Skip to content

release unique guards and version-guard the agent ttl sweep - #132

Merged
fabracht merged 2 commits into
mainfrom
hold-reclaim-ttl-backstop
Sep 4, 2026
Merged

fabracht merged 2 commits into
mainfrom
hold-reclaim-ttl-backstop

Conversation

@fabracht

@fabracht fabracht commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes two real bugs in the agent-mode TTL sweep, and lands the design + model for on-disconnect hold reclaim (docs/design/hold-reclaim.md).

The TTL sweep deleted expired rows with a bare batch.remove:

  • it never released the row's unique-constraint guards, so an expired row with a unique field left its guard behind and the value became permanently unclaimable (a new create kept hitting the stale guard)
  • it carried no precondition, so a row renewed between the sweep's scan and its commit was deleted on the stale snapshot (silent data loss)

The sweep now mirrors the normal delete: expect_value on the exact scanned bytes plus release_unique_guards, one batch per row so a single concurrently-renewed row no longer aborts cleanup of the rest. The pass/reap logic is factored into a small TtlSweepCtx so the spawned task and the tests share one path.

Also included: the design doc for the whole hold-reclaim effort, and specs/AbandonedHoldReclaim.tla (+ cfgs) modeling the reap/reconnect/reclaim invariant (safe with a CAS fence + reassert-on-reconnect; false-releases without either).

This is the agent half of the TTL backstop; the cluster rewire (through the replicated delete path) follows separately.

Test plan

  • cargo test -p mqdb-agent (new: ttl_sweep_releases_unique_guard_and_reclaims_seat, ttl_reap_skips_row_renewed_after_scan)
  • cargo clippy --all-targets --all-features -- -D warnings
  • tla check: specs/AbandonedHoldReclaim.cfg safe; _nocas.cfg and _noreassert.cfg violate InvNoFalseRelease

@fabracht
fabracht merged commit 8303693 into main Sep 4, 2026
9 checks passed
@fabracht
fabracht deleted the hold-reclaim-ttl-backstop branch September 4, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant