Owner clarification 2026-10-03: the central purpose is cross-model composition in one database for AI agents. DatabaseComposition and ADR-067 add bounded server-derived queue links -> canonical entities -> graph edges and graph -> queued actions inside the existing atomic command, reached through the same SQL CALL/catalog. This preserves the one-statement/one-canonical-operation boundary while making that operation compose source reads and effects. Full declarative sources/JOIN/ DML and native SQL client protocol remain required under ADR-065.
Owner direction2026-10-02: one server/database supports all models and their links; SQL is central and performance has first priority. This is not a request for a new single physical file. ADR-054, ADR-055, acceptance and plan define the current delivery contract.
| Model | Existing canonical behavior | Current SQL / relational source stage | Remaining product boundary |
|---|---|---|---|
| Documents | CRUD/PATCH, unique/composite indexes, atomic receipts | Q1 SELECT; CALL canonical read/commit | Distributed/full declarative operators |
| Relational rows | New optional schema on Collection entity storage | Scalar types, primary/id equality, nonnullable/closed rows, native partition-local unique indexes; Q1 SELECT/CALL mutation | JOIN, FK/check/default/cascade, migration jobs and dedicated performance proof |
| Graph | Canonical EntityRef endpoints, bounded authorized BFS | CALL existing traversal/atomic edge commands; table rows remain endpoints | Declarative graph source/ranked fusion/cross-partition traversal |
| Vectors/text/hybrid | Revision-matching vectors, exact ranking/BM25/RRF, bounded authorization | CALL existing search/vector commands; table rows remain vector subjects | Fused SQL SEARCH operator, ANN/global ranking and measured acceleration |
| Events | Revision/generation/EventId append, bounded projected replay | CALL existing stream/event commands/read | Declarative EVENTS source and advanced schema/retention |
| Queues/topics | Fenced delivery, inbox, scheduling, group/checkpoint state | CALL existing inspect/receive/complete/process; reads never claim implicitly | Declarative queue views retain inspection rights; generic UPDATE internal state forbidden |
| Time series | UTC samples, latest/raw aggregates/dense windows | CALL existing typed reads/append | Declarative time-series SQL and qualified rollups/retention |
| Files/blobs | Canonical staged chunks, publish CAS, integrity/partial reads | CALL all ten existing operations; typed SDK blob surface joins HTTP/MCP | Cross-feature blob mutation batch/outbox and cluster-cut backup contract |
SQL invocation syntax (version1):
SELECT * FROM agents WHERE id = @id LIMIT 1;
CALL keyload_search_execute(@arguments);
CALL keyload_documents_commit(@arguments);
CALL keyload_blobs_read_range(@arguments);Use the actual discovered canonical operation names. CALL's one named object
parameter is an argument envelope ({"request":...}, optional header commandId,
or {} for no-body reads); SELECT parameters remain Q1 scalars. Exactly one
statement compiles to exactly one canonical operation. SQL cannot call the SQL
adapter recursively, assert roles, replace IDs or bypass leases/revisions.
Results retain their actual canonical JSON shapes and safe domain errors.
The SQL wrapper reserves heavy-read DATA admission for every call. Direct control routes retain their own reserved lane; SQL control CALL can be rejected during DATA saturation. MCP hints therefore conservatively allow writes/consumption. This stage does not claim full vendor SQL compatibility or arbitrary model JOIN.
Pre-change main SHA b21c9eeaed701b7b2e267d4690fb3ac302c06c17 had queued run37065200835. Required baseline dispatched after planning: run37066160501 was cancelled before any job executed. The original37065200835 later completed failure: all three OS build/format/governance/unit/scalar/recovery jobs and analyzer rules passed; RF3 passed45/46 and comparisons2/4. The remaining snapshot/catch-up failure returned a generic recovery error. Node logs also show Orleans directory/placement connection rejection to a stopped node; the request dispatch phase and exact exception were not retained, so a causal attribution remains unproven. Comparisons lifecycle remained Waiting, and two retained StreamAppend smoke cases failed with unsupported ReadEventAsync. The root plan tracks exact jobs and cases. Exact new-source qualification is pending; no test count or speed result is inferred from authored cases, development builds or static governance.
The new RF3 sources cover genuine receive/ACK stable identities and forged/foreign token rejection, pre-cancelled SDK/MCP SELECT followed by healthy reads, and actual insufficient DATA byte admission on all three nodes with direct-control same-ID progress. They do not establish in-flight server cancellation or concurrent lane saturation; those qualifiers remain open until separately exercised.
The prior completed run37063262333 failed RF3 snapshot/catch-up and two TimeSeries flows, Windows snapshot interruption and comparison startup. Its catalog cut equality failure was repaired in later source. Root plan tracks each actual failure; current runs are the authority, not historical fixes.
Native equality extraction now targets equivalent operand orientations, avoiding full-scan requirements for reversed literal/parameter equality. Typed rows check one final image, with raw patch scalar preflight before decimal canonicalization. CALL grammar and bound target envelopes are rejected before gateway invocation. SELECT/EXPLAIN preserve the canonical Q1 actor's single grammar validation before any scan or effect, avoiding a second parse in the adapter. No extra SQL executor/storage engine/full dataset materialization is introduced. SIMD remains Search's portable .NET intrinsic validation stage; vector scoring grouping is unchanged. Dedicated SQL/table/CALL workload and database-node CPU/RAM/GC/contention/backlog measurements are still required alongside existing client-process samples. Numeric coverage, endurance and power-loss gates remain open; this work does not establish production readiness or performance superiority.
The first delivered candidate6cfdadf38 / 37068157832 failed builds on new enum CA1720 identifiers; analyzer-rule tests passed. Candidate b3f93431a / 37068458582 fixed those identifiers but exposed SDK null guards, aggregate type size and query nesting. Source repairs are joined without suppression: typed blob extensions share one internal transport, and equality extraction uses early iterator exits. Both failed before product runtime tests, so neither qualifies behavior.
The baseline transport finding also has a source repair under ADR-036/REQ-ROUTE-009: initial native Orleans/timeout RPC faults map to read OwnershipLost or uncertain command UnknownWriteOutcome. Genuine domain RecoveryRequired and caller cancellation retain their contracts; no extra dispatch/retry is introduced. Independent join review is complete; the next exact-SHA CI is the authority.
Candidateaf9e0d16b / 37069241980 stopped on one redundant namespace import before product tests. Candidate9f3acf5b9 / 37069574976 removes it and repeats complete qualification; results remain pending.
Candidate9f3acf5b9 passed Server/ComparisonTests compilation and reached comparison tests, but IntegrationTests/UnitTests compilation failed on CA1822/CA2000, missing TUnit enum namespace, repeated-format caching, synchronous cancellation and redundant imports. Bounded source repairs preserve the existing assertions and are awaiting a fresh complete CI; RF3 and units did not execute in that candidate.
Exact candidate3a744d19a / 37070004864 compiled the complete solution on all three OS and passed analyzer-rule tests. Genuine RF3 passed59/60 without skips, including all14 new SQL/relational model, authorization, atomicity, delivery, blob, cancellation and admission scenarios. The retained-replica catch-up case still returned server Cancelled; actual actor-token classification is being repaired without broadening retry acceptance. Linux recovery passed136/136; Windows135/136 failed receipt writing after completed atomic assertions/cleanup. Formatter failed3 exact source-layout/import findings, so unit/scalar suites did not execute. Comparisons repeat the exact baseline lifecycle/unsupported StreamRead caller failures (2/4 tests); no speed conclusion follows. See the source-bound receipt; complete new-SHA qualification remains required.