fix: Ensure backfilled events cannot become forward extremities #2119

Merged
nex merged 1 commit from eleboucher/continuwuity:fix/late-events-as-forward-extremities into main 2026-08-18 20:22:21 +00:00
Contributor

Events arriving after a child of theirs has already been backfilled are no longer installed as forward extremities. Backfilled events now mark their prev_events as referenced, and a backfilled event that nothing references can itself act as a forward extremity, so the branch it sits on stays reachable. Also corrected an inverted debug assertion in get_missing_events that made debug builds panic when an incoming event had none of its prev_events locally.

Fixes: #2115

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
<!-- In order to help reviewers know what your pull request does at a glance, you should ensure that 1. Your PR title is a short, single sentence describing what you changed 2. You have described in more detail what you have changed, why you have changed it, what the intended effect is, and why you think this will be beneficial to the project. If you have made any potentially strange/questionable design choices, but didn't feel they'd benefit from code comments, please don't mention them here - after opening your pull request, go to "files changed", and click on the "+" symbol in the line number gutter, and attach comments to the lines that you think would benefit from some clarification. --> Events arriving after a child of theirs has already been backfilled are no longer installed as forward extremities. Backfilled events now mark their prev_events as referenced, and a backfilled event that nothing references can itself act as a forward extremity, so the branch it sits on stays reachable. Also corrected an inverted debug assertion in `get_missing_events` that made debug builds panic when an incoming event had none of its prev_events locally. <!-- Example: This pull request allows us to warp through time and space ten times faster than before by double-inverting the warp drive with hyperheated jump fluid, both making the drive faster and more efficient. This resolves the common issue where we have to wait more than 10 milliseconds to engage, use, and disengage the warp drive when travelling between galaxies. --> <!-- Closes: #... --> Fixes: #2115 <!-- Uncomment the above line(s) if your pull request fixes an issue or closes another pull request by superseding it. Replace `#...` with the issue/pr number, such as `#123`. --> **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [x] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages
fix: Do not make late-arriving events forward extremities
All checks were successful
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 3s
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m12s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m12s
7e1c8e74aa
eleboucher force-pushed fix/late-events-as-forward-extremities from 7e1c8e74aa
All checks were successful
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 3s
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m12s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m12s
to c1d0fbbe64
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m13s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m24s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m11s
Checks / Changelog / Check changelog is added (pull_request_target) Has been cancelled
2026-08-08 13:02:16 +00:00
Compare
nex changed title from fix: Do not make late-arriving events forward extremities to fix: Ensure backfilled events cannot become forward extremities 2026-08-11 14:04:02 +00:00
eleboucher force-pushed fix/late-events-as-forward-extremities from c1d0fbbe64
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m13s
Update flake hashes / update-flake-hashes (pull_request) Successful in 1m24s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m11s
Checks / Changelog / Check changelog is added (pull_request_target) Has been cancelled
to f98f4ea8d7
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m11s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m23s
2026-08-11 14:04:18 +00:00
Compare
nex requested changes 2026-08-11 14:09:34 +00:00
Dismissed
@ -198,0 +202,4 @@
.pdu_metadata
.is_event_referenced(&incoming_pdu.room_id_or_hash(), incoming_pdu.event_id())
.await;
if !has_child || forward_extremities.is_empty() {
Owner

I'm icky about this being possible in the first place, but i guess it's not a terrible idea to have a break-glass workaround

I'm icky about this being possible in the first place, but i guess it's not a terrible idea to have a break-glass workaround
nex marked this conversation as resolved
@ -216,0 +220,4 @@
.mark_as_referenced(&room_id, pdu.prev_events().map(AsRef::as_ref));
// If nothing references this event, it is a leaf, so it belongs in the forward
// extremities.
Owner

There's never a situation in which a backfilled event is legally supposed to become a forward extremity as far as I'm aware - the server only starts tracking extremities after it finishes joining a room, at which point the membership event is the only extremity it cares about. Other servers should deal with unreferenced forks post factum if said forks aren't already convened by the join event itself

There's never a situation in which a backfilled event is legally supposed to become a forward extremity as far as I'm aware - the server only starts tracking extremities after it finishes joining a room, at which point the membership event is the only extremity it cares about. Other servers should deal with unreferenced forks post factum if said forks aren't already convened by the join event itself
Owner

Furthermore, we're expected to be able to serve state at for events we reference in prev events, which we cannot do for backfilled events yet (I'm working on this), so this might also potentially cause our subsequent events to be proactively dropped

Furthermore, we're expected to be able to serve state at for events we reference in prev events, which we cannot do for backfilled events yet (I'm working on this), so this might also potentially cause our subsequent events to be proactively dropped
eleboucher marked this conversation as resolved
eleboucher force-pushed fix/late-events-as-forward-extremities from f98f4ea8d7
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m11s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m23s
to c96f22da3f
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m10s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m16s
2026-08-11 14:27:27 +00:00
Compare
@ -158,2 +157,3 @@
} else {
i
} else {
i.expected_add(1)
Owner

idk anything about rust but these are usually saturating ? should this be expected ?

idk anything about rust but these are usually saturating ? should this be expected ?
Owner

An expected add is fine because the value will never overflow (u8 can store up to 255, but there can only be 20 prev events, effectively clamping the max value at 20)

An expected add is fine because the value will never overflow (u8 can store up to 255, but there can only be 20 prev events, effectively clamping the max value at 20)
Aranjedeath marked this conversation as resolved
eleboucher requested review from nex 2026-08-17 06:51:20 +00:00
eleboucher force-pushed fix/late-events-as-forward-extremities from c96f22da3f
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m10s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m16s
to 5dc46bf7d7
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m14s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m15s
2026-08-17 06:51:24 +00:00
Compare
eleboucher force-pushed fix/late-events-as-forward-extremities from 5dc46bf7d7
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m14s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m15s
to 0336850dc8
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Has been cancelled
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2026-08-18 16:55:24 +00:00
Compare
eleboucher force-pushed fix/late-events-as-forward-extremities from 0336850dc8
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Has been cancelled
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 3efb66c76c
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m18s
Checks / Prek / Check changed files (pull_request) Successful in 10s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m54s
Checks / Prek / Check changed files (push) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (push) Has been cancelled
Release Docker Image / Build linux-amd64 (release) (push) Has been cancelled
Release Docker Image / Build linux-arm64 (release) (push) Has been cancelled
Release Docker Image / Create Multi-arch Release Manifest (push) Has been cancelled
Release Docker Image / Build linux-amd64 (max-perf) (push) Has been cancelled
Release Docker Image / Build linux-arm64 (max-perf) (push) Has been cancelled
Release Docker Image / Create Max-Perf Manifest (push) Has been cancelled
Release Docker Image / Release Binaries (push) Has been cancelled
Release Docker Image / Mirror Images (push) Has been cancelled
Documentation / Build and Deploy Documentation (push) Has been cancelled
Checks / Prek / Pre-commit & Formatting (push) Has been cancelled
2026-08-18 16:55:49 +00:00
Compare
nex approved these changes 2026-08-18 20:22:17 +00:00
nex merged commit 3efb66c76c into main 2026-08-18 20:22:21 +00:00
nex deleted branch fix/late-events-as-forward-extremities 2026-08-18 20:22:21 +00:00
nex added this to the 26.8.0 milestone 2026-08-20 01:01:07 +00:00
Sign in to join this conversation.
No reviewers
nex
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!2119
No description provided.