Harden S3 transfer recovery and diagnostics #62

Merged
ober merged 1 commit from fix/astra-upload-recovery into main 2026-09-20 19:31:30 -04:00
Owner

What changed

Adds bounded, independently jittered retries with operation deadlines and cooperative cancellation; reports operation/phase and TLS request write context; replaces pooled TLS handles after stale I/O; refreshes DNS after repeated I/O failures; and avoids blind replay of ambiguous multipart initiation/completion requests. Ambiguous completion is reconciled by checking the exact remote object frames. Adds controlled HTTP/TLS fault fixtures, multipart/checksum integration coverage, and reproducible Linux musl cross-build targets. Bumps VERSION to 2.0.17.

Verification

  • make test — all unit, transport, real loopback TLS, and TLS fault fixture checks pass.
  • make clean && make && make binary && make binary-smoke — pass; installed-layout smoke ran with loader overrides removed. Packaged executable reports 2.0.17.
  • make linux-amd64, make linux-arm64, make freebsd-amd64 — pass.
  • Live HTTPS S3 integration with isolated prefix and 1 MiB test frames — checksum verification, multipart round-trip, multi-chunk/range downloads, copy, and move pass; test prefix was removed.
  • jerboa_check_balance, git diff --check, and changed-line security scan — pass.

A live S3 run using the default ~100 MiB multi-chunk stream received an HTTP response advertising a 16 MiB range but closing after about 12.8 MiB; the bounded GET retries exhausted. The 1 MiB-frame multi-chunk/multipart live run passed. This larger-response behavior is recorded as an unresolved object-store/transport limitation rather than claimed as verified.

## What changed Adds bounded, independently jittered retries with operation deadlines and cooperative cancellation; reports operation/phase and TLS request write context; replaces pooled TLS handles after stale I/O; refreshes DNS after repeated I/O failures; and avoids blind replay of ambiguous multipart initiation/completion requests. Ambiguous completion is reconciled by checking the exact remote object frames. Adds controlled HTTP/TLS fault fixtures, multipart/checksum integration coverage, and reproducible Linux musl cross-build targets. Bumps VERSION to 2.0.17. ## Verification - `make test` — all unit, transport, real loopback TLS, and TLS fault fixture checks pass. - `make clean && make && make binary && make binary-smoke` — pass; installed-layout smoke ran with loader overrides removed. Packaged executable reports `2.0.17`. - `make linux-amd64`, `make linux-arm64`, `make freebsd-amd64` — pass. - Live HTTPS S3 integration with isolated prefix and 1 MiB test frames — checksum verification, multipart round-trip, multi-chunk/range downloads, copy, and move pass; test prefix was removed. - `jerboa_check_balance`, `git diff --check`, and changed-line security scan — pass. A live S3 run using the default ~100 MiB multi-chunk stream received an HTTP response advertising a 16 MiB range but closing after about 12.8 MiB; the bounded GET retries exhausted. The 1 MiB-frame multi-chunk/multipart live run passed. This larger-response behavior is recorded as an unresolved object-store/transport limitation rather than claimed as verified.
Harden S3 transfer recovery and diagnostics
All checks were successful
version-policy / required (pull_request) Successful in 3m42s
required-ci / required (pull_request) Successful in 4m41s
71ec1e1760
ober scheduled this pull request to auto merge when all checks succeed 2026-09-20 19:31:05 -04:00
ober merged commit 39846dc053 into main 2026-09-20 19:31:30 -04:00
ober referenced this pull request from a commit 2026-09-20 19:31:32 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-drive!62
No description provided.