Skip to content

Archive retained executor work after joined shutdown - #365

Merged
ctfbruce merged 11 commits into
mainfrom
fix/retained-work-disposition
Oct 5, 2026
Merged

ctfbruce merged 11 commits into
mainfrom
fix/retained-work-disposition

Conversation

@ctfbruce

@ctfbruce ctfbruce commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Retained work from a retired executor session can otherwise keep local queue admission full indefinitely. Add dbl service archive-run: it inspects one run by default and requires an explicit reason to record a dated local disposition after successful managed shutdown.

The operation requires a disabled, joined managed executor and exclusive SQLite ownership, rechecks the service/configuration/schema, and refuses concurrent foreground executors. Original execution, output and terminal evidence remains intact; archived runs are excluded from restoration and delivery, and their identities cannot be reused. Only the local execution queue admission charge is released. Actual disk bytes, output-spool limits, dispatcher account quotas, remote outcomes and payments are unchanged.

Requires the explicit executor schema 7 upgrade. This is the interrupted-work disposition slice of #168; release activation and other acceptance gates remain separate.

Validation: focused scheduler/output/storage/service/CLI tests; actual executor command shutdown, archival and restart with real dispatcher transports and a real WASM measurement; archive and reconnect cases under -race -count=3. Independent review completed. CI 37015266603 passes all 16 checks, including the installed v0.2.0-to-candidate upgrade and backup rollback. Its test lane passed on retry after an unchanged SQLite-migration cancellation assertion exceeded its two-second bound once; 25 isolated repeats passed without changing that assertion.

TheodorAdrienIsaak Mattli added 6 commits October 5, 2026 12:10
Add a rehearsal of the composed chain settlement path on real SQLite
through the real payment handler and the scripted chain: a paid run
credited and paid out exactly once with duplicate and mismatching
receipts recorded; a lost response resolved by a verified lookup
without a second broadcast; the dispatcher stopped after reserving a
transfer and before submitting it, resubmitting the stored bytes once
with the same digest; stopped after submitting and before recording,
resolved after restart with one transfer in total; a failed refund
never sent again while an owed one is sent once from its reserved row;
the settlement pass delivering a credit once after the inline attempt
failed, with duplicate terminal reports ignored; every drill repeated
with the database closed and reopened after each step; and disabled
mode refusing every chain action, including for leftover chain orders,
while TEST flows are unchanged. Each drill asserts the exact rows of
the payment tables and the backend call counts. No wallet, network or
chain endpoint is involved.

GitHub issue #87.
Bring the branch up to date with main after the account recovery change. The
schema policy keeps both raised minima: dispatcher 20 from the account
recovery migration and executor 7 from the operator disposition migration.
Both require the explicit stopped-service database upgrade.

GitHub issue #168.
Bring the payout and refund branch at its corrected head under the
rehearsal drills, so that they run against the lifecycle as it will
merge: the refund outcome returned to callers, bounded reconciliation
lookups and the adapter's id validation.

GitHub issue #87.
The refund of an unadmitted intent now reports what became of the
money besides its error, so the drills read that outcome: nothing
transferred when chain payments are disabled, failed after a refund
that was not broadcast, and sent once the next refund is confirmed.

GitHub issue #87.
Exercise settlement rehearsals alongside the current payment lifecycle, quote pricing, allowances and operator documentation.

GitHub issue #87.
Preserve dispatcher schema 23 alongside executor schema 7 and keep the configuration guide aligned with both schema boundaries.

GitHub issue #168.
@ctfbruce
ctfbruce marked this pull request as ready for review October 5, 2026 14:19
@ctfbruce
ctfbruce marked this pull request as draft October 5, 2026 14:57
TheodorAdrienIsaak Mattli added 2 commits October 5, 2026 17:19
Keep the chain settlement rehearsal with the corrected TCP and UDP two-port test fixtures.

GitHub issues #87 and #389.
Keep retained work disposition and its schema boundaries together with the corrected distinct-port test fixtures.

GitHub issues #168 and #389.
@ctfbruce
ctfbruce marked this pull request as ready for review October 5, 2026 15:34
@ctfbruce ctfbruce added the Ready to merge Reviewed and CI passed; merge in dependency order after required approval. label Oct 5, 2026
@ctfbruce
ctfbruce merged commit ce6d52e into main Oct 5, 2026
16 of 32 checks passed
@vincent10400094
vincent10400094 deleted the fix/retained-work-disposition branch October 8, 2026 00:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready to merge Reviewed and CI passed; merge in dependency order after required approval.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant