Commit 5bc039e
fix(run-engine): enforce the writer-client rule, and close the deferred-output fail-open
An exhaustive walk of the deferred-output state space found the mechanism
sound, and asked for one change plus two cheap ones.
The required-writer rule could not be enforced by the type system. ReadClient
admits both a writer and a replica, and the two are structurally identical --
separable only by a runtime brand -- so a caller passing readOnlyPrisma would
type-check and quietly reinstate the replica-lag window that turns a committed
child output into a refused resume. The reader now asserts the brand. It is
built once at wiring time, so the check costs nothing per read.
A record marked as deferring its output while carrying no run id was the one
place this design failed OPEN rather than loud: it resolved the waitpoint with
no output and no error. Unreachable from the current record build, which
requires the run id before it marks anything derivable, but a reordering of
those conditions is all it would take. It now throws, like a record arriving
with no reader wired.
Also pins the orphan case against the oracle: a RUN waitpoint whose completing
run is gone keeps its own output inline and must omit the run sub-object, which
only the differential comparison catches.
Records the premise the deferred read rests on: the completing run's output
still holds what the waitpoint was completed with. Nothing overwrites it today,
and if that changes the divergence would be silent rather than loud.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>1 parent 5a42f06 commit 5bc039e
3 files changed
Lines changed: 79 additions & 2 deletions
File tree
- internal-packages/run-engine/src/engine/waitpointCoordinator
internal-packages/run-engine/src/engine/waitpointCoordinator/completedWaitpointEquivalence.test.ts
Lines changed: 23 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
236 | 236 | | |
237 | 237 | | |
238 | 238 | | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
239 | 262 | | |
240 | 263 | | |
241 | 264 | | |
| |||
Lines changed: 26 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
248 | 248 | | |
249 | 249 | | |
250 | 250 | | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
251 | 276 | | |
252 | 277 | | |
253 | 278 | | |
| |||
Lines changed: 30 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
1 | 2 | | |
2 | 3 | | |
3 | 4 | | |
| |||
76 | 77 | | |
77 | 78 | | |
78 | 79 | | |
79 | | - | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
80 | 91 | | |
81 | 92 | | |
82 | 93 | | |
83 | 94 | | |
84 | 95 | | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
85 | 103 | | |
86 | 104 | | |
87 | 105 | | |
| |||
295 | 313 | | |
296 | 314 | | |
297 | 315 | | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
298 | 327 | | |
299 | 328 | | |
300 | 329 | | |
| |||
0 commit comments