1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
//! What the runtime could not decide, and how a person answers it.
//!
//! A quarantine is this runtime's most serious conclusion and its most honest
//! one: an effect was announced, the process died or the provider went quiet,
//! and whether the call reached the world is unanswerable from the journal.
//! The rule that follows — never unwind around an unknown outcome — is what
//! separates a saga that is truthful about distributed systems from one that
//! tidies up and hopes.
//!
//! The rule has a cost, and this module is where the cost is paid. A run that
//! stops on doubt stops for good unless somebody supplies the fact the runtime
//! lacks, so the types here are the vocabulary of that supply: what is in
//! doubt ([`Undecided`]), why ([`Doubt`]), and what a person decided to do
//! about it ([`QuarantineDecision`]).
//!
//! Two properties are deliberate:
//!
//! * **A person's answer is evidence, not authority.** An operator asserts what
//! happened to one *effect*; the runtime still re-decides the *run*. Nobody
//! gets to declare a run successful.
//! * **Giving up is a recorded outcome, not a silence.** A doubt that is never
//! resolved outlives the run's status, because a status is something a later
//! action can overwrite and a finding is not.
use ;
use ;
/// Why one effect's outcome is unknown.
///
/// Two shapes, and an operator investigates them differently: one says the
/// runtime never heard back, the other says it heard back and was told nothing
/// useful.
/// One effect whose outcome the journal cannot establish.
///
/// Derived from records rather than remembered, so the same list is produced by
/// the executor deciding whether an unwind is safe, by the operator API
/// answering *what do I have to look up*, and by an offline audit of a history
/// nothing may resume. Three readers, one rule.
///
/// Only **mutating** effects appear. A read that never came back is safe to
/// repeat and nobody has to adjudicate it; the question here is exclusively
/// *did this change the outside world*.
/// What a person decided about a run the runtime could not decide.
///
/// The two honest answers, and there is deliberately no third. "Mark it
/// succeeded" is not here: a run's outcome is structural, and a person who
/// could declare one would be able to close a run over work that never
/// happened.
/// What a person asserts about an effect the runtime could not decide.
///
/// The same two answers a [`Reconciliation`](crate::core::Reconciliation) probe
/// can reach, minus the third. `Inconclusive` is missing on purpose: a probe
/// records it because *having asked* is a fact about the run, and the doubt
/// stands either way. A person who cannot tell has already left the doubt
/// standing, and their finding belongs in the reason on the decision that
/// closes the run — where somebody will read it — rather than in a record that
/// changes nothing.