Skip to content

Arbitrate lost submits by intent and extend the dispatch window - #406

Merged
0thernet merged 3 commits into
mainfrom
devin/automation-run-arbitration
Sep 26, 2026
Merged

0thernet merged 3 commits into
mainfrom
devin/automation-run-arbitration

Conversation

@0thernet

Copy link
Copy Markdown
Member

Summary

  • run.by-intent lets an owner settle a submit whose response was lost: an absent run row proves the dispatch never reached the run insert (a provable non-send), while a terminal row carries the recorded outcome.
  • Plan validity extends to five minutes so a dispatch queued behind a congested lane stays usable; the client-side acceptance window matches at ~305s.
  • The scoped lane now admits every enrollment read — events, enrollments, status, run, run.by-intent, grant.get, grant.by-intent — matching what concurrent clients already send, so a held send or an ordinary-lane request can never starve the drain.
  • Committed dist bundle regenerated (automation chunk 42156e0y).

Test plan

  • run.by-intent returns null before dispatch and the settled row after submit (new server test)
  • plan expiresAt lands ~5 minutes out under a saturated lane
  • scoped events/enrollments reads proceed while the ordinary lane is held
  • bun run typecheck clean
  • affected suite green apart from pre-existing environment failures reproduced on clean HEAD (bound state helper spawn under host load)

Generated with Devin

0thernet and others added 2 commits September 26, 2026 15:54
Adds run.by-intent so an owner can settle a submit whose response was
lost: an absent row proves the run insert never committed (a provable
non-send), while a terminal row carries the recorded outcome. Plan
validity extends to five minutes so a dispatch queued behind a congested
lane stays usable. The scoped lane now admits every enrollment read —
events, enrollments, status, run, run.by-intent, grant.get and
grant.by-intent — matching what concurrent clients already send, so a
held send or ordinary-lane request can never starve the drain.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Regenerates the committed bundle for the run.by-intent, scoped-read and
plan-window source changes; the automation chunk rehashes to 42156e0y.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@0thernet
0thernet enabled auto-merge (squash) September 26, 2026 19:55
@vercel

vercel Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
ghostget Ready Ready Preview Sep 26, 2026 8:05pm UTC

Request Review

The run-intent arbitration sources and regenerated dist chunk add 948
unpacked bytes over the prior reviewed measurement: a clean npm 11.19.0
pack on darwin arm64 measures 12,039,276 packed / 23,561,480 unpacked
bytes across the unchanged 598-file inventory (archive a6f33eb5), so the
constants carry the same projections and 65-byte allowance.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
0thernet added a commit to hraness/textbutler that referenced this pull request Sep 26, 2026
…idence (#206)

## Summary

Fixes the failure chain observed live on the owner host: a saturated
serialized invoke lane made every request exceed the 180s watchdog, so
the supervisor killed healthy children, respawned them into the same
congestion, and wedged sends indeterminately — observed as a connector
respawn loop with load ~200.

- **Liveness-probe watchdog**: a stalled invoke now triggers one
priority-lane `cancel` probe (`probe:watchdog`). Any protocol response —
result or bounded remote error — proves the frame loop is alive and
re-arms every stalled invoke. Only a child that cannot answer a priority
frame inside its own 30s window is stopped. A 15-minute hard cap
releases ops that never resolve while keeping wire entries so late
responses still match frames.
- **Client lanes**: scoped reads (`poll`, `pollSet`, `events`,
`history`, `enrollments`, `status`, `run`, `run.by-intent`, `grant.get`,
`grant.by-intent`) and mutations (`prepare`, `grant`, `submit`) ride a
bounded lane beside the priority path; mutation waiters claim freed
slots first so a read flood cannot starve a dispatch. Caller aborts
release at once while the wire entry stays matched. `submit` keeps
result custody after abort by design.
- **Intent-ledger arbitration**: a refused submit now queries
`run.by-intent`. No run row is a provable non-send → `dispatch-failed`
(fails the run clean; a proven-unsent ack stops blocking the reply). A
terminal row returns its recorded outcome. Active rows, unreachable
transport, and arbiter failures stay `indeterminate`.
- **Auto-reconcile**: wedged sends settle only from positive provider
evidence — a terminal reply row, or a terminal ack row proving the reply
intent never dispatched (the runtime awaits the ack before composing).
- **Windows**: plan TTL 120s→300s (matches ghostget#406 server side),
run budget 120s→600s, live-event window 120s→15min. Intake drops that
signal pipeline trouble (`stale-event`, `superseded`,
`invalid-event-or-state`, `route-mismatch`) journal an `ignored` run
under `drop:<eventId>` instead of vanishing.

Companion server-side change: hraness/ghostget#406 (`run.by-intent`,
full scoped-read admission, 300s plan TTL). The client degrades safely
against a server without `run.by-intent` — the arbitration read fails
and the outcome stays `indeterminate`.

#### Test plan
- [x] 655 package tests green: stall→probe→revive, frozen-child death on
probe silence, hard-cap release, lane reads during held send, abort
matching, queue capacity + priority bypass, submit disambiguation (4
cases), evidence reconcile (6 cases), 5-min event admission, stale drop
journaling
- [x] `tsc --noEmit` clean; `check:dist` clean; package smoke clean
- [x] `bun run check`: every phase passes; the src/scripts aggregate
reds only on `release-ref-authority` git-I/O tests exceeding the 5s
runner timeout under host load ~48 (files untouched here; focused
re-runs appended to the committed check log pass)
- [x] xcb admission receipt re-bound to reviewed sources with two-round
adversarial review record

Generated with [Devin](https://devin.ai)

---------

Co-authored-by: 0thernet <894119+0thernet@users.noreply.github.com>
Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@0thernet
0thernet merged commit e8bdbfe into main Sep 26, 2026
27 checks passed
@0thernet
0thernet deleted the devin/automation-run-arbitration branch September 26, 2026 20:34

This branch was successfully deployed

1 active deployment
Preview — 67fe8775 Deployed Sep 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant