CB-548: record delegator ownership only when a send is accepted #21

Closed
agent wants to merge 2 commits from worker/cb-548-rendezvous-guard-116b53-10 into main

2 Commits

Author SHA1 Message Date
Dai Ha cedab54ae8 CB-548: guard primary singleton to PRIMARY callers; open waiter before enqueue
CI / build (pull_request) Successful in 55s
CI / contract (pull_request) Successful in 1m9s
Fix two handler-level bugs found in PR #21:
- Only PRIMARY callers may update PrimaryRegistry.record (the legacy singleton 'primary'
  fallback for no-delegation inbox nudges). An architect SEND previously recorded its terminal
  as the fallback; the per-target delegation map does not cure the singleton. New
  BridgeMcp.recordPrimarySingleton uses the resolved role (caller.isPrimary()) — named leads
  (PRIMARY) still record, architects never do.
- MessageService.send now opens the rendezvous waiter BEFORE queueing delivery, fixing both the
  enqueue-before-open fast-reply race (a fast reply no longer orphans into the inbox) and
  callback-failure ordering: a throwing onAccepted (public callback) fails the send cleanly with
  no stale waiter and no queued, orphanable message.

Tests: architect SEND vs lead SEND primary-singleton regression; throwing onAccepted leaves no
stale waiter or queued orphan.
2026-08-13 19:19:14 +02:00
Dai Ha b39f700765 CB-548: record delegator ownership only when a send is accepted
CI / build (pull_request) Successful in 53s
CI / contract (pull_request) Successful in 1m18s
Record PrimaryRegistry delegator ownership via a MessageService accepted-delivery
hook (won the session lock + queued delivery), never at bridge_send request time, so
a concurrent sender that times out BUSY cannot steal a live turn's reply routing.
Make Rendezvous.open atomic fail-if-present so a double open trips loudly instead of
replacing the waiter another send is blocked on. Answering a bridge_ask keeps the same
ownership (no rewrite). Adds ownership/rendezvous regression tests.
2026-08-13 18:55:54 +02:00