Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 53 additions & 10 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ jobs:

- name: Run adopter type-check suite
if: matrix.python-version == '3.12'
run: mypy --strict tests/type_checks/
run: mypy --strict tests/type_checks/ examples/reporting_webhook_activity.py

- name: Enforce adopter type-check fixture contract
if: matrix.python-version == '3.12'
Expand All @@ -106,9 +106,15 @@ jobs:
run: pytest tests/ -v --cov=src/adcp --cov-report=term-missing

pg-conformance:
name: Postgres conformance tests (Postgres 16)
name: Postgres conformance tests (Postgres 16, ${{ matrix.lane }})
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
strategy:
fail-fast: false
matrix:
lane: [core, process]
services:
postgres:
# CI-local ephemeral database. POSTGRES_HOST_AUTH_METHOD=trust
Expand All @@ -130,6 +136,10 @@ jobs:
steps:
- uses: actions/checkout@v6

- name: Fetch reviewed reporting baseline for rolling binary tests
timeout-minutes: 1
run: git fetch --no-tags --depth=1 origin 17ee407ae3978c8a2bb54437287afbf9dafb8130

- name: Set up Python 3.12
uses: actions/setup-python@v6
with:
Expand All @@ -145,15 +155,48 @@ jobs:
- name: Run Postgres conformance tests
env:
ADCP_PG_TEST_URL: postgresql://postgres@localhost:5432/adcp_test
PG_LANE: ${{ matrix.lane }}
run: |
pytest tests/conformance/signing/test_pg_replay_store.py \
tests/conformance/signing/test_pg_replay_store_e2e.py \
tests/conformance/decisioning/test_pg_buyer_agent_registry.py \
tests/conformance/decisioning/test_pg_idempotency_backend.py \
tests/conformance/decisioning/test_pg_task_webhook_outbox.py \
tests/conformance/decisioning/test_pg_reference_workflow_queue.py \
tests/conformance/reporting/ \
-v
# Keep every case and its deadline. Separate process-crash controls
# so setup and teardown also fit inside each unchanged job budget.
case "$PG_LANE" in
core)
pytest tests/conformance/signing/test_pg_replay_store.py \
tests/conformance/signing/test_pg_replay_store_e2e.py \
tests/conformance/decisioning/test_pg_buyer_agent_registry.py \
tests/conformance/decisioning/test_pg_idempotency_backend.py \
tests/conformance/decisioning/test_pg_task_webhook_outbox.py \
tests/conformance/decisioning/test_pg_reference_workflow_queue.py \
tests/conformance/reporting/ \
--ignore=tests/conformance/reporting/test_reporting_notification_process_matrix.py \
-v
;;
process)
pytest tests/conformance/reporting/test_reporting_notification_process_matrix.py -v
;;
*)
echo "Unknown Postgres conformance lane"
exit 1
;;
esac

pg-conformance-required-gate:
name: Postgres conformance tests (Postgres 16)
runs-on: ubuntu-latest
timeout-minutes: 5
permissions: {}
needs: pg-conformance
if: ${{ always() }}
steps:
- name: Require every Postgres conformance lane
env:
PG_RESULT: ${{ needs.pg-conformance.result }}
run: |
if [ "$PG_RESULT" != "success" ]; then
echo "Postgres conformance matrix result: $PG_RESULT"
exit 1
fi
echo "All Postgres conformance lanes passed"

conventional-commits:
name: Validate conventional commit format
Expand Down
4 changes: 3 additions & 1 deletion docs/reporting-ledger-migration.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,9 @@ obligation IDs, the named obligations must exist in the requested account.
`reporting_ledger_account_generations.sql`,
`reporting_ledger_obligation_currency.sql`,
`reporting_ledger_reconciliation.sql`, and
`reporting_notification_outbox.sql` migrations in one transaction.
`reporting_notification_outbox.sql` and `reporting_webhook_activity.sql`
migrations in one transaction. For the later A-to-B additive upgrade and
activity activation barrier, see [durable reporting activity](reporting-webhook-activity.md).
3. Restart reporting work with the upgraded SDK on every instance.

