fix: fence reconciliation admission race

This commit is contained in:
2026-09-11 07:36:11 +00:00
parent d753e8b698
commit e79f882993
10 changed files with 193 additions and 16 deletions
+5 -2
View File
@@ -97,8 +97,11 @@ Scheduler is not used.
4. The server queues work while a client is offline and dispatches it only when
the active session advertises capacity. A replacement session immediately
performs bidirectional reconciliation between the server's non-terminal set
and the client's complete retained-command set. The server returns explicit
local terminate/discard decisions before new dispatch begins.
and the client's complete retained-command set. That comparison uses one
server receipt-time cutoff captured before session registration, so commands
admitted during the handshake remain fresh queued work rather than false
missing-client contradictions. The server returns explicit local
terminate/discard decisions before new dispatch begins.
## Command model
+6
View File
@@ -1751,6 +1751,12 @@ a lost final `EventAck` followed by server retention. Write this idempotent
result before dispatch. A client with unresolved essential-store corruption
cannot complete reconciliation or accept work.
Capture one server receipt-time cutoff immediately before registering the live
session, and use that identical cutoff when building `ReconcileRequest` and
applying its `ReconcileSnapshot`. A command admitted after that cutoff is new
work: it must remain queued for post-reconciliation dispatch, never be treated
as absent client evidence merely because its admission raced the handshake.
Implement reconciliation as this explicit matrix:
| Server state | Client evidence | Durable result |
+4 -1
View File
@@ -231,7 +231,10 @@ the real `rvbox.exe --install-service` path and proves completion through SCM.
`run` is for reconfiguration/restart scenarios after that first installation.
Neither action invokes the GUI-subsystem executable directly with the normal
Guest Control account. `collect` obtains only bounded/redacted artifacts, and
`reset` restores the exact clean baseline and leaves the VM powered off.
`reset` restores the exact clean baseline and leaves the VM powered off. It
first permits a bounded ACPI shutdown; if that hangs, it force-powers off only
the exact leased disposable VM before snapshot restoration. That intentional
state loss is confined to the test isolation boundary.
This service-driven protocol is required because VirtualBox Guest Control
7.2.16 does not reliably complete a direct GUI-subsystem `rvbox.exe` run;