broker: the ADR 0047 wire shape + event failure paths #1

Closed
jschoubben wants to merge 0 commits from events/adr-0047-alignment into main
Owner

The AMQP adapter now honours the full ADR 0047 contract, and handles event failures — not only the happy path.

Wire shape

  • events published persistent, metadata in headers, body is only the payload
  • a durable per-consumer queue <node>.<module>.events, prefetch 32
  • a dead-letter exchange mesh.events.dead (with a retention queue, so poison events are kept for inspection, not silently dropped)
  • manual ack → at-least-once

Failure paths

  • a confirm channel: a publish the broker never accepted fails the emit rather than vanishing — at-least-once starts at the emitter
  • a handler that keeps failing is requeued once, then dead-lettered (never looping)
  • an undecodable body is dead-lettered at once — it never decodes on redelivery and must not wedge the queue

Tests — binding conformance against a disposable broker (a stand-in for the mesh-hosted broker, ADR 0001): headers-on-the-wire with a pure body, the redelivery-limit dead-letter, and the poison-body dead-letter. Suite 4/4 against a real LavinMQ.

Note: this tests the AMQP adapter in isolation. Real event testing belongs in a lab scenario where the mesh raises the broker as tier-1 substrate — tracked separately.

Part of the ADR-0047 alignment across mesh-sdk / mesh-tools / mesh-catalog.

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

The AMQP adapter now honours the full ADR 0047 contract, and handles event failures — not only the happy path. **Wire shape** - events published **persistent**, metadata in **headers**, body is only the payload - a **durable per-consumer queue** `<node>.<module>.events`, prefetch 32 - a **dead-letter exchange** `mesh.events.dead` (with a retention queue, so poison events are kept for inspection, not silently dropped) - **manual ack** → at-least-once **Failure paths** - a **confirm channel**: a publish the broker never accepted **fails the emit** rather than vanishing — at-least-once starts at the emitter - a handler that **keeps failing** is requeued once, then **dead-lettered** (never looping) - an **undecodable body** is dead-lettered at once — it never decodes on redelivery and must not wedge the queue **Tests** — binding conformance against a disposable broker (a stand-in for the mesh-hosted broker, ADR 0001): headers-on-the-wire with a pure body, the redelivery-limit dead-letter, and the poison-body dead-letter. Suite 4/4 against a real LavinMQ. > Note: this tests the AMQP **adapter** in isolation. Real event testing belongs in a lab scenario where the mesh raises the broker as tier-1 substrate — tracked separately. Part of the ADR-0047 alignment across mesh-sdk / mesh-tools / mesh-catalog. https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-03 22:26:35 +00:00
The AMQP adapter now honours the full contract: events published
persistent with metadata in headers; a durable per-consumer queue
(<node>.<module>.events) with prefetch and a dead-letter exchange
(mesh.events.dead); manual ack for at-least-once.

Failure paths, not just the happy one:
- a confirm channel, so a publish the broker never accepted fails the
  emit rather than vanishing — at-least-once starts at the emitter;
- a handler that keeps failing is requeued once, then dead-lettered
  (poison set aside, never looping);
- an undecodable body is dead-lettered at once — it never decodes on
  redelivery, and must not wedge the queue.

Binding-conformance tests against a disposable broker (a stand-in for the
mesh-hosted broker, ADR 0001): headers on the wire with a pure body, the
redelivery-limit dead-letter, and the poison-body dead-letter.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-03 22:56:40 +00:00
'mesh-tools emit <type> [json]' connects, emits one ADR 0047 event (awaiting
the publish confirm), and exits. The serve path already runs a module's
on('#') subscription as an import side effect, so the runtime hosts both an
emitter and the audit-logger consumer.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben closed this pull request 2026-09-05 01:18:53 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-tools#1