Skip to content

v0.4.8

Latest

Choose a tag to compare

@justin-stanley justin-stanley released this 08 Oct 13:28
· 3 commits to main since this release
50e34f9

FeatherReader 0.4.8 hardens how it reads atproto repos:

  • A PDS that cuts a subscription list short can no longer drop a reader's subscriptions.
  • A publication read that fails is now filed under what the PDS actually sent, not as "unreachable".
  • A small publication that shares a repo with big ones is read in full.

Full engineering detail is in CHANGELOG.md.

Upgrade notes

  • No schema change and no new settings. Upgrading from 0.4.7 is a deploy, and rolling back to 0.4.7 is a redeploy. Both were rehearsed on a fork of a production volume: 0.4.8 booted with db: ok and served its pages, and 0.4.7 then booted on the result, also with db: ok.
  • A subscription listing that repeats its cursor is refused, and the reader sees their last-known list, as for any listing failure.
  • A refresh that would drop 3 or more of a reader's feeds reads the list twice. It is applied only if both reads agree. Otherwise the reader sees their last-known list with an alert, and nothing is removed.
  • The /stats "why they are failing" counts shift for publications. Listing failures that were counted as fetch now count as parse, status or body, according to what the PDS sent.
  • Publications a repo's shared read starved are re-read alone, within the existing read deadline.

Security

  • A truncated subscription listing could remove a reader's access to feeds (#278, closes #203). That listing replaces the reader's whole sub_ref authorization set.
    • Repeated cursor: the three subscription walks now refuse a repeated cursor on a non-empty page.
    • Large drop: a page with a cursor and no records is how a real PDS ends a list, so the walk can't treat it as an error. Instead, a refresh that would drop 3 or more feeds must read the same list twice before it is applied.
    • Failed second read: the reader is told the real cause.

Fixed

  • Publication listing failures were all filed as Fetch (#279, closes #227). They are now typed and mapped:
    • an empty body or no records field is Parse;
    • a 2xx error envelope is Status;
    • too many pages, bytes or records, or an oversized body, is Body.
  • Big siblings could starve a quiet publication in the same repo (#281, closes #229). It was latent at measured scale.
    • When: a publication the shared walk cut short because it ran out of bytes is re-read alone after the group's reads are stored. The page limit, a repeated cursor and the combined cap don't trigger a re-read.
    • Order: starved publications are re-read first.
    • Bounds: only one budget is held at a time, and re-reads stay within the existing read deadline. A failed re-read keeps the group's outcome.

Known

  • A page carrying a malformed record still charges its whole wire size to a repo's shared read budget, siblings' documents included.
  • A few refusals are still filed as Fetch (#280).