You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Atomically clamp overlay and write watermark in a single transaction
The overlay_ref scan and truncated_before watermark write were in
separate transactions, leaving a TOCTOU window: a fork created between
the clamping scan and watermark write could have snapshot_version <
before_version and slip through both checks.
Fix: combine them into a single FDB transaction. The overlay_ref range
is read with snapshot=false (adding it to the conflict set), clamping
is applied, and the watermark is written — all atomically. A concurrent
create_namespace that writes an overlay_ref entry causes a conflict and
retry, which sees the new child. After the transaction commits, the
watermark rejects any later forks at truncated versions.
This eliminates min_overlay_snapshot_version as a separate method — its
logic is inlined into the combined transaction.
Also bump all crates to v0.3.14.