Skip to content

Fix PUT read-state monotonicity guard - #431

Merged
TheGreatAxios merged 5 commits into
mainfrom
cl-7131-put-read-state-has-no-monotonicity-guard-an-out-of-order
Aug 29, 2026
Merged

TheGreatAxios merged 5 commits into
mainfrom
cl-7131-put-read-state-has-no-monotonicity-guard-an-out-of-order

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Fixes CL-7131 — https://linear.app/abklabs/issue/CL-7131

Problem

putReadState (packages/chat/src/store.ts:303-323) unconditionally
set lastSeenCreatedAt/lastSeenId to whatever
PUT /workbenches/:id/read-state (packages/chat/src/routes.ts:3498-3540)
carried, via an unconditional onConflictDoUpdate. A slower "read up
to X" request landing after a faster "read up to Y" request regressed
the stored cursor, flipping messages X..Y back to unread for that
reader. The in-memory store (packages/chat/src/store.ts:461) had the
same bug.

Change

  • Drizzle store: putReadState's onConflictDoUpdate now sets both
    columns via a CASE WHEN excluded.last_seen_created_at >= workbench_read_state.last_seen_created_at THEN excluded... ELSE workbench_read_state... END, so a strictly older write is a no-op
    that returns the still-current row, while an equal-timestamp write
    still lands.
  • In-memory store: same rule, expressed as a plain comparison against
    the existing row before overwriting.
  • The >= (not strict >) matters because workbench_messages.created_at
    has millisecond precision and same-millisecond messages are expected
    — a legitimate forward move to a later same-millisecond message must
    not be dropped as a no-op.
  • The route was left unchanged — it already just echoes back whatever
    row putReadState returns, so a no-op write now correctly reports
    the still-current cursor with a normal 200.

Tests

  • packages/chat/test/store.test.ts: in-memory cases for (a) a stale
    write landing after a newer one is a no-op, and (b) a same-millisecond
    forward move to a different message still lands. Both verified red
    against the old code, green after the fix.
  • packages/chat/test/read-state.drizzle.test.ts: new DB-gated suite
    (skipped without DATABASE_URL, mirrors the existing
    *.drizzle.test.ts pattern) proving the same three cases against the
    real Postgres upsert. Ran locally against a local Postgres with both
    red and green results for each case.

Covers the in-memory store (a stale write landing after a newer one
must not move the cursor back) and a real-Postgres drizzle test
proving the same for createDrizzleChatStore's SQL upsert.
A slower "read up to X" write landing after a faster "read up to Y"
regressed the stored cursor and flipped X..Y back to unread. Both
store implementations now keep the later lastSeenCreatedAt on
conflict — a conditional CASE WHEN in the Drizzle upsert, and an
equivalent comparison in the in-memory store.

Fixes CL-7131.
workbench_messages.created_at has millisecond precision and
same-millisecond messages are expected, so the monotonicity guard
must accept an equal-timestamp write, not just a strictly later one.
Covers the in-memory store and the drizzle-backed store.
The guard used a strict > comparison, so a same-millisecond write to
a later message in the same batch was dropped as a no-op and the
route echoed back the older cursor. Only a strictly older timestamp
is a no-op now; an equal timestamp lands the incoming write.
@TheGreatAxios
TheGreatAxios force-pushed the cl-7131-put-read-state-has-no-monotonicity-guard-an-out-of-order branch from 99421ea to 46bb2f7 Compare August 29, 2026 04:46

@TheGreatAxios TheGreatAxios left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critique · comment

Read-state GET and PATCH report through reportError and return { error, refId }.

  • packages/chat/src/read-state-routes.ts:89-97 and :146-157 — the 500 JSON includes refId. Tests cover the GET and PATCH reportError calls.

Walking-skeleton red on this PR is main deleting DATABASE_URL after memory-mount tests (CL-7182 / #465), not this diff.

@TheGreatAxios
TheGreatAxios merged commit bfaefe3 into main Aug 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant