fix(core): cron double-fire, materialize warnings, group quota fast path, SSE channel cap
Remediate the MEDIUM backend correctness/perf findings from the 2026-07-11 audit. B1 — a group cron template toggled disabled→enabled no longer re-fires every descendant's cron. Materialization now KEEPS a disabled cron template's copies (syncing `enabled` in place) instead of delete+recreate, preserving `last_fired_at`; the scheduler already skips disabled copies, so keeping them is inert. Queue/email arms still delete-on-disable (freeing the one-consumer slot). B2 — `rematerialize_stateful_templates` warnings are now logged at the app-create/delete and group-reparent chokepoints (were silently dropped); only the `Err` arm was handled before. B3 — the group KV/docs byte-quota check skips the O(rows) `SUM(octet_length(..))` scan when a cheap upper bound (`rows_after * max_value_bytes`) is already under the cap, so the full aggregate only runs near-cap. Every row is validated ≤ max_value_bytes, so the bound is sound (never lets an over-quota write through). B6 — the in-process SSE broadcaster caps live channels per map (`PICLOUD_REALTIME_MAX_CHANNELS`, default 100k); a subscribe that would open a NEW channel past the cap is refused with 503 + `Retry-After: 1` rather than growing the (app,topic)/(group,topic) maps unboundedly. Check+insert is atomic under the map mutex (no TOCTOU); an existing-channel subscribe is exempt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -318,8 +318,15 @@ async fn reparent_group(
|
||||
}
|
||||
// §4.5 M5: the moved subtree inherits a different set of ancestor-group
|
||||
// stateful templates — reconcile its materialized copies.
|
||||
if let Err(e) = crate::materialize::rematerialize_stateful_templates(&s.pool).await {
|
||||
tracing::warn!(error = %e, "groups: stateful-template materialization after reparent failed; it will self-heal");
|
||||
match crate::materialize::rematerialize_stateful_templates(&s.pool).await {
|
||||
Ok(warnings) => {
|
||||
for w in warnings {
|
||||
tracing::warn!(warning = %w, "groups: stateful-template materialization warning after reparent");
|
||||
}
|
||||
}
|
||||
Err(e) => {
|
||||
tracing::warn!(error = %e, "groups: stateful-template materialization after reparent failed; it will self-heal");
|
||||
}
|
||||
}
|
||||
Ok(Json(moved))
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user