Lewis
6ca6c45605
identity: Handle type for stored handles & extract_handle
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
d238affd76
repo: newtype commit cid & rev to CidLink & Tid
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
469255f5a9
db: newtype PasswordHash for users & app passwords
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
8559764d31
auth: newtype jti claims, sessions, & store
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
a405d523ca
oauth: newtype client, token, device & request ids
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 00:25:08 +03:00
Lewis
3c46e5fc73
lexicon: Nsid instead of strs for collections
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 00:21:32 +03:00
Lewis
f330dcd366
types: did, nsid, & rkey in AtUri::from_parts
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-11 16:14:56 +03:00
Lewis
aab1a945c2
session: deletes scope to did, route muts by did
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-28 09:55:11 +03:00
ave and Tangled
9dc184ee33
bsky(auth): add grace period to legacy session refresh
...
Concurrent or retried com.atproto.server.refreshSession calls presenting the
same refresh token hit the reuse-detection path, which deleted the session and
returned "Refresh token has been revoked due to suspected compromise" —
logging users out at random. The legacy flow had no grace period, unlike OAuth.
Mirror the reference atproto PDS: every rotated refresh token gets a 2h grace
window measured from its own rotation time (used_refresh_tokens.used_at in
postgres; a rotated_at_ms field appended to the metastore used-marker, with
old-format markers decoding as outside the window). A refresh presenting a
recently-rotated token is served the session's current tokens, re-minted on
the fly with the same jti/expiry — signed JWTs are never persisted. Reuse
outside the window still revokes the session.
The grace lookup returns the session's encrypted signing key so the handler
verifies the presented token's signature before minting replacement tokens or
revoking a session; a forged token bearing a known jti gets a generic
rejection with no side effects.
Integration tests asserting the old replay-gets-401 behavior are reworked to
the new contract and now also cover forged-signature replays and
out-of-window revocation.
2026-06-27 23:54:22 +03:00
Lewis
ab4eba6dc4
delegation: preset scopes grant identity & account
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-27 23:11:24 +03:00
Lewis and Tangled
39a2e40b35
invite codes: dedup consumption, iron out kinks
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-26 13:28:49 +03:00
Lewis and Tangled
b009ccdaf2
repo: the pg side of MST structural repair
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-08 16:58:51 +03:00
Lewis and Tangled
37fc06fb39
fix(store): unblock eventlog sync&freeze when writer dies
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-02 17:29:21 +03:00
Lewis and Tangled
3d49e99cc3
test(store): generic consistency checker, gauntlet fault/read
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-02 17:29:21 +03:00
Lewis
a220611a8b
test(store): D gauntlet faults, crash-loss oracley, recoverable scenarios
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:01:04 +03:00
Lewis
ca7a4b4b73
fix(store): recover eventlog lastseq from tail not sidecar
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:01:04 +03:00
Lewis
8ff02610e4
feat(store): inline-commit mode, committed-extent recovery, failsafe verify&rollback
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:01:04 +03:00
Lewis and Tangled
7f8e858137
test(store): gauntlet MST-repairable & misdirected-write scenario
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis and Tangled
44d73dac58
feat(store): rebuild & rewrite missing/corrupt MST blocks
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis and Tangled
b8cae15c12
feat(store): detect foreign&corrupt blocks on read & preserve blocks thru recovery
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis
31ee12ecd3
fix(store): torn hint-file tail should be recoverable on reopen
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 11:37:21 +03:00
Lewis
4015217a2e
feat(store): Clock trait for DST
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-30 23:46:22 +03:00
Lewis and Tangled
e9dc57d6f4
fix(firehose): lost events if seq commits out of order
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-30 21:10:38 +03:00
Lewis and Tangled
4d2c7d4723
feat(auth): verification-gate override, inbound-migration bypass, store deleter improvement
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-23 23:02:43 +03:00
Lewis
1815ddba9f
feat(gauntlet): index-backed/hint-backed/readable invariants, ExternalCorruption scenario
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 12:32:05 +03:00
Lewis
a7517ed5c9
feat(store): consistency check & repair for orphan hints etc
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 11:50:32 +03:00
Lewis
d07d702dd4
feat(store): try to self-heal phantom index entries on compaction
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 11:50:19 +03:00
Lewis and Tangled
fac9520a16
feat(tranquil-server): email config, tests, fmt
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-02 22:28:59 +03:00
Lewis and Tangled
eee6fb9ff4
feat(comms): EmailSender, permanent/transient routing
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-02 22:28:59 +03:00
Lewis
9b2cfb3a7e
fix(tranquil-store): durable-tail recovery + sync semantics
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-30 11:11:28 +03:00
Lewis
efd499bb26
fix(tranquil-store): barrier durability + torn-header recovery
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-29 15:35:42 +03:00
Lewis and Tangled
180de29984
fix(tranquil-pds): firehose car carries inductive proof
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-26 20:11:27 +03:00
Lewis
d436597184
feat(tranquil-store): flaky-device scenario, jemalloc heap-prof
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-24 10:50:08 +03:00
Lewis
4cfca6d956
feat(tranquil-store): soak harness driving leak gate, signal tweaks
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-23 08:39:16 +03:00
Lewis
98b94fb170
feat(tranquil-store): leak gate and metrics sampling for gauntlet
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-22 21:00:17 +03:00
Lewis
4fe01cff72
feat(tranquil-store): sweep subcommand with axis override fan-out
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-22 17:23:15 +03:00
Lewis
00c9eb732f
fix(tranquil-store): arc-counted cache handles, reader-eviction race
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-21 22:04:24 +03:00
Lewis
6d2d3b4be4
fix(tranquil-store): commit-marker batch replay, batch-boundary rotation
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-21 14:55:15 +03:00
Lewis
9d81e58803
fix(tranquil-store): no more orphan data files, recover torn-hint tails, header-safe resume
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-21 09:59:37 +03:00
Lewis
2afd075496
fix(tranquil-store): atomic record commits, hint-as-truth recovery
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-20 21:00:54 +03:00
Lewis
1285d5c675
fix(tranquil-store): bound writer fd usage across rotations
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-20 16:50:19 +03:00
Lewis
c30d73cd4d
test(tranquil-store): migrate some tests to gauntlet
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-19 23:50:27 +03:00
Lewis
0fab8f2eb9
feat(tranquil-store): tranquil-gauntlet CLI, config overrides, profiles
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-19 23:50:27 +03:00
Lewis
57336fa124
feat(tranquil-store/gauntlet): new invariants & scenarios
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-19 10:25:07 +03:00
Lewis
ace105899f
feat(tranquil-store/gauntlet): concurrent executor, eventlog, fault recovery
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-19 00:19:08 +03:00
Lewis
c80a525e0d
feat(tranquil-store/gauntlet): op surface, oracle, workload for eventlog & reads
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-18 10:36:30 +03:00
Lewis
7edb76507b
feat(tranquil-store/gauntlet): simulated io fault modes, shrinker, regression dump
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-18 10:36:30 +03:00
Lewis
09d437b3e3
feat(tranquil-store): gauntlet persistence & restart invariants
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-15 22:28:31 +03:00
Lewis
7f2e83e92f
feat(tranquil-store): beginnings of the gauntlet test suite
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-15 20:29:34 +03:00
Lewis
d51bfd59da
fix(tranquil-store): exclude 0 refcount blocks from has()
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-14 08:40:21 +03:00