feat(external-call): command-execution errors, rejection and handler SPI - #22
Draft
angelol wants to merge 6 commits into
Draft
Conversation
angelol
force-pushed
the
angelol/external-call-06-split-pr3-interp
branch
from
June 30, 2026 12:19
5fb3a81 to
e2cd4bd
Compare
angelol
force-pushed
the
angelol/external-call-06-split-pr2-codec
branch
from
June 30, 2026 12:19
82997b5 to
bfd7a14
Compare
angelol
force-pushed
the
angelol/external-call-06-split-pr3-interp
branch
from
June 30, 2026 14:33
e2cd4bd to
62d58c0
Compare
angelol
force-pushed
the
angelol/external-call-06-split-pr2-codec
branch
2 times, most recently
from
June 30, 2026 16:31
1db3847 to
c88e6cf
Compare
angelol
force-pushed
the
angelol/external-call-06-split-pr3-interp
branch
from
June 30, 2026 16:31
62d58c0 to
e2e961e
Compare
angelol
force-pushed
the
angelol/external-call-06-split-pr2-codec
branch
from
July 1, 2026 19:18
b0eab55 to
f52559e
Compare
angelol
force-pushed
the
angelol/external-call-06-split-pr3-interp
branch
from
July 1, 2026 19:21
85b4627 to
9afe465
Compare
angelol
force-pushed
the
angelol/external-call-06-split-pr2-codec
branch
from
July 3, 2026 05:56
f52559e to
8a3889f
Compare
…ults (digital-asset#550) ## Summary This is PR 2 of 8 in the external-call runtime-integration series tracked in digital-asset#513, stacked on PR 1. The external-call stack (digital-asset#513): digital-asset#506 added the transaction-side representation for recording external-call results; digital-asset#514 added the LF `EXTERNAL_CALL` builtin surface; digital-asset#518 wired it into Speedy and the LF engine; digital-asset#522 added transaction protobuf encoding/decoding; digital-asset#526 added Canton protocol serialization for recorded results; digital-asset#537 added the participant-side extension-service client. digital-asset#541 implemented the remaining runtime integration as one PR; this series splits digital-asset#541 into 8 independently reviewable PRs (each < 1000 lines) and supersedes it. This PR adds the interactive-submission representation and codec for recorded external-call results, so prepared transactions can round-trip them. ## Scope This PR adds: - the `ExternalCallResult` interactive-submission message (`interactive_submission_data.proto`) and the related service doc-comments (`interactive_submission_service.proto`) - prepared-transaction encoding/decoding of recorded external-call results (`PreparedTransactionEncoder` / `PreparedTransactionDecoder`) - the regenerated protobuf snapshot, `proto-data.yml` and `openapi.yaml` for the new message - prepared-transaction codec tests ## Out of scope Runtime dispatch of external-call questions (PR 3+), engine replay (PR 4), and validation (PR 6–8). ## Hashing Boundary Prepared/external-submission signatures authorize the LF action. Recorded external-call result payloads are Canton protocol data protected by the Canton view signature (see PR 1). Prepared transactions therefore carry external-call results for round-tripping, but those result payloads are intentionally excluded from the LF/prepared node hash. ## Stacking & review This PR is stacked on PR 1, so its diff against `main` is **cumulative** (it includes PR 1). The incremental change for this PR alone: digital-asset/canton@zenith-network:angelol/external-call-06-split-pr1-foundation...zenith-network:angelol/external-call-06-split-pr2-codec Refs digital-asset#513.
Add `def message` to the sealed `ExecutionFailed.Error` so callers read it directly, replacing the match/case that destructured `CallFailed`/`InvalidOutput` in CommandExecutionErrors. Addresses an upstream review comment on digital-asset#551.
Fold the near-identical "expected payload" and "empty payloads" engine tests into one payload table, loop-registering a named test per row (populated/empty) so the body is shared while both cases stay independently reported. Addresses an upstream review comment on digital-asset#551.
Fold the happy-path and empty-payloads Speedy tests into one payload table, loop-registering a named test per row (populated/empty) and unifying on the existing machineForRun helper so the body is shared while both cases stay independently reported. Addresses an upstream review comment on digital-asset#551.
angelol
force-pushed
the
angelol/external-call-06-split-pr3-interp
branch
from
July 3, 2026 07:17
04bbe6c to
5ddbc6f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is PR 3 of 8 in the external-call runtime-integration series tracked in digital-asset#513, stacked on PR 2.
The external-call stack (digital-asset#513): digital-asset#506 added the transaction-side representation for recording external-call results; digital-asset#514 added the LF
EXTERNAL_CALLbuiltin surface; digital-asset#518 wired it into Speedy and the LF engine; digital-asset#522 added transaction protobuf encoding/decoding; digital-asset#526 added Canton protocol serialization for recorded results; digital-asset#537 added the participant-side extension-service client. digital-asset#541 implemented the remaining runtime integration as one PR; this series splits digital-asset#541 into 8 independently reviewable PRs (each < 1000 lines) and supersedes it.This PR adds the command-execution error surface and the handler service-provider interface (SPI) that later PRs implement and wire in.
Scope
This PR adds:
CommandExecutionErrors) and theErrorResourcemetadata for themRejectionGenerators)ExternalCallHandler,ExternalCallMode) — the interface used by command interpretation to dispatch engine external-call questionsOut of scope
The concrete extension-service handler implementation and its wiring into command execution (PR 5), engine replay (PR 4), and validation/routing/factory (PR 6–8). The SPI ships with a no-op
Unsupportedhandler; nothing dispatches to a real service yet.Refs digital-asset#513.