Skip to main content

aion_server/worker/
declared_body.rs

1//! Server-side execution of declared action bodies.
2//!
3//! An action whose deployed contract carries an [`ActionBodyContract`] is
4//! executed BY THE SERVER, with no connected worker: the dispatch is
5//! intercepted at the [`ActivityDispatcher`] seam before task-queue routing,
6//! the declared command runs through the worker SDK's own executor
7//! ([`aion_worker::shell::ShellAction`] — argv-element substitution, no
8//! shell, process-group containment), and the result flows back through the
9//! engine's normal completion path. The engine still schedules, records, and
10//! replays the activity exactly as if a worker had served it.
11//!
12//! Actions with no declared body are delegated to the wrapped production
13//! dispatcher unchanged, so remote workers keep working exactly as before.
14//!
15//! # The command is readable while it runs
16//!
17//! The executing activity carries a live transcript seam
18//! ([`ActivityContext::with_transcript`](aion_worker::ActivityContext::with_transcript)),
19//! so every line the command writes to stdout or stderr is published onto the
20//! server's transcript sequencer AS IT ARRIVES — the same stream, envelope, and
21//! cursor reads an agent step's transcript uses (see
22//! [`super::declared_body_transcript`]). The activity's recorded result is
23//! untouched by this: it still carries the command's complete output.
24//!
25//! # The command can be stopped, by its bound and by its run
26//!
27//! Two things end a server-executed command early, and both reach the same
28//! cancellation the worker path already acts on — `SIGTERM` → grace →
29//! `SIGKILL` across the whole process group, with the verdict withheld until
30//! the group has been proven gone.
31//!
32//! The first is the attempt's own deadline. A dispatch carrying an authored
33//! per-attempt timeout (#223) ends its command at that bound HERE, in the
34//! server, where the process is — see [`run_bounded`]. The engine's own
35//! deadline stops the run WAITING and cannot reach a process, which is the
36//! right division of labour for a remote worker and no division at all for a
37//! body the server itself started. A dispatch that authored no bound is
38//! unbounded, exactly as before: the server adds no deadline of its own.
39//!
40//! The second is the run being cancelled. Every executing attempt registers in
41//! [`super::declared_body_cancel::DeclaredCommandAttempts`] for exactly as long
42//! as its command runs, which is how the cancel path reaches an activity no
43//! worker holds and no heartbeat tracks. An attempt that cannot register is
44//! refused rather than run: a command a cancelled run could not stop is the
45//! defect the registration exists to prevent.
46
47use std::collections::BTreeMap;
48use std::sync::{Arc, OnceLock};
49
50use aion::{ActivityDispatch, ActivityDispatcher};
51use aion_package::{ActionBodyContract, ContentHash};
52use aion_worker::shell::ShellAction;
53
54use super::declared_body_ambiguity::{DeclaringVersion, ambiguous_body_refusal};
55use super::declared_body_cancel::DeclaredCommandAttempts;
56use super::declared_body_selection::select_declared_body;
57use super::declared_body_transcript::publish_declared_transcript;
58use super::workspace_root::{WORKSPACE_ROOT_PLACEHOLDER, WorkspaceRoot};
59use crate::activity_publisher::ActivityEventPublisher;
60
61/// What a declared-body lookup found for one `(task_queue, action)` address.
62#[derive(Clone, Debug)]
63pub enum DeclaredBodyLookup {
64    /// No retained contract declares a body for this action — it is a
65    /// requirement on an out-of-band worker and must be delegated.
66    None,
67    /// Exactly one distinct body is declared across every retained package
68    /// version. Safe to execute.
69    Declared(ActionBodyContract),
70    /// Retained package versions declare DIFFERENT bodies for this action.
71    /// Executing one of them would guess which deploy the running workflow
72    /// meant, so the dispatch is refused by name instead.
73    Ambiguous {
74        /// Every retained version that declares a body for this action, in
75        /// catalog order. Carried rather than counted because the refusal has
76        /// to name the versions the operator must retire — a bare count leaves
77        /// them holding a terminal error with no way to act on it.
78        declaring: Vec<DeclaringVersion>,
79    },
80    /// The catalog could not be read. The reader reports why; the dispatch
81    /// is delegated so a readable worker path can still serve it.
82    Unreadable(String),
83}
84
85/// Which run a declared-body lookup is being made for.
86///
87/// A body is a property of the run's own package version, not of the queue, so
88/// the lookup cannot answer correctly without knowing whose dispatch it is —
89/// see [`super::declared_body_selection`].
90#[derive(Clone, Copy, Debug)]
91pub struct DispatchingRun<'a> {
92    /// The workflow the activity belongs to.
93    pub workflow_id: &'a aion_core::WorkflowId,
94    /// The concrete run within that workflow.
95    pub run_id: &'a aion_core::RunId,
96}
97
98/// A reader over the deployed contracts' declared action bodies.
99pub trait DeclaredBodies: Send + Sync {
100    /// Look up the declared body for `action` on `task_queue`, as the run
101    /// issuing the dispatch sees it.
102    fn body_for(
103        &self,
104        task_queue: &str,
105        action: &str,
106        run: DispatchingRun<'_>,
107    ) -> DeclaredBodyLookup;
108}
109
110/// Shared, install-once handle the dispatcher holds from construction and the
111/// boot path fills in once the engine exists.
112///
113/// Mirrors [`super::QueueDeclarationSource`]: the dispatcher is built before
114/// the engine, so the seam it consults is handed over afterwards through a
115/// clone of this handle rather than by rebuilding the dispatcher.
116#[derive(Clone, Default)]
117pub struct DeclaredBodySource {
118    inner: Arc<OnceLock<Arc<dyn DeclaredBodies>>>,
119}
120
121impl std::fmt::Debug for DeclaredBodySource {
122    fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
123        formatter
124            .debug_struct("DeclaredBodySource")
125            .field("installed", &self.inner.get().is_some())
126            .finish()
127    }
128}
129
130impl DeclaredBodySource {
131    /// Install the reader. A second install is ignored and logged: the source
132    /// is process-wide and must not silently change identity.
133    pub fn install(&self, source: Arc<dyn DeclaredBodies>) {
134        if self.inner.set(source).is_err() {
135            tracing::warn!("declared body source already installed; ignoring duplicate set");
136        }
137    }
138
139    /// Look up the declared body, or [`DeclaredBodyLookup::None`] when no
140    /// reader is installed yet.
141    ///
142    /// An uninstalled consult is stated at ERROR before delegating to the
143    /// worker path, never silently: a dispatch can only reach this seam from
144    /// a live run, and a live run's deploy is durable — so "nothing installed
145    /// yet" is a boot-ordering defect, not an empty catalog. This exact
146    /// silence was #266 Defect A: startup recovery replay re-dispatched
147    /// adopted in-flight declared-body activities before
148    /// `install_engine_backed_seams` filled this source, and every one fell
149    /// through here to a queue with no pollers and parked forever. The fix
150    /// (deferred startup recovery) removes the caller; this arm stays loud so
151    /// any future pre-install dispatch path names itself in the log instead
152    /// of stranding runs silently.
153    #[must_use]
154    pub fn body_for(
155        &self,
156        task_queue: &str,
157        action: &str,
158        run: DispatchingRun<'_>,
159    ) -> DeclaredBodyLookup {
160        self.inner.get().map_or_else(
161            || {
162                tracing::error!(
163                    operation = "declared_command_dispatch",
164                    task_queue,
165                    action,
166                    workflow_id = %run.workflow_id,
167                    run_id = %run.run_id,
168                    "declared body source consulted before it was installed; the dispatch \
169                     falls through to the worker path and will park if the queue's only \
170                     service is its declared bodies (#266 boot-ordering defect)"
171                );
172                DeclaredBodyLookup::None
173            },
174            |source| source.body_for(task_queue, action, run),
175        )
176    }
177}
178
179/// Reads declared bodies out of the engine's live workflow catalog.
180pub struct EngineDeclaredBodies {
181    engine: Arc<aion::Engine>,
182}
183
184impl EngineDeclaredBodies {
185    /// Build a reader over `engine`'s catalog.
186    #[must_use]
187    pub const fn new(engine: Arc<aion::Engine>) -> Self {
188        Self { engine }
189    }
190}
191
192impl std::fmt::Debug for EngineDeclaredBodies {
193    fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
194        formatter.write_str("EngineDeclaredBodies")
195    }
196}
197
198impl EngineDeclaredBodies {
199    /// The package version `run` is pinned to, or `None` when the registry
200    /// cannot name it.
201    ///
202    /// Two ways to reach `None`, and both are reported rather than swallowed:
203    /// the run has no handle (it left the registry), or the registry could not
204    /// be read at all. Neither is a reason to guess a body — the caller falls
205    /// back to the queue-wide reading, which refuses on disagreement.
206    fn version_of(&self, run: DispatchingRun<'_>) -> Option<ContentHash> {
207        match self.engine.registry().get(run.workflow_id, run.run_id) {
208            Ok(Some(handle)) => Some(handle.loaded_version().clone()),
209            Ok(None) => {
210                tracing::warn!(
211                    operation = "declared_command_dispatch",
212                    workflow_id = %run.workflow_id,
213                    run_id = %run.run_id,
214                    "no registry handle for the dispatching run; resolving its body \
215                     from the whole queue instead of from its own package version"
216                );
217                None
218            }
219            Err(error) => {
220                tracing::error!(
221                    operation = "declared_command_dispatch",
222                    workflow_id = %run.workflow_id,
223                    run_id = %run.run_id,
224                    %error,
225                    "registry unreadable while resolving the dispatching run's version; \
226                     resolving its body from the whole queue instead"
227                );
228                None
229            }
230        }
231    }
232}
233
234impl DeclaredBodies for EngineDeclaredBodies {
235    fn body_for(
236        &self,
237        task_queue: &str,
238        action: &str,
239        run: DispatchingRun<'_>,
240    ) -> DeclaredBodyLookup {
241        let contracts = match self.engine.worker_contracts_for_queue(task_queue) {
242            Ok(contracts) => contracts,
243            Err(error) => return DeclaredBodyLookup::Unreadable(error.to_string()),
244        };
245        // The RAW retained set is the right input here, unlike worker admission
246        // (see `Engine::worker_contracts_for_queue`): a run pinned to a version
247        // nothing else can reach still has to execute that version's body. What
248        // narrows the answer is the run's own identity, not reachability.
249        select_declared_body(&contracts, action, self.version_of(run).as_ref())
250    }
251}
252
253/// The dispatcher decorator that executes declared bodies at the server.
254///
255/// Wraps the production dispatcher. Consults the declared-body source before
256/// every dispatch; delegates untouched whenever the action carries no body.
257pub struct DeclaredCommandDispatcher {
258    inner: Arc<dyn ActivityDispatcher>,
259    bodies: DeclaredBodySource,
260    attempts: DeclaredCommandAttempts,
261    tokio: tokio::runtime::Handle,
262    workspace_root: WorkspaceRoot,
263    transcript: ActivityEventPublisher,
264}
265
266impl DeclaredCommandDispatcher {
267    /// Wrap `inner`, consulting `bodies` before every dispatch, registering
268    /// every attempt it executes in `attempts` so the run's cancel can reach
269    /// it, expanding `{workspace_root}` in declared commands with the
270    /// server-resolved `workspace_root`, and streaming each executed command's
271    /// output onto `transcript` — the deployment's one transcript sequencer,
272    /// shared with every agent step.
273    ///
274    /// `attempts` is required rather than optional because a dispatcher without
275    /// one would execute commands nothing could stop, which is precisely the
276    /// state this argument exists to end.
277    #[must_use]
278    pub fn new(
279        inner: Arc<dyn ActivityDispatcher>,
280        bodies: DeclaredBodySource,
281        attempts: DeclaredCommandAttempts,
282        tokio: tokio::runtime::Handle,
283        workspace_root: WorkspaceRoot,
284        transcript: ActivityEventPublisher,
285    ) -> Self {
286        Self {
287            inner,
288            bodies,
289            attempts,
290            tokio,
291            workspace_root,
292            transcript,
293        }
294    }
295
296    /// Parse the declared command into the executor's action, with the
297    /// server-resolved `{workspace_root}` already spliced in.
298    ///
299    /// Ratification condition (#139): a body that USES the placeholder is
300    /// refused terminally, by name, when the root cannot resolve to an absolute
301    /// directory that exists — no fallback to cwd, temp, or anything else. A
302    /// body without the placeholder never reaches the resolution at all
303    /// (`expand` returns `Ok(None)` untouched).
