fail closed before resumed publication side effects

This commit is contained in:
2026-08-12 00:23:17 +02:00
parent c498a15ecf
commit a3e2276bef
+6
View File
@@ -387,6 +387,12 @@ export class WorkspaceRegistry {
}
target = state.fetchedTargetCommit ?? target;
if (!target) throw new WorkspaceRegistryError("registry_bootstrap_recovery_conflict", "Bootstrap recovery is ambiguous or corrupt");
// Do not reacquire participant leases or run side effects when a restart finds a
// target-published job whose active pointer has drifted.
if (state.phase === "target_published") {
const active = await this.#tryActiveState();
if (!active || active.head !== target || registryDigest(active) !== state.targetManifestSha256) throw new WorkspaceRegistryError("registry_bootstrap_recovery_conflict", "Active registry target drifted");
}
// Once advertised, the run-specific ref is immutable evidence. Every resume after
// the fetch barrier revalidates it before reading or publishing any bytes.
if (state.phase !== "target_advertised" && state.phase !== "request_claimed") {