1b1385e4f7
materialize() removed the temp hard link in a finally that ran BEFORE syncDir() and before state.materialized/cursor advanced. If link() succeeded (log published) but the temp rm then threw, materialize() rejected after publishing — leaving state.materialized false, so the buffered events stayed unpersisted and every retry wedged on the "already exists" exists() backstop. Restructured to the robust shape: track link() success; on link failure remove the temp (the only reference) before propagating; on success fsync the directory, mark materialized, THEN best-effort remove the now-redundant temp link (a leftover *.tmp is harmless and never read). A temp-rm failure can no longer reject a session whose log published.