fix: fence reconciliation admission race
This commit is contained in:
@@ -97,8 +97,11 @@ Scheduler is not used.
|
||||
4. The server queues work while a client is offline and dispatches it only when
|
||||
the active session advertises capacity. A replacement session immediately
|
||||
performs bidirectional reconciliation between the server's non-terminal set
|
||||
and the client's complete retained-command set. The server returns explicit
|
||||
local terminate/discard decisions before new dispatch begins.
|
||||
and the client's complete retained-command set. That comparison uses one
|
||||
server receipt-time cutoff captured before session registration, so commands
|
||||
admitted during the handshake remain fresh queued work rather than false
|
||||
missing-client contradictions. The server returns explicit local
|
||||
terminate/discard decisions before new dispatch begins.
|
||||
|
||||
## Command model
|
||||
|
||||
|
||||
@@ -1751,6 +1751,12 @@ a lost final `EventAck` followed by server retention. Write this idempotent
|
||||
result before dispatch. A client with unresolved essential-store corruption
|
||||
cannot complete reconciliation or accept work.
|
||||
|
||||
Capture one server receipt-time cutoff immediately before registering the live
|
||||
session, and use that identical cutoff when building `ReconcileRequest` and
|
||||
applying its `ReconcileSnapshot`. A command admitted after that cutoff is new
|
||||
work: it must remain queued for post-reconciliation dispatch, never be treated
|
||||
as absent client evidence merely because its admission raced the handshake.
|
||||
|
||||
Implement reconciliation as this explicit matrix:
|
||||
|
||||
| Server state | Client evidence | Durable result |
|
||||
|
||||
+4
-1
@@ -231,7 +231,10 @@ the real `rvbox.exe --install-service` path and proves completion through SCM.
|
||||
`run` is for reconfiguration/restart scenarios after that first installation.
|
||||
Neither action invokes the GUI-subsystem executable directly with the normal
|
||||
Guest Control account. `collect` obtains only bounded/redacted artifacts, and
|
||||
`reset` restores the exact clean baseline and leaves the VM powered off.
|
||||
`reset` restores the exact clean baseline and leaves the VM powered off. It
|
||||
first permits a bounded ACPI shutdown; if that hangs, it force-powers off only
|
||||
the exact leased disposable VM before snapshot restoration. That intentional
|
||||
state loss is confined to the test isolation boundary.
|
||||
|
||||
This service-driven protocol is required because VirtualBox Guest Control
|
||||
7.2.16 does not reliably complete a direct GUI-subsystem `rvbox.exe` run;
|
||||
|
||||
Reference in New Issue
Block a user