Files
tuliprox/backend/dvr/tests
DarkBreakpoint 402837289b fix(dvr): shared entries are unique, disk counts files once, terminals release
Task 10, steps 3, 5 and 7. Auditing them found three things missing and
two more that are missing and not fixed here.

Step 3. Nothing stopped two shared library entries pointing at one file.
The shared library is one library, so a second shared link is a duplicate
of itself, and it charges the shared quota twice for bytes that exist
once. `check_reference_invariant` now refuses it. One shared link
alongside any number of personal ones stays legal, which is the whole
point of sharing.

Step 5. Every quota function summed per entry, which is right for a
user's own budget -- each attached entry is charged the whole size,
because that is what that user is keeping -- and wrong for disk, which
holds the file once. `physical_bytes` counts each file once, so a disk
decision cannot be made against space that was never taken. The trait
gained `media_key` with a deliberately conservative default: a view that
does not know about sharing counts separately rather than silently
merging two files.

Step 7. A reservation is a claim on disk for bytes still to be written,
and only two of the eight paths to a terminal state released it. Worker
cancellation, both failure paths, the restart resolutions and the
expired-window paths all kept it, so a user stayed charged for space no
recording occupies. All of them release now.

The reporting had the same hole from the other side:
`split_measured_reserved_for_user_from_tasks` read the stored field
whatever the state, while `charge_for_state` had already decided a
terminal recording is charged what it measured. A terminal recording now
reports no reservation by construction, so a stale field cannot show a
user space nobody holds.

Found and not fixed, because both are larger than a test and want their
own change:

  - `recording_disk.rs` is dead. `would_fit_on_disk` and
    `active_disk_reservations` are implemented and unit-tested, and
    nothing in production calls either. Disk admission is not enforced
    at all, which is why `physical_bytes` has no caller yet.
  - There is no pre-active recheck. After a provider wait or a retry the
    worker opens the destination without revisiting quota or disk, so a
    task admitted an hour ago writes into whatever space is left now.
2026-09-02 10:43:07 -05:00
..