--- id: ML-169.1 title: "Phase 3: Concurrent state change safety audit" status: Done assignee: [] created_date: "2026-05-08 08:59" updated_date: "2026-05-19 08:50" labels: - audit - ready dependencies: [] references: - lib/music_library/worker/ - lib/music_library/records.ex - lib/music_library_web/components/record_form.ex modified_files: - >- docs/audits/phase3-concurrent-state-safety/doc-26 - Audit-Report-Concurrent-State-Change-Safety-Phase-3.md parent_task_id: ML-169 priority: medium ordinal: 4000 --- ## Description Audit whether background Oban worker record mutations are safely reflected in LiveView state without data corruption or stale UI. Key risks to investigate: 1. Worker-broadcast consistency: do all record-modifying workers call Records.notify_update/1? 2. Form edit + background update race: editing in RecordForm modal while worker updates record 3. Double-update handling: two workers updating same record simultaneously ## Acceptance Criteria - [x] #1 Every record-modifying Oban worker audited for notify_update/1 call after success (RefreshCover, PopulateGenres, GenerateRecordEmbedding, RecordRefreshMusicBrainzData, ImportFromMusicbrainzRelease, ImportFromMusicbrainzReleaseGroup, all RecordAll\* batch workers) - [x] #2 Workers that do NOT modify records confirmed as correctly NOT broadcasting (PruneAssets, ApplyScrobbleRules, all ArtistRefresh\*, etc.) - [x] #3 Form edit + background update race evaluated: trace what happens when RecordForm holds stale @record assign while worker broadcasts {:update, record} to parent Show page - [x] #4 Double-update race evaluated: confirm both handle_info calls apply safely (workers touch different fields, second wins) - [x] #5 ArtistLive.Show confirmed as intentionally not handling {:update, record} (artist updates use ArtistLive.Form → {:saved, artist_info} path) - [x] #6 Findings report written as a Backlog.md document with file:line references, severity ratings, and fix recommendations ## Implementation Notes Audit complete. Report written at docs/audits/phase3-concurrent-state-safety/doc-26. Key findings: - All 8 record-modifying workers correctly broadcast notify_update or broadcast_index_changed - 18 non-record workers confirmed as correctly NOT broadcasting - MEDIUM finding: form edit + background update race — handle_info({:update, record}) overwrites @record during :edit. Recommended fix: add live_action guard to both Show LiveViews. - Double-update race is SAFE: Ecto changesets only UPDATE SET changed fields, SQLite serializes writes - ArtistLive.Show confirmed intentionally not handling {:update, record}