Repository navigation
Resolve server-move source access before freezing writes - #4838
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚨 SLOP COP 🚨 ·
new-issue-autopilotHuman comments
What was wrong
The server-move coordinator freezes public writes before obtaining the source host's Connect grant. Grant acquisition can require a POST to the account plugin, which the existing freeze middleware rejects with HTTP 503. The move then fails before handoff. Reproduced on trusted main in two clean checkouts: https://get-bb.github.io/reports/issues/4837.html
What changed
Resolve the source grant before freezing writes, honoring cancellation before entering the frozen stage. Keep the existing freeze exemptions, schedule pausing, stop-work, plugin suspension, and handoff behavior. Extend the existing Connect coordinator test to exercise account RPC availability through the real freeze middleware and a migrated SQLite database. No public protocol, authorization, dependency, or stored-data changes.
How you verified
Added the regression before changing production code. On unchanged main, it fails with account RPC status
[503]instead of[200]; the same failure repeats in a second clean checkout.After the fix,
pnpm exec turbo run test --filter=@bb/server -- test/server-move/coordinator.test.ts -t 'source grant requires'passes.pnpm exec turbo run test --filter=@bb/server -- test/server-move: 97 tests pass across 16 files, including cancellation, recovery, write fences, and handoff.pnpm exec turbo run typecheck --filter=@bb/server, the configured formatter check, andgit diff --checkpass.Changed-line count against
origin/main: 55 text lines (42 additions + 13 deletions), 2 files, no binary changes, one existing subsystem.Scope: coordinator/HTTP-boundary regression; no live authenticated cloud or macOS desktop run.
Review follow-up: the regression's freeze middleware now reads
coordinator.isFrozen(), the same predicate the production/api/v1/*freeze gate uses, instead of the SQLite freeze flag. Against the unfixed coordinator it still fails with[503]instead of[200], and after the fix it passes: 24 coordinator tests pass and 97 server-move tests pass across 16 files, withlint/typecheckfor@bb/servergreen.Fixes #4837