Found by the #807 review (pre-existing, not changed by that fix).
Coordinator.IsPrimaryWriter() returns c.localNode.IsPrimaryWriter() when a writer-failover manager is configured (internal/cluster/coordinator.go, around the IsPrimaryWriter method). Nothing in production ever sets c.localNode's writer state: onWriterPromoted mutates the registry's clones and re-registers them, and the #807 nodeFromRaftInfo carries the snapshot's writer state into the registry copy only. c.localNode is an identity pointer that Registry.Local() returns and that Register never replaces, so the primary writer's own gate reads a writer state that stays empty.
Effect: every caller of IsPrimaryWriter() on the failover-manager path (writer-only schedulers such as retention and CQ, the compaction gate) sees "not primary" on the node the FSM promoted. Shared-storage mode is unaffected (it keys off Raft leadership and role).
Fix shape: have onWriterPromoted (and the restore seeding) also update c.localNode when the promoted or demoted ID is the local node, or make IsPrimaryWriter read the registry entry for the local ID instead of the identity pointer. Add a test that promotes the local node through the FSM and asserts IsPrimaryWriter().
Found by the #807 review (pre-existing, not changed by that fix).
Coordinator.IsPrimaryWriter()returnsc.localNode.IsPrimaryWriter()when a writer-failover manager is configured (internal/cluster/coordinator.go, around theIsPrimaryWritermethod). Nothing in production ever setsc.localNode's writer state:onWriterPromotedmutates the registry's clones and re-registers them, and the #807nodeFromRaftInfocarries the snapshot's writer state into the registry copy only.c.localNodeis an identity pointer thatRegistry.Local()returns and thatRegisternever replaces, so the primary writer's own gate reads a writer state that stays empty.Effect: every caller of
IsPrimaryWriter()on the failover-manager path (writer-only schedulers such as retention and CQ, the compaction gate) sees "not primary" on the node the FSM promoted. Shared-storage mode is unaffected (it keys off Raft leadership and role).Fix shape: have
onWriterPromoted(and the restore seeding) also updatec.localNodewhen the promoted or demoted ID is the local node, or makeIsPrimaryWriterread the registry entry for the local ID instead of the identity pointer. Add a test that promotes the local node through the FSM and assertsIsPrimaryWriter().