Repository navigation
FeatherReader 0.4.8 hardens how it reads atproto repos:
- A PDS that cuts a subscription list short can no longer drop a reader's subscriptions.
- A publication read that fails is now filed under what the PDS actually sent, not as "unreachable".
- A small publication that shares a repo with big ones is read in full.
Full engineering detail is in CHANGELOG.md.
Upgrade notes
- No schema change and no new settings. Upgrading from 0.4.7 is a deploy, and rolling back to 0.4.7 is a redeploy. Both were rehearsed on a fork of a production volume: 0.4.8 booted with
db: okand served its pages, and 0.4.7 then booted on the result, also withdb: ok. - A subscription listing that repeats its cursor is refused, and the reader sees their last-known list, as for any listing failure.
- A refresh that would drop 3 or more of a reader's feeds reads the list twice. It is applied only if both reads agree. Otherwise the reader sees their last-known list with an alert, and nothing is removed.
- The
/stats"why they are failing" counts shift for publications. Listing failures that were counted asfetchnow count asparse,statusorbody, according to what the PDS sent. - Publications a repo's shared read starved are re-read alone, within the existing read deadline.
Security
- A truncated subscription listing could remove a reader's access to feeds (#278, closes #203). That listing replaces the reader's whole
sub_refauthorization set.- Repeated cursor: the three subscription walks now refuse a repeated cursor on a non-empty page.
- Large drop: a page with a cursor and no records is how a real PDS ends a list, so the walk can't treat it as an error. Instead, a refresh that would drop 3 or more feeds must read the same list twice before it is applied.
- Failed second read: the reader is told the real cause.
Fixed
- Publication listing failures were all filed as
Fetch(#279, closes #227). They are now typed and mapped:- an empty body or no
recordsfield isParse; - a 2xx error envelope is
Status; - too many pages, bytes or records, or an oversized body, is
Body.
- an empty body or no
- Big siblings could starve a quiet publication in the same repo (#281, closes #229). It was latent at measured scale.
- When: a publication the shared walk cut short because it ran out of bytes is re-read alone after the group's reads are stored. The page limit, a repeated cursor and the combined cap don't trigger a re-read.
- Order: starved publications are re-read first.
- Bounds: only one budget is held at a time, and re-reads stay within the existing read deadline. A failed re-read keeps the group's outcome.
Known
- A page carrying a malformed record still charges its whole wire size to a repo's shared read budget, siblings' documents included.
- A few refusals are still filed as
Fetch(#280).