This repository has no description

s3: fix five defects a self-review found in the spool/salvage work master

An adversarial review pass over the resilience branch surfaced these; all are now fixed and covered by tests: - Recorder failures were only logged in spool mode, but the spool was still acked — an object could complete in S3 with no completed s3_segments row, invisible to finalize forever, with the local copy deleted. objectWriter gains strictRecorder (set by the spool loop and salvage): RecordStart/RecordComplete errors now fail the object so the still-spooled segments retry into a properly-recorded one. - Startup salvage could race a stream session that begins during the boot window and drain/destroy its live spool. SalvageSpools now takes a boot-time cutoff captured before any listener starts; session dirs are named by creation UnixNano, so anything at/after the cutoff is a live session of this process and is never touched. - A retry that succeeded mid-object left retryAt set in the past, re-arming the wake timer every ~100ms until the object completed (up to cutoverEvery). process() now clears retryAt once it's due; backoff still only resets on a completed object. - Salvaged object keys could collide (objSeq resets per spool; keys are second-granularity mtime + objSeq), silently overwriting objects across spools or from the crashed run. Salvage keys now embed the spool session name (-salvaged-<session>). - Spool segment writes were neither fsynced nor atomic, so a host crash could lose acked segments or leave torn files that salvage would splice into a recording. Append now writes tmp + fsync + rename (and syncs meta.jsonl URI epochs); OpenSpool sweeps orphaned .tmp files. Also: a cutover now overrides any backoff with one immediate attempt, so a stream ending during an S3 blip completes its tail as soon as possible rather than waiting out the timer. Known remaining gaps (documented, need design input): segments salvaged or retried after a VOD finalize has already run reach the bucket but nothing re-triggers finalize; and a crash exactly between RecordComplete and spool Ack can duplicate one object's footage at finalize (no overlap dedup). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>