ME Authority + Quota Resets + WEB Replacement Rollback fixes

This commit is contained in:
Alexey
2026-09-22 03:01:17 +03:00
parent 51e706770c
commit baa9bfbb01
30 changed files with 1400 additions and 587 deletions
-1
View File
@@ -14,7 +14,6 @@ use crate::config::{WebCarrier, WebLimitsConfig};
use crate::maestro::generation::RuntimeGeneration;
use crate::web::telemetry::{WebRejectionReason, WebTelemetry};
use crate::web::trace::WebTraceStore;
// Credential maps, quotas, and token-bucket helpers remain private to the manager.
mod state;
// Carrier attempt metadata remains explicit and independent from HTTP parsing.
@@ -57,6 +57,8 @@ impl WebProcessRuntime {
return Err(ManagerError::Closed);
};
let Some(user_registration) = user_publication.take_registration() else {
// Rollback callbacks can retire active user owners and must not run under authority.
drop(user_publication);
drop(state);
self.cancel_replacement(bootstrap_hash, &replacement.old_session);
return Err(ManagerError::Closed);
@@ -65,6 +67,8 @@ impl WebProcessRuntime {
self.record_limit_hit();
self.telemetry
.record_rejection(crate::web::telemetry::WebRejectionReason::SessionCapacity);
drop(user_registration);
drop(user_publication);
drop(state);
self.cancel_replacement(bootstrap_hash, &replacement.old_session);
return Err(ManagerError::Limit);
@@ -99,6 +103,7 @@ impl WebProcessRuntime {
Some(user_registration),
);
let Some(supersede) = replacement.old_session.prepare_carrier_supersede() else {
drop(user_publication);
drop(state);
self.cancel_replacement(bootstrap_hash, &replacement.old_session);
session.close(crate::web::session::SessionCloseReason::Protocol);