Skip to content

fix(server): enable checkpoint_fullfsync for SQLite WAL checkpoints on macOS - #46

Closed
macodev00 wants to merge 1 commit into
mainfrom
cursor/macos-checkpoint-fullfsync-redo-261f
Closed

macodev00 wants to merge 1 commit into
mainfrom
cursor/macos-checkpoint-fullfsync-redo-261f

Conversation

@macodev00

Copy link
Copy Markdown
Owner

What Changed

The server's SQLite connection now sets PRAGMA checkpoint_fullfsync = ON immediately after enabling WAL mode, so WAL checkpoints on macOS request F_FULLFSYNC. Ordinary commits keep using plain fsync() (PRAGMA fullfsync stays off).

The same per-connection pragma is set on the t3-sqlite-state and migrate-dev-db writer connections, which bypass Sqlite.ts and can checkpoint state.sqlite.

Tests read the pragmas back on the main persistence layer and the state script: checkpoint_fullfsync = 1, fullfsync = 0.

Why

Issue pingdotgg#13544 is an accepted bug. A hard shutdown on macOS can corrupt state.sqlite because WAL checkpoints sync with fsync(), which does not flush the drive cache. Julius prescribed this fix in triage: after WAL, run PRAGMA checkpoint_fullfsync = ON, and leave ordinary fullfsync off.

This is a narrowly scoped durability fix for that hard-shutdown corruption on macOS. It is not a general product persistence default change beyond the prescribed pragma. fullfsync stays off, so per-commit sync behavior is unchanged. The pragma is a no-op on platforms without F_FULLFSYNC. It does change checkpoint durability and checkpoint cost on macOS, which is the accepted fix for pingdotgg#13544 and needs human review for that reason.

Fixes pingdotgg#13544

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in Web Open in Cursor 

A hard shutdown on macOS can corrupt state.sqlite because checkpoint syncs
use fsync(), which does not flush the drive cache. Set checkpoint_fullfsync
after WAL setup and on the other state.sqlite writers. Leave fullfsync off.

Fixes pingdotgg#13544
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS labels Sep 25, 2026
@macodev00 macodev00 closed this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Hard shutdown on macOS corrupts state.sqlite: SQLite never uses F_FULLFSYNC

1 participant