Skip to content

Reclaim ended allocations without synthesizing outcomes and order limit updates - #361

Merged
ctfbruce merged 2 commits into
mainfrom
fix/session-allocation-recovery
Oct 2, 2026
Merged

ctfbruce merged 2 commits into
mainfrom
fix/session-allocation-recovery

Conversation

@ctfbruce

@ctfbruce ctfbruce commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Ended execution windows previously fabricated a terminal result and settled payments, while a timed-out destination update could still overwrite a newer limit at the executor. This change records local allocation reclamation independently and makes current peers acknowledge ordered allocation snapshots.

  • Record an immutable reclamation timestamp after the existing window-plus-grace policy, release reservations by run identity, reject delayed reallocation and exclude reclaimed runs from restart restoration. Actual terminal evidence remains eligible under its original binding; cleanup does not replay work or settle payment.
  • Advertise ordered snapshot support during the existing handshake, reject older revisions at application, and acknowledge only fully published limits. Keep one pending revision per existing session and reconcile it on heartbeat; allocation delivery failures are returned to the caller.
  • Preserve legacy control compatibility. Legacy peers can allocate runs, but a live destination change records the admission cap and returns an actionable upgrade error instead of claiming ordered application.

Dispatcher schema 19 requires the existing operator-invoked database upgrade. API 1.14 adds optional allocation_reclaimed_at to recovery inspection. Reclamation is a local accounting fact: it neither proves remote traffic has stopped nor releases retained-work admission quotas.

Validation: focused dispatcher/executor regressions under -race -count=3, including replacement-session isolation; API destination compatibility and scheduler restoration tests; storage schema/client checks; dispatcher/executor vet. Independent source review found no outstanding correctness findings. Full candidate CI run 37004665121 passed all 16 jobs, including test, race, kernel, generated-file checks, packaged demo, compatibility and local deployment.

Refs #37, #44.

@ctfbruce ctfbruce added Source reviewed Current source evidence checked; no new runtime reproduction claimed by backlog creation. Ready for review Reviewed, green candidate; maintainer review and dependency checks still required. labels Oct 2, 2026
@ctfbruce
ctfbruce marked this pull request as ready for review October 2, 2026 12:17
@ctfbruce ctfbruce added Ready to merge Reviewed and CI passed; merge in dependency order after required approval. and removed Ready for review Reviewed, green candidate; maintainer review and dependency checks still required. labels Oct 2, 2026
@ctfbruce
ctfbruce merged commit 5e342d0 into main Oct 2, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready to merge Reviewed and CI passed; merge in dependency order after required approval. Source reviewed Current source evidence checked; no new runtime reproduction claimed by backlog creation.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant