fix(v2): reject stale identity snapshots after completed mutations - #888
Merged
Merged
Conversation
camy-x
marked this pull request as ready for review
September 29, 2026 06:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
An in-flight passive inventory can overwrite a completed API-key rotation/deletion or credential deletion after its pending intent is removed. Reproduced on
v2atf5d12c6ca4af1f36f087e8acd28e565c5a0ae655: the old source gets a new local identity, and a rotated identity becomesmissing.Capture the existing source-binding revision before fetching inventory and check it inside the reconciliation writer transaction. A conflicting snapshot is discarded; the next fresh capture reconciles normally.
Scope
Changes
User Impact
Prevents obsolete inventory responses from recreating retired local identities or temporarily marking a successfully rotated identity missing. The bug affects Manager identity records; it does not restore deleted keys or files in CPA.
Compatibility / Runtime Notes
Data / Security Notes
Reuses
gateway_source_binding_revision; no database migration, raw usage mutation, or new secret storage. Revision validation and snapshot writes share the existing SQLite immediate transaction. The counter is global, so an unrelated binding change may conservatively invalidate the whole capture. Locally constructed repository snapshots retain the existing optional-fence behavior; the remote reconciliation service always sets it, including revision zero.Risk / Rollback
Risk level: Low
Rollback notes: revert this change; no persisted schema change. Under frequent binding changes, passive synchronization may wait for a capture with a stable revision.
Verification
On WSL Ubuntu/Linux amd64 with Go 1.24.0,
GOFLAGS=-mod=readonly. Manager SQLite temporary files were placed in tmpfs; these results are not disk durability or performance claims.All passed. The behavioral regression cases fail against the original
v2source (rotation, API-key delete, credential delete) and pass with this change. Existing helper/opt-in baseline skips remain. Docker E2E, real CPA integration, and native Windows/macOS tests were not run. No frontend changes.Screenshots / Recordings
N/A — backend identity reconciliation only.
Docs
Docs decision: internal correctness fix; no new user-facing operation or configuration. The storage port and reconciliation sequence document the new precondition.
Related
V2 Phase 3 passive identity reconciliation and mutation-intent recovery. No linked issue.