Skip to content

Latest commit

Β 

History

History
301 lines (270 loc) Β· 23.8 KB

File metadata and controls

301 lines (270 loc) Β· 23.8 KB

Architecture validation and release evidence index

This index binds architecture validation, compatibility retirement, and production evidence to the current repository facts. Workflow artifacts are evidence only when their name includes the tested commit SHA; this document does not claim that a scheduled or release run succeeded.

Toolchain and root workspace

  • Formal Rust toolchain and MSRV: 1.95.0.
  • Root workspace packages: 28.
  • Full integration checks: cargo fmt --all -- --check, workspace Clippy, all-feature tests, and cargo doc --workspace --no-deps --all-features. Routine PR work is selected by changed paths; see the CI validation policy for feature and platform routing.
Package Workspace path
rocketmq-admin-cli rocketmq-tools/rocketmq-admin/rocketmq-admin-cli
rocketmq-admin-core rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-admin-tui rocketmq-tools/rocketmq-admin/rocketmq-admin-tui
rocketmq-auth rocketmq-auth
rocketmq-broker rocketmq-broker
rocketmq-client-rust rocketmq-client
rocketmq-controller rocketmq-controller
rocketmq-dashboard-common rocketmq-dashboard/rocketmq-dashboard-common
rocketmq-error rocketmq-error
rocketmq-filter rocketmq-filter
rocketmq-macros rocketmq-macros
rocketmq-model rocketmq-model
rocketmq-namesrv rocketmq-namesrv
rocketmq-observability rocketmq-observability
rocketmq-protocol rocketmq-protocol
rocketmq-proxy rocketmq-proxy
rocketmq-proxy-cluster rocketmq-proxy-cluster
rocketmq-proxy-core rocketmq-proxy-core
rocketmq-proxy-local rocketmq-proxy-local
rocketmq-runtime rocketmq-runtime
rocketmq-security-api rocketmq-security-api
rocketmq-store rocketmq-store
rocketmq-store-api rocketmq-store-api
rocketmq-store-inspect rocketmq-tools/rocketmq-store-inspect
rocketmq-store-local rocketmq-store-local
rocketmq-store-rocksdb rocketmq-store-rocksdb
rocketmq-tieredstore rocketmq-tieredstore
rocketmq-transport rocketmq-transport

Accepted code/system candidate

This acceptance covers the code/system phase. Target-hardware performance comparison, the six-hour soak, complete disaster recovery, Docker images, and real external adapters remain later V1 evidence.

Standalone Cargo validation matrix

Project Owner Toolchain Manifest Required commands Workflow
fuzz Fuzz and production input maintainers nightly-2026-07-05 fuzz/Cargo.toml cargo +nightly-2026-07-05 check --locked --manifest-path fuzz/Cargo.toml --all-targets --all-features .github/workflows/fuzz-ci.yml
example Examples maintainers 1.95.0 rocketmq-example/Cargo.toml cargo fmt --all -- --check
cargo clippy --all-targets -- -D warnings
cargo test
cargo build --examples
.github/workflows/rocketmq-example-ci.yaml
rocketmq-mcp RocketMQ MCP maintainers 1.95.0 rocketmq-ai/rocketmq-mcp/Cargo.toml cargo fmt --all -- --check
python scripts/check_read_only_boundary.py
cargo test --locked
cargo test --locked --all-features
cargo clippy --locked --all-targets --features streamable-http -- -D warnings
cargo doc --locked --no-deps
.github/workflows/rocketmq-mcp-ci.yaml
rocketmq-sre RocketMQ AI SRE maintainers 1.95.0 rocketmq-ai/rocketmq-sre/Cargo.toml cargo fmt -p rocketmq-sre-contracts -p rocketmq-sre-core -p rocketmq-sre-model-gateway -p rocketmq-sre-control-plane -p rocketmq-sre-connector -p rocketmq-sre-executor -p rocketmq-sre-execution-agent -p rocketmq-sre-probe -p rocketmq-sre-eval -p rocketmq-sre-client -p rocketmq-sre-cli -- --check
cargo test --locked --workspace --all-features
cargo clippy --locked --workspace --all-targets --all-features -- -D warnings
cargo doc --locked --workspace --no-deps
python scripts/check_source_layout.py
python scripts/check_execution_dependency_boundary.py
.github/workflows/rocketmq-sre-ci.yml
dashboard-gpui Dashboard GPUI maintainers 1.95.0 rocketmq-dashboard/rocketmq-dashboard-gpui/Cargo.toml cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo test
.github/workflows/dashboard-gpui-ci.yml
dashboard-tauri-backend Dashboard Tauri maintainers 1.95.0 rocketmq-dashboard/rocketmq-dashboard-tauri/src-tauri/Cargo.toml cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo test --all-features
.github/workflows/dashboard-tauri-ci.yml
dashboard-web-backend Dashboard Web backend maintainers 1.95.0 rocketmq-dashboard/rocketmq-dashboard-web/backend/Cargo.toml cargo fmt --all -- --check
cargo clippy --all-targets --all-features -- -D warnings
cargo test
.github/workflows/dashboard-web-ci.yml

Shared crate to standalone consumer edges

Standalone package Dependency Root target path
rocketmq-dashboard-gpui rocketmq-admin-core rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-dashboard-gpui rocketmq-dashboard-common rocketmq-dashboard/rocketmq-dashboard-common
rocketmq-dashboard-gpui rocketmq-observability rocketmq-observability
rocketmq-dashboard-gpui rocketmq-runtime rocketmq-runtime
rocketmq-dashboard-tauri rocketmq-admin-core rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-dashboard-tauri rocketmq-dashboard-common rocketmq-dashboard/rocketmq-dashboard-common
rocketmq-dashboard-tauri rocketmq-error rocketmq-error
rocketmq-dashboard-tauri rocketmq-model rocketmq-model
rocketmq-dashboard-tauri rocketmq-runtime rocketmq-runtime
rocketmq-dashboard-web-backend rocketmq-admin-core rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-dashboard-web-backend rocketmq-dashboard-common rocketmq-dashboard/rocketmq-dashboard-common
rocketmq-dashboard-web-backend rocketmq-error rocketmq-error
rocketmq-dashboard-web-backend rocketmq-observability rocketmq-observability
rocketmq-dashboard-web-backend rocketmq-runtime rocketmq-runtime
rocketmq-example rocketmq-client-rust rocketmq-client
rocketmq-example rocketmq-model rocketmq-model
rocketmq-example rocketmq-observability rocketmq-observability
rocketmq-example rocketmq-protocol rocketmq-protocol
rocketmq-example rocketmq-runtime rocketmq-runtime
rocketmq-example rocketmq-tools rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-mcp rocketmq-admin-core rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-mcp rocketmq-observability rocketmq-observability
rocketmq-mcp rocketmq-runtime rocketmq-runtime
rocketmq-mcp rocketmq-security-api rocketmq-security-api
rocketmq-mcp rocketmq-transport rocketmq-transport
rocketmq-rust-fuzz rocketmq-broker rocketmq-broker
rocketmq-rust-fuzz rocketmq-controller rocketmq-controller
rocketmq-rust-fuzz rocketmq-protocol rocketmq-protocol
rocketmq-rust-fuzz rocketmq-store-local rocketmq-store-local
rocketmq-sre-cli rocketmq-sre-client rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-client
rocketmq-sre-cli rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-client rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-connector rocketmq-admin-core rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-sre-connector rocketmq-observability rocketmq-observability
rocketmq-sre-connector rocketmq-runtime rocketmq-runtime
rocketmq-sre-connector rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-connector rocketmq-sre-core rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-core
rocketmq-sre-control-plane rocketmq-observability rocketmq-observability
rocketmq-sre-control-plane rocketmq-runtime rocketmq-runtime
rocketmq-sre-control-plane rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-control-plane rocketmq-sre-core rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-core
rocketmq-sre-control-plane rocketmq-sre-model-gateway rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-model-gateway
rocketmq-sre-core rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-eval rocketmq-runtime rocketmq-runtime
rocketmq-sre-eval rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-eval rocketmq-sre-core rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-core
rocketmq-sre-eval rocketmq-sre-model-gateway rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-model-gateway
rocketmq-sre-execution-agent rocketmq-admin-core rocketmq-tools/rocketmq-admin/rocketmq-admin-core
rocketmq-sre-execution-agent rocketmq-runtime rocketmq-runtime
rocketmq-sre-execution-agent rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-executor rocketmq-runtime rocketmq-runtime
rocketmq-sre-executor rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-executor rocketmq-sre-core rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-core
rocketmq-sre-executor rocketmq-sre-execution-agent rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-execution-agent
rocketmq-sre-model-gateway rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts
rocketmq-sre-probe rocketmq-client-rust rocketmq-client
rocketmq-sre-probe rocketmq-error rocketmq-error
rocketmq-sre-probe rocketmq-model rocketmq-model
rocketmq-sre-probe rocketmq-runtime rocketmq-runtime
rocketmq-sre-probe rocketmq-sre-contracts rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-contracts

Tokio feature declarations

full is allowed only at the application roots listed in the validation policy. Workspace libraries inherit an explicit feature union rather than the full meta-feature.

Manifest Dependency Features Inherited from workspace
Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time no
Cargo.toml tokio-stream fs, io-util, net, signal, sync, time no
Cargo.toml tokio-util codec, compat, io-util, net, rt, time no
rocketmq-ai/rocketmq-mcp/Cargo.toml tokio full no
rocketmq-ai/rocketmq-mcp/Cargo.toml tokio-util full no
rocketmq-ai/rocketmq-sre/Cargo.toml tokio macros, net, signal, sync, time no
rocketmq-ai/rocketmq-sre/Cargo.toml tokio-stream net, sync no
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-cli/Cargo.toml tokio macros, net, rt, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-client/Cargo.toml tokio macros, net, rt, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-connector/Cargo.toml tokio macros, net, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-control-plane/Cargo.toml tokio macros, net, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-control-plane/Cargo.toml tokio-stream net, sync yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-eval/Cargo.toml tokio macros, net, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-execution-agent/Cargo.toml tokio macros, net, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-executor/Cargo.toml tokio macros, net, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-model-gateway/Cargo.toml tokio io-util, macros, net, rt, signal, sync, time yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-model-gateway/Cargo.toml tokio-stream net, sync yes
rocketmq-ai/rocketmq-sre/crates/rocketmq-sre-probe/Cargo.toml tokio macros, net, signal, sync, time yes
rocketmq-auth/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-broker/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-broker/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-client/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-client/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-controller/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-controller/Cargo.toml tokio-stream net, sync no
rocketmq-controller/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-dashboard/rocketmq-dashboard-common/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-dashboard/rocketmq-dashboard-gpui/Cargo.toml tokio full no
rocketmq-dashboard/rocketmq-dashboard-gpui/Cargo.toml tokio-stream full no
rocketmq-dashboard/rocketmq-dashboard-gpui/Cargo.toml tokio-util full no
rocketmq-dashboard/rocketmq-dashboard-tauri/src-tauri/Cargo.toml tokio sync, time no
rocketmq-dashboard/rocketmq-dashboard-web/backend/Cargo.toml tokio full no
rocketmq-example/Cargo.toml tokio full no
rocketmq-namesrv/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-namesrv/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-observability/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-observability/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-proxy-cluster/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-proxy-cluster/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-proxy-core/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-proxy-core/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-proxy-local/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-proxy-local/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-proxy/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-proxy/Cargo.toml tokio-stream fs, io-util, net, signal, sync, time yes
rocketmq-proxy/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-runtime/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt, rt-multi-thread, signal, sync, time yes
rocketmq-runtime/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-store-local/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-store-local/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-store-rocksdb/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-store/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-store/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-tieredstore/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-tieredstore/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes
rocketmq-tools/rocketmq-admin/rocketmq-admin-cli/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-tools/rocketmq-admin/rocketmq-admin-core/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-tools/rocketmq-admin/rocketmq-admin-tui/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-tools/rocketmq-admin/rocketmq-admin-tui/Cargo.toml tokio-stream fs, io-util, net, signal, sync, time yes
rocketmq-transport/Cargo.toml tokio fs, io-std, io-util, macros, net, process, rt-multi-thread, signal, sync, time yes
rocketmq-transport/Cargo.toml tokio-util codec, compat, io-util, net, rt, time yes

Compatibility retirement

Debt Final state Evidence
StableConfig borrowed history Removed owned Arc snapshots; no retained-generation list or unsafe borrow
MessageStoreInner Removed the public MessageStore trait is generated in place; no inner trait or legacy adapter
MQAdminExtInner Removed marker, empty alias, modules, and crate-root re-exports deleted
Raw runtime/detached spawn Crate-private or removed RuntimeHandle and root creation are private; detached spawn has no public entry

The still-public MessageStore and producer facades retain real downstream value and remain narrow forwarders. Their next deletion review is the next approved major release. RuntimeContext remains document-hidden for tests and migration harnesses; production composition roots use RuntimeOwner and inject ChildServiceContext/TaskGroup capabilities.

Python architecture test inventory

  • Inventoried test modules: 45.
  • Guard runner: python scripts/run_architecture_tests.py --tier pr_static.
  • Contract runner: python scripts/run_architecture_tests.py --tier phase_contract --tier dynamic_fixture.
Tier Modules
pr_static 26
phase_contract 3
dynamic_fixture 12
deferred_validation 4

Evidence workflows and artifact identities

Evidence Workflow Artifact identity
fuzz .github/workflows/fuzz-ci.yml architecture-fuzz-<target>-<commit>
miri-loom-coverage .github/workflows/architecture-nightly-evidence.yml architecture-nightly-<kind>-<commit>

Coverage uses a root-workspace auto baseline with a 1% allowed regression and a 70% patch target. Each standalone application publishes a separate LCOV artifact; the fuzz standalone reports libFuzzer edge coverage and retains its versioned corpus rather than producing an empty unit-test LCOV report.

Critical evidence workflows pin checkout and artifact upload Actions to reviewed commit SHAs. Run maintained Cargo benchmark targets when performance behavior changes. Historical M10 fingerprints, frozen command inventories, and fixed comparison thresholds are retired. Fault and soak artifacts use their dedicated qualification policies; failures retain replay inputs and diagnostics without committing runtime output. The automated SLO and Kubernetes fault workflows are retired. Their local runners and evidence guards remain available for explicitly provisioned qualification environments. For published service images, use scripts/verify_service_image_publication.py to verify the signed five-image publication before deriving the candidate image map. The retained Kubernetes assets workflow performs static checks and does not produce live fault or soak evidence.

Unified production qualification bundle

scripts/architecture_evidence_bundle.py assembles a relocatable manifest for exactly five release evidence classes: performance, HA soak with observed RPO/RTO, disaster recovery, N-1 rolling upgrade, and the five-image supply chain. Records bind a fixed category/source, a full candidate commit, a strict fixture boolean, and an explicit pass, fail, or not-run status. A pass record requires a non-empty artifact list. The bundle hashes the record and verifies every explicit first-level artifact by raw bytes relative to the record directory; paths cannot escape or repeat. It does not recursively discover files or decide domain semantics such as performance budgets, RPO/RTO, disaster recovery, compatibility, vulnerability, or signature validity. Those verdicts remain the responsibility of the producer guard named by the fixed source.

Missing records remain not-run; fixture records cannot claim pass; candidate, source, category, or artifact mismatches become fail. At promotion, --require-pass also requires --candidate and rejects both incomplete bundles and a manifest bound to a different commit. Bundle and comparison outputs reject exact, symbolic-link, and hard-link aliases of their protected inputs, then publish through a unique same-directory temporary file and atomic replacement. --require-category-pass <category> is a scoped gate: it requires a matching full --candidate and a pass for that category while allowing the other categories to remain not-run. It does not weaken the full-bundle semantics of --require-pass.

python scripts/architecture_evidence_bundle.py assemble --candidate <full-sha> \
  --evidence-root <dir> --evidence performance=<record.json> --output bundle.json
python scripts/architecture_evidence_bundle.py validate --evidence-root <dir> \
  --manifest bundle.json
python scripts/architecture_evidence_bundle.py validate --evidence-root <dir> \
  --manifest bundle.json --require-pass --candidate <full-sha>
python scripts/architecture_evidence_bundle.py validate --evidence-root <dir> \
  --manifest bundle.json --require-category-pass performance --candidate <full-sha>

Architecture evidence cross-checks

  • Trait design and review guidance: rocketmq-doc/en/rust-trait-design-guidelines.md.
  • Dependency and public-facade state: scripts/architecture-dependency-policy.json and the package-boundary checker.
  • Manual Pin, production unsafe, panic/unwrap/expect, and historical mod.rs state: scripts/rust_hygiene_guard.py (safety checks plus advisory observations).
  • Runtime ownership: the runtime audit report and maintained cancellation/shutdown tests.
  • Distributed evidence: distribution/kubernetes/fault-matrix-policy.json and the SLO/fault guards.
  • Risk-to-test matrix: scripts/architecture-risk-test-matrix.json.
  • Deterministic property suites: scripts/property-state-suite-registry.json.
  • Fuzz corpus ownership and retention: fuzz/corpus-registry.json.
  • Unified production qualification manifest: scripts/architecture_evidence_bundle.py.
  • Core capability contracts: rocketmq-doc/en/core-capability-contracts.md.
  • Acknowledgement/failover ADR: rocketmq-doc/en/acknowledgement-failover-contract-adr.md.
  • Regional DR boundary: rocketmq-doc/en/regional-disaster-recovery-adr.md.