Skip to content

Support queueing-service through an opt-in gRPC event sink - #2811

Merged
MarcusSorealheis merged 3 commits into
mainfrom
feat/grpc-event-sink
Sep 30, 2026
Merged

MarcusSorealheis merged 3 commits into
mainfrom
feat/grpc-event-sink

Conversation

@MarcusSorealheis

@MarcusSorealheis MarcusSorealheis commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

What and why

Add opt-in grpc.store_type: "event_sink" for BEP/origin forwarding to queueing-service. String-key digests currently advertise the key length, so the ByteStream size validator rejects event payloads with a different length. Event sinks use the exact payload length and retain the key hash as the identifier.

Reject acknowledgements that report a different committed size. Document the receiver's durable-append acknowledgement and stable event-key duplicate handling, including retries after a lost acknowledgement.

How was this verified?

On the refreshed branch, Bazel 9.1.1 passed all 13 gRPC-store tests and 11 configuration tests with Clippy and rustfmt enabled. Coverage includes payload/key length differences; rejection of reads, existence checks, digest keys, and unknown upload sizes; incomplete acknowledgements; and replay with the same upload identity, offset, and payload after a lost acknowledgement.

Regenerated the configuration reference and passed snippet, anchor, spelling, prose, and repository hooks. The local generated hook config uses an unsupported language label; the same hook commands passed using a temporary config that maps local executables to system.

Earlier integration validation sent actual BES requests through the built NativeLink server, the Go queueing-service receiver, a Kafka-compatible broker, and MongoDB. A simulated crash after projection left the broker offset uncommitted; restart replayed the event and persisted the terminal build state. That multi-service integration was not rerun for the acknowledgement follow-up. CI passed on commit 8565881, including Linux and Windows Cargo tests, both Bazel versions, ASAN, coverage, pre-commit, documentation checks, and integration tests.

Risk

Explicit opt-in; existing CAS/AC configuration keeps its behavior. This protocol requires a dedicated receiver that acknowledges the full payload only after a durable append and does not implement CAS content verification. The byte-count check cannot independently prove receiver durability. A receiver must handle duplicate events using the stable event key, including retries that use a new upload UUID. This does not provide exactly-once processing or a durable publisher recovery ledger, and it retains the origin publisher's bounded in-memory retry policy.

AI assistance

I had help from several OpenAI models with the implementation, tests, and documentation. I directed the scope, and the coding agent ran the local checks described above. The coding agent also reviewed the final diff and posted its findings on this PR.


This change is Reviewable

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nativelink Ready Ready Preview Sep 30, 2026 6:42pm UTC
nativelink-aidm Ready Ready Preview Sep 30, 2026 6:42pm UTC

Request Review

Support string-keyed write-only event stores without changing CAS or Action Cache semantics. Carry the actual payload size in ByteStream resources, validate configuration, and regenerate the configuration reference.

Refresh the change onto main and retain the declaration-order lint fix. Replaces the same-author PR commits f775a29 and d5b1e4c.

AI-assisted implementation.
Reject event-sink responses whose committed size differs from the full payload. Cover incomplete acknowledgements and retries after the receiver consumes an event but loses its response. Document durable receiver acknowledgements, stable event-key deduplication, and the limits of publisher recovery.

Validated the 13 gRPC-store and 11 configuration tests with Bazel, including Clippy and rustfmt, and ran the documentation and repository hooks.

AI-assisted implementation at Marcus Eagan's direction.

@MarcusSorealheis MarcusSorealheis left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Completed an AI-assisted author-side review of the final diff at 8565881. No blocking findings.

Reviewed the event-sink configuration, StoreDriver operations, ByteStream upload/retry path, and the BEP/origin publisher call sites:

  • Event-sink writes require a string key and an exact payload size. The resource retains the key hash while advertising the payload length; digest-key writes, reads, existence checks, and read batching are rejected on the event-publisher path.
  • String-key events cannot enter the CAS compression path. Existing CAS/AC behavior remains unchanged by the new acknowledgement check.
  • A negative, partial, or oversized committed byte count is rejected. BEP acknowledges its client only after the store update succeeds. A receiver still must make its own durable append before acknowledging; the byte count alone does not prove durability.
  • The lost-ack regression verifies transport replay keeps the upload identity, offset, and payload. The BEP/origin publisher call sites also retain the event key across outer retries, which may create a new upload UUID. Receiver duplicate handling must therefore use the stable event key. Origin retries remain bounded in memory, with no new durable recovery ledger or exactly-once guarantee.

Validation: all 13 gRPC-store and 11 configuration tests passed locally with Bazel's Clippy/rustfmt checks, and documentation/hooks passed. Current CI is green, including Linux/Windows Cargo, both Bazel versions, ASAN, coverage, and integration tests. Both PR commits have valid GitHub signatures. The previously described multi-service receiver/broker/database experiment was not repeated for the acknowledgement follow-up.

The change is ready to leave draft. This is an author-side review, since the implementation and review were performed through the same account.

@MarcusSorealheis
MarcusSorealheis marked this pull request as ready for review September 30, 2026 07:54
@MarcusSorealheis
MarcusSorealheis merged commit 181a1d3 into main Sep 30, 2026
48 checks passed
@MarcusSorealheis
MarcusSorealheis deleted the feat/grpc-event-sink branch September 30, 2026 20:02

This branch was successfully deployed

2 active deployments
Preview – nativelink — 1ad7a414 Deployed Sep 30, 2026 by vercel[bot]
Preview – nativelink-aidm — 1ad7a414 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants