You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit c149aa5
Browse filesBrowse the repository at this point in the historyBrowse files
fix: bound POST uploads and reduce cleanup overhead (flop-labs#731)
## What
POST uploads expire after 10 seconds with 408 and a closed connection.
Conditional writes to missing notes refuse before creating note lock
files or namespace directories, including when cleanup expires the
target during the request. Full-store sweeps run at most every 10
minutes instead of 5.
## Why
Reduce the cost of stalled uploads, rejected writes, and repeated
cleanup without new dependencies. Retention ages stay unchanged; cleanup
and count repair may wait five extra minutes during ongoing writes.
Verified against main at `91a28151656a86c2583491512b6cbd87466c5613`.
Limiter locking is left to the existing flop-labs#618 to avoid duplicating its
fix.
## Checks
- [x] `uv sync --frozen`
- [x] `uv run coverage run -m pytest tests -q && uv run coverage report`
— 741 passed, 1 skipped; 97.96% coverage
- [x] Ruff lint/format and `uv run ty check`
- [x] Chromium `/humans` probe
- [x] Core-size baseline and caps: 2,314 code lines against 2,316
- [x] GET/POST regressions reproduce expired-note CAS lock recreation
before the fix and pass afterward
- [x] Manual, OpenAPI, and deployment guidance updated
- [x] New public surface: no new endpoint; existing POSTs gain a bounded
408 refusal
One initial full-suite run hit the existing duplicate-filter test's
broad `"429" not in response.text` assertion because its trace ID
contained those digits. The focused retry and full rerun passed.
"that does not verify is refused rather than downgraded. "
625
625
"The body names the lane that would work."
626
626
),
627
+
"408": _plain(
628
+
"The JSON body did not finish before the total upload deadline. "
629
+
"The response states the deadline and closes the connection; retry on a new connection."
630
+
),
627
631
"413": _plain(
628
632
f"Body over {max_body_bytes//1024} KiB. The body repeats the cap in bytes and says which of the two checks caught it — the declared Content-Length, or the stream passing it."
"403": _plain("The body names where to post instead."),
807
+
"408": _plain(
808
+
"The JSON body did not finish before the total upload deadline. "
809
+
"The response states the deadline and closes the connection; retry on a new connection."
810
+
),
803
811
"413": _plain(
804
812
f"Body over {max_body_bytes//1024} KiB. The body repeats the cap in bytes and says which of the two checks caught it — the declared Content-Length, or the stream passing it."
"actually there, so a loser can rebase without a second "
996
1004
"round trip."
997
1005
),
1006
+
"408": _plain(
1007
+
"The JSON body did not finish before the total upload deadline. "
1008
+
"The response states the deadline and closes the connection; retry on a new connection."
1009
+
),
998
1010
"413": _plain(
999
1011
f"Body over {max_body_bytes//1024} KiB. The body repeats the cap in bytes and says which of the two checks caught it — the declared Content-Length, or the stream passing it."
0 commit comments