Worker Dispatch Lease

Worker Dispatch Lease A sequence diagram generated by Archify. claimNext(taskId, workerId, leaseMs) assertClockDispatch(epoch, now) CLAIMED delivery, lease expires now + leaseMs authorize(claim, material, approvalId, policyKey) attempt DISPATCH_AUTHORIZED + intent PENDING claim + acknowledge envelope (attemptId must match) execute(command, workspace, timeout) spawn shell:false (native helper on win32) exit code, signal or timeout complete: SUCCEEDED, FAILED or UNKNOWN stage settled, next task + handoff created Claim Authorize + acknowledge Execute Settle Runner step · coding-workflow.ts · Sequence participant Runner step coding-workflow.ts Admission · admission.ts · Sequence participant Admission admission.ts Dispatch Store · worker thread · Sequence participant Dispatch Store worker thread Clock Gate · clock-repository.ts · Sequence participant Clock Gate clock-repository.ts Local Worker · worker-execution.ts · Sequence participant Local Worker worker-execution.ts Child Process · argv, no shell · Sequence participant Child Process argv, no shell Legend request return security default message

Lease, Not Heartbeat

  • • Deliveries move CLAIMED to ACKNOWLEDGED only while the lease is unexpired and worker plus epoch match
  • • Heartbeats live on coordinator workers and scheduler claims, not on deliveries

Nothing Runs Unapproved

  • • Admission rechecks approval expiry, policy revision and the material digest inside the transaction
  • • A lost storage reply never releases responsibility; the next step inspects durable records first

Outcome Classification

  • • A timeout, a signal or a null exit code is UNKNOWN on every platform
  • • A nonzero exit is FAILED; Windows self-termination is covered by the signed native helper