Repository navigation
Commit 8341ed2
feat(automation): once-per-tick-window dispatch claims for scheduled flows (#16585)
* feat(automation): once-per-window dispatch claims for scheduled flows
A `schedule` (cron) flow now takes a persisted `(flow, tick-window)` claim in
the same `sys_flow_dispatch` ledger a `time_relative` flow claims per
`(flow, window, record)`, and settles that claim with the run's outcome. That
closes the two live duplicate-delivery doors: a restart inside a tick window,
and an operator `IJobService.replay()` of a window that was already delivered.
`DbJobAdapter.replay` refuses a delivered window with the ADR-0112
`RESOURCE_CONFLICT` / 409 envelope the contract declares, and `{ force: true }`
is the door past it. The error-isolation catch in the schedule trigger keeps
protecting the ticker exactly as before; it stopped being silent, recording the
throw on the claim as a failed outcome instead of leaving the run
indistinguishable from a delivered one.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* test(trigger-schedule): pin the ticker property on the trigger's own handler
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* chore: changeset for the scheduled-flow dispatch-claim ledger
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* fix(automation): canonical by-id update for the claim settle, and split the pins by subject
The ledger's settle() wrote update(object, id, data, options); no engine
dispatches on that four-argument form. It is now the by-id payload shape
(update(object, { id, ...fields }, options)) the ObjectQL engine takes, and the
test doubles route through assertEngineUpdateDispatch so a fake can never again
be looser than the engine it stands in for.
The DbJobAdapter.replay pins move to service-job's own suite: reaching them from
trigger-schedule needed an entry in the shrink-only test-source-alias registry,
and that package's rootDir forecloses the paths route.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* fix(trigger-schedule): bound the replay pass to one per flow
A pass a job service asked for and then abandoned no longer outlives its
window: at most one outstanding pass per bound flow, dropped with the binding.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* test(service-job): route the replay-guard fake's update through the engine predicate
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* fix(automation): succeeded is absorbing in the dispatch-claim ledger
Patch round 1 on the contract review. settle() refuses succeeded -> failed in
both stores and in the engine's in-process fallback: a forced replay that throws
must not rewrite a delivered window, because that silently reopens the unforced
re-delivery door this card exists to close. failed -> succeeded stays required.
The two headers that recorded the immutability retirement stated a rule the code
did not hold; both now state the rule as implemented. Barrel surface narrowed to
what has consumers, and ReplayGuard is nameable from service-job.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* test(automation): pin the counting engine double to the dispatch predicate
It restates update() rather than passing the base double's through, so it is a
double in its own right and carries the predicate itself.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
* docs(automation): correct four statements this PR's own prose got wrong
Text only; no behaviour change and no new pins.
- settle()'s absorbing rule is enforced read-then-write against the persisted
store, so it is not atomic. The window is named rather than closed: the
engine's by-id update cannot express a conditional write.
- the replay-pass residue comment claimed a later fire clears an abandoned
pass. It does not -- the handler deletes only on a key match -- so the pass
outlives every fire in every other window, inert throughout.
- the readDispatch degradation warning described the both-absent ledger while
reading as if it covered a store with settle() but no read(), which is
weaker still.
- the once-schedule changeset line asserted an unmeasured restart behaviour
instead of the measured consequence: a replay before the due instant claims
the single window, so the real fire then no-ops.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zTkyNHJ7TkuN2oXtP5x37
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>1 parent 55bbd92 commit 8341ed2
18 files changed
Lines changed: 1849 additions & 71 deletions
File tree
- .changeset
- content/docs/permissions
- docs/audits
- packages
- services
- service-automation/src
- service-job/src
- triggers/trigger-schedule
- src
- scripts
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
98 | 98 | | |
99 | 99 | | |
100 | 100 | | |
101 | | - | |
| 101 | + | |
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| |||
147 | 147 | | |
148 | 148 | | |
149 | 149 | | |
150 | | - | |
| 150 | + | |
151 | 151 | | |
152 | | - | |
153 | | - | |
| 152 | + | |
| 153 | + | |
154 | 154 | | |
155 | 155 | | |
156 | 156 | | |
| |||
161 | 161 | | |
162 | 162 | | |
163 | 163 | | |
164 | | - | |
| 164 | + | |
165 | 165 | | |
166 | 166 | | |
167 | 167 | | |
168 | 168 | | |
169 | 169 | | |
170 | | - | |
| 170 | + | |
171 | 171 | | |
172 | 172 | | |
173 | 173 | | |
174 | | - | |
| 174 | + | |
175 | 175 | | |
176 | 176 | | |
177 | 177 | | |
| |||
183 | 183 | | |
184 | 184 | | |
185 | 185 | | |
186 | | - | |
187 | | - | |
| 186 | + | |
| 187 | + | |
188 | 188 | | |
189 | | - | |
| 189 | + | |
190 | 190 | | |
191 | | - | |
| 191 | + | |
192 | 192 | | |
193 | 193 | | |
194 | 194 | | |
195 | 195 | | |
196 | | - | |
| 196 | + | |
197 | 197 | | |
198 | 198 | | |
199 | 199 | | |
200 | 200 | | |
201 | 201 | | |
202 | | - | |
| 202 | + | |
203 | 203 | | |
204 | 204 | | |
205 | 205 | | |
206 | 206 | | |
207 | 207 | | |
208 | | - | |
| 208 | + | |
209 | 209 | | |
210 | 210 | | |
211 | 211 | | |
| |||
224 | 224 | | |
225 | 225 | | |
226 | 226 | | |
227 | | - | |
| 227 | + | |
228 | 228 | | |
229 | 229 | | |
230 | 230 | | |
231 | | - | |
232 | | - | |
| 231 | + | |
| 232 | + | |
233 | 233 | | |
234 | | - | |
| 234 | + | |
235 | 235 | | |
236 | 236 | | |
Lines changed: 10 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
33 | | - | |
| 32 | + | |
| 33 | + | |
34 | 34 | | |
35 | | - | |
| 35 | + | |
36 | 36 | | |
37 | | - | |
| 37 | + | |
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
55 | | - | |
| 55 | + | |
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
59 | | - | |
60 | | - | |
| 59 | + | |
| 60 | + | |
61 | 61 | | |
62 | | - | |
| 62 | + | |
63 | 63 | | |
64 | 64 | | |
65 | 65 | | |
| |||
160 | 160 | | |
161 | 161 | | |
162 | 162 | | |
| 163 | + | |
163 | 164 | | |
164 | 165 | | |
165 | 166 | | |
| |||
0 commit comments