Skip to content

Release the WAL writer lease despite a retained duplicate descriptor #736

Description

@flyingrobots

Defect and observable outcome

Echo PR #735's Tests (det_fixed) job failed in fixed_seed_filesystem_writer_epoch_chain_survives_bounded_reopens with WriterEpochLeaseUnavailable (run 37171057227, job 111343926195). The filesystem WAL store retains a raw locked File and relies on closing that one descriptor to release ownership. A retained duplicate or fork-inherited descriptor can extend the lock lifetime after the store owner drops.

The narrow repair makes the owning lease guard explicitly unlock on drop before its descriptor closes. Live owners must still exclude contenders, and closing an old retained descriptor must not release a successor's independently acquired lease.

Provenance

The recovered historical feat/falsification branch contains James Ross's isolated fix 54b7abc3edc95ed8609eb488f6c20c3d21cbd475, followed by test scratch-path adjustment 8df44b481d7c325795689c361deca2165c7e2efd. Port only the narrow lease behavior; do not merge the falsification branch. Use an atomically claimed test directory rather than deleting or sharing another invocation's fixture.

Acceptance / executable witness

  • A Docker-only duplicated-descriptor test deterministically reproduces the old failure, without sleeps or race timing.
  • The owner excludes contenders while live; dropping it permits a successor even while the old duplicate remains open.
  • Closing the old duplicate does not release the successor's lease.
  • WAL hardening tests pass in the ordinary and det_fixed configurations.
  • Formatting and strict Clippy pass for touched code.
  • WAL documentation states the drop fallback and its limitations accurately.

Scope and exclusions

Internal filesystem adapter guard, regression evidence, WAL topic documentation, changelog. No package/producer repins, historical WIP merge, scheduler changes, or WAL format changes. Best-effort Drop does not provide a fallible explicit-release result. The broader process-bound lease design, explicit release failure API, and fork authority contract remain in #718; this issue does not close it.

This is a separate CI repair prerequisite for #734 / PR #735, based on the existing pure-evaluation branch #726 so the work remains independently reviewable.

Implementation

PR #737, commit 00fd1e6c400b52297cb7953158a54d7e4dae0fdc. All acceptance checks above passed locally in copied-source Docker runs. Hosted CI is tracked separately on the PR; the issue remains open until integration.

Activity

  1. added
    enhancementNew feature or request
    work-in-progressSomeone is actively working this issue.
    bugSomething isn't working
    and removed
    enhancementNew feature or request
    on Oct 4, 2026
  2. flyingrobots commented on Oct 4, 2026

    @flyingrobots
    OwnerAuthor

    Implemented as focused PR #737 (00fd1e6c). The new regression first failed with WriterEpochLeaseUnavailable, then passed in ordinary and det_fixed builds. All 125 WAL hardening tests passed in each configuration; strict Clippy passed. All executable checks ran in Docker with copied sources and no host repository/Git mounts.

    The repair explicitly attempts unlock before closing the owner descriptor. It also proves that closing the retired duplicate cannot release a successor lease. The broader process-bound authority and fallible release API remain in #718. Hosted CI is pending.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingwork-in-progressSomeone is actively working this issue.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions