feat(multiplayer): report assignment-ready from the supervisor

Closes the second blocker named last commit. Re-traced the actual code
path rather than trusting the earlier assumption: server_boot.gd
verifies its mounted roster file synchronously in _ready(), before
NetworkManager.host() runs and before ServerControl.set_process_ready
is ever called -- so by the time the loopback /ready probe (and thus
Agones Ready, and thus process-ready registration) succeeds, Godot has
already verified its own roster. And the API's ASSIGNMENT_READY gate
(AdvanceServerRegistrationSQL) checks only durable `assignments` rows
server-side, nothing Godot reports. No new Godot-side state was needed
-- the earlier 'needs Godot's own roster-verification state exposed'
claim was overcautious and is corrected here.

The supervisor now calls registerControlPlane(ctx, true) right after
process-ready succeeds, with a bounded retry (default 5 attempts, 2s
apart, both configurable) rather than a single attempt: the durable
`assignments` rows the server-side gate checks may not have propagated
by the first attempt, and that is expected, not fatal. Unlike a
process-ready registration failure, a persistent assignment-ready
failure does NOT kill the child -- the process is already legitimately
listening and usable, and killing a healthy process over a lagging
control-plane read would be actively harmful; it's logged to stderr
instead.

Covered by two tests: the full process-ready-then-assignment-ready
sequence and body shapes, and a retry test that fails the assignment-
ready call twice with 409 (simulating the real gate not yet
satisfied) before succeeding on the third attempt, asserting Start()
still succeeds and the child is never killed.
This commit is contained in:
Josh Creek
2026-09-01 13:44:16 +01:00
parent 4c2ade3930
commit 4cad0f0cce
3 changed files with 127 additions and 5 deletions
+44
View File
@@ -70,6 +70,18 @@ type Config struct {
MatchID string
ProtocolVersion int
ImageDigest string
// AssignmentReadyAttempts/AssignmentReadyBackoff bound the retry loop for
// reporting assignment-ready once process-ready has already succeeded.
// The control-plane's own durable gate (every participant already
// holding a live, unexpired assignment -- see
// AdvanceServerRegistrationSQL) may not be satisfied on the very first
// attempt if the signed roster is still propagating, and that is
// expected, not fatal: unlike a process-ready registration failure, this
// does not kill the child, since the process is already legitimately
// listening and usable either way. Default 5 attempts, 2s apart.
AssignmentReadyAttempts int
AssignmentReadyBackoff time.Duration
}
type Supervisor struct {
@@ -91,6 +103,12 @@ func New(config Config) (*Supervisor, error) {
if config.PollInterval <= 0 {
config.PollInterval = 100 * time.Millisecond
}
if config.AssignmentReadyAttempts <= 0 {
config.AssignmentReadyAttempts = 5
}
if config.AssignmentReadyBackoff <= 0 {
config.AssignmentReadyBackoff = 2 * time.Second
}
if config.Transport == "" {
config.Transport = "enet"
}
@@ -176,9 +194,35 @@ func (s *Supervisor) Start(ctx context.Context) error {
_ = s.cmd.Process.Kill()
return err
}
s.reportAssignmentReady(ctx)
return nil
}
// reportAssignmentReady is best-effort: process-ready has already succeeded,
// so the process is legitimately usable either way. A persistent failure is
// written to stderr rather than returned, since treating it as fatal would
// kill a perfectly healthy process over what is usually just the signed
// roster's durable rows not having propagated yet.
func (s *Supervisor) reportAssignmentReady(ctx context.Context) {
if s.config.ControlPlaneURL == "" {
return
}
var lastErr error
for attempt := 0; attempt < s.config.AssignmentReadyAttempts; attempt++ {
if attempt > 0 {
select {
case <-ctx.Done():
return
case <-time.After(s.config.AssignmentReadyBackoff):
}
}
if lastErr = s.registerControlPlane(ctx, true); lastErr == nil {
return
}
}
fmt.Fprintf(os.Stderr, "game-server-supervisor: assignment-ready registration did not succeed after %d attempts: %v\n", s.config.AssignmentReadyAttempts, lastErr)
}
// registerControlPlane reports the allocated process's readiness to the
// matchmaking control plane (POST /v1/servers/{id}/register). It is a no-op
// whenever ControlPlaneURL is unset, which is the default and preserves