fix(deploy+cli): review findings — honest CLI timeouts, watermark-complete staleness, phase-2 staging, lock-safe cancellation

Six adversarial-review findings, each verified against the code first.

F1 (HIGH) CLI HttpClient capped every call at min(30s, caller timeout),
silently truncating deploy site's 5-minute BulkDeployTimeout and the
5-minute bundle export/preview/import calls — which printed a fake
"504 Request timed out" while the server kept working. HttpClient.Timeout
is now Timeout.InfiniteTimeSpan (the per-call CTS is the single overall
deadline, connect included) with the connect phase bounded separately on
SocketsHttpHandler.ConnectTimeout. The env override is renamed to
SCADABRIDGE_HTTP_CONNECT_TIMEOUT_SECONDS to match its new meaning.

F2 (HIGH) StaleInstanceProbe's process-static memo served stale hashes
because nothing bumped the watermark on three paths:
  (a) BundleImporter commits through the raw DbContext, so no import ever
      moved the watermark — a second import overwriting the same template
      could be OMITTED from ImportResult.StaleInstanceIds. It now bumps
      once per apply ATTEMPT: after the commit, and after the rollback too
      (the probe runs pre-commit, so a rolled-back attempt leaves memos for
      state that never landed; bumping on both paths is the simplest
      correct shape, versus threading transaction awareness through a
      process-static cache).
  (b) CollectWatermarkBumps' default: arm silently no-op'd, contradicting
      its own doc. It now sets unattributed=true — an over-broad bump costs
      extra work, a missed one produces stale work.
  (c) DataConnection edits route through SiteRepository.SaveChangesAsync,
      which had no watermark at all, yet Protocol/Primary+Backup config/
      FailoverRetryCount are revision-hash inputs. It now bumps (BumpAll —
      a connection has no owning template) after a commit that touched one.

F3 (MED) CLI TemplateTableProjection read child ARRAYS, but ListTemplates
now returns database-projected TemplateSummary rows, so template list
printed all zeros. It now prefers the *Count scalars and falls back to
array length (template get still returns full entities). --detail help
text and README corrected: a listing cannot yield definitions, so --detail
renders the raw summary payload and template get --id is the full dump.

F4 (MED) DeploySiteAsync staged every PendingDeployment in phase 1 against
a 5-min TTL while phase 2 reached them one batch at a time, so tail
instances' fetch tokens could expire before their command was sent.
Staging moved into phase 2, immediately before each send; prepare keeps
its flatten/validate/record work. The staging write is the phase's only
repository touch and is serialised behind a 1-permit semaphore, so the
non-thread-safe DbContext constraint holds and the sends stay concurrent.

F5 (MED, latent) DeploySiteAsync leaked every held operation lock if
cancelled — a wedged per-instance semaphore is permanent for the process.
Phase 2 no longer throws (cancellation is recorded as a per-instance
outcome so phase 3 still runs), and an escape from phase 1 or 3 now
unwinds every unfinalised entry: Failed status + lock release.

F6 (LOW) ScriptCompileVerdictCache's promotion wrote hot directly,
bypassing SegmentCapacity (true ceiling 3x against a documented 2x).
Promotion now goes through Store, keeping generational semantics; _hot
and _cold are volatile.

Tests: CLI 396, DeploymentManager 133, ManagementService 494,
TemplateEngine 478, ScriptAnalysis 60, Transport 157, Transport
integration 106, ConfigurationDatabase 366 — all green, 0 build warnings.
The F2/F4/F5 regression tests were each confirmed to FAIL with their fix
reverted.
This commit is contained in:
Joseph Doherty
2026-08-14 23:51:04 -04:00
parent b1de9dfdd4
commit e0e4b24679
16 changed files with 1172 additions and 174 deletions
@@ -7,6 +7,7 @@ using ZB.MOM.WW.ScadaBridge.Commons.Entities.Sites;
using ZB.MOM.WW.ScadaBridge.Commons.Entities.Templates;
using ZB.MOM.WW.ScadaBridge.Commons.Types.Enums;
using ZB.MOM.WW.ScadaBridge.Commons.Types.Notifications;
using ZB.MOM.WW.ScadaBridge.Commons.Types.Templates;
using ZB.MOM.WW.ScadaBridge.ConfigurationDatabase;
using ZB.MOM.WW.ScadaBridge.ConfigurationDatabase.Repositories;
using ZB.MOM.WW.ScadaBridge.ConfigurationDatabase.Services;
@@ -906,6 +907,71 @@ public class SiteRepositoryTests : IDisposable
{
Assert.Throws<ArgumentNullException>(() => new SiteRepository(null!));
}
/// <summary>
/// A data connection's protocol and primary/backup configuration are flattening
/// inputs — <c>FlatteningService</c> packages them into the flattened config's
/// <c>Connections</c> map and <c>RevisionHashService</c> folds them into the
/// revision hash. Without a watermark bump on save, the process-wide
/// <c>StaleInstanceProbe</c> memo and the flatten-session caches keep serving the
/// pre-edit hash, so an instance whose deployed config genuinely drifted reads as
/// up to date. (The bump is unattributed — a connection has no owning template —
/// so both the global and structure counters must move.)
/// </summary>
[Fact]
public async Task SaveChanges_DataConnectionEdit_BumpsWatermark()
{
var watermark = new TemplateGraphWatermark();
var repository = new SiteRepository(_context, watermark);
var site = new Site("Site1", "S-001");
await repository.AddSiteAsync(site);
await repository.SaveChangesAsync();
var afterSiteOnly = (watermark.Global, watermark.StructureVersion);
var conn = new DataConnection("Conn1", "OpcUa", site.Id);
await repository.AddDataConnectionAsync(conn);
await repository.SaveChangesAsync();
Assert.True(watermark.Global > afterSiteOnly.Global, "adding a data connection did not bump the global watermark");
Assert.True(watermark.StructureVersion > afterSiteOnly.StructureVersion,
"adding a data connection did not bump the structure watermark");
var afterAdd = (watermark.Global, watermark.StructureVersion);
conn.Protocol = "MxGateway";
await repository.UpdateDataConnectionAsync(conn);
await repository.SaveChangesAsync();
Assert.True(watermark.Global > afterAdd.Global, "editing a data connection did not bump the watermark");
var afterUpdate = watermark.Global;
await repository.DeleteDataConnectionAsync(conn.Id);
await repository.SaveChangesAsync();
Assert.True(watermark.Global > afterUpdate, "deleting a data connection did not bump the watermark");
}
/// <summary>
/// The bump is scoped to the entity that actually feeds the flattener: a save
/// that touches no data connection must leave the watermark alone, or every
/// site/area edit would needlessly invalidate the whole flatten cache.
/// </summary>
[Fact]
public async Task SaveChanges_WithoutDataConnectionChange_DoesNotBumpWatermark()
{
var watermark = new TemplateGraphWatermark();
var repository = new SiteRepository(_context, watermark);
var site = new Site("Site1", "S-001");
await repository.AddSiteAsync(site);
await repository.SaveChangesAsync();
Assert.Equal(0, watermark.Global);
Assert.Equal(0, watermark.StructureVersion);
}
}
public class DeploymentManagerRepositoryTests : IDisposable