First batch of v1 features. These were accepted in the public surface
since v0 but the engine ignored them — the documents called out
ORCA_RESULT_TIMEOUT as never produced, OrcaFatal as treated like
error. Now both are real.
actionTimeoutMs:
- In runAction, if action.actionTimeoutMs > 0, race the action's
promise against a timer scheduled on the injected TimerScheduler.
When the timer wins, it aborts the action's signal and resolves
with orcaTimeout(timeoutMs). The action's promise keeps running
in the background; the run trace records the timeout regardless.
- Each action gets its own AbortController, chained to the run-level
controller via an addEventListener('abort') hop. A timeout aborts
just that action; sibling actions in the same stage proceed.
- Diagnostic orca.action.timeout fires with timeoutMs and the usual
envelope identity.
- Run status: any TIMEOUT action puts the run in ORCA_RUN_TIMEOUT.
OrcaFatal:
- orcaFatal(error) result now maps to ORCA_ACTION_STATUS_FATAL (was
silently mapped to ERROR).
- In executeRun, FATAL status aborts the run unconditionally — it
overrides the action's onError policy. CONTINUE-flagged actions
that return fatal still abort.
- The FINALLY stage continues to run after a fatal abort.
- Diagnostic orca.action.fatal fires at LogLevel.FATAL with a
fatal: true marker and the error payload.
- Run status: any FATAL action puts the run in ORCA_RUN_FATAL.
Run-status precedence is now explicit:
FATAL > TIMEOUT > ABORTED > INTERRUPTED > PARTIAL > SUCCESS
Tests (+9):
v1 — actionTimeoutMs (5):
- produces ORCA_RESULT_TIMEOUT when action exceeds its timeout
- runs to completion when action finishes before timeout
- aborts the action signal when the timeout fires (cooperative
cancellation observable inside the action)
- emits orca.action.timeout diagnostic with timeoutMs
- lets later actions in the same stage proceed after a timeout
v1 — OrcaFatal (5):
- maps OrcaFatal to ORCA_ACTION_STATUS_FATAL
- aborts the run regardless of onError policy when fatal fires
- still runs FINALLY stage after a fatal abort
- emits orca.action.fatal diagnostic with fatal: true
- precedence: fatal beats every other status
The legacy "accepts actionTimeoutMs without enforcing timeout" test
from the v0 forward-compat block was removed; v0 promise is now v1
reality. Also dropped the equivalent OrcaFatal-as-error compatibility
behavior — fatal is now a distinct status across the engine.
Tests use the real createEngineTimers() in the timeout block so the
fake timer's not-implemented schedule() doesn't interfere; the existing
fake timer continues to serve every other test that doesn't rely on
actual scheduling.
Verification: 1373/1373 tests pass (63 in orca, +9 from this commit on
top of the 54 from the v0-kernel + verification commits).
README updated: actionTimeoutMs and OrcaFatal moved out of "Roadmap v1"
into a "Ya en el motor (de v1)" section. Remaining v1 items: compensate,
after/unless/abortOn gates, commit/replace queue policies, transaction
groups, parallel, payload-bearing tokens, fan-in, bus interception
(Option B), validate()/commit() static graph validation, and
createActiveOrca() reactive wrapper.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
master
parent
0f52fdfce6
commit
793767fe0d
Loading…
Reference in new issue