jcoffey-dev is traveling from Thursday 1 October through Sunday 4 October. Issues and pull requests are welcome, and will get an answer after that. Thanks for your patience.
Two fixes to delegation end dates (AL-5), found while writing the admin manual.
Access outlived the end date. When a delegation's until passed, the delegate dropped out of the lock's token, but the ACL grants on the locked account's folders stayed until the daily sweep. The delegate kept the account as an ordinary share for up to a day. Now each node sleeps until the soonest end date across all locks. A lock write on that node wakes it early, and it wakes at least hourly regardless, to catch writes on other nodes. At the date it re-applies that lock under a cluster-wide claim (KV_LOCK_TASK), so only one node does it.
The sweep's second run removed a real share. For a delegate past its date, the first reconcile put back the share it had before the lock and dropped the note of it. The next reconcile found no note and removed the share entirely. The note is now kept while the delegate is still listed.
Tests:
2 new unit tests.
system::account_lock now sets an end date 3 s out and checks that the session and the folders are gone 6 s later. The test fails with the timer disabled. It passes on RocksDB, PostgreSQL and MySQL.
Two fixes to delegation end dates (AL-5), found while writing the admin manual.
**Access outlived the end date.** When a delegation's `until` passed, the delegate dropped out of the lock's token, but the ACL grants on the locked account's folders stayed until the daily sweep. The delegate kept the account as an ordinary share for up to a day. Now each node sleeps until the soonest end date across all locks. A lock write on that node wakes it early, and it wakes at least hourly regardless, to catch writes on other nodes. At the date it re-applies that lock under a cluster-wide claim (`KV_LOCK_TASK`), so only one node does it.
**The sweep's second run removed a real share.** For a delegate past its date, the first reconcile put back the share it had before the lock and dropped the note of it. The next reconcile found no note and removed the share entirely. The note is now kept while the delegate is still listed.
Tests:
- 2 new unit tests.
- `system::account_lock` now sets an end date 3 s out and checks that the session and the folders are gone 6 s later. The test fails with the timer disabled. It passes on RocksDB, PostgreSQL and MySQL.
A delegation with an end date dropped out of the delegate's token then,
but its folder grants stayed until the daily sweep, so the delegate kept
the account as an ordinary share for up to a day. Each node now sleeps
until the soonest end date, woken early by any lock write and at least
hourly, and re-applies that lock under a cluster-wide claim.
The sweep also had a second-run bug: a delegation past its date gave the
delegate back its earlier share, then dropped the note, so the next sweep
removed that share entirely. The note is now kept while the delegate is
still listed.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Two fixes to delegation end dates (AL-5), found while writing the admin manual.
Access outlived the end date. When a delegation's
untilpassed, the delegate dropped out of the lock's token, but the ACL grants on the locked account's folders stayed until the daily sweep. The delegate kept the account as an ordinary share for up to a day. Now each node sleeps until the soonest end date across all locks. A lock write on that node wakes it early, and it wakes at least hourly regardless, to catch writes on other nodes. At the date it re-applies that lock under a cluster-wide claim (KV_LOCK_TASK), so only one node does it.The sweep's second run removed a real share. For a delegate past its date, the first reconcile put back the share it had before the lock and dropped the note of it. The next reconcile found no note and removed the share entirely. The note is now kept while the delegate is still listed.
Tests:
system::account_locknow sets an end date 3 s out and checks that the session and the folders are gone 6 s later. The test fails with the timer disabled. It passes on RocksDB, PostgreSQL and MySQL.