feat: execute durable client commands through supervisor

This commit is contained in:
2026-09-06 12:18:15 +00:00
parent 3f84d3b2f1
commit 56b15c7f4f
41 changed files with 4272 additions and 66 deletions
+19 -3
View File
@@ -28,9 +28,13 @@ const (
// still checks the identity/revision/source invariants because it is a second
// durability boundary and may be called after a restart.
type StartSpec struct {
IssueUUID domain.UUID
CommandRevision uint64
Execution *rvboxv1.ExecutionSpec
IssueUUID domain.UUID
CommandRevision uint64
Execution *rvboxv1.ExecutionSpec
// ScriptBody is the verified, durable body for Execution.script. It is
// supplied by the client spool only after the declared digest/length have
// been checked; command_text requests leave it empty.
ScriptBody []byte
WorkingDirectory string
Environment map[string]string
ExecutionProfiles []string
@@ -60,11 +64,23 @@ type EffectiveIdentity struct {
type Process interface {
IssueUUID() domain.UUID
Identity() EffectiveIdentity
// ReadOutput returns the next bounded stdout/stderr chunk. It continues
// until both child pipes reach EOF, so Wait never reports a terminal
// result before the captured output has drained.
ReadOutput(context.Context) (OutputChunk, error)
Wait(context.Context) (ExitStatus, error)
WriteStdin(context.Context, []byte, bool) error
CloseStdin(context.Context) error
}
// OutputChunk is intentionally raw. Compression, quota admission, local
// ordering, and wire sequencing belong to the client spool rather than the
// operating-system supervisor.
type OutputChunk struct {
Stream rvboxv1.StreamKind
Data []byte
}
type ExitStatus struct {
Code int32
Signaled bool