fix(queen): every bound on keys and pools said nothing when it bound, so stop counting to a number - #486
Merged
gHashTag merged 1 commit intoSep 19, 2026
Conversation
… so stop counting to a number The key list was read by counting: the unsuffixed variable, then _2 up to a constant. The constant was 16, then 1024, and both were the same mistake - the next variable past it looks configured in an editor and is read by nothing. Pools were counted the same way, to eight. The operator now wants to connect credentials without an upper edge, and any new constant would only move the place where a variable silently stops being read. So the names are READ FROM THE ENVIRONMENT. keysFor() asks which suffixed variables exist and takes them in numeric order (17 before 1024 before 4096), the unsuffixed name first, so every index already written still names the same key. A suffix must be a plain integer of two or more; _1, _02 and _x are not second names for an existing slot and are ignored rather than guessed at. Numbered pools are discovered the same way. The cost is the size of the environment instead of the size of a range. What is left is arithmetic, not policy: - a pool is cut at MAX_KEYS_PER_POOL = POOL_KEY_STRIDE - 1 (9999), because the next pool's durable key_index begins at the stride and that stride is already written in production rows, so it does not move; - a pool number above MAX_POOL_NUMBER cannot be addressed by a 32-bit key_index and is reported by endpointPoolProblems() instead of being dropped silently. The worker ceiling moves from 1024 to WORKER_SANITY_BOUND = 1_000_000 in the three places that must agree (queen-dispatch.ts and the two byte-identical QueenDelegation.swift copies). This reverses a choice made this morning, so the reasoning is stated plainly: as a typo guard 1024 protected little. An operator who meant 50 and typed 5000 over two thousand connected lanes got 1024 bees instead of 2000, and either ends a container sized for fifty. A mistyped value is bounded by the credential list, because dispatch refuses when every lane is taken. The constant now only stops a value that is not a number of bees at all. The default of four, and TRIOS_QUEEN_MAX_WORKERS as the operator's control, are untouched. Not claimed: that one container can run thousands of bees. Memory, worktree disk, the GitHub API quota, the review backlog and the supply of eligible issues bind long before any of these numbers. This change only guarantees that none of them is a constant in this file. Dispatch tests: 87 pass (82 before). Typecheck clean. The two Swift copies are byte-identical (cmp); I cannot build queend here, so queen-core-sync and queen-core need to be run where Swift for Linux is available. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
gHashTag
merged commit Sep 19, 2026
121410b
into
gHashTag:feat/queen-supervisor
15 of 21 checks passed
gHashTag
added a commit
that referenced
this pull request
Sep 19, 2026
The base moved under this branch by four commits on 19 Sep - the salvage rework and the unbounded keys and pools of #486 - and all three conflicts were two features reaching for the same lines, not two answers to one question. Every one is resolved by keeping BOTH sides: - `keptRunning` (kept because a bee is running there, from this branch) and `keptUnpushed` (kept because the branch holds commits only this volume has, from the base) are different protections. The body of `reapWorktrees` had already merged cleanly with both; only the result type and its initialiser conflicted. - The `reapWorktrees` call keeps this branch's shape, because the refusal below it already reads `gc ? ... : ...` and `gc.keptRunning` - the base's `keptUnpushed` is added to the same log line rather than replacing it. - `noteBeeEnded`/`releaseSession` (memory the container guard reserved) and the salvage-before-the-ending block (work committed before the row is reviewable) are independent: `releaseSession` is an HTTP delete against the session store and touches neither the worktree nor git. The release goes FIRST so a wedged git cannot hold a gigabyte of message history for the whole salvage deadline; the salvage still runs before `finishDispatch`, which is the invariant its comment states. - `noteBeeStarted` (the guard must not read the container as empty) and `markBeeRunningHere` (the stall sweep must not commit a live worktree) answer different questions and both now run. Verified: `tsc --noEmit` clean, and 156 pass / 0 fail across the five queen test files this branch touches. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The operator wants to connect credentials and run bees without an upper edge in code. After #484 and #485 the bounds were 1024 keys per pool, 8 pools and a worker ceiling of 1024. Each of them fails the same way the old 16 did: the next variable past the bound looks configured in an editor and is read by nothing, and a clamp reports nothing when it clamps.
What changes
keysFor()asks which suffixed variables exist and takes them in numeric order (17 before 1024 before 4096), the unsuffixed name first, so everykey_indexalready written still names the same key. A suffix must be a plain integer of two or more;_1,_02and_xare ignored rather than guessed at.MAX_KEYS_PER_POOL = POOL_KEY_STRIDE - 1(9999) because the next pool's durable index begins at the stride, and that stride is already in production rows, so it does not move. A pool number aboveMAX_POOL_NUMBERcannot be addressed by a 32-bitkey_index;endpointPoolProblems()reports it instead of dropping it silently.WORKER_SANITY_BOUND = 1_000_000in the three places that must agree:queen-dispatch.tsand the two byte-identicalQueenDelegation.swiftcopies.This reverses a choice from this morning
The 1024 clamp was kept deliberately as a typo guard, so here is the argument against it. An operator who meant 50 and typed 5000 over two thousand connected lanes got 1024 bees instead of 2000, and either number ends a container sized for fifty. A mistyped value is already bounded by the credential list, because dispatch refuses when every lane is taken. The constant now only stops a value that is not a number of bees at all. The default of four and
TRIOS_QUEEN_MAX_WORKERSas the operator's control are untouched. If you still want a tighter guard, say which number and what it protects, and I will put that in instead.Not claimed
That one container can run thousands of bees. Memory, worktree disk, the GitHub API quota, the review backlog and the supply of eligible issues bind long before any of these numbers. Observed today: capacity 32, and
/queen/statusansweredhealthy_idlewithno-eligible-work- the swarm was limited by work, not by keys or ceilings. This change only guarantees that none of the limits is a constant in this file.Verification
bun test tests/api/queen-dispatch.test.ts: 87 pass, 0 fail (82 before). New cases: numeric ordering of suffixes, names that only look like key variables, the cut at the stride, a ninth pool, a pool number no index can address, 5000 requested over 9999 credentials answers 5000, andqueenWorkerLimit()still refuses99999999999,many,0and unset.bun run typecheckclean;biome checkshows only the two pre-existing complexity warnings.cmp). I cannot buildqueendhere, somake queen-core-syncandmake queen-coreneed to run where Swift for Linux is available. The Swift change is one literal and its comment.🤖 Generated with Claude Code