Pin what the retention cursor does, not what it was meant to do - #1998
Merged
Merged
Conversation
Four checks that were reading the wrong thing. The "every citation site is probed" test matched the whole cursor file, and the drain reads ArtifactObjectId in three other places — so deleting the sibling-segment probe reddened nothing. It now reads only the existence questions inside the two citation methods, which is what makes a table a site rather than one the cursor happens to touch. The web client's test pinned a code it invented. The wire carries the AgentRunLogProblemCode name verbatim, so both sides now pin "Purged", and the backend half fails first if the enum member is ever renamed. The audit actor was pinned by value and by nothing else; the cursor could have passed anything. The purge requests are captured at the coordinator seam and asserted — actor, team, and the placement id an unnamed claim would have refused to choose. And a drained stream needed only ONE placement resting at Purged, so a deduplicated object with one purged placement beside one another path deleted earned a policy tombstone over a partial loss. Every placement has to rest at Purged now.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ArtifactObjectIdin three other places — so deletingSharesBytesAsync's sibling-segment probe reddened nothing. It now reads only theAnyAsyncexistence questions inside the two citation methods: a table is a citation site when something asks whether a row still names the bytes, not when the cursor happens to read the column.agentRunLogsApi.test.tspinnedcode: "log_bytes_purged", a literal it invented. The controller sendsProblemCode = problem.Code.ToString(), so the wire code is"Purged". Both sides now pin the real strings, and the backend half (A_purged_read_puts_its_availability_and_code_on_the_wire_verbatim) fails first if the enum member is renamed.IArtifactCasPurgeCoordinatorseam and asserted — actor, team, and the placement id that an unnamed claim would have refused to choose between.DrainedOrLostAsynctreated an object as drained when ANY placement rested atPurged, so a deduplicated object with one placement this plane purged beside one another path deleted earned a policy tombstone over a partial loss. Every placement has to rest atPurgednow — the state only this lifecycle writes.Test plan
Retention|AgentRunLog|ArtifactLocationVerifierin one invocation; the retention class is 27 tests, two of them new.pnpm build✓,pnpm lint0 errors,vitest src/api/agentRunLogsApi.test.ts12 passed.Purged; the actor dropped from the purge request; anyPurgedplacement read as drained.