fix(omo-senpi): journal mailbox persistence - #8968
Closed
code-yeongyu wants to merge 4 commits into
Closed
code-yeongyu wants to merge 4 commits into
code-yeongyu wants to merge 4 commits into
Conversation
code-yeongyu
force-pushed
the
fix/win-ci-mailbox-caps
branch
from
September 27, 2026 14:24
eace86e to
fbe8613
Compare
code-yeongyu
marked this pull request as ready for review
September 27, 2026 15:19
code-yeongyu
force-pushed
the
fix/win-ci-mailbox-caps
branch
from
September 27, 2026 17:42
fbe8613 to
47198da
Compare
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The ordered-delivery mailbox no longer rewrites and fsyncs its complete pending queue for every accepted message. It now records durable journal updates whose enqueue cost scales with the new message, repairs torn tails, rolls back failed appends, compacts the journal with bounded snapshots, and migrates existing
mailbox.jsonstate.The Windows cap-and-restart test keeps the count, byte, overflow, FIFO, and restart contracts with injected limits, and the prior 15-second timeout override is removed.
Root cause
mailbox.tspreviously serialized the full queue and called the atomic writer on every enqueue. The failing test performed 128 count-cap writes plus five growing 200 KiB writes, so Windows filesystem latency amplified quadratic total bytes written into a 16.6849-second test timeout.There is no Windows rename retry/backoff loop in this path. The atomic writer performs one
EPERM/EACCESunlink+rename fallback;EBUSYthrows. The measured wait was repeated full-state persistence, not hidden retries.Fix
r+handle and explicit end offset.mailbox.jsonsnapshots on first open.Evidence
Persistence benchmark
Twenty trials, real mailbox path:
This shows the previous enqueue cost grew with existing queue bytes; the fixed path stays tied to the new event.
Local checks
tsgo --noEmit -p packages/omo-senpi/tsconfig.json: pass.failed_scenarios=0, two documented environment/upstream checks skipped.The extra local
test:senpiaggregate was attempted with Bun 1.4.2. Its bundle-size gate passed, but other simultaneous worktree builds on the shared host caused existing 60-second minifier tests to time out. Focused package checks above are green; PR CI is the clean-runner aggregate gate.Local evidence hashes:
Windows proof
Three independent focused
windows-latestsoaks ran the fixedmailbox.test.ts10 iterations each on final soak headc8b885b1b7(the rebased PR head plus the throwaway paths-target workflow commit):PR CI on head
fbe8613faccompleted with 23 success, 6 intentional skips, 1 neutral external reviewer, 0 failures, and 0 pending checks. The full matrix included bothwindows-latesttest shards andsenpi-compatibility (windows-latest).Risks and residuals
r+fsync behavior is the platform-specific risk and is gated by three focused Windows soaks plus PR CI.Fixes #8948
Refs #8324
Summary by cubic
Switches the ordered-delivery mailbox from rewriting and fsyncing its full pending queue on every write to appending single durable journal events, so persistence cost scales with the new message instead of the queue size. This fixes the Windows cap-and-restart test that timed out at 16.7 seconds and removes the 15-second timeout override.
mailbox.jsonsnapshots to the newmailbox.jsonljournal on first open.Written for commit 3059961. Summary will update on new commits.