Validation evidence¶
Shared regex and Data Masking replacement acceptance (2026-09-23)¶
Extracted the existing Validation translators and unchanged Unicode 16.0 property data into the optional commons/regex module. Validation delegates both payload matching and strict property overlap checks, while Data Masking uses its existing replacement callback. Root Commons and plain masking retain dependency isolation.
Verified 7,671 Node v22.21.1 replacement cases, 19 invalid pattern/flag cases, 30 actual TypeScript v2.35.0 Data Masking compositions and all 23,071 existing Validation cases. Added native concurrency and operational-error tests. Differential cases exposed and corrected multiline Unicode line terminators, legacy case canonicalization, word boundaries and backend-only identity escapes.
The initial full packaged run accepted 24 modules before Validation failed to compile: schema_path.go still referenced two private character predicates from the extracted regex file. Its URI encoding now owns the equivalent inline character test. A continuation checked the six affected/remaining modules and four consumers, without rerunning already accepted modules. Combined acceptance covers 30 modules and 27 standalone consumers, with GOWORK=off, tests/vet/tidy and dependency isolation. MODULE_ACCEPTANCE_REGEX.json records sessions checkpoint-10 and checkpoint-01 and verifies every current non-documentation file against its tested archive. Documentation-only differences are enumerated. MODULE_ACCEPTANCE.json remains the previous uninterrupted full run; MODULE_ACCEPTANCE_SCOPED.json records the six-module continuation.
The runtime command reused these checks with --skip-module-checks, rebuilt normal/streaming handlers for Linux amd64 and arm64 with CGO_ENABLED=0, and passed 856/856 RIE assertions plus 95/95 real-Go-SDK/local-Runtime-API streaming checks. Saved Batch artifacts pass 14/14. Nine added runtime assertions cover named Unicode captures, global state reset and a sticky offset inside a surrogate pair. The report correctly distinguishes reused module checks from executed builds. Docker executed amd64; arm64 was cross-compiled. Temporary runtime resources were cleaned, and no AWS resources were used.
Unicode sets (v), advanced syntax/case/property boundaries, native JSON preservation of lone surrogates, exact diagnostics and performance remain open. The AWS Encryption SDK provider and caching interoperability are not implemented. See REGEX.md and DATAMASKING_PLAN.md.
Data Masking core acceptance (2026-09-23)¶
Implemented the independent default/dynamic/custom erasure and provider-orchestration module. Its 240 actual TypeScript cases compare complete values/errors/warnings and provider calls, with an additional async-failure timeline. Native tests cover 64 concurrent erasures, ownership, context, concurrent providers, first-rejection timing, error identity and panic propagation. The core has no third-party module dependencies; Commons supplies number parsing and object-key order.
The complete module check passed all 29 packaged modules and 26 standalone consumers: tests/vet/tidy, GOWORK=off and dependency isolation. Session checkpoint-02. During that run, source review corrected provider first-rejection timing. The final Data Masking code was then checked separately in checkpoint-03; all eight files match its accepted archive and the independent consumer has no external modules. Other modules retain the complete-run evidence. Forty-five integration archive files match current sources; only the Python runner differs due to the restored assertion text.
Normal and streaming handlers were rebuilt for Linux amd64/arm64 with CGO_ENABLED=0.
A runtime-only retry reused the built binaries and passed 847/847 RIE, 95/95 real-Go-SDK/local-Runtime-API streaming and 14/14 saved Batch checks. Its report correctly records that module checks and builds were reused. Docker executed amd64; arm64 was cross-compiled. Temporary containers/networks were cleaned without errors and no AWS resources were used.
Masking composition verifies rule precedence, caller input ownership, reversible provider round trips including null values, invocation/authenticated context, warning policy and missing-provider errors. The fixture provider is explicitly non-cryptographic. Built-in ECMAScript regex, AWS Encryption SDK interoperability, data-key caching, exhaustive native compatibility and performance remain open in DATAMASKING_PLAN.md.
Previous Kafka mixed event modes and Protobuf metadata acceptance (2026-09-23)¶
Verified 172 constructed SOURCE/JSON events directly and through the native Go Lambda SDK: both sources, Glue/Confluent metadata, text/JSON/Avro/Protobuf key/value combinations, repeated lazy reads, parser calls, original fields and null/empty/missing values. Complete reference errors are compared. A separate regression records aws-lambda-go v1.55.0 KafkaRecord's loss of schema metadata and field presence; the RawMessage wrapper preserves both.
