Skip to content

feat(sending): observe budget decisions and global ledger usage - #1066

Merged
jiashuoz merged 2 commits into
mainfrom
feat/sending-observation-contract
Oct 2, 2026
Merged

jiashuoz merged 2 commits into
mainfrom
feat/sending-observation-contract

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Budget shadow mode previously logged only the last exceeded pool, with an operation identifier, and provided no global-ledger usage or policy-freshness metrics. This adds bounded per-scope decision/deferral counters and a per-process sampler for global usage, policy generation, config mismatch, and observation freshness.

Counters publish only after commit and include account-trust decisions when legacy budgets are disabled. The sampler performs four indexed global-counter reads in a consistent policy snapshot, preserves the last successful sample on errors, and keeps database I/O off /metrics. Operator documentation explains retries, replica aggregation, stale samples, and the distinction between gate decisions and delivered mail.

Validation:

  • Focused race tests cover shadow overruns, enforced holds, rollback/commit failure, disabled budgets, account trust, UTC rollover, corrupt stored policy, bounded labels, and sampler shutdown.
  • Provider-authorization closure guard and formatting checks pass.
  • Live local HTTP/SMTP checks exercised two shadow sends, all four would-hold scopes, usage above 100%, and an enforced hold with no additional SMTP call; the final reviewed binary passed the same checks.
  • Final-head CI passes: 28 checks, including the complete integration suite, coverage gate, race checks, and all image builds; one release-only check is skipped.
  • The full local suite completed with outreach/counting failures (also reproduced on the unchanged base) and timing failures. The isolated contact-due webhook rerun passes. The initial missing SMTP fixture was supplied and the initial cumulative identity timeout was resolved by allowing 20 minutes. Local full-suite success is not claimed; CI is the clean full-suite evidence.
  • Independent correctness and adversarial reviews both pass after fixes for shared-cap hold attribution and database-authoritative UTC sampling. Both findings have regression tests demonstrated failing before the fixes and passing under the race detector.

This is an observation prerequisite. It does not activate controls, raise the compiled contract level, change public APIs, or implement the database-policy source switch/readiness and carryover steps.

@jiashuoz
jiashuoz marked this pull request as ready for review October 2, 2026 09:02
@jiashuoz
jiashuoz merged commit 85d9e0b into main Oct 2, 2026
29 checks passed
@jiashuoz
jiashuoz deleted the feat/sending-observation-contract branch October 2, 2026 10:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant