From ed28b51f12a8909418c3eed8dfdc21f34c32234a Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Sat, 12 Sep 2026 16:32:36 +0700 Subject: [PATCH] =?UTF-8?q?fleetd=20#513:=20fix=20TIMED=5FOUT=5FQUEUED=20j?= =?UTF-8?q?avadoc=20=E2=80=94=20cancelled,=20not=20queued?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two javadoc blocks (queuedDeliveries field, hasQueuedDelivery) said a timed-out message is still sitting in the injector's per-target queue. CB-640 made send() cancel it via Injector.cancel() instead, so the message is gone and will never arrive. Rewrote both to describe cancellation. Also fixed a third instance of the same stale claim in hasOrphanedDelegation's javadoc, and added a line to the TIMED_OUT_QUEUED enum constant's own comment clarifying the name is kept but no longer means the message stays queued. Per the ticket's follow-up comment: no rename (TIMED_OUT_QUEUED reaches FleetApp.java REST mapping and FleetMcp.java — out of scope here) and no behavior change; comments only. --- .../dev/ltms/fleet/msg/MessageService.java | 32 ++++++++++++------- 1 file changed, 21 insertions(+), 11 deletions(-) diff --git a/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java b/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java index b76c5cf..0c445bb 100644 --- a/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java +++ b/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java @@ -92,7 +92,13 @@ public final class MessageService { QUESTION, /** Timed out after the message was delivered — the worker is still working. */ TIMED_OUT_WORKING, - /** Timed out before delivery — the message is still queued for the worker. */ + /** + * Timed out before delivery. Despite the name, the message is not left queued: {@link + * #send} cancels the pending entry ({@link Injector#cancel}) before returning this + * outcome, so it will not arrive later — the target never saw a word of it. The name + * records that the message was still queued at the moment the caller gave up, not that it + * stays queued afterward. + */ TIMED_OUT_QUEUED, /** Another send to this session was in flight for the whole window. */ BUSY, @@ -301,10 +307,12 @@ public final class MessageService { /** * Targets whose last send timed out with {@link Outcome#TIMED_OUT_QUEUED} (CB-640) — the * message never reached the {@link Injector} delivery window before the caller's deadline, so - * it is still sitting in the injector's own per-target queue. Set where {@link #send} already - * computes {@code wasDelivered} for that outcome; no new queue is kept here, only the fact. - * Cleared the same way as {@link #strandedReplies}: the next accepted delivery for the target - * ({@link #send} opening a fresh waiter) or a teardown ({@link #abandon}). + * {@link #send} cancelled it via {@link Injector#cancel} before it could ever be delivered. The + * message is gone, not pending: it will not arrive later, and the target never saw it. Set + * where {@link #send} already computes {@code wasDelivered} for that outcome; no queue is kept + * here, only the fact that a delivery was cancelled. Cleared the same way as + * {@link #strandedReplies}: the next accepted delivery for the target ({@link #send} opening a + * fresh waiter) or a teardown ({@link #abandon}). */ private final ConcurrentHashMap queuedDeliveries = new ConcurrentHashMap<>(); private final AtomicLong ticketSeq = new AtomicLong(); @@ -393,10 +401,12 @@ public final class MessageService { * Read-only delegation fact for fleet views (CB-640): {@code target}'s last send timed out * before the {@link Injector} ever delivered it — the caller saw * {@link Outcome#TIMED_OUT_QUEUED} (see the {@code TimeoutException} branch of {@link #send}), - * and the message is still sitting in the injector's per-target queue waiting for the worker - * to go idle. Distinct from {@link Outcome#TIMED_OUT_WORKING}, where delivery already happened - * and only the reply is outstanding. Cleared the next time this target's delivery is accepted - * or the target is abandoned — see {@link #queuedDeliveries}. + * and {@link Injector#cancel} removed the pending entry before it could be delivered. Despite + * the method's name, the message is not queued and will not arrive later — the target never + * saw a word of it; this reports a cancellation, not a pending delivery. Distinct from + * {@link Outcome#TIMED_OUT_WORKING}, where delivery already happened and only the reply is + * outstanding. Cleared the next time this target's delivery is accepted or the target is + * abandoned — see {@link #queuedDeliveries}. */ public boolean hasQueuedDelivery(String target) { return target != null && queuedDeliveries.containsKey(target); @@ -416,8 +426,8 @@ public final class MessageService { /** * Read-only delegation fact for fleet views (CB-640): an async ticket is still * {@link Phase#PENDING} against {@code target}, yet nothing is actually in flight for it — no - * open rendezvous waiter ({@link #hasAcceptedDelivery}) and no message still sitting in the - * injector's queue ({@link #hasQueuedDelivery}). A healthy PENDING ticket can briefly look this + * open rendezvous waiter ({@link #hasAcceptedDelivery}) and no record of a cancelled, + * undelivered send ({@link #hasQueuedDelivery}). A healthy PENDING ticket can briefly look this * way while its virtual thread has not yet been scheduled or is blocked on the session lock * behind another send to the same target, so this is a snapshot fact for the health classifier * to weigh across ticks, not proof on its own that the ticket is stuck. It also genuinely