Fixed Protobuf schema ID selection for JSON objects with a numerically coerced length. The implementation reuses Commons ParseNumber and retains explicit cyclic/prototype limits. Its additional 97 reference cases bring the prefix corpus to 220, alongside nine native message cases. See KAFKA_MODES.md and KAFKA_BINARY.md.
Only the affected Protobuf and integration modules were repackaged and checked, reusing the previous complete 28-module/25-consumer acceptance for unchanged modules. Tests/vet/tidy and the independent Protobuf consumer passed. Session checkpoint-05 matches all six Protobuf and 45 integration archive files, including the mixed-event corpus and native SDK tests. MODULE_ACCEPTANCE_SCOPED.json records this narrower scope.
The runtime runner reused those completed module checks, rebuilt normal and streaming handlers for Linux amd64/arm64 with CGO_ENABLED=0, and passed 829/829 RIE assertions, 95/95 streaming checks and 14/14 saved Batch checks. Three new runtime assertions exercise a string-valued object length selecting the correct decoder path. Docker executed amd64; arm64 was cross-compiled. The report correctly records reused module checks and executed builds. Runtime resources were cleaned without errors; no AWS resources were used.
These events are constructed fixtures, not service captures. Actual registry delivery/framing removal/retries, complete native schema/error/serialization compatibility and performance remain open.
Previous Kafka binary adapter acceptance (2026-09-23)¶
The full run passed all 28 packaged modules and 25 standalone consumers with GOWORK=off, tests/vet/tidy and dependency isolation. Session: checkpoint-08. Both optional adapters match all six files in their accepted archives. Avro isolates hamba/avro; Protobuf isolates the official Go Protobuf library; Kafka core has no third-party module dependencies.
Normal and streaming Lambda handlers were built for Linux amd64/arm64 with CGO_ENABLED=0. Docker amd64 acceptance passed 826/826 RIE assertions, 95/95 real-Go-SDK/local-Runtime-API streaming checks and 14/14 saved Batch checks. Module checks and builds executed in the passing run. Disposable containers/networks were cleaned without errors; no AWS resources were used.
The 18 new runtime assertions exercise Avro records/tagged unions/bytes and precision rejection, native Protobuf plain/Glue/Confluent messages, adaptive index fallback and null-metadata errors across three successful invocations. The adapter corpora contain 370 Avro, 123 Protobuf prefix and nine native message scenarios.
After that run, 22 constructed JSON-mode event scenarios expanded the core corpus to 165. Packaged core tests/vet/tidy and an independent consumer check passed in checkpoint-09; its ten archive files match current core source. Only the generator, core reference test/corpus and documentation changed after the full runtime run, so runtime checks were not repeated. That historical scoped result is retained in its session progress.json; MODULE_ACCEPTANCE_SCOPED.json tracks the latest affected-module check. See KAFKA_MODES.md. Full SOURCE/service, schema/native/error compatibility and performance gates remain open.
Previous Kafka consumer acceptance (2026-09-23)¶
The independent primitive/JSON Kafka consumer passes 143 actual TypeScript v2.35.0 CommonJS scenarios and 64 concurrent contexts. Verified lazy/repeated access, parser transforms/issues/exception identity, strict Base64/UTF-16 length, UTF-8/BOM differences, original metadata and ordered flattening. The core only depends on Commons; binary codec adapters were not part of that milestone.
The complete run verified all 26 packaged modules and 23 standalone consumers, tests/vet/tidy/isolation with GOWORK=off, and built Linux amd64/arm64 normal and streaming Lambda executables with CGO_ENABLED=0. Session: checkpoint-07. All ten Kafka archive files match current source; the standalone Kafka dependency graph has no external modules.
A runtime-only retry passed 808/808 RIE assertions and 95/95 real-Go-SDK/local-Runtime-API streaming checks using the same built binaries. Saved artifacts also pass 14/14 Batch checks. The successful runtime report accurately records that module checks/builds were reused. This corrects Python acceptance bookkeeping only; no library or Go integration source changed after the successful packaged module checks.
Kafka composition verifies Parser rejection before persistence, one execution for duplicate records, context correlation through Logger/OTel, topic order, self-managed metadata, tombstones, empty keys and UTF-8 headers. Docker executed amd64; arm64 was cross-compiled. Containers/networks were cleaned with no cleanup errors. No AWS resources, public release, full binary decoding parity or performance acceptance is claimed.
