Fix guest reconnect expiry across database lock waits - #112
Merged
Merged
Conversation
jiashuoz
marked this pull request as ready for review
September 30, 2026 04:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reconnect expiry checks could run before a blocking database lock was acquired. A lock-only transaction could let enrollment or challenge issuance succeed after expiry; a maintenance SHARE table lock could also let final acceptance rotate the bootstrap token and advance the connection epoch after challenge expiry.
Acquire the bootstrap table's ROW EXCLUSIVE lock and the specific bootstrap row lock before checking expiry in all three mutations. Preserve runner → session → bootstrap ordering and the exact identity/attempt/generation acceptance predicates. ROW EXCLUSIVE remains compatible with ordinary concurrent writers. Update the design note to state this requirement.
Validation:
-race; CLI race checks, build, and vet also passed during validation.a8fc415: fullmake verify, non-root ownership regression, CLI/client race checks, and fleet-script syntax.This store path is not yet exposed as an enabled reconnect endpoint. Real PostgreSQL and signed-proof tests exercise the changed surface; the fix does not enable guest reconnect or change a public API. Two commits keep the initial correction and the review-discovered table-lock correction separate.