feat(log): log authority is the fleet default — adopt-at-open, oracle-gated; plus the power-cut throw-site cures and the loud torn-record contract
THE DEFAULT FLIP (ruled on proven evidence — at-ack survived 301/301 acked-writes-through-power-cut in block-layer fault injection; deferred tree authority demonstrably loses flush-covered acks): a brain with NO stored authority artifact now ADOPTS LOG AUTHORITY AT OPEN. The oracle gates the flip exactly as the guarded adoption path always did — curable divergences baseline-backfilled, the flip lands ONLY on a green verdict — and a brain that cannot verify STAYS tree-authoritative loudly, with the refusal recorded on the switch artifact so subsequent opens are cheap. config logAuthority: 'defer' is the explicit documented opt-out (no automatic adoption; declared flush-window loss; adoptLogAuthority() flips later). A stored artifact always wins. RELEASES.md carries the posture. Two standing .fails debt pins FLIP TO HOLDING under the default: the at-ack crash-survival gap and the ack-at-log durability target — both now permanent asserted truths, not aspirations. POWER-CUT THROW SITES (fault-injection findings, brainy-alone config): - A manifest-listed-but-unloadable column segment QUARANTINES at discovery (loud once, counted always, quarantinedSegments() exposed for the heal) and the field serves its remaining segments DEGRADED — never a raw throw killing every query on the field. Real storage faults still propagate untouched. - Torn generation artifacts (NaN/garbage in manifest or counter) DISCARD with narration at the store's open and recovery re-derives — plus a defensive finite-integer guard at the init consumer. Never a RangeError killing an open. THE LOUD TORN-RECORD CONTRACT: an existing-but-unparseable stored record now surfaces as a typed, counted TornRecordError on every entity-read surface (including fifteen previously-blind per-item batch catches); ENOENT stays clean-absent; artifact readers with designed absent-recovery keep null-tolerance behind the loud floor. Disk corruption can no longer read as silent data invisibility. Suite migration: the default's pins inverted deliberately, generation baselines made relative, quarantine-contract pins rewritten to the ruled behavior. Gates: tsc 0 · unit 2065/2065 (159 files) · integration 826 (93 files) · conformance 31/31 · kill-matrix 15/15 · torn-open guards 2/2.
This commit is contained in:
parent
67c606be69
commit
214c98b4d5
23 changed files with 833 additions and 154 deletions
|
|
@ -5,19 +5,22 @@
|
|||
* doing so dropped every entity in that segment out of `filter`/`rangeQuery`/
|
||||
* `sortTopK` with no error, so a corrupt index looked like a merely short result.
|
||||
*
|
||||
* The three failure classes and their required behaviour:
|
||||
* The three failure classes and their required behaviour (torn-segment
|
||||
* QUARANTINE contract — a raw throw at query time killed every query on the
|
||||
* field forever; a silent skip hid the loss; quarantine is the middle):
|
||||
* - a real storage IO fault (EIO) PROPAGATES verbatim — a present-but-unreadable
|
||||
* segment is not "absent", so it must not read as an empty result;
|
||||
* - a manifest-listed segment with undecodable bytes throws `ColumnSegmentLoadError`;
|
||||
* - a manifest-listed segment with NO bytes (gone on disk) throws `ColumnSegmentLoadError`.
|
||||
* - a manifest-listed segment with undecodable bytes is QUARANTINED at
|
||||
* discovery: the query serves the field's remaining segments degraded and
|
||||
* `quarantinedSegments()` reports the torn segment (loud once, counted
|
||||
* always, healable);
|
||||
* - a manifest-listed segment with NO bytes (gone on disk) quarantines the
|
||||
* same way.
|
||||
* Only genuine absence stays benign: querying a field that has no manifest at all
|
||||
* returns empty (nothing was ever written for it) — that is not a fault.
|
||||
*/
|
||||
import { describe, it, expect, beforeEach } from 'vitest'
|
||||
import {
|
||||
ColumnStore,
|
||||
ColumnSegmentLoadError
|
||||
} from '../../../../src/indexes/columnStore/ColumnStore.js'
|
||||
import { ColumnStore } from '../../../../src/indexes/columnStore/ColumnStore.js'
|
||||
import { MemoryStorage } from '../../../../src/storage/adapters/memoryStorage.js'
|
||||
import { EntityIdMapper } from '../../../../src/utils/entityIdMapper.js'
|
||||
|
||||
|
|
@ -80,30 +83,44 @@ describe('ColumnStore segment-load faults surface loudly, absence stays benign (
|
|||
return s
|
||||
}
|
||||
|
||||
it('propagates a storage IO fault verbatim — not [] and not a ColumnSegmentLoadError', async () => {
|
||||
it('propagates a storage IO fault verbatim — not [] and not a quarantine (a present-but-unreadable segment is not torn)', async () => {
|
||||
storage.faultMode = 'io'
|
||||
const store = await reopen()
|
||||
await expect(store.filter('createdAt', 300)).rejects.toMatchObject({
|
||||
code: 'EIO'
|
||||
})
|
||||
// An IO fault is NOT quarantined — the segment may be fine once the disk
|
||||
// recovers; only torn/absent bytes enter the ledger.
|
||||
expect(store.quarantinedSegments('createdAt')).toEqual([])
|
||||
await store.close()
|
||||
})
|
||||
|
||||
it('throws ColumnSegmentLoadError when a manifest-listed segment is undecodable', async () => {
|
||||
it('QUARANTINES an undecodable manifest-listed segment at discovery — the query serves degraded, the ledger names the tear', async () => {
|
||||
storage.faultMode = 'corrupt'
|
||||
const store = await reopen()
|
||||
await expect(
|
||||
store.sortTopK('createdAt', 'desc', 10)
|
||||
).rejects.toBeInstanceOf(ColumnSegmentLoadError)
|
||||
// Degraded-announced serve: the field's only segment is torn, so the
|
||||
// result is empty — but the query completes instead of throwing.
|
||||
const sorted = await store.sortTopK('createdAt', 'desc', 10)
|
||||
expect(sorted).toEqual([])
|
||||
const ledger = store.quarantinedSegments('createdAt')
|
||||
expect(ledger).toHaveLength(1)
|
||||
expect(ledger[0].error).toMatch(/decode failed/)
|
||||
expect(ledger[0].hits).toBeGreaterThanOrEqual(1)
|
||||
// Subsequent queries keep serving (skip + count), never a throw.
|
||||
const hitsBefore = ledger[0].hits
|
||||
await expect(store.filter('createdAt', 300)).resolves.toBeDefined()
|
||||
expect(store.quarantinedSegments('createdAt')[0].hits).toBeGreaterThan(hitsBefore)
|
||||
await store.close()
|
||||
})
|
||||
|
||||
it('throws ColumnSegmentLoadError when a manifest-listed segment has no loadable bytes', async () => {
|
||||
it('QUARANTINES a manifest-listed segment with no loadable bytes — degraded serve, ledger entry, never a throw', async () => {
|
||||
storage.faultMode = 'missing'
|
||||
const store = await reopen()
|
||||
await expect(
|
||||
store.rangeQuery('createdAt', 100, 500)
|
||||
).rejects.toBeInstanceOf(ColumnSegmentLoadError)
|
||||
const bitmap = await store.rangeQuery('createdAt', 100, 500)
|
||||
expect(bitmap.size).toBe(0)
|
||||
const ledger = store.quarantinedSegments('createdAt')
|
||||
expect(ledger).toHaveLength(1)
|
||||
expect(ledger[0].error).toMatch(/no loadable bytes/)
|
||||
await store.close()
|
||||
})
|
||||
|
||||
|
|
|
|||
Reference in a new issue