Bedrock milestone (2026-09-23, Asia/Shanghai): implemented the independent function-based Action Group module, ordered parameter conversion, explicit/default response envelopes, session references and execution diagnostics. Verified 371 actual TypeScript scenarios with exact body-string comparison, 64 concurrent contexts, cancellation, ownership, error identity, nil results and cycle handling. Also corrected the concrete GraphQL empty-batch TypeError; its differential and runtime-type tests pass. The complete run passed all 25 packaged modules/22 standalone consumers, both CGO-disabled Linux builds, 790/790 RIE assertions, 95/95 real-Go-SDK/local-Runtime-API streaming checks and 14/14 saved Batch artifact checks. Bedrock adds 24 Parser/Logger/OTel composition assertions across three successful invocations. The accepted Bedrock and GraphQL ZIPs match all current module files. Docker executed amd64; arm64 was cross-compiled. Runtime resources were cleaned and no AWS resources were used. Full native/type/service/performance/release gates remain open in BEDROCK_PLAN.md.
The initial full run stopped while compiling Tracer because D: had insufficient space; it did not reach cross-build or Docker acceptance. After explicit approval, 41 generated module-cache directories dated before 2026-09-22 were removed (14.46 GiB of logical file data); source, Git, documentation and recent evidence were retained. The complete retry passed. The module verifier now checks for at least 2 GiB of free workspace space before starting, decodes Go subprocess output as UTF-8, and atomically checkpoints completed modules without replacing the last full acceptance report on failure. The retry's partial checkpoint was inspected while running; its final completed checkpoint exactly matches MODULE_ACCEPTANCE.json. The threshold is an early guard, not a proven peak-space budget. A recursive diagnostic in the focused test itself was corrected before the passing Bedrock tests; no public library source correction followed the passing packaged verification.
HTTP inventory correction (2026-09-23): actual v2.35.0 HTTP/middleware namespaces, Router prototype, package export paths and complete Router declarations establish that no OpenAPI generator belongs to the pinned public contract. Original HTTP-09/H-08 is retired as outside that baseline, with no implementation claimed. Existing request/response schema checks remain in scope.
AppSync GraphQL milestone (2026-09-22): implemented the independent resolver/router module, default aggregate and sequential individual batches, exact-name exception handlers, concrete framework exceptions and scalar helpers. Verified 114 actual TypeScript resolver scenarios, 91 scalar cases, 64 concurrent invocation contexts, error identity, callback reentrancy and UUID structure. The complete run passed all 24 packaged modules/21 standalone consumers, both CGO-disabled Linux builds, 766/766 RIE assertions, 95/95 real-Go-SDK/local-Runtime-API streaming checks and 14/14 saved Batch artifact checks. GraphQL contributes 24 composed Parser/Logger/OTel assertions across the three successful RIE invocations. The full module report's GraphQL ZIP was compared with every current module file and matched. Docker executed amd64; arm64 was cross-compiled. Module checks and builds preceded runtime verification, temporary resources were cleaned and no AWS resources were used. No public library source correction followed the passing module checks. Full native/type/serialization/service parity and performance/release gates remain open in APPSYNC_GRAPHQL_PLAN.md.
AppSync Events milestone: Verified 100 actual TypeScript scenarios, 64 concurrent invocations, ordered concurrent item results, LRU eviction and authorization/callback error behavior; full verification passed 23 packaged modules/20 standalone consumers, both CGO-disabled Linux builds, 742/742 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. The initial focused fixtures exposed route-anchor and JSON-size discrepancies, which were corrected against the actual reference. The full-run AppSync archive preceded the concrete UnauthorizedException type-name correction. MODULE_ACCEPTANCE_SCOPED.json separately verifies the final AppSync source archive, tests/vet/tidy and standalone consumer; the Lambda binaries were built from the corrected source. Unaffected module suites and runtime invocations were not repeated. The new scoped verifier uses the same archive, dependency and consumer checks, writes a separate report and leaves default full-workspace verification unchanged.
Metrics wrapper milestone: Verified 876 actual TypeScript middleware-hook cases, exact output/warning/error and publication-order comparisons, 64 concurrent nested invocations, option snapshots, panic precedence and callback/writer cleanup; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 724/724 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. The full runner executed module checks, both builds and both runtime suites once after the final Go/runtime changes. The fixture executes actual Middy hooks directly, including early cleanup, and compares the PropagateErrors mode without rewriting error messages. Existing StartScope/HTTP consumers retain close-before-diagnostic behavior. Batch checks reused the same artifacts. Full decorator/framework and shared-instance semantics remain separate gates.
Metrics timestamp milestone: Verified 968 actual TypeScript numeric/Date timestamp scenarios, exact warnings/errors and clock-read counts, 64 concurrent scopes and late-write rejection; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 706/706 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. The final full runner executed module checks, both builds and both runtime suites once after adding the Lambda probe. The reference fixture compares complete JSON timestamps and cumulative clock calls; no error-message or value replacement hides differences. Batch checks reused the same artifacts.
Metrics value milestone: Verified 641 actual TypeScript value/error/key scenarios, exact warning/configuration error messages, shared key-order regression through Parser/Validation, all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 688/688 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. Both focused affected-module checks and the final packaged/runtime run passed. Prior warning/configuration tests now compare error messages without sentinel-text replacement. Module checks/builds preceded both runtime suites; no completed suite was repeated without a relevant code change.
Metrics configuration milestone: Verified 532 actual TypeScript configuration cases, exact custom getter order/errors, strict environment validation, single-metric reconstruction and constructor publication mode; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 673/673 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. The focused test initially found a missing test-only fmt import after call-site migration; after correcting it and adding constructor single-metric coverage, the final full runner passed once. Module checks/builds preceded both runtime suites. The configuration probe confirms custom getters execute once in order, default service restoration, independent disabled/empty policies and shared scope closure.
Metrics cold-start milestone: Verified 302 actual TypeScript cold-start cases, 64 concurrent captures, failed-write consumption, scoped function-name isolation and closed-scope rejection; all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 658/658 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks passed (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. The full runner executed module checks, both builds and both runtime suites once after the final code changes. The Lambda fixture explicitly sets on-demand initialization; wrapper/manual composition emits once, an independently bound cold instance emits once, and new instances in warm scopes emit nothing.
Metrics diagnostic milestone: Verified 203 actual TypeScript diagnostic scenarios, Unicode whitespace reuse, callback reentrancy/concurrent scopes, automatic flush and failed-output delivery, all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 646/646 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. Module checks, builds and both local runtime suites completed in one full run after the focused reference test exposed and corrected whitespace sanitization. Reports preserve the final run; no passed suites were repeated without a relevant change.
Metrics store milestone (2026-09-22): Verified 104 actual TypeScript store lifecycle scenarios, 64 concurrent scope policies, late-write rejection, all 22 packaged modules/19 consumers, both CGO-disabled Linux builds, 631/631 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. The completed runner executed module checks/builds and both local runtime suites without retries.
HTTP observability milestone (2026-09-22): Verified 176 Metrics and 128 Tracer middleware reference cases (2,066 HTTP cases across the three modules), scope/span concurrency and body lifecycle tests, all 22 packaged modules/19 independent consumers, both CGO-disabled Linux builds, 622/622 RIE assertions, 95/95 streaming Runtime API checks and 14/14 Batch artifact checks (2026-09-22, Asia/Shanghai). Docker ran amd64; arm64 was cross-compiled. No AWS resources were used. The first package attempt caught an incorrect new compression-length test; the corrected exact metadata comparison and absent/present length tests passed before the final full run. See HTTP_OBSERVABILITY.md.
HTTP streaming update (2026-09-17, Asia/Shanghai): ResolveStream/Streamify share the buffered router contracts and stream owned readers through native Lambda HTTP framing. HTTP now has 1,762 reference cases, including 272 streaming cases. All 20 packaged modules/17 consumers and both CGO-disabled Linux builds passed before the initial protocol run. The ordinary Lambda RIE suite passed 609/609 and its saved artifacts passed 14/14 Batch checks. The protocol run exposed cancellation publishing a closed-pipe error before producer cleanup; after fixing it, HTTP regression tests, both streaming binary builds and the separate real-Go-SDK/local-Runtime-API suite passed 95/95. The passing RIE suite was not repeated for this streaming-only fix. Both suites cleaned their temporary containers/network; Docker ran amd64 and arm64 was cross-compiled. Cloud streaming and the SDK response-mode header remain unverified; no AWS resources were used. See HTTP_STREAMING.md and STREAMING_ACCEPTANCE.json.
HTTP CORS/compression update (2026-09-17, Asia/Shanghai): 1,076 new reference cases bring HTTP coverage to 1,490. All 20 packaged modules/17 independent consumers passed with CGO disabled. After a development REST GET fixture was corrected from an empty body to null, both Linux architectures were rebuilt and Docker passed 609/609 assertions using --skip-module-checks. Public library source was unchanged; the successful continuation reused completed module checks and LOCAL_ACCEPTANCE.json records that accurately. The same artifacts passed 14/14 Batch checks; all temporary containers/network were cleaned. Docker executed amd64, while arm64 was cross-compiled only. No AWS resources were used. CORS defaults/preflight/route policies and gzip/deflate negotiation/body lifecycle are implemented; compressed bytes can differ by runtime and are compared by decoded payload with independently checked wire lengths. See HTTP_MIDDLEWARE.md. Streaming, remaining native/header/Unicode/error parity and release gates stay open.
HTTP event-handler update (2026-09-16, Asia/Shanghai): all 20 independently packaged modules passed tests/vet/tidy, seventeen independent consumers built, both Linux architectures compiled with CGO disabled, and Docker passed 501/501 assertions. The initial HTTP module adds 414 actual TypeScript reference cases plus 64-caller concurrency, snapshot/context, cancellation, panic and body-ownership tests. Four HTTP event formats compose actual Parser and JSON Schema Validation callbacks with Logger/OTel context; invalid requests do not reach the business handler. Parser's 3,493 and Validation's 23,071 reference cases remain passing. Root Commons, Parser and HTTP have no third-party module dependencies. The same runtime artifacts passed 14/14 Batch checks without new invocations. The complete run executed module checks/builds and cleaned temporary containers/network. Docker ran amd64; arm64 was cross-compiled only. No AWS resources were used. See HTTP.md; CORS/compression, streaming, inventory reconciliation and exhaustive compatibility remain open.
Validation condition-graph update (2026-09-16, Asia/Shanghai): all 23,071 Validation reference cases, 19 packaged modules/16 consumers, both CGO-disabled Linux builds and 442/442 local Docker assertions passed. Ignored conditions do not resolve inactive references; active references still reach their original conditional nodes. Nested dialect declarations, global nested resource aliases and ordered ExternalSchemas registrations now have scoped reference coverage. Thirty-two concurrent callers verify snapshots and exactly-once active callbacks. The complete run executed all module checks/builds, cleaned its temporary containers/network, and the same artifacts passed 14/14 Batch checks without new invocations. Docker ran amd64; arm64 was cross-compiled only. No AWS resources were used. The eight earlier ignored-reference/dialect observations are covered by the new 1,104-case graph corpus. See VALIDATION_GRAPHS.md; full resource identity, registration error, numeric, extension and release gates remain open.
Validation schema-shape update (2026-09-16, Asia/Shanghai): all 21,967 Validation reference cases, 19 packaged modules/16 consumers, both CGO-disabled Linux builds and 424/424 local Docker assertions passed. Reachable keyword types, inactive primitive fragments, annotation-only schemas, scoped conditional compilation and mixed property dependencies now match the expanded reference corpus. Callback tests prove compilation does not execute branch callbacks, selected branches run once and inactive conditions do not invoke callbacks. The complete run executed all module checks/builds, cleaned its temporary containers/network, and the same artifacts passed 14/14 Batch checks without new invocations. Docker ran amd64; arm64 was cross-compiled only. No AWS resources were used. Eight subsequent reference-only ignored-reference/dialect observations are excluded from the passing count. See VALIDATION_SHAPES.md; full graph/setup, numeric and extension parity remain open.
Validation keyword update (2026-09-16, Asia/Shanghai): all 16,203 Validation reference cases, 19 packaged modules/16 consumers, both CGO-disabled Linux builds and 403/403 local Docker assertions passed. Private compiled adapters preserve fractional/negative/large size limits, non-string required diagnostics, empty combinator behavior and default floating-point multipleOf decisions, including zero and exponential quotients. Thirty-two concurrent callers verify returned error parameters cannot mutate compiled state. The complete run executed all module checks/builds, cleaned all temporary containers/network, and the same artifacts passed 14/14 Batch checks without new invocations. Docker ran amd64; arm64 was cross-compiled only. No AWS resources were used. A subsequent 126-case reference-only keyword-shape probe is excluded from the passing count. See VALIDATION_KEYWORDS.md; complete malformed-schema, numeric and extension parity remains open.
Validation schema-setup update (2026-09-16, Asia/Shanghai): all 12,770 Validation reference cases, 19 packaged modules/16 consumers, both CGO-disabled Linux builds and 382/382 local Docker assertions passed. Original schema documents are structurally validated before adaptation; compilation-only checks follow reachable definitions, aliases and nested resource IDs. Always-valid patterns skip regex compilation unless additional-property rules require matching. Six additional checks per successful invocation verify these distinctions. The complete run executed all module checks and builds, cleaned its containers/network, and the same artifacts passed 14/14 Batch checks. Docker ran amd64; arm64 was cross-compiled only. No AWS resources were used. Fifty-five subsequent reference-only $defs keyword observations are excluded from the passing count. See VALIDATION_STRICT.md; complete schema setup, malformed keyword, numeric and error-contract parity remain open.
Validation strict-pattern update (2026-09-16, Asia/Shanghai): all 12,112 Validation reference cases, 19 packaged modules/16 consumers, both CGO-disabled Linux builds and 364/364 local Docker assertions passed. The strict property/pattern check now uses legacy UTF-16 matching independently of Unicode payload validation, retaining regex limits and typed resource errors. Three additional runtime checks per successful invocation cover strict overlap rejection, Unicode dot matching and property escape identity. The complete run executed all module checks and builds, cleaned all containers/network, and the same artifacts passed 14/14 Batch checks. Docker ran amd64; arm64 was cross-compiled only. No AWS resources were used. The 24 unused-definition observations are reference-only research and excluded from the passing Go count. See VALIDATION_STRICT.md; full strict-schema and regex compatibility remain open.
Validation type/reference update (2026-09-16, Asia/Shanghai): all 9,065 Validation reference cases, 19 packaged modules/16 consumers, both CGO-disabled Linux builds and 355/355 local Docker assertions passed. New coverage includes mixed rule groups, nullable arrays, numeric formats, nested $defs resource IDs, alias chains, external and recursive reference scopes. Concurrent reused-target and caller-ownership tests pass. The complete run executed all module checks and builds before five amd64 Lambda invocations; arm64 was cross-compiled only. Containers/network were cleaned, and the same artifacts passed 14/14 Batch checks. No AWS resources were used. See VALIDATION_REFERENCES.md; complete AJV and performance gates remain open.
Validation applicator update (2026-09-16, Asia/Shanghai): all 7,794 Validation reference cases, 19 packaged modules/16 consumers, both CGO-disabled Linux builds and 343/343 local Docker assertions passed. Scoped diagnostics cover conditional summaries, dependencies, property names, tuples, nested ordering and oneOf branch retention. Additional tests verify 32 concurrent callers, callback counts, single serialization snapshots and mutable diagnostic isolation using Commons. The complete run executed module checks and builds before all five amd64 Lambda invocations; containers/network were cleaned. The same artifacts passed 14/14 Batch checks. No AWS resources were used. See VALIDATION_APPLICATORS.md; exhaustive parity and performance remain open.
Validation regex update (2026-09-16, Asia/Shanghai): all 6,587 Validation reference cases, 19 packaged modules/16 consumers and both CGO-disabled Linux builds passed. The Unicode adapter covers lookarounds, backreferences, 433 property tables and 1,683 exact aliases, with original diagnostics and operational resource errors. Docker first passed 325/331 checks; six Unicode comparisons exposed locale-based decoding in the Windows test runner. Explicit UTF-8 decoding fixed the harness, and runtime-only continuation passed 331/331 using unchanged Go binaries. Batch artifact checks passed 14/14. Both runs cleaned their containers/network; no AWS resources were used. See VALIDATION_REGEX.md and LOCAL_VALIDATION.md. Full compatibility and performance gates remain open.
JSON Schema Validation update (2026-09-16, Asia/Shanghai): all 19 packaged modules passed tests/vet/tidy and sixteen independent consumers built. Validation passed 502 actual TypeScript/AJV reference cases plus snapshot, concurrency, cancellation, wrapper and error-preservation tests. Both CGO-disabled Linux Lambda architectures compiled. Local amd64 Docker passed 316/316 assertions across five invocations and cleaned all containers/network; the same artifacts passed 14/14 Batch checks. Parser's 3,493 cases remain covered, and Commons/Parser retain no third-party module dependencies. No AWS resources were used. See JSON_SCHEMA_VALIDATION.md, VALIDATION_PLAN.md and LOCAL_VALIDATION.md. Full AJV compatibility remains open.
Idempotency cache update (2026-09-15): all 17 packaged modules passed tests/vet/tidy and fourteen independent consumers built. Both Linux Lambda architectures compiled with CGO disabled. The optional Redis/Valkey adapter passed sixteen TypeScript persistence scenarios and additional guarded-recovery/validation/error tests. Real Valkey plus Lambda RIE passed 172/172 assertions, including warm replay, 32 overlapping conflicts per successful invocation, orphan recovery, validation retained by Go, and basic bidirectional TypeScript/Go JSON records. Batch artifact checks passed 14/14. Core tests also prove one custom marshaler call per default key snapshot. A dependency download EOF was resolved by reusing prior verified archive caches before the network; no test suite retry was needed. The acceptance summarizer was made compatible with an optional bridge-detail field and rerun against existing passing data. Full serialization, cache topology and server-expiry gates remain open; see IDEMPOTENCY_CACHE.md.
Idempotency update (2026-09-15): 16 packaged modules passed tests/vet/tidy checks and thirteen standalone consumers built. Linux amd64 and arm64 compiled with CGO disabled. Idempotency passed 25 canonical-key cases, 14 lifecycle scenarios, two DynamoDB SDK wire sequences, concurrent acquisition, cancellation/failure/retry boundaries, and response/operation isolation tests. Local Docker passed 155/155 assertions, including DynamoDB-backed warm replay and Batch composition; the same artifacts passed 14/14 Batch checks. The first runtime run exposed a test expectation inconsistent with the shared first-installed SDK marker rule. After correcting that assertion, runtime-only continuation passed using unchanged Go binaries. Redis/Valkey and full cross-language/live-service gates remain open. See IDEMPOTENCY_PLAN.md and LOCAL_VALIDATION.md.
Batch update (2026-09-15): 15 packaged modules passed tests/vet/tidy consistency and twelve standalone consumers built. Both Linux Lambda architectures compiled with CGO disabled. Docker initially required starting its Linux engine; runtime-only continuation reused the verified binaries and passed 129/129 assertions with cleanup. A separate inspection of the same artifacts passed 14/14 Batch/Logger/OTel composition checks without extra invocations. Batch includes 43 actual TypeScript reference scenarios, FIFO/group semantics, source identifiers, parser errors, cancellation, panic handling, and functional concurrency. Evidence: LOCAL_VALIDATION.md, BATCH_ACCEPTANCE.json, and BATCH_PLAN.md. No AWS deployment was performed.
Signer/JMESPath update (2026-09-14): all 14 packaged modules passed tests, vet, and tidy consistency; eleven isolated consumers built successfully. Both Lambda architecture builds passed with CGO disabled. Local Docker passed 114/114 assertions, including synthetic SigV4 verification, query decoding, and Logger correlation. Thirteen actual TypeScript signing cases and 78 query cases record exact results and deliberate differences. Logger struct/marshaler redaction and Tracer HTTP envelope extraction also passed regression tests. No AWS resources were deployed. See LOCAL_VALIDATION.md, SIGNER.md, and JMESPATH.md.
Logger/Tracer update (2026-09-14): all 12 packaged modules passed tests, vet, and dependency consistency checks; nine public modules passed independent consumer builds. Both Linux architectures compiled with CGO disabled and without the legacy X-Ray SDK. The OTel-only Docker fixture passed 105/105 assertions, including pure W3C success/error paths and log correlation. The deprecated SDK adapter retains regression coverage and a once-per-process migration warning. See LOCAL_VALIDATION.md and XRAY_MIGRATION.md. No new AWS deployment was performed for this update. Earlier results below retain their original scope.
Date: 2026-09-12. Local platform: Windows amd64. Toolchain: Go 1.26.2. All Go validation and builds use CGO_ENABLED=0.
Reference fixture¶
Generated with Node.js v22.21.1 and @aws-lambda-powertools/logger exactly 2.35.0, pinned in tools/reference/package-lock.json. The generated fixture is stored as source data under logger/testdata. Generation uses the actual package; no expected outputs were handwritten. Only timestamp is removed. Go tests compare parsed output for persistent/temporary/call attributes, key removal, INFO/WARN output, and filtered DEBUG output.
Node.js is a development-only fixture generator. Normal Go tests read the checked-in fixture, and Lambda executables have no Node.js dependency.
Local results¶
Update (2026-09-14): Metrics joins the integration handler. The updated Docker suite passed 85 assertions across five invocations; full Go tests/vet and both architecture builds passed. Additional sampling and Metrics TypeScript fixtures extend the original reference coverage. The new package has local EMF evidence only; earlier AWS results cover Logger/Tracer.
Parameters update (2026-09-14): All five providers now run in the integration handler. The final suite passed 94 Docker assertions, full Go tests/vet, and both architecture builds with CGO disabled. Default helpers, cache/transforms, SSM batching/writes, pagination, AppConfig token concurrency, and Agent behavior have local coverage, including actual pinned TypeScript outputs. PARAMETERS.md records compatibility boundaries. No additional cloud test was performed.
Commons/Metadata update (2026-09-14): Public shared helpers and the independent Metadata client are implemented, and compatible consumers were migrated after inspecting upstream call sites. Full tests/vet, both Linux builds, and 100 Docker assertions passed after the final waiter-cancellation fix. COMMONS.md maps contracts and remaining differences; COMMONS_REUSE.md records actual reuse. Metadata protocol behavior is locally verified; live LMDS remains unverified.
Update (2026-09-13): local Docker is now the default integration workflow. Five Lambda RIE invocations passed 72 assertions for Logger and OpenTelemetry. See LOCAL_VALIDATION.md; the historical results below remain identified by their original artifacts.
The offline local example passed: it emitted an INFO document with service demo, cold_start true, trace_id f0fcfc49b5939f589ab04b073945a6cc, span_id 71c2f0f5c1544e74, and a ## bootstrap span carrying the same trace ID. IDs are random on each run.
go test ./... passed for all packages. Coverage includes the TypeScript logger fixture, 100 concurrent logger invocations, buffer lifecycle, OTel context propagation and parent sampling, HTTP and DynamoDB instrumentation using fake transports, error/panic cleanup, provider ownership, flush failure, and X-Ray SDK handler/child metadata and closure. go vet ./... passed. The build and cache directories required permission outside the tool sandbox; this did not require changing CGO settings.
scripts/build.ps1 successfully built and packaged the complete examples/basic Lambda for both target architectures. The packaging utility verified ELF machine type, absence of a dynamic loader, Go build settings GOOS=linux and CGO_ENABLED=0, and a root-level bootstrap ZIP entry with mode 0755.
| Architecture | Binary | ZIP | Binary SHA256 |
|---|---|---|---|
| Linux amd64 / Lambda x86_64 | dist/amd64/bootstrap |
dist/lambda-amd64.zip |
976b367b7dd788db52f2d51d49a2a1ecb417d5d0a0fe8bcedf05a75f8f219489 |
| Linux arm64 / Lambda arm64 | dist/arm64/bootstrap |
dist/lambda-arm64.zip |
2b06f0468f3ee3646f086082bf5b0869ab8858e0e6d2e60fab0cf53a81e4af67 |
Build outputs are ignored by Git. The executable hashes above identify the tested artifacts; rebuilding with another toolchain or source revision can change them. See CHECKLIST.md for item-level progress.
The X-Ray test emitter receives a pre-serialization model. The SDK's public Subsegments JSON slice is populated by its default emitter during packing; it is not the internal live child list. Tests must inspect captured child lifecycle separately instead of expecting the JSON slice to already be populated.
Not executed¶
- Remote CI or GitLab jobs.
- Race detector, because CGO must always remain disabled.
- Cold-start benchmarks, size/performance budgets, hard-timeout/freeze recovery, and full upstream differential coverage.
AWS execution update¶
Real Lambda execution and CloudWatch/X-Ray/OTLP acceptance were completed in a private test account, region ap-east-1 (Hong Kong). Both architectures and backends passed 206 scoped assertions across 20 invocations. All temporary test resources were cleaned up. See AWS_VALIDATION.md and AWS_ACCEPTANCE.json for timestamps, hashes, findings, and the limits of this result.
AWS acceptance steps for a later deployment¶
After a function and its collector configuration are deployed, open the AWS Lambda console for that function and invoke {"name":"Go"}. Select the runtime provided.al2023 and architecture matching the uploaded package. Open its Monitor tab and follow the CloudWatch logs link. Verify one JSON record with the request ID, service, cold_start, and matching trace/span IDs; invoke again and verify cold_start is false in the same execution environment.
Open CloudWatch's X-Ray traces view for the function's region and locate the matching trace. Confirm handler/operation nesting, outbound HTTP/SDK spans, error behavior, and annotation indexing for the selected backend. Repeat with sampled and unsampled parents and check consecutive invocation isolation. Review collector logs for dropped data. The completed deployment results are recorded in AWS_VALIDATION.md; the disposable functions and log groups have since been deleted.