diff --git a/sw-block/design/v3-phase-15-g9df-qa-test-instruction.md b/sw-block/design/v3-phase-15-g9df-qa-test-instruction.md new file mode 100644 index 000000000..bdefe93a3 --- /dev/null +++ b/sw-block/design/v3-phase-15-g9df-qa-test-instruction.md @@ -0,0 +1,74 @@ +# V3 Phase 15 G9D/F QA Test Instruction + +Date: 2026-05-02 +Status: QA-verified on `phase-15@eeef486` +Scope: lifecycle registration, placement planning, verified placement, and authority-boundary guards + +## Headline + +At `phase-15@eeef486`, G9D/F proves master can discover/register desired volume +and node inventory, compute and verify placement readiness, but still does not +grant authority. + +## Environment + +- Repo: `seaweed_block` +- Branch: `phase-15` +- Minimum commit: `eeef486` +- Fidelity: component/L2 with real package wiring; not m01/M02 hardware +- Non-claim: no production authority minting, frontend service, or recovery run + +## Command + +```powershell +go test ./core/lifecycle ./core/host/master ./core/authority ./cmd/blockmaster ./cmd/blockvolume -count=1 +``` + +Expected result: all five packages pass. `cmd/blockvolume` can take about two +minutes because it includes the G8 subprocess failover tests. + +## Scenario Checklist + +1. Desired volume persists. + Backing test: `core/lifecycle/store_test.go::TestFileStore_CreateVolumePersistsAndIsIdempotent` + +2. Node inventory persists. + Backing test: `core/lifecycle/node_inventory_test.go::TestNodeInventoryStore_RegisterNodePersistsCapacityAndReplicas` + +3. Planner produces placement intent. + Backing test: `core/lifecycle/reconciler_test.go::TestReconcilePlacement_HappyPathWritesPlacementIntent` + +4. Insufficient inventory fails closed. + Backing test: `core/lifecycle/reconciler_test.go::TestReconcilePlacement_InsufficientInventoryReportsButDoesNotPersist` + +5. Existing replica conflict fails closed. + Backing test: `core/lifecycle/reconciler_test.go::TestReconcilePlacement_ExistingReplicaConflictIsReportOnly` + +6. Verified placement requires observation. + Backing tests: `core/lifecycle/verified_placement_test.go::TestG9F_PlacementIntentWithoutObservation_DoesNotVerify`, + `core/host/master/lifecycle_test.go::TestMasterLifecycleSnapshot_PlacementWithoutNodeObservationIsNotVerified` + +7. Fresh observation verifies an existing replica. + Backing test: `core/host/master/lifecycle_test.go::TestMasterLifecycleSnapshot_ExistingReplicaVerifiesFromObservationStore` + +8. Stale observation or missing address fails closed. + Backing tests: `core/lifecycle/verified_placement_test.go::TestG9F_PlacementIntentWithStaleObservation_DoesNotVerify`, + `core/lifecycle/verified_placement_test.go::TestG9F_FreshObservationMissingControlAddress_DoesNotVerify` + +9. No authority side effect. + Backing tests: `core/host/master/lifecycle_test.go::TestMasterLifecycleStore_OpensRegistrationStoresWithoutAuthority`, + `core/host/master/lifecycle_test.go::TestMasterLifecycleSnapshot_ExistingReplicaVerifiesFromObservationStore`, + `core/host/master/lifecycle_test.go::TestMasterLifecycleSnapshot_PlacementWithoutNodeObservationIsNotVerified` + +## Non-Claims + +- Does not auto-assign a newly created volume. +- Does not make any blockvolume become primary or replica. +- Does not start iSCSI, NVMe, or frontend service paths. +- Does not start recovery, rebuild, or WAL feeding. +- Does not call the authority publisher or mint epoch / endpoint-version facts. + +## Closure Sentence + +G9D/F is a verify-only fact-layer checkpoint: product intent and observation can +produce `VerifiedPlacement`, but `VerifiedPlacement` is still not authority. diff --git a/sw-block/design/v3-phase-15-g9f-placement-authority-bridge-mini-plan.md b/sw-block/design/v3-phase-15-g9f-placement-authority-bridge-mini-plan.md index 0d7f36a09..b1664ca0d 100644 --- a/sw-block/design/v3-phase-15-g9f-placement-authority-bridge-mini-plan.md +++ b/sw-block/design/v3-phase-15-g9f-placement-authority-bridge-mini-plan.md @@ -1,10 +1,16 @@ # V3 Phase 15 G9F - Placement Intent to Authority Bridge Mini-Plan Date: 2026-05-02 -Status: architect draft; code must not start until §1.A is accepted +Status: §1.A architect-ratified 2026-05-02 for verify-only first slice; implemented and merged at `phase-15@eeef486` Branch target: `p15-g9d/volume-lifecycle-intent` or successor branch off `phase-15` Scope: first bridge from placement intent facts toward authority publication +§1.A architect-ratified: 2026-05-02. Binding applies only to the verify-only first slice: +`PlacementIntent + fresh Observation -> VerifiedPlacement`, with no publisher wiring and no +authority minting. Any follow-up that turns `VerifiedPlacement` into an authority request, +assignment ask, publisher apply, epoch, or endpoint-version change requires a separate G9F-2 +mini-plan and ratification. + ## 0. Why this needs a mini-plan G9D-A through G9D-E intentionally stayed on the observation/product-intent side: @@ -168,4 +174,3 @@ Only after the verify-only bridge is green: 1. decide whether verified placement becomes input to existing `TopologyController`, a new placement controller, or a publisher directive adapter; 2. write a separate mini-plan for the authority-minting slice; 3. add a negative test that observation-only and placement-only each fail, while placement+fresh-observation can request authority. -