Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9a588ce12b |
+7
-8
@@ -1719,12 +1719,11 @@ issue #3 未关闭,`feat/fix-3-downlink-deadlock` 未合入 `main`。下面是
|
||||
- 备选方案:为每个未测子项补验收用例(本波不做,避免为变绿放松断言)。
|
||||
- 影响:汇总改为通过 19、部分通过 4(F03/F08/F21/F22)、失败 0。F19 仍引用仓库内 SDK 清单、本波不重跑。
|
||||
|
||||
### 复审修复 R3-07
|
||||
### 复审修复 R3-04
|
||||
|
||||
1. **客户端建群事务内复核创建者**
|
||||
- 日期:2026-09-30
|
||||
- 原条款:Gitea #71。`group.Create` 在 `Queue.Do` 里直接 `insertMemberTx` 群主,不跑 `endpointCheckTx`;停用/删除与建群抢在事务外对话密码窗口时,可插入已停用甚至刚删除的 `owner_id`。
|
||||
- 实际做法:`Create` 同一写事务里,插入群与群主成员之前对 `actorID` 做与 `createAdmin` 相同的 `endpointCheckTx`;已停用 `endpoint_disabled`,不存在 `invalid_target`,且不插入群。不改 `emit`、不改迁移编号。
|
||||
- 原因:成员侧已有事务内复核,群主侧缺对称校验,竞态会留下非法群主。
|
||||
- 备选方案:事务外再查一次创建者(否决,无法覆盖密码窗口与写事务之间的竞态)。
|
||||
- 影响:创建者在进入写事务前被停用/删除时建群失败且无新群行;与后台建群错误码对齐。
|
||||
- 日期:2026-09-30
|
||||
- 原条款:Gitea #68;`dispatchSend` 在 `PublishUp` 失败且未停止重连时清 inflight 后静默 return,`Send` 永久挂起。
|
||||
- 实际做法:失败且未 `stopReconnect` 时保留 id/body/send_at_ms,经 `regenerateSendLocked` 换新 rid,清本次 inflight 并 `drainSendQueue` 继续泵;已停止重连时仍 `finishSend` 返回错误。
|
||||
- 原因:条目已不在途,重连时的 `requeueInflightLocked` 不会捡回,调用方一直等 `result`。
|
||||
- 备选方案:失败即 `finishSend` 报错(否决,与断线/限速重交语义不一致);只换 rid 不唤醒队列(否决,等同 JS #69)。
|
||||
- 影响:仅 `sdk/go`;假传输可模拟 send 发布失败一次。
|
||||
|
||||
@@ -147,15 +147,6 @@ func (a *App) Create(ctx context.Context, actorID string, req *protocol.GroupCre
|
||||
|
||||
var inserted []string
|
||||
err := a.db.Queue.Do(ctx, func(tx *sql.Tx) error {
|
||||
if e := endpointCheckTx(tx, actorID); e != nil {
|
||||
if protoCode(e) == protocol.CodeInvalidTarget {
|
||||
return errCode(protocol.CodeInvalidTarget, "owner not found")
|
||||
}
|
||||
if protoCode(e) == protocol.CodeEndpointDisabled {
|
||||
return errCode(protocol.CodeEndpointDisabled, "owner disabled")
|
||||
}
|
||||
return e
|
||||
}
|
||||
var exists int
|
||||
qErr := tx.QueryRow(`SELECT 1 FROM groups WHERE id = ?`, gid).Scan(&exists)
|
||||
if qErr == nil {
|
||||
|
||||
@@ -604,106 +604,6 @@ func TestU02CreateDedupesMembers(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// raceTalk 在对话密码校验成功后执行一次 mutate,模拟事务外密码窗口里创建者被停用/删除。
|
||||
type raceTalk struct {
|
||||
inner group.TalkGate
|
||||
mutate func()
|
||||
once sync.Once
|
||||
}
|
||||
|
||||
func (r *raceTalk) CheckTalkPasswordForJoin(ctx context.Context, actorID, targetID, talkPassword, remoteIP string) error {
|
||||
err := r.inner.CheckTalkPasswordForJoin(ctx, actorID, targetID, talkPassword, remoteIP)
|
||||
if err == nil && r.mutate != nil {
|
||||
r.once.Do(r.mutate)
|
||||
}
|
||||
return err
|
||||
}
|
||||
|
||||
func TestR307CreateRejectsActorDisabledOrDeletedBeforeWrite(t *testing.T) {
|
||||
t.Parallel()
|
||||
cases := []struct {
|
||||
name string
|
||||
code string
|
||||
mutate func(ctx context.Context, t *testing.T, idApp *identity.App, db *store.DB)
|
||||
}{
|
||||
{
|
||||
name: "disabled",
|
||||
code: protocol.CodeEndpointDisabled,
|
||||
mutate: func(ctx context.Context, t *testing.T, idApp *identity.App, _ *store.DB) {
|
||||
t.Helper()
|
||||
if err := idApp.Disable(ctx, "alice"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "deleted",
|
||||
code: protocol.CodeInvalidTarget,
|
||||
mutate: func(ctx context.Context, t *testing.T, idApp *identity.App, _ *store.DB) {
|
||||
t.Helper()
|
||||
if err := idApp.Delete(ctx, "alice"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
},
|
||||
},
|
||||
}
|
||||
for _, tc := range cases {
|
||||
tc := tc
|
||||
t.Run(tc.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
db, err := store.Open(filepath.Join(t.TempDir(), "data"), "FULL")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Cleanup(func() { _ = db.Close() })
|
||||
fixed := time.UnixMilli(1_700_000_000_000)
|
||||
locks := auth.NewLoginLocks()
|
||||
idApp := identity.New(identity.Config{
|
||||
DB: db, Hash: auth.NewStubHashPool(), Locks: locks,
|
||||
Sessions: auth.NewSessionTokens(),
|
||||
Now: func() time.Time { return fixed },
|
||||
})
|
||||
gate := &raceTalk{inner: idApp}
|
||||
gApp := group.New(group.Config{
|
||||
DB: db, Talk: gate, MaxGroupMembers: 1000,
|
||||
Now: func() time.Time { return fixed }, DefaultRemoteIP: "1.1.1.1",
|
||||
})
|
||||
ctx := context.Background()
|
||||
insertEP(t, db, "alice", 1)
|
||||
insertEP(t, db, "bob", 1)
|
||||
if err := idApp.SelfSetTalkPassword(ctx, "bob", "secret"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
gate.mutate = func() { tc.mutate(ctx, t, idApp, db) }
|
||||
|
||||
var before int
|
||||
if qErr := db.Read.QueryRow(`SELECT COUNT(*) FROM groups`).Scan(&before); qErr != nil {
|
||||
t.Fatal(qErr)
|
||||
}
|
||||
_, err = gApp.Create(ctx, "alice", &protocol.GroupCreate{
|
||||
V: protocol.Version, Type: protocol.TypeGroupCreate, RID: "1",
|
||||
ID: "g_r307_" + tc.name, Name: "竞态群",
|
||||
Members: []protocol.GroupMemberIn{{ID: "bob", TalkPassword: "secret"}},
|
||||
})
|
||||
if protoCode(err) != tc.code {
|
||||
t.Fatalf("want %s got %v", tc.code, err)
|
||||
}
|
||||
var after int
|
||||
if qErr := db.Read.QueryRow(`SELECT COUNT(*) FROM groups`).Scan(&after); qErr != nil {
|
||||
t.Fatal(qErr)
|
||||
}
|
||||
if after != before {
|
||||
t.Fatalf("groups leaked: before=%d after=%d", before, after)
|
||||
}
|
||||
var exists int
|
||||
qErr := db.Read.QueryRow(`SELECT 1 FROM groups WHERE id = ?`, "g_r307_"+tc.name).Scan(&exists)
|
||||
if !errors.Is(qErr, sql.ErrNoRows) {
|
||||
t.Fatalf("expected no group row, got exists=%d err=%v", exists, qErr)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestU02AdminCreateOwnerMustExistAndEnabled(t *testing.T) {
|
||||
t.Parallel()
|
||||
gApp, _, _, db, down := setup(t)
|
||||
|
||||
@@ -156,6 +156,66 @@ func TestFrameTooLargeLocal(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestPublishUpFailRetriesWithNewRID(t *testing.T) {
|
||||
fake := NewFakeTransport()
|
||||
fake.FailSendPublishN(1)
|
||||
c := connectFake(t, fake)
|
||||
defer c.Close()
|
||||
|
||||
at := time.UnixMilli(1_700_000_000_000)
|
||||
fixedID := "msg-publish-retry"
|
||||
done := make(chan struct{})
|
||||
var firstRID, secondRID string
|
||||
|
||||
go func() {
|
||||
defer close(done)
|
||||
deadline := time.Now().Add(3 * time.Second)
|
||||
for time.Now().Before(deadline) {
|
||||
sends := fake.FindUp("send")
|
||||
if len(sends) < 2 {
|
||||
time.Sleep(5 * time.Millisecond)
|
||||
continue
|
||||
}
|
||||
first, second := sends[0], sends[1]
|
||||
firstRID, _ = first["rid"].(string)
|
||||
secondRID, _ = second["rid"].(string)
|
||||
if first["id"] != fixedID || second["id"] != fixedID {
|
||||
t.Errorf("id changed: %v -> %v", first["id"], second["id"])
|
||||
}
|
||||
if first["send_at_ms"] != second["send_at_ms"] {
|
||||
t.Errorf("send_at_ms changed: %v -> %v", first["send_at_ms"], second["send_at_ms"])
|
||||
}
|
||||
body1, _ := json.Marshal(first["body"])
|
||||
body2, _ := json.Marshal(second["body"])
|
||||
if string(body1) != string(body2) {
|
||||
t.Errorf("body changed: %s -> %s", body1, body2)
|
||||
}
|
||||
if firstRID == "" || firstRID == secondRID {
|
||||
t.Errorf("rid not regenerated: %q -> %q", firstRID, secondRID)
|
||||
}
|
||||
fake.ReplyOK(secondRID, map[string]any{
|
||||
"id": fixedID, "send_at_ms": second["send_at_ms"], "state": "scheduled",
|
||||
})
|
||||
return
|
||||
}
|
||||
t.Error("timed out waiting for send retry")
|
||||
}()
|
||||
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 3*time.Second)
|
||||
defer cancel()
|
||||
res, err := c.Send(ctx, Target{Kind: "endpoint", ID: "b"}, Body{Enc: "utf8", Data: "hi"}, SendOptions{ID: fixedID, SendAt: &at})
|
||||
<-done
|
||||
if err != nil {
|
||||
t.Fatalf("Send hung or failed: %v", err)
|
||||
}
|
||||
if res.ID != fixedID {
|
||||
t.Fatalf("result id=%q want %q", res.ID, fixedID)
|
||||
}
|
||||
if firstRID == "" || secondRID == "" || firstRID == secondRID {
|
||||
t.Fatalf("rids=%q/%q", firstRID, secondRID)
|
||||
}
|
||||
}
|
||||
|
||||
func TestResendKeepsIDAndSendAt(t *testing.T) {
|
||||
fake := NewFakeTransport()
|
||||
c := connectFake(t, fake)
|
||||
|
||||
@@ -3,6 +3,7 @@ package nixmsg
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"sync"
|
||||
"sync/atomic"
|
||||
"time"
|
||||
@@ -29,6 +30,8 @@ type FakeTransport struct {
|
||||
MaxFrameBytes int
|
||||
HelloDelay time.Duration
|
||||
ReceiveMaximumSet bool
|
||||
// failSendLeft 接下来若干次 type=send 的 PublishUp 返回错误(仍记入 up)。
|
||||
failSendLeft int
|
||||
}
|
||||
|
||||
type fakeConnect struct {
|
||||
@@ -65,6 +68,13 @@ func (f *FakeTransport) Start(ctx context.Context, cfg transportConfig) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// FailSendPublishN 让接下来 n 次 send 帧 PublishUp 失败(hello 等其它类型不受影响)。
|
||||
func (f *FakeTransport) FailSendPublishN(n int) {
|
||||
f.mu.Lock()
|
||||
f.failSendLeft = n
|
||||
f.mu.Unlock()
|
||||
}
|
||||
|
||||
func (f *FakeTransport) PublishUp(payload []byte) error {
|
||||
f.mu.Lock()
|
||||
cp := append([]byte(nil), payload...)
|
||||
@@ -80,6 +90,17 @@ func (f *FakeTransport) PublishUp(payload []byte) error {
|
||||
if auto && head.Type == "hello" && head.RID != "" {
|
||||
f.replyHello(head.RID)
|
||||
}
|
||||
if head.Type == "send" {
|
||||
f.mu.Lock()
|
||||
fail := f.failSendLeft > 0
|
||||
if fail {
|
||||
f.failSendLeft--
|
||||
}
|
||||
f.mu.Unlock()
|
||||
if fail {
|
||||
return errors.New("publish failed")
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
+7
-2
@@ -202,7 +202,10 @@ func (c *Client) dispatchSend(tr transport, item *sendItem, rid string, payload
|
||||
if err := tr.PublishUp(payload); err != nil {
|
||||
c.mu.Lock()
|
||||
delete(c.pending, rid)
|
||||
if item.epoch == epoch && item.inflight {
|
||||
if item.epoch != epoch || !item.inflight {
|
||||
c.mu.Unlock()
|
||||
return
|
||||
}
|
||||
item.inflight = false
|
||||
if c.inflight > 0 {
|
||||
c.inflight--
|
||||
@@ -213,8 +216,10 @@ func (c *Client) dispatchSend(tr transport, item *sendItem, rid string, payload
|
||||
c.finishSend(item, SendResult{}, errStop)
|
||||
return
|
||||
}
|
||||
}
|
||||
// 保留 id/body/send_at_ms,换新 rid 后继续泵,避免 Send 永久挂起。
|
||||
c.regenerateSendLocked(item)
|
||||
c.mu.Unlock()
|
||||
c.drainSendQueue()
|
||||
return
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user