mirror of
https://tangled.org/evan.jarrett.net/at-container-registry
synced 2026-09-29 05:25:35 +00:00
appview: read the sailor profile from the local users row, not the PDS, per request
Hold discovery in the registry middleware called getRecord on the repository owner's PDS for every request under /v2/: every HEAD, POST, PATCH, PUT and GET. A 10-layer push was 40 or more PDS round trips, and it was the last per-request network call on the push path that had nothing to do with moving bytes. Only two profile fields are used there: the default hold and the auto-remove-untagged flag. The users row already caches the default hold, written by the Jetstream processor on every profile event and prefilled by the backfill, and the auth gate already reads it from there. This makes the row a faithful copy of what the registry needs and switches the middleware to it. The auto-remove flag gets a nullable users column. NULL means the value has never been learned; the processor writes 0 or 1 on every profile event and never NULL. On a request whose row is missing or still NULL, the middleware does one live fetch, uses it, and writes both fields back, including a 0 for a user with no profile at all, so the fallback runs at most once per user. A failed fetch writes nothing and uses the appview default for that request, so a network error is never cached. That single mechanism covers the minutes after a deploy while the startup backfill fills the column, a brand-new user, and a user the backfill has not reached. The processor also stops returning early on an empty default hold, which left a user who removed their custom hold pushing to it forever. Empty is now written through and means the appview default, matching what the auth gate already reads. Tests count PDS requests with a test server: a populated row makes none, a NULL row makes exactly one and then none, a missing profile is cached as known, and a failed fetch degrades without writing. The migration was applied to a fresh database and to one built from the previous schema. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018Yf1ZVA7sXYhQNb9tCo1m5
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
47a107058d
commit
7045e84c00
@@ -573,9 +573,12 @@ func (p *Processor) ProcessSailorProfile(ctx context.Context, did string, record
|
||||
slog.Warn("Failed to cache registry domain preference", "component", "processor", "did", did, "registryDomain", profileRecord.RegistryDomain, "error", err)
|
||||
}
|
||||
|
||||
// Skip hold processing if no default hold set
|
||||
if profileRecord.DefaultHold == "" {
|
||||
return nil
|
||||
// Cache the untagged-cleanup preference. A processed profile is always a
|
||||
// known value, so this writes 0 or 1 and never leaves the column NULL. NULL
|
||||
// means "never learned", which is what makes the registry middleware fetch
|
||||
// the profile live once; writing here is what stops it doing so again.
|
||||
if err := db.UpdateUserAutoRemoveUntagged(p.db, did, profileRecord.AutoRemoveUntagged); err != nil {
|
||||
slog.Warn("Failed to cache autoRemoveUntagged preference", "component", "processor", "did", did, "autoRemoveUntagged", profileRecord.AutoRemoveUntagged, "error", err)
|
||||
}
|
||||
|
||||
// Convert hold URL/DID to canonical DID. On failure, cache the raw reference
|
||||
@@ -584,11 +587,22 @@ func (p *Processor) ProcessSailorProfile(ctx context.Context, did string, record
|
||||
// unresolvable must not fall through to managed. A managed hold's DID never
|
||||
// fails resolution (DIDs return as-is), so only unreachable URL-form refs land
|
||||
// here, and a raw non-DID value correctly reads as non-managed (fail closed).
|
||||
holdDID, err := atproto.ResolveHoldDID(ctx, profileRecord.DefaultHold)
|
||||
if err != nil {
|
||||
slog.Warn("Invalid hold reference in profile; caching raw value (fails closed for billing)",
|
||||
"component", "processor", "did", did, "default_hold", profileRecord.DefaultHold, "error", err)
|
||||
holdDID = profileRecord.DefaultHold
|
||||
//
|
||||
// An empty defaultHold is not resolved, it is written straight through. The
|
||||
// user cleared their custom hold, and "" is exactly how both the billing gate
|
||||
// and the auth gate's resolveHoldDID spell "fall back to the operator
|
||||
// default". Returning early here instead, as this used to, left the old value
|
||||
// in the row forever, so a user who moved back to the managed hold kept being
|
||||
// routed to a hold they had abandoned.
|
||||
holdDID := ""
|
||||
if profileRecord.DefaultHold != "" {
|
||||
resolved, err := atproto.ResolveHoldDID(ctx, profileRecord.DefaultHold)
|
||||
if err != nil {
|
||||
slog.Warn("Invalid hold reference in profile; caching raw value (fails closed for billing)",
|
||||
"component", "processor", "did", did, "default_hold", profileRecord.DefaultHold, "error", err)
|
||||
resolved = profileRecord.DefaultHold
|
||||
}
|
||||
holdDID = resolved
|
||||
}
|
||||
|
||||
// Cache default hold DID on the user record
|
||||
@@ -598,7 +612,8 @@ func (p *Processor) ProcessSailorProfile(ctx context.Context, did string, record
|
||||
|
||||
// Query and cache the captain record using provided function
|
||||
// This allows backfill-specific logic (retries, test mode handling) without duplicating it here
|
||||
if queryCaptainFn != nil {
|
||||
// There is nothing to query when the user has no hold of their own.
|
||||
if queryCaptainFn != nil && holdDID != "" {
|
||||
return queryCaptainFn(ctx, holdDID)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user