forked from anomalyco/opencode
-
Notifications
You must be signed in to change notification settings - Fork 0
[REQ-100] 安装/卸载事务提交语义 fail-open —— 账本写失败仍报成功 #336
Copy link
Copy link
Closed
Labels
area:dataPersistence or data qualityPersistence or data qualityarea:securitySecurity or access controlSecurity or access controlprio:P1High-value near-term deliveryHigh-value near-term deliverytype:bugSomething is incorrect or regressedSomething is incorrect or regressed
Description
Activity
Metadata
Metadata
Assignees
Labels
area:dataPersistence or data qualityPersistence or data qualityarea:securitySecurity or access controlSecurity or access controlprio:P1High-value near-term deliveryHigh-value near-term deliverytype:bugSomething is incorrect or regressedSomething is incorrect or regressed
现象
扩展安装/卸载在账本(receipt/record)写失败时仍提交事务并返回
ok:true,制造出「已落地但账本失真」的安装态 —— 后续卸载/更新会按错误或缺失的账本执行,是原子事务不变量的 fail-open。根因(file:line)
commit(tx)并返回成功:packages/ui-mac/src/main/ext-install-planner.ts:565附近(注释「账本写失败不谎报安装失败」)。removeRecordV2失败仍commit(tx)返回ok:true,仅附 warning:packages/ui-mac/src/main/ext-install-planner.ts:670。违反的不变量
REQ-100「原子事务:staging/materialization + rollback/quarantine」—— 账本是事务的提交证据,写失败应 rollback/quarantine 而非 commit。
边界
期望
账本写失败 → 事务 rollback 或将安装标记 quarantine(不可静默视为成功);卸载账本删除失败 → 不 commit,进入需人工/重试的 fail-closed 态;补账本写失败注入测试。
来源
批次1 Codex 只读诊断(REQ-099 #256 裁决「未覆盖发现」)。父需求 Refs #211(不 Fixes,父由验收 owner 手工关)。