fix(daemon): publish the Git transaction owner with authority - #2817
Merged
Merged
Conversation
Project open published each Git transaction owner when it started the service and installed the owner's authority later, so the slot held an Option and every lookup had to hide an authority-less owner as still mounting. Shutdown cleared the same Option, so a request that had already resolved an owner saw a policy denial instead of the daemon going away. `mount` now starts the service around an authority it has already constructed and inserts the entry in one step; remounting the same identity replaces the authority in place. The slot is `Installed` or `Revoked`, and a revoked owner answers `DaemonUnavailable`, which Git reads now map through the typed port problem instead of concealing it. The engine-side `ensure` wrapper, `install_authority`, the `installed` guard, and the session database threaded only to feed them are gone. Refs #2612
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #2612
Root cause
Project open published each Git transaction owner when
ensurestarted its service, and installed the owner's authority later inregister_project_open_production_owners. The authority slot was therefore anOption, and #2612 had to hide an authority-less owner infor_repository_root(!entry.authority.installed()) so requests in that window answeredmountinginstead of a policy denial. Shutdown cleared the sameOption, so a request that had already resolved an owner sawPolicyDenied. Git reads concealed it asnot_found_or_not_authorizedinstead of reporting that the daemon was going away.Change
DaemonGitIndexTransactionServiceRegistry::mountconstructs the production authority first. It then starts the service around it and inserts the entry in one step under the creation gate. Remounting the same identity reuses the started service and replaces its authority in place. A second identity at the same root is refused before any service starts, so no orphaned authority-less entry is left behind.Installed(source) | Revoked; there is no empty state. Shutdown revokes it, and a revoked owner answersDaemonUnavailable.map_git_port_probleminstead of concealing them all, so a revoked owner reportsgit_index.unavailable.PolicyDeniedis still concealed asnot_found_or_not_authorized.ensure,ensure_with,existing,install_authority,DaemonGitAuthoritySlot::{installed, clear}, the engine wrapperensure_git_index_transactions_for_mutation_owners(with its fabricatedmap_or(0)/unwrap_or(i64::MAX)clock), thegit_transactions_readyphase, and thePendingFullServerOwners.session_dbfield that existed only to feed it. Durable Git transaction recovery still runs before the source-edit mutation lane opens:mountsits immediately beforesource_edit_mutation.mark_ready().Fails on origin/master
The owner resolved before shutdown must report the daemon going away. On
origin/master(d4835ab), using the master API (ensure+install_authority):On this branch the same assertion lives in
daemon_owner_shutdown_fences_admission_clears_services_and_joins_store_actorand passes.daemon_owner_racing_a_cold_mount_is_absent_until_published_with_authoritydrives the cold-mount race deterministically. The store open insidemountblocks on a release channel the test holds. While it is held,for_repository_rootreturnsNone(callers answerapplication.runtime.mounting). After release, the resolved owner is the mounted service (Arc::ptr_eq) and carries the literal installed authority(policy_revision 7, digest('1')). On master the same window was already hidden by theinstalled()guard. This test guards the new ordering; the shutdown assertion above is the one that fails on master.Runtime journey (built
tracedecaydebug CLI, isolated HOME, ZeroFS clone, daemon undersystemd-run --user --scope -p MemoryMax=6G -p MemorySwapMax=1G)Verification
cargo test -p tracedecay-code-index-runtime --lib git_transactions::: 45 passed.cargo test -p tracedecay-code-index-runtime -p tracedecay-daemon-service -p tracedecay --lib --features tracedecay/test-helpers,tracedecay/test-transport -- git: 123 + 7 + 24 passed. This includesdaemon::tests::socket::socket_git_preview_apply_replay_and_pre_admission_problems_are_canonical,daemon::tests::bootstrap::shutdown_fences_git_index_transactions_and_joins_store_actors(a real project open mounts exactly one owner), anddaemon::project_open_owners::git_catalog_tests::git_owner_uses_explicit_canonical_catalog_and_rechecks_authorization(remount replaces the authority; revoked and expired grants deny).cargo clippy -p tracedecay-code-index-runtime -p tracedecay-daemon-service -p tracedecay --all-targets --features tracedecay/test-helpers,tracedecay/test-transport -- -D warnings: clean.cargo fmt --all -- --check: clean.cargo check --workspace --all-targets --target x86_64-pc-windows-gnu --features tracedecay/test-transport,tracedecay/test-helpers,tracedecay-cli/test-transport: exit 0.ripwire --quality-delta=HEAD: I fixed the duplicated test preamble by folding the revoked-owner assertion into the existing shutdown test. The remaining duplication rows match struct-constructor token shapes in unrelated crates, with nothing to share.Re-verified after rebase on 964c3d7 (lane recovered after the 2026-10-01 restart)
cargo test -p tracedecay-code-index-runtime -p tracedecay-daemon-service -p tracedecay --lib --features tracedecay/test-helpers,tracedecay/test-transport -- git: 122 + 7 + 24 passed.-D warnings(same crates,--all-targets) andcargo fmt --all -- --check: clean.