Repository navigation
fix(membership): preserve canonical membership views - #11296
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
One or more issues must be addressed before approval.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
What changed in this PR
Preserves membership snapshot invariants across provider reads, cleanup, development-table resets, and gossip cancellation.
Changes:
- Validates same-version membership fields while allowing heartbeat advancement and inactive cleanup.
- Adds development-provider refresh and version rollback handling.
- Expands regression coverage for snapshots, resets, and cancellation.
| File | Description |
|---|---|
| test/Orleans.Core.Tests/Membership/MembershipTableSnapshotTests.cs | Updated as part of this pull request. |
| test/Orleans.Core.Tests/Membership/MembershipTableManagerTests.cs | Updated as part of this pull request. |
| src/Orleans.Runtime/MembershipService/MembershipTableManager.cs | Updated as part of this pull request. |
| src/Orleans.Core/SystemTargetInterfaces/IMembershipTable.cs | Updated as part of this pull request. |
| src/Orleans.Core/Runtime/MembershipTableSnapshot.cs | Updated as part of this pull request. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Code coverage
Report-only conclusion: improved. The current-main baseline is commit Coverage combines every CI test matrix job, including providers, CodeGen, .NET 8/10, Linux, Windows, and macOS, using canonical physical source and branch identities. The comparison remains report-only while normal line and branch variance is calibrated. Coverage details |

The membership system provides monotonically versioned canonical membership views. Per-silo
IAmAliveTimeadvances independently of the view version, and local snapshots can compact rows which were already Dead.This change gives table reads and peer snapshots one merge rule: preserve accepted versioned fields at the same version, take versioned fields from newer views, and retain the maximum observed
IAmAliveTime. Successor detection relies on those canonical-field guarantees. A same-version snapshot can advance liveness or prune previously Dead rows while retaining every non-Dead row. Adding or replacing a row requires a newer version. Peer-snapshot application observes caller cancellation before publication.Losing the development primary's in-memory table invalidates the cluster.
SystemTargetBasedMembershipTabledirectly invokesIFatalErrorHandlerand rejects a row or full-table read whose version is below the membership version known before the read began. Capturing that version before the read preserves correct handling of overlapping reads. Ordinary gossip and shutdown behavior remain in place.Focused regressions cover same-version Dead-only pruning, retained canonical fields, maximum liveness timestamps, cancellation, and fatal rollback. Provider-level versioned compaction and its conformance suite remain separate work; this PR specifies snapshot acceptance. Documentation records the snapshot and cluster-lifetime guarantees. This is a main-based prerequisite for #10236.