Skip to content

A store the sink creates keeps the identity its index carries - #194

Open
torstei wants to merge 1 commit into
mainfrom
bugfix/identity-after-bare-create
Open

torstei wants to merge 1 commit into
mainfrom
bugfix/identity-after-bare-create

Conversation

@torstei

@torstei torstei commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Problem

timberfs create s.log writes no manifest. After append --records ran once, the next open failed:

the manifest says the store is 6056… and its index says 27b7… — two identities for one store

A pair gets its identity when its index is created, and bark::save adopts that identity into a manifest that has none (its comment says so, and says with_identity is the last resort for a store not on disk yet). The records sink called with_identity first, which mints one, so save found an id already present and adopted nothing. The manifest and the index then named different stores.

It was hidden wherever a manifest existed before the first append: the shipped unit runs timberfs set host=… first, which creates one. A bare create followed by an append, or a sink writing to a path nothing had set up, hit it.

Change

sink.rs hands save the manifest as it is, on both paths that write one: the end of the stream and the graceful exit. Nothing else changes: export mints for a bundle that does not exist on disk yet, and incus_intake mints the id before it creates the pair, as its comment explains.

Test

Runs the sink twice on a store with no manifest and checks that the manifest and the index carry the same id and that the second open succeeds. It fails on the previous code at the identity assertion. The same repro through the CLI (create, then three appends) now opens every time, and info shows one identity.

A store that already hit it

timberfs identity <store> reports the disagreement, and --keep index or --keep manifest resolves it. The manifest side is the one readers were using.

🤖 Generated with Claude Code

A pair gets its identity when its index is created, and bark::save adopts
that identity into a manifest that has none. The records sink called
with_identity first, which mints one, so save found an id already there and
adopted nothing: a store whose first writer was the sink ended up with a
manifest and an index naming different stores, and the next open refused it
as two identities for one store.

Only a store with no manifest before its first append was affected; a
manifest written first (the unit runs `set host=` before the appender) hides
it. The sink now hands save the manifest as it is, on the end-of-stream path
and on the graceful-exit path.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant