Run independent tool-call reads concurrently - #1867
Merged
Merged
Conversation
Contributor
Cloudflare previewTorn down — the PR is closed. |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-marketing | b3a0ddb | Commit Preview URL Branch Preview URL |
Aug 30 2026, 04:54 AM |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-cloud | b3a0ddb | Aug 30 2026, 04:56 AM |
@executor-js/cli
@executor-js/config
@executor-js/execution
@executor-js/sdk
@executor-js/codemode-core
@executor-js/runtime-quickjs
@executor-js/plugin-file-secrets
@executor-js/plugin-graphql
@executor-js/plugin-keychain
@executor-js/plugin-mcp
@executor-js/plugin-onepassword
@executor-js/plugin-openapi
executor
commit: |
RhysSullivan
marked this pull request as ready for review
August 30, 2026 05:04
Merged
midego1
added a commit
to midego1/executor
that referenced
this pull request
Aug 31, 2026
Upstream's execute-read-concurrency tests (UsefulSoftwareCo#1867) run execute under adversarial scheduler budgets, and with the audit wrapper in place two of them hung the run loop. The A/B pointed at Effect.timeout around the tool-call-log insert. Investigating why exposed the real defect: the write runs in an onExit finalizer, which is uninterruptible, so the timeout's interrupt could never land. The 2s cap this feature shipped with was decorative in exactly the sick-database case it was written for — it protected nothing, and its timer machinery deadlocked under adversarial budgets. Making the write interruptible inside the finalizer did not help; the timer itself is the problem there. So the write is now awaited, deliberately unbounded, and honest about it: bounding a stalled driver is the driver's job; what the wrapper owes the caller is that a row exists before the call returns and that a failed write never changes the call. TOOL_CALL_LOG_WRITE_TIMEOUT is gone from the public surface. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every MCP tools/call paid for its storage reads serially on the dynamic invoke path in packages/core/sdk/src/executor.ts. Two sites now overlap their independent reads:
Nothing moves relative to approval enforcement, the validateToolArgs pre-check, OAuth refresh coalescing, or the shape-memory path.
Tests: two overlap probes (instrumented FumaDb wrapper plus a counting credential provider) that fail when the reads are sequential, a regression test that a declined approval resolves no credentials, and a ConnectionNotFoundError test for a tool row that outlives its connection. Full packages/core/sdk suite, repo typecheck, lint, and format are green.