diff --git a/crates/rds-agent/tests/local_sync.rs b/crates/rds-agent/tests/local_sync.rs index bed9da9..efe2684 100644 --- a/crates/rds-agent/tests/local_sync.rs +++ b/crates/rds-agent/tests/local_sync.rs @@ -302,17 +302,25 @@ async fn canceled_transfer_releases_its_slot_without_closing_tcp_or_the_session( .await .unwrap() .unwrap(); - let stats = if upload { - client - .send_file(session, &destination.join("file")) - .await - .unwrap() - } else { - client - .recv_file(session, "file", &destination) - .await - .unwrap() - }; + // Remote RESET observation is not a fence for the local manager's + // canceled worker/permit destructor. Require bounded local admission + // after cleanup; only TransferBusy is a non-admitted probe. Never + // replay an accepted transfer or hide a transport/filesystem failure. + let stats = tokio::time::timeout(Duration::from_secs(3), async { + loop { + let result = if upload { + client.send_file(session, &destination.join("file")).await + } else { + client.recv_file(session, "file", &destination).await + }; + match result { + Err(Error::Rejected(ErrorCode::TransferBusy)) => tokio::task::yield_now().await, + result => break result.unwrap(), + } + } + }) + .await + .expect("canceled local transfer did not release admission within its bound"); assert_eq!(stats.bytes, 18); assert_eq!( std::fs::read(if upload { diff --git a/docs/local-sessions.md b/docs/local-sessions.md index 1f00ed9..7d9dab2 100644 --- a/docs/local-sessions.md +++ b/docs/local-sessions.md @@ -224,7 +224,10 @@ manager session remain usable. Blocking filesystem calls already in progress cannot be revoked: cancellation, timeout or a lost reply can leave a completed commit. Inspect the destination before retrying; no automatic replay or rollback is promised. An immediate retry may encounter the remote service's transient -busy refusal while cancellation cleanup finishes. +busy refusal while cancellation cleanup finishes. A remote stream RESET is +not an acknowledgement that the independent local manager has finished +dropping its admission permit; cancellation fixtures bound that local release +without replaying an accepted transfer. `sync_send` / `sync_recv` operation telemetry records duration and `ok` / `error` / `cancelled` outcomes through the existing safe JSON and Vector