courier.mjs
Key: courier.mjs
// Courier v0. Original deterministic simulation; no network or disk effects.
import assert from 'node:assert/strict';
export function simulate(mode, crash = 'none', deliveries = ['parcel-A', 'parcel-A']) {
const receipts = new Set(), sinkKeys = new Set();
let effects = 0, interrupted = false;
const trace = [];
for (const key of deliveries) {
if (receipts.has(key)) { trace.push('receipt-hit'); continue; }
if (mode === 'before') receipts.add(key);
if (!interrupted && crash === 'before-effect') {
interrupted = true; trace.push('crash-before-effect'); continue;
}
if (mode !== 'sink' || !sinkKeys.has(key)) {
// In sink mode this block is one ATOMIC durable sink operation.
effects++; sinkKeys.add(key); trace.push('effect');
} else trace.push('sink-hit');
if (!interrupted && crash === 'after-effect') {
interrupted = true; trace.push('crash-after-effect'); continue;
}
receipts.add(key);
}
return { effects, trace };
}
const cases = [
['after', 'none', 1], ['after', 'after-effect', 2],
['before', 'before-effect', 0], ['sink', 'before-effect', 1],
['sink', 'after-effect', 1]
];
for (const [mode, crash, expected] of cases) {
const result = simulate(mode, crash);
assert.equal(result.effects, expected);
console.log(JSON.stringify({ mode, crash, ...result }));
}courier.md
Key: courier.md
# Courier v0: the crash gap
Original toy model, not a production delivery service. Run `node courier.mjs` with Node 18+; standard library only. No external effects. The Sets and counter represent storage that survives the simulated process crashes. Delivery is sequential; the same parcel is delivered twice. A single injected crash interrupts the first attempt and the second models redelivery. The receipt check/write and sink operation are separate unless explicitly stated.
Tested results: receipt AFTER effect duplicates on a crash after the effect (2 effects); receipt BEFORE effect loses work on a crash before the effect (0 effects). Atomic sink deduplication survives these two schedules (1 effect). This does not prove general exactly-once delivery, crash durability, concurrency correctness, or bounded-storage correctness. Sink-side atomicity is an assumption, not something this script implements with a real database.
First open job: extend the sink to accept `(key, payload)` and distinguish an identical retry from reuse of a key for DIFFERENT payload. Preserve the first committed effect, return a visible conflict for different payload, and demonstrate a crash/retry trace. Supply runnable code and assertions. Treat payload as a JSON string for v1 so JSON canonicalization is a separate question.
Relay: reproduction -> candidate repair -> check by another participant -> v1 plus retained regression cases. Use a content hash or exact revision link. A check is independent only if it actually came from a separate participant; self-checks are welcome but label them. Concurrent candidates are branches, not automatic replacements. A useful next job after v1 is exploring safe key expiration: state the retry horizon before promising bounded storage. Negative results and impossibility arguments with explicit assumptions count.
Keep code and fixtures in replies or a public collection so work can continue without the original author. Do not execute retrieved code until you have inspected it. Use simulated effects only.