Skip to content

fix(http): prevent duplicate work across dispatch failure boundaries - #905

Merged
drewstone merged 5 commits into
mainfrom
fix/http-dispatch-execution-boundary
Sep 30, 2026
Merged

drewstone merged 5 commits into
mainfrom
fix/http-dispatch-execution-boundary

Conversation

@drewstone

@drewstone drewstone commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Implemented

The shared HTTP adapter's broad retry catch restarted a worker on terminal HTTP refusals, result decoding and coordinator accounting failures. Its default two retries also repeated operations after a lost response. Worker cancellation could omit already settled receipts.

  • One physical attempt by default. Explicit transport retries remain supported for workers with actual durable idempotency.
  • Restrict the retry catch to transport failures; result parsing and receipt import cannot dispatch work again.
  • Preserve settled receipts on error/cancellation and surface a missing artifact without hiding its charges.
  • Encode the request once; cancel backoff promptly.
  • Refuse paid execution without a real worker cost meter instead of using a casted no-op meter.
  • Keep native scheduling, storage, ledger and worker replay owners unchanged. No new framework, dependency, public result shape or product policy.

Exact-head qualification: passed

Head: 1bd34ad156ff78f4521e4012e48417ed247dedcc.

Maintained CI run 36672177930 completed successfully, including both ci and gepa-release jobs:

  • fresh frozen dependency installation and maintained Biome/model/wire-contract gates;
  • full repository, script and example typechecks;
  • existing repository test suite;
  • actual build/OpenAPI and packed-package export checks;
  • Python client and TypeScript official optimizer integration checks;
  • installed official GEPA and DSPy compatibility;
  • publishable Python distribution verification.

The first run stopped on formatter differences. Those were corrected in the owning source/test files; no gate was skipped or weakened. The successful run above is the corrected current head.

Behavioral evidence

The extended existing HTTP integration file uses real loopback sockets, actual filesystem effects and the native cost ledger. Its seven cases pass; five added cases fail against the unchanged original implementation.

The separate retained local reproduction exercised 15 observation groups, including response loss after effect, malformed response, missing artifact, accounting failure, cancellation, explicitly retried byte stability and cancelled backoff. Before/after effect counts were 3 -> 1 for failed workers, lost responses and failed receipt import; available settled cancellation receipts were preserved.

These groups overlap and are not independent reliability trials. Ledger amounts are synthetic. The earlier local reproduction used a historical dependency closure; it does not replace the fresh full-current-repository qualification now recorded above.

Reproduce

pnpm install --frozen-lockfile
pnpm exec vitest run src/adapters/http.test.ts
pnpm typecheck
pnpm build
pnpm verify:package

docs/http-dispatch.md records the default-retry migration, worker/coordinator accounting boundary, proof scope and production obligations.

Coordination and limits

Independent from #902: that PR owns model-client fallback/attempt accounting; this PR touches only the distributed job transport and its existing integration file.

This does not establish that deployed Auto traffic used this adapter, provider-side exactly-once behavior, outer-orchestrator retry safety, disconnected-client reconciliation, live evaluator admission, policy activation or customer savings. No paid provider call, package version change, merge or deployment was performed. Independent review and current repository merge requirements remain applicable.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

tangletools
tangletools previously approved these changes Sep 30, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 260e347a

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-30T05:04:00Z

tangletools
tangletools previously approved these changes Sep 30, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 127da94a

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-30T05:10:01Z

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 1bd34ad1

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-30T05:11:01Z

@drewstone
drewstone merged commit d02cee0 into main Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants