fix(global-db): keep session schema bumps off global.db - #2992
Merged
Merged
Conversation
Every registered store installs the unified schema, so global.db also records the LCM, git correlation and workflow schema markers. Admission refused a profile authority whose marker was older, which made the LCM 14 bump list global.db as reset-required: `wipe --stale` would delete the project registry, usage accounting and remote-deletion records, and project commands refused until every project was initialized again. The profile authority holds no session rows (LCM refuses writes to any non-session store, observations and retention route to session shards). A fresh profile authority still receives the whole registered schema, whose authority triggers reference the LCM tables, but an existing one no longer admits, refuses, re-ensures or converges the LCM, git correlation or workflow schemas; their markers stay inert. Session stores keep their scoped LCM reset. The session reset acceptance cases now age global.db with the same markers, and a census case reproduces the v1.0.0-beta.65 profile shape (every store at LCM 13): one scoped reset clears the session stores and both projects stay registered without another `tracedecay init`. Fixes #2979
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Root cause
Every registered store (
global.db,user-sessions.db,projects/<id>/sessions.db) installs the one unified registered schema, soglobal.dbalso records the LCM, git-correlation and workflow schema markers. Admission (classify_registered_schema_authorities) refused any store whose marker differed, and the reset census maps a refusedStoreShardScopeV1::Profiletoprofile authority. So the LCM 13 → 14 bump (#2864) listedglobal.dbas reset-required,wipe --stalewould delete the project registry, usage accounting and remote-deletion records, and project commands refused until every project wasinit-ed again.The code shows option (a) holds:
global.dbholds no LCM data any production path reads or writes. LCM compress/boundary writes refuse non-session stores (NotASessionStore), observations (the only source oflcm_raw_messagesrows) route only toProfileSessions/ProjectSessions, retention/payload GC run overmounted_session_databases()only, the privacy rescan uses the project session DB, Work/workflows register on the project session DB, and everylcm_ingest_raw_messagecaller is a test.Change
schema_stages.rs: a store's scope now decides whether it hosts the session features. An existing profile authority no longer admits, refuses, re-ensures or converges the LCM, git-correlation or workflow schemas (SessionFeatureSchema::NotHosted). Its LCM marker is never read, and its old tables and markers stay inert. A fresh profile authority still gets the whole registered schema, because the authority triggers referencelcm_raw_messages. Session stores keep their scoped refusal and reset.EmptyEarlier, the caseglobal.dbis in), and observation markers refuse only when observation rows exist. So neither resets the registry. git correlation and workflow identity refused on any mismatch, which had the same coupling, so they get the same treatment as LCM.docs/USER-GUIDE.md: states that a session-feature schema change never resets the registry.Proof
Fail before / pass after, with the fix reverted (
hosts_session_features→true):tracedecay-global-dbschema_stages::tests::released_session_feature_markers_refuse_session_stores_but_not_the_profile_authority: FAILED (global.dbrefused("LCM", Some(13), 14)), passes with the fix.transport_acceptance_suitestale_project_sessions_census::lcm_13_profile_resets_its_session_stores_and_keeps_the_registry(the v1.0.0-beta.65 shape: every store at LCM 13): FAILED, doctor listedStore profile authority requires reset (LCM profile schema 13 ...). Passes with the fix: one census names profile sessions plus both project sessions stores, both projects stay registered through the reset withoutinit, andglobal.dbstays byte-identical.stale_sessions_store_reset::session_stores_at_shipped_lcm_schema_13_refuse_sessions_only_until_their_scoped_reset(now also agesglobal.db): FAILED (census never matched), passes with the fix. The git-correlation and workflow cases also ageglobal.dband pass, and every case now assertstracedecay_project_liststill returns the project.Runtime journey: debug
tracedecaybuilt from this branch, isolatedHOME, daemon undersystemd-run --user --scope -p MemoryMax=6G. Afterinit, every store's LCM marker was set to 13 (global.db,user-sessions.db,projects/proj_84c124fad27b5e12/sessions.db):Suites (all non-zero counts):
tracedecay-global-db --lib390 passed;transport_acceptance_suite typed_terminal_restart_acceptance17 of 18 pass after rebase. The 18th,reset_required_serving::copying_session_temporal_store_is_served_typed_until_its_named_reset, fails on master because #2975 bumped session temporal to 8 and the test still expects 7; filed as #2991. Alsomcp_suite617 passed;tracedecay-applicationlib 486,application_suite66,pr_tracking7;tracedecay-store-runtimelib 134;tracedecay-dashboard-apilib 177;tracedecay-daemon-servicelib 325.cargo clippy -p tracedecay-global-db -p tracedecay --all-targets --features tracedecay/test-transport,tracedecay/test-helpers -- -D warningsis clean,cargo fmt --all -- --checkis clean, and the Windowscargo check --workspace --all-targets --target x86_64-pc-windows-gnu --features tracedecay/test-transport,tracedecay/test-helpers,tracedecay-cli/test-transportexits 0.Fixes #2979