Private release previewNo live purchasesRelease details ↗

EN · ORIGINAL REPOSITORY DOCUMENT

Implementation status

Original English text. Commands and evidence apply to the revision and environment stated in the document.

IMPLEMENTATION-STATUS.md

On this page

Modernization acceptance inventory

Current candidate: 1.26.0-rc.1, v2 namespace, PHP 8.2+/PhpRedis 6+.

Current workflow (2026-10-05): the owner has now explicitly requested code changes without running tests. Runtime, lint, static analysis and browser checks are deferred; no new passing result is inferred from source inspection. Earlier TTL/WordPress/Redis/minimum-runtime/concurrency/commerce results remain historical evidence for the exact revisions in RELEASE-COMPLETION.md. The subsequent CDN, reset handling and static-contract source edits have not been executed. Optional Query Monitor analysis declarations and guarded Members calls have since been added in source; whole-project analysis has not been rerun. Query Monitor now handles missing/replaced collectors and labels retained command data/omissions. Counter/remember stress, matched HTTP performance, backend/migration cases and operator-controlled rollout remain open.

The approved wp redis profile <url> method is implemented in source: one real same-site anonymous GET, a five-minute HMAC ticket consumed through captured-primary WATCH, early request-only 100% collection, actual site confirmation and a bounded signed Redis result consumed by CLI. Default 2,000 events, maximum 10,000/2 MiB; table/JSON expose omissions, logical size coverage and separate API/HTTP timing. Forced samples bypass hourly Insights persistence. Response bodies stream to an owned temporary file and cleanup is reported. HTTP-PROFILE.md records scope, failover/expiry, late shutdown, page-cache and privacy limits, plus deferred tests. A full signed profiling GET acceptance remains pending; shared observer syntax/static and regression checks have since run as recorded in RELEASE-COMPLETION.md. The HTTP profile now also records bounded confirmed-write TTL evidence from the existing write path: requested seconds, capped/sent ranges and nine buckets, with a maximum of 256 inspected replies per API call. Runtime-only and preserved counter expiry are explicit. Existing hourly hashes, cache semantics and Redis command counts are unchanged by this observation; actual overhead is unmeasured. The owner explicitly approved §9 on 2026-10-05. The separate opt-in TTL history store now has source implementation: request-wide 256 replies/64 rows, site/hour 64 named groups + other/64 KiB, captured-primary WATCH with finite EX and absolute EXPIREAT, 192-hour retention, bounded completed-hour reporting and explicit CLI/REST/admin loading. Existing hourly counters remain unchanged. See TTL-HISTORY.md for passing regression, real Redis, REST and browser results; extended backend/failure parity and overhead acceptance remain open.

The optional ttl_jitter setting defaults to zero and accepts integer percentages from zero to 100 (including valid integer strings through the existing configuration parser). It shortens effective positive TTLs only after the maximum/query limits, uses integer arithmetic without overflow and never creates a zero TTL. Single and bulk writes plus split alloptions share the policy; bulk keys are sampled separately. Effective zero/one-second TTLs, counter mutation expiry, nonpersistent groups and internal metadata/prefetch retention keep their existing behavior. Configuration export/diagnostics include the percentage. Existing keys are not rewritten; turning the option off does not undo earlier expiry. Jitter is not stampede protection; the separate recomputation/remember API now has its own approved contract below. Final validation must cover configuration boundaries, integer limits, NX/XX, zero/one/positive TTL, maximum/query caps, independent bulk draws, split alloptions, counter retention, both real backends and five-repeat off/on performance comparison.

The owner approved the separate ocp_remember() API. Source implementation adds default-empty stampede_groups, bounded leases/waiting on the existing captured primary transaction interface and conditional publication after at most one callback invocation outside transactions. Configured mutations use a confirmed lease cancellation before their watched value mutation; bulk operations use that per-key path. Group/site/namespace cleanup and stale-query pruning cancel old computations before scanning data. Cache conflicts do not replay mutations; unconfirmed results are evicted from local memory. Ordinary remember/sear helpers retain their acquisition/wait behavior, with the false-hit bug fixed. Nonpersistent groups retain runtime caching. Full details, Redis 6.0.9+ lease requirements, uniform-worker configuration, partial EXEC/failover limits and deferred final validation are recorded in STAMPEDE.md. No syntax/runtime/concurrency or performance test was executed for this feature; real backend parity is not established.

Cluster and cache-enabled Relay now retain up to eight direct transaction sockets per owning connection object, with oldest-idle eviction. Reuse requires unchanged connection settings and clean, unchanged native database/codec/retry/timeout state. Unsupported state inspection keeps the former one-operation socket lifetime. Exceptions, error-counter growth or uncertain cleanup retire the socket. Cluster still discovers CLUSTER SLOTS before every transaction; Relay conditional reads still bypass its local value cache. Neither path replays a transaction. Observation deltas avoid counting earlier operations twice; a new lease clears lastCommand. Initial codec setup now rejects failed native option changes and closes the client. Final tests must cover reuse/eviction, configuration changes, conflicts and error cleanup, metrics, unavailable capabilities, real Relay/Cluster failover/resharding, and five-repeat connection-cost/performance comparisons. No speedup is established.

Drop-in file mutations now require nonempty product-name and URI headers matching the bundled stub. Legacy upstream compatibility and the compatibility filter do not grant ownership. Protected files are explained in management/health screens; CLI disable also refuses to remove them. CLI enable –force retains its explicit replacement behavior and warns on unowned files. It does not create a backup. The filesystem guard refreshes cached identity, but is not an atomic compare-and-swap against other processes or a cryptographic integrity check. Existing drop-in and metadata fixtures need ownership cases before the final test phase; no prior passing report validates these changes.

The drop-in migration wizard is now implemented in source using the existing settings pages and WordPress filesystem API. It requires core POST nonces, cache management and plugin-installation capabilities, plus a network super administrator on multisite. Preview/backup/install bind both current and replacement fingerprints; the download issues a ten-minute, user/network-bound content-free confirmation. Backups contain signed, unencrypted PHP bytes (or an absent-file record), bound to the content path, network URL and auth signing key. Restore accepts the exact recorded replacement or an already-restored state, and never flushes Redis or rewrites provider configuration. The operator must prepare the fresh rollback namespace. Staging/verification/cleanup use WordPress’s transport; concurrent external writers and transport move/copy failures do not have an atomic rollback guarantee. See DROPIN-MIGRATION.md for limits and manual recovery. Core nonce and capability checks, download/upload flows, multisite, tampered/stale/oversized/link cases and actual filesystem/OPcache failures remain final-phase validation gates.

withoutMutations() now captures the physical client’s actual serializer and compression settings, validates option changes, restores both options despite an individual cleanup failure, attempts to close an uncertain client and retains the first error. Replicated scopes unwind the originally captured nodes, including partial setup and nested calls. Final verification must cover PhpRedis/Relay, replica setup/cleanup failures, callback/close error precedence, nested calls and Sentinel replacement during a raw callback. Active raw scopes now enroll each discovered primary/replica before it is exposed to callers. Nested scopes enroll new nodes from outermost to innermost and restore each captured physical client, including retired nodes, even after a setup/callback/cleanup error. Direct pinned Cluster/Relay transactions inherit their owner’s raw scope and restore normal options before a socket can reenter the pool. This closes the source-level gap where replacement/direct sockets used normal codecs inside a raw callback. Runtime evidence remains pending: cover read retry after rediscovery, a callback that catches a write failure and continues on the new primary, direct primary access, nested discovery, duplicate node references, raw/normal pooled operations, and native option failures. The Sentinel read/write replay policies are unchanged.

Historical validation below applies to its recorded revisions. The earlier error-buffer reporting update passed 38 PHP unit regression cases and 152 assertions on PHP 8.3.0, including 24 focused bounds/reporting checks. Ten PHP source/template/test files passed syntax checks. The seven-file PHPStan scope reports eight findings in unchanged API/diagnostic code; an immutable-source comparison reproduces all eight on 42f7acc, with no new findings. This is not a clean static-analysis result. The real WordPress evidence below predates this reporting update and does not validate its behavior in a live admin request.

This file records source implementation and its verification limits. Following the owner’s later authorization to run PHP tests after these updates, the local PHP 8.3.0/PHPUnit 9.6.37 suite passed 37 regression cases and 148 assertions on 2026-10-04. One real WordPress/Docker feature test was initially skipped. The owner then authorized the real WordPress run. A preceding fresh Docker fixture passed all seven integration scripts and the lifecycle suite, including that skipped test’s contracts.php scenario. All 37 regression cases also passed inside PHP 8.3.35. The fixture used WordPress 6.8.3, WooCommerce 10.2.2, PhpRedis 6.1.0 and Redis 7.4.2. Installed runtime/drop-in identity was verified against 187 source files. This establishes the recorded standalone behavior, not Relay or production acceptance. Browser, heavy concurrency, scale and performance gates remain open. Prior reports retain their original revision scope.

Plan requirement Current source/artifact Acceptance still needed
Attack-plan drop-in conflict protection and migration Separate product ownership; guarded admin/automatic writes and CLI disable; explicit CLI –force retained; preview, signed backup and guarded install/restore wizard Ownership/filter/legacy/link cases; real core nonce/capability and multisite checks; browser backup/restore; stale/tampered/oversized backup and filesystem/OPcache failure cases
Git baseline and rollback baseline/pre-modernization; MIGRATION-v2.md Target staging rollback rehearsal using a fresh prefix
Composer tooling and compatible base composer.lock, phpstan.neon.dist, PHP 8.2 headers/guards; PHP 8.3 regression suite passed Minimum PHP 8.2/PhpRedis 6.0 environment and real backend contracts
Repeatable WordPress/WooCommerce/Redis environment Fresh ocp-check-bf3a22fd1247 build/setup, source/drop-in verification, seven real contracts and lifecycle passed; owned containers/network/volumes removed Other supported runtime versions and topology/acceptance gates
Six cold/warm scenarios, p50/p95, traffic, memory and SQL benchmark.py, metrics.php, identity.php, provenance.py Five repetitions and baseline/candidate reports; no current reports exist
Five-percent warm regression gate compare.py validates raw samples, source provenance, fixture/config/harness parity Real comparison passes on the exact release candidate
Internal responsibility separation Keyspace, ExpirationPolicy, AllOptionsHash, KeyCleaner, PrefetchStore Contract parity across supported backend/runtime combinations
Primary-bound transaction/no replay TransactionalConnectionInterface, PhpRedis/Relay/Cluster transaction paths; first-error preservation and uncertain cleanup rejection covered with deterministic clients Real failover, resharding, timeout, ACL and partial-EXEC behavior
Atomic persistent counters (owner approved) Watched GET/arithmetic/conditional SET, CounterExpiration, failure-memory invalidation; real standalone counter script passed 148 checks, including interleaved writes and TTL Broad concurrency, lost replies, INFO/PTTL ACL failures, other Redis versions and overhead; legacy relative PX has deadline drift
Sentinel ordinary writes without replay (owner approved) Native retry suppression/restoration, first-error preservation, discovery for the next call; routing/native-policy/failover fixture sources Real lost replies, failure recovery, read-retry compatibility and licensed Relay
Lossless v2 key isolation Keyspace and adapted list/flush/prefetch/prune/invalidation consumers; key-isolation regression and real switch_to_blog isolation passed Full backend/runtime matrix
Cold migration/explicit legacy cleanup v2-only reads, scoped lifecycle flush, cleanup-legacy Legacy records untouched; rollback never reads stale pre-v2 keys
Optimistic alloptions NX/XX/TTL/field merging AllOptionsHash, syncAllOptions, bulk-memory publication; precondition regressions and 40 real bulk ADD checks passed with split/negative-cache modes off/on At least 20 processes: add, replace, independent updates, conflict results and memory invalidation; real ACL/read-error cases
Incremental cleanup and 500-key commands KeyCleaner, streaming pruneQueriesCount, SCAN default; validate zero/positive deletion counts without coercing failed replies 100k/1m keys, five repetitions, bounded memory and deletion scope
Legacy pruneQueries API Return-array signature retained; internal callers use count path External callers still allocate their explicitly requested result list
Prefetch bounds and site ownership 3600-second TTL, 256 keys, 1024 request records; membership-verified eviction, repair of detected metadata inconsistencies, failed-read guards and no reads after budget exhaustion; regression and 50 real Redis checks passed Real concurrent caps, server eviction, failure injection, expiry and multi-site transitions; added read overhead
Log and command limits ArrayLogger/log_limit; separate request-wide omitted-error counter, cache info, performance/overview widgets, diagnostics and Site Health totals; 24 focused checks and 38 unit cases passed Real WordPress admin rendering, browser behavior and sustained production requests
CLI child-only password handling REDISCLI_AUTH, CLI 5+ requirement, named profile resolution Process argument/env inspection on supported systems
Performance panel and history truthfulness PerformanceSnapshot, existing chart library, unified wait source Browser behavior, analytics off/on and failed-command metrics
Read-only cleanup preview CacheScope, bounded scan, fingerprints, explicit site/global/network/database labels and effective method/atomicity Capability/nonce handling, delegated site admin, global/all-sites scope and failure responses
CLI doctor JSON/table reports, nonzero errors, TLS/capability/drop-in/config facts; structured connection/client/header failure regression passed without exposing exception details Real standalone/Sentinel/Cluster/TLS/Relay diagnostics
Attack-plan CLI why Metadata-only wp redis why, live scope/policy/runtime flags, captured-primary TYPE/PTTL/hash-marker/lease snapshot, hypothetical TTL explanation, JSON/table and explicit error/conflict codes Final CLI/help/format/input/side-effect/error contracts; real PhpRedis/Relay/Sentinel/Cluster/TLS; no historical writer attribution is claimed; KEY-DIAGNOSTICS.md
Attack-plan Cache Insights 2% sampling, bounded caller/group counters and logical payload coverage, 256 named site/hour pairs on the owner-approved WATCH path, four-hour reads and 1,024-pair report merge; REST, admin charts/tables, CLI and six review rules Source review only. Final PHP/backend/concurrency/permissions/browser/privacy tests and five-repeat 0%/2%/100% overhead comparisons; partial EXEC/expiry/flush and measurement limits in CACHE-INSIGHTS.md
Attack-plan HTTP profile Signed one-use same-site anonymous GET; forced request-only sample, bounded events, actual-site confirmation and signed primary-side Redis handoff; bounded confirmed-write TTL evidence; CLI JSON/table Source review only; real HTTP/bootstrap/response, authorization/replay/expiry/ambiguity, multisite, limits/privacy, transport/cleanup, all backends and overhead tests in HTTP-PROFILE.md
Attack-plan TTL suggestion mode: evidence layer Completed-hour group classification across retained callers; current policy context, bounded conditional reviews and quality guards; admin/REST/JSON and CLI –ttl-review Source review only; final boundary, grouping, scope, rendering and zero-extra-command checks. Actual TTL/reuse/expiry/freshness measurements and numeric TTL recommendation remain open; adaptive TTL is not complete
Historical TTL write evidence (§9 approved) Separate opt-in ttl-v1 bounded JSON, shared request budget, confirmed-write histograms, explicit CLI/REST/admin history TTL-HISTORY.md final regression/Redis/browser/permissions/backend/overhead checks; no numeric optimum or freshness claim
Attack-plan key-explosion detector Opt-in sampled HMAC identity/patterns, fixed HLL slots, explicit bounded/fenced SCAN, scoped admin/REST/CLI and approximate comparison Source review only; final backend/ACL/expiry/partial-EXEC/concurrency/isolation/privacy/overhead acceptance in KEY-GROWTH.md; no production acceptance
Attack-plan configuration presets Owner-approved four candidates, bounded portable manifests, explicit precedence, exact group TTL caps, CLI import/export/diff and current-site REST/admin preview; shared key/TTL diagnostics Source review only; schema, configuration/TTL/backend, CLI, permission/browser and five-repeat performance gates in CONFIGURATION-PROFILES.md; no production acceptance
WooCommerce isolation and invalidation Real product invalidation contract passed; separate run.py –commerce source covers authenticated sessions, BACS checkout, order ownership and WooCommerce/SQL stock parity Execute –commerce; the product contract does not establish checkout/customer isolation, external gateways, shipping/tax or all storage modes
Distribution Deterministic immutable-commit package.py and changelog Candidate ZIP manifest, installed-version match, staging/pilot/network acceptance

