Skip to content

release: v2.2.0 Kafka-native serving and durable consumer SDK - #22

Merged
BobbyAxerol merged 180 commits into
mainfrom
dev
Sep 27, 2026
Merged

BobbyAxerol merged 180 commits into
mainfrom
dev

Conversation

@BobbyAxerol

Copy link
Copy Markdown
Owner

Release v2.2.0

PR #21 merged after all four jobs passed on d9d853f (CI run 36314967701). This release PR promotes the same tree through dev to main; no additional runtime changes.

  • Production Kafka-native serving; ten legacy SQLite reader/projector roles stopped.
  • Actual TS60 300s acceptance: 29/29 READY, zero fallback/overflow, 82,522 events.
  • SDK2.0.5 bounded off-loop fsynced cursor persistence and global shutdown recovery tested.
  • Inherited 50-client production load and endpoint latency receipts; whole stack 4.669 vCPU.
  • Certificate, exact image/config/wheel hashes, endpoint report and limitations: upgrade/evidence/releases/v2.2.0/.
  • Scoped cleanup removed three superseded images and nine cache records, no runtime restart or data deletion.

Wait for this PR CI before merge/tag. Release workflow verifies tagged SDK wheel hash and certificate/report before publishing assets. VN/DNSE stays V1; provider-discontinuous Binance 3d history remains explicitly incomplete. No alpha activation or order changes.

Phase 2 reopen: the tested cancelled-waiter fix (06b6cfe) is rolled to both
Query readers and proved on the running binary, not only in source.

Before touching them, the actual consumer showed the cost: market_data_service
logged 2,546 UNCLASSIFIED failures and 2,551 disconnects in 30 minutes, evenly
across all ten MARK_INDEX_PRICE products on both venues. The before-rollout
real-TS-identity probe measured Query 1 at 100/120 with MARK_INDEX 0/20 against
Query 2 at 120/120, 20/20.

Candidate qdl-v2-python:2.1.1-06b6cfe (sha256:fdfc4df7...) was built from git
archive on the retained a231 base with the network disabled, the R2 procedure.
Its only runtime change is the one-line waiter removal in qdl/query/lanes.py;
no manifest, catalog, contract, compose or dependency differs. 63/63 affected
tests passed inside the artifact, and the four new FIFO regressions were shown
to fail with TimeoutError on the production 43301d7 image while its other
eleven tests passed.

Rolled query_v2_1 then query_v2_2 with the R2 script logic unchanged,
ROLLED_HEALTHY, rollback 43301d7. After: both replicas 120/120 and MARK_INDEX
20/20, p95 23.2 and 30.3 ms. The consumer's disconnects fell from 67-98 a
minute to 1 a minute from 05:40, the survivors typed DATA_STALE on streams,
with zero MARK_INDEX failures and zero UNCLASSIFIED.

Also records the TS reader-boundary classification fix (TS 1193b13), not yet
deployed. Two pre-existing uncommitted typo edits in this file are left in the
working tree and are not part of this commit.
… repair

Deploys the BAR-edge native-recovery candidate and repairs the three OKX 1m
holes at 2026-09-23T00:44:00Z, proved from the venue to both Query replicas.

The candidate 2.1.1-d65b94d was deployed first because the running 9039236e
BAR image has no --observed-ms, --expected-open or --dry-run. Both images
bake a byte-identical catalog (c2fe0fe5, revision 8) and acquisition plan
(8ef05c5b, revision 17), so no checkpoint could be stranded. The service was
rendered from its own recorded chain plus an image-only overlay; a full
comparison found 16 fields with only image different.

The re-inventory is the publisher-disabled dry run, pinned with
--observed-ms 00:47:01Z and --rows 3 because 00:44Z is now outside any
240-row window from the present. It reported exactly one missing row per
binding at 00:44:00Z. The pinned apply CONVERGED with production_mutations 3,
remaining_rows 0 for each, and nothing else was written.

Both Query replicas then returned 400 FINAL rows with coverage FULL, the
repaired open exactly once, no discontinuity, duplicate or cross-mix, and
agreed on 400/400 opens with 0 mismatched rows on exact decimal identity.
Against OKX history-candles directly, OHLC, contract and base volume match
exactly for all three bars, each confirm=1.

Records one observation for the owner: the repaired bars carry
origin=VENUE_NATIVE like their live neighbours, so origin cannot tell a
recovered bar from a live one.
…rrections

Records the owner's 2026-09-23 decisions: keep the four runtime changes made
earlier today, take quota option A (raise the two existing alpha platform
identities), deploy TS 1193b13, rewrite the Phase-3 driver to the frozen
four-class target, and allow further fix-driven runtime changes under the
existing packet, rollback and cleanup discipline.

Records why option A, from measured demand and code rather than preference:
stage 50 needs 90 streams and 3,005 rpm against 360 rpm / 40 streams today;
execution_alpha shares one platform access identity across alphas, so that
identity's quota is the real production ceiling. Withdraws an earlier claim
that stage 5 does not fit: it applied the gateway's 20% reserve to identity
quota; stage 5 needs 301 rpm / 9 streams and fits.

Establishes the blast radius before any change: data_plane.py:355 checks only
the caller's own manifest revision and quota is per manifest, so the Trading
System is untouched; projector and bar edge read no quota or revision field,
so only Query x2 and Stream x2 are rebuilt and recreated, as one image.

Corrects the BAR entry's claim that the three-record repair ran under the
owner's instruction: it, and the three recreates, preceded an exact packet
approval, contrary to AGENTS rule 12. The owner has since approved keeping
them.
Adds build_target_workload_plan: the owner's four alpha classes with declared
streams and fixed request periods, stage mixes 5/20/35/50, venues interleaved
so every stage spans both identities. The offered load is an input; the plan
refuses to exist when a class product is missing or a sealed quota cannot
carry it, and never lowers a rate to fit.

Against the real manifests stage 50 is 90 streams and 50 hot req/s, 1,502 and
1,503 rpm with 45 streams per alpha identity. Quota option A is derived from
that with fixed-minute headroom: 2,400 rpm / 60 streams per identity. The
stream gateway carries 90 alpha + 40 TS streams within its 200 RPC ceiling.

11 new tests pin the owner's numbers and both refusals; 17/17 with the
unchanged preflight planner tests.
BobbyAxerol and others added 29 commits September 26, 2026 18:41
release: Kafka-native V2.2.0 and durable consumer SDK
@BobbyAxerol
BobbyAxerol merged commit 9fd8a8a into main Sep 27, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant