Skip to content

deps: Bump WolverineFx and 3 others - #63

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/Infrastructure/wolverine-de393297e4
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/Infrastructure/wolverine-de393297e4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Updated WolverineFx from 6.33.0 to 6.40.0.

Release notes

Sourced from WolverineFx's releases.

6.40.0

51 commits since V6.39.1. A minor release rather than a patch, because this wave carries new capability and not only fixes.

New capability

  • Capacity-aware agent assignment (#​3959) — agent distribution now accounts for node capacity rather than treating every node as interchangeable. Landed as @​mlh758's #​4297, then hardened in #​4596 and #​4598 to require a real load monitor, stop a shed draining the cluster, and hold pins across every distribution path. Note that the node-load advertisement is PostgreSQL-only until #​4593 lands for the other stores.
  • External table transport for Oracle (#​4482) — implemented by @​Trasvi in #​4558, with follow-ups in #​4574, #​4577 and #​4578. The shared ExternalTableTransportCompliance suite now holds Oracle, PostgreSQL, SQL Server, MySQL and Sqlite to the same bar.
  • A deduplication claim now rides the business transaction on Marten (#​4505), Polecat (#​4570) and Fisher (#​4571). The claim is enlisted in the same unit of work as the handler's own writes instead of being committed on a connection of its own and compensated with a release. A refusal that never commits therefore never claims the id, and there is no release left to mis-order.

Behaviour changes

  • An unknown tenant id answers 404 ProblemDetails instead of 500 (#​4516).
  • Concurrency failures can be mapped to 409 with a one-line opt-in (#​4512).
  • MissingNamedConnectionStringsException stays an InvalidOperationException (#​4527), and every named connection string is now validated in one pass at startup.
  • Wolverine's Kafka error handler composes with the user's instead of replacing it (#​4522).

Exception message wave

#​4511–#​4532 — 18 PRs making the framework's exceptions name a remedy rather than only a symptom: saga failures, handler discovery, SNS/Rabbit MQ/Azure Service Bus/Redis/SignalR configuration problems, oversized messages, unreadable HTTP bodies, and the transports' previously message-less exceptions.

Fixes

  • Stop reading steady-state throughput as a stuck recovery batch, and detect a genuinely stuck outbox from the head of the queue (#​4499).
  • Sweep expired handled envelopes on Cosmos DB, and make DeleteAllHandledAsync work (#​4509).
  • Bound SQLite's two reaps (#​4567).
  • Only ever write ASP.NET Core's endpoint data sources from the composition thread (#​4500).
  • Grandfather a group-affinity candidate per member rather than per partition (#​4562) — @​erdtsieck's #​4563, with blue/green Polecat coverage in #​4576.
  • Declare a module's ancillary store once per namespace (#​4507) — @​uniquelau's #​4508.
  • Apply an ISendMyself published from a projection side effect, on all three stores (#​4556) — built on @​erdtsieck's #​4557.
  • Reject conflicting sending and listening modes on shared listeners (#​4059) — built on @​tmorejon's #​4506.
  • Say "disabled tenant" when that is what happened, and actually refuse one (#​4586).
  • Stop the Redis protocol version header surviving a round trip (#​4595).
  • Do not treat a sticky-bound listen-only endpoint as a local send target (#​4510).
  • Scope Polecat's and Fisher's duplicate-message Discard() to the inbox table (#​4565).

Dependencies

Unchanged from 6.39.1 — Marten 9.35.0, Polecat 5.29.0, Fisher 1.10.0, Weasel 9.32.0, JasperFx 2.74.0. This release ships exactly what its CI has been green against; the pin bump follows separately.

Contributors

Thank you to everyone who contributed code to this release:

6.39.1

A bug fix release. If you use codegen test as a CI gate, run dead letter queues on any broker, or persist with Oracle, there's something in here for you.

codegen test works again

Since 6.37.0, dotnet run -- codegen test has failed on a clean checkout for any application that has message handlers, with one CS0234 per handler:

CS0234: The type or namespace name 'CreateInvoiceHandler2048194527' does not
exist in the namespace 'Internal.Generated.WolverineHandlers'

A lot of you use codegen test as the PR gate on pre-generated code, so this has been quietly breaking builds for two releases. codegen write followed by dotnet build was unaffected, and so was running in TypeLoadMode.Static, which is why it took a while to surface.

Two changes collided. codegen test compiles each generated file into its own assembly so it can enforce service-location rules per file, and 6.37.0 taught the handler registry to root every generated handler by name for native AOT. Compiled in isolation, those names point at types in other in-memory assemblies. HTTP-only applications never saw it, because their rooting only names the registry itself.

The fix is in JasperFx 2.73.2, which this release picks up. Wolverine's CI now runs codegen test against a project with message handlers, which nothing here did before -- the drift gate runs codegen write and the AOT smoke tests run publish, so this whole path had no coverage at all. (#​4486)

Thanks to @​andrevlins, who bisected it across four versions, found the root cause, wrote the upstream fix and validated it against four of his own services.

Dead lettering settles the message exactly once

MoveToErrorQueue always calls CompleteAsync() right after moving a message to the dead letter queue, and it has to: on SQS and Google Pub/Sub the dead letter move only sends a copy, so that trailing call is the only thing that ever settles the original. On Azure Service Bus and RabbitMQ the move is itself a settle, and the second one is redundant.

Azure Service Bus never said which it was doing. On a normal queue the redundant settle came back as "the lock supplied is invalid" and was swallowed -- harmless and invisible. On a session-enabled queue it comes back as SessionLockLost, which forces the AMQP management link closed and reopened before the next session can be accepted. The message always reached the dead letter queue; you paid for it in latency on whatever picked up that queue next. (#​4481)

Two more in the same area:

  • A message dead lettered from a session-specific listener now carries the failure diagnostics that the other three Azure Service Bus listeners attach. That listener was the only one not stamping them. (#​4481)
  • SQS was deleting a message twice when a requeue was retried. The guard meant to prevent it read a flag that nothing ever set, so it had never once fired. Deleting twice is harmless on SQS, but the flag is also how SQS reports whether it settled anything, which the next fix needs. (#​4489)
  • If you set MaximumBrokerRedeliveries, an over-delivered duplicate on SQS or Google Pub/Sub was dead lettered and then left unsettled, so the broker redelivered it and it was dead lettered again -- one copy per redelivery, in the very branch that exists to break that loop. (#​4488)

Oracle can recover incoming messages again

The durability agent threw on every cycle:

System.InvalidCastException: Unable to cast object of type 'System.Decimal' to type 'System.Int32'

Oracle returns count(*) as a NUMBER, which ODP.NET surfaces as decimal or Int64, and GetFieldValueAsync<int>() is a cast rather than a conversion -- it throws on anything but Int32. Recovery of incoming messages was dead for Oracle users. (#​4480)

This is the second time the same provider mapping has broken a durability operation, so the conversion now lives in one place rather than being fixed at each call site as it turns up. Thanks to @​Trasvi for the report, the bisect and the fix.

EF Core DbContext abstractions compile

If you registered an abstraction with WithDbContextAbstraction<IBillingDbContext, BillingDbContext>(), the generated handler came out as:

if (billingDbContext is not BillingDbContext billingDbContext) throw ...

... (truncated)

6.39.0

Two themes in this release: multi-tenancy correctness and modular monolith ergonomics, plus a health-signal fix that will quiet a lot of false alerts.

Declare a module's ancillary store once

Modular monoliths on ancillary stores had to repeat [Storage(typeof(IOrdersStore))] on every handler, endpoint and service in a module -- restating on each type a fact that belongs to the module, where missing one meant quietly committing to the wrong database.

opts.Policies.UseAncillaryStorageFromAssemblyContaining<OrdersModule>(typeof(IOrdersStore));

That covers message handlers, HTTP endpoints and gRPC services in that assembly, for Marten, Polecat and Fisher alike. An explicit [Storage] on a type still wins, so one handler can opt out of its module's default.

For gRPC this is not an ergonomic win but the only thing that works: the gRPC chains never apply chain-modifying attributes, so [Storage] on a gRPC service compiles, looks right, and does nothing. (#​4477)

The stuck-poller health check was mostly crying wolf

This was for CritterWatch

The scheduled-job "poller is stuck" signal counted every scheduled envelope, whether or not it was due yet. A queue holding messages that are not due is a queue doing its job -- so any deliberate delay longer than the check window reported the poller as stuck, and stayed that way. Ordinary retry scheduling has the same shape, which means the signal grew with correct usage.

Measured on a production fleet of 512 sharded message databases: 254 of 271 active alerts -- 94% -- were this one check, across 265 databases. 114 of those were "degraded" over a single envelope scheduled 15 minutes out by an application deliberately waiting for a quiet period.

PersistedCounts.ScheduledDue now counts only envelopes already past their execution time, and the health signal reads that instead. It is an int?, and null means not measured rather than zero: a store that does not report it makes the signal stand down rather than falling back to the undifferentiated count, because falling back is the defect. PostgreSQL implements it as a FILTER on the existing scan, so the due count costs no extra query; the other providers report null and are simply silent here for now. (#​4476)

Tenant message stores were sharing an identity

IMessageStore.Name is a tenant routing cache key, so two tenant stores answering to the same name send one tenant's messages to the other tenant's database.

  • PostgreSQL (#​4468): the sticky queue listener agents resolve their database by tenant id instead of falling through to the default store.
  • SQL Server (#​4471): tenant message stores are named after their database.
  • MySQL (#​4472): tenant stores registered by data source are named, and the queue keeps its sender.

If you run multi-tenanted durable messaging on any of these three, this release is worth taking.

RabbitMQ virtual-host tenants never got publisher confirms

ConfigureChannelCreation(...) reached only the parent transport's channels. Every virtual-host tenant created its channels with PublisherConfirmationsEnabled and PublisherConfirmationTrackingEnabled false regardless, with no public way to set them per tenant.

That matters more than a missing option: without confirmation tracking, BasicPublishAsync returns before the broker can refuse the publish, so the sending agent counts it successful and deletes the envelope from the durable outbox. A refused publish -- an ACCESS_REFUSED after a vhost user loses write permission, say -- silently drops a message whose enrolling transaction has already committed.

Behaviour change worth knowing about: if you call ConfigureChannelCreation and have tenants configured, your tenant channels now get confirms and ConsumerDispatchConcurrency where they previously got neither. Publishing to tenant vhosts gets slower, correctly so.

Thanks to @​outofrange-consulting for a report that arrived with a measurement table and the fix already located. (#​4473)

Ancillary-only hosts picked the wrong persistence strategy

A host registering only an ancillary store through IntegrateWithWolverine<T> registered no codegen extension, so [Entity] and storage-action code silently read an empty in-memory dictionary. Fixed for Marten (#​4464), Polecat (#​4465) and Fisher (#​4466).

Scheduled messages promoted from RavenDb and CosmosDb lost their store

... (truncated)

6.38.0

Eight issues, no breaking changes.

This is a correctness and operability release. Most of it is one shape of bug — something resolved against the wrong scope, which looked right only because two defaults usually coincide — plus the two remaining halves of recurring-schedule operability.

Multi-store and multi-tenancy

  • The multi-tenanted message store no longer swallows batch failures (#​4435). A durable batch spanning several tenants was split across stores, but RetryBlock never rethrows — so a store that refused its share failed silently while the receiver acknowledged the whole batch. Messages no store had accepted were acked and lost. The batch is now split by the resolved store and a failure propagates.

  • Natural keys resolve through the store the chain is routed to (#​4439).

  • Identity types resolve through the store the chain is routed to (#​4441).

    These two are a matched pair: a saga's natural key and its identity type are facts about the store, not about the application. A modular monolith with an ancillary store per module resolved both against the main store, so a saga in module B was looked up with module A's rules.

  • A Wolverine service name reaches JasperFx, so the Event Model canvas stays whole (#​4448). WolverineOptions.ServiceName and JasperFxOptions.ServiceName both name the one running service, but the value only ever travelled one way — so the documented way to name a Wolverine service left the JasperFx side on its default, the entry assembly name. The visible damage was an Event Model canvas splitting in two: Wolverine's source named its model one thing, a store's source named it another, and neither canvas held both halves. It only ever looked correct when a host's assembly name and service name happened to coincide, which is exactly why no test caught it.

Recurring schedules

The remaining core operability gaps from #​4437, which is closed by these two. (Durable last-run state, #​4447, stays closed as not-planned: run state lives in OpenTelemetry, and the operability view belongs in CritterWatch.)

  • Non-UTC recurring schedules now record their tracking row (#​4436). Cronos returns each occurrence carrying the schedule's offset, and Npgsql's timestamptz binder refuses any non-zero offset — so every tick of every zoned schedule threw on the bookkeeping write. Delivery was never affected; only the tracking row was missing. Normalizing in RecurringMessageRecord's init accessors fixes it in one place for all four relational providers.

  • Occurrences carry their schedule and their firing instant (#​4445). The schedule name already reached the handler span. The occurrence instant did not: ScheduledTime is cleared by the scheduled machinery at fire time, so a handler could only learn which firing it was serving by string-parsing the deduplication id. Occurrences now carry a recurring-occurrence header, surfaced as the wolverine.schedule.occurrence trace tag.

    Metrics also gained a schedule.name tag, so the success, failure and effective-time counters can finally be sliced per cron job. It is read off the envelope header rather than set locally, because the metric tag list is never serialized — an occurrence published on one node and handled on another would otherwise reach the counters with no attribution at all. The occurrence instant is deliberately trace-only: one distinct value per firing would make those series unbounded in cardinality.

  • IRecurringScheduleControl.TriggerAsync runs a schedule once, on demand (#​4446). Previously an operator's only option was hand-publishing the message type out of band, which bypasses the occurrence and deduplication machinery entirely. The request is recorded on the schedule's durable tracking row and the agent publishes one occurrence for it on its next pass, so it works from any node — the same reason pause already goes through the store.

    A manual run carries its own deduplication id, so a "run now" issued in the same instant as a scheduled firing is never silently collapsed into it. Triggering a paused schedule is refused: pausing says the schedule must not fire. A trigger is extra rather than a replacement — it leaves the cron cadence and the pending occurrence untouched, and it fires even for a fixed-date schedule whose occurrences have run out.

gRPC

  • A code-first gRPC contract can be registered without [WolverineGrpcService] on the interface (#​4396). A contract you do not own — or one carrying only [ServiceContract] — could not be registered at all. AddWolverineGrpc(grpc => grpc.IncludeCodeFirstContract<IMyService>()) now registers it explicitly. Thanks to @​erikshafer for the PR.

6.37.0

Eight issues, one of them breaking.

⚠️ Breaking change

ServiceCapabilities.EventModel is now an EventModelSetDescriptor rather than a single EventModelDescriptor (#​4424). A host can legitimately assemble several Event Models — each store names its own through StoreOptions.EventModelName, and a modular monolith registers an ancillary store per module — and the export used to fold them all into one named for the service, losing a model's name outright and reporting nothing.

This is a compile break for anything reading that property, and the capabilities wire shape changes with it. A consumer that can only render one model asks .Sole, or folds explicitly with .Collapse() and gets a ModelCollapse hotspot recording what it lost. CritterWatch consumes this shape and has the equivalent fold still to follow.

Everything else in the public surface is additive.

Event Modeling

  • The Automation rule is derived from the model's own links (#​4419). FinishModel carried a private copy of the cross-slice join; it is re-based on EventModelDescriptor.Links, so the pattern Wolverine derives and the arrow a viewer draws cannot disagree. A slice triggered by another slice's event through TriggerType — not only CommandType — is now classified too.
  • ReadsFrom is split out of ReadModelTypes (#​4419). [ReadModel] and [Entity] parameters are things a slice reads; IStorageAction<T> returns are what it produces. They shared one list, which meant the Automation input edge — Event → Read Model → ⚙ Command — could not be drawn at all.
  • Each derived source stamps its own Origin (#​4425). Wolverine registers two sources on the Derived rung, so a disagreement between them used to render as Derived claims X; Derived claims Y, naming neither file. It now reads event-model://wolverine against event-model://wolverine-http.

Native AOT

  • codegen write emits its own [DynamicDependency] rooting (#​4426). Every Native AOT application had to hand-write a rooting block covering the generated registry, every generated handler, every handler class, every message type, and MessageRouter<T>/EmptyMessageRouter<T> closed over each one. Codegen now emits an AotRoots companion anchored by [ModuleInitializer] — an unconditional ILC root — so there is no app-side code at all. Verified by a real PublishAot binary booting and dispatching with the hand-written roots deleted.

Bug fixes

  • An outgoing envelope recovered from an ancillary store is acknowledged there (#​4417). Envelope.Store does not survive persistence, so the acknowledgement fell back to the main store — the ancillary row survived, and the message was recovered, sent and handled again on every restart. Thanks to @​raypet-visma for the diagnosis and the fix sketch.
  • Kafka consumer teardown is bounded (#​4422). _consumer.Close() is a synchronous P/Invoke that can block forever against a degraded broker, so IHost.StopAsync never completed — observed wedged 20+ minutes, past both DrainTimeout and ShutdownTimeout. It now runs under the drain budget on a dedicated thread, and an abandoned teardown suppresses the consumer Dispose rather than destroying a handle another thread still owns.
  • A handler-class OnException returning OutgoingMessages compiles again (#​4416). It failed code generation with "Frame chain is being re-arranged" while the same method on a middleware class worked. Thanks to @​uniquelau for the report and for locating the exact divergence. The error-handling docs gained an example of using the hook to publish messages when the original message fails.

Build & dependencies

  • JasperFx 2.69.3, with Marten 9.35.0, Polecat 5.29.0, Fisher 1.10.0 and Weasel 9.32.0 on that line (#​4421). The committed codegen write output is regenerated and a CICodegenDrift gate now guards it — meaningful only now that the emitted statement order is deterministic. Regenerating surfaced real staleness rather than the expected reordering: six orphaned handler files and four missing registry files.

6.36.0

Heads up when upgrading

  • CircuitBreaker() on a buffered local queue now stops the host from starting with an InvalidListenerConfigurationException (#​4410, #​4412). A buffered local queue can't pause, so the circuit breaker used to be accepted and then silently ignored. Add UseDurableInbox() to the queue, or opts.Policies.UseDurableLocalQueues(), or remove the circuit breaker. Durable local queues and external listeners are unaffected. If you use WolverineFx.AI with DurableQueue = false plus a circuit breaker on the callout queue, this applies to you too.
  • In the Event Model, a message handler forwarded from a gRPC RPC now always derives SlicePattern.Command (#​4413).

New

  • [SlicePattern] declares the Event Model slice pattern of a message handler whose message has no producer in the model, such as a message from another service or a hosted service (#​4395, #​4413). It only fills the gap: an HTTP route, gRPC RPC, schedule or inbound external system still decides the pattern.
  • A Wolverine gRPC client can be injected into a handler (#​4403, #​4409).
  • Each retry attempt's trace span links to the failed attempt before it with an ActivityLink (#​4398, #​4405).

Fixes

  • Agent assignment: each node now checks its assigned agents against the ones actually running and fixes any mismatch (#​3987, #​4404). The follow-up makes assignment deletes owner-scoped, adds claim-if-absent, and hardens the sweep (#​4407, #​4408).
  • Batching: the per-pipeline pending count now counts every batched message, not just listener arrivals (#​4397, #​4406).
  • Security: System.Security.Cryptography.Xml is now 10.0.12, clearing a high-severity advisory (#​4401).

Docs

  • Local queues and buffered endpoints use System.Threading.Channels, not TPL Dataflow (#​4411).
  • Removed the nonexistent EnableNodeAgentSupport() from the exclusive node processing page (#​4414).

6.35.0

Store operation side effects, everywhere

MartenOps covered store / insert / update / delete plus StartStream; anything else meant taking an
IDocumentSession and giving up on the handler being a pure function. All three stores now cover
what their own session API supports.

Op Marten Polecat Fisher
HardDelete, HardDeleteWhere, UndoDeleteWhere ✅ ✅ ✅
UpdateExpectedVersion ✅ ✅ —
UpdateRevision ✅ ✅ ✅
TryUpdateRevision ✅ — ✅
Patch, PatchWhere ✅ — ✅
QueueSqlCommand ✅ ✅ ✅
InsertObjects, DeleteObjects ✅ — —
Append, ArchiveStream ✅ ✅ ✅
UnArchiveStream, TombstoneStream — ✅ —

The gaps are deliberate: each set was checked against that store's own session API rather than copied
across, and an op whose Execute could only throw is worse than the absence of one. Polecat's last
row is the reverse case — two operations Marten has no counterpart for.

Every op also implements ITenantedMartenOp / ITenantedPolecatOp / ITenantedFisherOp, so one
extension scopes any of them while preserving the concrete return type:

MartenOps.ArchiveStream(command.OrderId).ForTenant(command.TenantId);
PolecatOps.StoreMany(items).ForTenant(tenantId).With(oneMore);

Thanks to @​erdtsieck for the Marten half, which is where this started.

Event Modeling: a declared model and the code now meet

Three findings from one comparison of a curated Event Model against the application built from it
(#​4385, #​4386, #​4387):

  • Slices join on handler type. Slice names are the merge key, and a board names a slice for the
    behaviour (ConfirmAppointment) while a derived source names it for the message type or the route.
    An eleven-slice application assembled as twenty-two with no disagreements — not because the sources
    agreed, but because they never met.
  • [Emits(typeof(...))] lets a handler name the events its signature cannot carry. EventsToAppend
    and StartStream erase the element types, so the more idiomatically event-modelled an application
    was, the emptier its derived model got.
  • Pattern is left unclaimed for a message handler. A handler cannot tell a Command from an
    Automation, so a declaration wins the role instead of losing to a guess.

⚠️ Behaviour change: a plain message-handler slice no longer reports pattern: "Command" in
event-model output or the ServiceCapabilities snapshot. Pattern is still derived wherever the
code answers the question — HTTP routes, gRPC RPCs, schedules, external systems, and any slice whose
... (truncated)

6.34.0

Seventy commits since 6.33.0. The bulk of it is a sustained performance wave on the durability
and message-execution paths, alongside a new recurring-schedule feature, Native AOT support that
now boots end to end, and a long run of clustering and transport fixes.

New

  • Recurring cron-scheduled messages. opts.Schedules registers messages to be published on a
    cron expression, coordinated across the cluster so exactly one node fires each occurrence. (#​4307)
  • Azure Service Bus takes a configurable prefix for the system queues it names for itself, plus
    a transport-wide default dead letter queue name. Note the migration hazard called out in the docs
    if you adopt the prefix on an existing deployment. (#​4263, #​4281)
  • Amazon SQS takes the same kind of configurable prefix for the queues it names for itself. (#​4292)
  • The HTTP transport now answers to plain http:// destinations, not just https://.
    ITransport.AdditionalProtocols is the general mechanism, so any transport with legitimately
    multi-scheme addresses can opt in. (#​4200 / #​4379)
  • Broker resource setup honors ResourceMigrationFailureMode. FailFast stays the default and
    keeps resources setup strict; ContinueOnFailures lets a host whose broker topology is
    externally owned log the failures and start. (#​4119 / #​4380)

Performance

The GH-4316 wave, measured on the multi-transport perf rig rather than by inspection. Highlights:

  • Recovery poll and handled-cleanup get indexes they can actually use — three partial indexes on
    PostgreSQL and SQL Server, 37ms down to 0.04ms on the measured query. (#​4336)
  • Batched outbox stores for Oracle, RavenDB and Cosmos DB — 13.1x on Oracle, 61.4x on
    RavenDB. (#​4369 / #​4370)
  • Insert-side coalescing of the last un-batched per-message durability round trips: +24.5%
    throughput and 26% lower publish latency where the application publishes concurrently. (#​4319 / #​4368)
  • Fixed-arity batched inserts on PostgreSQL (1.35x) and pooled Envelope bodies above the LOH
    threshold
    (13.5x at 100KB, with Gen1/Gen2 collections gone). (#​4320, #​4333)
  • Batched durability commands are chunked under each provider's parameter ceiling, so a large
    transaction no longer trips SQL Server's 2100-parameter limit. (#​4375 / #​4376)
  • Per-message allocation and lookup trims across routing, the send path, the execution pipeline,
    header handling, and metric accumulation. DateTimeOffset.Now is gone from the per-message paths.
    (#​4322, #​4323, #​4324, #​4325, #​4326, #​4328, #​4335)
  • Idle polling stops hammering (#​4321); the database queue transports drop their per-poll temp
    tables (#​4334); SQL Server metrics counts come from index metadata instead of three full scans
    (#​4318); Redis Streams gains batched durable arrival, measured at +159% (#​4329).

Two changes measured negative on the rig and were reverted rather than shipped — the Azure Service
Bus prefetch default and the coalescer's Queue shape. Both are recorded so they are not revisited.

Native AOT

A Wolverine application now completes a Native AOT publish and boots through its own bootstrap.
(#​4287, #​4298, #​4301, #​4305). A Native AOT app with any external transport used to die building its
first route — fixed in #​4232 / #​4378. The AOT publish smoke test hard-asserts a full boot.

Clustering, agents and durability

... (truncated)

Commits viewable in compare view.

Updated WolverineFx.EntityFrameworkCore from 6.33.0 to 6.40.0.

Release notes

Sourced from WolverineFx.EntityFrameworkCore's releases.

6.40.0

51 commits since V6.39.1. A minor release rather than a patch, because this wave carries new capability and not only fixes.

New capability

  • Capacity-aware agent assignment (#​3959) — agent distribution now accounts for node capacity rather than treating every node as interchangeable. Landed as @​mlh758's #​4297, then hardened in #​4596 and #​4598 to require a real load monitor, stop a shed draining the cluster, and hold pins across every distribution path. Note that the node-load advertisement is PostgreSQL-only until #​4593 lands for the other stores.
  • External table transport for Oracle (#​4482) — implemented by @​Trasvi in #​4558, with follow-ups in #​4574, #​4577 and #​4578. The shared ExternalTableTransportCompliance suite now holds Oracle, PostgreSQL, SQL Server, MySQL and Sqlite to the same bar.
  • A deduplication claim now rides the business transaction on Marten (#​4505), Polecat (#​4570) and Fisher (#​4571). The claim is enlisted in the same unit of work as the handler's own writes instead of being committed on a connection of its own and compensated with a release. A refusal that never commits therefore never claims the id, and there is no release left to mis-order.

Behaviour changes

  • An unknown tenant id answers 404 ProblemDetails instead of 500 (#​4516).
  • Concurrency failures can be mapped to 409 with a one-line opt-in (#​4512).
  • MissingNamedConnectionStringsException stays an InvalidOperationException (#​4527), and every named connection string is now validated in one pass at startup.
  • Wolverine's Kafka error handler composes with the user's instead of replacing it (#​4522).

Exception message wave

#​4511–#​4532 — 18 PRs making the framework's exceptions name a remedy rather than only a symptom: saga failures, handler discovery, SNS/Rabbit MQ/Azure Service Bus/Redis/SignalR configuration problems, oversized messages, unreadable HTTP bodies, and the transports' previously message-less exceptions.

Fixes

  • Stop reading steady-state throughput as a stuck recovery batch, and detect a genuinely stuck outbox from the head of the queue (#​4499).
  • Sweep expired handled envelopes on Cosmos DB, and make DeleteAllHandledAsync work (#​4509).
  • Bound SQLite's two reaps (#​4567).
  • Only ever write ASP.NET Core's endpoint data sources from the composition thread (#​4500).
  • Grandfather a group-affinity candidate per member rather than per partition (#​4562) — @​erdtsieck's #​4563, with blue/green Polecat coverage in #​4576.
  • Declare a module's ancillary store once per namespace (#​4507) — @​uniquelau's #​4508.
  • Apply an ISendMyself published from a projection side effect, on all three stores (#​4556) — built on @​erdtsieck's #​4557.
  • Reject conflicting sending and listening modes on shared listeners (#​4059) — built on @​tmorejon's #​4506.
  • Say "disabled tenant" when that is what happened, and actually refuse one (#​4586).
  • Stop the Redis protocol version header surviving a round trip (#​4595).
  • Do not treat a sticky-bound listen-only endpoint as a local send target (#​4510).
  • Scope Polecat's and Fisher's duplicate-message Discard() to the inbox table (#​4565).

Dependencies

Unchanged from 6.39.1 — Marten 9.35.0, Polecat 5.29.0, Fisher 1.10.0, Weasel 9.32.0, JasperFx 2.74.0. This release ships exactly what its CI has been green against; the pin bump follows separately.

Contributors

Thank you to everyone who contributed code to this release:

6.39.1

A bug fix release. If you use codegen test as a CI gate, run dead letter queues on any broker, or persist with Oracle, there's something in here for you.

codegen test works again

Since 6.37.0, dotnet run -- codegen test has failed on a clean checkout for any application that has message handlers, with one CS0234 per handler:

CS0234: The type or namespace name 'CreateInvoiceHandler2048194527' does not
exist in the namespace 'Internal.Generated.WolverineHandlers'

A lot of you use codegen test as the PR gate on pre-generated code, so this has been quietly breaking builds for two releases. codegen write followed by dotnet build was unaffected, and so was running in TypeLoadMode.Static, which is why it took a while to surface.

Two changes collided. codegen test compiles each generated file into its own assembly so it can enforce service-location rules per file, and 6.37.0 taught the handler registry to root every generated handler by name for native AOT. Compiled in isolation, those names point at types in other in-memory assemblies. HTTP-only applications never saw it, because their rooting only names the registry itself.

The fix is in JasperFx 2.73.2, which this release picks up. Wolverine's CI now runs codegen test against a project with message handlers, which nothing here did before -- the drift gate runs codegen write and the AOT smoke tests run publish, so this whole path had no coverage at all. (#​4486)

Thanks to @​andrevlins, who bisected it across four versions, found the root cause, wrote the upstream fix and validated it against four of his own services.

Dead lettering settles the message exactly once

MoveToErrorQueue always calls CompleteAsync() right after moving a message to the dead letter queue, and it has to: on SQS and Google Pub/Sub the dead letter move only sends a copy, so that trailing call is the only thing that ever settles the original. On Azure Service Bus and RabbitMQ the move is itself a settle, and the second one is redundant.

Azure Service Bus never said which it was doing. On a normal queue the redundant settle came back as "the lock supplied is invalid" and was swallowed -- harmless and invisible. On a session-enabled queue it comes back as SessionLockLost, which forces the AMQP management link closed and reopened before the next session can be accepted. The message always reached the dead letter queue; you paid for it in latency on whatever picked up that queue next. (#​4481)

Two more in the same area:

  • A message dead lettered from a session-specific listener now carries the failure diagnostics that the other three Azure Service Bus listeners attach. That listener was the only one not stamping them. (#​4481)
  • SQS was deleting a message twice when a requeue was retried. The guard meant to prevent it read a flag that nothing ever set, so it had never once fired. Deleting twice is harmless on SQS, but the flag is also how SQS reports whether it settled anything, which the next fix needs. (#​4489)
  • If you set MaximumBrokerRedeliveries, an over-delivered duplicate on SQS or Google Pub/Sub was dead lettered and then left unsettled, so the broker redelivered it and it was dead lettered again -- one copy per redelivery, in the very branch that exists to break that loop. (#​4488)

Oracle can recover incoming messages again

The durability agent threw on every cycle:

System.InvalidCastException: Unable to cast object of type 'System.Decimal' to type 'System.Int32'

Oracle returns count(*) as a NUMBER, which ODP.NET surfaces as decimal or Int64, and GetFieldValueAsync<int>() is a cast rather than a conversion -- it throws on anything but Int32. Recovery of incoming messages was dead for Oracle users. (#​4480)

This is the second time the same provider mapping has broken a durability operation, so the conversion now lives in one place rather than being fixed at each call site as it turns up. Thanks to @​Trasvi for the report, the bisect and the fix.

EF Core DbContext abstractions compile

If you registered an abstraction with WithDbContextAbstraction<IBillingDbContext, BillingDbContext>(), the generated handler came out as:

if (billingDbContext is not BillingDbContext billingDbContext) throw ...

... (truncated)

6.39.0

Two themes in this release: multi-tenancy correctness and modular monolith ergonomics, plus a health-signal fix that will quiet a lot of false alerts.

Declare a module's ancillary store once

Modular monoliths on ancillary stores had to repeat [Storage(typeof(IOrdersStore))] on every handler, endpoint and service in a module -- restating on each type a fact that belongs to the module, where missing one meant quietly committing to the wrong database.

opts.Policies.UseAncillaryStorageFromAssemblyContaining<OrdersModule>(typeof(IOrdersStore));

That covers message handlers, HTTP endpoints and gRPC services in that assembly, for Marten, Polecat and Fisher alike. An explicit [Storage] on a type still wins, so one handler can opt out of its module's default.

For gRPC this is not an ergonomic win but the only thing that works: the gRPC chains never apply chain-modifying attributes, so [Storage] on a gRPC service compiles, looks right, and does nothing. (#​4477)

The stuck-poller health check was mostly crying wolf

This was for CritterWatch

The scheduled-job "poller is stuck" signal counted every scheduled envelope, whether or not it was due yet. A queue holding messages that are not due is a queue doing its job -- so any deliberate delay longer than the check window reported the poller as stuck, and stayed that way. Ordinary retry scheduling has the same shape, which means the signal grew with correct usage.

Measured on a production fleet of 512 sharded message databases: 254 of 271 active alerts -- 94% -- were this one check, across 265 databases. 114 of those were "degraded" over a single envelope scheduled 15 minutes out by an application deliberately waiting for a quiet period.

PersistedCounts.ScheduledDue now counts only envelopes already past their execution time, and the health signal reads that instead. It is an int?, and null means not measured rather than zero: a store that does not report it makes the signal stand down rather than falling back to the undifferentiated count, because falling back is the defect. PostgreSQL implements it as a FILTER on the existing scan, so the due count costs no extra query; the other providers report null and are simply silent here for now. (#​4476)

Tenant message stores were sharing an identity

IMessageStore.Name is a tenant routing cache key, so two tenant stores answering to the same name send one tenant's messages to the other tenant's database.

  • PostgreSQL (#​4468): the sticky queue listener agents resolve their database by tenant id instead of falling through to the default store.
  • SQL Server (#​4471): tenant message stores are named after their database.
  • MySQL (#​4472): tenant stores registered by data source are named, and the queue keeps its sender.

If you run multi-tenanted durable messaging on any of these three, this release is worth taking.

RabbitMQ virtual-host tenants never got publisher confirms

ConfigureChannelCreation(...) reached only the parent transport's channels. Every virtual-host tenant created its channels with PublisherConfirmationsEnabled and PublisherConfirmationTrackingEnabled false regardless, with no public way to set them per tenant.

That matters more than a missing option: without confirmation tracking, BasicPublishAsync returns before the broker can refuse the publish, so the sending agent counts it successful and deletes the envelope from the durable outbox. A refused publish -- an ACCESS_REFUSED after a vhost user loses write permission, say -- silently drops a message whose enrolling transaction has already committed.

Behaviour change worth knowing about: if you call ConfigureChannelCreation and have tenants configured, your tenant channels now get confirms and ConsumerDispatchConcurrency where they previously got neither. Publishing to tenant vhosts gets slower, correctly so.

Thanks to @​outofrange-consulting for a report that arrived with a measurement table and the fix already located. (#​4473)

Ancillary-only hosts picked the wrong persistence strategy

A host registering only an ancillary store through IntegrateWithWolverine<T> registered no codegen extension, so [Entity] and storage-action code silently read an empty in-memory dictionary. Fixed for Marten (#​4464), Polecat (#​4465) and Fisher (#​4466).

Scheduled messages promoted from RavenDb and CosmosDb lost their store

... (truncated)

6.38.0

Eight issues, no breaking changes.

This is a correctness and operability release. Most of it is one shape of bug — something resolved against the wrong scope, which looked right only because two defaults usually coincide — plus the two remaining halves of recurring-schedule operability.

Multi-store and multi-tenancy

  • The multi-tenanted message store no longer swallows batch failures (#​4435). A durable batch spanning several tenants was split across stores, but RetryBlock never rethrows — so a store that refused its share failed silently while the receiver acknowledged the whole batch. Messages no store had accepted were acked and lost. The batch is now split by the resolved store and a failure propagates.

  • Natural keys resolve through the store the chain is routed to (#​4439).

  • Identity types resolve through the store the chain is routed to (#​4441).

    These two are a matched pair: a saga's natural key and its identity type are facts about the store, not about the application. A modular monolith with an ancillary store per module resolved both against the main store, so a saga in module B was looked up with module A's rules.

  • A Wolverine service name reaches JasperFx, so the Event Model canvas stays whole (#​4448). WolverineOptions.ServiceName and JasperFxOptions.ServiceName both name the one running service, but the value only ever travelled one way — so the documented way to name a Wolverine service left the JasperFx side on its default, the entry assembly name. The visible damage was an Event Model canvas splitting in two: Wolverine's source named its model one thing, a store's source named it another, and neither canvas held both halves. It only ever looked correct when a host's assembly name and service name happened to coincide, which is exactly why no test caught it.

Recurring schedules

The remaining core operability gaps from #​4437, which is closed by these two. (Durable last-run state, #​4447, stays closed as not-planned: run state lives in OpenTelemetry, and the operability view belongs in CritterWatch.)

  • Non-UTC recurring schedules now record their tracking row (#​4436). Cronos returns each occurrence carrying the schedule's offset, and Npgsql's timestamptz binder refuses any non-zero offset — so every tick of every zoned schedule threw on the bookkeeping write. Delivery was never affected; only the tracking row was missing. Normalizing in RecurringMessageRecord's init accessors fixes it in one place for all four relational providers.

  • Occurrences carry their schedule and their firing instant (#​4445). The schedule name already reached the handler span. The occurrence instant did not: ScheduledTime is cleared by the scheduled machinery at fire time, so a handler could only learn which firing it was serving by string-parsing the deduplication id. Occurrences now carry a recurring-occurrence header, surfaced as the wolverine.schedule.occurrence trace tag.

    Metrics also gained a schedule.name tag, so the success, failure and effective-time counters can finally be sliced per cron job. It is read off the envelope header rather than set locally, because the metric tag list is never serialized — an occurrence published on one node and handled on another would otherwise reach the counters with no attribution at all. The occurrence instant is deliberately trace-only: one distinct value per firing would make those series unbounded in cardinality.

  • IRecurringScheduleControl.TriggerAsync runs a schedule once, on demand (#​4446). Previously an operator's only option was hand-publishing the message type out of band, which bypasses the occurrence and deduplication machinery entirely. The request is recorded on the schedule's durable tracking row and the agent publishes one occurrence for it on its next pass, so it works from any node — the same reason pause already goes through the store.

    A manual run carries its own deduplication id, so a "run now" issued in the same instant as a scheduled firing is never silently collapsed into it. Triggering a paused schedule is refused: pausing says the schedule must not fire. A trigger is extra rather than a replacement — it leaves the cron cadence and the pending occurrence untouched, and it fires even for a fixed-date schedule whose occurrences have run out.

gRPC

  • A code-first gRPC contract can be registered without [WolverineGrpcService] on the interface (#​4396). A contract you do not own — or one carrying only [ServiceContract] — could not be registered at all. AddWolverineGrpc(grpc => grpc.IncludeCodeFirstContract<IMyService>()) now registers it explicitly. Thanks to @​erikshafer for the PR.

6.37.0

Eight issues, one of them breaking.

⚠️ Breaking change

ServiceCapabilities.EventModel is now an EventModelSetDescriptor rather than a single EventModelDescriptor (#​4424). A host can legitimately assemble several Event Models — each store names its own through StoreOptions.EventModelName, and a modular monolith registers an ancillary store per module — and the export used to fold them all into one named for the service, losing a model's name outright and reporting nothing.

This is a compile break for anything reading that property, and the capabilities wire shape changes with it. A consumer that can only render one model asks .Sole, or folds explicitly with .Collapse() and gets a ModelCollapse hotspot recording what it lost. CritterWatch consumes this shape and has the equivalent fold still to follow.

Everything else in the public surface is additive.

Event Modeling

  • The Automation rule is derived from the model's own links (#​4419). FinishModel carried a private copy of the cross-slice join; it is re-based on EventModelDescriptor.Links, so the pattern Wolverine derives and the arrow a viewer draws cannot disagree. A slice triggered by another slice's event through TriggerType — not only CommandType — is now classified too.
  • ReadsFrom is split out of ReadModelTypes (#​4419). [ReadModel] and [Entity] parameters are things a slice reads; IStorageAction<T> returns are what it produces. They shared one list, which meant the Automation input edge — Event → Read Model → ⚙ Command — could not be drawn at all.
  • Each derived source stamps its own Origin (#​4425). Wolverine registers two sources on the Derived rung, so a disagreement between them used to render as Derived claims X; Derived claims Y, naming neither file. It now reads event-model://wolverine against event-model://wolverine-http.

Native AOT

  • codegen write emits its own [DynamicDependency] rooting (#​4426). Every Native AOT application had to hand-write a rooting block covering the generated registry, every generated handler, every handler class, every message type, and MessageRouter<T>/EmptyMessageRouter<T> closed over each one. Codegen now emits an AotRoots companion anchored by [ModuleInitializer] — an unconditional ILC root — so there is no app-side code at all. Verified by a real PublishAot binary booting and dispatching with the hand-written roots deleted.

Bug fixes

  • An outgoing envelope recovered from an ancillary store is acknowledged there (#​4417). Envelope.Store does not survive persistence, so the acknowledgement fell back to the main store — the ancillary row survived, and the message was recovered, sent and handled again on every restart. Thanks to @​raypet-visma for the diagnosis and the fix sketch.
  • Kafka consumer teardown is bounded (#​4422). _consumer.Close() is a synchronous P/Invoke that can block forever against a degraded broker, so IHost.StopAsync never completed — observed wedged 20+ minutes, past both DrainTimeout and ShutdownTimeout. It now runs under the drain budget on a dedicated thread, and an abandoned teardown suppresses the consumer Dispose rather than destroying a handle another thread still owns.
  • A handler-class OnException returning OutgoingMessages compiles again (#​4416). It failed code generation with "Frame chain is being re-arranged" while the same method on a middleware class worked. Thanks to @​uniquelau for the report and for locating the exact divergence. The error-handling docs gained an example of using the hook to publish messages when the original message fails.

Build & dependencies

  • JasperFx 2.69.3, with Marten 9.35.0, Polecat 5.29.0, Fisher 1.10.0 and Weasel 9.32.0 on that line (#​4421). The committed codegen write output is regenerated and a CICodegenDrift gate now guards it — meaningful only now that the emitted statement order is deterministic. Regenerating surfaced real staleness rather than the expected reordering: six orphaned handler files and four missing registry files.

6.36.0

Heads up when upgrading

  • CircuitBreaker() on a buffered local queue now stops the host from starting with an InvalidListenerConfigurationException (#​4410, #​4412). A buffered local queue can't pause, so the circuit breaker used to be accepted and then silently ignored. Add UseDurableInbox() to the queue, or opts.Policies.UseDurableLocalQueues(), or remove the circuit breaker. Durable local queues and external listeners are unaffected. If you use WolverineFx.AI with DurableQueue = false plus a circuit breaker on the callout queue, this applies to you too.
  • In the Event Model, a message handler forwarded from a gRPC RPC now always derives SlicePattern.Command (#​4413).

New

  • [SlicePattern] declares the Event Model slice pattern of a message handler whose message has no producer in the model, such as a message from another service or a hosted service (#​4395, #​4413). It only fills the gap: an HTTP route, gRPC RPC, schedule or inbound external system still decides the pattern.
  • A Wolverine gRPC client can be injected into a handler (#​4403, #​4409).
  • Each retry attempt's trace span links to the failed attempt before it with an ActivityLink (#​4398, #​4405).

Fixes

  • Agent assignment: each node now checks its assigned agents against the ones actually running and fixes any mismatch (#​3987, #​4404). The follow-up makes assignment deletes owner-scoped, adds claim-if-absent, and hardens the sweep (#​4407, #​4408).
  • Batching: the per-pipeline pending count now counts every batched message, not just listener arrivals (#​4397, #​4406).
  • Security: System.Security.Cryptography.Xml is now 10.0.12, clearing a high-severity advisory (#​4401).

Docs

  • Local queues and buffered endpoints use System.Threading.Channels, not TPL Dataflow (#​4411).
  • Removed the nonexistent EnableNodeAgentSupport() from the exclusive node processing page (#​4414).

6.35.0

Store operation side effects, everywhere

MartenOps covered store / insert / update / delete plus StartStream; anything else meant taking an
IDocumentSession and giving up on the handler being a pure function. All three stores now cover
what their own session API supports.

Op Marten Polecat Fisher
HardDelete, HardDeleteWhere, UndoDeleteWhere ✅ ✅ ✅
UpdateExpectedVersion ✅ ✅ —
UpdateRevision ✅ ✅ ✅
TryUpdateRevision ✅ — ✅
Patch, PatchWhere ✅ — ✅
QueueSqlCommand ✅ ✅ ✅
InsertObjects, DeleteObjects ✅ — —
Append, ArchiveStream ✅ ✅ ✅
UnArchiveStream, TombstoneStream — ✅ —

The gaps are deliberate: each set was checked against that store's own session API rather than copied
across, and an op whose Execute could only throw is worse than the absence of one. Polecat's last
row is the reverse case — two operations Marten has no counterpart for.

Every op also implements ITenantedMartenOp / ITenantedPolecatOp / ITenantedFisherOp, so one
extension scopes any of them while preserving the concrete return type:

MartenOps.ArchiveStream(command.OrderId).ForTenant(command.TenantId);
PolecatOps.StoreMany(items).ForTenant(tenantId).With(oneMore);

Thanks to @​erdtsieck for the Marten half, which is where this started.

Event Modeling: a declared model and the code now meet

Three findings from one comparison of a curated Event Model against the application built from it
(#​4385, #​4386, #​4387):

  • Slices join on handler type. Slice names are the merge key, and a board names a slice for the
    behaviour (ConfirmAppointment) while a derived source names it for the message type or the route.
    An eleven-slice application assembled as twenty-two with no disagreements — not because the sources
    agreed, but because they never met.
  • [Emits(typeof(...))] lets a handler name the events its signature cannot carry. EventsToAppend
    and StartStream erase the element types, so the more idiomatically event-modelled an application
    was, the emptier its derived model got.
  • Pattern is left unclaimed for a message handler. A handler cannot tell a Command from an
    Automation, so a declaration wins the role instead of losing to a guess.

⚠️ Behaviour change: a plain message-handler slice no longer reports pattern: "Command" in
event-model output or the ServiceCapabilities snapshot. Pattern is still derived wherever the
code answers the question — HTTP routes, gRPC RPCs, schedules, external systems, and any slice whose
... (truncated)

6.34.0

Seventy commits since 6.33.0. The bulk of it is a sustained performance wave on th...

Description has been truncated

Bumps WolverineFx from 6.33.0 to 6.40.0
Bumps WolverineFx.EntityFrameworkCore from 6.33.0 to 6.40.0
Bumps WolverineFx.Postgresql from 6.33.0 to 6.40.0
Bumps WolverineFx.RuntimeCompilation from 6.33.0 to 6.40.0

---
updated-dependencies:
- dependency-name: WolverineFx
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: wolverine
- dependency-name: WolverineFx.EntityFrameworkCore
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: wolverine
- dependency-name: WolverineFx.Postgresql
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: wolverine
- dependency-name: WolverineFx.RuntimeCompilation
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: wolverine
- dependency-name: WolverineFx.RuntimeCompilation
  dependency-version: 6.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: wolverine
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Type: dependency updates (deps) labels Sep 27, 2026
@github-actions github-actions Bot added backend Area: .NET backend and its tests worker Area: the job worker host labels Sep 27, 2026
@Surentz Surentz closed this Sep 27, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/nuget/src/Infrastructure/wolverine-de393297e4 branch September 27, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend Area: .NET backend and its tests dependencies Type: dependency updates (deps) .NET Pull requests that update .NET code worker Area: the job worker host

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant