Repository navigation
feat: add bounded local change scans and proven directory recovery - #14
Merged
Merged
Conversation
Reuse the admitted operation lease and validated destination for preparation, proof retry, and post-native reconciliation. Keep new public work rejected during Stopping. Cover both shutdown cuts with real Cloud Files and SQLite, with and without an owned feed, and verify durable state after reopening.
Capture the loss generation before each batch snapshot and recheck it after releasing the read transaction. A persisted loss marker cannot make an old checkpoint dispatchable. Cover overflow and watcher-error handoffs with real SQLite, preserve original journal fields, and verify explicit rescan recovery.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deferred, unacknowledged operations can hide later independent changes behind the default feed batch, while external directory renames can leave durable descendants at their old paths. This series adds finite typed scans and historical native evidence for atomic reconciliation of the known subtree.
Change type
breakingfeature— backward-compatible capabilities and correctionsfixChanges
@Quaternion8192owner with MirrorPulse Team attribution.Review corrections
Owner shutdown stops notification production and drains accepted renames outside the lifecycle lock. Internal feed path admission remains available during Stopping; failed drain persists a rescan fence before cancellation. A persistence failure retains the worker/store for retry, and new public work remains rejected.
Rename/undo/repeated rename uses current retained provenance to create a fresh preparation. Historical proof, manifest, and receipt remain immutable, and completed replay cannot roll current state backward.
Admitted directory moves reuse their existing lease, store, and validated target through post-native persistence. Disposal waits for completion. Real Cloud Files/SQLite regressions cover both shutdown cuts, owned-feed and no-feed configurations, queued rename tails, and reopened durable state.
Batch reads and scan capture retain the durable loss generation from before the journal snapshot. Overflow/error pending at entry or received during the read cannot disappear when its marker commits after transaction release. Eight deterministic SQLite cases cover both windows and explicit recovery.
Background source consumption does not capture the startup SynchronizationContext. Regression callbacks also run independently of the caller context, and completed read tokens cannot invalidate follow-up journal/ACK verification. A paused-context test proves durable marker persistence after the startup caller exits.
Batch placeholder creation and each provider population page now share staged native binding capture and deduplicated membership refresh. All item rows are written first; each new directory and captured ancestor is scanned and encoded once before the same transaction commits. Existing metadata limits and immutable recovery evidence are preserved. Real SQLite/Cloud Files tests use 512 files, one new directory, two shared ancestors, tombstones, and completed historical receipts; a separate capacity case verifies safe omission of oversized live metadata.
Directory move preparation resolves the validated destination parent's actual native spelling, then appends the exact requested child name. Automatic, explicit-proof, feed and failed-projection retry paths agree; case-only leaf renames remain supported and a different final-name spelling is rejected. Admitted operations continue to complete during shutdown.
Child directory projection refreshes the union of source and destination ancestors once within the same transaction. Their existing bindings and immutable historical preparation/manifest/receipt stay unchanged. Same-parent and cross-parent moves via facade or feed allow subsequent automatic parent recovery; an ancestor-write fault rolls back official rows, receipt and live metadata together, and the original proof retries successfully.
Known file moves now use the same deduplicated source/destination ancestor refresh within the official path transaction, both through the facade (including missing-source retries and its remote wrapper) and through the feed. Same-parent, cross-parent, case-only, move-out and move-in paths retain current membership for later parent recovery. Existing bindings, immutable recovery evidence and pending journal operations stay unchanged; real storage failures retain their unresolved observation/rescan fence until application reconciliation.
First discovery of a local file or directory now refreshes captured ancestor membership in the same item/journal transaction. Create and first Modified observations support later parent recovery without altering immutable preparations or inferring a binding for ordinary local children. Their legitimate rescan requirement remains.
Ordinary ancestor moves now relocate all existing managed descendant live binding paths and rebuild mutable members in the official path transaction, preserving native identities and immutable/pending history. Directories without retained bindings acquire no recovery evidence. Ordinary missing-source recovery continues to fail closed without original proof.
The existing native commit-fault fixture now reports missing checkpoints instead of rejecting the required getter. Unexpected writes still fail; strengthened assertions verify the exact original commit failure and preserve completed native work. This test-only adjustment is a separate atomic commit.
Automatic directory preparation now checks cancellation again after successful completion or capability fallback and immediately before issuing the native move. Cancellation in that window leaves native/official paths unchanged and retains committed proof metadata; the original proof remains usable after restart. Native success still completes durable recovery with CancellationToken.None.
Verification
Current head:
8ecab286a540b1113530d3955caeeb88ea6fdb86; targetsdevelop. Final-source full validation is complete; previous-head results remain historical evidence only.dab7e0fd17920908090abd5234769a136ee667ea.All40branch commits use the environment-default Quaternion8192 identity and Conventional Commits. This cancellation fix includes its tests and English XML/guide in one atomic commit. Drafts, logs and artifacts remain ignored. PR targets develop; no merge or public package publication.