304    fn declared_action(
305        &self,
306        request: &ActivityDispatch,
307        command: &str,
308    ) -> Result<ShellAction, String> {
309        let expanded = self.workspace_root.expand(command).map_err(|error| {
310            format!(
311                "terminal:declared body for action `{name}` uses the {placeholder} \
312                 placeholder and cannot dispatch: {error}",
313                name = request.name,
314                placeholder = WORKSPACE_ROOT_PLACEHOLDER,
315            )
316        })?;
317        if let Some(expansion) = &expanded {
318            tracing::info!(
319                operation = "declared_command_dispatch",
320                workflow_id = %request.workflow_id,
321                activity_id = %request.activity_id,
322                activity_name = %request.name,
323                task_queue = %request.task_queue,
324                attempt = request.attempt,
325                workspace_root = %expansion.workspace_root,
326                "expanded the workspace-root placeholder in the declared command"
327            );
328        }
329        let command = expanded
330            .as_ref()
331            .map_or(command, |expansion| expansion.command.as_str());
332        ShellAction::new(command).map_err(|error| {
333            // The AWL checker refuses these at compile time, so reaching this
334            // arm means a defective contract got deployed — name the defect
335            // rather than hiding it behind a generic dispatch failure.
336            format!("terminal:declared command failed to parse at dispatch: {error}")
337        })
338    }
339
340    /// Put the attempt on this server's cancel path BEFORE its command starts.
341    ///
342    /// The returned guard keeps it there for exactly as long as the command
343    /// runs, so an attempt that ended — completed, failed, or unwound — can
344    /// never be signalled afterwards. A registration that cannot be made is a
345    /// command nothing could stop, so the dispatch is refused rather than run:
346    /// an uncancellable command on the operator's machine is the whole defect
347    /// this registration exists to prevent, and starting one to avoid an error
348    /// message would be choosing it.
349    fn join_cancel_path(
350        &self,
351        request: &ActivityDispatch,
352        cancellation: &aion_worker::ActivityCancellationHandle,
353    ) -> Result<super::DeclaredAttemptRegistration, String> {
354        self.attempts
355            .register(
356                super::AttemptKey::new(
357                    request.workflow_id.clone(),
358                    request.run_id.clone(),
359                    request.activity_id.clone(),
360                    request.attempt,
361                ),
362                cancellation.clone(),
363            )
364            .map_err(|error| {
365                format!(
366                    "terminal:declared body for action `{name}` cannot dispatch: the attempt \
367                     could not join this server's cancel path, and a command a cancelled run \
368                     could not stop must not be started: {error}",
369                    name = request.name,
370                )
371            })
372    }
373
374    /// Execute one declared command attempt and encode the outcome onto the
375    /// FFI string contract (`retryable:`/`terminal:` on the error side).
376    fn run_declared_command(
377        &self,
378        request: &ActivityDispatch,
379        command: &str,
380    ) -> Result<String, String> {
381        let arguments = decode_arguments(&request.input)?;
382        let action = self.declared_action(request, command)?;
383        // The live transcript seam for this attempt. The context owns the
384        // sending end, so dropping it after the run closes the stream and ends
385        // the pump — which is then awaited, so no observed line is abandoned
386        // unpublished when the command finishes.
387        let (events, drain) = tokio::sync::mpsc::unbounded_channel();
388        let (context, cancellation) = aion_worker::ActivityContext::with_transcript(
389            request.workflow_id.clone(),
390            request.run_id.clone(),
391            request.activity_id.clone(),
392            request.attempt,
393            events,
394        );
395        let registration = self.join_cancel_path(request, &cancellation)?;
396
397        tracing::info!(
398            operation = "declared_command_dispatch",
399            workflow_id = %request.workflow_id,
400            activity_id = %request.activity_id,
401            activity_name = %request.name,
402            task_queue = %request.task_queue,
403            attempt = request.attempt,
404            "executing declared action body at the server"
405        );
406        // All three 2026-08-16 anonymous deaths correlated with workflow
407        // execution and the third died on exactly this path; the breadcrumb
408        // makes the in-flight site a death-note fact, not a log inference.
409        crate::death_note::breadcrumb(&format!(
410            "declared-action start action={} workflow_id={} run_id={} activity_id={} attempt={}",
411            request.name, request.workflow_id, request.run_id, request.activity_id, request.attempt,
412        ));
413
414        // #223: the bound the DISPATCH authored, or `None` when it authored
415        // none. Read through the engine's own decoder so the server cannot
416        // answer "what did this document authorise" differently from the retry
417        // loop, and so an unbounded body stays unbounded — the server invents
418        // no deadline of its own.
419        let bound = aion::activity_timeout_from_config(&request.config);
420        let transcript = self.transcript.clone();
421        let ended = self.tokio.block_on(async move {
422            let pump = tokio::spawn(publish_declared_transcript(transcript, drain));
423            let ended = run_bounded(&action, &arguments, &context, &cancellation, bound).await;
424            // Closing the seam is what ends the pump; the context holds it.
425            drop(context);
426            if let Err(error) = pump.await {
427                tracing::warn!(
428                    %error,
429                    operation = "declared_command_dispatch",
430                    "declared command transcript: the publishing task ended abnormally; some \
431                     output lines may not have been retained"
432                );
433            }
434            ended
435        });
436        // The command is over and its group is gone, so the attempt leaves the
437        // cancel path. Dropped explicitly, here and not earlier: while this
438        // lives, a cancel arriving mid-run still reaches the process.
439        drop(registration);
440
441        encode_end(request, ended)
442    }
443}
444
445/// Encode how the attempt ended onto the FFI string contract.
446///
447/// Three vocabularies, one per honest outcome: the encoded result, the
448/// classified failure the executor produced (`retryable:`/`terminal:`), and the
449/// engine's own `timeout:` reason for an attempt that outlived its authored
450/// bound.
451fn encode_end(request: &ActivityDispatch, ended: AttemptEnd) -> Result<String, String> {
452    let outcome = match ended {
453        AttemptEnd::Ran(outcome) => outcome,
454        AttemptEnd::Expired { bound, ran_anyway } => {
455            if let Some(exit_code) = ran_anyway {
456                // The command reached its own end inside the stopping window.
457                // Its result is discarded — the attempt is already recorded as
458                // having outlived its bound, and answering with a late success
459                // would contradict a terminal the run has already been told
460                // about — but the fact is said, not swallowed.
461                tracing::warn!(
462                    operation = "declared_command_dispatch",
463                    workflow_id = %request.workflow_id,
464                    activity_id = %request.activity_id,
465                    activity_name = %request.name,
466                    attempt = request.attempt,
467                    exit_code,
468                    bound_ms = bound.as_millis(),
469                    "the declared command finished while it was being stopped on its \
470                     authored bound; its result is discarded in favour of the timeout"
471                );
472            }
473            return Err(aion::activity_timeout_reason(bound));
474        }
475    };
476
477    match outcome {
478        Ok(result) => serde_json::to_string(&result)
479            .map_err(|error| format!("terminal:declared command result failed to encode: {error}")),
480        Err(failure) => {
481            let prefix = match failure.classification() {
482                aion_worker::Classification::Retryable => "retryable",
483                aion_worker::Classification::PolicyRefused => "policy_refused",
484                aion_worker::Classification::Terminal => "terminal",
485            };
486            Err(format!("{prefix}:{}", failure.message()))
487        }
488    }
489}
490
491/// How one declared-command attempt ended.
492#[derive(Debug)]
493enum AttemptEnd {
494    /// The command ran to its own end — completed, failed, or was stopped by
495    /// something other than the authored bound.
496    Ran(Result<aion_worker::shell::ShellOutcome, aion_worker::ActivityFailure>),
497    /// The attempt outlived the per-attempt bound its dispatch authored, and
498    /// its process group has been stopped and PROVEN gone.
499    Expired {
500        /// The authored bound that fired, carried so the refusal can name it.
501        bound: std::time::Duration,
502        /// The exit code of a command that reached its own end inside the
503        /// stopping window, when that happened. `None` — the ordinary case —
504        /// means the command was still running when the bound was enforced.
505        ran_anyway: Option<i32>,
506    },
507}
508
509/// Run the declared command, ending it at the bound its dispatch authored.
510///
511/// # Why the server enforces a bound the engine already applies
512///
513/// The engine wraps every attempt in `tokio::time::timeout` at the same
514/// authored bound (`nif_activity_retry_dispatch::deliver_one_attempt`), and is
515/// explicit about what that achieves: "the dispatch future is DROPPED, which
516/// stops this run waiting and nothing more... the worker-side call runs on to
517/// its own end and its result is discarded". For a REMOTE worker that is
518/// someone else's machine and the right division of labour. For a declared body
519/// it is a process tree in the server's own process group hierarchy, on the
520/// operator's machine, with nothing left that could ever stop it — the run has
521/// already moved on.
522///
523/// So the bound is enforced HERE as well, where the process is. On expiry the
524/// activity's cancellation is signalled and the SAME run future is awaited to
525/// its end: [`aion_worker::run_cancellable_command`] does not return until
526/// `SIGTERM` → [`aion_worker::PROCESS_GROUP_TERMINATION_GRACE`] → `SIGKILL` has
527/// been delivered to the whole group and the group has been PROVEN gone. This
528/// therefore returns only once the command is genuinely stopped, and the
529/// termination ladder and its grace are the worker path's, not a second copy.
530///
531/// A dispatch that authored no bound is awaited exactly as before.
532async fn run_bounded(
533    action: &ShellAction,
534    arguments: &BTreeMap<String, serde_json::Value>,
535    context: &aion_worker::ActivityContext,
536    cancellation: &aion_worker::ActivityCancellationHandle,
537    bound: Option<std::time::Duration>,
538) -> AttemptEnd {
539    let run = action.run(arguments, context);
540    let Some(bound) = bound else {
541        return AttemptEnd::Ran(run.await);
542    };
543    tokio::pin!(run);
544    match tokio::time::timeout(bound, &mut run).await {
545        Ok(outcome) => AttemptEnd::Ran(outcome),
546        Err(_elapsed) => {
547            cancellation.cancel();
548            AttemptEnd::Expired {
549                bound,
550                ran_anyway: run.await.ok().map(|outcome| outcome.exit_code),
551            }
552        }
553    }
554}
555
556impl std::fmt::Debug for DeclaredCommandDispatcher {
557    fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
558        formatter
559            .debug_struct("DeclaredCommandDispatcher")
560            .field("bodies", &self.bodies)
561            .finish_non_exhaustive()
562    }
563}
564
565impl ActivityDispatcher for DeclaredCommandDispatcher {
566    fn dispatch(&self, request: ActivityDispatch) -> Result<String, String> {
567        let run = DispatchingRun {
568            workflow_id: &request.workflow_id,
569            run_id: &request.run_id,
570        };
571        match self
572            .bodies
573            .body_for(&request.task_queue, &request.name, run)
574        {
575            DeclaredBodyLookup::None => self.inner.dispatch(request),
576            DeclaredBodyLookup::Unreadable(reason) => {
577                // Delegated, not refused: a catalog read failure must not
578                // strand a queue that live workers could still serve. Loud so
579                // an operator sees a bodied action falling through.
580                tracing::error!(
581                    operation = "declared_command_dispatch",
582                    workflow_id = %request.workflow_id,
583                    activity_name = %request.name,
584                    task_queue = %request.task_queue,
585                    %reason,
586                    "declared-body catalog read failed; delegating to the worker path"
587                );
588                self.inner.dispatch(request)
589            }
590            DeclaredBodyLookup::Ambiguous { declaring } => Err(ambiguous_body_refusal(
591                &request.name,
592                &request.task_queue,
593                &declaring,
594            )),
595            DeclaredBodyLookup::Declared(ActionBodyContract::Run { command }) => {
596                self.run_declared_command(&request, &command)
597            }
598        }
599    }
600}
601
602/// Decode the dispatch's JSON input into the declared action's arguments.
603///
604/// A declared action's parameters are named in its `.awl` declaration, so the
605/// input must be a JSON object; anything else cannot bind to `$name`
606/// references and is refused by shape. Retrying cannot change the input, so
607/// the refusal is terminal.
608fn decode_arguments(input: &str) -> Result<BTreeMap<String, serde_json::Value>, String> {
609    let value: serde_json::Value = serde_json::from_str(input)
610        .map_err(|error| format!("terminal:declared command input is not valid JSON: {error}"))?;
611    match value {
612        serde_json::Value::Object(members) => Ok(members.into_iter().collect()),
613        other => Err(format!(
614            "terminal:declared command input must be a JSON object binding the action's \
615             parameters by name; got {}",
616            json_kind(&other)
617        )),
618    }
619}
620
621/// A JSON value's kind, named for a refusal message.
622const fn json_kind(value: &serde_json::Value) -> &'static str {
623    match value {
624        serde_json::Value::Null => "null",
625        serde_json::Value::Bool(_) => "a boolean",
626        serde_json::Value::Number(_) => "a number",
627        serde_json::Value::String(_) => "a string",
628        serde_json::Value::Array(_) => "an array",
629        serde_json::Value::Object(_) => "an object",
630    }
631}
632
633/// Containment of a server-executed body: the authored per-attempt bound, and
634/// the run's cancellation. Its own file because its subjects are live process
635/// trees rather than dispatcher shapes; it builds them out of the fixtures
636/// [`tests`] shares with it.
637#[cfg(test)]
638#[path = "declared_body_containment_tests.rs"]
639mod declared_body_containment_tests;
640
641#[cfg(test)]
642mod tests {
643    use std::collections::BTreeMap;
644    use std::sync::{Arc, Mutex};
645
646    use aion::{ActivityDispatch, ActivityDispatcher};
647    use aion_core::{ActivityId, RunId, WorkflowId};
648    use aion_package::ActionBodyContract;
649
650    use aion_core::ActivityEventKind;
651    use aion_store::ActivityStreamKey;
652
653    use super::super::workspace_root::{WorkspaceRoot, WorkspaceRootError};
654    use super::{
655        ActivityEventPublisher, DeclaredBodies, DeclaredBodyLookup, DeclaredBodySource,
656        DeclaredCommandAttempts, DeclaredCommandDispatcher, DeclaringVersion, DispatchingRun,
657        decode_arguments,
658    };
659
660    /// What a test returns. Every fallible step is carried rather than
661    /// unwrapped, because the workspace denies panicking accessors in test
662    /// code as firmly as in library code.
663    pub(super) type TestResult = Result<(), Box<dyn std::error::Error>>;
664
665    /// Inner dispatcher that records whether it was reached.
666    struct RecordingInner {
667        reached: Arc<Mutex<Vec<String>>>,
668        reply: Result<String, String>,
669    }
670
671    impl ActivityDispatcher for RecordingInner {
672        fn dispatch(&self, request: ActivityDispatch) -> Result<String, String> {
673            match self.reached.lock() {
674                Ok(mut names) => names.push(request.name),
675                Err(poisoned) => poisoned.into_inner().push(request.name),
676            }
677            self.reply.clone()
678        }
679    }
680
681    struct FixedBodies {
682        lookup: DeclaredBodyLookup,
683    }
684
685    impl DeclaredBodies for FixedBodies {
686        fn body_for(
687            &self,
688            _task_queue: &str,
689            _action: &str,
690            _run: DispatchingRun<'_>,
691        ) -> DeclaredBodyLookup {
692            self.lookup.clone()
693        }
694    }
695
696    /// A reader that records whose dispatch it was asked about.
697    ///
698    /// The selection rule is unit-tested on its own inputs, which proves the
699    /// rule and nothing about the plumbing. This double closes that gap: it
700    /// captures the [`DispatchingRun`] the dispatcher hands over, so the
701    /// identity can be compared against the request it came from.
702    struct RecordingBodies {
703        seen: Arc<Mutex<Vec<(WorkflowId, RunId)>>>,
704    }
705
706    impl DeclaredBodies for RecordingBodies {
707        fn body_for(
708            &self,
709            _task_queue: &str,
710            _action: &str,
711            run: DispatchingRun<'_>,
712        ) -> DeclaredBodyLookup {
713            let observed = (run.workflow_id.clone(), run.run_id.clone());
714            match self.seen.lock() {
715                Ok(mut seen) => seen.push(observed),
716                Err(poisoned) => poisoned.into_inner().push(observed),
717            }
718            DeclaredBodyLookup::None
719        }
720    }
721
722    pub(super) fn request(name: &str, input: &str) -> ActivityDispatch {
723        ActivityDispatch {
724            namespace: "default".to_owned(),
725            task_queue: "shell".to_owned(),
726            node: None,
727            workflow_id: WorkflowId::new_v4(),
728            run_id: RunId::new_v4(),
729            activity_id: ActivityId::from_sequence_position(1),
730            name: name.to_owned(),
731            input: input.to_owned(),
732            config: "{}".to_owned(),
733            attempt: 1,
734            labels: BTreeMap::new(),
735            advisory: false,
736        }
737    }
738
739    fn dispatcher(
740        lookup: DeclaredBodyLookup,
741        reply: Result<String, String>,
742    ) -> (DeclaredCommandDispatcher, Arc<Mutex<Vec<String>>>) {
743        // These tests exercise bodies without the placeholder, so the root's
744        // value is never read; it is an explicit existing directory rather
745        // than a default so nothing here depends on resolution.
746        let (decorated, reached, _transcript) = dispatcher_with_root(
747            lookup,
748            reply,
749            WorkspaceRoot::from_resolution(Ok(std::env::temp_dir())),
750        );
751        (decorated, reached)
752    }
753
754    /// The live-tail buffer these tests give their transcript sequencer. A
755    /// `const` match rather than an unwrap: the workspace denies panicking
756    /// accessors in test code as firmly as in library code.
757    const TRANSCRIPT_CAPACITY: std::num::NonZeroUsize = match std::num::NonZeroUsize::new(64) {
758        Some(capacity) => capacity,
759        None => std::num::NonZeroUsize::MIN,
760    };
761
762    /// A dispatcher whose executing attempts nothing external will signal.
763    ///
764    /// Correct for every test whose subject runs to its own end. A test that
765    /// CANCELS its subject needs the registry the cancel signals through, and
766    /// uses [`dispatcher_with_attempts`] to hold the same instance.
767    pub(super) fn dispatcher_with_root(
768        lookup: DeclaredBodyLookup,
769        reply: Result<String, String>,
770        workspace_root: WorkspaceRoot,
771    ) -> (
772        DeclaredCommandDispatcher,
773        Arc<Mutex<Vec<String>>>,
774        ActivityEventPublisher,
775    ) {
776        dispatcher_with_attempts(
777            lookup,
778            reply,
779            workspace_root,
780            DeclaredCommandAttempts::new(),
781        )
782    }
783
784    pub(super) fn dispatcher_with_attempts(
785        lookup: DeclaredBodyLookup,
786        reply: Result<String, String>,
787        workspace_root: WorkspaceRoot,
788        attempts: DeclaredCommandAttempts,
789    ) -> (
790        DeclaredCommandDispatcher,
791        Arc<Mutex<Vec<String>>>,
792        ActivityEventPublisher,
793    ) {
794        let reached = Arc::new(Mutex::new(Vec::new()));
795        let inner = RecordingInner {
796            reached: Arc::clone(&reached),
797            reply,
798        };
799        let bodies = DeclaredBodySource::default();
800        bodies.install(Arc::new(FixedBodies { lookup }));
801        let store: Arc<dyn aion_store::ObservabilityStore> =
802            Arc::new(aion_store::InMemoryObservabilityStore::default());
803        let transcript = ActivityEventPublisher::new(
804            store,
805            TRANSCRIPT_CAPACITY,
806            crate::activity_publisher::TranscriptBatchPolicy::UNBATCHED,
807        );
808        let decorated = DeclaredCommandDispatcher::new(
809            Arc::new(inner),
810            bodies,
811            attempts,
812            tokio::runtime::Handle::current(),
813            workspace_root,
814            transcript.clone(),
815        );
816        (decorated, reached, transcript)
817    }
818
819    pub(super) fn reached_names(reached: &Arc<Mutex<Vec<String>>>) -> Vec<String> {
820        match reached.lock() {
821            Ok(names) => names.clone(),
822            Err(poisoned) => poisoned.into_inner().clone(),
823        }
824    }
825
826    #[tokio::test(flavor = "multi_thread")]
827    async fn a_bodiless_action_is_delegated_untouched() -> TestResult {
828        let (decorated, reached) =
829            dispatcher(DeclaredBodyLookup::None, Ok("\"worker-served\"".to_owned()));
830        let handle =
831            tokio::task::spawn_blocking(move || decorated.dispatch(request("plain", "{}")));
832        let result = handle.await?;
833        assert_eq!(result, Ok("\"worker-served\"".to_owned()));
834        assert_eq!(reached_names(&reached), vec!["plain".to_owned()]);
835        Ok(())
836    }
837
838    #[tokio::test(flavor = "multi_thread")]
839    async fn a_declared_body_executes_without_touching_the_worker_path() -> TestResult {
840        let (decorated, reached) = dispatcher(
841            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
842                command: "echo $greeting".to_owned(),
843            }),
844            Err("terminal:the worker path must never be reached".to_owned()),
845        );
846        let handle = tokio::task::spawn_blocking(move || {
847            decorated.dispatch(request(
848                "greet",
849                "{\"greeting\":\"hello from the contract\"}",
850            ))
851        });
852        let result = handle.await?;
853        let encoded = result.map_err(|error| format!("declared command failed: {error}"))?;
854        let outcome: serde_json::Value = serde_json::from_str(&encoded)?;
855        assert_eq!(outcome["stdout"], "hello from the contract");
856        assert_eq!(outcome["exit_code"], 0);
857        assert!(
858            reached_names(&reached).is_empty(),
859            "the worker path must not be consulted for a bodied action"
860        );
861        Ok(())
862    }
863
864    /// THE MID-STEP ANSWER: a server-run declared body's output reaches the
865    /// deployment's transcript sequencer as one event per line, on both streams,
866    /// keyed to the dispatch's own `(workflow, activity, attempt)` — the same
867    /// durable stream an agent step's transcript is read from, so every reader
868    /// that already serves transcripts serves this without change.
869    ///
870    /// The completion contract is asserted on the same run: the recorded result
871    /// still carries the command's whole stdout.
872    #[tokio::test(flavor = "multi_thread")]
873    async fn a_declared_body_publishes_its_output_onto_the_transcript() -> TestResult {
874        let (decorated, reached, transcript) = dispatcher_with_root(
875            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
876                command: "sh -c 'echo one; echo two; echo warned >&2'".to_owned(),
877            }),
878            Err("terminal:the worker path must never be reached".to_owned()),
879            WorkspaceRoot::from_resolution(Ok(std::env::temp_dir())),
880        );
881        let dispatch = request("noisy", "{}");
882        let key = ActivityStreamKey::new(
883            dispatch.workflow_id.clone(),
884            dispatch.run_id.clone(),
885            dispatch.activity_id.clone(),
886            dispatch.attempt,
887        );
888
889        let handle = tokio::task::spawn_blocking(move || decorated.dispatch(dispatch));
890        let encoded = handle
891            .await?
892            .map_err(|error| format!("declared command failed: {error}"))?;
893
894        // The replay-authoritative result is untouched by the streaming.
895        let outcome: serde_json::Value = serde_json::from_str(&encoded)?;
896        assert_eq!(outcome["stdout"], "one\ntwo");
897        assert_eq!(outcome["stderr"], "warned");
898        assert!(reached_names(&reached).is_empty());
899
900        // ...and the same output is on the durable transcript, line by line.
901        let retained = transcript.replay_from(&key, 0).await?;
902        let lines = retained
903            .iter()
904            .map(|record| match &record.event.kind {
905                ActivityEventKind::Message { text, .. } => {
906                    (record.event.agent_role.clone(), text.clone())
907                }
908                other => (record.event.agent_role.clone(), format!("{other:?}")),
909            })
910            .collect::<Vec<_>>();
911        assert!(
912            lines.contains(&("command stdout".to_owned(), "one".to_owned()))
913                && lines.contains(&("command stdout".to_owned(), "two".to_owned())),
914            "each stdout line must be its own transcript event: {lines:?}"
915        );
916        assert!(
917            lines.contains(&("command stderr".to_owned(), "warned".to_owned())),
918            "stderr must be on the transcript, labelled by its stream: {lines:?}"
919        );
920        // Sequencing is the publisher's: the durable order is gap-free from 0.
921        let sequences = retained
922            .iter()
923            .map(|record| record.store_seq)
924            .collect::<Vec<_>>();
925        assert_eq!(
926            sequences,
927            (0..u64::try_from(retained.len())?).collect::<Vec<_>>(),
928            "the sequencer assigns a gap-free durable order"
929        );
930        Ok(())
931    }
932
933    #[tokio::test(flavor = "multi_thread")]
934    async fn a_failing_declared_command_reports_retryable_with_its_stderr() -> TestResult {
935        let (decorated, _reached) = dispatcher(
936            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
937                command: "sh -c 'echo boom >&2; exit 7'".to_owned(),
938            }),
939            Ok("unused".to_owned()),
940        );
941        let handle =
942            tokio::task::spawn_blocking(move || decorated.dispatch(request("fails", "{}")));
943        let Err(error) = handle.await? else {
944            return Err("a non-zero exit must fail the dispatch".into());
945        };
946        assert!(
947            error.starts_with("retryable:"),
948            "a non-zero exit is retryable by default: {error}"
949        );
950        assert!(
951            error.contains("boom"),
952            "stderr must ride the failure: {error}"
953        );
954        Ok(())
955    }
956
957    /// The hash the refusal prints must be one the deploy API will accept, or
958    /// the remedy is a command that cannot run — the exact failure the old
959    /// "redeploy so one body remains" wording had.
960    ///
961    /// The oracle is the deploy API's own parser, not a length or a shape:
962    /// `EngineDeclaredBodies` renders the version with `ContentHash::to_string`,
963    /// so this takes a real hash through that rendering, pulls the token back
964    /// out of the printed command, and parses it the way
965    /// `decode_version_target` does.
966    #[test]
967    fn the_printed_hash_parses_back_as_a_content_hash() -> TestResult {
968        let version = aion_package::ContentHash::from_bytes([0x5a; 32]);
969        let routed = aion_package::ContentHash::from_bytes([0xa5; 32]);
970        let refusal = super::ambiguous_body_refusal(
971            "find_repositories",
972            "local",
973            &[
974                DeclaringVersion {
975                    content_hash: version.to_string(),
976                    workflow_types: vec!["sweeper".to_owned()],
977                    route_active: false,
978                    body: 0,
979                },
980                DeclaringVersion {
981                    content_hash: routed.to_string(),
982                    workflow_types: vec!["sweeper".to_owned()],
983                    route_active: true,
984                    body: 1,
985                },
986            ],
987        );
988        let Some(command) = refusal.split("`aion unload sweeper ").nth(1) else {
989            return Err(format!("no unload command in the refusal: {refusal}").into());
990        };
991        let Some(printed) = command.split('`').next() else {
992            return Err(format!("the unload command is unterminated: {refusal}").into());
993        };
994        let parsed: aion_package::ContentHash = printed.parse()?;
995        assert_eq!(
996            parsed, version,
997            "the printed hash must round-trip to the version it names"
998        );
999        Ok(())
1000    }
1001
1002    #[tokio::test(flavor = "multi_thread")]
1003    async fn ambiguous_bodies_refuse_terminally_by_name() -> TestResult {
1004        let superseded = "1111111111111111111111111111111111111111111111111111111111111111";
1005        let routed = "2222222222222222222222222222222222222222222222222222222222222222";
1006        let (decorated, reached) = dispatcher(
1007            DeclaredBodyLookup::Ambiguous {
1008                declaring: vec![
1009                    DeclaringVersion {
1010                        content_hash: superseded.to_owned(),
1011                        workflow_types: vec!["sweeper".to_owned()],
1012                        route_active: false,
1013                        body: 0,
1014                    },
1015                    DeclaringVersion {
1016                        content_hash: routed.to_owned(),
1017                        workflow_types: vec!["sweeper".to_owned()],
1018                        route_active: true,
1019                        body: 1,
1020                    },
1021                ],
1022            },
1023            Ok(String::new()),
1024        );
1025        let handle = tokio::task::spawn_blocking(move || decorated.dispatch(request("torn", "{}")));
1026        let Err(error) = handle.await? else {
1027            return Err("ambiguous bodies must refuse".into());
1028        };
1029        assert!(error.starts_with("terminal:"), "{error}");
1030        assert!(error.contains("torn"), "{error}");
1031        // The refusal must reach the dispatcher carrying an act-on-able remedy,
1032        // not just a count: the operator reads this string and nothing else.
1033        assert!(
1034            error.contains(&format!("`aion unload sweeper {superseded}`")),
1035            "the dispatch refusal must name the version to retire: {error}"
1036        );
1037        assert!(reached_names(&reached).is_empty());
1038        Ok(())
1039    }
1040
1041    #[tokio::test(flavor = "multi_thread")]
1042    async fn a_placeholder_bearing_body_executes_with_the_expanded_root() -> TestResult {
1043        let scratch = tempfile::tempdir()?;
1044        let root = scratch.path().join("clones");
1045        let root_text = root.to_string_lossy().into_owned();
1046        let (decorated, reached, _transcript) = dispatcher_with_root(
1047            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
1048                command: "echo {workspace_root}".to_owned(),
1049            }),
1050            Err("terminal:the worker path must never be reached".to_owned()),
1051            WorkspaceRoot::from_resolution(Ok(root.clone())),
1052        );
1053        let handle =
1054            tokio::task::spawn_blocking(move || decorated.dispatch(request("provision", "{}")));
1055        let result = handle.await?;
1056        let encoded = result.map_err(|error| format!("declared command failed: {error}"))?;
1057        let outcome: serde_json::Value = serde_json::from_str(&encoded)?;
1058        assert_eq!(
1059            outcome["stdout"], root_text,
1060            "the command must observe the server-resolved root as its argv word"
1061        );
1062        assert_eq!(outcome["exit_code"], 0);
1063        assert!(
1064            root.is_dir(),
1065            "dispatching a placeholder-bearing body must create the missing root"
1066        );
1067        assert!(reached_names(&reached).is_empty());
1068        Ok(())
1069    }
1070
1071    #[tokio::test(flavor = "multi_thread")]
1072    async fn a_placeholder_bearing_body_refuses_terminally_when_the_root_is_unresolved()
1073    -> TestResult {
1074        let (decorated, reached, _transcript) = dispatcher_with_root(
1075            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
1076                command: "echo {workspace_root}".to_owned(),
1077            }),
1078            Ok("unused".to_owned()),
1079            WorkspaceRoot::from_resolution(Err(WorkspaceRootError::Unresolvable {
1080                reason: "cannot resolve Aion home: set AION_HOME or HOME".to_owned(),
1081            })),
1082        );
1083        let handle =
1084            tokio::task::spawn_blocking(move || decorated.dispatch(request("provision", "{}")));
1085        let Err(error) = handle.await? else {
1086            return Err("an unresolved root must refuse a placeholder-bearing body".into());
1087        };
1088        assert!(error.starts_with("terminal:"), "{error}");
1089        assert!(
1090            error.contains("provision"),
1091            "the refusal must name the action: {error}"
1092        );
1093        assert!(
1094            error.contains("cannot resolve Aion home"),
1095            "the refusal must carry the resolution failure's reason: {error}"
1096        );
1097        assert!(
1098            reached_names(&reached).is_empty(),
1099            "a refused body must not fall through to the worker path"
1100        );
1101        Ok(())
1102    }
1103
1104    #[tokio::test(flavor = "multi_thread")]
1105    async fn a_shape_changing_root_refuses_terminally_naming_the_action() -> TestResult {
1106        // `$` in the root would open a parameter reference after splicing.
1107        let (decorated, reached, _transcript) = dispatcher_with_root(
1108            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
1109                command: "echo {workspace_root}".to_owned(),
1110            }),
1111            Ok("unused".to_owned()),
1112            WorkspaceRoot::from_resolution(Ok(std::path::PathBuf::from("/absolute/with$dollar"))),
1113        );
1114        let handle =
1115            tokio::task::spawn_blocking(move || decorated.dispatch(request("provision", "{}")));
1116        let Err(error) = handle.await? else {
1117            return Err("a shape-changing root must refuse a placeholder-bearing body".into());
1118        };
1119        assert!(error.starts_with("terminal:"), "{error}");
1120        assert!(
1121            error.contains("provision"),
1122            "the refusal must name the action: {error}"
1123        );
1124        assert!(
1125            error.contains("would change the parsed shape"),
1126            "the refusal must carry the shape-changing diagnosis: {error}"
1127        );
1128        assert!(
1129            reached_names(&reached).is_empty(),
1130            "a refused body must not fall through to the worker path"
1131        );
1132        Ok(())
1133    }
1134
1135    #[tokio::test(flavor = "multi_thread")]
1136    async fn an_uncreatable_root_refuses_terminally_naming_the_action() -> TestResult {
1137        // A root beneath a regular file cannot be created by any retry.
1138        let scratch = tempfile::tempdir()?;
1139        let file = scratch.path().join("occupied");
1140        std::fs::write(&file, b"not a directory")?;
1141        let (decorated, reached, _transcript) = dispatcher_with_root(
1142            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
1143                command: "echo {workspace_root}".to_owned(),
1144            }),
1145            Ok("unused".to_owned()),
1146            WorkspaceRoot::from_resolution(Ok(file.join("clones"))),
1147        );
1148        let handle =
1149            tokio::task::spawn_blocking(move || decorated.dispatch(request("provision", "{}")));
1150        let Err(error) = handle.await? else {
1151            return Err("an uncreatable root must refuse a placeholder-bearing body".into());
1152        };
1153        assert!(error.starts_with("terminal:"), "{error}");
1154        assert!(
1155            error.contains("provision"),
1156            "the refusal must name the action: {error}"
1157        );
1158        assert!(
1159            error.contains("could not be created"),
1160            "the refusal must carry the creation-failure diagnosis: {error}"
1161        );
1162        assert!(
1163            reached_names(&reached).is_empty(),
1164            "a refused body must not fall through to the worker path"
1165        );
1166        Ok(())
1167    }
1168
1169    #[tokio::test(flavor = "multi_thread")]
1170    async fn a_body_without_the_placeholder_is_untouched_by_resolution_failure() -> TestResult {
1171        let (decorated, _reached, _transcript) = dispatcher_with_root(
1172            DeclaredBodyLookup::Declared(ActionBodyContract::Run {
1173                command: "echo $greeting".to_owned(),
1174            }),
1175            Ok("unused".to_owned()),
1176            WorkspaceRoot::from_resolution(Err(WorkspaceRootError::Unresolvable {
1177                reason: "cannot resolve Aion home: set AION_HOME or HOME".to_owned(),
1178            })),
1179        );
1180        let handle = tokio::task::spawn_blocking(move || {
1181            decorated.dispatch(request("greet", "{\"greeting\":\"still served\"}"))
1182        });
1183        let result = handle.await?;
1184        let encoded = result.map_err(|error| format!("declared command failed: {error}"))?;
1185        let outcome: serde_json::Value = serde_json::from_str(&encoded)?;
1186        assert_eq!(outcome["stdout"], "still served");
1187        Ok(())
1188    }
1189
1190    #[tokio::test(flavor = "multi_thread")]
1191    async fn an_unreadable_catalog_delegates_to_the_worker_path() -> TestResult {
1192        let (decorated, reached) = dispatcher(
1193            DeclaredBodyLookup::Unreadable("catalog offline".to_owned()),
1194            Ok("\"served anyway\"".to_owned()),
1195        );
1196        let handle =
1197            tokio::task::spawn_blocking(move || decorated.dispatch(request("resilient", "{}")));
1198        let result = handle.await?;
1199        assert_eq!(result, Ok("\"served anyway\"".to_owned()));
1200        assert_eq!(reached_names(&reached), vec!["resilient".to_owned()]);
1201        Ok(())
1202    }
1203
1204    #[test]
1205    fn non_object_input_is_refused_terminally_by_shape() {
1206        for (input, kind) in [
1207            ("[1,2]", "an array"),
1208            ("\"text\"", "a string"),
1209            ("3", "a number"),
1210            ("null", "null"),
1211            ("true", "a boolean"),
1212        ] {
1213            let Err(error) = decode_arguments(input) else {
1214                unreachable_refusal(input);
1215                return;
1216            };
1217            assert!(error.starts_with("terminal:"), "{error}");
1218            assert!(error.contains(kind), "{error} must name {kind}");
1219        }
1220    }
1221
1222    /// Fails the calling test without a panicking accessor.
1223    fn unreachable_refusal(input: &str) {
1224        assert!(
1225            input.is_empty(),
1226            "input `{input}` must have been refused by shape"
1227        );
1228    }
1229
1230    /// The selection rule cannot be right if it is asked about the wrong run.
1231    ///
1232    /// `select_declared_body` is unit-tested on inputs the test itself
1233    /// constructs, which proves the rule and nothing about the plumbing. This
1234    /// asserts the other half: the identity the dispatcher hands the reader is
1235    /// the identity of the dispatch it is serving, not a placeholder and not
1236    /// another run's.
1237    #[tokio::test(flavor = "multi_thread")]
1238    async fn the_reader_is_asked_about_the_run_that_is_dispatching() -> TestResult {
1239        let seen = Arc::new(Mutex::new(Vec::new()));
1240        let bodies = DeclaredBodySource::default();
1241        bodies.install(Arc::new(RecordingBodies {
1242            seen: Arc::clone(&seen),
1243        }));
1244        let reached = Arc::new(Mutex::new(Vec::new()));
1245        let decorated = DeclaredCommandDispatcher::new(
1246            Arc::new(RecordingInner {
1247                reached: Arc::clone(&reached),
1248                reply: Ok("\"worker-served\"".to_owned()),
1249            }),
1250            bodies,
1251            DeclaredCommandAttempts::new(),
1252            tokio::runtime::Handle::current(),
1253            WorkspaceRoot::from_resolution(Ok(std::env::temp_dir())),
1254            ActivityEventPublisher::new(
1255                Arc::new(aion_store::InMemoryObservabilityStore::default()),
1256                TRANSCRIPT_CAPACITY,
1257                crate::activity_publisher::TranscriptBatchPolicy::UNBATCHED,
1258            ),
1259        );
1260
1261        let dispatch = request("plain", "{}");
1262        let expected = (dispatch.workflow_id.clone(), dispatch.run_id.clone());
1263        let handle = tokio::task::spawn_blocking(move || decorated.dispatch(dispatch));
1264        handle
1265            .await?
1266            .map_err(|error| format!("dispatch failed: {error}"))?;
1267
1268        let observed = match seen.lock() {
1269            Ok(observed) => observed.clone(),
1270            Err(poisoned) => poisoned.into_inner().clone(),
1271        };
1272        assert_eq!(
1273            observed,
1274            vec![expected],
1275            "the body reader must be asked about the dispatching run itself"
1276        );
1277        Ok(())
1278    }
1279}