Trellara correctness report

Deterministic failure proof for Postgres CDC

This static report is generated from Trellara's replayable simulator and curated chaos matrix. It is designed for CI publishing so buyers can inspect the failure boundaries instead of trusting a reliability claim.

OverallPASS
Simulations28
Chaos Scenarios63
Seed20260812

CI Contract

Verification command: cargo test --workspace

Mode: deterministic_failure_matrix

Report Identity

Artifact: docs/correctness-report.html

Report version: 2026-08-mvp

Package version: 0.1.0

Source revision: 2583232ab4f8627ad4a5b0a687dc198a0f6652ac

Source repository: trellara/trellara

Workflow run: https://github.com/trellara/trellara/actions/runs/36459738535

Generated by: trellara chaos report

Freshness check: make verify-correctness-report

Performance Envelope

Quickstart target: 8 minute estimate within 10 minute budget

Default local relay/apply bound: 100 transactions / 100 messages

Stream spill threshold: 1024 changes

Stream spill location: quickstart configs set source.stream_spill_dir to ./target/trellara-spill

Large transaction mode: pgoutput protocol v2 streaming with Trellara manifest and commit marker barriers

Local durability acknowledgement: source acknowledgement advances only after local durable append

Local indexed replay: stream inspection rebuilds missing, stale, or corrupt sidecar indexes from durable log frames and exposes last valid offsets plus seek guidance for replay

Enterprise Proof Review Path

This report is the public failure-evidence leg of the same proof chain exported by trellara pilot-package. Reviewers should connect the deterministic failure matrix to live source, boundary, convergence, and recovery artifacts before approving a production pilot.

Review questionProof surfaceEnterprise gate
Is the source safe to capture?trellara check --config <flow> --format textNo critical slot, WAL retention, replica identity, failover-slot, or subscription conflict blockers
Does CDC preserve transaction boundaries?trellara inspect-transaction --file <envelope.pb> --format textChecksum status is match, affected tables are explicit, manifest boundary_mode names strict chunk or partition semantics, and manifest counts bind to the commit marker
Can a first snapshot hand off to the stream safely?trellara snapshot --config <flow> --run-id <run>Every selected table reaches stream_handoff_ready with a durable handoff watermark
Has the target converged?trellara verify --config <flow>Row counts and checksums match at a caught-up target checkpoint
Can operators recover without silent skips?trellara status --config <flow> --view diagnostics --format textQuarantine, repair-plan, metrics, and replay-ready commands identify the safe next action
Have durable-boundary failure harnesses and observability assertions passed?trellara chaos report --output docs/correctness-report.htmlSource promotion, broker quorum loss, target restart, object-store/catalog split, and 24-hour large-transaction soak all pass with named recovery and metric evidence
Can partitioned scale expose global visibility safely?trellara partition-watermarks --config <flow>Every partition has checkpoint evidence before global current-state visibility advances
Can the proof package be shared and audited?trellara pilot-package --config <flow>proof-bundle.md and manifest.json bind the review chain to SHA-256 digests

Replayable Simulation Suite

Failure pointStatusSeedTransactionsSkipped duplicatesInvariant evidence
publish_ack_losspass202608128/8 applied1cargo test -p trellara-sim publish_ack_loss
crash_after_publish_before_source_ackpass202608138/8 applied1cargo test -p trellara-sim crash_after_publish_before_source_ack
source_failover_after_publish_before_ackpass202608148/8 applied1cargo test -p trellara-sim source_failover_after_publish_before_ack
duplicate_deliverypass202608158/8 applied1cargo test -p trellara-sim duplicate_delivery
target_failure_before_commitpass202608168/8 applied0cargo test -p trellara-sim target_failure_before_commit
target_quarantine_repair_replaypass202608178/8 applied0cargo test -p trellara-sim target_quarantine_repair_replay
checkpoint_failure_during_applypass202608188/8 applied0cargo test -p trellara-sim checkpoint_failure_during_apply
stream_ack_loss_after_applypass202608198/8 applied1cargo test -p trellara-sim stream_ack_loss_after_apply

Snapshot Handoff Simulation Suite

Failure pointStatusSeedTablesPost-snapshot replayInvariant evidence
snapshot_source_crash_during_table_copypass202609124/4 copied6/6 replayedcargo test -p trellara-sim snapshot_source_crash_during_table_copy
snapshot_relay_crash_during_table_copypass202609134/4 copied6/6 replayedcargo test -p trellara-sim snapshot_relay_crash_during_table_copy
snapshot_target_crash_during_table_copypass202609144/4 copied6/6 replayedcargo test -p trellara-sim snapshot_target_crash_during_table_copy
snapshot_duplicate_copy_attemptpass202609154/4 copied6/6 replayedcargo test -p trellara-sim snapshot_duplicate_copy_attempt
snapshot_ddl_during_table_copypass202609164/4 copied6/6 replayedcargo test -p trellara-sim snapshot_ddl_during_table_copy
snapshot_handoff_recorded_before_stream_startpass202609174/4 copied6/6 replayedcargo test -p trellara-sim snapshot_handoff_recorded_before_stream_start

Strict Chunk Simulation Suite

Failure pointStatusSeedChunksDuplicatesApply boundaryInvariant evidence
strict_chunk_relay_crash_after_chunks_before_manifestpass202610124/4 published41 applied after manifestcargo test -p trellara-sim strict_chunk_relay_crash_after_chunks_before_manifest
strict_chunk_relay_crash_after_manifest_before_source_ackpass202610134/4 published01 applied after manifestcargo test -p trellara-sim strict_chunk_relay_crash_after_manifest_before_source_ack
strict_chunk_manifest_arrives_with_missing_chunkpass202610144/4 published01 applied after manifestcargo test -p trellara-sim strict_chunk_manifest_arrives_with_missing_chunk
strict_chunk_manifest_arrives_before_chunkspass202610154/4 published01 applied after manifestcargo test -p trellara-sim strict_chunk_manifest_arrives_before_chunks
strict_chunk_target_crash_after_staging_before_commitpass202610164/4 published01 applied after manifestcargo test -p trellara-sim strict_chunk_target_crash_after_staging_before_commit

Fleet Fan-In Lake Simulation Suite

Failure pointStatusEpochSourcesRowsStateInvariant evidence
fleet_fanin_offline_stores_publish_with_gapspassepoch-00000000013528f89/12 complete, 3 missing, 0 quarantined9 transactions / 9 changes, 9 replayscomplete_with_gapscargo test -p trellara-sim fleet_fanin_offline_stores_publish_with_gaps
fleet_fanin_late_store_recovery_completes_epochpassepoch-00000000013528f912/12 complete, 0 missing, 0 quarantined12 transactions / 12 changes, 12 replayscomplete_with_gaps -> completecargo test -p trellara-sim fleet_fanin_late_store_recovery_completes_epoch
fleet_fanin_duplicate_store_transaction_replaypassepoch-00000000013528fa9/12 complete, 3 missing, 0 quarantined9 transactions / 9 changes, 2 replayscomplete_with_gapscargo test -p trellara-sim fleet_fanin_duplicate_store_transaction_replay
fleet_fanin_conflicting_duplicate_quarantinepassepoch-00000000013528fb8/12 complete, 3 missing, 1 quarantined9 transactions / 9 changes, 1 replaysquarantinedcargo test -p trellara-sim fleet_fanin_conflicting_duplicate_quarantine

Lane D Qualification Suite

Failure pointStatusDurable boundaryTransactionsSoak/loadObservability assertionsInvariant evidence
qualification_source_promotion_while_relay_disconnectedpasssource_failover_slot_to_relay_restart
promoted_source_replays_from_last_durable_ack
12/12 applied, 1 replayedfailure harnesssource_failover_promotion_detected: status reports promoted source identity plus failover slot replay
source_ack_lag_visible: metrics expose acknowledgement lag while relay is disconnected
cargo test -p trellara-sim qualification_source_promotion_while_relay_disconnected
trellara source-safety --config <flow> --format text; trellara relay --config <flow>
qualification_broker_outage_quorum_losspassbroker_quorum_publish_ack
source_ack_waits_for_broker_quorum
12/12 applied, 0 replayedfailure harnessbroker_quorum_unavailable: readyz and metrics mark broker quorum unavailable before source feedback
publish_retry_recovered: publish retry counter increments after quorum is restored
cargo test -p trellara-sim qualification_broker_outage_quorum_loss
trellara status --config <flow> --view alerts --format text; trellara relay --config <flow>
qualification_target_restart_during_applypasstarget_apply_transaction_commit
target_restart_replays_uncheckpointed_apply
12/12 applied, 1 replayedfailure harnesstarget_restart_replay_required: diagnostics name the uncheckpointed apply boundary and replay command
target_checkpoint_not_advanced_early: target checkpoint stays behind until redelivery commits
cargo test -p trellara-sim qualification_target_restart_during_apply
trellara status --config <flow> --view diagnostics --format text; trellara apply --config <flow>
qualification_object_store_success_catalog_timeoutpassobject_store_write_before_catalog_visibility
catalog_timeout_cannot_publish_uncommitted_epoch
12/12 applied, 0 replayedfailure harnesscatalog_commit_pending: lake completeness marks the epoch pending_catalog_commit
catalog_retry_idempotent: catalog retry discovers the existing data-file receipt before release
cargo test -p trellara-sim qualification_object_store_success_catalog_timeout
trellara lake fanin verify --config <flow> --format json
qualification_twenty_four_hour_soak_large_transaction_memory_ceilingpasslarge_transaction_stream_spill_memory_ceiling
soak_large_transactions_stay_within_memory_ceiling
12/12 applied, 0 replayed24h soak, 50000 changes, 64 / 128 MiBsoak_window_completed: qualification records a 24-hour soak window with passing assertions
large_transaction_memory_ceiling: peak relay memory remains below the configured ceiling
cargo test -p trellara-sim qualification_twenty_four_hour_soak_large_transaction_memory_ceiling
trellara performance --config <flow> --format json; trellara chaos report --output docs/correctness-report.html

Curated Failure Matrix

ScenarioStatusBoundaryInvariantSafety propertyProofRecovery
relay_before_broker_publishcoveredstrict_transaction_ordersource_checkpoint_after_broker_acksource durable checkpoint is not advanced, so the transaction is captured againcargo test -p trellara-relay failed_publish_does_not_advance_checkpointautomatic
relay_after_broker_publish_before_source_feedbackcoveredstrict_transaction_ordersource_checkpoint_after_broker_ackduplicate stream delivery is possible, but no committed transaction is missedcargo test -p trellara-relay ambiguous_publish_replays_duplicate_without_advancing_checkpointautomatic
source_failover_after_publish_before_ackcoveredstrict_transaction_order_with_failover_slotfailover_slot_replay_preserves_transaction_boundaryrelay restart on the promoted source may redeliver the last transaction, but downstream dedup preserves exactly-once applycargo test -p trellara-sim source_failover_after_publish_before_ack_recovers_with_duplicate_replaytrellara check --config <flow>
source_failover_slot_unsyncedcoveredsource_failover_readinessfailover_slot_sync_before_promotionsource-safety warns before operators rely on a promoted standby that may not retain the CDC boundarycargo test -p trellara-cli --lib source_safety_warns_when_failover_slot_is_not_syncedtrellara check --config <flow> --format text
source_failover_slot_disabledcoveredsource_failover_readinessfailover_slot_enabled_before_promotionsource-safety reports the disabled failover posture as an explicit recovery boundary before CDC depends on promotioncargo test -p trellara-cli --lib source_safety_warns_when_failover_slot_is_disabled && cargo test -p trellara-cli --lib direct_source_safety_warns_when_failover_slot_is_disabledtrellara check --config <flow> --format text
source_slot_abandoned_idle_timeoutcoveredsource_safety_slot_lifecycleinactive_slot_cleanup_posture_is_explicitsource-safety degrades the flow, names inactive-since metadata, and distinguishes disabled from configured idle_replication_slot_timeout cleanupcargo test -p trellara-cli --lib direct_source_safety_mentions_disabled_idle_slot_timeout && cargo test -p trellara-cli --lib direct_source_safety_surfaces_configured_idle_slot_timeouttrellara-check <source> --format text
broker_publish_failurecoveredstrict_transaction_ordersource_checkpoint_after_broker_ackrelay does not advance source checkpoint without broker acknowledgementcargo test -p trellara-relay failed_publish_does_not_advance_checkpointautomatic
local_stream_index_rebuildcoveredbrokerless_local_streamlocal_index_rebuild_preserves_replay_offsetsthe local stream rebuilds the derived offset index from durable log frames, excludes torn tails, and reports the last valid replay offset plus locate/seek commandscargo test -p trellara-stream-local missing_index_is_rebuilt_for_offset_replay --lib && cargo test -p trellara-stream-local stale_index_discovers_durable_tail_without_truncating --lib && cargo test -p trellara-stream-local inspect_reports_corrupt_index_rebuild --lib && cargo test -p trellara-stream-local inspect_reports_torn_tail_bytes_before_recovery_append --lib && cargo test -p trellara-cli local_stream_inspect_summary_reports_depth_and_pending_messages --libtrellara stream inspect-local --config <flow>
local_stream_publish_ack_after_fsync_durabilitycoveredbrokerless_local_streamsource_ack_after_local_fsync_durabilitya returned publish acknowledgement identifies an offset whose frame, sidecar index entry, and zero-torn-tail inspection state are immediately replayable under default fsync durabilitycargo test -p trellara-stream-local fsync_publish_ack_follows_durable_frame_and_index --libtrellara stream inspect-local --config <flow>
applier_before_target_commitcoveredstrict_transaction_ordertarget_checkpoint_same_transaction_as_applytarget checkpoint and dedup state are not advancedcargo test -p trellara-apply-postgres missing_target_table_fails_closed_without_checkpoint_or_deduptrellara quarantine list --config <flow>
applier_after_target_commit_before_stream_ackcoveredstrict_transaction_ordertransaction_dedup_before_reapplytransaction-level dedup makes redelivery safe and the replay is acknowledgedcargo test -p trellara-apply-postgres apply_worker_replays_safely_when_ack_fails_after_applyautomatic
duplicate_transaction_replaycoveredstrict_transaction_ordertransaction_dedup_before_reapplysecond delivery is skipped without reapplying target changescargo test -p trellara-apply-postgres applies_transaction_once_and_records_checkpointautomatic
target_schema_missingcoveredstrict_transaction_orderfail_closed_target_contracttransaction is quarantined without advancing checkpoint or dedup statecargo test -p trellara-apply-postgres missing_target_table_fails_closed_without_checkpoint_or_deduptrellara quarantine replay-ready --config <flow> --transaction-id <tx> --commit-lsn <lsn>
target_update_delete_zero_rowscoveredstrict_transaction_orderno_silent_target_divergencetransaction is quarantined as no_rows_matched without advancing checkpoint or dedup statecargo test -p trellara-apply-postgres update_delete_zero_row_match_fails_closedtrellara verify --config <flow>; trellara reseed --config <flow>
filtered_reseed_preserves_out_of_scope_rowscoveredfiltered_reseed_repairrow_filter_reseed_scope_is_preservedreseed deletes and replaces only rows matching the configured row_filter while preserving target-owned columns and out-of-scope target rowscargo test -p trellara-verify --test postgres_snapshot_integration postgres_reseed_with_row_filter_replaces_only_matching_target_rowstrellara reseed --config <flow> --table <schema.table>
pgoutput_schema_change_during_streamcoveredpgoutput_relation_metadatasource_schema_fingerprint_fail_closedcapture stops before assembling changes under an unexpected relation schemacargo test -p trellara-pg-capture pgoutput_decoder_fails_closed_on_relation_schema_change && cargo test -p trellara-pg-capture pgoutput_decoder_fails_closed_on_schema_change_during_streamtrellara contract-test --config <flow>
pgoutput_row_without_relation_metadatacoveredpgoutput_relation_metadatarelation_metadata_required_before_rowscapture fails closed before constructing a transaction envelope with unknown column identitycargo test -p trellara-pg-capture pgoutput_decoder_fails_closed_without_relation_metadatatrellara contract-test --config <flow>
source_schema_handoff_recoverycoveredpgoutput_relation_metadataschema_drift_requires_fresh_snapshot_handoffoperators receive a scripted schema-discover, contract-test, fresh snapshot handoff, resume, and verify sequence before CDC continuescargo test -p trellara-cli --lib source_schema_drift_recovery_action_requires_fresh_handoff && cargo test -p trellara-cli --lib contract_test_scripts_schema_handoff_when_pinned_fingerprint_driftstrellara repair-plan --config <flow>
pgoutput_dml_truncate_envelope_mappingcoveredpgoutput_relation_metadatapgoutput_dml_maps_to_transaction_envelopeeach pgoutput operation maps to the expected Trellara envelope operation with relation identity, row images, source ordering, and checksum evidencecargo test -p trellara-pg-capture pgoutput_decoder_tracks_relation_and_insert_tuple && cargo test -p trellara-pg-capture pgoutput_decoder_parses_update_key_and_omits_unchanged_toast && cargo test -p trellara-pg-capture pgoutput_decoder_parses_delete_truncate_and_commit_boundaries && cargo test -p trellara-pg-capture assembler_expands_truncate_relations_in_source_ordertrellara inspect-transaction --file <envelope.pb>
pgoutput_ddl_only_boundarycoveredpgoutput_transaction_boundaryddl_only_transaction_preserves_commit_boundarycapture emits a valid DDL-only transaction envelope with the source transaction id, commit LSN, schema version evidence, and post-DDL DML release gatecargo test -p trellara-pg-capture assembler_emits_ddl_only_transactiontrellara schema ddl-envelope-plan --config <flow> --file <envelope.pb>
pgoutput_mixed_ddl_dml_boundarycoveredpgoutput_transaction_boundarymixed_ddl_dml_transaction_preserves_total_ordercapture keeps DDL and DML in one transaction envelope, preserves source total order, and forces downstream release through the DDL barriercargo test -p trellara-pg-capture assembler_preserves_mixed_ddl_and_dml_total_ordertrellara inspect-transaction --file <envelope.pb>
pgoutput_streamed_transaction_spills_until_commitcoveredpgoutput_protocol_v2_streamingstreamed_transaction_visible_only_after_stream_commitcapture may spill buffered changes to disk, but emits one committed transaction only after STREAM COMMITcargo test -p trellara-pg-capture assembler_emits_streamed_transaction_only_on_stream_commitautomatic
pgoutput_stream_abort_discards_partial_changescoveredpgoutput_protocol_v2_streamingstream_abort_discards_partial_changesaborted stream fragments are removed from memory and spill files, and no partial transaction becomes visiblecargo test -p trellara-pg-capture assembler_drops_aborted_stream_subtransaction_changes && cargo test -p trellara-pg-capture assembler_removes_spill_file_after_stream_aborttrellara relay --config <flow>
pgoutput_keepalive_reports_last_durable_ackcoveredpgoutput_replication_protocolkeepalive_ack_uses_last_durable_boundarythe standby status update repeats only the last durable acknowledged LSN for written, flushed, and applied watermarkscargo test -p trellara-pg-capture standby_status_boundary_uses_only_last_durable_acknowledged_lsn && cargo test -p trellara-pg-capture standby_status_update_payload_reports_acknowledged_lsn_for_every_watermarktrellara status --config <flow> --view report --format text
missing_replica_identitycoveredstrict_transaction_orderpreflight_before_cdc_startpreflight and contract-test fail before relay startscargo test -p trellara-pg-capture capture_preflight_reports_replica_identity_safetytrellara contract-test --config <flow>
default_replica_identity_primary_key_applycoveredstrict_transaction_orderprimary_key_predicate_apply_without_fullUPDATE and DELETE statements use key predicates, so ordinary primary-key tables do not require REPLICA IDENTITY FULLcargo test -p trellara-apply-postgres plans_update_with_key_predicatetrellara contract-test --config <flow>
default_replica_identity_key_change_applycoveredstrict_transaction_orderprimary_key_moves_match_old_key_and_set_new_keyUPDATE statements match the old key from the before image and assign the new key from the after image in the same target transactioncargo test -p trellara-apply-postgres key_changing_update_sets_new_key_and_matches_old_key && cargo test -p trellara-apply-postgres --test postgres_integration key_changing_update_moves_primary_key_with_old_key_predicatetrellara contract-test --config <flow>
unchanged_toast_columns_preservedcoveredpgoutput_relation_metadataabsent_toast_columns_are_unchangedapply plans omit absent or explicit unchanged TOAST markers for non-key columns so target data is preservedcargo test -p trellara-apply-postgres update_omits_absent_non_key_columns_for_unchanged_toast && cargo test -p trellara-apply-postgres update_omits_explicit_unchanged_toast_markertrellara contract-test --config <flow>
snapshot_duplicate_copy_attemptcoveredinitial_snapshot_to_stream_handoffsnapshot_copy_idempotent_by_run_and_tablecompleted table copies are reported as skipped instead of creating a second initial copycargo test -p trellara-sim snapshot_duplicate_copy_attempt_skips_completed_table_before_handoff && cargo test -p trellara-cli completed_snapshot_summary_reuses_handoff_ready_runautomatic
snapshot_incomplete_copy_resumecoveredinitial_snapshot_to_stream_handoffsnapshot_handoff_requires_complete_tablesactive or incomplete table progress is not falsely treated as handoff-readycargo test -p trellara-cli completed_snapshot_summary_requires_terminal_run_and_complete_tablestrellara snapshot --config <flow> --run-id <run>
snapshot_source_crash_during_copycoveredinitial_snapshot_to_stream_handoffsnapshot_source_failure_retries_before_handoffsource copy failure marks the run recoverable, retries the table, and records handoff only after all selected tables are completecargo test -p trellara-sim snapshot_source_crash_during_table_copy_retries_before_handofftrellara snapshot --config <flow> --run-id <run>
snapshot_relay_crash_during_copycoveredinitial_snapshot_to_stream_handoffsnapshot_copy_idempotent_by_tablethe table copy is retried and handoff is recorded only after every selected table is completecargo test -p trellara-sim snapshot_relay_crash_during_table_copy_retries_before_handofftrellara snapshot --config <flow> --run-id <run>
snapshot_target_crash_during_copycoveredinitial_snapshot_to_stream_handoffsnapshot_copy_no_handoff_until_completetarget copy is retried and stream handoff is withheld until convergence proof can include all tablescargo test -p trellara-sim snapshot_target_crash_during_table_copy_retries_before_handofftrellara snapshot --config <flow> --run-id <run>
snapshot_copy_failure_marked_recoverablecoveredinitial_snapshot_to_stream_handoffsnapshot_failure_state_is_durable_before_retrysnapshot run and table progress are marked failed_recoverable before retry, and correctness reports surface the recovery actioncargo test -p trellara-sim snapshot_relay_crash_during_table_copy_retries_before_handoff && cargo test -p trellara-cli --lib snapshot_copy_failure_records_recoverable_run_and_table_state && cargo test -p trellara-cli --lib correctness_report_surfaces_recoverable_snapshot_copy_failuretrellara snapshot --config <flow> --run-id <run>
snapshot_invalid_state_regressioncoveredinitial_snapshot_to_stream_handoffsnapshot_state_machine_monotonic_until_recoverableunsafe backward transitions are rejected unless the run is explicitly marked recoverablecargo test -p trellara-checkpoint snapshot_run_state_rejects_unsafe_backward_transitionstrellara snapshot --config <flow> --run-id <run> --force
snapshot_exported_visibility_boundarycoveredinitial_snapshot_to_stream_handoffsnapshot_copy_uses_exported_lsn_boundaryinitial copy sees only rows visible in the exported snapshot; later writes must arrive through the streamcargo test -p trellara-verify postgres_reseed_imports_exported_source_snapshotautomatic
partition_manifest_missing_chunkcoveredpartitioned_scale_modemanifest_barrier_before_partition_applybarrier reconstruction rejects incomplete, duplicate, or malformed manifest partition boundaries before target applycargo test -p trellara-protocol barrier_reconstruction_rejects_missing_chunks && cargo test -p trellara-protocol barrier_reconstruction_rejects_exact_duplicate_chunks && cargo test -p trellara-protocol barrier_reconstruction_rejects_duplicate_manifest_partitions && cargo test -p trellara-protocol commit_marker_rejects_duplicate_manifest_partitionstrellara partition-watermarks --config <flow>
partition_chunk_routing_header_mismatchcoveredpartitioned_scale_modepartition_chunk_headers_are_apply_trust_boundarystream producers and target appliers reject mismatched partition id, event count, checksum, transaction identity, or unlisted manifest membership before buffering, applying, or acknowledging the chunk, and runtime pending stats expose extra chunk blockerscargo test -p trellara-stream chunk_message_rejects_envelope_transaction_mismatch --lib && cargo test -p trellara-apply-postgres --lib barrier_worker_rejects_chunk_partition_routing_header_mismatch && cargo test -p trellara-apply-postgres --lib barrier_worker_rejects_unlisted_chunk_buffered_before_manifest && cargo test -p trellara-apply-postgres --lib barrier_worker_rejects_unlisted_chunk_after_manifest && cargo test -p trellara-apply-postgres pending_stats_reports_extra_chunks_separately && cargo test -p trellara-stream-local --lib reconstruct_local_barrier_transaction_rejects_chunk_header_payload_mismatchtrellara run --local --verify --config <flow>
partition_commit_marker_ack_ambiguouscoveredpartitioned_scale_modepartition_source_checkpoint_waits_for_commit_marker_acksource durable checkpoint and source feedback do not advance until the partition chunk, manifest, and commit marker are all acknowledgedcargo test -p trellara-relay partitioned_ambiguous_commit_marker_publish_does_not_advance_checkpointtrellara relay --config <flow>
partition_commit_marker_manifest_mismatchcoveredpartitioned_scale_modepartition_commit_marker_matches_manifest_before_applystream producers reject mismatched barrier payload identity; the barrier-aware applier rejects mismatched commit markers before target apply or acknowledgement, and runtime pending stats expose invalid commit-marker blockerscargo test -p trellara-stream manifest_message_rejects_envelope_boundary_mismatch --lib && cargo test -p trellara-stream commit_marker_message_rejects_envelope_boundary_mismatch --lib && cargo test -p trellara-apply-postgres barrier_worker_rejects_mismatched_commit_marker && cargo test -p trellara-apply-postgres pending_stats_reports_invalid_commit_marker_separately && cargo test -p trellara-cli apply_summary_exposes_invalid_commit_marker_blockertrellara status --config <flow> --view report --format text
strict_chunk_manifest_missing_chunkcoveredstrict_chunked_transaction_orderstrict_chunk_manifest_barrier_before_applybarrier reconstruction rejects incomplete large transactions before target applycargo test -p trellara-sim strict_chunk_missing_chunk_waits_for_replay_before_applytrellara status --config <flow> --view report --format text
strict_chunk_out_of_order_arrivalcoveredstrict_chunked_transaction_orderstrict_chunk_manifest_waits_for_completenessbarrier-aware apply buffers the manifest and waits for every chunk before applyingcargo test -p trellara-sim strict_chunk_manifest_before_chunks_waits_for_complete_chunk_settrellara apply --config <flow>
strict_chunk_relay_crash_after_chunks_before_manifestcoveredstrict_chunked_transaction_orderstrict_chunk_manifest_required_before_applytarget waits for the manifest and commit marker barrier, replayed chunks are deduplicated, and no partial transaction is appliedcargo test -p trellara-sim strict_chunk_crash_after_chunks_waits_for_manifest_before_applytrellara relay --config <flow>
strict_chunk_partial_publish_failurecoveredstrict_chunked_transaction_ordersource_checkpoint_waits_for_all_barrier_messagessource durable checkpoint and source feedback do not advance until every chunk, manifest, and commit marker publish succeedscargo test -p trellara-relay strict_chunked_partial_publish_failure_does_not_advance_checkpoint_or_source_acktrellara relay --config <flow>
strict_chunk_relay_crash_after_manifest_before_source_ackcoveredstrict_chunked_transaction_orderstrict_chunk_source_ack_after_manifest_publishsource checkpoint remains behind until the complete chunk set and manifest can be replayed safelycargo test -p trellara-sim strict_chunk_crash_after_manifest_recovers_without_moving_source_ack_earlytrellara relay --config <flow>
strict_chunk_target_crash_after_staging_before_commitcoveredstrict_chunked_transaction_orderstrict_chunk_stage_not_visible_before_target_commituncommitted staged chunks are discarded on restart, the manifest is replayed, and the target applies the transaction exactly oncecargo test -p trellara-sim strict_chunk_target_crash_after_staging_applies_once_after_replaytrellara apply --config <flow>
protocol_property_chunk_manifest_reconstructioncoveredstrict_chunked_or_partitioned_barriermanifest_barriers_reconstruct_source_order_for_all_generated_inputsproperty tests reconstruct every generated strict chunk or partitioned transaction in source order and reject missing chunks with minimized failing reproscargo test -p trellara-protocol strict_chunk_manifest_property_reconstructs_source_order && cargo test -p trellara-protocol partitioned_manifest_property_reconstructs_source_orderautomatic
strict_chunk_checksum_tamperingcoveredstrict_chunked_transaction_orderchunk_checksum_mismatch_fails_closedbarrier reconstruction rejects the transaction before apply when a chunk checksum no longer matches the manifestcargo test -p trellara-protocol barrier_reconstruction_rejects_chunk_checksum_tamperingtrellara status --config <flow> --view report --format text
barrier_conflicting_duplicate_messagescoveredstrict_chunked_or_partitioned_barrierconflicting_duplicate_barrier_messages_fail_closedthe barrier-aware applier rejects conflicting duplicate chunks, manifests, and commit markers before target apply or stream acknowledgementcargo test -p trellara-apply-postgres barrier_worker_rejects_conflicting_duplicate_chunks && cargo test -p trellara-apply-postgres barrier_worker_rejects_conflicting_duplicate_manifests && cargo test -p trellara-apply-postgres barrier_worker_rejects_conflicting_duplicate_commit_markers_before_manifesttrellara status --config <flow> --view report --format text
partition_applier_before_ackcoveredpartitioned_scale_modemanifest_checkpoint_same_transaction_as_applypartition checkpoints and dedup state make redelivery safe without partial visibilitycargo test -p trellara-apply-postgres manifest_envelope_records_partition_checkpoints_atomicallytrellara status --config <flow> --view dashboard --format text
fleet_fanin_offline_stores_publish_with_gapscoveredfleet_fanin_epoch_completenesslake_epoch_gaps_are_explicita publish-with-gaps policy marks missing sources explicitly and only exposes the epoch as complete_with_gapscargo test -p trellara-sim fleet_fanin_offline_stores_publish_with_explicit_gap_statetrellara lake plan --config <flow> --format json
fleet_fanin_late_store_recoverycoveredfleet_fanin_epoch_completenesslate_sources_recompute_epoch_completenesslate source envelopes can recompute the same epoch from complete_with_gaps to complete without double counting prior storescargo test -p trellara-sim fleet_fanin_late_sources_recompute_epoch_to_completetrellara lake plan --config <flow> --format json
fleet_fanin_duplicate_store_replaycoveredfleet_fanin_epoch_completenessfleet_fanin_deduplicates_by_transaction_boundaryidentical source transaction replays are skipped so epoch transaction and change counts stay stablecargo test -p trellara-sim fleet_fanin_duplicate_store_replay_is_deduplicatedautomatic
fleet_fanin_conflicting_duplicate_quarantinecoveredfleet_fanin_epoch_completenessfleet_fanin_conflicting_duplicates_fail_closedconflicting duplicate evidence quarantines the epoch instead of publishing an ambiguous current-state or SCD2 viewcargo test -p trellara-sim fleet_fanin_conflicting_duplicate_quarantines_epochtrellara status --config <flow> --view diagnostics --format text
qualification_source_promotion_while_relay_disconnectedcoveredsource_failover_slot_to_relay_restartpromoted_source_replays_from_last_durable_ackrelay restart on the promoted source replays from the last durable acknowledgement, downstream dedup absorbs the replay, and source acknowledgement lag remains visible while disconnectedcargo test -p trellara-sim qualification_source_promotion_while_relay_disconnectedtrellara check --config <flow> --format text; trellara relay --config <flow>
qualification_broker_outage_quorum_losscoveredbroker_quorum_publish_acksource_ack_waits_for_broker_quorumsource feedback is withheld during quorum loss, publish retry is observable, and acknowledgement advances only after broker quorum returnscargo test -p trellara-sim qualification_broker_outage_quorum_losstrellara status --config <flow> --view alerts --format text; trellara relay --config <flow>
qualification_target_restart_during_applycoveredtarget_apply_transaction_committarget_restart_replays_uncheckpointed_applyuncheckpointed apply state rolls back, redelivery applies the transaction exactly once, and diagnostics name the replay boundarycargo test -p trellara-sim qualification_target_restart_during_applytrellara status --config <flow> --view diagnostics --format text; trellara apply --config <flow>
qualification_object_store_success_catalog_timeoutcoveredobject_store_write_before_catalog_visibilitycatalog_timeout_cannot_publish_uncommitted_epochthe epoch remains pending_catalog_commit, catalog retry discovers the existing object-store receipt, and downstream Spark consumption is held until catalog evidence is durablecargo test -p trellara-sim qualification_object_store_success_catalog_timeouttrellara lake fanin verify --config <flow> --format json
qualification_twenty_four_hour_soak_large_transaction_memory_ceilingcoveredlarge_transaction_stream_spill_memory_ceilingsoak_large_transactions_stay_within_memory_ceilingthe qualification harness records a 24-hour soak window, proves large transactions spill before publish, and asserts peak relay memory stays below the configured ceilingcargo test -p trellara-sim qualification_twenty_four_hour_soak_large_transaction_memory_ceilingtrellara performance --config <flow> --format json; trellara chaos report --output docs/correctness-report.html
snapshot_ddl_during_copycoveredinitial_snapshot_to_stream_handoffsnapshot_contract_before_handoffschema drift withholds handoff until contract refresh and table-copy retry completecargo test -p trellara-sim snapshot_ddl_during_table_copy_withholds_handoff_until_contract_refreshtrellara snapshot --config <flow> --run-id <run> --force
snapshot_handoff_recorded_before_stream_startcoveredinitial_snapshot_to_stream_handoffsnapshot_handoff_before_stream_checkpointpost-snapshot writes are replayed only after the stream restarts from the recorded handoff boundarycargo test -p trellara-sim handoff_recorded_before_stream_start_recovers_before_replaytrellara relay --config <flow>
repair_and_replay_readycoveredstrict_transaction_order_or_partitioned_scale_modeoperator_replay_preserves_transaction_boundarydedup/quarantine state can be cleared so redelivery applies instead of skippingcargo test -p trellara-sim target_quarantine_repair_replay_applies_after_operator_marks_replay_readytrellara quarantine replay-ready --config <flow> --transaction-id <tx> --commit-lsn <lsn>
quarantine_replay_ready_requires_exact_boundarycoveredstrict_transaction_order_or_partitioned_scale_modereplay_ready_requires_exact_quarantine_boundaryreplay-ready fails closed unless the exact quarantined transaction boundary exists, so operators do not clear dedup or request redelivery for the wrong CDC transactioncargo test -p trellara-cli quarantine_replay_ready_refuses_unknown_transaction_boundarytrellara quarantine list --config <flow>