Web RPC Retry Safety Decision

Web RPC Retry Safety Decision A workflow diagram generated by Archify. 01 / Caller 02 / RpcExecutor 03 / Retries enabled EX / Retries disabled Enter Classify Dispatch rpc_call · public API · Caller › Enter rpc_call public API Registry · 5 policies · RpcExecutor › Classify Registry 5 policies Resolve · retry flag · RpcExecutor › Dispatch Resolve retry flag Set op · replay ok · Retries enabled › Classify Set op replay ok At least · dupe cost · Retries enabled › Dispatch At least dupe cost Probe · probe loop · Retries disabled › Classify Probe probe loop No retry · surface it · Retries disabled › Dispatch No retry surface it Dispatch · wire POST · RpcExecutor › Dispatch Dispatch wire POST replay safe side effects no dedupe key no probe Legend Agent logic Policy Tool action Context / trace Cloud service External system

Why it exists

  • • Every mutating Web RPC is exposed to a commit-lost failure over HTTPS
  • • Retry safety is a property of the RPC, declared once in the registry

The five policies

  • • IDEMPOTENT_SET_OP and AT_LEAST_ONCE_ACCEPTED keep inner retries on
  • • PROBE_THEN_CREATE and NON_IDEMPOTENT_NO_RETRY force them off

Closed axis

  • • UNCLASSIFIED survives only as a placeholder for hand-built test registries
  • • A sixth policy needs an ADR amendment and an executor change in lockstep