mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 08:03:20 +00:00
Carries the durable multi-agent workflow work (#16904) through this branch. Both PRs touch the same subsystem, so most of this is deciding which of two independent solutions to the same problem survives. #16904 did not generalize past the PTY assumption anywhere, so nothing here is redundant: it hardens the first authority source, this branch adds a second under the same contracts. Schema. Both sides independently wrote a `current < 31` migration from a shared base of 30, with different bodies, and main went on to 38. Version 31 therefore means two different schemas, and the skew checker asserts main's five v31 columns for anything stamped >= 31 — so a database written by this branch failed the completeness check and replayed the whole chain from v6. That is the checker working correctly, not a defect, and the replay is row-safe (every DROP in the chain is a copy-forward rebuild gated on shape, and there is no DELETE or TRUNCATE anywhere in it). Nothing shipped stamped 31 with this branch's content: the commit is in no tag and no release branch. So the migration renumbers to 39 in its own file. It no longer creates `structured_pointer_operations` — that is redundant, because `createTables` runs unconditionally on every open, ahead of migration. Only the widened archive CHECK needs a migration, since IF NOT EXISTS cannot widen a constraint on an existing table. The gratuitous rename of migrate-v13-v30.ts is reverted, which removes a conflict outright. Batch selection. Both sides changed the same region: this branch extracted it verbatim into `selectOrchestrationPointerBatch`, main edited it in place and dropped the JS post-filter. Main is right, and provably so — the unfiltered waiter returns early, so every surviving waiter contributes a concrete type list that SQL excludes byte-exactly (`messages.type` is TEXT with no NOCASE collation), and the trailing slice sits behind an identical SQL LIMIT. Nothing can reach the post-pass in a filtering state, for either lane, and selection is synchronous throughout so no waiter can register inside it. The extraction survives and main's lane now calls it, so the two lanes cannot drift again. The docblock claimed the post-filter caught a mid-selection waiter; that hazard does not exist and the claim is gone. Nothing covered this, so it now has tests against a real database rather than a stub. Delivery gate. This branch gated only `run:` mailboxes, on the premise that a delivery row exists only for a `run:` address. Main made that false — deliveries are keyed by any mailbox handle — and generalized correctly, keying the lookup on the exact handle being nudged, so a coordinator's run delivery cannot suppress the nudges it sends its workers. Adopted. It is worth more here than in the PTY lane: a structured nudge costs a whole provider turn. Archive kind. Main's new `summarizeWorkerOutputArchive` is a two-way switch that JSON-parses every non-transcript_pin kind as a terminal tail, so this branch's `structured_journal` reached `content.lines.every(...)` and threw, at three live call sites. A structured session's journal reports as `transcript`: it IS the session's transcript, and a third source value would both leak the structured/terminal split into a CLI surface this PR keeps uniform and widen a shape that reaches paired clients. PTY pointer refusal. Main shipped the same fix independently and narrower, so this branch's hunk is dropped. Its guard fires only when a session is bound, which is exactly the set the blanket refusal covered — an unbound pty is always admitted, so a denial implies a binding. Also: this branch's release-receipt extraction gives way to main's, with the structured lease check moved into main's lease module; the worker RPC tree moves into main's orchestration/{worker,messaging,federation} layout, with this branch's structured branches replayed into the new homes. pnpm tc clean. Verified by grepping the MERGED files, not the diffs, that main's migration registrations, its six durability attach calls, its reset delete, its fleet-status additions and its dispatch-pointer support all survived — each of those would have been dropped silently by a keep-ours resolution, with no conflict marker and a green typecheck. Both merged files crossed the 300-line cap, which must be split rather than disabled. Four extractions, each a whole step rather than an arbitrary cut: assertExplicitWorkerTerminalUsable (the three refusals that must happen before anything is created), deliverWorkerDispatchPreamble (one preamble, two transports), tearDownFailedWorkerStart (undo what a failed start created), and stopStructuredWorkerForRelease (the close half of a release for a worker with no terminal to close). One thing this merge restores rather than adds: `canDispatchSubWorkers` on the local worker's dispatch preamble. The shared ancestor passed it; main's extraction of startLocalWorker does not, and `buildDispatchPreamble` treats its absence as false, so a locally started worker on main is no longer taught the sub-dispatch verbs. With the default nested depth of 1 that section applied to every first-generation worker, and main still passes the same argument at three other call sites, so this reads as a line lost while moving ~300 lines rather than a decision. Restored here for both lanes, since a worker is taught the same verbs whichever mode it runs in.