Skip to content

Iggy provider, deep e2e suites, GA hardening (0.4.0) - #3

Merged
ZhiXiao-Lin merged 9 commits into
mainfrom
feat/iggy-provider-ga
Sep 30, 2026
Merged

ZhiXiao-Lin merged 9 commits into
mainfrom
feat/iggy-provider-ga

Conversation

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor

Summary

  • Apache Iggy provider (feature iggy, SDK 0.11 / server 0.9): category=topic mapping with client-side filter narrowing, durable subscriptions as consumer groups with explicitly stored offsets (at-least-once, last-consumed convention), subscribe-time head probing for New/Last, provider-owned connect deadline, PAT/password login. Fail-closed where the broker can't honor the contract (expected_sequence, LastPerSubject); documented no-ops (max_deliver etc., single-partition topics).
  • Test assets: cross-provider conformance suite (tier 0 all providers ×7 / tier 1 persistent ×5), feature e2e (pipeline, routing/bridge, cron, crypto, CloudEvents, messaging, DLQ/schema completion, error paths), 32-row iggy contract matrix incl. poison-message tolerance, opt-in chaos suite (iggy/nats restart mid-stream, PAT login).
  • Fixes (several independently found by the deep tests, incl. one this merge surfaced): broker routing failures now reach the DLQ, symmetric wildcard matching in InMemoryMessaging, NATS consumer names sanitized at BOTH call sites, ByStartTime positioning held until a poll returns, set_schema_registry/from_provider API symmetry.
  • Hardening: A3S_EVENT_REQUIRE_BROKERS/_REQUIRE_NATS fail-closed harnesses (dead service container fails CI instead of skip-passing green), pid-first subject isolation, criterion baselines, unit coverage 82.9%, CHANGELOG 0.4.0 with migration notes, GA readiness audit.

Known upstream issue

Iggy server 0.9.0 intermittently panics on restart boot replay (client_id 0 is reserved for internal use) — 4 reproductions locally; draft in docs/upstream-iggy-restart-panic.md. Until fixed upstream the iggy feature is documented as not GA-hardened (memory/nats are).

Verification

  • default features: 283 passed / 0 failed
  • nats,iggy: 249 passed / 0 failed (require-brokers mode, live brokers)
  • clippy -D warnings clean on both feature sets; fmt clean; cargo publish --dry-run clean

🤖 Generated with Claude Code

RoyLin and others added 9 commits September 30, 2026 21:13
Provider: Apache Iggy backend (feature `iggy`, SDK 0.11 / server 0.9) —
subject-category=topic mapping with client-side filter narrowing, durable
subscriptions as consumer groups with explicitly stored offsets
(at-least-once, last-consumed convention), subscribe-time head probing for
New/Last positioning, provider-owned connect deadline, PAT or password
login; fail-closed where the broker cannot honor the contract.

Test assets: cross-provider conformance suite (tier 0 on every provider x7
deep scenarios, tier 1 persistent-only x5), feature e2e suites (pipeline,
routing/bridge, cron, crypto, CloudEvents, messaging, DLQ/schema/sinks
completion, error paths), 32-row iggy contract matrix fully implemented
incl. poison-message tolerance, opt-in chaos suite (iggy + nats restart
mid-stream, PAT login).

Fixes surfaced by the deep e2e: broker routing failures now reach the DLQ
(previously logged only), wildcard pattern matching corrected in
InMemoryMessaging, NATS durable consumer names sanitized (JetStream rejects
'.','*','>' — migration warning in CHANGELOG), NATS history Last->All,
Iggy ByStartTime positioning held until a poll returns messages,
schema-registry setter symmetry, bounded e2e connect retry.

GA hardening: unit coverage measured (82.9% lines lib-only), criterion
baselines in README, minimal core cross-compiles for linux x64/arm64 +
windows, crate CI workflow (3-OS matrix + broker service containers +
chaos + coverage), CHANGELOG 0.4.0 with migration notes and the known
upstream iggy 0.9.0 restart-replay panic (client_id 0 reserved) that the
chaos suite found.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
…p-if-unreachable into a hard failure; CI service jobs set it

Without this, a service container that never started yields a green build
of silently skipped e2e suites. Verified in both directions against a live
and a dead iggy container.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Merge of feat/iggy-provider-ga-local (unrelated-histories) onto origin/main,
resolved per file:
- nats/client.rs history: keep main's bounded pending-aware scan (already
  fixed DeliverPolicy Last->All in #2)
- store.rs: keep GA additions (set_schema_registry, from_provider, broker
  DLQ wiring) + adopt main's subscription_consumer_name helper at BOTH
  call sites (the second site still used the '.'-only replace — latent bug
  this merge surfaced and fixes)
- nats_integration.rs: keep main's superset tests (Require-NATS fail-closed,
  single-thread discipline) + pid-first subject isolation so re-runs on a
  shared server never overlap old wildcard streams
- CI: main's quality/jetstream jobs + new Apache Iggy job (digest-pinned
  nats stays; iggy container with seccomp=unconfined, single shard, 2s
  rebalance) + iggy clippy in quality
- README: main's (incl. zh-CN switcher) + iggy provider section, provider
  table row, Operations section
- Cargo.toml/lib/provider/mod/messaging: GA side (0.4.0, iggy feature,
  symmetric wildcard fix)

Merged-tree verification: default 283 / nats+iggy 249 (require-brokers
fail-closed mode), clippy -D warnings clean both feature sets, fmt clean.

Co-Authored-By: Claude Code <noreply@anthropic.com>
The umbrella A3S_EVENT_REQUIRE_BROKERS made the iggy job (which starts only
an iggy container) fail-closed on all 12 NATS conformance scenarios —
first remote run failed exactly there. Each job now gates only the broker
it starts; the umbrella var remains for local all-broker runs.

Co-Authored-By: Claude Code <noreply@anthropic.com>
--all-targets executes the criterion bench target, which rejects
--test-threads (harness = false). --tests covers lib + integration suites
and skips benches.

Co-Authored-By: Claude Code <noreply@anthropic.com>
iggy 0.9.0 intermittently panics on boot/restart replay (apache/iggy#4361,
six reproductions today), which can kill the server mid-suite and fail the
job through the REQUIRE_IGGY fail-closed gate — correctly. One retry on a
fresh container keeps CI signal honest: a genuine regression fails twice.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@ZhiXiao-Lin
ZhiXiao-Lin merged commit db48a4a into main Sep 30, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants