Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
83 commits
Select commit Hold shift + click to select a range
4b3a019
docs(inflight) #197: record the v6 merge order, and what it deliberat…
astubbs Aug 8, 2026
219d31b
docs(release) astubbs#197: record the v6 scope decisions of 2026-09-07
astubbs Sep 7, 2026
3cc95d2
docs(release) astubbs#197: v6 is a bug release, overdue - the burn-do…
astubbs Sep 7, 2026
a94843d
docs(release) astubbs#197: record the merge-order note this decision …
astubbs Sep 7, 2026
cea3892
Merge branch 'docs/v6-merge-order' into docs/v6-burndown-checklist
astubbs Sep 7, 2026
2c874ec
docs(inflight) astubbs#197: retire the superseded v6 merge-order note
astubbs Sep 7, 2026
4f344fc
docs(inflight) astubbs#197: fold the artefact-correctness register in…
astubbs Sep 7, 2026
410f863
docs(release) astubbs#197: give every no-PR defect a disposition agai…
astubbs Sep 8, 2026
4dd3a9c
docs(release) astubbs#197: tick the first tier 1 merge, and hand its …
astubbs Sep 8, 2026
5860f41
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 8, 2026
6770542
Merge branch 'docs/v6-scope-decisions' into docs/v6-burndown-checklist
astubbs Sep 8, 2026
a9664df
Merge origin/master (astubbs#476, the vetting sweep) into docs/v6-bur…
astubbs Sep 8, 2026
6899b09
docs(inflight): mark the coverage note post-merge-checked where it ci…
astubbs Sep 8, 2026
a45e2e0
docs(release) astubbs#197: promote the poller-death fix into tier 1 a…
astubbs Sep 8, 2026
3e4fe97
docs(release) astubbs#197: absorb the sweep's gating list, queue the …
astubbs Sep 8, 2026
22bde74
docs(release) astubbs#197: two unknowns become known - the eager stal…
astubbs Sep 8, 2026
f6f4d3b
docs(release) astubbs#197: tier 1 follows the owner to astubbs#481, a…
astubbs Sep 8, 2026
5c35be4
docs(release) astubbs#197: the cross-module batch flake is known - th…
astubbs Sep 8, 2026
d621be4
docs(release) astubbs#197: the run-length ceiling is decided - in v6 …
astubbs Sep 8, 2026
2a8c02a
docs(release) astubbs#197: the deadlock fix is proven by control arm,…
astubbs Sep 8, 2026
8a71db9
docs(release) astubbs#197: state why a stability release is the right…
astubbs Sep 8, 2026
49c7d9d
docs(release) astubbs#197: name the PR in the tier 1 note for astubbs…
astubbs Sep 8, 2026
46c5bd9
docs(release) astubbs#197: rename the scope note to release-v6-scope.md
astubbs Sep 8, 2026
3c0e166
docs(release) astubbs#197: the offset-reset replay branch is refuted,…
astubbs Sep 8, 2026
a63713d
docs(release) astubbs#197: the intake stall astubbs#471 found joins t…
astubbs Sep 8, 2026
ca90d7e
docs(refactoring): the codec manager now also asks the broker for end…
astubbs Sep 8, 2026
b42ca47
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 8, 2026
47e3b93
docs(release) astubbs#197: tick astubbs#470 and astubbs#473 - tier 1 …
astubbs Sep 8, 2026
f8c217d
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 8, 2026
df9c54f
docs(release) astubbs#197: tick astubbs#481 - the retry-queue lock fi…
astubbs Sep 8, 2026
4281dc0
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 8, 2026
f72f38f
docs(release) astubbs#197: astubbs#482 merged - the batch-test expect…
astubbs Sep 8, 2026
5277fc2
docs(release) astubbs#197: the fifth open item is the group protocol,…
astubbs Sep 8, 2026
593dd60
docs(release) astubbs#197: qualify two issue references the gate caught
astubbs Sep 8, 2026
6bc41e1
docs(release) astubbs#197: split the 857 still-open list from what ha…
astubbs Sep 8, 2026
a5e421d
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 8, 2026
dfbb043
docs(release) astubbs#197: tick astubbs#469 and record astubbs#485 me…
astubbs Sep 8, 2026
eed89a2
Merge origin/master (astubbs#477) into docs/v6-burndown-checklist - t…
astubbs Sep 8, 2026
ef97bb7
docs(release) astubbs#197: astubbs#484 merged - the offset-reset repl…
astubbs Sep 8, 2026
78c9f1b
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 8, 2026
66afbcb
docs(release) astubbs#197: astubbs#483 and astubbs#486 merged, and wh…
astubbs Sep 8, 2026
e3e83bc
docs(release) astubbs#197: the still-open 857 lines get a box each, a…
astubbs Sep 8, 2026
40b96b1
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 8, 2026
addff84
docs(release) astubbs#197: astubbs#478 merged - the eager stall withd…
astubbs Sep 8, 2026
02ee26d
docs(release) astubbs#197: the known unknowns name what the merges le…
astubbs Sep 8, 2026
114b347
docs(release) astubbs#197: the intake stall is the load gate, and the…
astubbs Sep 8, 2026
bbd5d0f
docs(refactoring): astubbs#480 no longer deepens the codec's consumer…
astubbs Sep 8, 2026
95b3fcb
docs(release) astubbs#197: the intake stall is an eventual certainty,…
astubbs Sep 8, 2026
8d5b150
docs(release) astubbs#197: the intake stall latches on an idle instan…
astubbs Sep 8, 2026
14f4dae
docs(release) astubbs#197: the known unknowns keep only what is still…
astubbs Sep 8, 2026
38989d5
docs(release) astubbs#197: the false-truncation warning is decided - …
astubbs Sep 9, 2026
e90530f
docs(release) astubbs#197: the flake register's remaining rows are wo…
astubbs Sep 9, 2026
4d3c7ed
docs(release) astubbs#197: name every v6 note at the top, and absorb …
astubbs Sep 9, 2026
dfce710
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
ab35568
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
318ea59
docs(release) astubbs#197: tier 1 is complete - astubbs#480 and astub…
astubbs Sep 9, 2026
eb4e623
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
9c8b26c
docs(release) astubbs#197: astubbs#490 merged - the flake register ro…
astubbs Sep 9, 2026
1c9f764
docs(release) astubbs#197: the README's trademark wording joins the t…
astubbs Sep 9, 2026
e41c205
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
d707990
docs(release) astubbs#197: astubbs#491 closes the commit half of the …
astubbs Sep 9, 2026
daa3f2a
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
9423375
docs(release) astubbs#197: astubbs#487 and astubbs#492 merged - the i…
astubbs Sep 9, 2026
2d2c831
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
3277e71
docs(release) astubbs#197: the cut-off is confirmed, the second excep…
astubbs Sep 9, 2026
8781803
docs(release) astubbs#197: the batchSize validation bound rides in v6
astubbs Sep 9, 2026
1c90a0f
docs(release) astubbs#197: two review nits - the warning is not merge…
astubbs Sep 9, 2026
5e03f92
docs(release) astubbs#197: the scope note keeps only what releases v6
astubbs Sep 9, 2026
3a0371d
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
854eb8d
docs(release) astubbs#197: astubbs#494 merged - the false-truncation …
astubbs Sep 9, 2026
12050ac
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
7d71729
docs(upstream) astubbs#162: the confluentinc#546 manifest entry reads…
astubbs Sep 9, 2026
9d7d5fd
docs(release) astubbs#197: cite the write-up that replaced the retire…
astubbs Sep 9, 2026
64d9be5
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
3a1da1f
docs(release) astubbs#197: astubbs#446 merged - the announcement plan…
astubbs Sep 9, 2026
53d0375
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
b252fef
docs(release) astubbs#197: astubbs#496 merged - the batchSize bound i…
astubbs Sep 9, 2026
930e4c6
docs(release) astubbs#197: mark the announcement note's citation of t…
astubbs Sep 9, 2026
ab8a4c9
docs(release) astubbs#197: the gate-latch warning has a PR, astubbs#497
astubbs Sep 9, 2026
1ebb748
docs(release) astubbs#197: the changelog section is being finalised i…
astubbs Sep 9, 2026
0f8b87b
docs(release) astubbs#197: the claim amendment is carried by astubbs#498
astubbs Sep 9, 2026
30da940
Merge remote-tracking branch 'origin/master' into docs/v6-burndown-ch…
astubbs Sep 9, 2026
f6b0a43
docs(release) astubbs#197: astubbs#499 merged - the no-progress windo…
astubbs Sep 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 9 additions & 6 deletions docs/data/roadmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -86,10 +86,13 @@ entries:
one term, on both rebalance assignors, with the pre-fix arm failing every repetition and the
fixed arm none. The family is not closed by it - the transactional revoke wait (astubbs#44,
which carries upstream's verified-bug label) is a separate defect in a commit mode that fix
cannot reach, a third mechanism (a closing instance polling too little to leave its group
cleanly) has an open fix attempt in astubbs#444, and the family ledger
(`docs/inflight/bug-857-family.md`) still carries unattributed stall sightings reproducing on
trees that already carry astubbs#29's fix.
cannot reach - and on 2026-09-07 the owner placed it outside 0.6.0.0 for now, so the release
claim names it as the known exception rather than the release waiting on it. The suspected
third mechanism (a closing instance polling too little to leave its group cleanly) was measured
by astubbs#444 as the consumer-group protocol under the test's churn rate, not a PC defect. The
family ledger (`docs/inflight/bug-857-family.md`) still carries stall sightings on trees that
already carry astubbs#29's fix; the ones since classified are calibration and worker
saturation, not wedges.
why_now: The release claim rests on it, and the evidence has to be inspectable rather than asserted.
done_when: >-
No known critical defect open in release scope, and each resolution has a named guard that
Expand All @@ -100,7 +103,7 @@ entries:
- id: streams-parallelism-preview
title: Give a Kafka Streams topology the per-key parallelism of Parallel Consumer
serves: [flexibility, performance]
horizon: "0.6.0.0"
horizon: next-0x
blocks_1_0: false
stage: limited-poc
stage_delivery: draft
Expand All @@ -117,7 +120,7 @@ entries:
- id: connect-integration-preview
title: Run a Kafka Connect sink with Parallel Consumer underneath
serves: [flexibility]
horizon: "0.6.0.0"
horizon: next-0x
blocks_1_0: false
stage: limited-poc
stage_delivery: draft
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@

<!-- inflight-type: bug -->
<!-- inflight-impact: misdirection -->
<!-- post-merge: checked - astubbs#475 is cited as the docs-only PR whose coverage flags both went green, which stays true after it merges -->
<!-- inflight-state: closed - the stated delete-when now holds. Master's own two flags report DIFFERENT figures (at 49f81f155, `codecov/project/unit` 78.95% against `codecov/project/integration` 61.44%), which the identical-figure tell said could not happen while both flags held the same data; and astubbs#475, a PR with no `.java` in its diff, shows `codecov/project/unit` and `codecov/project/integration` both green. `maven.yml` carries the repair: `find`-built comma lists through `$GITHUB_OUTPUT`, `disable_search: true` on every `codecov/codecov-action` call, the master collector no longer on `always()`, and push runs keyed per SHA. Kept rather than deleted because [`docs/ci.md`](../ci.md) cites it and the files-count tell that separates the two causes is the part a later reader wants. -->
<!-- inflight-vetted: 2026-09-08 - applied: closed per the accepted proposal, state marker added, body left as the record; checked: `maven.yml` has `disable_search: true` on each upload, the per-SHA push `concurrency` group, and the master collector without `always()`; `gh pr checks 475 -R astubbs/parallel-consumer` shows both per-flag gates passing -->

Expand Down
99 changes: 88 additions & 11 deletions docs/inflight/process-candidate-ranking.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,16 +55,32 @@ astubbs/parallel-consumer#29 carried.

## What gates v6, as the sweep read it

[`release-when-is-v6-good-enough.md`](release-when-is-v6-good-enough.md) set the bar as "the bugs
that are already open". Six area sweeps each named what they read as gating (the owner's pass over
Moved into `release-v6-scope.md` on 2026-09-08 and back here on 2026-09-09, because it is the
sweep's dated reading rather than a decision; the burn-down's tiers override it where they
disagree and say so there. Kept whole as the record.

### The sweep's list, 2026-09-07

Moved here from `process-candidate-ranking.md` on 2026-09-08 (it was written by the six-agent sweep
on 2026-09-07 and is the agents' reading, with their stated confidence - not the owner's decision).
Where it disagrees with the tiers above, the tiers say so: the poisoned-transaction pair (the sweep:
not gating; the owner named it the second exception on 2026-09-09), the transactional revoke wait (the sweep read
astubbs#466 as having replaced the unbounded wait, which is right, and astubbs#408 as owning the
bound), and the `batchSize` validation bound (the sweep: cheapest real fix; the triage had filed
it as 0.6.0.x, and the owner moved it into tier 1 on 2026-09-09). Item 2 in its list, the dead poll thread, is
astubbs#477, merged.

The bar above is "the bugs that are already open". Six area sweeps each named what they read as gating (the owner's pass over
the sweep's proposals is done - [`process-inflight-vet-sweep.md`](process-inflight-vet-sweep.md)
records it); this is the union,
ordered by user-visible consequence, with the confidence each agent stated. The mechanical gate
comes first because nothing else matters until it clears.

- **The quarantine registry is non-empty, and every entry is unowned.** `release.yml` refuses the
cut while [`docs/quarantined-tests.md`](../quarantined-tests.md) lists anything; read that file,
not this line.
- ~~**The quarantine registry is non-empty, and every entry is unowned.**~~ *The sweep's reading on
2026-09-07; the registry is empty on master (astubbs#80 emptied it and nothing has joined since),
which this note says in its tag-day checks.* `release.yml` refuses the cut while
[`docs/quarantined-tests.md`](../quarantined-tests.md) lists anything; read that file, not this
line.
- **Verified defects, in the code as written today:**
1. `bug-857-transactional-revoke-wait.md` - was the unbounded wait inside the revoke callback,
with a user report carrying upstream's verified-bug label. astubbs#466 (merged the day the sweep
Expand All @@ -73,14 +89,15 @@ comes first because nothing else matters until it clears.
`core-revoke-commit-skips-the-work-mailbox-drain.md` as gating - a deterministic exactly-once
break with C9 refuted - and the same commit fixed it; the note is gone and the record is in
`docs/solutions/logic-errors/`.
2. A dead poll thread holding its partitions for `max.poll.interval.ms` in the default commit mode -
read as gating, and traced end to end but untested and unfixed when the sweep ran. Now tested
and fixed: `maybeCloseConsumer` gained an arm for a poll thread that ended without closing the
consumer, the note is gone, and the record is in
`docs/solutions/logic-errors/a-duty-assigned-by-role-is-unassigned-when-the-role-holder-dies-2026-09-08.md`.
2. A dead poll thread holding its partitions for `max.poll.interval.ms` in the default commit
mode - read as gating, traced end to end but untested and unfixed when the sweep ran. Now
tested and fixed by astubbs#477 (merged): `maybeCloseConsumer` gained an arm for a poll thread
that ended without closing the consumer; the note is gone and the record is in
`docs/solutions/logic-errors/`.
3. `pr-431-must-pair-its-queue-removal-with-the-shard-removal.md` with
`bug-retry-queue-write-lock-on-the-rebalance-path.md` - the retry-queue orphan window; master
is still shard-first and astubbs#431 is a draft.
is still shard-first and astubbs#431 is a draft. *(Since overtaken: astubbs#431 closed as
superseded by the owner's astubbs#481, ready and green, which is what tier 1 lists.)*
4. `batchSize(0)` silently processing nothing - read as the cheapest real fix in the set, and it
was. Now fixed: `validate()` rejects zero, a negative and null, which is astubbs#311's
validation half; the arithmetic half stays open in `bug-batch-quantity-over-request.md`. The
Expand Down Expand Up @@ -117,6 +134,66 @@ comes first because nothing else matters until it clears.
by the shared-nothing rework); and the poisoned-transaction pair, where today's behaviour is
strictly better than what it replaced.

### Every open bug note's disposition against the v6 bar, as of 2026-09-08

The sweep's reading above agrees with the look-at items below and added one this section had filed
as 0.6.0.x: `batchSize(0)` silently processes nothing, and the sweep calls the `validate()` bound
"the cheapest real fix in the set" (astubbs#311) - now in tier 1 by the owner's 2026-09-09 decision. Its list of instruments the release decision is
read through that are currently lying or unproven is worth reading before trusting a green.

"Gate on open bugs" only works if every open bug has a disposition, so this is every `bug-` note on
master that no queue PR addresses (`ls docs/inflight/bug-*.md` is the list; the impact tag on each
is the sort key). Re-derive it before the tag rather than trusting it: a note can gain a PR or lose
its subject at any merge.

**Look at before the tag - these contradict the release claim if left silent:**

- ~~The eager-mode stall that reproduces with the fixes applied~~ - **withdrawn, astubbs#478 (merged)**
(2026-09-08): not a defect, a timing bound crossing on processor count. Nothing to ship or name.
- ~~Poller death leaves the consumer open in consumer-commit modes~~ - **now astubbs#477 in tier 1**
(2026-09-08). The fix was as small as the note proposed, and its defect-class sweep - cleanup gated
on "am I the role-holder?" where the holder may be dead - found no other instance across the four
modules' `close()` paths.

**Owner's decision - taken 2026-09-08: in v6, as astubbs#480 (tier 1).**

- ~~Run-length plausibility ceiling~~ - a readable but absurd run length marked a vast range complete
and PC silently skipped it; data-loss class, reachable only through a corrupt or foreign payload,
which is why astubbs#207 did not cover it. astubbs#480 bounds every decoded run and bitset by the
partition's log end offset - the one bound that cannot reject a real map, since PC only encodes
offsets it polled - routed through `invalidOffsetMetadataPolicy` with no parallel policy, failing
open with a warn if the broker will not answer. The same defect class was found and fixed in the
bitset decoder; the simple serialisation has no declared count and is clean. The inflight note is
retired into `docs/solutions/`.

**0.6.0.x - open, real, not a gate for a bug release:**

- Config lies: `maxFailureHistory` is read nowhere; `offsetCommitTimeout` bounds two different
waits; `batchSize`'s over-request arithmetic (astubbs#311's other half, deferred) - its validation
bound is in tier 1 since 2026-09-09.
- Blind spots: the racy and uncalled pause API; no metric for a discarded offset map under the
default `IGNORE` policy; the worker future swallowing framework exceptions.
- Misdirection: the plain-`int` out-for-processing counter; the module's processor reference
overwritten before the owner guard; the rest of the unbounded-log-lines class; the two 857 mirror
attributions never verified against the reporter's environment.
- Deferred with a reason in the note, and outside a bug release: the shard's available-work
counter undercounting after a stale replacement
([`bug-processing-shard-available-work-undercount.md`](bug-processing-shard-available-work-undercount.md)
- a gauge inaccuracy that loses no records; the decision is whether the counter is worth keeping);
the deferred-commit WARN naming no offsets
([`bug-deferred-commit-warn-names-no-offsets.md`](bug-deferred-commit-warn-names-no-offsets.md) -
astubbs#352 owns the method and adds the field the fix needs); and batching requesting a full
extra in-flight target ([`bug-batch-quantity-over-request.md`](bug-batch-quantity-over-request.md)
- throughput only).
- The shutdown teardown race; the test-only `close()` shadowing; and
[`bug-shared-collections-across-the-poll-boundary.md`](bug-shared-collections-across-the-poll-boundary.md),
which is mostly stale - the metrics set and the shared empty set it names are both fixed on master
and the note needs shrinking to whatever remains.

**Not a bug note, but a signal - settled:** the `simpleBatchTest` failures across the Reactor,
Mutiny and Vert.x modules were the test's own randomised key draw, not the batcher (astubbs#482,
see the known-unknowns section). The register's most-sighted row is retired.

## Ready picks

Collisions are in `pr-blockers-and-collisions.md`. The ranked backlog and full verdicts live in
Expand Down
18 changes: 17 additions & 1 deletion docs/inflight/release-0.6.0.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -127,7 +127,7 @@ worth.

At release, when the changelog section is regenerated, check both survived into `=== Breaking`:
generation reads the commit log, so they are only as findable as those commit bodies. The rename side
of that same check is in [`release-0600-blockers.md`](release-0600-blockers.md).
of that same check is in [`release-v6-scope.md`](release-v6-scope.md), under the tag-day artefact checks.

## Public API change landing with astubbs#204: the commit give-up exception

Expand Down Expand Up @@ -212,6 +212,22 @@ Evidence is in `docs/data/testing-evidence.yaml`; the checks to run are in
`docs/data/module-maturity.yaml` under `release_validation`. If a check fails, amend the claim rather
than waive the item.

**The claim is amended, 2026-09-07: one known critical defect is outside 0.6.0.0's scope, and the
release notes must name it.** The transactional revoke wait - astubbs#44, upstream's only
verified-bug label, `PERIODIC_TRANSACTIONAL_PRODUCER` only; **bounded since astubbs#466 by
`commitLockAcquisitionTimeout`, not yet declined** (astubbs#408 measures that bound and holds the decline seam; astubbs#466 refuted declining as the fix, so it is only the deadline fallback), so the release
note says "bounded, not yet declined" rather than "unbounded" - detail in
[`bug-857-transactional-revoke-wait.md`](bug-857-transactional-revoke-wait.md) - has its fix in
astubbs#408, which depends on producer-fencing recovery (astubbs#410) by design, and the owner has
placed that work after v6 for now. So the published sentence is not "every known critical defect",
it is "every known critical defect except this one, which is named, reproduced, and fixed on a
branch". **Amended again 2026-09-09: a second named exception, the poisoned-transaction wedge** -
in `PERIODIC_TRANSACTIONAL_PRODUCER` mode a single record the producer rejects as too large is
never aborted while the instance runs, so its partition stops for the life of the process; fixed
by astubbs#434 on the same stack, outside 0.6.0.0 by the same decision, and named beside
astubbs#44 rather than carried as a standalone abort. The standard is unchanged; the claim is what moved, which is the order this paragraph asks
for. If astubbs#410 lands before the tag, delete this paragraph.

**Deliberately not in this release:** virtual threads, micro-batching and the dead letter queue. These
are new capabilities rather than known-defect exceptions, so deferring them does not weaken the gate.
They carry horizons in `docs/data/roadmap.yaml`.
Expand Down
Loading
Loading