Conversation
A dispatch refused by a capacity limit already reaches the client as the retryable `57P03` class, but nothing counted the refusals, so an operator could not see dispatch pressure without reading logs. Every refusal path now goes through one helper that counts the refusal before it hands the request back, so the counter and the client-visible class cannot drift apart. The count is process-wide because the condition is the same one whichever core, database, or tenant hit its limit. Rendered as `nodedb_dispatch_capacity_busy_total` on `/metrics` and as the `dispatch_capacity_busy_total` row of `SHOW STATS`; the architecture doc names the class, the SQLSTATE, and the counter.
A refusal is only useful if it is observable. Assert the counter that `nodedb_dispatch_capacity_busy_total` reports reaches an operator from SQL (`SHOW STATS`) and from a Prometheus scrape, so neither surface can drift from the refusals the dispatcher actually counted.
`dispatch_to_core` refuses on a full weighted-fair queue with a flat `Error::DispatchCapacity`, so it could not route through the shared refusal helper that records the count: that helper returns a boxed refusal carrying the request back. The refusal was reported to the client and left out of `nodedb_dispatch_capacity_busy_total`, so an operator reading the counter saw fewer refusals than clients received. Record the count on this path directly. The refusal keeps its type and the request is still dropped rather than handed back, because this signature has nowhere to hand it.
EnRaiha
force-pushed
the
pr/374-371-dispatch-capacity-counter
branch
from
October 2, 2026 07:24
c7b3442 to
2d0c6c2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A dispatch refused by a capacity limit already reaches the client as the retryable
57P03class. Nothing counted the refusals, so an operator could not see dispatch pressure without reading logs.Every refusal path now goes through one helper that counts the refusal before it hands the request back, so the counter and the client-visible class cannot drift apart. The count is process-wide because the condition is the same one whichever core, database, or tenant hit its limit.
Rendered as
nodedb_dispatch_capacity_busy_totalon/metricsand as thedispatch_capacity_busy_totalrow ofSHOW STATS.Notes
DispatchCapacityvariant and its57P03class already exist. This adds the counter only; it does not change the class or the error shape.Evidence
The tests fail on
mainwithout this change. Proof: the test was copied onto a cleanorigin/main(bd8da7dc2) worktree and run there first.cargo nextest run -p nodedb --test wire -E 'test(~pgwire_show_dispatch)'on a cleanmain: FAIL, 2 tests (show_stats_carries_the_dispatch_capacity_counterreports the row missing from theSHOW STATSoutput;metrics_exposes_the_dispatch_capacity_counterreports the sample missing from/metrics).pgwire_show_dispatch20/20 pass.capacity_refusals_are_counted_once_eachdrives a full WFQ and a per-tenant in-flight cap and asserts at least two counts. The counter is process-wide, so the assertion is a lower bound.cargo check -p nodedb,cargo fmt --all -- --check, and a lib clippy run are clean.capacity_refusals_are_counted_once_eachfails; restored, it passes.What CI does not cover locally
Closes #371