Remaining implementation and evidence work

  • The new wp redis why source probes one scoped key without reading its value, retries or a keyspace scan. Existing transaction routing and native type constants are reused. TTL explanation shares the existing jitter reduction arithmetic and draws no random number. Syntax/static/runtime verification has not run for this change. Component attribution and the Insights screen/rules now have source implementation under the separately approved bounded storage contract (§5 of REFACTOR-DECISIONS.md); their runtime and performance acceptance remains open. wp redis profile now has source implementation under the separately approved contract in §6 and HTTP-PROFILE.md. TTL/persistence classification and read-only evidence review now use the existing completed-hour counters without changing storage. Exact TTL/reuse/expiry/freshness measurement and numeric TTL proposals remain phase-two development work; the evidence layer does not complete adaptive TTL. None of these new source changes have runtime or performance acceptance.

  • Key-explosion detection now has source implementation under the explicitly approved HLL/fingerprint/SCAN contract in REFACTOR-DECISIONS.md §7. Collection defaults off. HMAC observations, fixed site/hour slots, primary-side HLLs, fenced explicit scans, bounded history, scoped REST/admin/CLI output and opt-in doctor guidance are described in KEY-GROWTH.md. Source review only; no PHP, static, runtime, browser or performance checks have run for this change. Missing, partial, incompatible and approximate results are explicit; no automatic scan, cleanup, configuration change or production acceptance. Source follow-up: hourly JSON and scan-history writes now also confirm EXPIREAT at the approved absolute retention deadline. SET keeps its finite EX fallback; both replies are required. This removes relative-TTL transport/queue drift on successful publication, adds one expiry command per metadata write, and does not promise rollback or a durable marker for partial expiry failure. Delay/ACL/ clock-skew checks remain deferred in KEY-GROWTH.md.

  • The owner approved REFACTOR-DECISIONS.md §8 on 2026-10-05. Configuration profiles now have source implementation: preserved early config, four built-ins/custom manifest data, explicit-field precedence, exact group TTL caps, bounded local import and JSON export, CLI differences and read-only current-site management previews. Existing bootstrap groups and counter TTL retention remain. No live configuration file was changed. CONFIGURATION-PROFILES.md records semantics, rollback and final schema/TTL/CLI/REST/backend/browser/performance gates. Tests have not run; source completion does not grant phase-two/production acceptance.

  • Dedicated 20-process alloptions and 100k/1m cleanup sources are connected to the explicit run.py –acceptance option, with installed-source verification. They have not run. A separate –commerce source scenario now submits two real HTTP checkouts and checks session/order/stock isolation; it is also unexecuted.

  • Local regression coverage includes scopes, budgets, new connection capabilities, cleanup failure precedence and request-memory invalidation. Old bulk-key/counter fixtures now follow the approved v2/transaction contracts. An IPv6 seed port bug found during the run was fixed. Eleven changed PHP files passed syntax checks; nine connection/configuration files passed PHPStan level 5 with zero errors.

  • Equal-sized prefetch record/index containers can contain different members after a partial EXEC failure. Eviction now verifies the space it needs and repairs detected mismatches in that site’s metadata. Regression coverage includes a partially applied EXEC and fresh/stale native errors. Real Redis passed 50 checks with seeded inconsistent metadata, serialization, TTL and site/data isolation; it did not inject a real server EXEC failure. Three PHP files passed syntax checks and three related production files passed PHPStan level 5. Extra reads have not been benchmarked; failed EXEC still has no rollback guarantee.

  • Freeze a new review ZIP from the final immutable source after remaining acceptance.

  • The eight errors in log-bounds-static-comparison.json describe its historical baseline/candidate, not the current checkout. Source inspection on 2026-10-05 found the callable multisite initialization guard in api.php, the Basename bootstrap/dynamic-constant setup in phpstan.neon.dist and tests/PHPStan/constants.php, and the single-instance Relay adaptive-cache guard and removed obsolete ignores in Diagnostics.php already present. Do not implement those fixes a second time. A fresh final-stage static run is still required to establish the current result; source inspection and historical reports do not verify real Relay behavior.

  • Cursor-based management group listing remains a proposal in REFACTOR-DECISIONS.md; the existing full-list behavior has not been changed without separate approval.

  • Local PHP regressions and the default fresh WordPress integration run are now authorized and completed. Topology/TLS, browser, heavy load and performance gates remain open. Licensed Relay behavior is explicitly unverified.

  • No new frontend framework, hosted CI provider, update server, automatic optimizer, production deployment or external telemetry is introduced in this release.

Local reports are under build/modernization: phpunit-final.txt/phpunit-final.xml, transaction-cleanup-syntax.json and transaction-cleanup-static.json. Counts and changed PHP source hashes are recorded in tests/integration/status.json. These results cover their stated scope only. Error-buffer evidence is in log-bounds-unit.xml, log-bounds-syntax.json, log-bounds-static.json and log-bounds-static-comparison.json; its source hashes and limits are under log_bounds_validation in status.json. The real WordPress evidence is in tests/integration/results/ocp-check-bf3a22fd1247/run.json; its digest, tested source hashes and summary are recorded under prefetch_membership_validation in status.json. The earlier ocp-check-cab5b3ed7a90 evidence retains its original scope. The latest run tested the checkout based on 5055471 plus the prefetch fix, not an exported ZIP. A commit/ZIP records a reviewable checkpoint, not successful production acceptance.