You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit eb21592
Browse filesBrowse the repository at this point in the historyBrowse files
libsql-server: reconcile indeterminate fence commits and restart at each boundary
Add crash-restart tests for the namespace fence: each server lifetime runs on
its own runtime and is ended without any shutdown code while a fence command
is parked at a hook point, so the next start takes the real dirty-recovery
path on the same directory. They cover every persistence boundary of
AcquireSourceWriteFence and ReleaseSourceWriteFence (including a marker that
lags the metastore commit), a restart in SOURCE_DRAINING with a writer active
at the crash, indeterminate commits through the drain path (applied and not
applied), and lost acquisition responses resolved by replay and inspection.
The tests exposed that a source restarted while draining could never finish
its drain: dirty recovery rebuilds the replication log under a new log id,
and completing the drain refused a boundary on a log other than the one the
fence was acquired against, leaving the namespace in SOURCE_DRAINING for
good. The frozen boundary now names the log that is live when the drain is
proven, the record's identity keeps the acquisition log id, and the server
warns when the two differ. Write admission was durably closed throughout, so
the data at the boundary is unchanged.
The BeforeMetastoreCommit test hook can now report a commit as indeterminate
without running it. The contract document describes the restart and log
rebuild semantics.
Co-authored-by: Tomasz Szymczyszyn <tomasz.szymczyszyn@shopify.com>
0 commit comments