End a locked account's delegation at its date #66

Merged
jcoffey-dev merged 1 commits from fix/delegation-until into main 2026-09-27 23:31:30 +00:00
Owner

Two fixes to delegation end dates (AL-5), found while writing the admin manual.

Access outlived the end date. When a delegation's until passed, the delegate dropped out of the lock's token, but the ACL grants on the locked account's folders stayed until the daily sweep. The delegate kept the account as an ordinary share for up to a day. Now each node sleeps until the soonest end date across all locks. A lock write on that node wakes it early, and it wakes at least hourly regardless, to catch writes on other nodes. At the date it re-applies that lock under a cluster-wide claim (KV_LOCK_TASK), so only one node does it.

The sweep's second run removed a real share. For a delegate past its date, the first reconcile put back the share it had before the lock and dropped the note of it. The next reconcile found no note and removed the share entirely. The note is now kept while the delegate is still listed.

Tests:

  • 2 new unit tests.
  • system::account_lock now sets an end date 3 s out and checks that the session and the folders are gone 6 s later. The test fails with the timer disabled. It passes on RocksDB, PostgreSQL and MySQL.
Two fixes to delegation end dates (AL-5), found while writing the admin manual. **Access outlived the end date.** When a delegation's `until` passed, the delegate dropped out of the lock's token, but the ACL grants on the locked account's folders stayed until the daily sweep. The delegate kept the account as an ordinary share for up to a day. Now each node sleeps until the soonest end date across all locks. A lock write on that node wakes it early, and it wakes at least hourly regardless, to catch writes on other nodes. At the date it re-applies that lock under a cluster-wide claim (`KV_LOCK_TASK`), so only one node does it. **The sweep's second run removed a real share.** For a delegate past its date, the first reconcile put back the share it had before the lock and dropped the note of it. The next reconcile found no note and removed the share entirely. The note is now kept while the delegate is still listed. Tests: - 2 new unit tests. - `system::account_lock` now sets an end date 3 s out and checks that the session and the folders are gone 6 s later. The test fails with the timer disabled. It passes on RocksDB, PostgreSQL and MySQL.
jcoffey-dev added 1 commit 2026-09-27 23:26:22 +00:00
End a locked account's delegation at its date
ci / fork-checks (pull_request) Successful in 44s
ci / build (pull_request) Successful in 4m59s
a36236efff
A delegation with an end date dropped out of the delegate's token then,
but its folder grants stayed until the daily sweep, so the delegate kept
the account as an ordinary share for up to a day. Each node now sleeps
until the soonest end date, woken early by any lock write and at least
hourly, and re-applies that lock under a cluster-wide claim.

The sweep also had a second-run bug: a delegation past its date gave the
delegate back its earlier share, then dropped the note, so the next sweep
removed that share entirely. The note is now kept while the delegate is
still listed.
jcoffey-dev merged commit dd3eec3936 into main 2026-09-27 23:31:30 +00:00
jcoffey-dev deleted branch fix/delegation-until 2026-09-27 23:31:31 +00:00
jcoffey-dev referenced this issue from a commit 2026-09-27 23:35:47 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: inbuxa/inbuxa-server#66