Skip to content

Bump WolverineFx from 6.25.3 to 6.28.2 - #324

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/nuget/benchmarks/Foundatio.Mediator.Benchmarks/WolverineFx-6.28.2
Aug 24, 2026
Merged

Bump WolverineFx from 6.25.3 to 6.28.2#324
github-actions[bot] merged 1 commit into
mainfrom
dependabot/nuget/benchmarks/Foundatio.Mediator.Benchmarks/WolverineFx-6.28.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Updated WolverineFx from 6.25.3 to 6.28.2.

Release notes

Sourced from WolverineFx's releases.

6.28.2

A bug fix release, with one new opt-in on the RabbitMQ listener contributed by the community.

Store agnostic document sessions

A handler can now take the JasperFx.Events.Documents contracts — IDocumentSessionOperations, IDocumentWriteOperations, IDocumentReadOperations — straight as parameters, and they bind and commit on Marten, Polecat and Fisher alike (#​3962, closes #​3956):

// Valid against all three stores -- nothing store specific is named
public static void Handle(RecordNote command, IDocumentSessionOperations session)
    => session.Store(new Note { Id = command.Id, Text = command.Text });

These are the document side counterparts to the IEventOperations contracts Wolverine already understood, and they are the only way store agnostic source can take a session without naming a concrete store type.

Before this, such a handler failed codegen outright on a stock host. Once bound, its writes were queued into the session's unit of work and silently discarded — no exception. Both halves are fixed.

⚠️ Importing the JasperFx.Events.Documents namespace makes ToListAsync() ambiguous with each store's own queryable extensions (CS0121). Alias the individual contracts rather than importing the namespace.

Durability agents no longer assigned to nodes that cannot run them

A node started with Durability.DurabilityAgentEnabled = false never registers the durability agent family, so it threw Unrecognized agent scheme 'wolverinedb' the moment the leader handed it one. The leader re-issued the identical assignment every five minutes indefinitely, no durability agent ran anywhere for that store, and owner_id = 0 outgoing envelopes were never recovered (#​3963, closes #​3954).

The failure was silent in both directions — every queue table read zero while the backlog grew. Nodes now publish a marker capability when the family is actually registered, the leader skips nodes that have not, and when no node in the cluster is capable a warning names the condition and the setting.

If you run a Balanced cluster with DurabilityAgentEnabled = false on any node, this release is worth taking.

Ancillary store transaction ownership

Ancillary store inference scanned chain.ServiceDependencies(), which walks constructor graphs recursively — so a dependency that merely held an ancillary store matched. A read only store injected two hops down counted the same as an injected DbContext, and a tenant Marten handler had its inbox and dead letters stolen by the wrong store (#​3957, closes #​3953).

That inference was only ever correct for EF Core. There is a new default null IPersistenceFrameProvider.TryDetermineTransactionOwnerType for it, implemented only by EF Core.

RabbitMQ

  • Wait for prefetched messages on drain (#​3796) — contributed by @​benjamin-alexander-simplisafe. Opt in with ListenToRabbitQueue("orders").DrainWaitForPrefetch() to let already prefetched messages finish rather than letting the broker requeue them.
  • The prefetch drain is safe for a non terminal stop (#​3960) — StopAsync is not always terminal, and a BatchingChannel silently discards a post after completion, so a delivery landing between the drain and the dispose latch vanished and was redelivered.
  • A rejected settle quiesces the channel the broker already closed (#​3964, addresses #​3950) — feeding a channel that is being torn down is what makes RabbitMQ.Client race itself and escalate a dead channel into a close of the entire connection (code=541). This narrows the window and speeds recovery; it does not prevent the close, whose root cause is upstream in rabbitmq-dotnet-client.
  • Listener recovery after a mid flight connection death is now asserted (#​3961).

Idle reaper no longer latches durable endpoints

A durable endpoint reached only via EndpointFor(uri) looked as disposable as an ephemeral reply queue and was reaped; the rebuilt agent then wrapped a disposed sender and latched forever (#​3958, closes #​3955). SendingAgentIdleTimeout had no test coverage at all before this.

6.28.1

Patch release over 6.28.0.

New package

WolverineFx.Http.Fisher (#​3949, closes #​3944) — there was a Wolverine.Http.Marten and a Wolverine.Http.Polecat and no Fisher equivalent, so a Fisher-backed application had nothing to reference for the aggregate/document HTTP attributes. The third flavour now exists alongside its siblings.

Fixes

A SQLite "schema name" is now the table name prefix it was documented to be

(#​3945, closes #​3943)

Setting FisherIntegration.MessageStorageSchemaName, or the schemaName argument to PersistMessagesWithSqlite(), reached the message store as a schema.table qualifier. SQLite has no user-defined schemas — the only names a plain connection knows are main, temp, and whatever has been ATTACHed — so any value other than main emitted SQL against a database that never existed, and the host died on the first envelope write with:

SQLite Error 1: 'no such table: <name>.wolverine_incoming_envelopes'

The two halves had disagreed all along. Weasel's SqliteObjectName drops the schema from its qualified name, so the DDL had been creating a bare wolverine_incoming_envelopes while the inherited DML asked for a qualified one; the main default is the only thing that hid it.

The name is now folded into the table names as a prefix — a meaning SQLite can honour, giving several logically separate Wolverine table sets inside one database file:

opts.PersistMessagesWithSqlite(connectionString, "reporting");
// => reporting_wolverine_incoming_envelopes, reporting_wolverine_outgoing_envelopes, ...

This covers the envelope, node, control queue, tenant, listener and saga tables, plus the dead-letter index names, since SQLite shares one identifier namespace between tables and indexes.

No migration. main is the default and prefixes nothing, so every database provisioned before this release keeps its existing wolverine_* names. Only hosts that explicitly set a non-main name see different table names — and those hosts could not start at all before this fix. Postgres, SQL Server, MySQL and Oracle render exactly as before.

FisherIntegration.TransportSchemaName is now documented as what it has always been on a Fisher host: inert. Tracked in #​3947.

Polecat unwraps Nullable<T> when determining an aggregate's id type

(#​3948, closes #​3942) Marten and Polecat disagreed for an aggregate whose id property is nullable: Polecat answered Nullable<T> verbatim, which is not a primitive id type, so the documented IdentifiedBy<T> escape hatch was skipped entirely. The two stores now agree.

Dependencies

Fisher 0.7.0 (#​3946) — the package floor moves from 0.6.0 to 0.7.0. Note that Fisher 0.7.0 bundles JasperFx.Events.SourceGenerator inside its own nupkg, as Polecat already does. A project that also references that generator explicitly will get two analyzer instances and a CS0433 duplicate-type error until one copy is removed.

Full changelog: JasperFx/wolverine@V6.28.0...V6.28.1

6.28.0

Storage agnostic conventions wave: write handlers and HTTP endpoints that read and append without naming a store.

Highlights

  • Storage.AppendEvents() / Storage.StartStream() (#​3934) — event stream counterparts to Storage.Store(), expressed entirely against JasperFx.Events.IEventOperations, so the same handler is valid on Marten, Polecat or Fisher with no IDocumentSession.
  • [FirstOrDefault] (#​3933) — the singleton document [Entity] cannot express, since it has no identity to look up by.
  • [All] and [Queryable] (#​3936) — every document of a type as an IReadOnlyList<T>, and a raw IQueryable<T> escape hatch.
  • Batched reads (#​3938) — on Marten, Polecat and Fisher, two or more batchable reads in the same handler now resolve in a single database round trip. Nothing to turn on.
  • OnMissing.EmptyContentWith204, [NoContentIfMissing] / [NotFoundIfMissing] (#​3931) — answer an empty 204 instead of a 404 when there is simply nothing to return.
  • DateTime / DateTimeOffset now in Wolverine.HTTP (#​3932) — matches the long standing message handler convention. Previously such a parameter silently bound from the query string and arrived as default.

Notable fix

An IEventStoreOperations / IEventOperations handler or endpoint parameter now resolves and commits (#​3936). CanApply recognized no event operations type, so AutoApplyTransactions skipped those chains and appended events were queued into the session's unit of work and never committed — with no exception thrown. This also affected each store's own event operations types, so it predates this release.

Also: [All] / [Queryable] / [FirstOrDefault] provider errors now name the declaring method (#​3937).

Full detail in CHANGELOG.md.

6.27.1

Wolverine 6.27.1

A same-day patch on 6.27.0, fixing a regression that release introduced and closing the asymmetry that surfaced it.

Regression fix: [WriteAggregate] lost its not-found guard in 6.27.0

WriteAggregateAttribute derives from WriteModelAttribute and overrides neither Modify nor Required, so it inherited 6.27.0's nullability inference (GH-3916) wholesale. [WriteAggregate] shipped a year before that inference, so in 6.27.0 an existing handler like:

public static Events Handle(RecordDeposit command, [WriteAggregate] Account? account)

silently lost its not-found guard and began running against a model that was never loaded — for a write model, that means appending events against a stream that was not fetched.

[WriteAggregate] and [ReadAggregate] now pin the unconditional Required = true they have always had, in Marten, Polecat and Fisher alike. Say Required = false explicitly, or move to [WriteModel] / [ReadModel], to opt out.

If you are on 6.27.0 and use [WriteAggregate] with a nullable parameter and no explicit Required, upgrade.

[ReadModel] takes Required from the parameter's nullable annotation (#​3929)

Matching what GH-3916 did for [WriteModel]: Order order is required and gets a not-found guard, Order? order is not and is handed to your method as null so your own null branch runs. An explicit Required at the call site still wins over the annotation.

This closes the write/read asymmetry — a handler moving between the two forms no longer needs a different attribute spelling for identical intent.

What deliberately did not change

  • [Entity] keeps its unconditional Required = true. It is the oldest and most widely used of these attributes and is heavily used in HTTP endpoints, where Required = true with OnMissing.Simple404 is the documented 404 behaviour. Loosening it would turn a clean 404 into a runtime NullReferenceException in an endpoint body.
  • [DeciderFunction] and [DcbModel] keep Required = false. Their model is folded out of an event stream or boundary and is always materialized, so absence is not the normal case; inferring here would tighten the default and could stop messages that process today.

Worth knowing

In an assembly compiled with <Nullable>disable</Nullable> a reference-type parameter reads as unknown rather than nullable, so [WriteModel] and [ReadModel] fall back to Required = true. The inference is a no-op for those projects rather than a silent behaviour change. Now documented in the persistence guide.

6.27.0

Wolverine 6.27.0

New: WolverineFx.Fisher

Fisher — the embedded SQLite document database and event store — is now a first-class Wolverine persistence integration, alongside Marten and Polecat.

builder.Services.AddFisher(opts => opts.Connection("Data Source=app.db"))
    .ApplyAllDatabaseChangesOnStartup()
    .IntegrateWithWolverine();

A Fisher-backed service is zero-infrastructure: no server, no container, no network. The transactional inbox/outbox, saga storage and the full aggregate handler workflow all work, and the store-agnostic [WriteModel] / [ReadModel] / [DeciderFunction] / [DcbModel] attributes run against it unchanged — the same handler code compiles and runs on any of the three stores.

Two SQLite realities shape it, both documented:

  • One writer per file. Wolverine's durability tables commit on Fisher's own connection inside Fisher's transaction. A second connection to the same file is a second writer and presents as a hang rather than an error.
  • DurabilityMode.Solo. Leader election and agent distribution need several nodes sharing one database; a Fisher store is a file.

Ancillary stores work too. AddFisherStore<T>().IntegrateWithWolverine() is supported, and [Storage(typeof(IMyStore))] routes a handler to it without naming Fisher in the consumer's source.

Not in this first release, each for a reason rather than for lack of time: multi-tenancy (Fisher's tenancy is a file per tenant), cluster durability modes, and transport schema stamping (SQLite has no schemas). See Fisher Integration.

Requires Fisher 0.6.0.

New: [DcbModel] — Dynamic Consistency Boundaries, store-agnostic

The DCB workflow joins the store-agnostic vocabulary in Wolverine core. Where [WriteModel] is about one stream, [DcbModel] spans every stream whose events match a tag query, with the store asserting at commit that no matching event landed in the meantime.

public static EventTagQuery Load(ReserveSeat command)
    => EventTagQuery.For(command.ScreeningId).Or(command.CustomerId);

public static SeatReserved Handle(ReserveSeat command, [DcbModel] SeatAvailability availability)
    => new(command.ScreeningId, command.CustomerId);

Wolverine.Marten.BoundaryModelAttribute and Wolverine.Polecat.BoundaryModelAttribute now inherit from it and behave identically — existing [BoundaryModel] code needs no change. Prefer [DcbModel] in new code.

[WriteModel] fixes

  • Required now defaults from the parameter's nullable annotation (#​3916). Order order is required and gets a not-found guard; Order? order is not, and is handed to your method as null so your own null branch runs. A nullable annotation with Required = true was a contradiction that silently resolved in favour of the attribute default, making the handler's null branch dead code. Setting Required explicitly still overrides the annotation either way.

    ⚠️ Behaviour change for a handler with a nullable model parameter that relied on the implicit guard. Set Required = true explicitly to keep it.

  • [Identity] is now honoured (#​3918). [DeciderFunction] always respected [Identity] on the command member; [WriteModel] did not, so the same command against the same model needed an explicit [WriteModel("...")] under one form and nothing under the other. Resolution order is now: explicit [WriteModel("orderId")], then [Identity], then {Model}Id, then id, then a strong typed id match.

Amazon SQS: oversized messages (#​3926)

A message too big for SQS is no longer retried forever. SQS caps a message at 256KB and rejects a larger one with InvalidParameterValue - Message must be shorter than 262144 bytes (SenderFault: true). SenderFault: true means the identical request will fail identically forever, but Wolverine treated it as a transient send failure and re-queued it — which is why this presented as a flood of identical errors rather than one. An oversized message is now logged once and discarded.
... (truncated)

6.26.0

Upgrade note

This release moves the Critter Stack dependencies forward together:

package from to
JasperFx, JasperFx.Events (+ both source generators) 2.46.0 2.47.0
Marten, Marten.AspNetCore, Marten.Newtonsoft 9.22.6 9.23.0
Polecat [5.7.0,6.0.0) (resolving to 5.7.0) [5.12.0,6.0.0)

Polecat users get the larger jump of the two: the old range pin resolved to its 5.7.0 floor, so this is 5.7.0 → 5.12.0 in practice.

If you reference JasperFx.Events.SourceGenerator explicitly and reference Polecat, you may hit CS0433 ("the type <X>Evolver exists in both <YourAssembly> and <YourAssembly>"). The generator ships both bundled inside the Polecat nupkg and as a standalone package; when the two copies are the same version they load as two analyzer instances and each emits every projection's Evolver dispatcher. Polecat 5.12.0 bundles 2.47.0, which is what this release pins, so the pair now matches. The fix is to drop one instance — see PolecatTests.csproj for the DropDuplicateBundledEventSourceGenerator target we use, which keeps the explicitly-pinned generator and removes the bundled duplicate.

Two new packages

WolverineFx.DataAnnotationsValidation and WolverineFx.FluentValidation.Grpc are published for the first time in this release. Both were documented as installable but had never actually shipped — every version returned BlobNotFound from nuget.org — because each declared a PackageId while being absent from the packaging list. If you followed the Data Annotations validation or gRPC error details docs and found the package missing, it exists now. A build-time check keeps the two lists from drifting apart again. (#​3905, #​3909)

Fixes

A [WriteAggregate]-only chain now reports IsTransactional correctly. The Marten and Polecat aggregate handler workflows appended a SaveChangesAsync postprocessor but never set IChain.IsTransactional, so a chain reported having no transactional middleware while its generated code committed. The disagreement was visible to IHttpPolicy authors, who had no reliable signal for whether a chain would commit — the workaround was an unused IDocumentSession parameter on every such endpoint, purely to flip the detection. Thanks to @​esond for the report and the fix. (#​3893, #​3901)

Outgoing batches no longer serialize eagerly. OutgoingMessageBatch built its contiguous byte[] in its constructor whether or not anything read it. (#​3906)

Aggregate handler workflow unification (#​3907, increment one)

Wolverine has carried two near-identical copies of the aggregate handler workflow — one in Wolverine.Marten, one in Wolverine.Polecat — and improvements had been landing on one copy at a time. This release starts implementing it once, in core.

Nothing is retired and no public API changes. [WriteAggregate], [ReadAggregate], [AggregateHandler], [ConsistentAggregate], Events, MartenOps/PolecatOps and the rest of each integration's surface stay exactly where they are.

What landed:

  • The drift between the two copies is reconciled, taking whichever side was correct rather than merging mechanically. The substantive one: AggregateHandling.DetermineVersionMember now returns MemberInfo? — Marten's copy used a null-forgiving operator that was masking a real null from IAggregateVersioning.VersionMember. Polecat regains AOT annotations it had dropped. Two reflectively-closed codegen frames widen a class constraint to notnull, matching IEventStream<T>'s own declaration; the narrower form threw for a struct aggregate instead of generating the same correct code.
  • IEventSourcingFrameProvider, the store seam — deliberately a sibling of IPersistenceFrameProvider rather than new members on it, so stores without event sourcing never grow no-op aggregate members.
  • The first shared mechanism moved into Wolverine.Persistence.EventSourcing: the event-capture frames and DetermineEventCaptureHandling, all written purely against JasperFx.Events' IEventStream<T>.
  • A reflection test enforcing that no core type shares a simple name with a public type in a Wolverine.<Store> integration, so a CS0104 ambiguity for users is caught by a failing test instead.

The bulk extraction continues in #​3911. Also in this release: #​3908, which pins what [Storage(typeof(...))] actually promises against a Marten ancillary store.

Upstream halves of this work: JasperFx/jasperfx#​648, JasperFx/marten#​5221, JasperFx/polecat#​453.

6.25.5

6.25.5 supersedes the never-published 6.25.4 (its tag and release were retired), so the first two fixes below make their first NuGet appearance here.

Fixes

PostgreSQL dead-letter and outgoing counts are exact for small tables (GH-3885)

The PostgreSQL message-store counts for the dead-letter and outgoing tables now report exact numbers for small tables instead of the estimate that could read as zero right after activity. First staged for 6.25.4; this is its first published release.

The durable inbox routes by endpoint for sticky handlers (GH-3886)

Durable inbox recovery now routes each envelope by its owning endpoint, so sticky-handler ([StickyHandler] / endpoint-scoped) messages recovered from the inbox execute on the endpoint they were received on rather than falling back to the default route. Also first staged for 6.25.4.

Never export empty metrics snapshots + idle-tenant eviction (#​3891)

Wolverine no longer exports metrics snapshots that contain no data, and per-tenant metric state for tenants that have gone idle is evicted after a configurable number of cycles via WolverineOptions.Metrics.TenantIdleEvictionCycles. This is the upstream half of CritterWatch#​963 — at very high tenant counts, idle tenants no longer pin memory or pad every export.

Agents that exhaust node-local auto-restarts are released to a capable peer (GH-3888, #​3896)

When a stalled agent uses up its node-local auto-restart budget, the node now releases the agent so a capable peer can pick it up, instead of retrying forever on the same node. A capability embargo prevents the agent from bouncing straight back to the node that just failed it.

Short-circuiting Before + Finally middleware no longer NREs (GH-3892, #​3895)

Middleware that combines a short-circuiting Before method with a Finally method no longer produces a NullReferenceException at codegen time — and Finally now runs on the short-circuit path, as the middleware contract promises.

Saga diagnostics tolerate an unprovisioned saga table (GH-3887, #​3894)

DatabaseSagaStoreDiagnostics.ReadSagaAsync / ListSagaInstancesAsync treat a missing saga table (Postgres 42P01 / SQL Server 208) as null / empty rather than surfacing a raw undefined-table error. A declared-but-never-persisted saga is a legitimate state, since AddSagaType is optional.

Polecat TransportSchemaName is honored (GH-3884, #​3897)

PolecatIntegration.TransportSchemaName is now actually applied — previously the setting was inert and the transport tables always landed in the default schema.

Improvements

The stalled-agent auto-restart path is testable (#​3890)

The auto-restart path now runs on TimeProvider, making it deterministic under test — with coverage added. Thanks @​erdtsieck!

Message types can be exempted from partitioned processing (GH-3899, #​3902)

MessagePartitioning.ExemptFromPartitionedProcessing<T>() exempts a message type from partitioned (GroupId-keyed) processing — exempt types ride the endpoint's normal parallelism while partitioned types keep strict per-group ordering.

Batched members' DeliverBy expiry is enforced again (GH-3898, #​3903)

Expired members are shed at batch assembly with the normal discard observability, and a whole-batch backstop expires batches whose every member has lapsed.

The sharded execution block deserializes in parallel with ordered emission (GH-3900, #​3904)

The sharded execution block's decompress/deserialize stage now runs N-wide while preserving per-group FIFO byte-for-byte.

... (truncated)

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: WolverineFx
  dependency-version: 6.28.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Aug 24, 2026
@github-actions
github-actions Bot merged commit f2d3f29 into main Aug 24, 2026
2 of 4 checks passed
@github-actions
github-actions Bot deleted the dependabot/nuget/benchmarks/Foundatio.Mediator.Benchmarks/WolverineFx-6.28.2 branch August 24, 2026 22:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment