A rule change on a large entitlement set is shown as not applied when its first recomputation fails on one pool, although it was applied #217
Open
opened 2026-10-10 23:59:47 +00:00 by cgalo5758
·
0 comments
Labels
Clear labels
accessibility
area/billing
area/catalog
area/discourse
area/domains
area/entitlements
area/fedwiki
area/identity
area/integrations
area/licensing
area/member-ui
area/meta
area/operator-ui
area/ops
area/testing
duplicate
good-first-issue
invalid
privacy
security
upstream
wontfix
A barrier for people using assistive technology or a keyboard alone.
The Stripe mirror, checkout, subscriptions, invoices, fulfillment.
Products, prices, plan ladders, purchasability.
The Discourse integration.
The domains registry, claims, placements, the certificate ask.
Entitlement sets, rules, grants, pools, provisioning.
The Federated Wiki integration and farm sync.
Sign-in, sessions, persons, organizations, workspaces, roles.
The provider registry, outbox and webhooks in general.
Licenses, the contributor agreement, SPDX headers.
Member pages.
The repository itself, its contributing guide, CI, the tracker and the workflow.
Operator pages, forms, lists, the design system.
Deployment, configuration, migrations, workflows, instance settings.
The test stack, screens, lint, walkthroughs.
Closed because another issue already covers it.
Small, self-contained, and explained enough to be a first contribution.
Closed because it is not a ticket for this repository.
Touches what a person's data reveals.
Touches authentication, authorization, secrets or data exposure.
Waits on another repository or project before it can move.
Closed because it will not be done, with the reason in the last comment.
kind
bug
The software does something other than what it promises; closed when it again does what it promises.
kind
debt
Code, tests or tooling to clean up with nothing visible changing; closed when they are cleaner.
kind
design
A question to settle before work can be defined; closed when the decision is written down.
kind
docs
Documentation that is wrong or missing; closed when it says the right thing.
kind
enhancement
Something the software does not do yet; closed when it does.
priority
critical
Blocks the active milestone or harms members now.
priority
high
Next in line inside the active milestone.
priority
low
Inside the active milestone, when nothing else is left.
priority
medium
Inside the active milestone, after the high ones.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: wiki-cafe/member-console#217
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What happens
A rule change on an entitlement set carried by more than 250 pools is applied in two parts. The commit stores the new rules, one change record per rule, and an obligation to recompute each pool under each of those changes. Those are durable from that point. The request then recomputes up to 50 pools within 2 seconds (its drain) and leaves the rest to the poller, which picks up outstanding obligations every 5 seconds. (A pool is the record of what one organization is allowed.)
If that drain fails on any pool,
RuleChangeBatchCommitreturns its result together with the drain error. The commit stands either way.ApplyEntitlementSetRulestreats any error that is not a refusal as a failed apply:startEntitlementRecomputeDrain, so the remaining pools wait for the poller instead of the drain workflow, which the commit normally starts at once.A pool can fail the drain because another transaction holds its row past the lock timeout, or because of the deadlock described in #196. The failure is recorded as an attempt, and after five attempts the obligation needs the operator's Retry.
What should happen
The spec (entitlement-set-management, "A rule change commit reaches every carrying pool") says the deferred path drains what it can before returning and leaves the rest to be settled without an operator, and that both paths report their outcome in one toast. A commit that returns a result with a drain error is answered as applied. The error is logged, the tray clears, the toast reports how far the request got ("Rule change applied. of pools recomputed."), and
startEntitlementRecomputeDrainruns; it already starts the drain whenFailedis above zero.RuleChangeBatchCommitreturns a result only when the commit stands, so the handler can tell this case from a real failure. A handler test runs a deferred commit with one pool that fails.Where
internal/server/operator_entitlement_set_rule_change.go:ApplyEntitlementSetRules.internal/entitlements/rule_change.go: the deferred branch at the end ofRuleChangeBatchCommitandDrainChange.TestDrainObligationAttemptBudgetAndDeadLetterininternal/entitlements/rule_change_test.gocovers the engine returning both a result and an error. No test covers the handler's answer.Steps
Why it matters
An operator is told a rule change failed when it is live, sees old values in the rules table, and may apply the same batch again.