Repository navigation
fix(agent): isolate storage failure and release completed transfer admission - #114
Merged
Merged
Conversation
rldyourmnd
marked this pull request as ready for review
October 6, 2026 16:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A publisher capacity failure previously stopped the whole endpoint/local manager; immediate consecutive sync transfers also had a completion race where peer-visible FIN preceded release of connection exclusion and the data lane. ENOSPC/quota now pause only durable publication with bounded retries. Sync now owns both admission resources, joins control/filesystem work and releases them before terminal FIN; cancellation retains RAII cleanup and transfer inputs are never replayed.
Publisher recovery retains exclusive ownership and accepts only the preceding verified state or its exact attempted successor, synchronizing those bytes before clearing uncertainty. Clock rollback, corrupt/unrelated history, unsafe files and other I/O remain fatal. Signed revision allocation and authorization expiry remain. Pause/recovery and sync greeting/transfer-stage metadata improve diagnostics without a wire or identity change.
Validation: five publisher tests cover all five real atomic-file checkpoints, repeated capacity failure, ownership, exact signed retries/revisions after reopening and invalid-history rejection. Native Mac discovery64pass/1pre-existing4096-identity capacity test ignored; net101/101pass. All78sync unit/integration tests (including v1/v2), real CLI local-manager1/1and IPC/QUIC local-sync3/3pass, including cancellation/directional grants and eight immediate resumptions per backend with a single data lane. Strict workspace desktop/Noq Clippy and fmt pass. Earlierb019d15CI exposed the completion race;9a07f2bCI on both OSes then exposed an added-close double-join. The owned reader now keeps its handle across canceled waits and consumes completion exactly once; repeat close/drain tests pass. Those failures remain recorded and no failed refinement was deployed. Final-source CI passes on Ubuntu and macOS (16successful checks,2standard skips). Native Linux expanded checks and final release are being verified; installed qualification remains open. Device/runtime facts stay in the private estate. Details: docs/reports/rds-publication-storage-isolation-20261006.md.