Expand description
Command execution: the journal, the domain, the outbox and the one atomic write (spec §16, §23 steps M and N).
Everything the runtime does that a user could notice happens here, and it happens in a fixed order that the rest of the library depends on:
- Admission before effect. Every envelope is admitted to the command
journal under
UNIQUE (account_id, idempotency_key)before the domain is asked to do anything (§16.2). A key that is already there is not a second command:Admission::Settledreturns the outcome that was recorded the first time, without running the effect again (I14). - Optimistic concurrency. The batch carries the revision it was planned
against and the executor checks it in the same statement that writes
(§16.1, I13). A mismatch is
CommandOutcome::RevisionConflict, never a blind overwrite. - Uncertainty is a state. A timeout after transmission is
CommandOutcome::OutcomeUnknowncarrying anAttemptId, because the effect may exist. Nothing in this module retries it (I15, §16.5). - One write. The journal outcomes, the events, the card resolutions,
the new cards, the outbox rows, the replay record and the phase marker
travel in one
CommitBundleand land together or not at all (§16.3, §23 step N).
§What the batch is the unit of
A CommandBatch commits as a whole: one revision, one set of events. The
per-command CommandOutcomeRecords therefore all report the same
revision, and the batch’s event identifiers are recorded once, against its
first envelope, so two receipts can never cite the same events as if they
were two separate outcomes.
§What is deliberately not atomic
The domain’s own state commit may live in another database, and Turnframe
does not attempt a distributed transaction. Safety across that seam is the
journal: the entry exists before the effect, the executor is idempotent on
the key, and crate::recover resumes a pending entry by that key
(§23.1).
Structs§
- Command
Executor - Runs command batches against the domain, the journal and the outbox.
- Execution
Report - What executing one turn’s batches produced.
Enums§
- Admission
- What the journal said about one envelope before it ran.
Functions§
- command_
type - A stable label for an erased command, for the journal’s
command_type. - derive_
attempt_ id - Derives the attempt identifier a command’s unknown outcome is reconciled by.
- derive_
outbox_ id - Derives the outbox row identifier of
command_id, so replaying a turn enqueues the same row instead of a second one.