Issue 120: a provisioner remembers what it did, not what is there #114

Merged
jschoubben merged 1 commits from issue/120-a-provisioner-remembers-what-it-did-not-what-is into main 2026-09-26 12:14:18 +00:00
Owner

Located, not fixed. This PR records the issue only.

The provisioner harness skips any consumer whose login, password and values hash hasn't changed. It never checks the backend.

  • The cache. It has no ACL file, so its per-consumer users live only in memory. A server restart erases them. The provisioner, still running, does nothing about it. Every consumer fails to authenticate, and nothing reports it.
  • Wider cases. The same gap opens for:
    • a restored backup;
    • a login removed by hand;
    • a server recreated on an empty data directory.
  • The reverse drift. A contribution that disappears while the provisioner is down is never removed.

Found during research 016, in hq PR #113.

The open questions are in the report:

  • apply on every pass instead of trusting a hash;
  • an ACL file for the cache;
  • where the applied record should live.

records.py, index.py and cycle.py pass.

**Located, not fixed.** This PR records the issue only. The provisioner harness skips any consumer whose login, password and values hash hasn't changed. It never checks the backend. - **The cache.** It has no ACL file, so its per-consumer users live only in memory. A server restart erases them. The provisioner, still running, does nothing about it. Every consumer fails to authenticate, and nothing reports it. - **Wider cases.** The same gap opens for: - a restored backup; - a login removed by hand; - a server recreated on an empty data directory. - **The reverse drift.** A contribution that disappears while the provisioner is down is never removed. Found during research 016, in hq PR #113. The open questions are in the report: - apply on every pass instead of trusting a hash; - an ACL file for the cache; - where the applied record should live. `records.py`, `index.py` and `cycle.py` pass.
jschoubben added 1 commit 2026-09-25 22:44:20 +00:00
The harness compares against its own memory, so a backend that loses
what was provisioned (the cache's ACL users on a server restart) is
never provisioned again, silently.
jschoubben merged commit de0c9b6cfc into main 2026-09-26 12:14:18 +00:00
jschoubben deleted branch issue/120-a-provisioner-remembers-what-it-did-not-what-is 2026-09-26 12:14:18 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#114