fix(high-severity): close 9 of 10 open High findings across 8 modules
Comm-016: delete dead HandleConnectionStateChanged + _debugSubscriptions / _inProgressDeployments tracking + ConnectionStateChanged message record. Disconnect detection is owned by the transport layers (gRPC keepalive PING ~25s; Ask-timeout at CommunicationService). Updates the Component-Communication.md design doc to make that explicit. SnF-018: NotificationForwarder.DeliverAsync now discards a corrupt buffered payload (Warning log + return true) instead of returning false and parking the row — honoring the design's "notifications do not park" invariant. DM-018: reconciliation no longer force-sets Enabled, preserving an intentional Disabled state after central failover. ESG-018: DeliverBufferedAsync (both ExternalSystemClient + DatabaseGateway) catches JsonException and returns false, turning a corrupt buffered row into a parked operation instead of a retry-forever poison message. InboundAPI-022: register ActiveNodeGate as IActiveNodeGate in the Central DI branch so standby-node gating is actually wired up in production. NS-019: remove orphaned NotificationDeliveryService / INotificationDeliveryService / NotificationResult; central notification delivery now lives entirely in NotificationOutbox. SEL-016: normalise From/To filters to UTC before ISO-string compare so non-UTC DateTimeOffset clients no longer get spuriously excluded events. TE-017: include Description on attributes/alarms and a HashableConnections projection (protocol, endpoint JSON, failover count) in the revision hash and DiffService; staleness detection now catches description-only and connection-endpoint edits. Transport-001 and Transport-002 (also High) remain Open — they're being handled in a follow-up batch because both touch BundleImporter.cs and must serialise.
This commit is contained in:
@@ -774,9 +774,25 @@ than being masked by an endpoint-agnostic mock.
|
||||
|--|--|
|
||||
| Severity | High |
|
||||
| Category | Design-document adherence |
|
||||
| Status | Open |
|
||||
| Status | Resolved |
|
||||
| Location | `src/ScadaLink.Communication/Actors/CentralCommunicationActor.cs:169`, `src/ScadaLink.Communication/Actors/CentralCommunicationActor.cs:338-375` |
|
||||
|
||||
**Resolution** — deleted the dead code path in favour of the keepalive-based
|
||||
detection that is the actual production behaviour: removed the
|
||||
`Receive<ConnectionStateChanged>` handler, the `HandleConnectionStateChanged`
|
||||
method, the `_debugSubscriptions` / `_inProgressDeployments` tracking dicts
|
||||
+ the `TrackMessageForCleanup` helper that fed them, and the dead message
|
||||
record `src/ScadaLink.Commons/Messages/Communication/ConnectionStateChanged.cs`.
|
||||
The two dead tests (`ConnectionLost_DebugStreamsKilled` in
|
||||
CentralCommunicationActorTests, `RoundTrip_ConnectionStateChanged_Succeeds`
|
||||
in CompatibilityTests) were removed alongside. The design doc
|
||||
`docs/requirements/Component-Communication.md` "Connection Failure Behavior"
|
||||
section was updated to state explicitly that disconnect is detected at the
|
||||
transport layer (gRPC keepalive PING ~25 s for debug streams; Ask-timeout
|
||||
at the CommunicationService layer for command/control), with no
|
||||
application-level signal. `DebugStreamTerminated` survives because
|
||||
`DebugStreamBridgeActor` uses it for an unrelated intra-actor stop signal.
|
||||
|
||||
**Description**
|
||||
|
||||
`CentralCommunicationActor.HandleConnectionStateChanged` is wired to
|
||||
|
||||
Reference in New Issue
Block a user