Bump WolverineFx from 6.25.3 to 6.28.2 - #324
Merged
github-actions[bot] merged 1 commit intoAug 24, 2026
Merged
Conversation
--- updated-dependencies: - dependency-name: WolverineFx dependency-version: 6.28.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
github-actions
Bot
deleted the
dependabot/nuget/benchmarks/Foundatio.Mediator.Benchmarks/WolverineFx-6.28.2
branch
August 24, 2026 22:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated WolverineFx from 6.25.3 to 6.28.2.
Release notes
Sourced from WolverineFx's releases.
6.28.2
A bug fix release, with one new opt-in on the RabbitMQ listener contributed by the community.
Store agnostic document sessions
A handler can now take the
JasperFx.Events.Documentscontracts —IDocumentSessionOperations,IDocumentWriteOperations,IDocumentReadOperations— straight as parameters, and they bind and commit on Marten, Polecat and Fisher alike (#3962, closes #3956):These are the document side counterparts to the
IEventOperationscontracts Wolverine already understood, and they are the only way store agnostic source can take a session without naming a concrete store type.Before this, such a handler failed codegen outright on a stock host. Once bound, its writes were queued into the session's unit of work and silently discarded — no exception. Both halves are fixed.
Durability agents no longer assigned to nodes that cannot run them
A node started with
Durability.DurabilityAgentEnabled = falsenever registers the durability agent family, so it threwUnrecognized agent scheme 'wolverinedb'the moment the leader handed it one. The leader re-issued the identical assignment every five minutes indefinitely, no durability agent ran anywhere for that store, andowner_id = 0outgoing envelopes were never recovered (#3963, closes #3954).The failure was silent in both directions — every queue table read zero while the backlog grew. Nodes now publish a marker capability when the family is actually registered, the leader skips nodes that have not, and when no node in the cluster is capable a warning names the condition and the setting.
If you run a Balanced cluster with
DurabilityAgentEnabled = falseon any node, this release is worth taking.Ancillary store transaction ownership
Ancillary store inference scanned
chain.ServiceDependencies(), which walks constructor graphs recursively — so a dependency that merely held an ancillary store matched. A read only store injected two hops down counted the same as an injectedDbContext, and a tenant Marten handler had its inbox and dead letters stolen by the wrong store (#3957, closes #3953).That inference was only ever correct for EF Core. There is a new default null
IPersistenceFrameProvider.TryDetermineTransactionOwnerTypefor it, implemented only by EF Core.RabbitMQ
ListenToRabbitQueue("orders").DrainWaitForPrefetch()to let already prefetched messages finish rather than letting the broker requeue them.StopAsyncis not always terminal, and aBatchingChannelsilently discards a post after completion, so a delivery landing between the drain and the dispose latch vanished and was redelivered.code=541). This narrows the window and speeds recovery; it does not prevent the close, whose root cause is upstream in rabbitmq-dotnet-client.Idle reaper no longer latches durable endpoints
A durable endpoint reached only via
EndpointFor(uri)looked as disposable as an ephemeral reply queue and was reaped; the rebuilt agent then wrapped a disposed sender and latched forever (#3958, closes #3955).SendingAgentIdleTimeouthad no test coverage at all before this.6.28.1
Patch release over 6.28.0.
New package
WolverineFx.Http.Fisher(#3949, closes #3944) — there was aWolverine.Http.Martenand aWolverine.Http.Polecatand no Fisher equivalent, so a Fisher-backed application had nothing to reference for the aggregate/document HTTP attributes. The third flavour now exists alongside its siblings.Fixes
A SQLite "schema name" is now the table name prefix it was documented to be
(#3945, closes #3943)
Setting
FisherIntegration.MessageStorageSchemaName, or theschemaNameargument toPersistMessagesWithSqlite(), reached the message store as aschema.tablequalifier. SQLite has no user-defined schemas — the only names a plain connection knows aremain,temp, and whatever has beenATTACHed — so any value other thanmainemitted SQL against a database that never existed, and the host died on the first envelope write with:The two halves had disagreed all along. Weasel's
SqliteObjectNamedrops the schema from its qualified name, so the DDL had been creating a barewolverine_incoming_envelopeswhile the inherited DML asked for a qualified one; themaindefault is the only thing that hid it.The name is now folded into the table names as a prefix — a meaning SQLite can honour, giving several logically separate Wolverine table sets inside one database file:
This covers the envelope, node, control queue, tenant, listener and saga tables, plus the dead-letter index names, since SQLite shares one identifier namespace between tables and indexes.
No migration.
mainis the default and prefixes nothing, so every database provisioned before this release keeps its existingwolverine_*names. Only hosts that explicitly set a non-mainname see different table names — and those hosts could not start at all before this fix. Postgres, SQL Server, MySQL and Oracle render exactly as before.FisherIntegration.TransportSchemaNameis now documented as what it has always been on a Fisher host: inert. Tracked in #3947.Polecat unwraps
Nullable<T>when determining an aggregate's id type(#3948, closes #3942) Marten and Polecat disagreed for an aggregate whose id property is nullable: Polecat answered
Nullable<T>verbatim, which is not a primitive id type, so the documentedIdentifiedBy<T>escape hatch was skipped entirely. The two stores now agree.Dependencies
Fisher 0.7.0 (#3946) — the package floor moves from 0.6.0 to 0.7.0. Note that Fisher 0.7.0 bundles
JasperFx.Events.SourceGeneratorinside its own nupkg, as Polecat already does. A project that also references that generator explicitly will get two analyzer instances and aCS0433duplicate-type error until one copy is removed.Full changelog: JasperFx/wolverine@V6.28.0...V6.28.1
6.28.0
Storage agnostic conventions wave: write handlers and HTTP endpoints that read and append without naming a store.
Highlights
Storage.AppendEvents()/Storage.StartStream()(#3934) — event stream counterparts toStorage.Store(), expressed entirely againstJasperFx.Events.IEventOperations, so the same handler is valid on Marten, Polecat or Fisher with noIDocumentSession.[FirstOrDefault](#3933) — the singleton document[Entity]cannot express, since it has no identity to look up by.[All]and[Queryable](#3936) — every document of a type as anIReadOnlyList<T>, and a rawIQueryable<T>escape hatch.OnMissing.EmptyContentWith204,[NoContentIfMissing]/[NotFoundIfMissing](#3931) — answer an empty 204 instead of a 404 when there is simply nothing to return.DateTime/DateTimeOffset nowin Wolverine.HTTP (#3932) — matches the long standing message handler convention. Previously such a parameter silently bound from the query string and arrived asdefault.Notable fix
An
IEventStoreOperations/IEventOperationshandler or endpoint parameter now resolves and commits (#3936).CanApplyrecognized no event operations type, soAutoApplyTransactionsskipped those chains and appended events were queued into the session's unit of work and never committed — with no exception thrown. This also affected each store's own event operations types, so it predates this release.Also:
[All]/[Queryable]/[FirstOrDefault]provider errors now name the declaring method (#3937).Full detail in CHANGELOG.md.
6.27.1
Wolverine 6.27.1
A same-day patch on 6.27.0, fixing a regression that release introduced and closing the asymmetry that surfaced it.
Regression fix:
[WriteAggregate]lost its not-found guard in 6.27.0WriteAggregateAttributederives fromWriteModelAttributeand overrides neitherModifynorRequired, so it inherited 6.27.0's nullability inference (GH-3916) wholesale.[WriteAggregate]shipped a year before that inference, so in 6.27.0 an existing handler like:silently lost its not-found guard and began running against a model that was never loaded — for a write model, that means appending events against a stream that was not fetched.
[WriteAggregate]and[ReadAggregate]now pin the unconditionalRequired = truethey have always had, in Marten, Polecat and Fisher alike. SayRequired = falseexplicitly, or move to[WriteModel]/[ReadModel], to opt out.If you are on 6.27.0 and use
[WriteAggregate]with a nullable parameter and no explicitRequired, upgrade.[ReadModel]takesRequiredfrom the parameter's nullable annotation (#3929)Matching what GH-3916 did for
[WriteModel]:Order orderis required and gets a not-found guard,Order? orderis not and is handed to your method asnullso your own null branch runs. An explicitRequiredat the call site still wins over the annotation.This closes the write/read asymmetry — a handler moving between the two forms no longer needs a different attribute spelling for identical intent.
What deliberately did not change
[Entity]keeps its unconditionalRequired = true. It is the oldest and most widely used of these attributes and is heavily used in HTTP endpoints, whereRequired = truewithOnMissing.Simple404is the documented 404 behaviour. Loosening it would turn a clean 404 into a runtimeNullReferenceExceptionin an endpoint body.[DeciderFunction]and[DcbModel]keepRequired = false. Their model is folded out of an event stream or boundary and is always materialized, so absence is not the normal case; inferring here would tighten the default and could stop messages that process today.Worth knowing
In an assembly compiled with
<Nullable>disable</Nullable>a reference-type parameter reads as unknown rather than nullable, so[WriteModel]and[ReadModel]fall back toRequired = true. The inference is a no-op for those projects rather than a silent behaviour change. Now documented in the persistence guide.6.27.0
Wolverine 6.27.0
New:
WolverineFx.FisherFisher — the embedded SQLite document database and event store — is now a first-class Wolverine persistence integration, alongside Marten and Polecat.
A Fisher-backed service is zero-infrastructure: no server, no container, no network. The transactional inbox/outbox, saga storage and the full aggregate handler workflow all work, and the store-agnostic
[WriteModel]/[ReadModel]/[DeciderFunction]/[DcbModel]attributes run against it unchanged — the same handler code compiles and runs on any of the three stores.Two SQLite realities shape it, both documented:
DurabilityMode.Solo. Leader election and agent distribution need several nodes sharing one database; a Fisher store is a file.Ancillary stores work too.
AddFisherStore<T>().IntegrateWithWolverine()is supported, and[Storage(typeof(IMyStore))]routes a handler to it without naming Fisher in the consumer's source.Not in this first release, each for a reason rather than for lack of time: multi-tenancy (Fisher's tenancy is a file per tenant), cluster durability modes, and transport schema stamping (SQLite has no schemas). See Fisher Integration.
Requires Fisher 0.6.0.
New:
[DcbModel]— Dynamic Consistency Boundaries, store-agnosticThe DCB workflow joins the store-agnostic vocabulary in Wolverine core. Where
[WriteModel]is about one stream,[DcbModel]spans every stream whose events match a tag query, with the store asserting at commit that no matching event landed in the meantime.Wolverine.Marten.BoundaryModelAttributeandWolverine.Polecat.BoundaryModelAttributenow inherit from it and behave identically — existing[BoundaryModel]code needs no change. Prefer[DcbModel]in new code.[WriteModel]fixesRequirednow defaults from the parameter's nullable annotation (#3916).Order orderis required and gets a not-found guard;Order? orderis not, and is handed to your method asnullso your own null branch runs. A nullable annotation withRequired = truewas a contradiction that silently resolved in favour of the attribute default, making the handler's null branch dead code. SettingRequiredexplicitly still overrides the annotation either way.Required = trueexplicitly to keep it.[Identity]is now honoured (#3918).[DeciderFunction]always respected[Identity]on the command member;[WriteModel]did not, so the same command against the same model needed an explicit[WriteModel("...")]under one form and nothing under the other. Resolution order is now: explicit[WriteModel("orderId")], then[Identity], then{Model}Id, thenid, then a strong typed id match.Amazon SQS: oversized messages (#3926)
A message too big for SQS is no longer retried forever. SQS caps a message at 256KB and rejects a larger one with
InvalidParameterValue - Message must be shorter than 262144 bytes (SenderFault: true).SenderFault: truemeans the identical request will fail identically forever, but Wolverine treated it as a transient send failure and re-queued it — which is why this presented as a flood of identical errors rather than one. An oversized message is now logged once and discarded.... (truncated)
6.26.0
Upgrade note
This release moves the Critter Stack dependencies forward together:
[5.7.0,6.0.0)(resolving to 5.7.0)[5.12.0,6.0.0)Polecat users get the larger jump of the two: the old range pin resolved to its 5.7.0 floor, so this is 5.7.0 → 5.12.0 in practice.
If you reference
JasperFx.Events.SourceGeneratorexplicitly and reference Polecat, you may hitCS0433("the type<X>Evolverexists in both<YourAssembly>and<YourAssembly>"). The generator ships both bundled inside the Polecat nupkg and as a standalone package; when the two copies are the same version they load as two analyzer instances and each emits every projection's Evolver dispatcher. Polecat 5.12.0 bundles 2.47.0, which is what this release pins, so the pair now matches. The fix is to drop one instance — seePolecatTests.csprojfor theDropDuplicateBundledEventSourceGeneratortarget we use, which keeps the explicitly-pinned generator and removes the bundled duplicate.Two new packages
WolverineFx.DataAnnotationsValidationandWolverineFx.FluentValidation.Grpcare published for the first time in this release. Both were documented as installable but had never actually shipped — every version returnedBlobNotFoundfrom nuget.org — because each declared aPackageIdwhile being absent from the packaging list. If you followed the Data Annotations validation or gRPC error details docs and found the package missing, it exists now. A build-time check keeps the two lists from drifting apart again. (#3905, #3909)Fixes
A
[WriteAggregate]-only chain now reportsIsTransactionalcorrectly. The Marten and Polecat aggregate handler workflows appended aSaveChangesAsyncpostprocessor but never setIChain.IsTransactional, so a chain reported having no transactional middleware while its generated code committed. The disagreement was visible toIHttpPolicyauthors, who had no reliable signal for whether a chain would commit — the workaround was an unusedIDocumentSessionparameter on every such endpoint, purely to flip the detection. Thanks to @esond for the report and the fix. (#3893, #3901)Outgoing batches no longer serialize eagerly.
OutgoingMessageBatchbuilt its contiguousbyte[]in its constructor whether or not anything read it. (#3906)Aggregate handler workflow unification (#3907, increment one)
Wolverine has carried two near-identical copies of the aggregate handler workflow — one in
Wolverine.Marten, one inWolverine.Polecat— and improvements had been landing on one copy at a time. This release starts implementing it once, in core.Nothing is retired and no public API changes.
[WriteAggregate],[ReadAggregate],[AggregateHandler],[ConsistentAggregate],Events,MartenOps/PolecatOpsand the rest of each integration's surface stay exactly where they are.What landed:
AggregateHandling.DetermineVersionMembernow returnsMemberInfo?— Marten's copy used a null-forgiving operator that was masking a real null fromIAggregateVersioning.VersionMember. Polecat regains AOT annotations it had dropped. Two reflectively-closed codegen frames widen aclassconstraint tonotnull, matchingIEventStream<T>'s own declaration; the narrower form threw for a struct aggregate instead of generating the same correct code.IEventSourcingFrameProvider, the store seam — deliberately a sibling ofIPersistenceFrameProviderrather than new members on it, so stores without event sourcing never grow no-op aggregate members.Wolverine.Persistence.EventSourcing: the event-capture frames andDetermineEventCaptureHandling, all written purely againstJasperFx.Events'IEventStream<T>.Wolverine.<Store>integration, so aCS0104ambiguity for users is caught by a failing test instead.The bulk extraction continues in #3911. Also in this release: #3908, which pins what
[Storage(typeof(...))]actually promises against a Marten ancillary store.Upstream halves of this work: JasperFx/jasperfx#648, JasperFx/marten#5221, JasperFx/polecat#453.
6.25.5
6.25.5 supersedes the never-published 6.25.4 (its tag and release were retired), so the first two fixes below make their first NuGet appearance here.
Fixes
PostgreSQL dead-letter and outgoing counts are exact for small tables (GH-3885)
The PostgreSQL message-store counts for the dead-letter and outgoing tables now report exact numbers for small tables instead of the estimate that could read as zero right after activity. First staged for 6.25.4; this is its first published release.
The durable inbox routes by endpoint for sticky handlers (GH-3886)
Durable inbox recovery now routes each envelope by its owning endpoint, so sticky-handler (
[StickyHandler]/ endpoint-scoped) messages recovered from the inbox execute on the endpoint they were received on rather than falling back to the default route. Also first staged for 6.25.4.Never export empty metrics snapshots + idle-tenant eviction (#3891)
Wolverine no longer exports metrics snapshots that contain no data, and per-tenant metric state for tenants that have gone idle is evicted after a configurable number of cycles via
WolverineOptions.Metrics.TenantIdleEvictionCycles. This is the upstream half of CritterWatch#963 — at very high tenant counts, idle tenants no longer pin memory or pad every export.Agents that exhaust node-local auto-restarts are released to a capable peer (GH-3888, #3896)
When a stalled agent uses up its node-local auto-restart budget, the node now releases the agent so a capable peer can pick it up, instead of retrying forever on the same node. A capability embargo prevents the agent from bouncing straight back to the node that just failed it.
Short-circuiting Before + Finally middleware no longer NREs (GH-3892, #3895)
Middleware that combines a short-circuiting
Beforemethod with aFinallymethod no longer produces aNullReferenceExceptionat codegen time — andFinallynow runs on the short-circuit path, as the middleware contract promises.Saga diagnostics tolerate an unprovisioned saga table (GH-3887, #3894)
DatabaseSagaStoreDiagnostics.ReadSagaAsync/ListSagaInstancesAsynctreat a missing saga table (Postgres 42P01 / SQL Server 208) as null / empty rather than surfacing a raw undefined-table error. A declared-but-never-persisted saga is a legitimate state, sinceAddSagaTypeis optional.Polecat
TransportSchemaNameis honored (GH-3884, #3897)PolecatIntegration.TransportSchemaNameis now actually applied — previously the setting was inert and the transport tables always landed in the default schema.Improvements
The stalled-agent auto-restart path is testable (#3890)
The auto-restart path now runs on
TimeProvider, making it deterministic under test — with coverage added. Thanks @erdtsieck!Message types can be exempted from partitioned processing (GH-3899, #3902)
MessagePartitioning.ExemptFromPartitionedProcessing<T>()exempts a message type from partitioned (GroupId-keyed) processing — exempt types ride the endpoint's normal parallelism while partitioned types keep strict per-group ordering.Batched members'
DeliverByexpiry is enforced again (GH-3898, #3903)Expired members are shed at batch assembly with the normal discard observability, and a whole-batch backstop expires batches whose every member has lapsed.
The sharded execution block deserializes in parallel with ordered emission (GH-3900, #3904)
The sharded execution block's decompress/deserialize stage now runs N-wide while preserving per-group FIFO byte-for-byte.
... (truncated)
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)