Expand description
The atomicity model: one CommitBundle, one all-or-nothing write
(spec §16.3, §23 step N, ADR-006 point 8).
After the executor has committed the domain state, the runtime still has the journal outcomes, the committed events, the card resolutions, the cards the new state requires and the ones the new revision invalidates, the outbox rows, the replay record and the phase marker to write. A partial write across those is an invariant violation, not a degraded success.
So CommitStore::commit takes the whole bundle and applies it all or
nothing, and “nothing” covers the records a bundle changes, not only the
ones it creates — which is what
crate::conformance::check_commit_bundle_restores_modified_records holds
an implementation to.
Why the executor’s own commit is deliberately outside that transaction, and
what makes the seam safe anyway, is in
docs/persistence.md.
Structs§
- Case
Invalidation - Invalidates the revision-bound interactions of one case.
- Commit
Bundle - Everything one commit writes, applied all or nothing.
- Commit
Receipt - What a successful commit reports back.
- Interaction
Finish - Settles one
Resolvinginteraction. - Interaction
Insert - Inserts one new interaction.
- Journal
Completion - Records the outcome of one journaled command.
- Turn
Phase Update - Writes the phase marker of a turn.
Traits§
- Commit
Store - The all-or-nothing write of a
CommitBundle.