fix: release prepared-replacement terminal cutover leases - #286
Conversation
|
During the #240 M5 recovery/deployment, one additional terminal-hygiene edge case was reproduced. A cutover that had:
was rejected by
The current #286 guard recognizes normal typed-restart completion and prepared-replacement completion, but not this exact “drained + externally reloaded exact replacement + positive reconciliation” terminal generation. A bounded local recovery patch added that exact generation while preserving the same replacement identity / finish-pair checks; This does not block the final #240 typed-restart path, but the edge case remains a tracked gap for any future external exact-reload recovery. |
Fixes a terminal-hygiene gap exposed while deploying Wave 2.
#279 added the exact coordination-bound active PREPARED replacement closure path. A cutover completed by that path is legitimately terminal with:
However,
releaseClosedCutoverLeaseLocal()still only accepted the older drain + restart + finish shape. That left the completed #242 cutover lease blocking every successor cutover.This repair does not widen cutover execution authority. Terminal lease cleanup now accepts either:
For the prepared-replacement shape it additionally requires the terminal operation's
lifecycleActionto prove:finish;All existing revoked-root-carrier, terminal record hash, operation terminality, finished/unpinned lease, CAS version, replay, and no-state-rewrite guards remain.
Exact Candidate:
cb33bb7c6f200141b9797c56efdaf2964c726dcfae334e6f11cc3ca1aee1463255ca25df222cb9996ff5c1345c7a10705984783b5217c913f4379035src/carrier-binding.ts,src/carrier-binding.test.tsVerification on exact bytes:
Terminal lease release requires one normally completed cutover generationcarrier-binding.test.ts: 45/45 PASSnpm run typecheck: PASSnpm run build: PASSgit diff --check: PASSThis is required to clear the stale terminal #242 lease through the supported host-local hygiene seam; no direct database mutation is used.