Skip to content

Move PostgreSQL transactions and the execution lease into pgunit - #301

Merged
SaladDay merged 1 commit into
mainfrom
refactor/pgunit
Sep 30, 2026
Merged

SaladDay merged 1 commit into
mainfrom
refactor/pgunit

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

This is the first step of removing the store package. The shared PostgreSQL transaction and execution-lease mechanics move to services/core/internal/persistence/postgres/pgunit, where later domain adapters (persistence/postgres/<domain>pg) can use them without importing store.

What changes

  • pgunit (new):
    • Pool.Transaction: read committed, read-write.
    • Pool.Snapshot: repeatable read, read-only.
    • Lease: the advisory-lock connection, the serializing gate, the ownership ping, cancelling operations only between leased operations, close with the cleanup wait, and the 5 s execution deadline.
  • pgtest (new, tests only):
    • Open(t) for guarded, migrated test databases.
    • OpenIsolated(t, …) for tests of database-wide state such as the lease or provider identity.
  • The connection is fixed at construction:
    • store.New builds a pooled Store.
    • store.NewExecution(ctx, s) acquires the lease, and that lease is both the writer and the authority.
    • Nothing picks a connection by checking whether a lease is present. Execution-only operations on a pooled Store return the typed store.ErrExecutionAuthority. There is no pooled fallback after lease loss or close.
    • AppendTurnEvents checks the whole batch before any write or replay.
  • Deleted:
    • store/execution_lease.go and ExecutionLease.Store().
    • Every direct pgx.Begin/BeginFunc in non-test store code; 31 files now go through pgunit.
  • Transitional: the runtime authority check disappears with store. New adapters take a *pgunit.Lease for execution operations, so authority becomes a type. This is recorded in the new Layering section of IMPLEMENTATION.md.
  • go vet ./services/core/... is clean; the copylocks findings are fixed.

Minor behaviour changes

  • Worker.CheckOwnership is bounded by the 5 s execution deadline.
  • Read-write transactions state READ COMMITTED explicitly.
  • Converted manual transactions roll back with the operation's context, as pgx and the lease already did.
  • Execution-only calls on a pooled Store return ErrExecutionAuthority instead of ErrInvalidInput or ad-hoc errors. No production caller reaches them.

Checks

  • go build ./..., go vet ./services/core/..., check-names.py and the markdown link test pass.
  • go test against PostgreSQL over persistence, store, execution, cmd, sandbox, api, runtime* and tests: 1175 passed, 12 skipped. The skips need a native daemon, a real model or a Docker image; none was for lack of a database.

A blind review (Claude subagent) found nothing material.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

persistence/postgres/pgunit now owns Core's transaction mechanics: pooled
read-write and snapshot transactions, and the execution lease with its
dedicated connection, gate, ownership check, cancellation fence, close and
five-second execution deadline. store runs every transaction through it.

The connection choice is fixed at construction. store.New builds a pooled
Store; store.NewExecution takes the lease and builds the execution writer
whose Session and execution-only transactions run on the leased connection.
Execution-only operations on a pooled Store fail with ErrExecutionAuthority.
ExecutionLease and its Store() view are gone.

persistence/postgres/pgtest is the shared test database helper: the
oac_*_tests guard, migrations, and isolated databases for database-wide
state. It replaces the per-package database setup in store, execution and
sandbox/providers tests.

Also fix the go vet copylocks warnings in the store dispatch fixtures and
record the layering in services/core/IMPLEMENTATION.md.
@SaladDay
SaladDay merged commit 7aee88a into main Sep 30, 2026
5 of 6 checks passed
@SaladDay
SaladDay deleted the refactor/pgunit branch September 30, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant