Skip to content

Give the execution lease to the composition root and the Worker - #312

Merged
SaladDay merged 1 commit into
mainfrom
refactor/execution-owner
Sep 30, 2026
Merged

SaladDay merged 1 commit into
mainfrom
refactor/execution-owner

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Part of #1 (store layering), foundation PR 1f. The composition root now owns the execution lease, and store tests get one fixture value to build adapters from.

Execution lease

  • New execution.Owner{Lease, Store} and Ownership, which *pgunit.Lease implements.
  • cmd/server acquires the lease with pgunit.AcquireLease and passes the same pointer to store.NewExecution(s, lease) and to execution.StartWorker(ctx, dispatcher, owner).
  • StartWorker takes over the lease as soon as it is called. A failed start closes it exactly once, and a started Worker closes it after Run drains. Each close gets its own bounded context.
  • Execution uses the lease directly. The lease is passed explicitly to the runtime manager, cancellation and RunEnvironmentInput.
  • Deleted from store: CheckExecutionOwnership, CancelExecutionOperations, CloseExecution, and store's own lease acquisition.

Store test harness

  • fixtureDB{pool, cipher} holds the pool and cipher each test's Store was built from.
  • startWorker and startWorkerErr do exactly what cmd/server does, and every StartWorker site uses them.
  • publicHandler(t, s, db, keys, engine, …) takes the fixture at all 71 call sites. Later domain cutovers add their adapter inside the fixture without changing call sites.

IMPLEMENTATION.md records the composition and cleanup rule.

Behaviour changes

  • A failed start also returns any lease-close error.
  • A second Core fails at AcquireLease before it builds a Worker.

Checks

Check Result
go build ./..., go vet ./services/core/..., gofmt -l, scripts/check-names.py pass
persistence/... 9 passed
execution/... 201 passed, including new lease tests: start failure closes the lease once, and Run closes it after draining
cmd/... 116 passed
sandbox/providers/... 433 passed
full store package 1038 ran, 12 skipped

The 12 skips need a native daemon or opt-in large storage.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit 83d488c into main Sep 30, 2026
5 of 6 checks passed
@SaladDay
SaladDay deleted the refactor/execution-owner branch September 30, 2026 16:45
cmd/server acquires the execution lease and passes it, with the store
execution writer built on it, to execution.StartWorker as an
execution.Owner. The Worker owns cleanup from that call: a failed start
closes the lease, and Run closes it after cancelling and draining.
Store borrows the lease and no longer acquires, checks, cancels or
closes it for execution.

Store integration tests start the Worker through one startWorker helper
and pass the fixtureDB that built their Store to publicHandler, so later
cutovers change only the helpers.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant