fdeb09a596
A host timeout previously left the timed-out worker holding the durable per-session compression lock AND refreshing its lease indefinitely, so a truly hung summary blocked every later compression attempt; and a LATE successful summary could clear the failure cooldown the host had just recorded. Transplant the lease-cancellation invariants from PR #71569 (@ciabata-git): the worker publishes an idempotent, holder-scoped release hook on the fence once it owns the durable lock (begin_lock_setup / register_cancelled_lock_release close the acquire→publish race), the refresher start is serialized against the release path, and the host invokes the hook on idle timeout, hygiene timeout, and every unwind (revoke_commit_admission now also releases). ABA safety: the SessionDB release is holder-qualified (DELETE ... WHERE holder = ?), so a stale release can never free a replacement holder's lease. State ordering: the compressor consults a fence-cancellation check BEFORE clearing the failure cooldown, so a late worker cannot undo the host's timeout cooldown; the check is installed only for the fenced call and removed in a finally. Regression implements the reviewer's exact 5-step scenario: summary blocked indefinitely → host timeout → a NEW compressor acquires the durable lock while the old summary is STILL blocked → old worker released → it cannot clear cooldown, release the new holder's lease, or publish stale state. PR #76354 review, blocking finding 4 / merge gates 4 + 5. Co-authored-by: ciabata-git <ciabata-git@users.noreply.github.com>