Skip to content

fix(rust_brain): preserve HLC timestamps on snapshot restore and gossip - #74

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-investigation-0830
Draft

fix(rust_brain): preserve HLC timestamps on snapshot restore and gossip#74
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-investigation-0830

Conversation

@cursor

@cursor cursor Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Bug and impact

restore_from_file() assigned fresh HLC timestamps instead of restoring the snapshotted values. After disaster recovery, gossip replays and causal successor writes with pre-crash HLC were rejected with TimestampRegressionsilent data loss in distributed deployments.

Concrete trigger: Snapshot a node with hlc=(5000, 10, "nodeA"), restore, then attempt a causal successor write with hlc=(5000, 11, "nodeA"). The write fails because restore assigned a fresh wall-clock HLC far in the future.

Root cause

v0.6.0 added HLC-based monotonic ordering, but restore_from_file(), bulk_write(), and gossip.receive() never preserved or applied HLC timestamps from their payloads.

Fix

  • Add _parse_hlc() for wire/snapshot normalisation (backward-compatible with pre-v0.6.0 snapshots)
  • Restore HLC and advance global clock on snapshot restore
  • Pass HLC through bulk_write() row payloads
  • Apply HLC in gossip.receive() with stale-update rejection
  • Hold lock during restore to prevent concurrent mutation

Validation

  • Reproduced bug on main: HLC not preserved, successor write rejected
  • 29 targeted tests pass: test_hlc_snapshot_gossip.py, test_enterprise_backup.py, test_gossip.py, test_rust_brain.py
Open in Web View Automation 

restore_from_file() assigned fresh HLC values instead of restoring the
snapshotted timestamps. After disaster recovery, gossip replays and
causal successor writes with pre-crash HLC were rejected with
TimestampRegression — silent data loss in distributed deployments.

- Add _parse_hlc() for wire/snapshot normalisation
- Restore HLC and advance global clock on snapshot restore
- Pass HLC through bulk_write() row payloads
- Apply HLC in gossip.receive() with stale-update rejection
- Hold lock during restore to prevent concurrent mutation

Regression tests in test_hlc_snapshot_gossip.py (29 targeted tests pass).

Co-authored-by: Daniel <DJLougen@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant