THE DEFAULT FLIP (ruled on proven evidence — at-ack survived 301/301 acked-writes-through-power-cut in block-layer fault injection; deferred tree authority demonstrably loses flush-covered acks): a brain with NO stored authority artifact now ADOPTS LOG AUTHORITY AT OPEN. The oracle gates the flip exactly as the guarded adoption path always did — curable divergences baseline-backfilled, the flip lands ONLY on a green verdict — and a brain that cannot verify STAYS tree-authoritative loudly, with the refusal recorded on the switch artifact so subsequent opens are cheap. config logAuthority: 'defer' is the explicit documented opt-out (no automatic adoption; declared flush-window loss; adoptLogAuthority() flips later). A stored artifact always wins. RELEASES.md carries the posture. Two standing .fails debt pins FLIP TO HOLDING under the default: the at-ack crash-survival gap and the ack-at-log durability target — both now permanent asserted truths, not aspirations. POWER-CUT THROW SITES (fault-injection findings, brainy-alone config): - A manifest-listed-but-unloadable column segment QUARANTINES at discovery (loud once, counted always, quarantinedSegments() exposed for the heal) and the field serves its remaining segments DEGRADED — never a raw throw killing every query on the field. Real storage faults still propagate untouched. - Torn generation artifacts (NaN/garbage in manifest or counter) DISCARD with narration at the store's open and recovery re-derives — plus a defensive finite-integer guard at the init consumer. Never a RangeError killing an open. THE LOUD TORN-RECORD CONTRACT: an existing-but-unparseable stored record now surfaces as a typed, counted TornRecordError on every entity-read surface (including fifteen previously-blind per-item batch catches); ENOENT stays clean-absent; artifact readers with designed absent-recovery keep null-tolerance behind the loud floor. Disk corruption can no longer read as silent data invisibility. Suite migration: the default's pins inverted deliberately, generation baselines made relative, quarantine-contract pins rewritten to the ruled behavior. Gates: tsc 0 · unit 2065/2065 (159 files) · integration 826 (93 files) · conformance 31/31 · kill-matrix 15/15 · torn-open guards 2/2.
97 lines
4.3 KiB
TypeScript
97 lines
4.3 KiB
TypeScript
/**
|
|
* @module tests/unit/db/torn-open-guards
|
|
* @description Power-cut throw-site cures (brainy-alone fault-injection
|
|
* findings, both release-gating):
|
|
* 1. A torn generation manifest/counter (NaN/garbage where a generation
|
|
* belongs) DISCARDS with narration and re-derives — never a RangeError
|
|
* killing the open.
|
|
* 2. A manifest-listed-but-unloadable column segment QUARANTINES at
|
|
* discovery with narration; the field serves its remaining segments
|
|
* DEGRADED — never a raw throw killing every query on the field.
|
|
*/
|
|
import { describe, it, expect, afterEach } from 'vitest'
|
|
import { mkdtempSync, rmSync, readdirSync, writeFileSync, readFileSync, existsSync } from 'node:fs'
|
|
import { tmpdir } from 'node:os'
|
|
import { join } from 'node:path'
|
|
import { gzipSync } from 'node:zlib'
|
|
import { Brainy } from '../../../src/index.js'
|
|
import { NounType } from '../../../src/types/graphTypes.js'
|
|
|
|
const dirs: string[] = []
|
|
const brains: Brainy[] = []
|
|
afterEach(async () => {
|
|
for (const b of brains.splice(0)) await b.close().catch(() => {})
|
|
for (const d of dirs.splice(0)) rmSync(d, { recursive: true, force: true })
|
|
})
|
|
|
|
async function open(dir: string): Promise<Brainy> {
|
|
const b = new Brainy({ storage: { type: 'filesystem', path: dir }, requireSubtype: false })
|
|
await b.init()
|
|
brains.push(b)
|
|
return b
|
|
}
|
|
|
|
describe('torn-open guards', () => {
|
|
it('a torn generation manifest (NaN) opens with narrated discard — never a RangeError', async () => {
|
|
const dir = mkdtempSync(join(tmpdir(), 'brainy-torn-gen-'))
|
|
dirs.push(dir)
|
|
let brain = await open(dir)
|
|
const id = await brain.add({ data: 'survivor row', type: NounType.Document, metadata: { k: 1 } })
|
|
await brain.flush()
|
|
await brain.close()
|
|
brains.pop()
|
|
|
|
// The power-cut shape: the manifest's generation field is garbage.
|
|
const sys = join(dir, '_system')
|
|
const manifestPath = ['manifest.json', 'manifest.json.gz']
|
|
.map((f) => join(sys, f))
|
|
.find((p) => existsSync(p))!
|
|
const torn = { version: 1, generation: 'NaN-garbage', committedAt: 'x', horizon: null }
|
|
if (manifestPath.endsWith('.gz')) writeFileSync(manifestPath, gzipSync(JSON.stringify(torn)))
|
|
else writeFileSync(manifestPath, JSON.stringify(torn))
|
|
|
|
// Open MUST succeed (narrated discard + recovery re-derivation), and the
|
|
// durable row must still serve (log-authority replay recovers it).
|
|
brain = await open(dir)
|
|
expect((await brain.get(id))!.data).toContain('survivor row')
|
|
// Writes continue with a sane monotonic generation.
|
|
await brain.add({ data: 'post-recovery', type: NounType.Document, metadata: { k: 2 } })
|
|
expect(Number.isSafeInteger(brain.generation())).toBe(true)
|
|
}, 120000)
|
|
|
|
it('a torn column segment quarantines at discovery; the field serves remaining segments degraded — never a raw throw', async () => {
|
|
const dir = mkdtempSync(join(tmpdir(), 'brainy-torn-seg-'))
|
|
dirs.push(dir)
|
|
let brain = await open(dir)
|
|
for (let i = 0; i < 6; i++) {
|
|
await brain.add({ data: `row ${i}`, type: NounType.Document, metadata: { bucket: i % 2 } })
|
|
}
|
|
await brain.flush()
|
|
await brain.close()
|
|
brains.pop()
|
|
|
|
// Tear ONE column segment's bytes on disk (manifest keeps listing it) —
|
|
// the QUERIED field's own segment, so the quarantine path provably
|
|
// engages. Column segments live under the raw-blob root:
|
|
// `<root>/_blobs/_column_index/<field>/L<level>-<id>.bin`.
|
|
const segDir = join(dir, '_blobs', '_column_index', 'bucket')
|
|
let tornOne = false
|
|
if (existsSync(segDir)) {
|
|
for (const f of readdirSync(segDir, { withFileTypes: true })) {
|
|
if (!f.isDirectory() && /^L\d+-.*\.bin$/.test(f.name)) {
|
|
writeFileSync(join(segDir, f.name), Buffer.from([0x00, 0x01, 0x02])) // garbage
|
|
tornOne = true
|
|
break
|
|
}
|
|
}
|
|
}
|
|
expect(tornOne, 'found a segment file to tear (layout probe)').toBe(true)
|
|
|
|
// Queries on the field MUST NOT throw — degraded-announced service.
|
|
brain = await open(dir)
|
|
const rows = await brain.find({ where: { bucket: 0 }, limit: 10 })
|
|
expect(Array.isArray(rows), 'query survives the torn segment').toBe(true)
|
|
// Full completeness is NOT asserted (the torn segment's rows may be
|
|
// absent — that is the documented degraded contract until heal).
|
|
}, 120000)
|
|
})
|