Arbitrate lost submits by intent and extend the dispatch window - #406
Merged
Merged
Conversation
Adds run.by-intent so an owner can settle a submit whose response was lost: an absent row proves the run insert never committed (a provable non-send), while a terminal row carries the recorded outcome. Plan validity extends to five minutes so a dispatch queued behind a congested lane stays usable. The scoped lane now admits every enrollment read — events, enrollments, status, run, run.by-intent, grant.get and grant.by-intent — matching what concurrent clients already send, so a held send or ordinary-lane request can never starve the drain. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Regenerates the committed bundle for the run.by-intent, scoped-read and plan-window source changes; the automation chunk rehashes to 42156e0y. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
0thernet
enabled auto-merge (squash)
September 26, 2026 19:55
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
The run-intent arbitration sources and regenerated dist chunk add 948 unpacked bytes over the prior reviewed measurement: a clean npm 11.19.0 pack on darwin arm64 measures 12,039,276 packed / 23,561,480 unpacked bytes across the unchanged 598-file inventory (archive a6f33eb5), so the constants carry the same projections and 65-byte allowance. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Merged
4 tasks
0thernet
added a commit
to hraness/textbutler
that referenced
this pull request
Sep 26, 2026
…idence (#206) ## Summary Fixes the failure chain observed live on the owner host: a saturated serialized invoke lane made every request exceed the 180s watchdog, so the supervisor killed healthy children, respawned them into the same congestion, and wedged sends indeterminately — observed as a connector respawn loop with load ~200. - **Liveness-probe watchdog**: a stalled invoke now triggers one priority-lane `cancel` probe (`probe:watchdog`). Any protocol response — result or bounded remote error — proves the frame loop is alive and re-arms every stalled invoke. Only a child that cannot answer a priority frame inside its own 30s window is stopped. A 15-minute hard cap releases ops that never resolve while keeping wire entries so late responses still match frames. - **Client lanes**: scoped reads (`poll`, `pollSet`, `events`, `history`, `enrollments`, `status`, `run`, `run.by-intent`, `grant.get`, `grant.by-intent`) and mutations (`prepare`, `grant`, `submit`) ride a bounded lane beside the priority path; mutation waiters claim freed slots first so a read flood cannot starve a dispatch. Caller aborts release at once while the wire entry stays matched. `submit` keeps result custody after abort by design. - **Intent-ledger arbitration**: a refused submit now queries `run.by-intent`. No run row is a provable non-send → `dispatch-failed` (fails the run clean; a proven-unsent ack stops blocking the reply). A terminal row returns its recorded outcome. Active rows, unreachable transport, and arbiter failures stay `indeterminate`. - **Auto-reconcile**: wedged sends settle only from positive provider evidence — a terminal reply row, or a terminal ack row proving the reply intent never dispatched (the runtime awaits the ack before composing). - **Windows**: plan TTL 120s→300s (matches ghostget#406 server side), run budget 120s→600s, live-event window 120s→15min. Intake drops that signal pipeline trouble (`stale-event`, `superseded`, `invalid-event-or-state`, `route-mismatch`) journal an `ignored` run under `drop:<eventId>` instead of vanishing. Companion server-side change: hraness/ghostget#406 (`run.by-intent`, full scoped-read admission, 300s plan TTL). The client degrades safely against a server without `run.by-intent` — the arbitration read fails and the outcome stays `indeterminate`. #### Test plan - [x] 655 package tests green: stall→probe→revive, frozen-child death on probe silence, hard-cap release, lane reads during held send, abort matching, queue capacity + priority bypass, submit disambiguation (4 cases), evidence reconcile (6 cases), 5-min event admission, stale drop journaling - [x] `tsc --noEmit` clean; `check:dist` clean; package smoke clean - [x] `bun run check`: every phase passes; the src/scripts aggregate reds only on `release-ref-authority` git-I/O tests exceeding the 5s runner timeout under host load ~48 (files untouched here; focused re-runs appended to the committed check log pass) - [x] xcb admission receipt re-bound to reviewed sources with two-round adversarial review record Generated with [Devin](https://devin.ai) --------- Co-authored-by: 0thernet <894119+0thernet@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
run.by-intentlets an owner settle a submit whose response was lost: an absent run row proves the dispatch never reached the run insert (a provable non-send), while a terminal row carries the recorded outcome.events,enrollments,status,run,run.by-intent,grant.get,grant.by-intent— matching what concurrent clients already send, so a held send or an ordinary-lane request can never starve the drain.42156e0y).Test plan
run.by-intentreturns null before dispatch and the settled row after submit (new server test)expiresAtlands ~5 minutes out under a saturated laneevents/enrollmentsreads proceed while the ordinary lane is heldbun run typecheckcleanGenerated with Devin