From 37b62fa0249337928b56cf1b37f561849a137fcb Mon Sep 17 00:00:00 2001 From: Sawyer Cutler Date: Sun, 30 Aug 2026 22:41:34 -0700 Subject: [PATCH 1/2] Add tests for exclusive-allocation run-key history --- .../run-key-history/test/listener.test.ts | 95 ++++++------------- 1 file changed, 30 insertions(+), 65 deletions(-) diff --git a/packages/run-key-history/test/listener.test.ts b/packages/run-key-history/test/listener.test.ts index 105a9409a..c263c8469 100644 --- a/packages/run-key-history/test/listener.test.ts +++ b/packages/run-key-history/test/listener.test.ts @@ -49,7 +49,7 @@ describe("createRunKeyHistoryListener", () => { ]); }); - test("skips an exclusive-allocation ack, mirroring vendor's own guard", () => { + test("records an exclusive-allocation ack", () => { const events = createFakeEventBus(); const store = createFakeStore(); createRunKeyHistoryListener({ events, store }); @@ -64,7 +64,9 @@ describe("createRunKeyHistoryListener", () => { }, }); - expect(store.calls).toEqual([]); + expect(store.calls).toEqual([ + { runAddress: "run_1@ten1.test", publicKey: "key-a" }, + ]); }); test("dispose stops observing further acks", () => { @@ -78,70 +80,33 @@ describe("createRunKeyHistoryListener", () => { expect(store.calls).toEqual([]); }); - // CL-7274: the "skips an exclusive-allocation ack" test above documents an - // assumption -- that vendor "skips its own workflow_run update for the same - // ack" the way this listener does -- that does not hold. - // - // Read from vendored source, not inferred: - // - vendor/intx/hub-sessions/src/ws/sidecar-handler.ts:3070-3094 - // (`handleDeployAck`) stamps `allocated: {...}` onto every - // `agent.deploy.ack` emitted for a connection whose `identity.kind` is - // "allocated" -- unconditionally, for every exclusive-allocation deploy. - // - vendor/intx/hub-sessions/src/session-service.ts:1812-1872 - // (`updateAnchorPublicKeyUnderAllocationLock`) reads that SAME ack's - // `publicKey` (via `emitSourceRefDeployFrame` -> `sendAgentDeployToAllocation`) - // and unconditionally writes it onto `workflow_run.public_key` -- no - // `allocated` guard of its own. It is called from - // `deployPreparedCodeSourcedWorkflow` (session-service.ts:1884), which - // `workflow-allocation-service.ts:387`'s `deployReadyAllocation` drives - // from apps/hub/src/index.ts's live 1s allocation-reconciliation loop - // (`onReady` callback) for every exclusive-allocation deploy AND every - // allocation replacement after a sidecar failure (the prior key is first - // nulled by vendor/intx/db/src/sidecar-allocation-store.ts:620-631's - // `beginReplacement`, then re-stamped here). - // - // So vendor's OWN write to `workflow_run.public_key` for this ack is NOT - // event-driven and carries no `allocated` filter -- only THIS listener (and - // `hub-session-orchestrator.ts`'s own event-driven mirror of it) skip the - // ack. The key rotates; run-key-history never observes it. Every - // exclusive-allocation-deployed workflow run -- a live, wired-up product - // path (apps/hub/src/index.ts's `sidecarPlacement`/dedicated-capacity - // feature) -- has a permanent, 100%-reproducible history gap: not one - // key, ever, including its very first one. - // - // This test is `.failing`: it documents the gap against the CURRENT listener - // contract without turning it red for everyone. Flip it to a plain `test` - // once the fix (or the upstream ruling from CL-7274) lands. - test.failing( - "CL-7274: an exclusive-allocation ack still rotates workflow_run.public_key, so it must be recorded", - () => { - const events = createFakeEventBus(); - const store = createFakeStore(); - createRunKeyHistoryListener({ events, store }); + // Exclusive-allocation deploys stamp `allocated` on the ack and rotate + // `workflow_run.public_key` on the service path + // (`updateAnchorPublicKeyUnderAllocationLock`), not the orchestrator + // listener. History must still record that key. + test("an exclusive-allocation ack still rotates workflow_run.public_key, so it must be recorded", () => { + const events = createFakeEventBus(); + const store = createFakeStore(); + createRunKeyHistoryListener({ events, store }); - // Models vendor's OWN independent, unconditional write to - // `workflow_run.public_key` for this exact ack (session-service.ts:1853). - const workflowRun: { publicKey: string | null } = { publicKey: null }; - events.on("agent.deploy.ack", (event) => { - workflowRun.publicKey = event.publicKey; - }); + const workflowRun: { publicKey: string | null } = { publicKey: null }; + events.on("agent.deploy.ack", (event) => { + workflowRun.publicKey = event.publicKey; + }); - events.emit({ - agentAddress: "run_1@ten1.test", - publicKey: "key-a", - allocated: { - allocationId: "alloc_1", - anchorRunId: "run_1", - generation: 1, - }, - }); + events.emit({ + agentAddress: "run_1@ten1.test", + publicKey: "key-a", + allocated: { + allocationId: "alloc_1", + anchorRunId: "run_1", + generation: 1, + }, + }); - // The rotation is real and already landed on workflow_run... - expect(workflowRun.publicKey).toBe("key-a"); - // ...but run-key-history never recorded it. This is the gap. - expect(store.calls).toEqual([ - { runAddress: "run_1@ten1.test", publicKey: "key-a" }, - ]); - }, - ); + expect(workflowRun.publicKey).toBe("key-a"); + expect(store.calls).toEqual([ + { runAddress: "run_1@ten1.test", publicKey: "key-a" }, + ]); + }); }); From 88192f48c8b5bec2194d590adfa0fcdbd8e64d4c Mon Sep 17 00:00:00 2001 From: Sawyer Cutler Date: Sun, 30 Aug 2026 22:41:46 -0700 Subject: [PATCH 2/2] Record exclusive-allocation deploys in run-key history --- packages/run-key-history/src/listener.ts | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/packages/run-key-history/src/listener.ts b/packages/run-key-history/src/listener.ts index fdf9b1885..21925c314 100644 --- a/packages/run-key-history/src/listener.ts +++ b/packages/run-key-history/src/listener.ts @@ -34,11 +34,11 @@ export type RunKeyHistoryListener = { /** * Subscribes to `agent.deploy.ack` and records every observed key - * against `RunKeyHistoryStore`. Mirrors vendor's own guard: an - * exclusive-allocation ack (`allocated !== undefined`) publishes its - * key only after every deploy and asset pack succeeds under the - * allocation generation fence, so it is skipped here exactly as - * vendor skips its own `workflow_run` update for the same ack. + * against `RunKeyHistoryStore`, including exclusive-allocation acks + * (`allocated !== undefined`). Vendor's orchestrator listener skips + * those acks when writing `workflow_run.public_key`; the service path + * (`updateAnchorPublicKeyUnderAllocationLock`) still stamps the key, + * so history must record it too. */ export function createRunKeyHistoryListener( deps: CreateRunKeyHistoryListenerDeps, @@ -46,7 +46,6 @@ export function createRunKeyHistoryListener( const log = getLogger(["run-key-history", "listener"]); const unsubscribe = deps.events.on("agent.deploy.ack", (event) => { - if (event.allocated !== undefined) return; deps.store .recordObservedKey(event.agentAddress, event.publicKey) .catch((cause: unknown) => {