From 32d4c56212c7453a223bf5ca04ea27cc03e133f1 Mon Sep 17 00:00:00 2001 From: Xiaoyang Han Date: Thu, 8 Oct 2026 05:08:41 +0800 Subject: [PATCH] fix(mst2): finish chunk-map admission and isolate native observers Fix the missing native_chunk_maps field in the shared test Storage constructor and replace the redundant install-flight initializer closure without changing its behavior. The persisted-META reader/GC race now observes the actual lock wait through a separate one-connection pool, preserving the original two-connection service pool and every protection, release/GC, owned-byte and damage assertion; the prior observer itself consumed the connection needed by its competitor. Certificate lifetime checks bind the requested ten-day expiry to the actual issuance request interval rather than time spent later parsing/verifying the certificate, preserving the X509/response expiry equality, key and SAN checks. Exact earlier #76 native result was 2413 passed/2 failed/2 ignored (reader observer and certificate timing); #77 failed all-target Clippy for the missing constructor field and redundant closure. Production trust/lease/retention guards remain. Format/diff/locked offline metadata pass; corrected native tests remain pending. --- .../snapshot_persisted_metadata_tests.rs | 19 +++++++++++-------- src/ceres/snapshot/chunk_map_gate.rs | 2 +- src/contract/vault/pki.rs | 17 ++++++++++------- src/jupiter/tests.rs | 1 + 4 files changed, 23 insertions(+), 16 deletions(-) diff --git a/src/api/router/snapshot_persisted_metadata_tests.rs b/src/api/router/snapshot_persisted_metadata_tests.rs index f66d58da..057d9d26 100644 --- a/src/api/router/snapshot_persisted_metadata_tests.rs +++ b/src/api/router/snapshot_persisted_metadata_tests.rs @@ -685,14 +685,17 @@ async fn mst2_persisted_meta_reader_holds_protection_until_all_route_bytes_are_o } }) }; - let observer = fixture - .state - .storage - .mono_storage() - .get_connection() - .begin() - .await - .unwrap(); + // The two service connections belong to the reader and competitor. + // Observe their lock wait without competing for either connection. + let mut observer_config = fixture.state.storage.config().database.clone(); + assert_eq!(observer_config.max_connection, 2); + observer_config.max_connection = 1; + observer_config.min_connection = 0; + let observer_connection = + crate::jupiter::storage::init::database_connection(&observer_config) + .await + .unwrap(); + let observer = observer_connection.begin().await.unwrap(); tokio::select! { () = wait_retention_waiter(&observer) => {}, outcome = &mut competing => { diff --git a/src/ceres/snapshot/chunk_map_gate.rs b/src/ceres/snapshot/chunk_map_gate.rs index 5c56a504..765e6c3b 100644 --- a/src/ceres/snapshot/chunk_map_gate.rs +++ b/src/ceres/snapshot/chunk_map_gate.rs @@ -25,7 +25,7 @@ pub(crate) struct InstallFlight { impl InstallFlight { pub(crate) fn acquire(key: [u8; 32]) -> Result { static REGISTRY: OnceLock>> = OnceLock::new(); - Self::from_registry(REGISTRY.get_or_init(|| Arc::default()).clone(), key) + Self::from_registry(REGISTRY.get_or_init(Arc::default).clone(), key) } fn from_registry(registry: Arc>, key: [u8; 32]) -> Result { diff --git a/src/contract/vault/pki.rs b/src/contract/vault/pki.rs index cc111aaa..2f262a2c 100644 --- a/src/contract/vault/pki.rs +++ b/src/contract/vault/pki.rs @@ -385,8 +385,16 @@ mod tests_raw { .unwrap() .clone(); + let issuance_started = SystemTime::now() + .duration_since(UNIX_EPOCH) + .unwrap() + .as_secs(); // issue cert let resp = test_write_api(core, "pki/issue/tls/test", true, Some(issue_data)).await; + let issuance_completed = SystemTime::now() + .duration_since(UNIX_EPOCH) + .unwrap() + .as_secs(); assert!(resp.is_ok()); let resp_body = resp.unwrap(); assert!(resp_body.is_some()); @@ -429,15 +437,10 @@ mod tests_raw { let ttl_compare = cert.not_after().compare(&expiration_time); assert!(ttl_compare.is_ok()); assert_eq!(ttl_compare.unwrap(), std::cmp::Ordering::Equal); - let now_timestamp = SystemTime::now() - .duration_since(UNIX_EPOCH) - .unwrap() - .as_secs(); let expiration_ttl = cert_data["expiration"].as_u64().unwrap(); - let ttl = expiration_ttl - now_timestamp; let expect_ttl = 10 * 24 * 60 * 60; - assert!(ttl <= expect_ttl); - assert!((ttl + 10) > expect_ttl); + assert!(expiration_ttl >= issuance_started + expect_ttl); + assert!(expiration_ttl <= issuance_completed + expect_ttl); let authority_key_id = cert.authority_key_id(); assert!(authority_key_id.is_some()); diff --git a/src/jupiter/tests.rs b/src/jupiter/tests.rs index 2b03da07..4f39f1ad 100644 --- a/src/jupiter/tests.rs +++ b/src/jupiter/tests.rs @@ -379,6 +379,7 @@ pub async fn test_storage_with_config(temp_dir: impl AsRef, config: Config app_service: Arc::new(svc), native_projection_cache: Arc::default(), native_snapshot_sessions: Arc::default(), + native_chunk_maps: Arc::default(), projection_observation_sink: None, cl_service: CLService::mock(), push_queue_service: PushQueueService::new(