Repository navigation
GO-7561 acl: only the first consensus event finishes loading an acl object - #805
Merged
Merged
Conversation
…bject newAclObject waits for the first event of its watch. AddConsensusError and AddConsensusRecords both closed ready while the store was still empty, so an error followed by more events for the same watch closed it twice and panicked. The consensus client delivers a batch of events to the watcher at once, and a watch restored after a reconnect can report the same missing log again, so the coordinator could crash. The first event now finishes the load once; later events after a failed load are dropped, and records after a successful load are added as before.
Coverage provided by https://github.com/seriousben/go-patch-cover-action |
cheggaaa
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
newAclObjectwaits for the first consensus event of its watch. BothAddConsensusErrorandAddConsensusRecordsclosedreadywhile the store was still empty, so a watch that delivered more than one event before the object was dropped closed it twice:This can happen in any service that uses
acl.New()(coordinator, filenode, filenode2):newAclObjectcan't unwatch between them;UnWatch+Watchof a missing log while the client restores its watches after a reconnect (the restore is sent outside the client mutex) can get two errors for the same watcher; before, the server skipped the second request.Records that arrived after records which failed to build a list also reached a nil list.
Fix
The first event finishes the load, once (
finishLoad). After a failed load, later events are dropped; after a successful one, records are added as before and an error is only logged, now with the space id.Tests
TestAclObject_EventsAfterTheFirst: error then records, two errors, and broken records then records panic on main; an error after the records leaves the object loaded.Part of GO-7561. Must be deployed to the coordinator and both filenodes before anyproto/any-sync-consensusnode#115.
Release: services are on any-sync v0.13.6, and
mainafter it also has #802 (GO-7556, net/pool and net/peer changes). Either tag a v0.13.6-based patch with only this change, or ship #802 together with it.