You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 12d6c41
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/design/2026-09-27-managed-extension-authority.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -128,11 +128,11 @@ The generated WebShell types gain the two task routes, the task schemas and the
128
128
- the record bodies, task states and outbox states, as constants;
129
129
- 7 task ID cases;
130
130
- 50 run start and 32 Monitor start cases;
131
-
-45 single-revision views and 11 run histories, with their outbox membership;
131
+
-46 single-revision views and 12 run histories, with their outbox membership;
132
132
- 2 Monitor chains that both sides commit through their authority or store, and 12 chains they must refuse: one reuses the command that opened another record, and three attach a Runtime again under the same or an older generation, or without an unknown outcome;
133
-
- 10 Broker cases, one per execution state of the Broker's ledger, each with the wire status the Broker reports for it and the execution the Harness reads from that, and 8 wire-status cases.
133
+
- 10 Broker cases, one per execution state of the Broker's ledger, each with the wire status the Broker reports for it and the execution the Harness reads from that.
134
134
135
-
A Python labeler written from this document, independent of both languages and kept outside the repository as for H0b, produced the labels. `managed-extension-projection.test.ts` and `ManagedExtensionProjectionContractTest` both replay the task ID, start, view and history cases. Java maps each Broker case's state; TypeScript maps its wire status and the wire-status cases, and checks that the two readings differ only for `DISPATCHING`, as decision 10 says; and the Broker's `ManagedExtensionExecutionContractTest` checks that the Broker reports those wire statuses. The authority suite, `ManagedExtensionRecordStoreTest` and `ManagedAgentMySqlIT` commit the chains.
135
+
A Python labeler written from this document, independent of both languages and kept outside the repository as for H0b, produced the labels. `managed-extension-projection.test.ts` and `ManagedExtensionProjectionContractTest` both replay the task ID, start, view and history cases. Java maps each Broker case's state; TypeScript maps its wire status, and checks that the two readings differ only for `DISPATCHING`, as decision 10 says; and the Broker's `ManagedExtensionExecutionContractTest` checks that the Broker reports those wire statuses. The authority suite, `ManagedExtensionRecordStoreTest` and `ManagedAgentMySqlIT` commit the chains.
136
136
137
137
`managed-extension-journal-v1.fixtures.json` holds the requests that the TypeScript authority sent through its HTTP store for a Session with two Monitor revisions, the second with a notification input and its wake. The HTTP store test fails when the writer's output changes, and rewrites the file when run with `QWEN_WRITE_GOLDEN=1`. `ManagedSessionStoreIntegrationTest` sends the same requests to the Java store, which must accept every one and project the same task.
138
138
@@ -173,7 +173,7 @@ A Python labeler written from this document, independent of both languages and k
173
173
4.**Logical and physical start.** H0b lets a run stay `admitted` while its execution is already `running_attached`, so such a task shows `pending` with the Runtime state `ready` and no start time. Tightening that rule is a change to the H0b contract.
174
174
5.**Replayed domain records.**`commitDomainRecord` publishes a new body before it detects a replayed command, and returns that body's reference instead of the committed one. `commitExtensionRecord` checks for the replay first; the older method is left for a separate fix.
175
175
6.**Notification wakes.** A revision that commits a notification input also commits its `wake.requested`, but nothing consumes the wake yet. The hosted Session path refuses to reopen a Session while an accepted input has no `turn.settled` (`hosted_turn_recovery_required`), so H3 must run or settle such inputs before it enables a domain that notifies.
176
-
7.**Bodies added later.** The Java store materializes only the bodies it knows and passes the `domain.committed` events of other domains through, as before H0c. A slice that adds a body must reach the server before any writer commits the domain, or backfill the rows from the journal when the server gains the body. Otherwise the first revision that such a server sees for a record is not a start, so it is refused and the writer stops. H0c's only body, `monitor_run`, ships on both sides and stays disabled.
176
+
7. **Bodies added later.** The Java store materializes only the bodies it knows and passes the `domain.committed` events of other domains through, as before H0c. The enabled domains that commit their records as envelopes are listed as `MANAGED_SESSION_ENVELOPE_DOMAINS`, and a body never registers for one of them: the bodies module refuses the collision when it loads, and a reopened authority skips their pre-registration envelopes — records no closed body could ever parse — instead of dying on them. Whichever slice registers the next body owes these four checks: the list, the tripwire, the skip and the key disjointness the skip counts on — the envelope's three keys, `operationId`, `revision` and `previousRecordRef`, must stay out of every body's closed key set, or reopening would skip the body's own committed revisions. A body that ships with its domain from the start, as the H1 and H2 records did, needs no such move. Registering one for a domain that already commits through `commitExtensionRecord` still means reaching the server before any writer commits it, or backfilling its rows from the journal. H0c's only body, `monitor_run`, ships on both sides and stays disabled.
0 commit comments