Repository navigation
fix(worker): clean unpublished downloads after restart - #131
jerelvelarde merged 1 commit into
Conversation
|
Reviewed head High-value download recovery fix. The patch removes unpublished bytes before marking the journal failed, retains pending journals when cleanup cannot finish, and preserves published PDFs and ordinary reads of active transfers. The added real-filesystem cases cover partial cleanup retry, metadata errors, missing files and repeated recovery; no blocking security or template-fit issue found in the diff. Prioritize the controlled fixtures in #127, then recheck the browser suite with this recovery patch. The current workflow is |
jerelvelarde
left a comment
There was a problem hiding this comment.
Useful bounded recovery fix: removes unpublished PDF/temp metadata before marking interrupted downloads failed, preserves published files, and propagates inspection errors without losing retry state. Template documents actual checks/limits. All 24 browser/API tests pass locally, including real filesystem error/retry regressions. No actionable correctness or security findings.
What changed
If the worker exits while copying a PDF, restart recovery changes its pending transfer journal to failed but leaves the unpublished PDF on disk. A metadata write interrupted before rename can also leave a
.json.tmpfile.Reuse the existing recovery path to remove both files before persisting the failure. Only
ENOENTmeans metadata is absent; other inspection or cleanup errors propagate and leave the journal pending for retry. Published downloads retain their PDF and metadata, and ordinary failure-list reads leave active transfers alone. Previously failed historical records are outside this change.Add real-filesystem regressions for cleanup, failure preservation, published downloads, missing files, repeated recovery, metadata inspection errors, and partial cleanup retry. Extend the existing worker startup/API test to verify orphan removal.
Verification
pnpm lint,pnpm typecheck,pnpm --dir apps/worker typecheck, andpnpm build:serverpassed.pnpm test: 282/282 passed, no skips.--max-workers 2.Integration limits
pnpm test:browserfails locally before download recovery: httpbin URL validation returnsBLOCKED_URLwhere the test expectsNAVIGATION_FAILED. The same failure was reproduced on the unmodified baseline. Chromium installation succeeded.