For deployments managed by a migration tool, the standalone migration is
Expand Down
35 changes: 19 additions & 16 deletions docs/reporting-notification-outbox.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,10 +12,11 @@ It retains a durable status-dirty handoff for the later complete status projecto
| Managed destination/reconciliation change | Consumer-scoped status-dirty evidence |
| Verified materialization with its frozen Managed binding | `reporting.delivery_ready`, scoped to the reconciliation consumer |

There is no `reporting.status_changed` emitter. Clock sweeps, complete status
fingerprint deduplication, and webhook activity projection belong to #1168B.
The capability helper omits `status_notification` and sets
`supports_webhook_activity=false`.
There is no `reporting.status_changed` emitter. Clock sweeps and complete status
fingerprint deduplication belong to #1168C. The optional
[#1168B activity layer](reporting-webhook-activity.md) adds durable HTTP reservations
and a list-accounts projection. Without that mounted layer the capability helper
omits `status_notification` and sets `supports_webhook_activity=false`.

## Optional wiring

Expand Down Expand Up @@ -63,8 +64,9 @@ Core subscriber request cannot create a readiness event or capability.

The helper verifies that the opted-in ledger and outbox use the same store or
pool, that current registrations have usable authentication, and that the
entire installed PostgreSQL chain matches its column, constraint, index,
trigger, and guard-function contract. It does not infer operational readiness
required objects in the PostgreSQL chain match their column, constraint, index,
trigger, and guard-function contracts. Unrelated adopter objects are allowed.
It does not infer operational readiness
from the presence of objects. Continue scheduling the worker while advertising
these fields. Custom stores can implement the additive outbox protocol;
automatic capability verification conservatively covers the SDK reference stores.
Expand Down Expand Up @@ -185,8 +187,9 @@ deduplicate using a trusted publisher identity that survives key rotation and
the idempotency key. A lost ACK can produce another authenticated request with
identical body/key and a fresh signature. Polling remains the recovery path.

This slice retains events, expansion checkpoints, prepared bindings and dirty
evidence indefinitely. It has no purge API or finite advertised activity horizon.
The base outbox retains events, expansion checkpoints, prepared bindings and dirty
evidence indefinitely. The optional activity layer retains pending reservations
and counters indefinitely; its scoped purge enforces a 30-day terminal-history floor.
Do not delete parent events, keys, or prepared bindings while any delivery is
nonterminal or within an adopter's promised retry/activity retention horizon.

Expand All @@ -195,12 +198,12 @@ nonterminal or within an adopter's promised retry/activity retention horizon.
`reporting_notification_outbox.sql` follows the reviewed four-file foundation
chain. It adds notification events, expansion/delivery leases, ordered dirty
records, projector checkpoints, and typed issue scope storage. It rewrites and
backfills no ledger evidence. `create_schema()` installs all five steps atomically;
backfills no ledger evidence. `reporting_webhook_activity.sql` follows as an
additive sixth step. `create_schema()` installs all six steps atomically;
opted-in stores and `PgReportingOutbox.create_schema()` also validate the complete
installed contract before committing. Default-off Core startup preserves its
compatibility with adopter indexes. The conservative notification readiness check
requires the SDK table definitions, including their indexes and guards, to match
the bundled contract. Concurrent and repeated installations serialize on the schema
required outbox contract before committing. Activity startup additionally validates
the sixth step. Readiness validates required objects independently and ignores
unrelated adopter additions. Concurrent and repeated installations serialize on the schema
advisory lock. The standalone outbox SQL is atomic even on an autocommit
connection with the foundation already installed. See
[reporting ledger migrations](reporting-ledger-migration.md).
Expand All @@ -216,6 +219,6 @@ cover commit/fanout and real TLS HTTP acceptance/ACK. All child, pipe, receiver
and barrier waits have hard watchdogs with sanitized role/PID/checkpoint
diagnostics; no timing sleeps control an interleaving. The receiver fixture
self-check verifies both rotation keys before the full process lane is run.
The distribution tests build an sdist, build its wheel, import a real base
installation with PostgreSQL absent, then install `[pg]` and exercise migration,
commit and restart from that wheel.
The distribution tests build an sdist and its wheel, install each with PostgreSQL
absent, then install each with `[pg]` and exercise migration, commit, retry,
activity projection and restart on PostgreSQL 16.
Loading
Loading