateService never replaced old tasks, so services-stable never
  succeeded; rolling deployments now honour MaximumPercent and
  MinimumHealthyPercent, and DescribeServices returns service events.
- cloudformation: UpdateStack ignored property changes to existing
  resources; changes now apply in place (Lambda, SQS, Step Functions) or
  by replacement honouring UpdateReplacePolicy, with AWS's events and
  the custom-name replacement error. SQS create applies its attributes.
- apigateway: mapping templates run a Velocity subset (#set, #foreach,
  #if, $input.params) instead of regex substitution; MOCK integrations,
  PassthroughBehavior, 502 on Lambda proxy failure, multiValueHeaders.
- stepfunctions: redrive resumes at the failed state and keeps history
  (it restarted and re-ran succeeded states); Parallel/Map/retry history
  events with details.
- lambda: SQS event sources with BatchSize over 10 never polled (SQS caps
  a receive at 10); alias routing, reserved concurrency floor, JSON
  payload and mapping validation.
- secretsmanager: the rotation Lambda can write AWSPENDING over the
  placeholder RotateSecret creates.
- test/integration: tests updated to the realistic flows the realism
  passes now require (InService endpoints, existing thing types and
  versions, valid ids and engine versions).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Query result capacity no longer derives from the caller's $top, and
States.ArrayPartition clones each chunk instead of sizing make() from
an index subtraction. Results are unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants