Skip to content

feat: add bounded local change scans and proven directory recovery - #14

Merged
Quaternion8192 merged 40 commits into
developfrom
fix/preview4-public-capabilities
Oct 8, 2026
Merged

Quaternion8192 merged 40 commits into
developfrom
fix/preview4-public-capabilities

Conversation

@Quaternion8192

@Quaternion8192 Quaternion8192 commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Deferred, unacknowledged operations can hide later independent changes behind the default feed batch, while external directory renames can leave durable descendants at their old paths. This series adds finite typed scans and historical native evidence for atomic reconciliation of the known subtree.

Change type

  • breaking
  • feature — backward-compatible capabilities and corrections
  • fix

Changes

  • Add optional SQLite journal paging and typed finite feed scans, preserving operation IDs, batch/ACK compatibility, and reconciliation fences.
  • Add independent directory preparations and proof-aware recovery. Known subtree paths, immutable receipts, formal Move observations, and checkpoints commit together; conflicts preserve unrelated rows and pending operations.
  • Fence schema 6 recovery metadata while preserving genuine preview.3 state, existing content confirmation, and default TrackAll behavior.
  • Update XML, English guides, package verification, native/subprocess and crash-recovery coverage. CODEOWNERS retains the approved @Quaternion8192 owner with MirrorPulse Team attribution.

Review corrections

  • Owner shutdown stops notification production and drains accepted renames outside the lifecycle lock. Internal feed path admission remains available during Stopping; failed drain persists a rescan fence before cancellation. A persistence failure retains the worker/store for retry, and new public work remains rejected.

  • Rename/undo/repeated rename uses current retained provenance to create a fresh preparation. Historical proof, manifest, and receipt remain immutable, and completed replay cannot roll current state backward.

  • Admitted directory moves reuse their existing lease, store, and validated target through post-native persistence. Disposal waits for completion. Real Cloud Files/SQLite regressions cover both shutdown cuts, owned-feed and no-feed configurations, queued rename tails, and reopened durable state.

  • Batch reads and scan capture retain the durable loss generation from before the journal snapshot. Overflow/error pending at entry or received during the read cannot disappear when its marker commits after transaction release. Eight deterministic SQLite cases cover both windows and explicit recovery.

  • Background source consumption does not capture the startup SynchronizationContext. Regression callbacks also run independently of the caller context, and completed read tokens cannot invalidate follow-up journal/ACK verification. A paused-context test proves durable marker persistence after the startup caller exits.

  • Batch placeholder creation and each provider population page now share staged native binding capture and deduplicated membership refresh. All item rows are written first; each new directory and captured ancestor is scanned and encoded once before the same transaction commits. Existing metadata limits and immutable recovery evidence are preserved. Real SQLite/Cloud Files tests use 512 files, one new directory, two shared ancestors, tombstones, and completed historical receipts; a separate capacity case verifies safe omission of oversized live metadata.

  • Directory move preparation resolves the validated destination parent's actual native spelling, then appends the exact requested child name. Automatic, explicit-proof, feed and failed-projection retry paths agree; case-only leaf renames remain supported and a different final-name spelling is rejected. Admitted operations continue to complete during shutdown.

  • Child directory projection refreshes the union of source and destination ancestors once within the same transaction. Their existing bindings and immutable historical preparation/manifest/receipt stay unchanged. Same-parent and cross-parent moves via facade or feed allow subsequent automatic parent recovery; an ancestor-write fault rolls back official rows, receipt and live metadata together, and the original proof retries successfully.

  • Known file moves now use the same deduplicated source/destination ancestor refresh within the official path transaction, both through the facade (including missing-source retries and its remote wrapper) and through the feed. Same-parent, cross-parent, case-only, move-out and move-in paths retain current membership for later parent recovery. Existing bindings, immutable recovery evidence and pending journal operations stay unchanged; real storage failures retain their unresolved observation/rescan fence until application reconciliation.

  • First discovery of a local file or directory now refreshes captured ancestor membership in the same item/journal transaction. Create and first Modified observations support later parent recovery without altering immutable preparations or inferring a binding for ordinary local children. Their legitimate rescan requirement remains.

  • Ordinary ancestor moves now relocate all existing managed descendant live binding paths and rebuild mutable members in the official path transaction, preserving native identities and immutable/pending history. Directories without retained bindings acquire no recovery evidence. Ordinary missing-source recovery continues to fail closed without original proof.

  • The existing native commit-fault fixture now reports missing checkpoints instead of rejecting the required getter. Unexpected writes still fail; strengthened assertions verify the exact original commit failure and preserve completed native work. This test-only adjustment is a separate atomic commit.

  • Automatic directory preparation now checks cancellation again after successful completion or capability fallback and immediately before issuing the native move. Cancellation in that window leaves native/official paths unchanged and retains committed proof metadata; the original proof remains usable after restart. Native success still completes durable recovery with CancellationToken.None.

Verification

Current head: 8ecab286a540b1113530d3955caeeb88ea6fdb86; targets develop. Final-source full validation is complete; previous-head results remain historical evidence only.

  • Pre-fix cancellation reproduction: both normal and controlled capability-fallback cases failed because the canceled call still moved. Both post-native cancellation controls passed.
  • Corrected cancellation regression 4/4, using real Cloud Files roots and SQLite with existing transaction hooks. Verifies unchanged pre-move rows/live metadata/journal, committed immutable proof/manifest without receipt, restart and original-proof retry, and completed projection despite cancellation before its commit after native success. Capability fallback is controlled exception injection at the real preparation completion boundary.
  • Whole formatting, platform matrix and18 documentation source-link cases passed. The production change is one additional cancellation check; no public signature/schema/dependency/native ABI or lifetime change.
  • Final locked restore / complete Release build (zero warnings/errors) and local ARM64 ordinary suite: 519 passed, zero failed/skipped.
  • API baseline 1/1, win-x64/win-arm64 runtime trim/AOT boundaries and dependency audit (10 projects / 25 packages).
  • Final-source DocFX: 589 files, zero warnings/errors, source commit matches head.
  • Fresh local preview.4 packages: three packages and symbol packages; isolated cache restore; all four trim/AOT combinations compiled and both ARM64 consumers executed successfully, source commit matches head.
  • Final-head CI37803790264 succeeded: x64 and ARM64 each 519/519 ordinary tests, ABI 41/41 and both package consumer matrices. All four new regressions passed on both architectures. Attempt 1 ARM64 had one existing independent-process rename sharing-conflict failure; unchanged-head failed-job rerun (attempt 2) passed all tests and package checks. Raw reports for both attempts are retained separately. CI package source matches PR test merge dab7e0fd17920908090abd5234769a136ee667ea.

All40branch commits use the environment-default Quaternion8192 identity and Conventional Commits. This cancellation fix includes its tests and English XML/guide in one atomic commit. Drafts, logs and artifacts remain ignored. PR targets develop; no merge or public package publication.

Reuse the admitted operation lease and validated destination for preparation, proof retry, and post-native reconciliation. Keep new public work rejected during Stopping. Cover both shutdown cuts with real Cloud Files and SQLite, with and without an owned feed, and verify durable state after reopening.
Capture the loss generation before each batch snapshot and recheck it after releasing the read transaction. A persisted loss marker cannot make an old checkpoint dispatchable. Cover overflow and watcher-error handoffs with real SQLite, preserve original journal fields, and verify explicit rescan recovery.
@Quaternion8192
Quaternion8192 merged commit d9e0d7f into develop Oct 8, 2026
8 of 9 checks passed
@Quaternion8192
Quaternion8192 deleted the fix/preview4-public-capabilities branch October 8, 2026 23:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant