Files
buzz/desktop/scripts
npub1mn7jgtj4w2pd0g0zeuhxsa6jy6p0rewxz4kujt98my82ahfmp72sxjexk7andWill Pfleger 5f96c738d8 fix(archive): close TOCTOU race on shared owner_p row with atomic DB merge
Two concurrent seed hooks (observer 24200 + metric 44200) each fire on
first internal-build run with no prior owner_p row. The old TS-side
read-then-write merge raced: each hook read [] before the other had
written, so last writer clobbered the first kind.

Add store::merge_owner_p_kinds: reads existing kinds JSON, unions in
new_kind, and writes back under a single SQLite unchecked_transaction.
Concurrent callers serialize on the SQLite write lock — last writer
always reads the first writer's committed row.

Add merge_save_subscription_kinds Tauri command in archive/mod.rs (same
module as the other subscription commands; registered in lib.rs).

Both seed hooks and their deps interfaces now call this single command
with just their own kind, replacing the list+merge+create pattern.
tauriArchive.ts gains a mergeSaveSubscriptionKinds() binding.

Tests added:
- store.rs: create-when-none, adds-kind-to-existing, idempotent,
  concurrent-interleave (observer writes first, metric second, both
  kinds survive)
- useAgentMetricArchiveSeed.test.mjs: updated to new deps interface,
  adds test_concurrent_seeds_both_kinds_survive (Promise.all interleave)
- useObserverArchiveSeed.test.mjs: symmetric update to new interface

File-size overrides bumped: archive/mod.rs +30 (command), store.rs
+110 (new fn + 4 tests — first override for store.rs).

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
2026-07-06 17:45:15 -04:00
..