Files
orca/src
Neil e4d38dd8ce fix(relay): scope nextPendingExpiry the way hasDemand is scoped
`hasDemand` requires four things of a standing binding — mobile scope, matching
owner identity, matching relay host, and allowed by the live pairing policy.
`nextPendingExpiry` applied NONE of them: it took the minimum `inviteExpiresAt`
across every device in the registry. So it armed the `demandExpiryTimer` wake in
`refreshDemand` off state that provably cannot produce demand.

Three cases measured returning a wake time where `hasDemand` was already false:
a binding for a different relayHostId, a runtime-scope (non-mobile) device, and
a phone the live LAN policy excludes.

Low severity on its own — the fired timer just reconciles to no demand — but it
is spurious wakeup churn from the class that owns the correct predicate three
lines above, which is the kind of drift that stops being harmless later. The
shared clause is now `demandCandidateBinding`; the owner check stays in
`hasDemand` because `nextPendingExpiry` takes no identity. The `hasDemand` side
is a pure conjunction reorder, confirmed behaviour-preserving by mutation rather
than by eye.

Re-arming after a policy exclusion is safe: `pairingPolicyChanged()` calls
`refreshDemand()`, so a flip back to automatic restores the timer. That round
trip is asserted rather than assumed.

Also records two things next to the code that would otherwise be lost:

- Transient refs carry NO OWNER IDENTITY, so `hasDemand`'s transient loop answers
  true for any signed-in identity while the two branches below it filter on
  `ownerIdentityKey`. Nothing defends the current behaviour OR that regression:
  scoping the loop by owner fails exactly one test across the whole relay suite,
  the characterisation test added for it. Deliberately not fixed here, and the
  comment says why the in-file version is unsafe —
  `withTransientDemand('provision')` calls `setMobileRelayBinding` INSIDE the
  operation, so during a re-pair the device still holds the old owner's binding
  and an inferred filter would drop demand mid-provision, tearing the broker down
  under the operation holding the ref. The real fix threads identity through
  `acquireTransient`, whose call site is desktop-relay-service.ts.

- The `if (!current) return` guard in the release closure is unreachable today
  and mutating it away breaks nothing. Kept and labelled INERT rather than
  deleted: it goes load-bearing the moment the ledger grows a dispose()/clear(),
  and nothing in the suite would catch that.

The ref-counting core itself came back clean under every hazard exercised:
policy flip between acquire and release (the release closure is policy-blind by
construction, and the demand filter is a live pull per call rather than an
acquire-time snapshot, so neither a permanent pin nor a dropped-but-needed
demand); double release; opposite-order release of two refs on one key; and
cross-device release.
2026-09-11 01:11:22 -07:00
..