Canonical requirement state (current): R1 decision · in progress (implementation candidate: #140). A dedicated minimal PR may reference this issue; merge, release, and acceptance are separate decisions.
Summary
The canonical main Qoder ingest checkpoint writer uses one shared <checkpoint>.tmp name and a final rename with no cross-process serialization. Concurrent ingests of the same transcript can overwrite a newer LastLine with an older value, or race on the same staging path. A regressed cursor causes avoidable re-ingestion and undermines the documented monotonic incremental-ingest behavior.
Source reproduction
On main @ cc727db0bc72655f299166de1f60756f5c686cc7, server/cmd/mem/qoder_checkpoint.go writes every checkpoint through p + ".tmp" and unconditionally renames it over p. Two writers for the same transcript therefore have neither a unique staging name nor a compare/serialization point before commit.
Affected area
server/cmd/mem/qoder_checkpoint.go
- Qoder incremental ingest checkpoint persistence only.
Scope boundary
This is separate from draft PR #129 and Issue #111. It must ship as a clean current-main bug fix, not by reviving the stale draft. It does not change transcript format, the ingest command contract, remote API behavior, or checkpoint semantics other than guaranteeing non-regression under concurrent writers.
Evidence level
E2 — canonical-source race analysis; implementation must add deterministic E3-style regression evidence without real credentials or user transcript data.
Summary
The canonical
mainQoder ingest checkpoint writer uses one shared<checkpoint>.tmpname and a final rename with no cross-process serialization. Concurrent ingests of the same transcript can overwrite a newerLastLinewith an older value, or race on the same staging path. A regressed cursor causes avoidable re-ingestion and undermines the documented monotonic incremental-ingest behavior.Source reproduction
On
main @ cc727db0bc72655f299166de1f60756f5c686cc7,server/cmd/mem/qoder_checkpoint.gowrites every checkpoint throughp + ".tmp"and unconditionally renames it overp. Two writers for the same transcript therefore have neither a unique staging name nor a compare/serialization point before commit.Affected area
server/cmd/mem/qoder_checkpoint.goScope boundary
This is separate from draft PR #129 and Issue #111. It must ship as a clean current-main bug fix, not by reviving the stale draft. It does not change transcript format, the ingest command contract, remote API behavior, or checkpoint semantics other than guaranteeing non-regression under concurrent writers.
Evidence level
E2 — canonical-source race analysis; implementation must add deterministic E3-style regression evidence without real credentials or user transcript data.