Consume operator cassette operations instead of counts #106
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/cassette-ops-consumer"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Phase 3 machine side: the ATM owns its bay counts and applies operator operations instead of counts.
Schema v13 adds
cassette_ops, the dedup ledger. A delta applied twice is wrong and addressable events are re-delivered on every reconnect, so the operator mints an id per op and this table records what was applied. That retires thecreated_atwatermark on this path: it was the only replay defence under absolute counts, but it drops an out-of-order event whole, where per-op ids let the unseen ops through and no-op the rest.A window applies oldest-first by
at, ties broken by id, in one transaction with the count mutation. A recount then a refill is not the same as the reverse.A malformed op, or one naming a bay this machine does not have, is neither applied nor recorded. It stays pending on the operator's dashboard, which is the honest outcome.
The state document gains
applied_ops,seqandschema_version.applied_opsis the acknowledgement leg: echoing ids back is the only way the operator can tell an op that landed from one merely sent.ADR-004's status section is updated and decision 4a is marked superseded.
Merge AFTER aiolabs/spirekeeper#46 is deployed to ariege. Strict cutover, no compatibility code.
135 machine tests and 38 state-machine tests pass, full build clean.