Repository navigation
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
During a bot handoff, a delayed node can overwrite/delete its successor's lease. Independently, accepted messages live only in the receiving process: rebalance removes its client, and restart loses queued replies after the poll cursor has already advanced. This PR fixes those paths, restores the tests omitted by Linux shell glob expansion, and updates the dependencies flagged by the production audit.
Changes
client_id. Keep the reply plan stable across runtime configuration changes.Validation
pnpm -r typecheck: passes on local Node 24.19.0 / pnpm 11.15.0.pnpm -r testwith dedicated Redis databases: 666 passed, 0 failed, 0 skipped.pnpm audit --prod --registry=https://registry.npmjs.org --json: 0 vulnerabilities at review time. Existing advisory-only CI policy is unchanged.git diff --check: passes./health,/health/ready,/and/appreturn 200; unauthenticated access to the inbox admin endpoint returns 401. Workers and external services were disabled for this smoke check.action_required; the same commit is fully checked by the fork CI above.Operations and limits
The queue requires one shared, non-cluster Redis database with Lua and the used data-structure/TIME commands enabled. Configure persistence, backups, and no eviction. Payloads contain message text, context tokens, media credentials, and reply checkpoints; protect them like existing bot credentials.
INBOX_MAX_LENnow caps retained jobs per bot, including failed jobs. Failed jobs do not expire automatically; manual retry appends to that peer's queue while retaining checkpoints. See the updated Docker, runbook and admin API docs.Drain old in-memory work and upgrade all nodes together; mixed old/new workers retain unsafe paths. Old binaries do not consume the new queue, so drain it before rollback. Completion dedup retains the existing ten-minute window.
This provides recoverable, bounded at-least-once processing, not end-to-end exactly-once delivery. A process can die after an external operation succeeds but before its checkpoint is saved. Stable
client_idreduces ambiguity, but actual iLink deduplication has not been verified; generation/P2P state transitions can also repeat in that window. No live WeChat/model calls, Lightsail deployment or cross-region load test was performed.