feat: execute durable client commands through supervisor

This commit is contained in:
2026-09-06 12:18:15 +00:00
parent 3f84d3b2f1
commit 56b15c7f4f
41 changed files with 4272 additions and 66 deletions
+27
View File
@@ -1765,6 +1765,24 @@ rows in order. Advertise capacity and accept new dispatch only in `active`.
Cancellation of one session context must join all its readers/writers before a
new session can use their queues.
The current implementation checkpoint is intentionally split at this seam:
`internal/client/agent.RunOnce` owns the reconnect/session reader and remains
the sole live-session writer; `internal/client/spool` owns the SQLite source of
truth; and `internal/client/agent.Executor` owns process lifetime independently
of the WebSocket context. A bounded event-notification channel wakes the active
writer to assign and send newly appended events, while reconnect replay uses
the same spool rows and a per-session sent cursor. Every accepted dispatch is
stored with its deterministic execution specification (and, for scripts, its
descriptor reservation) before acknowledgement.
Add a schema launch barrier to every implementation of the executor. Persist
`prepared` before entering the supervisor, persist `authorized` before the OS
release boundary, and clear it only when a terminal lifecycle transition is
committed. Startup recovery must convert any non-terminal `authorized` row to
one `interrupted` event before registering a new network session. This is the
at-most-once fence for a crash between process release and the first `running`
event; it is not a substitute for verifying a native process creation identity.
### 7.2 Output capture and offline caps
Create non-blocking readers for stdout and stderr immediately after process
@@ -1917,6 +1935,15 @@ Implement Windows code in platform-specific files so non-Windows builds never
import Windows APIs. Keep launch phases identical across platforms:
`accepted -> launch_prepared -> launch_authorized -> running`, with no shortcut.
The first native adapter is now required to expose this contract through
`internal/client/supervisor.Supervisor`: the non-Windows adapter is test-only,
while the Windows implementation must perform token selection and Job setup
inside the same `Start` call. It may return only after the child has been
assigned to its kill-on-close Job and released; all token/session attempts must
be represented in the returned immutable identity. A failed start clears the
pre-launch barrier and produces one rejected lifecycle event; an uncertain
authorized row is never retried as a fresh process.
Implement one exhaustive token selector; do not scatter token fallback across
launch code: