Retain external facts and harden protocol delivery recovery - #274
Open
patrickleet wants to merge 11 commits into
Open
patrickleet wants to merge 11 commits into
patrickleet wants to merge 11 commits into
Conversation
Retain engine-owned selected exports and share compiled metadata across request seeds. Principal, preset values, scope tokens and visibility authorization remain per request. Public manifests remain independent clones. Validated 1052 library and43 protocol integration tests. In the retained Forge runtime, repeated authenticated GraphQL fell from about1.1s to14–22ms; warm page DOM times fell from3–7s to97–291ms. Cold dev compilation remains separately documented.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Preserve pre-disposal frame fencing, then reopen only the blocked receiver beyond the retirement boundary. Keep unrelated layout subscriptions active. Refs Forge repository preparing incident; all403 JS tests and actual fresh repository live transition pass.
Keep public archive prefix checks fail-closed. Qualify reviewed original single-publication aggregate logs without synthesizing private publications; retain external identity and source snapshot fences.
A failed @LiVe execution (e.g. a statement timeout while storage is unreachable) reached clients as an error-only frame with only the base envelope. The replica required snapshot/live metadata on every live frame with errors, so it replaced the real GraphQL error with "Invalid Distributed GraphQL protocol envelope at extensions.distributed.live". Spec (docs/live-query-delivery.md) now defines that frame as a terminal, receipt-only failure frame. The client surfaces its errors, admits no data, cursors, ownership or command receipts, and reopens the subscription with 1s-30s backoff so live queries recover without a reload. The server producer stops after its first error so a failure can never take a later frame's snapshot/live metadata. Data-bearing frames without live metadata remain invalid. Resolves [[incidents/forge-dashboard-protocol-20260929]] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A single sequential event consumer ran every route for a delivery before receiving the next, so latency-sensitive process policies waited 1-4s behind unrelated projections and kernel effects. A permanently failing message NAK'd without delay was redelivered ~6/s between every new message. - Opt-in delivery lanes (`Service::lane`) within one durable consumer: each lane runs deliveries in broker order; a delivery is acknowledged only after every lane settles it; bounded in-flight window. Sources that settle only in order (Kafka, SQL) keep the sequential loop. - Retryable NATS NAKs back off by delivery count (50ms doubling to 5s, configurable), so a failing message cannot monopolize a consumer. Spec: docs/consumer-delivery-lanes.md (incl. cross-delivery reordering constraints). Tests: lane unit tests, service lane tests, NATS integration tests (publish-after-idle, backoff, lanes over JetStream). Implements [[tasks/forge-provisioning-latency-20260930]] Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pages that open several live subscriptions over the same root lookup
(e.g. git_repositories by id) let the first subscriber own the shared
root list and rejected every later whole frame, including frames whose
shared lists were identical. Fields only the rejected subscription
selects (a repository's branch refs) never updated after a push, and
stored rows could drift from rejected lists ("Loading branches…").
A live frame is now admitted when it provably agrees with the owner on
every shared list (same rows, order and nulls; owner complete and
current); it writes only its own lists. Disagreement or unprovable
agreement is still rejected, and the rejected subscription reopens when
another query rewrites a shared list.
Spec: docs/live-query-delivery.md. Tests: replica-protocol (new
agreement/rejection cases; 408/408).
Resolves [[incidents/forge-branches-page-writes-disabled-20260930]]
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This extends the existing protocol-manifest cache and live-stream recovery work with authenticated external facts. An external ledger or webhook can now retain its own source identity and position without pretending to be an event-sourced aggregate.
Compatibility and migration
Migration 0009 adds delivery aliases while preserving the canonical unique message binding. A replay into a new projection generation still applies the event once. External facts participate in durable transport archival and replay; source position and broker delivery position remain distinct.
No global authority cache, new inbox subsystem, cursor reset, forced poison acknowledgement, or application polling workaround is introduced. See
docs/external-facts.md,docs/protocol-manifest-reuse.md, anddocs/live-retired-owner-handoff.md.Original-log coverage is an offline operator/source-adapter trust boundary, not authentication of arbitrary private payloads. Retain and review original export provenance/digests; missing public occurrences, changed identity/content, unknown private contracts and truncated streams remain errors. No generic one-to-many publication completeness is inferred.
Validation
git diff --checkpassed.Earlier application measurements demonstrated authenticated-query latency declining from roughly 1.1 seconds to 14–22 milliseconds after manifest reuse; these observations are not SLA assertions. Application-wide migration and end-to-end adoption are outside this framework PR's completion claim.