fix(federation): Make transactions infallible #2137

Merged
nex merged 3 commits from nex/fix/txn-safety into main 2026-08-15 16:10:39 +00:00
Owner

Previously, a transaction panicking in the handle() call would cause the transaction to be indefinitely logged as "running" in the transaction handler. This means subsequent transactions from the sending server would be met with the "You're still sending me a txn!" 429 response, forever, effectively causing defederation between the two servers, until continuwuity is fully restarted.

I could just fix the known panics in the handle function and internal calls, however there's so many subsystems that could reasonably panic that it is just better to have a safer approach and ensure that the handle call is infallible.

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
Previously, a transaction panicking in the handle() call would cause the transaction to be indefinitely logged as "running" in the transaction handler. This means subsequent transactions from the sending server would be met with the "You're still sending me a txn!" 429 response, forever, effectively causing defederation between the two servers, until continuwuity is fully restarted. I could just fix the known panics in the handle function and internal calls, however there's so many subsystems that could reasonably panic that it is just better to have a safer approach and ensure that the handle call is infallible. <!-- Closes: #... --> <!-- Fixes: #... --> <!-- Uncomment the above line(s) if your pull request fixes an issue or closes another pull request by superseding it. Replace `#...` with the issue/pr number, such as `#123`. --> **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [ ] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages
nex added this to the 26.8.0 milestone 2026-08-15 14:56:19 +00:00
fix(federation): Make transactions infallible
Some checks failed
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 3s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m3s
Checks / Changelog / Check changelog is added (pull_request_target) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
cdb5e11a22
Previously, a transaction panicking in the handle() call would cause the
transaction to be indefinitely logged as "running" in the transaction
handler. This means subsequent transactions from the sending server
would be met with the "You're still sending me a txn!" 429 response,
forever, effectively causing defederation between the two servers, until
continuwuity is fully restarted.

I could just fix the known panics in the handle function and internal
calls, however there's so many subsystems that could reasonably panic
that it is just better to have a safer approach and ensure that the
handle call is infallible.
chore: Add newsfrag
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m3s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 55s
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m12s
c07eef0514
nex requested review from Owners 2026-08-15 14:58:06 +00:00
ginger approved these changes 2026-08-15 15:55:54 +00:00
ginger left a comment

jorp

jorp
@ -38,3 +39,4 @@
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
match self {
| Self::ShuttingDown => write!(f, "Server is shutting down"),
| Self::Unexpected => write!(f, "Fatal Internal Server Error"),
Owner

mystery title case...?

mystery title case...?
nex marked this conversation as resolved
eleboucher approved these changes 2026-08-15 15:57:15 +00:00
Aranjedeath approved these changes 2026-08-15 16:05:31 +00:00
Dismissed
style: Rephrase error message
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 7s
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m2s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 55s
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 9m42s
fa5e771c52
nex merged commit a148174c59 into main 2026-08-15 16:10:39 +00:00
nex deleted branch nex/fix/txn-safety 2026-08-15 16:10:39 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
4 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!2137
No description provided.