feat: execute durable client commands through supervisor

This commit is contained in:
2026-09-06 12:18:15 +00:00
parent 3f84d3b2f1
commit 56b15c7f4f
41 changed files with 4272 additions and 66 deletions
+34
View File
@@ -20,6 +20,7 @@ var (
ErrScriptBounds = errors.New("script chunk is outside declared bounds")
ErrScriptState = errors.New("stored script state is corrupt")
ErrScriptTerminal = errors.New("terminal command cannot accept script data")
ErrScriptNotReady = errors.New("script has not been durably committed")
)
type ScriptDescriptor struct {
@@ -33,6 +34,39 @@ type ScriptStatus struct {
Duplicate bool
}
// ScriptBody returns a copy of the verified script body only after the
// contiguous upload has been committed. It is the sole spool read used by the
// supervisor; callers never reconstruct script bytes from individual chunks.
func (store *Store) ScriptBody(ctx context.Context, issueUUID domain.UUID) ([]byte, error) {
if !validUUID(issueUUID) {
return nil, ErrUnknownCommand
}
var row storedScript
var digest []byte
var storedBytes uint64
var compression uint32
var committed int
err := store.db.QueryRowContext(ctx, `SELECT declared_raw_bytes, declared_sha256, received_raw_bytes, stored_bytes, compression, stored_data, charged_bytes, committed FROM scripts WHERE issue_uuid = ?`, issueUUID[:]).Scan(&row.DeclaredBytes, &digest, &row.ReceivedBytes, &storedBytes, &compression, &row.Stored, &row.ChargedBytes, &committed)
if errors.Is(err, sql.ErrNoRows) {
return nil, ErrScriptNotReady
}
if err != nil {
return nil, err
}
if len(digest) != sha256.Size || storedBytes != uint64(len(row.Stored)) || compression != 2 || committed == 0 || row.ReceivedBytes != row.DeclaredBytes {
if committed == 0 {
return nil, ErrScriptNotReady
}
return nil, ErrScriptState
}
copy(row.DeclaredSHA256[:], digest)
body, err := decompressScript(row.Stored, row.ReceivedBytes, store.maxScriptBytes)
if err != nil || sha256.Sum256(body) != row.DeclaredSHA256 {
return nil, ErrScriptState
}
return append([]byte(nil), body...), nil
}
// BeginScript persists the immutable descriptor at command acceptance time. A
// matching replay is harmless; a different descriptor is a protocol conflict.
func (store *Store) BeginScript(ctx context.Context, issueUUID domain.UUID, descriptor ScriptDescriptor) (ScriptStatus, error) {