EN · ORIGINAL REPOSITORY DOCUMENT
Implementation status
Original English text. Commands and evidence apply to the revision and environment stated in the document.
IMPLEMENTATION-STATUS.md
On this page
Modernization acceptance inventory
Current candidate: 1.26.0-rc.1, v2 namespace, PHP 8.2+/PhpRedis 6+.
Current workflow (2026-10-05): the owner has now explicitly requested code changes without running tests. Runtime, lint, static analysis and browser checks are deferred; no new passing result is inferred from source inspection. Earlier TTL/WordPress/Redis/minimum-runtime/concurrency/commerce results remain historical evidence for the exact revisions in RELEASE-COMPLETION.md. The subsequent CDN, reset handling and static-contract source edits have not been executed. Optional Query Monitor analysis declarations and guarded Members calls have since been added in source; whole-project analysis has not been rerun. Query Monitor now handles missing/replaced collectors and labels retained command data/omissions. Counter/remember stress, matched HTTP performance, backend/migration cases and operator-controlled rollout remain open.
The approved wp redis profile <url> method is implemented in source: one real
same-site anonymous GET, a five-minute HMAC ticket consumed through captured-primary
WATCH, early request-only 100% collection, actual site confirmation and a bounded
signed Redis result consumed by CLI. Default 2,000 events, maximum 10,000/2 MiB;
table/JSON expose omissions, logical size coverage and separate API/HTTP timing.
Forced samples bypass hourly Insights persistence. Response bodies stream to an
owned temporary file and cleanup is reported. HTTP-PROFILE.md records scope,
failover/expiry, late shutdown, page-cache and privacy limits, plus deferred tests.
A full signed profiling GET acceptance remains pending; shared observer syntax/static and regression checks have since run as recorded in RELEASE-COMPLETION.md.
The HTTP profile now also records bounded confirmed-write TTL evidence from the
existing write path: requested seconds, capped/sent ranges and nine buckets, with
a maximum of 256 inspected replies per API call. Runtime-only and preserved
counter expiry are explicit. Existing hourly hashes, cache semantics and Redis
command counts are unchanged by this observation; actual overhead is unmeasured.
The owner explicitly approved §9 on 2026-10-05. The separate opt-in TTL history
store now has source implementation: request-wide 256 replies/64 rows,
site/hour 64 named groups + other/64 KiB, captured-primary WATCH with finite EX
and absolute EXPIREAT, 192-hour retention, bounded completed-hour reporting and
explicit CLI/REST/admin loading. Existing hourly counters remain unchanged.
See TTL-HISTORY.md for passing regression, real Redis, REST and browser results;
extended backend/failure parity and overhead acceptance remain open.
The optional ttl_jitter setting defaults to zero and accepts integer percentages
from zero to 100 (including valid integer strings through the existing configuration
parser). It shortens effective positive TTLs only after the maximum/query limits,
uses integer arithmetic without overflow and never creates a zero TTL. Single and
bulk writes plus split alloptions share the policy; bulk keys are sampled separately.
Effective zero/one-second TTLs, counter mutation expiry, nonpersistent groups and
internal metadata/prefetch retention keep their existing behavior. Configuration
export/diagnostics include the percentage. Existing keys are not rewritten; turning
the option off does not undo earlier expiry. Jitter is not stampede protection;
the separate recomputation/remember API now has its own approved contract below.
Final validation must cover configuration boundaries, integer limits, NX/XX,
zero/one/positive TTL, maximum/query caps, independent bulk draws, split alloptions,
counter retention, both real backends and five-repeat off/on performance comparison.
The owner approved the separate ocp_remember() API. Source implementation adds
default-empty stampede_groups, bounded leases/waiting on the existing captured
primary transaction interface and conditional publication after at most one
callback invocation outside transactions. Configured mutations use a confirmed
lease cancellation before their watched value mutation; bulk operations use that
per-key path. Group/site/namespace cleanup and stale-query pruning cancel old
computations before scanning data. Cache conflicts do not replay mutations;
unconfirmed results are evicted from local memory. Ordinary remember/sear helpers
retain their acquisition/wait behavior, with the false-hit bug fixed. Nonpersistent
groups retain runtime caching. Full details, Redis 6.0.9+ lease requirements,
uniform-worker configuration, partial EXEC/failover limits and deferred final
validation are recorded in STAMPEDE.md. No syntax/runtime/concurrency or performance
test was executed for this feature; real backend parity is not established.
Cluster and cache-enabled Relay now retain up to eight direct transaction sockets per owning connection object, with oldest-idle eviction. Reuse requires unchanged connection settings and clean, unchanged native database/codec/retry/timeout state. Unsupported state inspection keeps the former one-operation socket lifetime. Exceptions, error-counter growth or uncertain cleanup retire the socket. Cluster still discovers CLUSTER SLOTS before every transaction; Relay conditional reads still bypass its local value cache. Neither path replays a transaction. Observation deltas avoid counting earlier operations twice; a new lease clears lastCommand. Initial codec setup now rejects failed native option changes and closes the client. Final tests must cover reuse/eviction, configuration changes, conflicts and error cleanup, metrics, unavailable capabilities, real Relay/Cluster failover/resharding, and five-repeat connection-cost/performance comparisons. No speedup is established.
Drop-in file mutations now require nonempty product-name and URI headers matching the bundled stub. Legacy upstream compatibility and the compatibility filter do not grant ownership. Protected files are explained in management/health screens; CLI disable also refuses to remove them. CLI enable –force retains its explicit replacement behavior and warns on unowned files. It does not create a backup. The filesystem guard refreshes cached identity, but is not an atomic compare-and-swap against other processes or a cryptographic integrity check. Existing drop-in and metadata fixtures need ownership cases before the final test phase; no prior passing report validates these changes.
The drop-in migration wizard is now implemented in source using the existing settings pages and WordPress filesystem API. It requires core POST nonces, cache management and plugin-installation capabilities, plus a network super administrator on multisite. Preview/backup/install bind both current and replacement fingerprints; the download issues a ten-minute, user/network-bound content-free confirmation. Backups contain signed, unencrypted PHP bytes (or an absent-file record), bound to the content path, network URL and auth signing key. Restore accepts the exact recorded replacement or an already-restored state, and never flushes Redis or rewrites provider configuration. The operator must prepare the fresh rollback namespace. Staging/verification/cleanup use WordPress’s transport; concurrent external writers and transport move/copy failures do not have an atomic rollback guarantee. See DROPIN-MIGRATION.md for limits and manual recovery. Core nonce and capability checks, download/upload flows, multisite, tampered/stale/oversized/link cases and actual filesystem/OPcache failures remain final-phase validation gates.
withoutMutations() now captures the physical client’s actual serializer and
compression settings, validates option changes, restores both options despite
an individual cleanup failure, attempts to close an uncertain client and retains
the first error. Replicated scopes unwind the originally captured nodes, including
partial setup and nested calls. Final verification must cover PhpRedis/Relay,
replica setup/cleanup failures, callback/close error precedence, nested calls and
Sentinel replacement during a raw callback. Active raw scopes now enroll each
discovered primary/replica before it is exposed to callers. Nested scopes enroll
new nodes from outermost to innermost and restore each captured physical client,
including retired nodes, even after a setup/callback/cleanup error. Direct pinned
Cluster/Relay transactions inherit their owner’s raw scope and restore normal
options before a socket can reenter the pool. This closes the source-level gap
where replacement/direct sockets used normal codecs inside a raw callback.
Runtime evidence remains pending: cover read retry after rediscovery, a callback
that catches a write failure and continues on the new primary, direct primary
access, nested discovery, duplicate node references, raw/normal pooled operations,
and native option failures. The Sentinel read/write replay policies are unchanged.
Historical validation below applies to its recorded revisions. The earlier error-buffer reporting update passed 38 PHP unit regression cases and 152 assertions on PHP 8.3.0, including 24 focused bounds/reporting checks. Ten PHP source/template/test files passed syntax checks. The seven-file PHPStan scope reports eight findings in unchanged API/diagnostic code; an immutable-source comparison reproduces all eight on 42f7acc, with no new findings. This is not a clean static-analysis result. The real WordPress evidence below predates this reporting update and does not validate its behavior in a live admin request.
This file records source implementation and its verification limits. Following the owner’s later authorization to run PHP tests after these updates, the local PHP 8.3.0/PHPUnit 9.6.37 suite passed 37 regression cases and 148 assertions on 2026-10-04. One real WordPress/Docker feature test was initially skipped. The owner then authorized the real WordPress run. A preceding fresh Docker fixture passed all seven integration scripts and the lifecycle suite, including that skipped test’s contracts.php scenario. All 37 regression cases also passed inside PHP 8.3.35. The fixture used WordPress 6.8.3, WooCommerce 10.2.2, PhpRedis 6.1.0 and Redis 7.4.2. Installed runtime/drop-in identity was verified against 187 source files. This establishes the recorded standalone behavior, not Relay or production acceptance. Browser, heavy concurrency, scale and performance gates remain open. Prior reports retain their original revision scope.
| Plan requirement | Current source/artifact | Acceptance still needed |
|---|---|---|
| Attack-plan drop-in conflict protection and migration | Separate product ownership; guarded admin/automatic writes and CLI disable; explicit CLI –force retained; preview, signed backup and guarded install/restore wizard | Ownership/filter/legacy/link cases; real core nonce/capability and multisite checks; browser backup/restore; stale/tampered/oversized backup and filesystem/OPcache failure cases |
| Git baseline and rollback | baseline/pre-modernization; MIGRATION-v2.md | Target staging rollback rehearsal using a fresh prefix |
| Composer tooling and compatible base | composer.lock, phpstan.neon.dist, PHP 8.2 headers/guards; PHP 8.3 regression suite passed | Minimum PHP 8.2/PhpRedis 6.0 environment and real backend contracts |
| Repeatable WordPress/WooCommerce/Redis environment | Fresh ocp-check-bf3a22fd1247 build/setup, source/drop-in verification, seven real contracts and lifecycle passed; owned containers/network/volumes removed | Other supported runtime versions and topology/acceptance gates |
| Six cold/warm scenarios, p50/p95, traffic, memory and SQL | benchmark.py, metrics.php, identity.php, provenance.py | Five repetitions and baseline/candidate reports; no current reports exist |
| Five-percent warm regression gate | compare.py validates raw samples, source provenance, fixture/config/harness parity | Real comparison passes on the exact release candidate |
| Internal responsibility separation | Keyspace, ExpirationPolicy, AllOptionsHash, KeyCleaner, PrefetchStore | Contract parity across supported backend/runtime combinations |
| Primary-bound transaction/no replay | TransactionalConnectionInterface, PhpRedis/Relay/Cluster transaction paths; first-error preservation and uncertain cleanup rejection covered with deterministic clients | Real failover, resharding, timeout, ACL and partial-EXEC behavior |
| Atomic persistent counters (owner approved) | Watched GET/arithmetic/conditional SET, CounterExpiration, failure-memory invalidation; real standalone counter script passed 148 checks, including interleaved writes and TTL | Broad concurrency, lost replies, INFO/PTTL ACL failures, other Redis versions and overhead; legacy relative PX has deadline drift |
| Sentinel ordinary writes without replay (owner approved) | Native retry suppression/restoration, first-error preservation, discovery for the next call; routing/native-policy/failover fixture sources | Real lost replies, failure recovery, read-retry compatibility and licensed Relay |
| Lossless v2 key isolation | Keyspace and adapted list/flush/prefetch/prune/invalidation consumers; key-isolation regression and real switch_to_blog isolation passed | Full backend/runtime matrix |
| Cold migration/explicit legacy cleanup | v2-only reads, scoped lifecycle flush, cleanup-legacy | Legacy records untouched; rollback never reads stale pre-v2 keys |
| Optimistic alloptions NX/XX/TTL/field merging | AllOptionsHash, syncAllOptions, bulk-memory publication; precondition regressions and 40 real bulk ADD checks passed with split/negative-cache modes off/on | At least 20 processes: add, replace, independent updates, conflict results and memory invalidation; real ACL/read-error cases |
| Incremental cleanup and 500-key commands | KeyCleaner, streaming pruneQueriesCount, SCAN default; validate zero/positive deletion counts without coercing failed replies | 100k/1m keys, five repetitions, bounded memory and deletion scope |
| Legacy pruneQueries API | Return-array signature retained; internal callers use count path | External callers still allocate their explicitly requested result list |
| Prefetch bounds and site ownership | 3600-second TTL, 256 keys, 1024 request records; membership-verified eviction, repair of detected metadata inconsistencies, failed-read guards and no reads after budget exhaustion; regression and 50 real Redis checks passed | Real concurrent caps, server eviction, failure injection, expiry and multi-site transitions; added read overhead |
| Log and command limits | ArrayLogger/log_limit; separate request-wide omitted-error counter, cache info, performance/overview widgets, diagnostics and Site Health totals; 24 focused checks and 38 unit cases passed | Real WordPress admin rendering, browser behavior and sustained production requests |
| CLI child-only password handling | REDISCLI_AUTH, CLI 5+ requirement, named profile resolution | Process argument/env inspection on supported systems |
| Performance panel and history truthfulness | PerformanceSnapshot, existing chart library, unified wait source | Browser behavior, analytics off/on and failed-command metrics |
| Read-only cleanup preview | CacheScope, bounded scan, fingerprints, explicit site/global/network/database labels and effective method/atomicity | Capability/nonce handling, delegated site admin, global/all-sites scope and failure responses |
| CLI doctor | JSON/table reports, nonzero errors, TLS/capability/drop-in/config facts; structured connection/client/header failure regression passed without exposing exception details | Real standalone/Sentinel/Cluster/TLS/Relay diagnostics |
| Attack-plan CLI why | Metadata-only wp redis why, live scope/policy/runtime flags, captured-primary TYPE/PTTL/hash-marker/lease snapshot, hypothetical TTL explanation, JSON/table and explicit error/conflict codes | Final CLI/help/format/input/side-effect/error contracts; real PhpRedis/Relay/Sentinel/Cluster/TLS; no historical writer attribution is claimed; KEY-DIAGNOSTICS.md |
| Attack-plan Cache Insights | 2% sampling, bounded caller/group counters and logical payload coverage, 256 named site/hour pairs on the owner-approved WATCH path, four-hour reads and 1,024-pair report merge; REST, admin charts/tables, CLI and six review rules | Source review only. Final PHP/backend/concurrency/permissions/browser/privacy tests and five-repeat 0%/2%/100% overhead comparisons; partial EXEC/expiry/flush and measurement limits in CACHE-INSIGHTS.md |
| Attack-plan HTTP profile | Signed one-use same-site anonymous GET; forced request-only sample, bounded events, actual-site confirmation and signed primary-side Redis handoff; bounded confirmed-write TTL evidence; CLI JSON/table | Source review only; real HTTP/bootstrap/response, authorization/replay/expiry/ambiguity, multisite, limits/privacy, transport/cleanup, all backends and overhead tests in HTTP-PROFILE.md |
| Attack-plan TTL suggestion mode: evidence layer | Completed-hour group classification across retained callers; current policy context, bounded conditional reviews and quality guards; admin/REST/JSON and CLI –ttl-review | Source review only; final boundary, grouping, scope, rendering and zero-extra-command checks. Actual TTL/reuse/expiry/freshness measurements and numeric TTL recommendation remain open; adaptive TTL is not complete |
| Historical TTL write evidence (§9 approved) | Separate opt-in ttl-v1 bounded JSON, shared request budget, confirmed-write histograms, explicit CLI/REST/admin history | TTL-HISTORY.md final regression/Redis/browser/permissions/backend/overhead checks; no numeric optimum or freshness claim |
| Attack-plan key-explosion detector | Opt-in sampled HMAC identity/patterns, fixed HLL slots, explicit bounded/fenced SCAN, scoped admin/REST/CLI and approximate comparison | Source review only; final backend/ACL/expiry/partial-EXEC/concurrency/isolation/privacy/overhead acceptance in KEY-GROWTH.md; no production acceptance |
| Attack-plan configuration presets | Owner-approved four candidates, bounded portable manifests, explicit precedence, exact group TTL caps, CLI import/export/diff and current-site REST/admin preview; shared key/TTL diagnostics | Source review only; schema, configuration/TTL/backend, CLI, permission/browser and five-repeat performance gates in CONFIGURATION-PROFILES.md; no production acceptance |
| WooCommerce isolation and invalidation | Real product invalidation contract passed; separate run.py –commerce source covers authenticated sessions, BACS checkout, order ownership and WooCommerce/SQL stock parity | Execute –commerce; the product contract does not establish checkout/customer isolation, external gateways, shipping/tax or all storage modes |
| Distribution | Deterministic immutable-commit package.py and changelog | Candidate ZIP manifest, installed-version match, staging/pilot/network acceptance |
Remaining implementation and evidence work
-
The new
wp redis whysource probes one scoped key without reading its value, retries or a keyspace scan. Existing transaction routing and native type constants are reused. TTL explanation shares the existing jitter reduction arithmetic and draws no random number. Syntax/static/runtime verification has not run for this change. Component attribution and the Insights screen/rules now have source implementation under the separately approved bounded storage contract (§5 of REFACTOR-DECISIONS.md); their runtime and performance acceptance remains open.wp redis profilenow has source implementation under the separately approved contract in §6 and HTTP-PROFILE.md. TTL/persistence classification and read-only evidence review now use the existing completed-hour counters without changing storage. Exact TTL/reuse/expiry/freshness measurement and numeric TTL proposals remain phase-two development work; the evidence layer does not complete adaptive TTL. None of these new source changes have runtime or performance acceptance. -
Key-explosion detection now has source implementation under the explicitly approved HLL/fingerprint/SCAN contract in REFACTOR-DECISIONS.md §7. Collection defaults off. HMAC observations, fixed site/hour slots, primary-side HLLs, fenced explicit scans, bounded history, scoped REST/admin/CLI output and opt-in doctor guidance are described in KEY-GROWTH.md. Source review only; no PHP, static, runtime, browser or performance checks have run for this change. Missing, partial, incompatible and approximate results are explicit; no automatic scan, cleanup, configuration change or production acceptance. Source follow-up: hourly JSON and scan-history writes now also confirm EXPIREAT at the approved absolute retention deadline. SET keeps its finite EX fallback; both replies are required. This removes relative-TTL transport/queue drift on successful publication, adds one expiry command per metadata write, and does not promise rollback or a durable marker for partial expiry failure. Delay/ACL/ clock-skew checks remain deferred in KEY-GROWTH.md.
-
The owner approved REFACTOR-DECISIONS.md §8 on 2026-10-05. Configuration profiles now have source implementation: preserved early config, four built-ins/custom manifest data, explicit-field precedence, exact group TTL caps, bounded local import and JSON export, CLI differences and read-only current-site management previews. Existing bootstrap groups and counter TTL retention remain. No live configuration file was changed. CONFIGURATION-PROFILES.md records semantics, rollback and final schema/TTL/CLI/REST/backend/browser/performance gates. Tests have not run; source completion does not grant phase-two/production acceptance.
-
Dedicated 20-process alloptions and 100k/1m cleanup sources are connected to the explicit run.py –acceptance option, with installed-source verification. They have not run. A separate –commerce source scenario now submits two real HTTP checkouts and checks session/order/stock isolation; it is also unexecuted.
-
Local regression coverage includes scopes, budgets, new connection capabilities, cleanup failure precedence and request-memory invalidation. Old bulk-key/counter fixtures now follow the approved v2/transaction contracts. An IPv6 seed port bug found during the run was fixed. Eleven changed PHP files passed syntax checks; nine connection/configuration files passed PHPStan level 5 with zero errors.
-
Equal-sized prefetch record/index containers can contain different members after a partial EXEC failure. Eviction now verifies the space it needs and repairs detected mismatches in that site’s metadata. Regression coverage includes a partially applied EXEC and fresh/stale native errors. Real Redis passed 50 checks with seeded inconsistent metadata, serialization, TTL and site/data isolation; it did not inject a real server EXEC failure. Three PHP files passed syntax checks and three related production files passed PHPStan level 5. Extra reads have not been benchmarked; failed EXEC still has no rollback guarantee.
-
Freeze a new review ZIP from the final immutable source after remaining acceptance.
-
The eight errors in log-bounds-static-comparison.json describe its historical baseline/candidate, not the current checkout. Source inspection on 2026-10-05 found the callable multisite initialization guard in api.php, the Basename bootstrap/dynamic-constant setup in phpstan.neon.dist and tests/PHPStan/constants.php, and the single-instance Relay adaptive-cache guard and removed obsolete ignores in Diagnostics.php already present. Do not implement those fixes a second time. A fresh final-stage static run is still required to establish the current result; source inspection and historical reports do not verify real Relay behavior.
-
Cursor-based management group listing remains a proposal in REFACTOR-DECISIONS.md; the existing full-list behavior has not been changed without separate approval.
-
Local PHP regressions and the default fresh WordPress integration run are now authorized and completed. Topology/TLS, browser, heavy load and performance gates remain open. Licensed Relay behavior is explicitly unverified.
-
No new frontend framework, hosted CI provider, update server, automatic optimizer, production deployment or external telemetry is introduced in this release.
Local reports are under build/modernization: phpunit-final.txt/phpunit-final.xml, transaction-cleanup-syntax.json and transaction-cleanup-static.json. Counts and changed PHP source hashes are recorded in tests/integration/status.json. These results cover their stated scope only. Error-buffer evidence is in log-bounds-unit.xml, log-bounds-syntax.json, log-bounds-static.json and log-bounds-static-comparison.json; its source hashes and limits are under log_bounds_validation in status.json. The real WordPress evidence is in tests/integration/results/ocp-check-bf3a22fd1247/run.json; its digest, tested source hashes and summary are recorded under prefetch_membership_validation in status.json. The earlier ocp-check-cab5b3ed7a90 evidence retains its original scope. The latest run tested the checkout based on 5055471 plus the prefetch fix, not an exported ZIP. A commit/ZIP records a reviewable checkpoint, not successful production acceptance.