Skip to content

CacheLayer 4.0 security and correctness hardening - #29

Merged
abmmhasan merged 434 commits into
mainfrom
feature/improvements
Sep 29, 2026
Merged

abmmhasan merged 434 commits into
mainfrom
feature/improvements

Conversation

@abmmhasan

@abmmhasan abmmhasan commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

CacheLayer 4.0 release candidate.

Completed scope

  • Batch 1 — security and transaction containment (R01, R03, R04, R05, R09, R10)
  • Batch 2 — authenticated payload/storage identity (R02, R15, R18)
  • Batch 3 — durable invalidation protocol and cursor ownership (R06, R07)
  • Batch 4 — cache contracts, memoization, deferred lifecycle, tier coherence, Memcached TTLs (R08, R11, R12, R13, R16, R17)
  • Batch 5 — atomic counters and backend race hardening (R14 + race review)
  • Batch 6 — release gates, migration/rollback, packaging, real-backend verification
  • Batch 7 — required Runwire 2.1 integration while keeping Runwire an optional consumer dependency
  • Batch 8 — release re-audit remediation for F01–F09
  • Batch 9 — final release sweep: codec traversal symmetry, Runwire certification evidence, and release-contract documentation
  • Independent verification follow-up V01–V03:
    • accepted codec nesting depth now round-trips through the complete record envelope
    • tier mutation/promotion failures fence upper tiers on both false returns and exceptions
    • new cluster history identities cold-clear local state before runtime exposure; recreated/restored histories require coordinated rotation to a new, never-used transportIdentity
  • Final documentation wrap:
    • public cluster examples now include the required transportIdentity
    • global memoization docs reflect Runwire request ownership and concurrent no-scope bypass semantics
    • release verification and history-reset contracts are documented
    • completed internal 4.0 plan/re-audit files were removed after their release facts were transferred to public docs and this PR

4.0 contract

  • minimum PHP: 8.4
  • no 3.x backward-compatibility preservation requirement beyond required PSR/interface contracts and safe persisted-state transition guidance
  • signed records use identity-bound cl3-sig: envelopes; plain/compressed records remain cl2: / cl2-gz:
  • Runwire 2.1 integration is part of the 4.0 feature set but Runwire remains optional at install time
  • hosts own Runwire workers, supervisors, request/task scopes, and event loops
  • cluster event-log recreation/restoration/ID reuse requires a new history identity plus coordinated APCu/L1 reconciliation; arbitrary same-identity resets are intentionally unsupported

Final exact-head verification

Final PR head: f8c9f0eeaf611c18c0dfcc13de80852056314b67

  • Security & Standards #519 — passed (11/11 jobs)
    • PHP 8.4 / 8.5
    • stable / prefer-lowest QA
    • analysis, benchmarks, clean install
    • unchanged PHPForge gates
  • Release Verification #159 — passed (14/14 jobs)
    • Linux + Windows core smoke
    • clean no-dev consumers
    • independent PSR-6 / PSR-16 contracts
    • documentation warnings-as-errors
    • real Redis Cluster
    • real Scylla CQL
    • Runwire 2.1 PHP 8.4/8.5 stable/lowest consumers and persistent-worker coverage
  • Real MongoDB coverage remains in the PHPForge service matrix.
  • The preceding V01–V03 implementation head 73701d87963ac029874209b5c71957251b4fae71 also passed Security & Standards #518 / Release Verification #158.
  • Runwire certification reports 3,500 reads + 500 writes for each 4,000-operation measured workload, with 250 warmup iterations excluded from the RPM denominator.
  • 0 unresolved PR review threads.
  • Deptrac uncovered dependencies remain visible as tooling-coverage follow-up; no baseline/exclusion weakening was introduced.

Maintainer handoff

Implementation, re-audit remediation, independent verification follow-ups, public documentation, and final exact-head CI are complete.

Do not merge or tag automatically. Maintainer will merge PR #29 and create the 4.0.0 tag/release.

Comment thread src/Support/BoundedValueTraversal.php Fixed
Comment thread src/Support/BoundedValueTraversal.php Fixed
Comment thread src/Support/BoundedValueTraversal.php Fixed
Comment thread src/Support/BoundedValueTraversal.php Fixed
Comment thread src/Node/Connection/NodeSqliteConnection.php Fixed
Comment thread src/Support/OptionalCassandra.php Fixed
Comment thread src/Support/OptionalCassandra.php Fixed
Comment thread src/Cache/Adapter/CachePayloadCodec.php Fixed
Comment thread src/Cache/Adapter/SharedMemoryCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/SharedMemoryCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/SharedMemoryCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/SharedMemoryCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/SharedMemoryCacheAdapter.php Fixed
Comment thread src/Cluster/Cursor/SqliteCursorStore.php Fixed
Comment thread src/Cluster/Transport/Pdo/PdoInvalidationTransport.php Fixed
Comment thread src/Cluster/ClusterCache.php Fixed
Comment thread src/Cluster/Cursor/SqliteCursorStore.php Fixed
Comment thread src/Cache/Adapter/CachePayloadCodec.php Fixed
Comment thread src/Cache/Adapter/CachePayloadCodec.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Adapter/CachePayloadCodec.php Fixed
Comment thread src/Cache/Adapter/CachePayloadCodec.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Adapter/AbstractCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/AbstractCacheAdapter.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Cache.php Fixed
Comment thread src/Cache/Adapter/MemcachedCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/MemcachedCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/MemcachedCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/MemcachedCacheAdapter.php Fixed
Comment thread src/Cache/Adapter/MemcachedCacheAdapter.php Fixed
…e tiers on failure

- Update cluster cache creation to cold-clear unseen cursor scopes before returning the runtime ✨
- Fix tiered cache adapter to apply monotonic coherence fences on false returns and exceptions 🐛
- Align payload codec deserialization max depth with the value traversal limit 🎨
- Update cluster recovery and cursor documentation with coordinated identity rotation instructions 📝
@abmmhasan
abmmhasan marked this pull request as ready for review September 29, 2026 06:49
- Add push triggers for version tags in security standards workflow 👷
- Add conditional release workflow job for tagged commits 🚀
- Cut GitHub Actions workflow for PHPForge Pint diagnostic 🔥
@abmmhasan
abmmhasan merged commit 58ae96d into main Sep 29, 2026
28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants