From de47ce8cd2bfbefb25dc2ccd15410d545b98f59a Mon Sep 17 00:00:00 2001 From: Arnaud Gourlay Date: Wed, 12 Aug 2026 13:51:05 +0200 Subject: [PATCH] fix: do not panic when the global quota manager is installed twice (#10185) `TableOfContent::new` installs the process-global quota manager, and `set_global` treated a second install as a startup-order bug worth a `debug_assert!`. A test binary runs all of its tests in a single process, and every test that builds a table of contents installs the manager again, so all but the first one panic. Building several tables of contents in one process is legitimate for test harnesses, so the second install is no longer fatal. A node that installs twice still reports it loudly through the existing error log. Co-authored-by: Claude Opus 5 (1M context) --- lib/shard/src/quota/mod.rs | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/lib/shard/src/quota/mod.rs b/lib/shard/src/quota/mod.rs index f56b74e30f..8df32e22cf 100644 --- a/lib/shard/src/quota/mod.rs +++ b/lib/shard/src/quota/mod.rs @@ -36,15 +36,16 @@ static GLOBAL: OnceLock> = OnceLock::new(); /// Install the node's quota manager, once at startup before anything measures a /// resource. `storage` does it while building the table of contents. /// -/// A second call is a startup-order bug — the quota it configures would silently -/// not be the one enforced — so it is loud rather than ignored. +/// In a node, a second call is a startup-order bug: the quota it configures +/// would silently not be the one enforced, so it is logged loudly. It is not +/// fatal, because test harnesses legitimately build several tables of contents +/// in one process, and the first one installed is as good as any there. pub fn set_global(manager: Arc) { if GLOBAL.set(manager).is_err() { log::error!( "Global quota manager was already initialized; \ the quota configured for this node is not the one being enforced", ); - debug_assert!(false, "global quota manager initialized twice"); } }