Skip to content

Pin what the retention cursor does, not what it was meant to do - #1998

Merged
ppXD merged 1 commit into
mainfrom
fix/pin-what-the-retention-cursor-actually-does
Sep 19, 2026
Merged

ppXD merged 1 commit into
mainfrom
fix/pin-what-the-retention-cursor-actually-does

Conversation

@ppXD

@ppXD ppXD commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Summary

  • The "every citation site is probed" check matched the whole cursor file, and the drain reads ArtifactObjectId in three other places — so deleting SharesBytesAsync's sibling-segment probe reddened nothing. It now reads only the AnyAsync existence questions inside the two citation methods: a table is a citation site when something asks whether a row still names the bytes, not when the cursor happens to read the column.
  • agentRunLogsApi.test.ts pinned code: "log_bytes_purged", a literal it invented. The controller sends ProblemCode = problem.Code.ToString(), so the wire code is "Purged". Both sides now pin the real strings, and the backend half (A_purged_read_puts_its_availability_and_code_on_the_wire_verbatim) fails first if the enum member is renamed.
  • The audit actor was pinned by value with nothing asserting the cursor passed it. The purge requests are captured at the IArtifactCasPurgeCoordinator seam and asserted — actor, team, and the placement id that an unnamed claim would have refused to choose between.
  • DrainedOrLostAsync treated an object as drained when ANY placement rested at Purged, so a deduplicated object with one placement this plane purged beside one another path deleted earned a policy tombstone over a partial loss. Every placement has to rest at Purged now — the state only this lifecycle writes.

Test plan

  • Unit: full suite 10831 passed / 1 skipped / 0 failed.
  • Integration (real Postgres + real local-rwx destination): 188 passed / 0 failed across Retention|AgentRunLog|ArtifactLocationVerifier in one invocation; the retention class is 27 tests, two of them new.
  • Frontend: pnpm build ✓, pnpm lint 0 errors, vitest src/api/agentRunLogsApi.test.ts 12 passed.
  • Mutations run, each named test red then green again: the sibling-segment probe deleted; the wire code renamed to something else for Purged; the actor dropped from the purge request; any Purged placement read as drained.

Four checks that were reading the wrong thing.

The "every citation site is probed" test matched the whole cursor file, and
the drain reads ArtifactObjectId in three other places — so deleting the
sibling-segment probe reddened nothing. It now reads only the existence
questions inside the two citation methods, which is what makes a table a
site rather than one the cursor happens to touch.

The web client's test pinned a code it invented. The wire carries the
AgentRunLogProblemCode name verbatim, so both sides now pin "Purged", and
the backend half fails first if the enum member is ever renamed.

The audit actor was pinned by value and by nothing else; the cursor could
have passed anything. The purge requests are captured at the coordinator
seam and asserted — actor, team, and the placement id an unnamed claim
would have refused to choose.

And a drained stream needed only ONE placement resting at Purged, so a
deduplicated object with one purged placement beside one another path
deleted earned a policy tombstone over a partial loss. Every placement has
to rest at Purged now.
@ppXD
ppXD merged commit e2035d1 into main Sep 19, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant