TanStack

Content temporarily unavailable

Publication deferral cleanup review

Reviewed state and law

  • Base commit: 33a194941c8d51f8f98babb999fef2987dd6ff8b.
  • Reviewed implementation and oracle head: 8a6a024e (the review record follows that immutable commit).
  • Owner: packages/db/tests/collection-subscription-lifecycle-publication.property.test.ts with its deferral histories in collection-subscription-lifecycle-grammar.ts.

Collection cleanup ends a sync run. A publication deferral from that run cannot discard or publish a later run's subscriber batch. The new run publishes its committed changes when its own deferral closes with publish(). Its own discard() suppresses those changes. The driver compares the exact subscriber batch after each handle closes and checks for early delivery after an old handle closes.

The bounded grammar has two sync runs and one or two new rows. It crosses an inner handle's publish() or discard(), four old outer-handle close modes, and the new handle's publish() or discard(). One close mode leaves the old handle open. Another closes it before the new deferral. The last two close it with publish() or discard() while the new deferral is active. The grammar contains 32 unique histories.

RED, repair, and GREEN

On the base commit, the first controlled witness reached the new subscriber callback checkpoint. It expected [["c"]] and observed []. The first 16-case grammar produced four assertion failures. Each failure required an inner discard before cleanup and a new publication after restart.

A one-line reset of the old discard flag made those 16 cases pass. An independent prep review then found a second legal history. The old outer handle could close the new run's active deferral. With an old publish(), the subscriber received the new batch before the new handle closed. With an old discard(), the subscriber missed the new batch. The expanded 32-case grammar rejected that reset-only repair in 12 cases. These were assertion failures at the intended old-handle or new-handle checkpoint. They were not setup failures or timeouts.

The repair gives each deferral its own record. Each handle captures that record. Cleanup retires the record. A handle from the retired run cannot close the new record. The 32 histories and the adjacent sync reentrancy suite passed, 160 tests total. The DB oracle campaign passed 42 files and 2,669 tests with no Vitest type errors. Changed-file ESLint, Prettier, and git diff --check passed. Direct package tsc --noEmit still reports two unresolved @tanstack/db self-imports in conformance files in this unbuilt checkout. It reports no error in the changed files.

ORC-001 through ORC-011

RequirementOutcome
ORC-001 authority and limitsPass. Collection cleanup and publication contracts require a restarted run to publish independently. The executable opening and coverage map state the finite history limit.
ORC-002 independent judgmentPass. The reference selects post-restart writes and the new handle's close action. It does not read production depth, discard flags, revision fields, or event queues.
ORC-003 distinct responsibilitiesPass. The opening states the law. The shared grammar defines histories and the reference. The driver calls the real Collection sync, cleanup, restart, deferral, and subscription APIs. Subscriber batches at close are the refinement check.
ORC-004 grammar controlsPass for bounded enumeration. The grammar reconstructs the reported sticky-discard history and the adjacent stale-handle overlap. Without inner discard, the original fault is absent. Without overlap, the second fault is absent. One and two rows distinguish loss from batch grouping. A new discard is a negative control. The range is two runs, one old row, and one or two new rows. Construction excludes a new-handle close before its open and restart before cleanup.
ORC-005 path and observationPass. The driver records two actual sync invocations and uses a real subscribeChanges callback. It checks no early batch during writes or an old-handle close, then checks the exact batch when the new handle closes.
ORC-006 checker calibrationPass. The base failed four of 16 cells. The reset-only wrong design failed 12 of 32 cells. Both reached the intended subscriber comparison with an assertion failure.
ORC-007 campaigns and replayNot applicable to this bounded enumeration. The owner's existing fixed-seed and seedless generated properties remain in the 42-file campaign.
ORC-008 model minimalityPass. Post-restart row keys and the new close action determine this law's expected batch. An old-run close cannot change it. A different new row or close action changes the promised observation.
ORC-009 vocabularyPass. cleanup ends a sync run. restart begins a new sync run. Each write is one immediate sync transaction. A callback batch is the public publication observation. The grammar's handle labels identify deferrals, not acquisitions.
ORC-010 failure fidelityPass. The driver keeps the primary mismatch, attempts unsubscribe and cleanup separately, and places any cleanup errors after the primary error in an AggregateError with its cause.
ORC-011 second formulationNot triggered. The identified wrong designs are rejected by the reference and real callback trace. A second semantic formulation has no named shared-fault hypothesis here.

This versioned record supplies ORC-012 evidence for the reviewed head.

Coverage boundary and review loss audit

The Collection lifecycle publication owner covers the direct Collection path for the 32 histories. The includes publication owner still needs a compiled includes witness: cleanup during a discarded source deferral, then a parent or child publication observed at its callback boundary. The coverage map names that owner and witness. This direct-path result does not establish all includes graph schedules or arbitrary numbers of nested handles.

The source audit's three recorded claims and the prep review's adjacent finding are accounted for. The sticky-discard and stale-handle product bugs are fixed now. The missing lifecycle transition is covered by the bounded grammar. The proposed one-record shape was useful but needed an identity check to isolate old handles. No finding is refuted or silently deferred. The compiled includes witness is an explicit remaining coverage item.

Follow-up review: subscriber change payloads

  • Reviewed executable head: 126ee08789d1146dcb1db3b173c66a39e8933701.
  • The review record follows that immutable commit. This follow-up changes the oracle only; the Collection implementation and 32-history grammar are the same as in the first review.

The Collection API says that _deferPublication() delays subscriber events until a coherent commit ends, cleanup() clears the Collection and permits a later sync run, and subscribeChanges() delivers change messages. The glossary defines cleanup as the end of a sync run. This PR makes one explicit design decision at their boundary: a deferral handle belongs to the sync run in which it opened. Cleanup retires that handle's authority over later publications.

RequirementFollow-up outcome
ORC-001 authority and limitsPass with the API, glossary, and design decision above. The direct Collection path and finite-history limits remain as stated above.
ORC-002 independent judgmentPass. The reference still selects only post-restart fixture writes and the current handle's close action. It now describes each expected insert's key and row value.
ORC-003 distinct responsibilitiesPass. The existing opening, shared grammar, real Collection driver, and subscriber comparison remain visible.
ORC-004 grammar controlsPass. The same 32 histories, ablations, range, and exclusions apply.
ORC-005 path and observationPass. The callback recorder now preserves each change's type, key, row value, and prior value. It keeps callback boundaries and excludes virtual fields from this bounded comparison.
ORC-006 checker calibrationPass. A temporary mutant changed deferred callback row values to -1. Before this follow-up, all 32 histories survived. With the stronger recorder, 16 histories failed at the new-handle subscriber assertion. The original base and reset-only controls remain rejected.
ORC-007 campaigns and replayNot applicable to the bounded enumeration, as above.
ORC-008 model minimalityPass. The reference remains a stateless projection of fixture writes and the current close action.
ORC-009 vocabularyPass. The command-to-production mapping above remains unchanged.
ORC-010 failure fidelityPass. The driver still preserves the primary assertion and secondary cleanup errors separately.
ORC-011 second formulationNot triggered. No new shared-fault hypothesis arose from the payload observation.

The focused publication and lifecycle suites passed 334 tests with no Vitest type errors. Changed-file ESLint, Prettier, and git diff --check passed. The compiled includes witness remains open with the same coverage-map owner.

Follow-up review: retired queue ownership and null prior values

  • Reviewed executable head: cda3e71fbf900d1bcdab0bd28be027fca8c605ac.
  • This record follows that immutable commit. The production change releases queued messages from deferrals retired by cleanup or their final close.

A later CodeRabbit review of 9b069242 identified a retained queue. A stale handle remains reachable after cleanup and captures the old deferral record. Cleanup removed the manager's reference, but left its queued publications in the captured record. changes.ts was byte-identical at the later 4e615774 head, so the same finding applied there. A focused test queued one publication, held the old handle, and checked the retired record after cleanup. Before the repair it failed with one retained publication at the queue-cardinality assertion. The adjacent final-close case retained the queue as well. The repair empties each retired queue while preserving the messages needed for a normal publish(). Both cases pass, and stale handles still cannot affect a new run.

Queue retention has no public subscriber observation: a subscriber sees the same messages whether a retired, reachable handle retains an array or releases it. The focused internal invariant test is the appropriate witness for this memory-ownership law. The 32 public publication histories remain the oracle for delivery and isolation. The direct Collection path still does not prove the compiled includes witness named above.

A separate checker control exposed a null-value observation gap. A temporary subject mutant injected previousValue: null at the final subscriber callback. The first payload recorder treated that prior value as absent, and all 32 histories stayed green. The corrected recorder preserves null and omits only undefined; the mutant then failed 16 of 32 histories at the subscriber equality assertion. Unmutated production passed all 32. This control changes the oracle's observation fidelity, not the product contract or history grammar.

The focused publication, sync reentrancy, and lifecycle suites passed 361 of 361 tests with no Vitest type errors. Changed-file ESLint, Prettier, and git diff --check passed. Against origin/main, production changes.ts is 36 lines added and 30 removed, a net increase of six lines. Tests and review documentation are accounted for separately.