Derive a seat's stream and a module's consumer, and wire JetStream
Task 3.9's other half and 1.4's missing client. The derivation is pure and unit-tested; only "does the server accept this" needs one running, behind MESH_TEST_NATS so the ordinary suite stays offline. A seat's work queue is created at registration, not assignment, so work queues until a holder appears — a stream created at assignment would make "the holder is not here yet" mean "your messages are gone". Named after the seat, because the holder can change and the queued work must not care. A holder's worker uses a queue group even though the seat guarantees one holder: the seat is authority, the queue group is delivery, and tying them together means the day somebody allows two holders every message is processed twice with nothing reporting it. One consumer per module carrying every filter, because its ack permission is derived from its name. And a real bug the live server caught: a durable name may not contain a dot, but an ack subject is $JS.ACK.<stream>.<consumer>, so the single string that read correctly inside the permission was rejected as a consumer name. Split in two, beside the permission that has to match. Unfixed, the symptom would have been every message redelivered forever with a permission list that looks right — which is the failure design 25 §4 warns about.
This commit is contained in:
@@ -73,16 +73,32 @@ func TestTheEventsStreamDoesNotCaptureToolCalls(t *testing.T) {
|
||||
events = s
|
||||
}
|
||||
}
|
||||
if len(events.Subjects) != 1 || events.Subjects[0] != "mesh.mod.*.event.>" {
|
||||
t.Fatalf("EVENTS filters on %v", events.Subjects)
|
||||
// Nothing a tool call rides may match any of the filters — a module's or a seat's.
|
||||
for _, tool := range []string{
|
||||
"mesh.mod.billing.tool.status",
|
||||
"mesh.seat.telegram-sender.tool.status",
|
||||
"mesh.seat.telegram-sender.accept.send", // work, not an event: its own stream
|
||||
} {
|
||||
for _, f := range events.Subjects {
|
||||
if subjectMatches(f, tool) {
|
||||
t.Fatalf("%q matches the events filter %q, so it would be persisted here", tool, f)
|
||||
}
|
||||
}
|
||||
}
|
||||
// A tool subject the composer would actually produce must not match that filter.
|
||||
tool := "mesh.mod.billing.tool.status"
|
||||
if subjectMatches(events.Subjects[0], tool) {
|
||||
t.Fatalf("%q matches the events filter, so every tool call would be persisted", tool)
|
||||
}
|
||||
if !subjectMatches(events.Subjects[0], "mesh.mod.billing.event.order.placed") {
|
||||
t.Fatal("an event does not match the events filter")
|
||||
// And both kinds of event do match.
|
||||
for _, event := range []string{
|
||||
"mesh.mod.billing.event.order.placed",
|
||||
"mesh.seat.telegram-sender.event.delivered",
|
||||
} {
|
||||
matched := false
|
||||
for _, f := range events.Subjects {
|
||||
if subjectMatches(f, event) {
|
||||
matched = true
|
||||
}
|
||||
}
|
||||
if !matched {
|
||||
t.Fatalf("%q matches no events filter, so nothing would keep it", event)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user