Sim tier specified but missing: no internal/sim, make sim is a no-op, budgets unasserted #338
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub#338
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Child of #331 (audit findings 3228/3229, commit
70d29dd). AGENTS.md law 6 says happy-path budgets 'are asserted in the sim (docs/go/15_testing.md)' and working rules say 'make sim when you touched internal/wal'; 15_testing.md:180-206 normatively specifies internal/sim scenarios (TestSim_SafetyThenLiveness, TestSim_HealthyRequestRoundTripBudgets via FaultStore Stats.Ops, TestSim_LivenessUnderRandomSeeds). Reality: internal/sim/ does not exist, Makefile:76 lists sim in .PHONY with no recipe ('Nothing to be done for sim'), FaultStore (internal/store/fault/fault.go:105) exists but nothing consumes it for budgets. Also doc 15 D3 names Make targets with no recipe: test-slow, contract-fs, dev. Fix: either land the sim package + recipes (preferred, the law depends on it) or amend the law/doc to stop claiming it; either way amend D3 target list to the actual Makefile.Preferred path taken — sim tier landed: #350 (branch fix/issue-338-sim; note fix/issue-338 is held by another active worktree, possible duplicate effort).
What landed: internal/sim (11/12 scenarios, budgets asserted, law-6 reconciliation written into §4.1), make sim + contract-fs, sim in ci, D3 corrected. Gaps G1/G2/G3 stated in package doc + D8.
The sim earned its keep before landing: proving safety exposed 3 real wal liveness bugs, all fixed + regression-pinned in the PR (orphan-sweep race corrupting listed segments; orphan-backlog death spiral to the ErrCorrupt cap; wiped version token spinning the CAS ladder). Full details + test evidence in the PR description. Not merging — review requested.
REVIEW PR #350 (fix/issue-338-sim, commit
76454cdincl. 1 review fix): READY TO MERGE (no blockers).VERIFIED (scratch worktree /tmp/pr350, removed after):
THE 3 WAL FIXES (all sound):
(a) sweepBurned recheck-latest: SOUND on success path — CAS linearity makes it airtight (a manifest newly listing S can only CAS from a base with head<S, so any such commit linearizes before our post-commit recheck; ladder never commits seq<=head per claimSlot publish.go:783 restart). Regression test pins it.
(b) failure-path sweep: same guard, batch-local map + committedBatch flag so no double-sweep; cross-batch overlap idempotent via Head-absent skip. No corruption vector.
(c) token adopt on guard-reject: SOUND — writes only into empty slot (handle.go:170), never overwrites a held token; ref view/heldRev untouched (StaleInstance pins rev==2); worst case a wrong token self-heals via 412->re-sync. Exactly-one-winner untouched (CAS decides; ConcurrentPushers proves loser convergence).
FINDINGS (1 fixed, 2 suggestions):
76454cd): runBatch comment claimed the failure sweep 'cannot harm a concurrent committer' — overclaim. Residual ms-window TOCTOU remains on the FAILURE path only (owner CAS landing between recheck-GET and segment-DELETE; success path is airtight per above). Comment now states the window honestly (same accepted check-then-act class as 20.9 S3 delete).Fixed by PR #350 (review clean — harness, 3 wal fixes, budgets, gates all verified + one comment-honesty fix by reviewer; sim green, -race clean, coverage holds), merged. Closing.